Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-48099 Path Traversal in wsgidav (CVE-2026-48099)
path traversal in wsgidav (CVE-2026-48099). Confidential information can be exposed externally. Mitigation: upgrade to `4.3.4` or later.
CVE-2026-48089 Vulnerability in github.com/l3montree-dev/devguard (CVE-2026-48089)
vulnerability in github.com/l3montree-dev/devguard (CVE-2026-48089). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.2` or later.
CVE-2026-48067 Vulnerability in filament/tables (CVE-2026-48067)
vulnerability in filament/tables (CVE-2026-48067). Data can be tampered with by attackers. Exploitable via ``Select``. Mitigation: upgrade to `3.3.51` or later.
MINI-hvgj-qx82-c8gf MINI-hvgj-qx82-c8gf
MINI-p899-9fv2-pwj5 MINI-p899-9fv2-pwj5
MINI-837p-xmvr-ggrj MINI-837p-xmvr-ggrj
MINI-878g-p8rj-cq5m MINI-878g-p8rj-cq5m
MINI-r9p9-mcxv-95gh MINI-r9p9-mcxv-95gh
MINI-924g-x82g-3x98 MINI-924g-x82g-3x98
MINI-55j3-xf27-33pq MINI-55j3-xf27-33pq
CVE-2026-48059 Vulnerability in io.netty:netty-codec-haproxy (CVE-2026-48059)
vulnerability in io.netty:netty-codec-haproxy (CVE-2026-48059). Risk of unauthorized operations or information disclosure. Exploitable via ``PP2_TYPE_SSL``. Mitigation: upgrade to `4.1.135.Final` or later.
MINI-r2pg-hjmx-hp7w MINI-r2pg-hjmx-hp7w
MINI-hx8v-mrf8-cf27 MINI-hx8v-mrf8-cf27
MINI-whrw-fm5q-rwm8 MINI-whrw-fm5q-rwm8
CVE-2026-53782 @steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
@steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
CVE-2026-53781 Vulnerability in @steipete/summarize-core (CVE-2026-53781)
vulnerability in @steipete/summarize-core (CVE-2026-53781). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.17.0` or later.
CVE-2026-49973 Vulnerability in CVE-2026-49973 (CVE-2026-49973)
vulnerability in CVE-2026-49973 (CVE-2026-49973). Confidential information can be exposed externally.
CVE-2026-49949 Vulnerability in CVE-2026-49949 (CVE-2026-49949)
vulnerability in CVE-2026-49949 (CVE-2026-49949). Confidential information can be exposed externally.
CVE-2026-46622 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any...
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconf...
CVE-2026-46489 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG f...
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every...
CVE-2026-45175 Vulnerability in paloaltonetworks (CVE-2026-45175)
vulnerability in paloaltonetworks (CVE-2026-45175). Successful exploitation can lead to full system takeover.
CVE-2026-12038 Vulnerability in CVE-2026-12038 (CVE-2026-12038)
vulnerability in CVE-2026-12038 (CVE-2026-12038). Risk of unauthorized operations or information disclosure.
MINI-668g-gmhr-g3c2 MINI-668g-gmhr-g3c2
MINI-ggr5-r8pj-xpqr MINI-ggr5-r8pj-xpqr
MINI-c3hj-pf49-6qfw MINI-c3hj-pf49-6qfw
MINI-9rfj-xwwh-5gjr MINI-9rfj-xwwh-5gjr
MINI-c4m2-9h8m-cwp9 MINI-c4m2-9h8m-cwp9
DEBIAN-CVE-2026-53702 Vulnerability in gst-plugins-bad1.0 (DEBIAN-CVE-2026-53702)
vulnerability in gst-plugins-bad1.0 (DEBIAN-CVE-2026-53702). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.3-1` or later.
CVE-2026-53702 Out-of-Bounds Write in CVE-2026-53702 (CVE-2026-53702)
out-of-bounds write in CVE-2026-53702 (CVE-2026-53702). Risk of unauthorized operations or information disclosure.
ALPINE-CVE-2026-52858 Vulnerability in vim (ALPINE-CVE-2026-52858)
vulnerability in vim (ALPINE-CVE-2026-52858). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0498-r0` or later.
ALPINE-CVE-2026-52860 Vulnerability in vim (ALPINE-CVE-2026-52860)
vulnerability in vim (ALPINE-CVE-2026-52860). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0602-r0` or later.
ALPINE-CVE-2026-52859 Vulnerability in vim (ALPINE-CVE-2026-52859)
vulnerability in vim (ALPINE-CVE-2026-52859). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0567-r0` or later.
DEBIAN-CVE-2026-52860 Vulnerability in vim (DEBIAN-CVE-2026-52860)
vulnerability in vim (DEBIAN-CVE-2026-52860). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-52858 Vulnerability in vim (DEBIAN-CVE-2026-52858)
vulnerability in vim (DEBIAN-CVE-2026-52858). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-52859 Vulnerability in vim (DEBIAN-CVE-2026-52859)
vulnerability in vim (DEBIAN-CVE-2026-52859). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-53701 Vulnerability in gst-plugins-bad1.0 (DEBIAN-CVE-2026-53701)
vulnerability in gst-plugins-bad1.0 (DEBIAN-CVE-2026-53701). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.3-1` or later.
CVE-2026-53701 Out-of-Bounds Write in c (CVE-2026-53701)
out-of-bounds write in c (CVE-2026-53701). Risk of unauthorized operations or information disclosure.
CVE-2026-52860 Code Injection in vim (CVE-2026-52860)
code injection in vim (CVE-2026-52860). Successful exploitation can lead to full system takeover.
CVE-2026-52859 Out-of-Bounds Read in c (CVE-2026-52859)
vulnerability in c (CVE-2026-52859). Risk of unauthorized operations or information disclosure.
CVE-2026-52858 Code Injection in vim (CVE-2026-52858)
code injection in vim (CVE-2026-52858). Successful exploitation can lead to full system takeover.
CVE-2026-48547 OS Command Injection in CVE-2026-48547 (CVE-2026-48547)
OS command injection in CVE-2026-48547 (CVE-2026-48547). Confidential information can be exposed externally.
CVE-2026-47189 Vulnerability in CVE-2026-47189 (CVE-2026-47189)
vulnerability in CVE-2026-47189 (CVE-2026-47189). Risk of unauthorized operations or information disclosure.
CVE-2026-47188 Vulnerability in CVE-2026-47188 (CVE-2026-47188)
vulnerability in CVE-2026-47188 (CVE-2026-47188). Risk of unauthorized operations or information disclosure.
CVE-2026-47181 Vulnerability in CVE-2026-47181 (CVE-2026-47181)
vulnerability in CVE-2026-47181 (CVE-2026-47181). Risk of unauthorized operations or information disclosure.
CVE-2026-47177 Information Disclosure in CVE-2026-47177 (CVE-2026-47177)
vulnerability in CVE-2026-47177 (CVE-2026-47177). Risk of unauthorized operations or information disclosure.
CVE-2026-47176 Information Disclosure in CVE-2026-47176 (CVE-2026-47176)
vulnerability in CVE-2026-47176 (CVE-2026-47176). Risk of unauthorized operations or information disclosure.
CVE-2026-47175 Vulnerability in CVE-2026-47175 (CVE-2026-47175)
vulnerability in CVE-2026-47175 (CVE-2026-47175). Risk of unauthorized operations or information disclosure.
CVE-2026-47174 Vulnerability in CVE-2026-47174 (CVE-2026-47174)
vulnerability in CVE-2026-47174 (CVE-2026-47174). Risk of unauthorized operations or information disclosure.
CVE-2026-47173 Vulnerability in CVE-2026-47173 (CVE-2026-47173)
vulnerability in CVE-2026-47173 (CVE-2026-47173). Risk of unauthorized operations or information disclosure.
CVE-2026-47172 Vulnerability in CVE-2026-47172 (CVE-2026-47172)
vulnerability in CVE-2026-47172 (CVE-2026-47172). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →