Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| SUSE-SU-2026:2376-1 |
|
Vulnerability in webkit2gtk3-soup2 (SUSE-SU-2026:2376-1)
vulnerability in webkit2gtk3-soup2 (SUSE-SU-2026:2376-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.52.4-150600.12.68.1` or later.
|
| SUSE-SU-2026:2375-1 |
|
Vulnerability in openssh (SUSE-SU-2026:2375-1)
vulnerability in openssh (SUSE-SU-2026:2375-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.4p1-150300.3.65.1` or later.
|
| CVE-2026-42947 |
|
Vulnerability in cisa (CVE-2026-42947)
vulnerability in cisa (CVE-2026-42947). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10557 |
|
Vulnerability in cisa (CVE-2026-10557)
vulnerability in cisa (CVE-2026-10557). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50245 |
|
Vulnerability in cisa (CVE-2026-50245)
vulnerability in cisa (CVE-2026-50245). Confidential information can be exposed externally.
|
| SUSE-SU-2026:2374-1 |
|
Vulnerability in tomcat11 (SUSE-SU-2026:2374-1)
vulnerability in tomcat11 (SUSE-SU-2026:2374-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.22-150600.13.21.1` or later.
|
| openSUSE-SU-2026:20956-1 |
|
Vulnerability in trivy (openSUSE-SU-2026:20956-1)
vulnerability in trivy (openSUSE-SU-2026:20956-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.71.0-160000.1.1` or later.
|
| USN-8424-1 |
|
Vulnerability in ubuntu-kylin-software-center (USN-8424-1)
vulnerability in ubuntu-kylin-software-center (USN-8424-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.5.77.1ubuntu0.1` or later.
|
| CGA-qjfx-qgmq-rx2r |
|
CGA-qjfx-qgmq-rx2r |
| CGA-w5j6-rh9m-w7x2 |
|
CGA-w5j6-rh9m-w7x2 |
| CGA-9235-w657-fhjp |
|
CGA-9235-w657-fhjp |
| CGA-vpj9-9rmc-8m7j |
|
CGA-vpj9-9rmc-8m7j |
| ROOT-APP-MAVEN-CVE-2019-16942 |
|
Vulnerability in io.root.com.fasterxml.jackson.core:jackson-databind (ROOT-APP-MAVEN-CVE-2019-16942)
vulnerability in io.root.com.fasterxml.jackson.core:jackson-databind (ROOT-APP-MAVEN-CVE-2019-16942). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.2-root.io.1, 2.9.2-root.io.2` or later.
|
| CVE-2026-8406 |
|
Vulnerability in CVE-2026-8406 (CVE-2026-8406)
vulnerability in CVE-2026-8406 (CVE-2026-8406). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6338 |
|
Vulnerability in CVE-2026-6338 (CVE-2026-6338)
vulnerability in CVE-2026-6338 (CVE-2026-6338). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53661 |
|
Vulnerability in CVE-2026-53661 (CVE-2026-53661)
vulnerability in CVE-2026-53661 (CVE-2026-53661). Risk of unauthorized operations or information disclosure. Exploitable via ``_boruta_identity_web_user_remember_me``.
|
| CVE-2026-38581 |
|
SQL Injection in sqli (CVE-2026-38581)
SQL injection in sqli (CVE-2026-38581). Successful exploitation can lead to full system takeover.
|
| DEBIAN-CVE-2026-11816 |
|
Vulnerability in keras (DEBIAN-CVE-2026-11816)
vulnerability in keras (DEBIAN-CVE-2026-11816). Confidential information can be exposed externally. Exploitable via ``AttributeError``.
|
| CVE-2026-11816 |
|
Path Traversal in keras (CVE-2026-11816)
path traversal in keras (CVE-2026-11816). Confidential information can be exposed externally. Exploitable via ``AttributeError``. Mitigation: upgrade to `3.14.0` or later.
|
| CVE-2026-10847 |
|
Vulnerability in privilege-escalation (CVE-2026-10847)
vulnerability in privilege-escalation (CVE-2026-10847). Successful exploitation can lead to full system takeover.
|
| GHSA-4mx5-f4mw-64v7 |
|
Vulnerability in vqlxjmpr (GHSA-4mx5-f4mw-64v7)
vulnerability in vqlxjmpr (GHSA-4mx5-f4mw-64v7). Risk of unauthorized operations or information disclosure.
|
| GHSA-c389-4m23-j8gj |
|
Vulnerability in zatzdbai (GHSA-c389-4m23-j8gj)
vulnerability in zatzdbai (GHSA-c389-4m23-j8gj). Risk of unauthorized operations or information disclosure.
|
| GHSA-vq59-5vfc-9rh5 |
|
Vulnerability in downlynpm (GHSA-vq59-5vfc-9rh5)
vulnerability in downlynpm (GHSA-vq59-5vfc-9rh5). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:2372-1 |
|
Vulnerability in google-cloud-sap-agent (SUSE-SU-2026:2372-1)
vulnerability in google-cloud-sap-agent (SUSE-SU-2026:2372-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14-150100.3.71.1` or later.
|
| SUSE-SU-2026:2371-1 |
|
Vulnerability in openssh (SUSE-SU-2026:2371-1)
vulnerability in openssh (SUSE-SU-2026:2371-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.6p1-150600.6.42.1` or later.
|
| GHSA-6cc8-4vwg-c56v |
|
Vulnerability in @tribe-digital/shopify-starter-theme (GHSA-6cc8-4vwg-c56v)
vulnerability in @tribe-digital/shopify-starter-theme (GHSA-6cc8-4vwg-c56v). Risk of unauthorized operations or information disclosure.
|
| GHSA-4pgr-qgvj-c2wh |
|
Vulnerability in @tenforce/toolbox-fontmap (GHSA-4pgr-qgvj-c2wh)
vulnerability in @tenforce/toolbox-fontmap (GHSA-4pgr-qgvj-c2wh). Risk of unauthorized operations or information disclosure.
|
| GHSA-5pm3-rqcf-522w |
|
Vulnerability in @sazka/web (GHSA-5pm3-rqcf-522w)
vulnerability in @sazka/web (GHSA-5pm3-rqcf-522w). Risk of unauthorized operations or information disclosure.
|
| GHSA-c33m-qf7q-vg8q |
|
Vulnerability in @snowsight/debug-tooling (GHSA-c33m-qf7q-vg8q)
vulnerability in @snowsight/debug-tooling (GHSA-c33m-qf7q-vg8q). Risk of unauthorized operations or information disclosure.
|
| GHSA-x2r7-fmjp-vqq2 |
|
Vulnerability in @ngt-frontend/widgets-core (GHSA-x2r7-fmjp-vqq2)
vulnerability in @ngt-frontend/widgets-core (GHSA-x2r7-fmjp-vqq2). Risk of unauthorized operations or information disclosure.
|
| GHSA-5cx4-3w47-xm4h |
|
Vulnerability in @marketplace-shared/components (GHSA-5cx4-3w47-xm4h)
vulnerability in @marketplace-shared/components (GHSA-5cx4-3w47-xm4h). Risk of unauthorized operations or information disclosure.
|
| GHSA-qjh8-96ph-q57w |
|
Vulnerability in @iobeya/spa-auth (GHSA-qjh8-96ph-q57w)
vulnerability in @iobeya/spa-auth (GHSA-qjh8-96ph-q57w). Risk of unauthorized operations or information disclosure.
|
| GHSA-wrxv-8jhh-m4x2 |
|
Vulnerability in @integrations-center/utils (GHSA-wrxv-8jhh-m4x2)
vulnerability in @integrations-center/utils (GHSA-wrxv-8jhh-m4x2). Risk of unauthorized operations or information disclosure.
|
| GHSA-2v2g-hp62-vhwj |
|
Vulnerability in @hatcha-captcha/core (GHSA-2v2g-hp62-vhwj)
vulnerability in @hatcha-captcha/core (GHSA-2v2g-hp62-vhwj). Risk of unauthorized operations or information disclosure.
|
| GHSA-wfq6-44px-2h89 |
|
Vulnerability in @coterie-baby/common (GHSA-wfq6-44px-2h89)
vulnerability in @coterie-baby/common (GHSA-wfq6-44px-2h89). Risk of unauthorized operations or information disclosure.
|
| GHSA-rxf2-69g9-4hpq |
|
Vulnerability in @ntnx/nx-react-components (GHSA-rxf2-69g9-4hpq)
vulnerability in @ntnx/nx-react-components (GHSA-rxf2-69g9-4hpq). Risk of unauthorized operations or information disclosure.
|
| GHSA-r344-wgf5-fqf4 |
|
Vulnerability in @visma-net-platform/module-navigator (GHSA-r344-wgf5-fqf4)
vulnerability in @visma-net-platform/module-navigator (GHSA-r344-wgf5-fqf4). Risk of unauthorized operations or information disclosure.
|
| GHSA-mp9q-fvp5-ww2c |
|
Vulnerability in sitecore-mm-component-style (GHSA-mp9q-fvp5-ww2c)
vulnerability in sitecore-mm-component-style (GHSA-mp9q-fvp5-ww2c). Risk of unauthorized operations or information disclosure.
|
| GHSA-96f9-39p2-gjwm |
|
Vulnerability in pui-diagnostics (GHSA-96f9-39p2-gjwm)
vulnerability in pui-diagnostics (GHSA-96f9-39p2-gjwm). Risk of unauthorized operations or information disclosure.
|
| GHSA-x6pw-87r3-jc97 |
|
Vulnerability in mm-ts-utils-client (GHSA-x6pw-87r3-jc97)
vulnerability in mm-ts-utils-client (GHSA-x6pw-87r3-jc97). Risk of unauthorized operations or information disclosure.
|
| GHSA-hwp4-g2h4-2v7r |
|
Vulnerability in fed-callnative (GHSA-hwp4-g2h4-2v7r)
vulnerability in fed-callnative (GHSA-hwp4-g2h4-2v7r). Risk of unauthorized operations or information disclosure.
|
| GHSA-wg43-49xc-v68q |
|
Vulnerability in experian-analytics-components (GHSA-wg43-49xc-v68q)
vulnerability in experian-analytics-components (GHSA-wg43-49xc-v68q). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48045 |
|
Vulnerability in zeroconf (CVE-2026-48045)
vulnerability in zeroconf (CVE-2026-48045). Risk of unauthorized operations or information disclosure. Exploitable via ``AsyncListener.handle_query_or_defer``. Mitigation: upgrade to `0.149.12` or later.
|
| CVE-2026-48043 |
|
Vulnerability in io.netty:netty-codec-http2 (CVE-2026-48043)
vulnerability in io.netty:netty-codec-http2 (CVE-2026-48043). Risk of unauthorized operations or information disclosure. Exploitable via ``DelegatingDecompressorFrameListener``. Mitigation: upgrade to `4.2.15.Final` or later.
|
| CVE-2026-48039 |
|
Authentication Bypass in meta-ads-mcp (CVE-2026-48039)
authentication bypass in meta-ads-mcp (CVE-2026-48039). Confidential information can be exposed externally. Exploitable via `POST /mcp`. Mitigation: upgrade to `1.0.109` or later.
|
| MAL-2026-5653 |
|
Vulnerability in pc-optimizer (MAL-2026-5653)
vulnerability in pc-optimizer (MAL-2026-5653). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48068 |
|
Vulnerability in @grpc/grpc-js (CVE-2026-48068)
vulnerability in @grpc/grpc-js (CVE-2026-48068). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.14.4` or later.
|
| CVE-2026-48069 |
|
Vulnerability in @grpc/grpc-js (CVE-2026-48069)
vulnerability in @grpc/grpc-js (CVE-2026-48069). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.14.4` or later.
|
| CVE-2026-48038 |
|
Vulnerability in joi (CVE-2026-48038)
vulnerability in joi (CVE-2026-48038). Risk of unauthorized operations or information disclosure. Exploitable via ``RangeError``. Mitigation: upgrade to `17.13.4` or later.
|
| CVE-2026-48054 |
|
Code Injection in @openzeppelin/wizard (CVE-2026-48054)
code injection in @openzeppelin/wizard (CVE-2026-48054). Successful exploitation can lead to full system takeover. Exploitable via ``opts.name``. Mitigation: upgrade to `0.10.9` or later.
|