Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-r5jc-6p65-wg55 |
|
MINI-r5jc-6p65-wg55 |
| MINI-f263-r7hh-w766 |
|
MINI-f263-r7hh-w766 |
| MINI-97qf-89fg-r8f3 |
|
MINI-97qf-89fg-r8f3 |
| MINI-m3hm-h5m8-q2x7 |
|
MINI-m3hm-h5m8-q2x7 |
| CGA-gxmj-xx3h-94hw |
|
CGA-gxmj-xx3h-94hw |
| ROOT-APP-NPM-CVE-2025-13033 |
|
Vulnerability in @rootio/nodemailer (ROOT-APP-NPM-CVE-2025-13033)
vulnerability in @rootio/nodemailer (ROOT-APP-NPM-CVE-2025-13033). Confidential information can be exposed externally. Mitigation: upgrade to `6.9.15-root.io.2, 6.9.15-root.io.3, 6.9.15-root.io.4` or later.
|
| CVE-2026-5513 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5513)
cross-site scripting in wordpress (CVE-2026-5513). Risk of unauthorized operations or information disclosure.
|
| GHSA-wfff-g64j-qx73 |
|
Vulnerability in easy-time666 (GHSA-wfff-g64j-qx73)
vulnerability in easy-time666 (GHSA-wfff-g64j-qx73). Risk of unauthorized operations or information disclosure. Exploitable via ``npm.wdf1.eyes.sh``.
|
| MAL-2026-5749 |
|
Vulnerability in easy-time666 (MAL-2026-5749)
vulnerability in easy-time666 (MAL-2026-5749). Risk of unauthorized operations or information disclosure. Exploitable via ``npm.wdf1.eyes.sh``.
|
| ROOT-APP-NPM-CVE-2021-3918 |
|
Vulnerability in @rootio/json-schema (ROOT-APP-NPM-CVE-2021-3918)
vulnerability in @rootio/json-schema (ROOT-APP-NPM-CVE-2021-3918). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2.3-root.io.1, 0.2.3-root.io.2` or later.
|
| ROOT-APP-NPM-CVE-2024-34448 |
|
Vulnerability in @rootio/tryghost__members-csv (ROOT-APP-NPM-CVE-2024-34448)
vulnerability in @rootio/tryghost__members-csv (ROOT-APP-NPM-CVE-2024-34448). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.3-root.io.1, 2.0.3-root.io.2, 2.0.3-root.io.3` or later.
|
| ECHO-049a-1ec4-f2f6 |
|
ECHO-049a-1ec4-f2f6 |
| CVE-2026-1291 |
|
Vulnerability in wordpress (CVE-2026-1291)
vulnerability in wordpress (CVE-2026-1291). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11624 |
|
Vulnerability in github.com/googleapis/mcp-toolbox (CVE-2026-11624)
vulnerability in github.com/googleapis/mcp-toolbox (CVE-2026-11624). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.25.0` or later.
|
| RHSA-2026:25534 |
|
Red Hat Security Advisory: kernel security, bug fix, and enhancement update
Red Hat Security Advisory: kernel security, bug fix, and enhancement update
|
| RHSA-2026:25533 |
|
Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
|
| RHSA-2026:25520 |
|
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
|
| CVE-2026-9629 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9629)
cross-site scripting in wordpress (CVE-2026-9629). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3297 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3297)
cross-site scripting in wordpress (CVE-2026-3297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2470 |
|
Authorization Flaw in wordpress (CVE-2026-2470)
vulnerability in wordpress (CVE-2026-2470). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5739 |
|
Vulnerability in sheratan_haha (MAL-2026-5739)
vulnerability in sheratan_haha (MAL-2026-5739). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
|
| GHSA-3m8w-m4vc-8f58 |
|
Vulnerability in postcss-minify-selector-parser (GHSA-3m8w-m4vc-8f58)
vulnerability in postcss-minify-selector-parser (GHSA-3m8w-m4vc-8f58). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
|
| MAL-2026-5737 |
|
Vulnerability in postcss-minify-selector-parser (MAL-2026-5737)
vulnerability in postcss-minify-selector-parser (MAL-2026-5737). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
|
| CVE-2026-9134 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9134)
cross-site scripting in wordpress (CVE-2026-9134). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9109 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9109)
cross-site scripting in wordpress (CVE-2026-9109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9062 |
|
Path Traversal in wordpress (CVE-2026-9062)
path traversal in wordpress (CVE-2026-9062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9061 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9061)
cross-site scripting in wordpress (CVE-2026-9061). Risk of unauthorized operations or information disclosure. Exploitable via ``unfiltered_html``.
|
| GHSA-j5hw-j4vj-f38v |
|
Vulnerability in postinstall-logger-7x9z (GHSA-j5hw-j4vj-f38v)
vulnerability in postinstall-logger-7x9z (GHSA-j5hw-j4vj-f38v). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5738 |
|
Vulnerability in postinstall-logger-7x9z (MAL-2026-5738)
vulnerability in postinstall-logger-7x9z (MAL-2026-5738). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5730 |
|
Vulnerability in class-synth (MAL-2026-5730)
vulnerability in class-synth (MAL-2026-5730). Risk of unauthorized operations or information disclosure. Exploitable via ``__init``.
|
| MAL-2026-5735 |
|
Vulnerability in node-multi-downloader (MAL-2026-5735)
vulnerability in node-multi-downloader (MAL-2026-5735). Risk of unauthorized operations or information disclosure. Exploitable via ``uqlyosvp1f9.oob.evilsec.xyz``.
|
| MAL-2026-5734 |
|
Vulnerability in node-denv (MAL-2026-5734)
vulnerability in node-denv (MAL-2026-5734). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
|
| MAL-2026-5736 |
|
Vulnerability in node-stack-frames (MAL-2026-5736)
vulnerability in node-stack-frames (MAL-2026-5736). Risk of unauthorized operations or information disclosure. Exploitable via ``http``.
|
| MAL-2026-5733 |
|
Vulnerability in node-app-doctor (MAL-2026-5733)
vulnerability in node-app-doctor (MAL-2026-5733). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5731 |
|
Vulnerability in houzidawang807 (MAL-2026-5731)
vulnerability in houzidawang807 (MAL-2026-5731). Risk of unauthorized operations or information disclosure. Exploitable via ``build``.
|
| MAL-2026-5732 |
|
Vulnerability in houzidawang808 (MAL-2026-5732)
vulnerability in houzidawang808 (MAL-2026-5732). Risk of unauthorized operations or information disclosure.
|
| GHSA-v82c-5c2q-hx9g |
|
Path Traversal in github.com/grafana/grafana-operator (GHSA-v82c-5c2q-hx9g)
path traversal in github.com/grafana/grafana-operator (GHSA-v82c-5c2q-hx9g). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11769 |
|
Information Disclosure in github.com/grafana/grafana-operator (CVE-2026-11769)
vulnerability in github.com/grafana/grafana-operator (CVE-2026-11769). Successful exploitation can lead to full system takeover. Exploitable via ``Dashboard``. Mitigation: upgrade to `5.24.0` or later.
|
| BELL-CVE-2026-49839 |
|
BELL-CVE-2026-49839 |
| BELL-CVE-2026-11526 |
|
BELL-CVE-2026-11526 |
| BELL-CVE-2026-11824 |
|
BELL-CVE-2026-11824 |
| BELL-CVE-2026-11822 |
|
BELL-CVE-2026-11822 |
| BELL-CVE-2026-52859 |
|
BELL-CVE-2026-52859 |
| MAL-2026-5729 |
|
Vulnerability in houzidawang806 (MAL-2026-5729)
vulnerability in houzidawang806 (MAL-2026-5729). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2025-15104 |
|
Vulnerability in vnu (DEBIAN-CVE-2025-15104)
vulnerability in vnu (DEBIAN-CVE-2025-15104). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9848 |
|
SQL Injection in wordpress (CVE-2026-9848)
SQL injection in wordpress (CVE-2026-9848). Confidential information can be exposed externally. Exploitable via ``posts_request``.
|
| CVE-2026-12089 |
|
Path Traversal in wordpress (CVE-2026-12089)
path traversal in wordpress (CVE-2026-12089). Confidential information can be exposed externally.
|
| CVE-2026-54230 |
|
Vulnerability in abrt-project (CVE-2026-54230)
vulnerability in abrt-project (CVE-2026-54230). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54231 |
|
Vulnerability in abrt-project (CVE-2026-54231)
vulnerability in abrt-project (CVE-2026-54231). Data can be tampered with by attackers.
|
| CVE-2026-54229 |
|
Vulnerability in CVE-2026-54229 (CVE-2026-54229)
vulnerability in CVE-2026-54229 (CVE-2026-54229). Successful exploitation can lead to full system takeover.
|