Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| ROOT-APP-MAVEN-CVE-2026-27314 |
|
Vulnerability in io.root.org.apache.cassandra:cassandra-all (ROOT-APP-MAVEN-CVE-2026-27314)
vulnerability in io.root.org.apache.cassandra:cassandra-all (ROOT-APP-MAVEN-CVE-2026-27314). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.0.6-root.io.1, 5.0.6-root.io.2` or later.
|
| ROOT-APP-MAVEN-CVE-2021-36090 |
|
Vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2021-36090)
vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2021-36090). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.21-root.io.1, 1.21-root.io.2` or later.
|
| ROOT-APP-MAVEN-CVE-2021-35515 |
|
Vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2021-35515)
vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2021-35515). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.21-root.io.1, 1.21-root.io.2` or later.
|
| ROOT-APP-MAVEN-CVE-2021-35517 |
|
Vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2021-35517)
vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2021-35517). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.21-root.io.1, 1.21-root.io.2` or later.
|
| ROOT-APP-MAVEN-CVE-2021-35516 |
|
Vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2021-35516)
vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2021-35516). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.21-root.io.1, 1.21-root.io.2` or later.
|
| CVE-2026-48797 |
|
Vulnerability in backpropagate (CVE-2026-48797)
vulnerability in backpropagate (CVE-2026-48797). Risk of unauthorized operations or information disclosure. Exploitable via ``BACKPROPAGATE_UI_AUTH``. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-48788 |
|
Vulnerability in github.com/umputun/remark42 (CVE-2026-48788)
vulnerability in github.com/umputun/remark42 (CVE-2026-48788). Confidential information can be exposed externally. Exploitable via ``http.DetectContentType``. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-48783 |
|
Vulnerability in CVE-2026-48783 (CVE-2026-48783)
vulnerability in CVE-2026-48783 (CVE-2026-48783). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48782 |
|
SSRF (Server-Side Request Forgery) in pydantic-ai-slim (CVE-2026-48782)
SSRF in pydantic-ai-slim (CVE-2026-48782). Confidential information can be exposed externally. Exploitable via ``FileUrl``. Mitigation: upgrade to `2.0.0b3` or later.
|
| CVE-2026-48781 |
|
Vulnerability in CVE-2026-48781 (CVE-2026-48781)
vulnerability in CVE-2026-48781 (CVE-2026-48781). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48745 |
|
Vulnerability in CVE-2026-48745 (CVE-2026-48745)
vulnerability in CVE-2026-48745 (CVE-2026-48745). Confidential information can be exposed externally.
|
| CVE-2026-48055 |
|
Vulnerability in path-traversal (CVE-2026-48055)
vulnerability in path-traversal (CVE-2026-48055). Data can be tampered with by attackers.
|
| CVE-2026-47277 |
|
Path Traversal in CVE-2026-47277 (CVE-2026-47277)
path traversal in CVE-2026-47277 (CVE-2026-47277). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-48779 |
|
Vulnerability in node-ws (UBUNTU-CVE-2026-48779)
vulnerability in node-ws (UBUNTU-CVE-2026-48779). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-44587 |
|
Vulnerability in ruby-carrierwave (UBUNTU-CVE-2026-44587)
vulnerability in ruby-carrierwave (UBUNTU-CVE-2026-44587). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-12199 |
|
Vulnerability in nltk (UBUNTU-CVE-2026-12199)
vulnerability in nltk (UBUNTU-CVE-2026-12199). Risk of unauthorized operations or information disclosure. Exploitable via ``nltk.app.wordnet_app``.
|
| USN-8446-1 |
|
Vulnerability in gst-plugins-bad1.0 (USN-8446-1)
vulnerability in gst-plugins-bad1.0 (USN-8446-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.2-1ubuntu1.1` or later.
|
| MINI-24x8-c52w-83cr |
|
MINI-24x8-c52w-83cr |
| MINI-hg87-9g6r-f69v |
|
MINI-hg87-9g6r-f69v |
| MINI-m8h9-gxgg-2952 |
|
MINI-m8h9-gxgg-2952 |
| MINI-ppff-wm83-8g24 |
|
MINI-ppff-wm83-8g24 |
| MINI-rq4p-2rwm-gj2p |
|
MINI-rq4p-2rwm-gj2p |
| MINI-pqwp-vf92-hp44 |
|
MINI-pqwp-vf92-hp44 |
| GHSA-4cgm-w872-8q5g |
|
Vulnerability in sodel-pych (GHSA-4cgm-w872-8q5g)
vulnerability in sodel-pych (GHSA-4cgm-w872-8q5g). Risk of unauthorized operations or information disclosure.
|
| USN-8445-1 |
|
Vulnerability in libconfig-inifiles-perl (USN-8445-1)
vulnerability in libconfig-inifiles-perl (USN-8445-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.000003-1ubuntu0.1` or later.
|
| ROOT-APP-NPM-CVE-2021-33587 |
|
Vulnerability in @rootio/css-what (ROOT-APP-NPM-CVE-2021-33587)
vulnerability in @rootio/css-what (ROOT-APP-NPM-CVE-2021-33587). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.0-root.io.1` or later.
|
| MINI-jxgh-6wcp-mvfj |
|
MINI-jxgh-6wcp-mvfj |
| GHSA-wwvg-mj5j-mqx8 |
|
Vulnerability in sort-btree (GHSA-wwvg-mj5j-mqx8)
vulnerability in sort-btree (GHSA-wwvg-mj5j-mqx8). Risk of unauthorized operations or information disclosure.
|
| GHSA-c9fj-mvvf-834r |
|
Vulnerability in @ignacionunez91/keccak24 (GHSA-c9fj-mvvf-834r)
vulnerability in @ignacionunez91/keccak24 (GHSA-c9fj-mvvf-834r). Risk of unauthorized operations or information disclosure.
|
| MINI-q5cw-2p76-gw65 |
|
MINI-q5cw-2p76-gw65 |
| MINI-ch4p-j36q-ppm7 |
|
MINI-ch4p-j36q-ppm7 |
| MINI-fg83-2gm3-mwq4 |
|
MINI-fg83-2gm3-mwq4 |
| MINI-wvgp-g668-3g5g |
|
MINI-wvgp-g668-3g5g |
| MINI-rjhq-wqcr-5rcg |
|
MINI-rjhq-wqcr-5rcg |
| CGA-52wq-gppq-x56q |
|
CGA-52wq-gppq-x56q |
| USN-8444-1 |
|
Vulnerability in graphite2 (USN-8444-1)
vulnerability in graphite2 (USN-8444-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.3.14-1ubuntu0.1` or later.
|
| MINI-g8q9-fgrx-x6c5 |
|
MINI-g8q9-fgrx-x6c5 |
| MINI-w5m3-cw48-8gj9 |
|
MINI-w5m3-cw48-8gj9 |
| MINI-h6mx-c5vp-v32x |
|
MINI-h6mx-c5vp-v32x |
| MINI-m9r4-vjp6-89rg |
|
MINI-m9r4-vjp6-89rg |
| GHSA-qxgr-xx42-5g6p |
|
Vulnerability in express-validates (GHSA-qxgr-xx42-5g6p)
vulnerability in express-validates (GHSA-qxgr-xx42-5g6p). Risk of unauthorized operations or information disclosure.
|
| GHSA-684f-7c48-5hhq |
|
Vulnerability in qrcode-express (GHSA-684f-7c48-5hhq)
vulnerability in qrcode-express (GHSA-684f-7c48-5hhq). Risk of unauthorized operations or information disclosure.
|
| GHSA-xwr3-cg53-gqv5 |
|
Vulnerability in tailwindcss-animates-css (GHSA-xwr3-cg53-gqv5)
vulnerability in tailwindcss-animates-css (GHSA-xwr3-cg53-gqv5). Risk of unauthorized operations or information disclosure.
|
| GHSA-8856-m673-rcwx |
|
Vulnerability in qrcode-generator-node (GHSA-8856-m673-rcwx)
vulnerability in qrcode-generator-node (GHSA-8856-m673-rcwx). Risk of unauthorized operations or information disclosure.
|
| MINI-pp8j-3qr3-g434 |
|
MINI-pp8j-3qr3-g434 |
| ROOT-APP-PYPI-CVE-2023-43810 |
|
Vulnerability in rootio-opentelemetry-instrumentation (ROOT-APP-PYPI-CVE-2023-43810)
vulnerability in rootio-opentelemetry-instrumentation (ROOT-APP-PYPI-CVE-2023-43810). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.36b0+root.io.1` or later.
|
| ROOT-APP-MAVEN-CVE-2022-40151 |
|
Vulnerability in io.root.com.thoughtworks.xstream:xstream (ROOT-APP-MAVEN-CVE-2022-40151)
vulnerability in io.root.com.thoughtworks.xstream:xstream (ROOT-APP-MAVEN-CVE-2022-40151). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.20-root.io.1, 1.4.20-root.io.2` or later.
|
| ROOT-APP-MAVEN-CVE-2022-41966 |
|
Vulnerability in io.root.com.thoughtworks.xstream:xstream (ROOT-APP-MAVEN-CVE-2022-41966)
vulnerability in io.root.com.thoughtworks.xstream:xstream (ROOT-APP-MAVEN-CVE-2022-41966). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.20-root.io.1, 1.4.20-root.io.2` or later.
|
| MINI-739g-2gcg-8v79 |
|
MINI-739g-2gcg-8v79 |
| MINI-f2qq-2673-4f43 |
|
MINI-f2qq-2673-4f43 |