Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MAL-2026-5458 |
|
Vulnerability in ultimate-ai-power (MAL-2026-5458)
vulnerability in ultimate-ai-power (MAL-2026-5458). Risk of unauthorized operations or information disclosure.
|
| GHSA-xr7v-2mxc-cw5x |
|
Vulnerability in comos-sdk (GHSA-xr7v-2mxc-cw5x)
vulnerability in comos-sdk (GHSA-xr7v-2mxc-cw5x). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5404 |
|
Vulnerability in cubifyanything (MAL-2026-5404)
vulnerability in cubifyanything (MAL-2026-5404). Risk of unauthorized operations or information disclosure.
|
| USN-8409-1 |
|
Vulnerability in uriparser (USN-8409-1)
vulnerability in uriparser (USN-8409-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.7.5-1ubuntu2+esm5` or later.
|
| USN-8156-2 |
|
Vulnerability in gdk-pixbuf (USN-8156-2)
vulnerability in gdk-pixbuf (USN-8156-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.32.2-1ubuntu1.6+esm3` or later.
|
| USN-8412-1 |
|
Vulnerability in qemu (USN-8412-1)
vulnerability in qemu (USN-8412-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0+dfsg-2ubuntu1.47+esm6` or later.
|
| CVE-2026-8045 |
|
XXE (XML External Entity) in schneider-electric (CVE-2026-8045)
vulnerability in schneider-electric (CVE-2026-8045). Confidential information can be exposed externally.
|
| CVE-2026-8025 |
|
SQL Injection in sqli (CVE-2026-8025)
SQL injection in sqli (CVE-2026-8025). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49948 |
|
Vulnerability in CVE-2026-49948 (CVE-2026-49948)
vulnerability in CVE-2026-49948 (CVE-2026-49948). Confidential information can be exposed externally. Exploitable via `POST /configure`.
|
| CVE-2026-49938 |
|
Vulnerability in fortinet (CVE-2026-49938)
vulnerability in fortinet (CVE-2026-49938). Confidential information can be exposed externally.
|
| CVE-2026-25089 KEV |
|
[KEV] OS Command Injection in Fortinet fortisandbox (CVE-2026-25089)
OS command injection in Fortinet fortisandbox (CVE-2026-25089). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-24065 |
|
Vulnerability in privilege-escalation (CVE-2026-24065)
vulnerability in privilege-escalation (CVE-2026-24065). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24064 |
|
Vulnerability in privilege-escalation (CVE-2026-24064)
vulnerability in privilege-escalation (CVE-2026-24064). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10727 |
|
OS Command Injection in CVE-2026-10727 (CVE-2026-10727)
OS command injection in CVE-2026-10727 (CVE-2026-10727). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10523 |
|
Vulnerability in ivanti (CVE-2026-10523)
vulnerability in ivanti (CVE-2026-10523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10520 KEV |
|
[KEV] OS Command Injection in Ivanti standalone-sentry (CVE-2026-10520)
OS command injection in Ivanti standalone-sentry (CVE-2026-10520). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-67862 |
|
Vulnerability in fortinet (CVE-2025-67862)
vulnerability in fortinet (CVE-2025-67862). Successful exploitation can lead to full system takeover.
|
| MAL-2026-5387 |
|
Vulnerability in @0xlr/sentry-web (MAL-2026-5387)
vulnerability in @0xlr/sentry-web (MAL-2026-5387). Risk of unauthorized operations or information disclosure.
|
| USN-8413-1 |
|
Vulnerability in cyborg (USN-8413-1)
vulnerability in cyborg (USN-8413-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.0.0-3+deb13u1build0.25.10.1` or later.
|
| MAL-2026-5385 |
|
Vulnerability in @0xlr/clerk-auth (MAL-2026-5385)
vulnerability in @0xlr/clerk-auth (MAL-2026-5385). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5386 |
|
Vulnerability in @0xlr/prisma-client-js (MAL-2026-5386)
vulnerability in @0xlr/prisma-client-js (MAL-2026-5386). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5391 |
|
Vulnerability in @0xlr/vercel-analytics (MAL-2026-5391)
vulnerability in @0xlr/vercel-analytics (MAL-2026-5391). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5389 |
|
Vulnerability in @0xlr/stripe-frontend (MAL-2026-5389)
vulnerability in @0xlr/stripe-frontend (MAL-2026-5389). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5388 |
|
Vulnerability in @0xlr/stripe-checkout-js (MAL-2026-5388)
vulnerability in @0xlr/stripe-checkout-js (MAL-2026-5388). Risk of unauthorized operations or information disclosure.
|
| GHSA-x2w5-px4q-j9wq |
|
Vulnerability in ui-weave (GHSA-x2w5-px4q-j9wq)
vulnerability in ui-weave (GHSA-x2w5-px4q-j9wq). Risk of unauthorized operations or information disclosure. Exploitable via ``data.cookie``.
|
| MAL-2026-5390 |
|
Vulnerability in @0xlr/supabase-db (MAL-2026-5390)
vulnerability in @0xlr/supabase-db (MAL-2026-5390). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5399 |
|
Vulnerability in kraken-ui (MAL-2026-5399)
vulnerability in kraken-ui (MAL-2026-5399). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5393 |
|
Vulnerability in @sflyinc-knapsack/shutterfly-react (MAL-2026-5393)
vulnerability in @sflyinc-knapsack/shutterfly-react (MAL-2026-5393). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5392 |
|
Vulnerability in @open-banking/cabinet-providers (MAL-2026-5392)
vulnerability in @open-banking/cabinet-providers (MAL-2026-5392). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5401 |
|
Vulnerability in savant-listing (MAL-2026-5401)
vulnerability in savant-listing (MAL-2026-5401). Risk of unauthorized operations or information disclosure. Exploitable via ``install``.
|
| MAL-2026-5402 |
|
Vulnerability in screenpipe-mcp-http (MAL-2026-5402)
vulnerability in screenpipe-mcp-http (MAL-2026-5402). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5400 |
|
Vulnerability in multica (MAL-2026-5400)
vulnerability in multica (MAL-2026-5400). Risk of unauthorized operations or information disclosure. Exploitable via ``multica``.
|
| MAL-2026-5397 |
|
Vulnerability in create-docs-mcp (MAL-2026-5397)
vulnerability in create-docs-mcp (MAL-2026-5397). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5403 |
|
Vulnerability in t-invest-mcp-server (MAL-2026-5403)
vulnerability in t-invest-mcp-server (MAL-2026-5403). Risk of unauthorized operations or information disclosure.
|
| MINI-pp6w-q65m-hm4v |
|
MINI-pp6w-q65m-hm4v |
| MINI-5mcr-4xx5-w3gr |
|
MINI-5mcr-4xx5-w3gr |
| MINI-p2r5-r4w9-5jgw |
|
MINI-p2r5-r4w9-5jgw |
| MINI-fwh9-796c-r36w |
|
MINI-fwh9-796c-r36w |
| MINI-vgq5-p8qx-rv46 |
|
MINI-vgq5-p8qx-rv46 |
| MINI-2mj6-jgrp-42r7 |
|
MINI-2mj6-jgrp-42r7 |
| MINI-5f6h-wv66-xv4x |
|
MINI-5f6h-wv66-xv4x |
| MINI-r8h5-w8hq-vr97 |
|
MINI-r8h5-w8hq-vr97 |
| MINI-p297-6w5v-99r9 |
|
MINI-p297-6w5v-99r9 |
| MINI-gph3-h5cm-gww5 |
|
MINI-gph3-h5cm-gww5 |
| MINI-p88c-h56p-q7r5 |
|
MINI-p88c-h56p-q7r5 |
| MINI-38ph-r5x6-2gv7 |
|
MINI-38ph-r5x6-2gv7 |
| MINI-45xm-5x8x-pqrp |
|
MINI-45xm-5x8x-pqrp |
| MINI-fx8h-jcj7-4w3m |
|
MINI-fx8h-jcj7-4w3m |
| MINI-j8rf-6xmw-wphf |
|
MINI-j8rf-6xmw-wphf |
| MINI-v75p-c3rc-gqf7 |
|
MINI-v75p-c3rc-gqf7 |