Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MAL-2026-5458 Vulnerability in ultimate-ai-power (MAL-2026-5458)
vulnerability in ultimate-ai-power (MAL-2026-5458). Risk of unauthorized operations or information disclosure.
GHSA-xr7v-2mxc-cw5x Vulnerability in comos-sdk (GHSA-xr7v-2mxc-cw5x)
vulnerability in comos-sdk (GHSA-xr7v-2mxc-cw5x). Risk of unauthorized operations or information disclosure.
MAL-2026-5404 Vulnerability in cubifyanything (MAL-2026-5404)
vulnerability in cubifyanything (MAL-2026-5404). Risk of unauthorized operations or information disclosure.
USN-8409-1 Vulnerability in uriparser (USN-8409-1)
vulnerability in uriparser (USN-8409-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.7.5-1ubuntu2+esm5` or later.
USN-8156-2 Vulnerability in gdk-pixbuf (USN-8156-2)
vulnerability in gdk-pixbuf (USN-8156-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.32.2-1ubuntu1.6+esm3` or later.
USN-8412-1 Vulnerability in qemu (USN-8412-1)
vulnerability in qemu (USN-8412-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0+dfsg-2ubuntu1.47+esm6` or later.
CVE-2026-8045 XXE (XML External Entity) in schneider-electric (CVE-2026-8045)
vulnerability in schneider-electric (CVE-2026-8045). Confidential information can be exposed externally.
CVE-2026-8025 SQL Injection in sqli (CVE-2026-8025)
SQL injection in sqli (CVE-2026-8025). Successful exploitation can lead to full system takeover.
CVE-2026-49948 Vulnerability in CVE-2026-49948 (CVE-2026-49948)
vulnerability in CVE-2026-49948 (CVE-2026-49948). Confidential information can be exposed externally. Exploitable via `POST /configure`.
CVE-2026-49938 Vulnerability in fortinet (CVE-2026-49938)
vulnerability in fortinet (CVE-2026-49938). Confidential information can be exposed externally.
CVE-2026-25089 KEV [KEV] OS Command Injection in Fortinet fortisandbox (CVE-2026-25089)
OS command injection in Fortinet fortisandbox (CVE-2026-25089). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-24065 Vulnerability in privilege-escalation (CVE-2026-24065)
vulnerability in privilege-escalation (CVE-2026-24065). Successful exploitation can lead to full system takeover.
CVE-2026-24064 Vulnerability in privilege-escalation (CVE-2026-24064)
vulnerability in privilege-escalation (CVE-2026-24064). Successful exploitation can lead to full system takeover.
CVE-2026-10727 OS Command Injection in CVE-2026-10727 (CVE-2026-10727)
OS command injection in CVE-2026-10727 (CVE-2026-10727). Successful exploitation can lead to full system takeover.
CVE-2026-10523 Vulnerability in ivanti (CVE-2026-10523)
vulnerability in ivanti (CVE-2026-10523). Successful exploitation can lead to full system takeover.
CVE-2026-10520 KEV [KEV] OS Command Injection in Ivanti standalone-sentry (CVE-2026-10520)
OS command injection in Ivanti standalone-sentry (CVE-2026-10520). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2025-67862 Vulnerability in fortinet (CVE-2025-67862)
vulnerability in fortinet (CVE-2025-67862). Successful exploitation can lead to full system takeover.
MAL-2026-5387 Vulnerability in @0xlr/sentry-web (MAL-2026-5387)
vulnerability in @0xlr/sentry-web (MAL-2026-5387). Risk of unauthorized operations or information disclosure.
USN-8413-1 Vulnerability in cyborg (USN-8413-1)
vulnerability in cyborg (USN-8413-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.0.0-3+deb13u1build0.25.10.1` or later.
MAL-2026-5385 Vulnerability in @0xlr/clerk-auth (MAL-2026-5385)
vulnerability in @0xlr/clerk-auth (MAL-2026-5385). Risk of unauthorized operations or information disclosure.
MAL-2026-5386 Vulnerability in @0xlr/prisma-client-js (MAL-2026-5386)
vulnerability in @0xlr/prisma-client-js (MAL-2026-5386). Risk of unauthorized operations or information disclosure.
MAL-2026-5391 Vulnerability in @0xlr/vercel-analytics (MAL-2026-5391)
vulnerability in @0xlr/vercel-analytics (MAL-2026-5391). Risk of unauthorized operations or information disclosure.
MAL-2026-5389 Vulnerability in @0xlr/stripe-frontend (MAL-2026-5389)
vulnerability in @0xlr/stripe-frontend (MAL-2026-5389). Risk of unauthorized operations or information disclosure.
MAL-2026-5388 Vulnerability in @0xlr/stripe-checkout-js (MAL-2026-5388)
vulnerability in @0xlr/stripe-checkout-js (MAL-2026-5388). Risk of unauthorized operations or information disclosure.
GHSA-x2w5-px4q-j9wq Vulnerability in ui-weave (GHSA-x2w5-px4q-j9wq)
vulnerability in ui-weave (GHSA-x2w5-px4q-j9wq). Risk of unauthorized operations or information disclosure. Exploitable via ``data.cookie``.
MAL-2026-5390 Vulnerability in @0xlr/supabase-db (MAL-2026-5390)
vulnerability in @0xlr/supabase-db (MAL-2026-5390). Risk of unauthorized operations or information disclosure.
MAL-2026-5399 Vulnerability in kraken-ui (MAL-2026-5399)
vulnerability in kraken-ui (MAL-2026-5399). Risk of unauthorized operations or information disclosure.
MAL-2026-5393 Vulnerability in @sflyinc-knapsack/shutterfly-react (MAL-2026-5393)
vulnerability in @sflyinc-knapsack/shutterfly-react (MAL-2026-5393). Risk of unauthorized operations or information disclosure.
MAL-2026-5392 Vulnerability in @open-banking/cabinet-providers (MAL-2026-5392)
vulnerability in @open-banking/cabinet-providers (MAL-2026-5392). Risk of unauthorized operations or information disclosure.
MAL-2026-5401 Vulnerability in savant-listing (MAL-2026-5401)
vulnerability in savant-listing (MAL-2026-5401). Risk of unauthorized operations or information disclosure. Exploitable via ``install``.
MAL-2026-5402 Vulnerability in screenpipe-mcp-http (MAL-2026-5402)
vulnerability in screenpipe-mcp-http (MAL-2026-5402). Risk of unauthorized operations or information disclosure.
MAL-2026-5400 Vulnerability in multica (MAL-2026-5400)
vulnerability in multica (MAL-2026-5400). Risk of unauthorized operations or information disclosure. Exploitable via ``multica``.
MAL-2026-5397 Vulnerability in create-docs-mcp (MAL-2026-5397)
vulnerability in create-docs-mcp (MAL-2026-5397). Risk of unauthorized operations or information disclosure.
MAL-2026-5403 Vulnerability in t-invest-mcp-server (MAL-2026-5403)
vulnerability in t-invest-mcp-server (MAL-2026-5403). Risk of unauthorized operations or information disclosure.
MINI-pp6w-q65m-hm4v MINI-pp6w-q65m-hm4v
MINI-5mcr-4xx5-w3gr MINI-5mcr-4xx5-w3gr
MINI-p2r5-r4w9-5jgw MINI-p2r5-r4w9-5jgw
MINI-fwh9-796c-r36w MINI-fwh9-796c-r36w
MINI-vgq5-p8qx-rv46 MINI-vgq5-p8qx-rv46
MINI-2mj6-jgrp-42r7 MINI-2mj6-jgrp-42r7
MINI-5f6h-wv66-xv4x MINI-5f6h-wv66-xv4x
MINI-r8h5-w8hq-vr97 MINI-r8h5-w8hq-vr97
MINI-p297-6w5v-99r9 MINI-p297-6w5v-99r9
MINI-gph3-h5cm-gww5 MINI-gph3-h5cm-gww5
MINI-p88c-h56p-q7r5 MINI-p88c-h56p-q7r5
MINI-38ph-r5x6-2gv7 MINI-38ph-r5x6-2gv7
MINI-45xm-5x8x-pqrp MINI-45xm-5x8x-pqrp
MINI-fx8h-jcj7-4w3m MINI-fx8h-jcj7-4w3m
MINI-j8rf-6xmw-wphf MINI-j8rf-6xmw-wphf
MINI-v75p-c3rc-gqf7 MINI-v75p-c3rc-gqf7

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →