Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-48747 Vulnerability in symfony/mailomat-mailer (CVE-2026-48747)
vulnerability in symfony/mailomat-mailer (CVE-2026-48747). Risk of unauthorized operations or information disclosure. Exploitable via ``md4``. Mitigation: upgrade to `8.0.13` or later.
CVE-2026-48736 Vulnerability in symfony/http-client (CVE-2026-48736)
vulnerability in symfony/http-client (CVE-2026-48736). Confidential information can be exposed externally. Exploitable via ``NoPrivateNetworkHttpClient``. Mitigation: upgrade to `5.4.53` or later.
GHSA-38x4-9p94-xg4p Vulnerability in boardflow (GHSA-38x4-9p94-xg4p)
vulnerability in boardflow (GHSA-38x4-9p94-xg4p). Risk of unauthorized operations or information disclosure. Exploitable via ``_0xNNNN``.
MAL-2026-5800 Vulnerability in boardstep (MAL-2026-5800)
vulnerability in boardstep (MAL-2026-5800). Risk of unauthorized operations or information disclosure.
CVE-2026-48712 Vulnerability in protobufjs (CVE-2026-48712)
vulnerability in protobufjs (CVE-2026-48712). Risk of unauthorized operations or information disclosure. Exploitable via ``google.protobuf.Any``. Mitigation: upgrade to `8.4.1` or later.
CVE-2026-48489 Authorization Flaw in symfony/security-http (CVE-2026-48489)
vulnerability in symfony/security-http (CVE-2026-48489). Confidential information can be exposed externally. Exploitable via ``DefaultAuthenticationFailureHandler``. Mitigation: upgrade to `8.0.13` or later.
CVE-2026-54269 Vulnerability in protobufjs (CVE-2026-54269)
vulnerability in protobufjs (CVE-2026-54269). Risk of unauthorized operations or information disclosure. Exploitable via ``hasOwnProperty``. Mitigation: upgrade to `8.6.0` or later.
CVE-2026-54264 Information Disclosure in @angular/service-worker (CVE-2026-54264)
vulnerability in @angular/service-worker (CVE-2026-54264). Risk of unauthorized operations or information disclosure. Exploitable via ``Authorization``.
MINI-qmwm-v282-gqj2 MINI-qmwm-v282-gqj2
CVE-2026-54268 Vulnerability in @angular/common (CVE-2026-54268)
vulnerability in @angular/common (CVE-2026-54268). Risk of unauthorized operations or information disclosure. Exploitable via ``formatDate``.
MAL-2026-5824 Vulnerability in testpgagent (MAL-2026-5824)
vulnerability in testpgagent (MAL-2026-5824). Risk of unauthorized operations or information disclosure. Exploitable via ``mshta.exe``.
MINI-8c86-jv9h-qcvw MINI-8c86-jv9h-qcvw
MINI-j8hc-w2fr-xffv MINI-j8hc-w2fr-xffv
USN-8431-1 Vulnerability in ruby2.3 (USN-8431-1)
vulnerability in ruby2.3 (USN-8431-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.1-2~ubuntu16.04.16+esm14` or later.
MINI-pprc-m89w-pfm4 MINI-pprc-m89w-pfm4
GHSA-pgcr-8w67-72j9 Vulnerability in flow-lending (GHSA-pgcr-8w67-72j9)
vulnerability in flow-lending (GHSA-pgcr-8w67-72j9). Risk of unauthorized operations or information disclosure.
CVE-2026-54266 Vulnerability in @angular/common (CVE-2026-54266)
vulnerability in @angular/common (CVE-2026-54266). Risk of unauthorized operations or information disclosure. Exploitable via ``HttpTransferCache``.
GHSA-r79w-4mcq-g2fm Vulnerability in flow-lending-sdk (GHSA-r79w-4mcq-g2fm)
vulnerability in flow-lending-sdk (GHSA-r79w-4mcq-g2fm). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
GHSA-24j3-x8g2-c23q Vulnerability in flowdefi (GHSA-24j3-x8g2-c23q)
vulnerability in flowdefi (GHSA-24j3-x8g2-c23q). Risk of unauthorized operations or information disclosure. Exploitable via ``flowdefi``.
GHSA-6762-f2rg-qwfv Vulnerability in surf-lending (GHSA-6762-f2rg-qwfv)
vulnerability in surf-lending (GHSA-6762-f2rg-qwfv). Risk of unauthorized operations or information disclosure. Exploitable via ``scripts.preinstall``.
MINI-6wv2-hrc7-v3mg MINI-6wv2-hrc7-v3mg
GHSA-m774-6g93-j76m Vulnerability in bodega-sdk (GHSA-m774-6g93-j76m)
vulnerability in bodega-sdk (GHSA-m774-6g93-j76m). Risk of unauthorized operations or information disclosure.
GHSA-7wqh-42c8-vqcx Vulnerability in flowcardano (GHSA-7wqh-42c8-vqcx)
vulnerability in flowcardano (GHSA-7wqh-42c8-vqcx). Risk of unauthorized operations or information disclosure. Exploitable via ``flowcardano``.
MINI-vp2r-7p9v-g958 MINI-vp2r-7p9v-g958
MINI-j8jh-344w-xxqw MINI-j8jh-344w-xxqw
MINI-36cc-3gg5-578g MINI-36cc-3gg5-578g
MINI-x4cq-2jx5-66c8 MINI-x4cq-2jx5-66c8
CVE-2026-54265 Cross-Site Scripting (XSS) in @angular/compiler (CVE-2026-54265)
cross-site scripting in @angular/compiler (CVE-2026-54265). Risk of unauthorized operations or information disclosure. Exploitable via ``innerHTML``.
MINI-w88g-92m9-f8mw MINI-w88g-92m9-f8mw
MINI-p3f6-vmmw-qhj6 MINI-p3f6-vmmw-qhj6
MINI-34g8-34gv-3hcp MINI-34g8-34gv-3hcp
MINI-4grc-w528-8cv8 MINI-4grc-w528-8cv8
MINI-6h49-v86m-rh2f MINI-6h49-v86m-rh2f
CVE-2026-50557 Cross-Site Scripting (XSS) in @angular/core (CVE-2026-50557)
cross-site scripting in @angular/core (CVE-2026-50557). Risk of unauthorized operations or information disclosure.
MINI-m3mq-hm99-6p3v MINI-m3mq-hm99-6p3v
MINI-cm5f-cr85-mc4x MINI-cm5f-cr85-mc4x
MINI-g8qp-4cg4-vvq6 MINI-g8qp-4cg4-vvq6
CVE-2026-50556 Cross-Site Scripting (XSS) in @angular/platform-server (CVE-2026-50556)
cross-site scripting in @angular/platform-server (CVE-2026-50556). Risk of unauthorized operations or information disclosure. Exploitable via ``domino``.
MINI-fjw7-mppp-wrwc MINI-fjw7-mppp-wrwc
MINI-f62r-r4r4-xpqv MINI-f62r-r4r4-xpqv
MINI-qv59-5g6c-mcjj MINI-qv59-5g6c-mcjj
CVE-2026-50555 Cross-Site Scripting (XSS) in @angular/platform-server (CVE-2026-50555)
cross-site scripting in @angular/platform-server (CVE-2026-50555). Risk of unauthorized operations or information disclosure. Exploitable via ``domino``.
CVE-2026-53655 Vulnerability in tar (CVE-2026-53655)
vulnerability in tar (CVE-2026-53655). Data can be tampered with by attackers. Exploitable via ``tar``. Mitigation: upgrade to `7.5.16` or later.
CVE-2026-53632 Vulnerability in launch-editor (CVE-2026-53632)
vulnerability in launch-editor (CVE-2026-53632). Risk of unauthorized operations or information disclosure. Exploitable via ``smbserver.py``. Mitigation: upgrade to `2.14.1` or later.
CVE-2026-53571 Path Traversal in vite (CVE-2026-53571)
path traversal in vite (CVE-2026-53571). Confidential information can be exposed externally. Exploitable via ``server.fs.deny``. Mitigation: upgrade to `6.4.3` or later.
MAL-2026-5786 Vulnerability in @solana-labs/ancor (MAL-2026-5786)
vulnerability in @solana-labs/ancor (MAL-2026-5786). Risk of unauthorized operations or information disclosure. Exploitable via ``process.platform``.
MAL-2026-5787 Vulnerability in @solana-labs/spl-toke (MAL-2026-5787)
vulnerability in @solana-labs/spl-toke (MAL-2026-5787). Risk of unauthorized operations or information disclosure. Exploitable via ``curl``.
MAL-2026-5788 Vulnerability in @solana-labs/web3js (MAL-2026-5788)
vulnerability in @solana-labs/web3js (MAL-2026-5788). Risk of unauthorized operations or information disclosure. Exploitable via ``child_process``.
CVE-2026-53550 Vulnerability in js-yaml (CVE-2026-53550)
vulnerability in js-yaml (CVE-2026-53550). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.15.0` or later.
CVE-2026-49356 Path Traversal in @babel/core (CVE-2026-49356)
path traversal in @babel/core (CVE-2026-49356). Risk of unauthorized operations or information disclosure. Exploitable via ``inputSourceMap``. Mitigation: upgrade to `7.29.6` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →