Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-27xm-32ch-hh9g |
|
MINI-27xm-32ch-hh9g |
| MINI-v6j2-6x8w-fw84 |
|
MINI-v6j2-6x8w-fw84 |
| MINI-qgp8-xw2q-f8cx |
|
MINI-qgp8-xw2q-f8cx |
| MAL-2026-6080 |
|
Vulnerability in boardflow (MAL-2026-6080)
vulnerability in boardflow (MAL-2026-6080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48823 |
|
Cross-Site Scripting (XSS) in CVE-2026-48823 (CVE-2026-48823)
cross-site scripting in CVE-2026-48823 (CVE-2026-48823). Confidential information can be exposed externally.
|
| CVE-2026-48822 |
|
Cross-Site Scripting (XSS) in CVE-2026-48822 (CVE-2026-48822)
cross-site scripting in CVE-2026-48822 (CVE-2026-48822). Confidential information can be exposed externally.
|
| CVE-2026-48814 |
|
Vulnerability in network-ai (CVE-2026-48814)
vulnerability in network-ai (CVE-2026-48814). Confidential information can be exposed externally. Exploitable via `POST /mcp`. Mitigation: upgrade to `5.7.2` or later.
|
| UBUNTU-CVE-2026-55200 |
|
Vulnerability in libssh2 (UBUNTU-CVE-2026-55200)
vulnerability in libssh2 (UBUNTU-CVE-2026-55200). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.11.1-1ubuntu0.25.10.2` or later.
|
| UBUNTU-CVE-2026-55199 |
|
Vulnerability in libssh2 (UBUNTU-CVE-2026-55199)
vulnerability in libssh2 (UBUNTU-CVE-2026-55199). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.11.0-4.1ubuntu0.24.04.2` or later.
|
| UBUNTU-CVE-2026-55202 |
|
Vulnerability in tinyproxy (UBUNTU-CVE-2026-55202)
vulnerability in tinyproxy (UBUNTU-CVE-2026-55202). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| UBUNTU-CVE-2026-54388 |
|
Vulnerability in tinyproxy (UBUNTU-CVE-2026-54388)
vulnerability in tinyproxy (UBUNTU-CVE-2026-54388). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-54387 |
|
Vulnerability in tinyproxy (UBUNTU-CVE-2026-54387)
vulnerability in tinyproxy (UBUNTU-CVE-2026-54387). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-48823 |
|
Vulnerability in shaarli (UBUNTU-CVE-2026-48823)
vulnerability in shaarli (UBUNTU-CVE-2026-48823). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-48822 |
|
Vulnerability in shaarli (UBUNTU-CVE-2026-48822)
vulnerability in shaarli (UBUNTU-CVE-2026-48822). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-48817 |
|
Vulnerability in starlette (UBUNTU-CVE-2026-48817)
vulnerability in starlette (UBUNTU-CVE-2026-48817). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-48818 |
|
Vulnerability in starlette (UBUNTU-CVE-2026-48818)
vulnerability in starlette (UBUNTU-CVE-2026-48818). Confidential information can be exposed externally. Mitigation: upgrade to `1.1.0` or later.
|
| GHSA-fq5h-gc4g-76cp |
|
Vulnerability in opt-archetype-check (GHSA-fq5h-gc4g-76cp)
vulnerability in opt-archetype-check (GHSA-fq5h-gc4g-76cp). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6076 |
|
Vulnerability in pystylish (MAL-2026-6076)
vulnerability in pystylish (MAL-2026-6076). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| MAL-2026-6069 |
|
Vulnerability in @civitatis/bot-ui (MAL-2026-6069)
vulnerability in @civitatis/bot-ui (MAL-2026-6069). Risk of unauthorized operations or information disclosure. Exploitable via ``child_process``.
|
| CVE-2026-55590 |
|
Open Redirect in cakephp/authentication (CVE-2026-55590)
vulnerability in cakephp/authentication (CVE-2026-55590). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.11.1` or later.
|
| CVE-2026-55518 |
|
Vulnerability in avo (CVE-2026-55518)
vulnerability in avo (CVE-2026-55518). Confidential information can be exposed externally. Exploitable via `GET /resources/`. Mitigation: upgrade to `4.0.0.beta.51` or later.
|
| CVE-2026-55517 |
|
Vulnerability in deno (CVE-2026-55517)
vulnerability in deno (CVE-2026-55517). Risk of unauthorized operations or information disclosure. Exploitable via ``WebSocket``. Mitigation: upgrade to `2.7.5` or later.
|
| CVE-2026-55471 |
|
XXE (XML External Entity) in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471). Confidential information can be exposed externally. Exploitable via `GET /evil-fhir-xslt-ssrf.dtd`. Mitigation: upgrade to `6.9.10` or later.
|
| CVE-2026-55470 |
|
Vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-55470)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-55470). Risk of unauthorized operations or information disclosure. Exploitable via ``RegexTimeout``. Mitigation: upgrade to `6.9.10` or later.
|
| CVE-2026-55450 |
|
Information Disclosure in langflow (CVE-2026-55450)
vulnerability in langflow (CVE-2026-55450). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/upload/{flow_id}`. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-55760 |
|
Path Traversal in com.github.jknack:handlebars (CVE-2026-55760)
path traversal in com.github.jknack:handlebars (CVE-2026-55760). Confidential information can be exposed externally. Mitigation: upgrade to `4.5.2` or later.
|
| CVE-2026-55409 |
|
Cross-Site Scripting (XSS) in filament/forms (CVE-2026-55409)
cross-site scripting in filament/forms (CVE-2026-55409). Confidential information can be exposed externally. Exploitable via ``RichEditor``. Mitigation: upgrade to `3.3.53` or later.
|
| CVE-2026-55405 |
|
SQL Injection in dev.langchain4j:langchain4j-mariadb (CVE-2026-55405)
SQL injection in dev.langchain4j:langchain4j-mariadb (CVE-2026-55405). Confidential information can be exposed externally. Exploitable via ``COMBINED_JSON``. Mitigation: upgrade to `1.16.3-beta26` or later.
|
| MAL-2026-6070 |
|
Vulnerability in libsc-runtime-telemetry (MAL-2026-6070)
vulnerability in libsc-runtime-telemetry (MAL-2026-6070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30799 |
|
Vulnerability in rti (CVE-2026-30799)
vulnerability in rti (CVE-2026-30799). Data can be tampered with by attackers.
|
| CVE-2026-48591 |
|
Cross-Site Scripting (XSS) in earmark (CVE-2026-48591)
cross-site scripting in earmark (CVE-2026-48591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39199 |
|
snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
|
| CVE-2026-3894 |
|
Out-of-Bounds Read in rti (CVE-2026-3894)
vulnerability in rti (CVE-2026-3894). Confidential information can be exposed externally.
|
| CVE-2026-7300 |
|
Vulnerability in rti (CVE-2026-7300)
vulnerability in rti (CVE-2026-7300). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53805 |
|
Unsafe Deserialization in CVE-2026-53805 (CVE-2026-53805)
vulnerability in CVE-2026-53805 (CVE-2026-53805). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30803 |
|
Vulnerability in rti (CVE-2026-30803)
vulnerability in rti (CVE-2026-30803). Confidential information can be exposed externally.
|
| GHSA-4mpj-78p6-rj59 |
|
Vulnerability in picklescan (GHSA-4mpj-78p6-rj59)
vulnerability in picklescan (GHSA-4mpj-78p6-rj59). Successful exploitation can lead to full system takeover.
|
| GHSA-cc5p-54x3-hcf8 |
|
Vulnerability in picklescan (GHSA-cc5p-54x3-hcf8)
vulnerability in picklescan (GHSA-cc5p-54x3-hcf8). Risk of unauthorized operations or information disclosure.
|
| GHSA-5v23-73v4-w2fp |
|
Path Traversal in picklescan (GHSA-5v23-73v4-w2fp)
path traversal in picklescan (GHSA-5v23-73v4-w2fp). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.35` or later.
|
| GHSA-82fg-2r99-h7v6 |
|
Vulnerability in picklescan (GHSA-82fg-2r99-h7v6)
vulnerability in picklescan (GHSA-82fg-2r99-h7v6). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.4` or later.
|
| GHSA-j6c9-qvp8-699f |
|
Unsafe Deserialization in picklescan (GHSA-j6c9-qvp8-699f)
vulnerability in picklescan (GHSA-j6c9-qvp8-699f). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2674 |
|
Out-of-Bounds Write in rti (CVE-2026-2674)
out-of-bounds write in rti (CVE-2026-2674). Data can be tampered with by attackers.
|
| CVE-2026-20190 |
|
Vulnerability in cisco (CVE-2026-20190)
vulnerability in cisco (CVE-2026-20190). Confidential information can be exposed externally.
|
| CVE-2026-53873 |
|
Vulnerability in picklescan (CVE-2026-53873)
vulnerability in picklescan (CVE-2026-53873). Successful exploitation can lead to full system takeover. Exploitable via ``profile.Profile.run``. Mitigation: upgrade to `1.0.4` or later.
|
| CVE-2026-53875 |
|
Vulnerability in picklescan (CVE-2026-53875)
vulnerability in picklescan (CVE-2026-53875). Risk of unauthorized operations or information disclosure. Exploitable via ``scan_pytorch``. Mitigation: upgrade to `1.0.3` or later.
|
| CVE-2026-35068 |
|
SQL Injection in sqli (CVE-2026-35068)
SQL injection in sqli (CVE-2026-35068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36418 |
|
Code Injection in CVE-2026-36418 (CVE-2026-36418)
code injection in CVE-2026-36418 (CVE-2026-36418). Confidential information can be exposed externally.
|
| CVE-2026-53874 |
|
Unsafe Deserialization in picklescan (CVE-2026-53874)
vulnerability in picklescan (CVE-2026-53874). Successful exploitation can lead to full system takeover. Exploitable via ``eval``. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-12515 |
|
Vulnerability in katello (CVE-2026-12515)
vulnerability in katello (CVE-2026-12515). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0.rc1` or later.
|
| CVE-2026-32652 |
|
Vulnerability in dell (CVE-2026-32652)
vulnerability in dell (CVE-2026-32652). Successful exploitation can lead to full system takeover.
|