Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48022 |
|
Vulnerability in @hapi/wreck (CVE-2026-48022)
vulnerability in @hapi/wreck (CVE-2026-48022). Confidential information can be exposed externally. Exploitable via ``beforeRedirect``. Mitigation: upgrade to `18.1.2` or later.
|
| CVE-2026-48020 |
|
Path Traversal in github.com/traefik/traefik/v2 (CVE-2026-48020)
path traversal in github.com/traefik/traefik/v2 (CVE-2026-48020). Confidential information can be exposed externally. Mitigation: upgrade to `2.11.48` or later.
|
| CVE-2026-48007 |
|
Information Disclosure in @element-hq/element-call-embedded (CVE-2026-48007)
vulnerability in @element-hq/element-call-embedded (CVE-2026-48007). Risk of unauthorized operations or information disclosure. Exploitable via ``posthog``. Mitigation: upgrade to `0.19.4` or later.
|
| CVE-2026-48006 |
|
Vulnerability in io.netty:netty-codec-redis (CVE-2026-48006)
vulnerability in io.netty:netty-codec-redis (CVE-2026-48006). Risk of unauthorized operations or information disclosure. Exploitable via ``depths``. Mitigation: upgrade to `4.1.135.Final` or later.
|
| CVE-2026-47781 |
|
Code Injection in pdm (CVE-2026-47781)
code injection in pdm (CVE-2026-47781). Risk of unauthorized operations or information disclosure. Exploitable via ``Core``. Mitigation: upgrade to `2.27.0` or later.
|
| CVE-2026-47780 |
|
Vulnerability in github.com/free5gc/udr (CVE-2026-47780)
vulnerability in github.com/free5gc/udr (CVE-2026-47780). Risk of unauthorized operations or information disclosure. Exploitable via `POST /nudr-dr/v2/subscription-data/{ueId}/context-data/ee-subscriptions`.
|
| MINI-8ggv-7qcv-xg7v |
|
MINI-8ggv-7qcv-xg7v |
| MAL-2026-5648 |
|
Vulnerability in unified-ui-components-library (MAL-2026-5648)
vulnerability in unified-ui-components-library (MAL-2026-5648). Risk of unauthorized operations or information disclosure. Exploitable via ``downloadImage``.
|
| SUSE-SU-2026:2370-1 |
|
Vulnerability in nginx (SUSE-SU-2026:2370-1)
vulnerability in nginx (SUSE-SU-2026:2370-1). Risk of unauthorized operations or information disclosure. Exploitable via ``ngx_http_rewrite_module``. Mitigation: upgrade to `1.21.5-150400.3.20.1` or later.
|
| MINI-8v3f-wm99-2g84 |
|
MINI-8v3f-wm99-2g84 |
| MINI-2g4f-75v8-5mrm |
|
MINI-2g4f-75v8-5mrm |
| MINI-9pp6-h96c-7h9r |
|
MINI-9pp6-h96c-7h9r |
| MINI-p34f-22cf-hrvj |
|
MINI-p34f-22cf-hrvj |
| MINI-rx49-v9x9-c985 |
|
MINI-rx49-v9x9-c985 |
| MINI-w64p-3698-cqh9 |
|
MINI-w64p-3698-cqh9 |
| GHSA-cwjv-7gg4-fp86 |
|
Vulnerability in ts-ecro (GHSA-cwjv-7gg4-fp86)
vulnerability in ts-ecro (GHSA-cwjv-7gg4-fp86). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5647 |
|
Vulnerability in ts-ecro (MAL-2026-5647)
vulnerability in ts-ecro (MAL-2026-5647). Risk of unauthorized operations or information disclosure.
|
| MINI-7jcv-p5c3-v39x |
|
MINI-7jcv-p5c3-v39x |
| MINI-2q44-gv48-9g2g |
|
MINI-2q44-gv48-9g2g |
| MINI-9xf6-c737-w7mf |
|
MINI-9xf6-c737-w7mf |
| MINI-7374-5m8g-m49x |
|
MINI-7374-5m8g-m49x |
| CVE-2026-7852 |
|
Unrestricted File Upload in CVE-2026-7852 (CVE-2026-7852)
vulnerability in CVE-2026-7852 (CVE-2026-7852). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11956 |
|
Vulnerability in CVE-2026-11956 (CVE-2026-11956)
vulnerability in CVE-2026-11956 (CVE-2026-11956). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11561 |
|
Vulnerability in CVE-2026-11561 (CVE-2026-11561)
vulnerability in CVE-2026-11561 (CVE-2026-11561). Successful exploitation can lead to full system takeover.
|
| MINI-m6q4-54h5-6qp8 |
|
MINI-m6q4-54h5-6qp8 |
| MINI-55gq-5mxc-g77j |
|
MINI-55gq-5mxc-g77j |
| MINI-9m8x-58g7-9f7g |
|
MINI-9m8x-58g7-9f7g |
| MINI-9xpv-pwr3-gc84 |
|
MINI-9xpv-pwr3-gc84 |
| MINI-j8hv-jqm8-787p |
|
MINI-j8hv-jqm8-787p |
| MINI-283c-768r-cq7h |
|
MINI-283c-768r-cq7h |
| GHSA-pwmh-97g7-2r34 |
|
Vulnerability in optional-cpu-features (GHSA-pwmh-97g7-2r34)
vulnerability in optional-cpu-features (GHSA-pwmh-97g7-2r34). Risk of unauthorized operations or information disclosure. Exploitable via ``install``.
|
| MAL-2026-5642 |
|
Vulnerability in optional-cpu-features (MAL-2026-5642)
vulnerability in optional-cpu-features (MAL-2026-5642). Risk of unauthorized operations or information disclosure. Exploitable via ``install``.
|
| MINI-9m6f-ph53-7hwx |
|
MINI-9m6f-ph53-7hwx |
| MINI-6m8x-7w2x-364g |
|
MINI-6m8x-7w2x-364g |
| MINI-8vvc-vcm3-38h8 |
|
MINI-8vvc-vcm3-38h8 |
| MINI-p86g-mxg9-8285 |
|
MINI-p86g-mxg9-8285 |
| MINI-4cp5-5994-p3h8 |
|
MINI-4cp5-5994-p3h8 |
| MINI-mc42-68ph-r2g5 |
|
MINI-mc42-68ph-r2g5 |
| MINI-4x5c-cp46-c2hj |
|
MINI-4x5c-cp46-c2hj |
| CVE-2026-53723 |
|
Vulnerability in guzzlehttp/guzzle-services (CVE-2026-53723)
vulnerability in guzzlehttp/guzzle-services (CVE-2026-53723). Risk of unauthorized operations or information disclosure. Exploitable via ``additionalParameters``. Mitigation: upgrade to `1.5.4` or later.
|
| CVE-2026-48998 |
|
Vulnerability in guzzlehttp/psr7 (CVE-2026-48998)
vulnerability in guzzlehttp/psr7 (CVE-2026-48998). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `2.10.2` or later.
|
| CVE-2026-49214 |
|
Vulnerability in guzzlehttp/psr7 (CVE-2026-49214)
vulnerability in guzzlehttp/psr7 (CVE-2026-49214). Risk of unauthorized operations or information disclosure. Exploitable via ``Uri``. Mitigation: upgrade to `2.10.2` or later.
|
| MAL-2026-5644 |
|
Vulnerability in self-certificate (MAL-2026-5644)
vulnerability in self-certificate (MAL-2026-5644). Risk of unauthorized operations or information disclosure.
|
| ROOT-APP-MAVEN-CVE-2024-25710 |
|
Vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2024-25710)
vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2024-25710). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.21-root.io.1, 1.24.0-root.io.1` or later.
|
| ROOT-APP-MAVEN-CVE-2024-26308 |
|
Vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2024-26308)
vulnerability in io.root.org.apache.commons:commons-compress (ROOT-APP-MAVEN-CVE-2024-26308). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.21-root.io.1, 1.24.0-root.io.1` or later.
|
| MINI-3x76-mwrr-mf4p |
|
MINI-3x76-mwrr-mf4p |
| MINI-cm5p-hw3f-53wf |
|
MINI-cm5p-hw3f-53wf |
| MINI-r56h-8pvr-xv68 |
|
MINI-r56h-8pvr-xv68 |
| MINI-2gqh-76v5-vr24 |
|
MINI-2gqh-76v5-vr24 |
| MINI-6fj2-4p23-5v83 |
|
MINI-6fj2-4p23-5v83 |