Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
RLSA-2026:24340 Vulnerability in frr (RLSA-2026:24340)
vulnerability in frr (RLSA-2026:24340). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:7.5.1-24.el8_10` or later.
RLSA-2026:24545 Vulnerability in libyang (RLSA-2026:24545)
vulnerability in libyang (RLSA-2026:24545). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:1.0.184-2.el8_10` or later.
RLSA-2026:24365 Vulnerability in unbound (RLSA-2026:24365)
vulnerability in unbound (RLSA-2026:24365). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:1.16.2-5.11.el8_10` or later.
RLSA-2026:25030 Vulnerability in postgresql-jdbc (RLSA-2026:25030)
vulnerability in postgresql-jdbc (RLSA-2026:25030). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:42.2.14-4.el8_10` or later.
RLSA-2026:24339 Vulnerability in bind (RLSA-2026:24339)
vulnerability in bind (RLSA-2026:24339). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:9.11.36-16.el8_10.8` or later.
RLSA-2026:23258 Vulnerability in kernel (RLSA-2026:23258)
vulnerability in kernel (RLSA-2026:23258). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:4.18.0-553.129.1.el8_10` or later.
MAL-2026-5576 Vulnerability in vite-tsconfig (MAL-2026-5576)
vulnerability in vite-tsconfig (MAL-2026-5576). Risk of unauthorized operations or information disclosure. Exploitable via ``configJson``.
GHSA-w43g-ccrm-v8xv Vulnerability in ai-sdk-helpers (GHSA-w43g-ccrm-v8xv)
vulnerability in ai-sdk-helpers (GHSA-w43g-ccrm-v8xv). Risk of unauthorized operations or information disclosure.
MAL-2026-5565 Vulnerability in ai-sdk-helpers (MAL-2026-5565)
vulnerability in ai-sdk-helpers (MAL-2026-5565). Risk of unauthorized operations or information disclosure.
CVE-2026-40985 Vulnerability in org.springframework.webflow:spring-webflow (CVE-2026-40985)
vulnerability in org.springframework.webflow:spring-webflow (CVE-2026-40985). Confidential information can be exposed externally.
MAL-2026-5566 Vulnerability in fastify-addon (MAL-2026-5566)
vulnerability in fastify-addon (MAL-2026-5566). Risk of unauthorized operations or information disclosure.
GHSA-x58x-qmg9-8q8v Vulnerability in web-pool (GHSA-x58x-qmg9-8q8v)
vulnerability in web-pool (GHSA-x58x-qmg9-8q8v). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
MAL-2026-5577 Vulnerability in web-pool (MAL-2026-5577)
vulnerability in web-pool (MAL-2026-5577). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
MAL-2026-5572 Vulnerability in sendgrid-sdk (MAL-2026-5572)
vulnerability in sendgrid-sdk (MAL-2026-5572). Risk of unauthorized operations or information disclosure.
MAL-2026-5579 Vulnerability in webpack-cache-cycle (MAL-2026-5579)
vulnerability in webpack-cache-cycle (MAL-2026-5579). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
MAL-2026-5581 Vulnerability in webpack-patch (MAL-2026-5581)
vulnerability in webpack-patch (MAL-2026-5581). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
GHSA-82q4-cw9w-vjj4 Vulnerability in webpack-cache-clean (GHSA-82q4-cw9w-vjj4)
vulnerability in webpack-cache-clean (GHSA-82q4-cw9w-vjj4). Risk of unauthorized operations or information disclosure. Exploitable via ``manifest.session``.
MAL-2026-5580 Vulnerability in webpack-cache-reset (MAL-2026-5580)
vulnerability in webpack-cache-reset (MAL-2026-5580). Risk of unauthorized operations or information disclosure. Exploitable via ``manifest.session``.
MAL-2026-5578 Vulnerability in webpack-cache-clean (MAL-2026-5578)
vulnerability in webpack-cache-clean (MAL-2026-5578). Risk of unauthorized operations or information disclosure. Exploitable via ``manifest.session``.
MAL-2026-5582 Vulnerability in wp-env (MAL-2026-5582)
vulnerability in wp-env (MAL-2026-5582). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env.INIT_CWD``.
MAL-2026-5561 Vulnerability in @bestlzk/sectest (MAL-2026-5561)
vulnerability in @bestlzk/sectest (MAL-2026-5561). Risk of unauthorized operations or information disclosure. Exploitable via ``config.setup``.
MAL-2026-5564 Vulnerability in @tonsdk/core (MAL-2026-5564)
vulnerability in @tonsdk/core (MAL-2026-5564). Risk of unauthorized operations or information disclosure.
GHSA-hj2h-j6cr-5mq8 Vulnerability in js-crypto-promise (GHSA-hj2h-j6cr-5mq8)
vulnerability in js-crypto-promise (GHSA-hj2h-j6cr-5mq8). Risk of unauthorized operations or information disclosure. Exploitable via ``prepinstall.js``.
MAL-2026-5569 Vulnerability in js-crypto-promise (MAL-2026-5569)
vulnerability in js-crypto-promise (MAL-2026-5569). Risk of unauthorized operations or information disclosure. Exploitable via ``prepinstall.js``.
MAL-2026-5563 Vulnerability in @sentry-internal-sdk/profiling-node (MAL-2026-5563)
vulnerability in @sentry-internal-sdk/profiling-node (MAL-2026-5563). Risk of unauthorized operations or information disclosure. Exploitable via ``cli.js``.
GHSA-hqj4-8wc5-r66r Vulnerability in forge-jsx2 (GHSA-hqj4-8wc5-r66r)
vulnerability in forge-jsx2 (GHSA-hqj4-8wc5-r66r). Risk of unauthorized operations or information disclosure. Exploitable via ``fsProtocol.js``.
MAL-2026-5568 Vulnerability in forge-jsx2 (MAL-2026-5568)
vulnerability in forge-jsx2 (MAL-2026-5568). Risk of unauthorized operations or information disclosure. Exploitable via ``fsProtocol.js``.
MAL-2026-5570 Vulnerability in nim-submit-for-test (MAL-2026-5570)
vulnerability in nim-submit-for-test (MAL-2026-5570). Risk of unauthorized operations or information disclosure.
MAL-2026-5562 Vulnerability in @koadz/sso (MAL-2026-5562)
vulnerability in @koadz/sso (MAL-2026-5562). Risk of unauthorized operations or information disclosure.
MAL-2026-5567 Vulnerability in field-upload-tool (MAL-2026-5567)
vulnerability in field-upload-tool (MAL-2026-5567). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
MAL-2026-5573 Vulnerability in solana-rpc-pool (MAL-2026-5573)
vulnerability in solana-rpc-pool (MAL-2026-5573). Risk of unauthorized operations or information disclosure.
MAL-2026-5574 Vulnerability in spotify-url-resolver (MAL-2026-5574)
vulnerability in spotify-url-resolver (MAL-2026-5574). Risk of unauthorized operations or information disclosure.
MAL-2026-5575 Vulnerability in testzapier (MAL-2026-5575)
vulnerability in testzapier (MAL-2026-5575). Risk of unauthorized operations or information disclosure. Exploitable via `User-Agent header`.
MAL-2026-5571 Vulnerability in qa-handoff (MAL-2026-5571)
vulnerability in qa-handoff (MAL-2026-5571). Risk of unauthorized operations or information disclosure.
GHSA-63rx-hcxw-wmpq Vulnerability in tailwind-dark-mode-kit (GHSA-63rx-hcxw-wmpq)
vulnerability in tailwind-dark-mode-kit (GHSA-63rx-hcxw-wmpq). Risk of unauthorized operations or information disclosure.
GHSA-95f6-59wp-jpv8 Vulnerability in polymarket-clob-api (GHSA-95f6-59wp-jpv8)
vulnerability in polymarket-clob-api (GHSA-95f6-59wp-jpv8). Risk of unauthorized operations or information disclosure.
CVE-2026-35273 KEV [KEV] Vulnerability in Oracle c (CVE-2026-35273)
vulnerability in Oracle c (CVE-2026-35273). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
GHSA-j6hp-9w2p-jwpw Vulnerability in emittery_styled (GHSA-j6hp-9w2p-jwpw)
vulnerability in emittery_styled (GHSA-j6hp-9w2p-jwpw). Risk of unauthorized operations or information disclosure.
GHSA-4qrx-h7cq-cqh6 Vulnerability in justgetit (GHSA-4qrx-h7cq-cqh6)
vulnerability in justgetit (GHSA-4qrx-h7cq-cqh6). Risk of unauthorized operations or information disclosure.
CVE-2026-2827 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2827)
cross-site scripting in wordpress (CVE-2026-2827). Risk of unauthorized operations or information disclosure.
MAL-2026-5547 Vulnerability in @403name/electron-buidler (MAL-2026-5547)
vulnerability in @403name/electron-buidler (MAL-2026-5547). Risk of unauthorized operations or information disclosure.
MAL-2026-5549 Vulnerability in @403name/fsevent (MAL-2026-5549)
vulnerability in @403name/fsevent (MAL-2026-5549). Risk of unauthorized operations or information disclosure.
MAL-2026-5548 Vulnerability in @403name/ether-js (MAL-2026-5548)
vulnerability in @403name/ether-js (MAL-2026-5548). Risk of unauthorized operations or information disclosure.
MAL-2026-5559 Vulnerability in solana-dev-tools (MAL-2026-5559)
vulnerability in solana-dev-tools (MAL-2026-5559). Risk of unauthorized operations or information disclosure.
GHSA-f4f4-69p9-w9f9 Vulnerability in sensivity (GHSA-f4f4-69p9-w9f9)
vulnerability in sensivity (GHSA-f4f4-69p9-w9f9). Risk of unauthorized operations or information disclosure. Exploitable via ``wJWta2lO0Lw``.
MAL-2026-5560 Vulnerability in solana-web3-community (MAL-2026-5560)
vulnerability in solana-web3-community (MAL-2026-5560). Risk of unauthorized operations or information disclosure.
GHSA-pcx2-ghwc-5cp6 Vulnerability in janus-flow (GHSA-pcx2-ghwc-5cp6)
vulnerability in janus-flow (GHSA-pcx2-ghwc-5cp6). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
MAL-2026-5556 Vulnerability in janus-flow (MAL-2026-5556)
vulnerability in janus-flow (MAL-2026-5556). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
GHSA-9pc7-vjjr-gxpr Vulnerability in janus-ft (GHSA-9pc7-vjjr-gxpr)
vulnerability in janus-ft (GHSA-9pc7-vjjr-gxpr). Risk of unauthorized operations or information disclosure.
MAL-2026-5557 Vulnerability in janus-ft (MAL-2026-5557)
vulnerability in janus-ft (MAL-2026-5557). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →