Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-11525 |
|
Vulnerability in undici (CVE-2026-11525)
vulnerability in undici (CVE-2026-11525). Risk of unauthorized operations or information disclosure. Exploitable via ``SameSite``. Mitigation: upgrade to `8.5.0` or later.
|
| UBUNTU-CVE-2026-11525 |
|
Vulnerability in node-undici (UBUNTU-CVE-2026-11525)
vulnerability in node-undici (UBUNTU-CVE-2026-11525). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`.
|
| UBUNTU-CVE-2026-39199 |
|
snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file. |
| CVE-2026-55636 |
|
Authorization Flaw in github.com/projectcapsule/capsule (CVE-2026-55636)
vulnerability in github.com/projectcapsule/capsule (CVE-2026-55636). Data can be tampered with by attackers. Exploitable via ``rules.resources``. Mitigation: upgrade to `0.13.6` or later.
|
| MAL-2026-6071 |
|
Vulnerability in n8n-nodes-security-test-poc (MAL-2026-6071)
vulnerability in n8n-nodes-security-test-poc (MAL-2026-6071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25779 |
|
Open Redirect in github.com/go-gitea/gitea (CVE-2026-25779)
vulnerability in github.com/go-gitea/gitea (CVE-2026-25779). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `1.26.0` or later.
|
| CVE-2026-28737 |
|
Cross-Site Scripting (XSS) in code.gitea.io/gitea (CVE-2026-28737)
cross-site scripting in code.gitea.io/gitea (CVE-2026-28737). Confidential information can be exposed externally. Exploitable via ``innerHTML``. Mitigation: upgrade to `1.26.0` or later.
|
| CVE-2026-24791 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-24791)
vulnerability in code.gitea.io/gitea (CVE-2026-24791). Confidential information can be exposed externally. Exploitable via `GET /api/v1/users/{privateUser}`. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-22555 |
|
Authorization Flaw in code.gitea.io/gitea (CVE-2026-22555)
vulnerability in code.gitea.io/gitea (CVE-2026-22555). Confidential information can be exposed externally. Exploitable via `POST /api/v1/repos/{owner}/{repo}/forks`. Mitigation: upgrade to `1.26.0` or later.
|
| CVE-2026-54324 |
|
Vulnerability in github.com/daytonaio/daytona (CVE-2026-54324)
vulnerability in github.com/daytonaio/daytona (CVE-2026-54324). Confidential information can be exposed externally. Mitigation: upgrade to `0.185.0` or later.
|
| CVE-2026-54316 |
|
Vulnerability in @anthropic-ai/claude-code (CVE-2026-54316)
vulnerability in @anthropic-ai/claude-code (CVE-2026-54316). Confidential information can be exposed externally. Mitigation: upgrade to `2.1.163` or later.
|
| ROOT-APP-MAVEN-CVE-2025-37731 |
|
Vulnerability in io.root.org.elasticsearch:elasticsearch (ROOT-APP-MAVEN-CVE-2025-37731)
vulnerability in io.root.org.elasticsearch:elasticsearch (ROOT-APP-MAVEN-CVE-2025-37731). Confidential information can be exposed externally. Mitigation: upgrade to `9.1.3-root.io.1, 9.2.0-root.io.1, 9.1.3-root.io.2, 9.2.0-root.io.2, 9.1.3-root.io.3` or later.
|
| ROOT-APP-MAVEN-CVE-2025-37727 |
|
Vulnerability in io.root.org.elasticsearch:elasticsearch (ROOT-APP-MAVEN-CVE-2025-37727)
vulnerability in io.root.org.elasticsearch:elasticsearch (ROOT-APP-MAVEN-CVE-2025-37727). Confidential information can be exposed externally. Mitigation: upgrade to `9.1.3-root.io.2, 9.1.3-root.io.3` or later.
|
| CVE-2026-54022 |
|
Vulnerability in open-webui (CVE-2026-54022)
vulnerability in open-webui (CVE-2026-54022). Confidential information can be exposed externally. Exploitable via ``document_id``. Mitigation: upgrade to `0.8.11` or later.
|
| RLSA-2026:26455 |
|
Vulnerability in 389-ds-base (RLSA-2026:26455)
vulnerability in 389-ds-base (RLSA-2026:26455). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.8.0-7.el9_8` or later.
|
| CVE-2026-54021 |
|
Authorization Flaw in open-webui (CVE-2026-54021)
vulnerability in open-webui (CVE-2026-54021). Risk of unauthorized operations or information disclosure. Exploitable via `POST /ollama/api/chat/{url_idx}`. Mitigation: upgrade to `>= 0.9.6` or later.
|
| CVE-2026-54019 |
|
Vulnerability in open-webui (CVE-2026-54019)
vulnerability in open-webui (CVE-2026-54019). Confidential information can be exposed externally. Exploitable via `POST /api/v1/retrieval/query/collection`. Mitigation: upgrade to `0.9.6` or later.
|
| ROOT-APP-MAVEN-CVE-2025-68390 |
|
Vulnerability in io.root.org.elasticsearch.plugin:x-pack-core (ROOT-APP-MAVEN-CVE-2025-68390)
vulnerability in io.root.org.elasticsearch.plugin:x-pack-core (ROOT-APP-MAVEN-CVE-2025-68390). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0-root.io.1, 9.2.0-root.io.2, 9.1.3-root.io.1, 9.1.3-root.io.2, 9.2.0-root.io.3` or later.
|
| CVE-2026-54018 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-54018)
SSRF in open-webui (CVE-2026-54018). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-54017 |
|
Path Traversal in open-webui (CVE-2026-54017)
path traversal in open-webui (CVE-2026-54017). Confidential information can be exposed externally. Exploitable via `GET /api/v1/terminals/server1/..`. Mitigation: upgrade to `0.9.6` or later.
|
| ROOT-APP-MAVEN-GHSA-wjpw-4j6x-6rwh |
|
Vulnerability in io.root.org.eclipse.jetty:jetty-http (ROOT-APP-MAVEN-GHSA-wjpw-4j6x-6rwh)
vulnerability in io.root.org.eclipse.jetty:jetty-http (ROOT-APP-MAVEN-GHSA-wjpw-4j6x-6rwh). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.26-root.io.1, 11.0.26-root.io.2, 11.0.26-root.io.3` or later.
|
| ROOT-APP-MAVEN-CVE-2024-27309 |
|
Vulnerability in io.root.org.apache.kafka:kafka-metadata (ROOT-APP-MAVEN-CVE-2024-27309)
vulnerability in io.root.org.apache.kafka:kafka-metadata (ROOT-APP-MAVEN-CVE-2024-27309). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.0-root.io.2, 3.6.0-root.io.3` or later.
|
| CVE-2026-9675 |
|
Vulnerability in undici (CVE-2026-9675)
vulnerability in undici (CVE-2026-9675). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayloadSize``. Mitigation: upgrade to `8.5.0` or later.
|
| UBUNTU-CVE-2026-9675 |
|
Vulnerability in node-undici (UBUNTU-CVE-2026-9675)
vulnerability in node-undici (UBUNTU-CVE-2026-9675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12151 |
|
Vulnerability in undici (CVE-2026-12151)
vulnerability in undici (CVE-2026-12151). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayloadSize``. Mitigation: upgrade to `8.5.0` or later.
|
| UBUNTU-CVE-2026-12151 |
|
Vulnerability in node-undici (UBUNTU-CVE-2026-12151)
vulnerability in node-undici (UBUNTU-CVE-2026-12151). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6065 |
|
Vulnerability in lab-services (MAL-2026-6065)
vulnerability in lab-services (MAL-2026-6065). Risk of unauthorized operations or information disclosure.
|
| CGA-vhhh-3ggv-2x45 |
|
CGA-vhhh-3ggv-2x45 |
| CGA-mxwc-vww2-3q6q |
|
CGA-mxwc-vww2-3q6q |
| GHSA-qcr2-hwcg-gf9g |
|
Vulnerability in swift-parse-stream (GHSA-qcr2-hwcg-gf9g)
vulnerability in swift-parse-stream (GHSA-qcr2-hwcg-gf9g). Risk of unauthorized operations or information disclosure. Exploitable via ``getPlugin``.
|
| GHSA-8p89-7m4q-45qm |
|
Vulnerability in quirky-token (GHSA-8p89-7m4q-45qm)
vulnerability in quirky-token (GHSA-8p89-7m4q-45qm). Risk of unauthorized operations or information disclosure. Exploitable via ``model``.
|
| openSUSE-SU-2026:21079-1 |
|
Vulnerability in amazon-ssm-agent (openSUSE-SU-2026:21079-1)
vulnerability in amazon-ssm-agent (openSUSE-SU-2026:21079-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.4624.0-160000.1.1` or later.
|
| SUSE-SU-2026:22157-1 |
|
Vulnerability in amazon-ssm-agent (SUSE-SU-2026:22157-1)
vulnerability in amazon-ssm-agent (SUSE-SU-2026:22157-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.4624.0-160000.1.1` or later.
|
| MINI-rjgp-hvfc-vvgm |
|
MINI-rjgp-hvfc-vvgm |
| MINI-9g3f-jm52-5vcc |
|
MINI-9g3f-jm52-5vcc |
| MINI-rg63-2xpq-3p2j |
|
MINI-rg63-2xpq-3p2j |
| MINI-5c25-v63v-42m8 |
|
MINI-5c25-v63v-42m8 |
| MINI-fvcq-7xm6-xvx9 |
|
MINI-fvcq-7xm6-xvx9 |
| MINI-jx2c-gf52-2pw6 |
|
MINI-jx2c-gf52-2pw6 |
| MINI-7p69-f6m2-cc4r |
|
MINI-7p69-f6m2-cc4r |
| MINI-357x-mh56-h27j |
|
MINI-357x-mh56-h27j |
| MINI-p4w5-hp5r-gr3m |
|
MINI-p4w5-hp5r-gr3m |
| MINI-hr4w-3jv6-88hh |
|
MINI-hr4w-3jv6-88hh |
| MINI-hf8x-63c9-g428 |
|
MINI-hf8x-63c9-g428 |
| MINI-g24w-7f5h-r52v |
|
MINI-g24w-7f5h-r52v |
| MINI-5w97-pcgf-v4jp |
|
MINI-5w97-pcgf-v4jp |
| MINI-5273-prf6-h7f2 |
|
MINI-5273-prf6-h7f2 |
| MINI-j2xf-p2vr-gwfm |
|
MINI-j2xf-p2vr-gwfm |
| MINI-pr6r-6gjw-3xr9 |
|
MINI-pr6r-6gjw-3xr9 |
| MINI-cmrx-jmrx-m2fg |
|
MINI-cmrx-jmrx-m2fg |