Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-xhpx-xg48-q48c |
|
MINI-xhpx-xg48-q48c |
| MINI-7f2c-6f6r-hxmx |
|
MINI-7f2c-6f6r-hxmx |
| MINI-6r5v-vjhv-qgrg |
|
MINI-6r5v-vjhv-qgrg |
| MINI-2vxc-4x6h-cj2x |
|
MINI-2vxc-4x6h-cj2x |
| MINI-2vf5-v3cj-mwcc |
|
MINI-2vf5-v3cj-mwcc |
| MINI-v2g8-5phm-c9q7 |
|
MINI-v2g8-5phm-c9q7 |
| MINI-7px6-fx4c-7f32 |
|
MINI-7px6-fx4c-7f32 |
| MINI-fpqq-fpjx-cr84 |
|
MINI-fpqq-fpjx-cr84 |
| MINI-mx77-7rcx-8wmg |
|
MINI-mx77-7rcx-8wmg |
| MINI-55ch-q7xq-85q8 |
|
MINI-55ch-q7xq-85q8 |
| MINI-8x7p-89m6-4vfj |
|
MINI-8x7p-89m6-4vfj |
| MINI-49qq-72w3-p3x4 |
|
MINI-49qq-72w3-p3x4 |
| MINI-v87r-r2cf-c3x3 |
|
MINI-v87r-r2cf-c3x3 |
| MINI-hg4r-84vf-w9rp |
|
MINI-hg4r-84vf-w9rp |
| MINI-vrcf-3j64-wp2r |
|
MINI-vrcf-3j64-wp2r |
| MINI-w8jw-j428-2294 |
|
MINI-w8jw-j428-2294 |
| MINI-rmw7-vwxr-j39v |
|
MINI-rmw7-vwxr-j39v |
| MINI-q7jx-58r9-3pq9 |
|
MINI-q7jx-58r9-3pq9 |
| MINI-97wj-wmfr-hrwh |
|
MINI-97wj-wmfr-hrwh |
| MINI-pxjx-mprr-rj82 |
|
MINI-pxjx-mprr-rj82 |
| MINI-mjh8-mr8f-6vrx |
|
MINI-mjh8-mr8f-6vrx |
| MINI-gwgv-g3gc-3xg7 |
|
MINI-gwgv-g3gc-3xg7 |
| MINI-x9xc-jh8p-h64c |
|
MINI-x9xc-jh8p-h64c |
| MINI-3rmh-pgq6-52x3 |
|
MINI-3rmh-pgq6-52x3 |
| MINI-j9px-8w57-jcp9 |
|
MINI-j9px-8w57-jcp9 |
| MINI-hmc7-52wf-4655 |
|
MINI-hmc7-52wf-4655 |
| MINI-35wc-369q-rp6x |
|
MINI-35wc-369q-rp6x |
| CVE-2026-6893 |
|
OS Command Injection in CVE-2026-6893 (CVE-2026-6893)
OS command injection in CVE-2026-6893 (CVE-2026-6893). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1220 |
|
Vulnerability in google (CVE-2026-1220)
vulnerability in google (CVE-2026-1220). Successful exploitation can lead to full system takeover.
|
| DEBIAN-CVE-2026-53689 |
|
Vulnerability in libnfs (DEBIAN-CVE-2026-53689)
vulnerability in libnfs (DEBIAN-CVE-2026-53689). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47764 |
|
Path Traversal in pdm (CVE-2026-47764)
path traversal in pdm (CVE-2026-47764). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.27.0` or later.
|
| CVE-2026-47763 |
|
Vulnerability in pdm (CVE-2026-47763)
vulnerability in pdm (CVE-2026-47763). Risk of unauthorized operations or information disclosure. Exploitable via ``pdm.toml``. Mitigation: upgrade to `2.27.0` or later.
|
| CVE-2026-50127 |
|
SSRF (Server-Side Request Forgery) in weblate (CVE-2026-50127)
SSRF in weblate (CVE-2026-50127). Confidential information can be exposed externally. Exploitable via ``VCS_RESTRICT_PRIVATE``. Mitigation: upgrade to `2026.6` or later.
|
| CVE-2026-46529 |
|
Command Injection in c (CVE-2026-46529)
command injection in c (CVE-2026-46529). Successful exploitation can lead to full system takeover. Exploitable via ``g_shell_quote``. Mitigation: upgrade to `1.6.2` or later.
|
| DEBIAN-CVE-2026-1220 |
|
Vulnerability in chromium (DEBIAN-CVE-2026-1220)
vulnerability in chromium (DEBIAN-CVE-2026-1220). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `144.0.7559.96-1~deb12u1` or later.
|
| CVE-2026-47753 |
|
Vulnerability in github.com/lxc/incus/v7 (CVE-2026-47753)
vulnerability in github.com/lxc/incus/v7 (CVE-2026-47753). Risk of unauthorized operations or information disclosure. Exploitable via `POST /1.0/instances`. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-47751 |
|
OS Command Injection in anthropics/claude-code-action (CVE-2026-47751)
OS command injection in anthropics/claude-code-action (CVE-2026-47751). Risk of unauthorized operations or information disclosure. Exploitable via ``enableAllProjectMcpServers``. Mitigation: upgrade to `1.0.74` or later.
|
| CVE-2026-48063 |
|
Vulnerability in baileys (CVE-2026-48063)
vulnerability in baileys (CVE-2026-48063). Risk of unauthorized operations or information disclosure. Exploitable via ``messages.upsert``. Mitigation: upgrade to `7.0.0-rc12` or later.
|
| MAL-2026-5531 |
|
Vulnerability in telegramlite (MAL-2026-5531)
vulnerability in telegramlite (MAL-2026-5531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50639 |
|
Vulnerability in pevans (CVE-2026-50639)
vulnerability in pevans (CVE-2026-50639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50638 |
|
Vulnerability in pevans (CVE-2026-50638)
vulnerability in pevans (CVE-2026-50638). Confidential information can be exposed externally.
|
| CVE-2026-50637 |
|
Vulnerability in pevans (CVE-2026-50637)
vulnerability in pevans (CVE-2026-50637). Data can be tampered with by attackers.
|
| CVE-2026-11626 |
|
Vulnerability in privilege-escalation (CVE-2026-11626)
vulnerability in privilege-escalation (CVE-2026-11626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48061 |
|
Vulnerability in litestar (CVE-2026-48061)
vulnerability in litestar (CVE-2026-48061). Data can be tampered with by attackers. Exploitable via `Host header`. Mitigation: upgrade to `2.22.0` or later.
|
| CVE-2026-48060 |
|
Cross-Site Scripting (XSS) in litestar (CVE-2026-48060)
cross-site scripting in litestar (CVE-2026-48060). Confidential information can be exposed externally. Exploitable via `GET /vulnerable`. Mitigation: upgrade to `2.22.0` or later.
|
| CVE-2026-10740 |
|
Vulnerability in Amazon s2n-quic (CVE-2026-10740)
vulnerability in Amazon s2n-quic (CVE-2026-10740). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.82.0` or later.
|
| CVE-2026-48058 |
|
Vulnerability in github.com/juev/nebula-mesh (CVE-2026-48058)
vulnerability in github.com/juev/nebula-mesh (CVE-2026-48058). Risk of unauthorized operations or information disclosure. Exploitable via ``HttpOnly``. Mitigation: upgrade to `0.3.2` or later.
|
| MAL-2026-5526 |
|
Vulnerability in chai-check-error (MAL-2026-5526)
vulnerability in chai-check-error (MAL-2026-5526). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
|
| MAL-2026-5527 |
|
Vulnerability in check-error-util (MAL-2026-5527)
vulnerability in check-error-util (MAL-2026-5527). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
|
| GHSA-27vg-w6vw-2rq8 |
|
Vulnerability in websocket-slot (GHSA-27vg-w6vw-2rq8)
vulnerability in websocket-slot (GHSA-27vg-w6vw-2rq8). Risk of unauthorized operations or information disclosure. Exploitable via ``scripts.postinstall``.
|