Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-54394 |
|
Path Traversal in path-traversal (CVE-2026-54394)
path traversal in path-traversal (CVE-2026-54394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54396 |
|
Information Disclosure in CVE-2026-54396 (CVE-2026-54396)
vulnerability in CVE-2026-54396 (CVE-2026-54396). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54362 |
|
Authorization Flaw in CVE-2026-54362 (CVE-2026-54362)
vulnerability in CVE-2026-54362 (CVE-2026-54362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54395 |
|
Cross-Site Scripting (XSS) in CVE-2026-54395 (CVE-2026-54395)
cross-site scripting in CVE-2026-54395 (CVE-2026-54395). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24618 |
|
Vulnerability in CVE-2026-24618 (CVE-2026-24618)
vulnerability in CVE-2026-24618 (CVE-2026-24618). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12129 |
|
Cross-Site Scripting (XSS) in CVE-2026-12129 (CVE-2026-12129)
cross-site scripting in CVE-2026-12129 (CVE-2026-12129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12130 |
|
Cross-Site Scripting (XSS) in CVE-2026-12130 (CVE-2026-12130)
cross-site scripting in CVE-2026-12130 (CVE-2026-12130). Risk of unauthorized operations or information disclosure.
|
| GHSA-9j3j-4vjh-6h88 |
|
Vulnerability in ect-472839-ctf (GHSA-9j3j-4vjh-6h88)
vulnerability in ect-472839-ctf (GHSA-9j3j-4vjh-6h88). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5718 |
|
Vulnerability in ect-472839-ctf (MAL-2026-5718)
vulnerability in ect-472839-ctf (MAL-2026-5718). Risk of unauthorized operations or information disclosure.
|
| GHSA-q226-9qx7-fxmj |
|
Vulnerability in ect-654321 (GHSA-q226-9qx7-fxmj)
vulnerability in ect-654321 (GHSA-q226-9qx7-fxmj). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5719 |
|
Vulnerability in ect-654321 (MAL-2026-5719)
vulnerability in ect-654321 (MAL-2026-5719). Risk of unauthorized operations or information disclosure.
|
| GHSA-v786-gqcj-q437 |
|
Vulnerability in ect-839201 (GHSA-v786-gqcj-q437)
vulnerability in ect-839201 (GHSA-v786-gqcj-q437). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5720 |
|
Vulnerability in ect-839201 (MAL-2026-5720)
vulnerability in ect-839201 (MAL-2026-5720). Risk of unauthorized operations or information disclosure.
|
| GHSA-g7vq-rhjq-x8rw |
|
Vulnerability in ect-839201-ctf (GHSA-g7vq-rhjq-x8rw)
vulnerability in ect-839201-ctf (GHSA-g7vq-rhjq-x8rw). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
|
| MAL-2026-5721 |
|
Vulnerability in ect-839201-ctf (MAL-2026-5721)
vulnerability in ect-839201-ctf (MAL-2026-5721). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
|
| DEBIAN-CVE-2026-54057 |
|
Vulnerability in kitty (DEBIAN-CVE-2026-54057)
vulnerability in kitty (DEBIAN-CVE-2026-54057). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-54056 |
|
Vulnerability in kitty (DEBIAN-CVE-2026-54056)
vulnerability in kitty (DEBIAN-CVE-2026-54056). Data can be tampered with by attackers. Exploitable via ``O_NOFOLLOW``.
|
| CVE-2026-54057 |
|
Code Injection in kovidgoyal (CVE-2026-54057)
code injection in kovidgoyal (CVE-2026-54057). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54056 |
|
Vulnerability in kovidgoyal (CVE-2026-54056)
vulnerability in kovidgoyal (CVE-2026-54056). Data can be tampered with by attackers. Exploitable via ``O_NOFOLLOW``.
|
| CVE-2026-53607 |
|
SSRF (Server-Side Request Forgery) in apostrophe (CVE-2026-53607)
SSRF in apostrophe (CVE-2026-53607). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `4.31.0` or later.
|
| CVE-2026-53606 |
|
Cross-Site Scripting (XSS) in sanitize-html (CVE-2026-53606)
cross-site scripting in sanitize-html (CVE-2026-53606). Risk of unauthorized operations or information disclosure. Exploitable via ``allowedSchemesAppliedToAttributes``. Mitigation: upgrade to `2.17.5` or later.
|
| CVE-2026-4870 |
|
Vulnerability in dos (CVE-2026-4870)
vulnerability in dos (CVE-2026-4870). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47264 |
|
Information Disclosure in discourse (CVE-2026-47264)
vulnerability in discourse (CVE-2026-47264). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-47263 |
|
Information Disclosure in discourse (CVE-2026-47263)
vulnerability in discourse (CVE-2026-47263). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-45775 |
|
Path Traversal in discourse (CVE-2026-45775)
path traversal in discourse (CVE-2026-45775). Confidential information can be exposed externally. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-45085 |
|
Information Disclosure in discourse (CVE-2026-45085)
vulnerability in discourse (CVE-2026-45085). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-45014 |
|
Cross-Site Scripting (XSS) in CVE-2026-45014 (CVE-2026-45014)
cross-site scripting in CVE-2026-45014 (CVE-2026-45014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44786 |
|
Information Disclosure in discourse (CVE-2026-44786)
vulnerability in discourse (CVE-2026-44786). Confidential information can be exposed externally. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-44785 |
|
Information Disclosure in discourse (CVE-2026-44785)
vulnerability in discourse (CVE-2026-44785). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-44784 |
|
Information Disclosure in discourse (CVE-2026-44784)
vulnerability in discourse (CVE-2026-44784). Confidential information can be exposed externally. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-44783 |
|
Vulnerability in discourse (CVE-2026-44783)
vulnerability in discourse (CVE-2026-44783). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-44782 |
|
Information Disclosure in discourse (CVE-2026-44782)
vulnerability in discourse (CVE-2026-44782). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-44780 |
|
Information Disclosure in discourse (CVE-2026-44780)
vulnerability in discourse (CVE-2026-44780). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CVE-2026-44779 |
|
Information Disclosure in discourse (CVE-2026-44779)
vulnerability in discourse (CVE-2026-44779). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|
| CGA-mvjp-52pq-9xxr |
|
CGA-mvjp-52pq-9xxr |
| CVE-2026-54096 |
|
Vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-54096)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-54096). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.63.7` or later.
|
| MAL-2026-5722 |
|
Vulnerability in textwrap-toolkit-stager (MAL-2026-5722)
vulnerability in textwrap-toolkit-stager (MAL-2026-5722). Risk of unauthorized operations or information disclosure. Exploitable via ``__init__.py``.
|
| CVE-2026-54697 |
|
Vulnerability in org.connectbot.sshlib:sshlib (CVE-2026-54697)
vulnerability in org.connectbot.sshlib:sshlib (CVE-2026-54697). Risk of unauthorized operations or information disclosure. Exploitable via ``Int``.
|
| CVE-2026-54700 |
|
Vulnerability in org.connectbot.sshlib:sshlib (CVE-2026-54700)
vulnerability in org.connectbot.sshlib:sshlib (CVE-2026-54700). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``.
|
| CVE-2026-54097 |
|
Vulnerability in github.com/filebrowser/filebrowser (CVE-2026-54097)
vulnerability in github.com/filebrowser/filebrowser (CVE-2026-54097). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.63.6` or later.
|
| CVE-2026-46371 |
|
Information Disclosure in github.com/fleetdm/fleet/v4 (CVE-2026-46371)
vulnerability in github.com/fleetdm/fleet/v4 (CVE-2026-46371). Confidential information can be exposed externally. Exploitable via `GET /api/v1/fleet/mdm/apple/commands`. Mitigation: upgrade to `4.84.2` or later.
|
| CVE-2026-46370 |
|
SQL Injection in github.com/fleetdm/fleet/v4 (CVE-2026-46370)
SQL injection in github.com/fleetdm/fleet/v4 (CVE-2026-46370). Confidential information can be exposed externally. Exploitable via `GET /api/v1/fleet/labels/{id}/hosts`. Mitigation: upgrade to `4.84.2` or later.
|
| CVE-2026-44311 |
|
Cross-Site Scripting (XSS) in fabric (CVE-2026-44311)
cross-site scripting in fabric (CVE-2026-44311). Risk of unauthorized operations or information disclosure. Exploitable via ``color``. Mitigation: upgrade to `7.4.0` or later.
|
| MAL-2026-5717 |
|
Vulnerability in claudechor (MAL-2026-5717)
vulnerability in claudechor (MAL-2026-5717). Risk of unauthorized operations or information disclosure. Exploitable via ``WORKER_URL``.
|
| MAL-2026-5716 |
|
Vulnerability in beamz (MAL-2026-5716)
vulnerability in beamz (MAL-2026-5716). Risk of unauthorized operations or information disclosure. Exploitable via ``cmdPush``.
|
| openSUSE-SU-2026:20961-1 |
|
Vulnerability in GraphicsMagick (openSUSE-SU-2026:20961-1)
vulnerability in GraphicsMagick (openSUSE-SU-2026:20961-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.3.45-160000.7.1` or later.
|
| CGA-3h5q-4hq8-7qg7 |
|
CGA-3h5q-4hq8-7qg7 |
| CGA-782w-pqj4-7xvq |
|
CGA-782w-pqj4-7xvq |
| MAL-2026-5709 |
|
Vulnerability in chalk-plus-js (MAL-2026-5709)
vulnerability in chalk-plus-js (MAL-2026-5709). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5711 |
|
Vulnerability in chalk-pro (MAL-2026-5711)
vulnerability in chalk-pro (MAL-2026-5711). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
|