Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MAL-2026-5757 |
|
Vulnerability in npm-sandbox-ping-c8f2a (MAL-2026-5757)
vulnerability in npm-sandbox-ping-c8f2a (MAL-2026-5757). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
|
| GHSA-54f7-37vp-p38f |
|
Vulnerability in npm-sandbox-research-c5d6 (GHSA-54f7-37vp-p38f)
vulnerability in npm-sandbox-research-c5d6 (GHSA-54f7-37vp-p38f). Risk of unauthorized operations or information disclosure. Exploitable via ``beacon11.js``.
|
| GHSA-qxgv-pg7p-c4qr |
|
Vulnerability in npm-sandbox-research-8b2f (GHSA-qxgv-pg7p-c4qr)
vulnerability in npm-sandbox-research-8b2f (GHSA-qxgv-pg7p-c4qr). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
|
| MAL-2026-5758 |
|
Vulnerability in npm-sandbox-research-8b2f (MAL-2026-5758)
vulnerability in npm-sandbox-research-8b2f (MAL-2026-5758). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
|
| MAL-2026-5760 |
|
Vulnerability in npm-sandbox-research-c5d6 (MAL-2026-5760)
vulnerability in npm-sandbox-research-c5d6 (MAL-2026-5760). Risk of unauthorized operations or information disclosure. Exploitable via ``beacon11.js``.
|
| GHSA-r53w-2vfx-w3p4 |
|
Vulnerability in npm-sandbox-research-d7e8 (GHSA-r53w-2vfx-w3p4)
vulnerability in npm-sandbox-research-d7e8 (GHSA-r53w-2vfx-w3p4). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5761 |
|
Vulnerability in npm-sandbox-research-d7e8 (MAL-2026-5761)
vulnerability in npm-sandbox-research-d7e8 (MAL-2026-5761). Risk of unauthorized operations or information disclosure.
|
| GHSA-p2j4-q5x6-2gc4 |
|
Vulnerability in npm-sandbox-research-g3h4 (GHSA-p2j4-q5x6-2gc4)
vulnerability in npm-sandbox-research-g3h4 (GHSA-p2j4-q5x6-2gc4). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5763 |
|
Vulnerability in npm-sandbox-research-g3h4 (MAL-2026-5763)
vulnerability in npm-sandbox-research-g3h4 (MAL-2026-5763). Risk of unauthorized operations or information disclosure.
|
| GHSA-rfp8-4gmx-2fhj |
|
Vulnerability in npm-sandbox-research-9c4e (GHSA-rfp8-4gmx-2fhj)
vulnerability in npm-sandbox-research-9c4e (GHSA-rfp8-4gmx-2fhj). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5759 |
|
Vulnerability in npm-sandbox-research-9c4e (MAL-2026-5759)
vulnerability in npm-sandbox-research-9c4e (MAL-2026-5759). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5764 |
|
Vulnerability in sys-info-cli-app (MAL-2026-5764)
vulnerability in sys-info-cli-app (MAL-2026-5764). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-54421 |
|
Vulnerability in ironic (DEBIAN-CVE-2026-54421)
vulnerability in ironic (DEBIAN-CVE-2026-54421). Confidential information can be exposed externally.
|
| CVE-2026-54421 |
|
Vulnerability in ironic (CVE-2026-54421)
vulnerability in ironic (CVE-2026-54421). Confidential information can be exposed externally. Mitigation: upgrade to `37.0.1` or later.
|
| CVE-2026-54420 KEV |
|
[KEV] Vulnerability in litespeed (CVE-2026-54420)
vulnerability in litespeed (CVE-2026-54420). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| MAL-2026-5756 |
|
Vulnerability in easyaillm (MAL-2026-5756)
vulnerability in easyaillm (MAL-2026-5756). Risk of unauthorized operations or information disclosure. Exploitable via ``pkg_installer.exe``.
|
| MAL-2026-5755 |
|
Vulnerability in anthropickit (MAL-2026-5755)
vulnerability in anthropickit (MAL-2026-5755). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12175 |
|
Vulnerability in sqli (CVE-2026-12175)
vulnerability in sqli (CVE-2026-12175). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12176 |
|
Cross-Site Scripting (XSS) in CVE-2026-12176 (CVE-2026-12176)
cross-site scripting in CVE-2026-12176 (CVE-2026-12176). Risk of unauthorized operations or information disclosure.
|
| openSUSE-SU-2026:11029-1 |
|
Vulnerability in chromium (openSUSE-SU-2026:11029-1)
vulnerability in chromium (openSUSE-SU-2026:11029-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `149.0.7827.114-1.1` or later.
|
| DEBIAN-CVE-2025-55641 |
|
DEBIAN-CVE-2025-55641 |
| DEBIAN-CVE-2025-55650 |
|
DEBIAN-CVE-2025-55650 |
| DEBIAN-CVE-2025-55660 |
|
DEBIAN-CVE-2025-55660 |
| DEBIAN-CVE-2025-55662 |
|
DEBIAN-CVE-2025-55662 |
| DEBIAN-CVE-2025-55663 |
|
DEBIAN-CVE-2025-55663 |
| DEBIAN-CVE-2025-55661 |
|
DEBIAN-CVE-2025-55661 |
| DEBIAN-CVE-2025-55649 |
|
DEBIAN-CVE-2025-55649 |
| DEBIAN-CVE-2025-55648 |
|
DEBIAN-CVE-2025-55648 |
| DEBIAN-CVE-2025-55643 |
|
DEBIAN-CVE-2025-55643 |
| DEBIAN-CVE-2025-55645 |
|
DEBIAN-CVE-2025-55645 |
| DEBIAN-CVE-2025-55642 |
|
DEBIAN-CVE-2025-55642 |
| DEBIAN-CVE-2025-55644 |
|
DEBIAN-CVE-2025-55644 |
| DEBIAN-CVE-2025-55652 |
|
DEBIAN-CVE-2025-55652 |
| DEBIAN-CVE-2025-55647 |
|
DEBIAN-CVE-2025-55647 |
| MAL-2026-5753 |
|
Vulnerability in @gbrlxvi/ts-form-utils (MAL-2026-5753)
vulnerability in @gbrlxvi/ts-form-utils (MAL-2026-5753). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5754 |
|
Vulnerability in salesforce-sysutils-diagnostics (MAL-2026-5754)
vulnerability in salesforce-sysutils-diagnostics (MAL-2026-5754). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12174 |
|
Buffer Overflow in dlink (CVE-2026-12174)
vulnerability in dlink (CVE-2026-12174). Successful exploitation can lead to full system takeover.
|
| MAL-2026-5752 |
|
Vulnerability in patientdocuments (MAL-2026-5752)
vulnerability in patientdocuments (MAL-2026-5752). Risk of unauthorized operations or information disclosure. Exploitable via ``test``.
|
| GHSA-4rw6-v77j-67gx |
|
Vulnerability in mailconfirmer (GHSA-4rw6-v77j-67gx)
vulnerability in mailconfirmer (GHSA-4rw6-v77j-67gx). Risk of unauthorized operations or information disclosure. Exploitable via ``mailconfirmer``.
|
| MAL-2026-5747 |
|
Vulnerability in @giftyhq/widget-components (MAL-2026-5747)
vulnerability in @giftyhq/widget-components (MAL-2026-5747). Risk of unauthorized operations or information disclosure. Exploitable via ``process.platform``.
|
| MAL-2026-5751 |
|
Vulnerability in oh-my-ashclaw (MAL-2026-5751)
vulnerability in oh-my-ashclaw (MAL-2026-5751). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
|
| MAL-2026-5748 |
|
Vulnerability in chai-utils-test (MAL-2026-5748)
vulnerability in chai-utils-test (MAL-2026-5748). Risk of unauthorized operations or information disclosure. Exploitable via ``global.atob``.
|
| MAL-2026-5741 |
|
Vulnerability in @achuthvp/postinstall-poc (MAL-2026-5741)
vulnerability in @achuthvp/postinstall-poc (MAL-2026-5741). Risk of unauthorized operations or information disclosure. Exploitable via ``https.request``.
|
| MAL-2026-5740 |
|
Vulnerability in 2fa-exe (MAL-2026-5740)
vulnerability in 2fa-exe (MAL-2026-5740). Risk of unauthorized operations or information disclosure. Exploitable via ``model``.
|
| GHSA-7h69-vjfv-w92w |
|
Vulnerability in environment-gate (GHSA-7h69-vjfv-w92w)
vulnerability in environment-gate (GHSA-7h69-vjfv-w92w). Risk of unauthorized operations or information disclosure. Exploitable via ``conosle.log``.
|
| MAL-2026-5743 |
|
Vulnerability in environment-gate (MAL-2026-5743)
vulnerability in environment-gate (MAL-2026-5743). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5745 |
|
Vulnerability in oa-crm-webapi (MAL-2026-5745)
vulnerability in oa-crm-webapi (MAL-2026-5745). Risk of unauthorized operations or information disclosure.
|
| GHSA-f4w9-3fvx-q5xw |
|
Vulnerability in axl-ui (GHSA-f4w9-3fvx-q5xw)
vulnerability in axl-ui (GHSA-f4w9-3fvx-q5xw). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5742 |
|
Vulnerability in axl-ui (MAL-2026-5742)
vulnerability in axl-ui (MAL-2026-5742). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5746 |
|
Vulnerability in xy-shared (MAL-2026-5746)
vulnerability in xy-shared (MAL-2026-5746). Risk of unauthorized operations or information disclosure. Exploitable via ``dns.resolve``.
|