Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MAL-2026-5551 Vulnerability in @my_name_is_khn/express-security-tool-v1 (MAL-2026-5551)
vulnerability in @my_name_is_khn/express-security-tool-v1 (MAL-2026-5551). Risk of unauthorized operations or information disclosure. Exploitable via `GET /robots.txt`.
MAL-2026-5552 Vulnerability in @my_name_is_khn/express-security-tool-v3 (MAL-2026-5552)
vulnerability in @my_name_is_khn/express-security-tool-v3 (MAL-2026-5552). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
MAL-2026-5550 Vulnerability in @my_name_is_khn/express-security-tool (MAL-2026-5550)
vulnerability in @my_name_is_khn/express-security-tool (MAL-2026-5550). Risk of unauthorized operations or information disclosure. Exploitable via `GET /favicon.ico`.
MAL-2026-5555 Vulnerability in express-timer (MAL-2026-5555)
vulnerability in express-timer (MAL-2026-5555). Risk of unauthorized operations or information disclosure. Exploitable via `GET /robots.txt`.
MAL-2026-5554 Vulnerability in express-self-destruct2 (MAL-2026-5554)
vulnerability in express-self-destruct2 (MAL-2026-5554). Risk of unauthorized operations or information disclosure. Exploitable via ``app``.
MAL-2026-5553 Vulnerability in express-self-destruct (MAL-2026-5553)
vulnerability in express-self-destruct (MAL-2026-5553). Risk of unauthorized operations or information disclosure. Exploitable via `GET /robots.txt`.
MAL-2026-5542 Vulnerability in india-map-react (MAL-2026-5542)
vulnerability in india-map-react (MAL-2026-5542). Risk of unauthorized operations or information disclosure.
MAL-2026-5541 Vulnerability in @w2d/web-components (MAL-2026-5541)
vulnerability in @w2d/web-components (MAL-2026-5541). Risk of unauthorized operations or information disclosure.
MAL-2026-5543 Vulnerability in jailbreak-code (MAL-2026-5543)
vulnerability in jailbreak-code (MAL-2026-5543). Risk of unauthorized operations or information disclosure. Exploitable via ``c2ReportApiKey``.
MAL-2026-5545 Vulnerability in acme-widget-layout-utils (MAL-2026-5545)
vulnerability in acme-widget-layout-utils (MAL-2026-5545). Risk of unauthorized operations or information disclosure.
MAL-2026-5544 Vulnerability in pocteszep (MAL-2026-5544)
vulnerability in pocteszep (MAL-2026-5544). Risk of unauthorized operations or information disclosure.
MGASA-2026-0194 Vulnerability in roundcubemail (MGASA-2026-0194)
vulnerability in roundcubemail (MGASA-2026-0194). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.16-1.mga9` or later.
GHSA-5g45-cfrj-qc64 Vulnerability in @monitoring-lib/error-tracking (GHSA-5g45-cfrj-qc64)
vulnerability in @monitoring-lib/error-tracking (GHSA-5g45-cfrj-qc64). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
MAL-2026-5540 Vulnerability in @monitoring-lib/error-tracking (MAL-2026-5540)
vulnerability in @monitoring-lib/error-tracking (MAL-2026-5540). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
CLEANSTART-2026-EG39405 Vulnerability in trino (CLEANSTART-2026-EG39405)
vulnerability in trino (CLEANSTART-2026-EG39405). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `480-r3` or later.
CLEANSTART-2026-BM78291 Vulnerability in dex (CLEANSTART-2026-BM78291)
vulnerability in dex (CLEANSTART-2026-BM78291). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.45.1-r4` or later.
CLEANSTART-2026-NM83456 Vulnerability in airflow-2 (CLEANSTART-2026-NM83456)
vulnerability in airflow-2 (CLEANSTART-2026-NM83456). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.10.3-r2` or later.
CLEANSTART-2026-SQ76279 Vulnerability in dex (CLEANSTART-2026-SQ76279)
vulnerability in dex (CLEANSTART-2026-SQ76279). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.45.1-r4` or later.
CLEANSTART-2026-XC13942 Vulnerability in mountpoint-s3-csi-driver (CLEANSTART-2026-XC13942)
vulnerability in mountpoint-s3-csi-driver (CLEANSTART-2026-XC13942). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.3.0-r1` or later.
CLEANSTART-2026-WA48911 Vulnerability in percona-server-mongodb-operator (CLEANSTART-2026-WA48911)
vulnerability in percona-server-mongodb-operator (CLEANSTART-2026-WA48911). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.22.0-r1` or later.
GHSA-xmj9-vhj4-8q6c Vulnerability in mermaid-v11 (GHSA-xmj9-vhj4-8q6c)
vulnerability in mermaid-v11 (GHSA-xmj9-vhj4-8q6c). Risk of unauthorized operations or information disclosure. Exploitable via ``mermaid``.
MAL-2026-5539 Vulnerability in mermaid-v11 (MAL-2026-5539)
vulnerability in mermaid-v11 (MAL-2026-5539). Risk of unauthorized operations or information disclosure. Exploitable via ``mermaid``.
CLEANSTART-2026-AO11810 Vulnerability in apache-zookeeper (CLEANSTART-2026-AO11810)
vulnerability in apache-zookeeper (CLEANSTART-2026-AO11810). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.5-r1` or later.
CLEANSTART-2026-OK35650 Vulnerability in rancher-agent (CLEANSTART-2026-OK35650)
vulnerability in rancher-agent (CLEANSTART-2026-OK35650). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.13.1-r0` or later.
CLEANSTART-2026-HW72470 Vulnerability in apache-zookeeper (CLEANSTART-2026-HW72470)
vulnerability in apache-zookeeper (CLEANSTART-2026-HW72470). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.4-r4` or later.
CLEANSTART-2026-CC73064 Vulnerability in apache-zookeeper (CLEANSTART-2026-CC73064)
vulnerability in apache-zookeeper (CLEANSTART-2026-CC73064). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.7.2-r6` or later.
CLEANSTART-2026-YM13650 Vulnerability in apache-zookeeper (CLEANSTART-2026-YM13650)
vulnerability in apache-zookeeper (CLEANSTART-2026-YM13650). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.8.6-r1` or later.
CLEANSTART-2026-GB30250 Vulnerability in apache-zookeeper (CLEANSTART-2026-GB30250)
vulnerability in apache-zookeeper (CLEANSTART-2026-GB30250). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.9.4-r6` or later.
CLEANSTART-2026-YP53663 Vulnerability in lvm-driver (CLEANSTART-2026-YP53663)
vulnerability in lvm-driver (CLEANSTART-2026-YP53663). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.1-r2` or later.
CLEANSTART-2026-JY46135 Vulnerability in modelmesh-runtime-adapter (CLEANSTART-2026-JY46135)
vulnerability in modelmesh-runtime-adapter (CLEANSTART-2026-JY46135). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.12.0-r3` or later.
CLEANSTART-2026-LO88261 Vulnerability in eck-operator (CLEANSTART-2026-LO88261)
vulnerability in eck-operator (CLEANSTART-2026-LO88261). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2.0-r1` or later.
CLEANSTART-2026-KN74022 Vulnerability in local-static-provisioner-fips (CLEANSTART-2026-KN74022)
vulnerability in local-static-provisioner-fips (CLEANSTART-2026-KN74022). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.8.0-r3` or later.
CLEANSTART-2026-GU65783 Vulnerability in eck-operator (CLEANSTART-2026-GU65783)
vulnerability in eck-operator (CLEANSTART-2026-GU65783). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2.0-r1` or later.
CLEANSTART-2026-XW33274 Vulnerability in kyverno-policy-reporter-kyverno-plugin-fips (CLEANSTART-2026-XW33274)
vulnerability in kyverno-policy-reporter-kyverno-plugin-fips (CLEANSTART-2026-XW33274). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.6.4-r5` or later.
CLEANSTART-2026-KV53168 Vulnerability in kyverno-policy-reporter-kyverno-plugin (CLEANSTART-2026-KV53168)
vulnerability in kyverno-policy-reporter-kyverno-plugin (CLEANSTART-2026-KV53168). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.6.4-r0` or later.
GHSA-6p55-6hvr-3xmg Vulnerability in @common-stack/generate-plugin (GHSA-6p55-6hvr-3xmg)
vulnerability in @common-stack/generate-plugin (GHSA-6p55-6hvr-3xmg). Risk of unauthorized operations or information disclosure.
MAL-2026-5537 Vulnerability in @entos-ems/xerxes-client-js (MAL-2026-5537)
vulnerability in @entos-ems/xerxes-client-js (MAL-2026-5537). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
GHSA-jc42-pxfc-29x3 Vulnerability in hex-type (GHSA-jc42-pxfc-29x3)
vulnerability in hex-type (GHSA-jc42-pxfc-29x3). Risk of unauthorized operations or information disclosure. Exploitable via ``ulid``.
RLSA-2026:25090 Vulnerability in httpd (RLSA-2026:25090)
vulnerability in httpd (RLSA-2026:25090). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.4.37-65.module+el8.10.0+1830+22f0c9e0` or later.
ALSA-2026:25341 Important: tomcat9 update
Important: tomcat9 update
ALSA-2026:25225 Vulnerability in mod_http2 (ALSA-2026:25225)
vulnerability in mod_http2 (ALSA-2026:25225). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.29-4.el10_2.1` or later.
UBUNTU-CVE-2026-48858 (Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ft ...)
ALSA-2026:25239 Vulnerability in openssl (ALSA-2026:25239)
vulnerability in openssl (ALSA-2026:25239). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:3.5.5-4.el9_8` or later.
ALSA-2026:25219 Vulnerability in redis (ALSA-2026:25219)
vulnerability in redis (ALSA-2026:25219). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.2.14-1.module_el9.8.0+258+b8f945d3` or later.
ALSA-2026:25222 Vulnerability in aspnetcore-runtime-10.0 (ALSA-2026:25222)
vulnerability in aspnetcore-runtime-10.0 (ALSA-2026:25222). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.0.9-1.el9_8` or later.
ALSA-2026:25221 Vulnerability in aspnetcore-runtime-9.0 (ALSA-2026:25221)
vulnerability in aspnetcore-runtime-9.0 (ALSA-2026:25221). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.17-1.el9_8` or later.
ALSA-2026:25220 Vulnerability in aspnetcore-runtime-8.0 (ALSA-2026:25220)
vulnerability in aspnetcore-runtime-8.0 (ALSA-2026:25220). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.28-1.el9_8` or later.
UBUNTU-CVE-2026-53689 Vulnerability in libnfs (UBUNTU-CVE-2026-53689)
vulnerability in libnfs (UBUNTU-CVE-2026-53689). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.0-1ubuntu0.1` or later.
UBUNTU-CVE-2026-6893 Vulnerability in dracut (UBUNTU-CVE-2026-6893)
vulnerability in dracut (UBUNTU-CVE-2026-6893). Successful exploitation can lead to full system takeover.
UBUNTU-CVE-2026-52726 Vulnerability in dulwich (UBUNTU-CVE-2026-52726)
vulnerability in dulwich (UBUNTU-CVE-2026-52726). Risk of unauthorized operations or information disclosure. Exploitable via ``dulwich.porcelain.submodule_update``.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →