Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2023-40200 |
|
Vulnerability in CVE-2023-40200 (CVE-2023-40200)
vulnerability in CVE-2023-40200 (CVE-2023-40200). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-33999 |
|
Cross-Site Scripting (XSS) in CVE-2023-33999 (CVE-2023-33999)
cross-site scripting in CVE-2023-33999 (CVE-2023-33999). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53901 |
|
Vulnerability in CVE-2026-53901 (CVE-2026-53901)
vulnerability in CVE-2026-53901 (CVE-2026-53901). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.37` or later.
|
| CVE-2024-32110 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2024-32110)
vulnerability in csrf (CVE-2024-32110). Risk of unauthorized operations or information disclosure.
|
| ROOT-APP-NPM-CVE-2026-47135 |
|
Vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47135)
vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47135). Confidential information can be exposed externally. Mitigation: upgrade to `3.11.3-root.io.1, 3.11.3-root.io.2` or later.
|
| ROOT-APP-NPM-CVE-2026-47140 |
|
Vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47140)
vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47140). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.3-root.io.1, 3.11.3-root.io.2` or later.
|
| ROOT-APP-NPM-CVE-2026-47209 |
|
Vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47209)
vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47209). Data can be tampered with by attackers. Mitigation: upgrade to `3.11.3-root.io.1, 3.11.3-root.io.2` or later.
|
| ROOT-APP-NPM-CVE-2026-47137 |
|
Vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47137)
vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47137). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.3-root.io.1, 3.11.3-root.io.2` or later.
|
| ROOT-APP-NPM-CVE-2026-47208 |
|
Vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47208)
vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47208). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.3-root.io.1, 3.11.3-root.io.2` or later.
|
| ROOT-APP-NPM-CVE-2026-47139 |
|
Vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47139)
vulnerability in @rootio/vm2 (ROOT-APP-NPM-CVE-2026-47139). Confidential information can be exposed externally. Mitigation: upgrade to `3.11.3-root.io.1, 3.11.3-root.io.2` or later.
|
| MAL-2026-5622 |
|
Vulnerability in @whatnot-web/www-legacy (MAL-2026-5622)
vulnerability in @whatnot-web/www-legacy (MAL-2026-5622). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:2367-1 |
|
Vulnerability in gnutls (SUSE-SU-2026:2367-1)
vulnerability in gnutls (SUSE-SU-2026:2367-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.27-3.18.1` or later.
|
| SUSE-SU-2026:2366-1 |
|
Vulnerability in gnutls (SUSE-SU-2026:2366-1)
vulnerability in gnutls (SUSE-SU-2026:2366-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.17-8.23.1` or later.
|
| MAL-2026-5623 |
|
Vulnerability in edu-npm-dependency-chain-demo (MAL-2026-5623)
vulnerability in edu-npm-dependency-chain-demo (MAL-2026-5623). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5624 |
|
Vulnerability in edu-npm-postinstall-demo2 (MAL-2026-5624)
vulnerability in edu-npm-postinstall-demo2 (MAL-2026-5624). Risk of unauthorized operations or information disclosure. Exploitable via ``build``.
|
| CGA-mhx9-cq4h-j57h |
|
CGA-mhx9-cq4h-j57h |
| CGA-vgvw-4grv-5fjc |
|
CGA-vgvw-4grv-5fjc |
| CGA-2r3f-8xvr-3672 |
|
CGA-2r3f-8xvr-3672 |
| CGA-v8wj-6895-grc3 |
|
CGA-v8wj-6895-grc3 |
| CGA-4pf8-cgch-9rvx |
|
CGA-4pf8-cgch-9rvx |
| CGA-9q73-qf7g-7g7m |
|
CGA-9q73-qf7g-7g7m |
| CGA-7cxf-5qq9-3jqj |
|
CGA-7cxf-5qq9-3jqj |
| CGA-4x9c-9p39-m4x3 |
|
CGA-4x9c-9p39-m4x3 |
| CGA-r22v-prf2-rh9w |
|
CGA-r22v-prf2-rh9w |
| CGA-2hx8-pjgm-f5vg |
|
CGA-2hx8-pjgm-f5vg |
| CGA-9rr4-3j45-jg93 |
|
CGA-9rr4-3j45-jg93 |
| CGA-3qcp-c7r3-629f |
|
CGA-3qcp-c7r3-629f |
| CGA-jx52-q5p3-jc33 |
|
CGA-jx52-q5p3-jc33 |
| CGA-vfrc-p9m8-wf7h |
|
CGA-vfrc-p9m8-wf7h |
| CGA-7f93-qm24-9fc8 |
|
CGA-7f93-qm24-9fc8 |
| CGA-v85c-gx55-whmm |
|
CGA-v85c-gx55-whmm |
| CGA-39mr-jp3c-8ccj |
|
CGA-39mr-jp3c-8ccj |
| SUSE-SU-2026:2365-1 |
|
Vulnerability in cosign (SUSE-SU-2026:2365-1)
vulnerability in cosign (SUSE-SU-2026:2365-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.6-150400.3.42.1` or later.
|
| DEBIAN-CVE-2026-6893 |
|
Vulnerability in dracut (DEBIAN-CVE-2026-6893)
vulnerability in dracut (DEBIAN-CVE-2026-6893). Risk of unauthorized operations or information disclosure.
|
| ROOT-APP-NUGET-CVE-2025-26646 |
|
Vulnerability in Rootio.Microsoft.Build.Tasks.Core (ROOT-APP-NUGET-CVE-2025-26646)
vulnerability in Rootio.Microsoft.Build.Tasks.Core (ROOT-APP-NUGET-CVE-2025-26646). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.11.31.120071` or later.
|
| MAL-2026-5607 |
|
Vulnerability in chai-net-test (MAL-2026-5607)
vulnerability in chai-net-test (MAL-2026-5607). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
|
| GHSA-mx93-wj6x-87wp |
|
Vulnerability in tailwind-animator-scroll (GHSA-mx93-wj6x-87wp)
vulnerability in tailwind-animator-scroll (GHSA-mx93-wj6x-87wp). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5618 |
|
Vulnerability in tailwind-animator-scroll (MAL-2026-5618)
vulnerability in tailwind-animator-scroll (MAL-2026-5618). Risk of unauthorized operations or information disclosure.
|
| GHSA-j9jx-c8pr-c3gr |
|
Vulnerability in tailwind-typography-plus (GHSA-j9jx-c8pr-c3gr)
vulnerability in tailwind-typography-plus (GHSA-j9jx-c8pr-c3gr). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5619 |
|
Vulnerability in tailwind-typography-plus (MAL-2026-5619)
vulnerability in tailwind-typography-plus (MAL-2026-5619). Risk of unauthorized operations or information disclosure.
|
| openSUSE-SU-2026:20943-1 |
|
Vulnerability in java-17-openj9 (openSUSE-SU-2026:20943-1)
vulnerability in java-17-openj9 (openSUSE-SU-2026:20943-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `17.0.19.0-bp160.1.1` or later.
|
| MAL-2026-5608 |
|
Vulnerability in claimora (MAL-2026-5608)
vulnerability in claimora (MAL-2026-5608). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
|
| GHSA-w6mr-3c22-93v5 |
|
Vulnerability in janus-erc20 (GHSA-w6mr-3c22-93v5)
vulnerability in janus-erc20 (GHSA-w6mr-3c22-93v5). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
|
| MAL-2026-5614 |
|
Vulnerability in janus-erc20 (MAL-2026-5614)
vulnerability in janus-erc20 (MAL-2026-5614). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
|
| GHSA-wg39-m2jm-wxhp |
|
Vulnerability in cache-section-helper (GHSA-wg39-m2jm-wxhp)
vulnerability in cache-section-helper (GHSA-wg39-m2jm-wxhp). Risk of unauthorized operations or information disclosure. Exploitable via ``manifest.session``.
|
| MAL-2026-5604 |
|
Vulnerability in cache-section-helper (MAL-2026-5604)
vulnerability in cache-section-helper (MAL-2026-5604). Risk of unauthorized operations or information disclosure. Exploitable via ``manifest.session``.
|
| MAL-2026-5611 |
|
Vulnerability in datetime-toolkit (MAL-2026-5611)
vulnerability in datetime-toolkit (MAL-2026-5611). Risk of unauthorized operations or information disclosure. Exploitable via ``datetime.js``.
|
| GHSA-qcg5-4gpc-33h2 |
|
Vulnerability in internallib_v346 (GHSA-qcg5-4gpc-33h2)
vulnerability in internallib_v346 (GHSA-qcg5-4gpc-33h2). Risk of unauthorized operations or information disclosure. Exploitable via ``command``.
|
| MAL-2026-5613 |
|
Vulnerability in internallib_v346 (MAL-2026-5613)
vulnerability in internallib_v346 (MAL-2026-5613). Risk of unauthorized operations or information disclosure. Exploitable via ``command``.
|
| MAL-2026-5605 |
|
Vulnerability in chai-as-victimed (MAL-2026-5605)
vulnerability in chai-as-victimed (MAL-2026-5605). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
|