Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
GHSA-8g7g-hmwm-6rv2 Path Traversal in n8n-mcp (GHSA-8g7g-hmwm-6rv2)
path traversal in n8n-mcp (GHSA-8g7g-hmwm-6rv2). Risk of unauthorized operations or information disclosure. Exploitable via ``DISABLED_TOOLS``. Mitigation: upgrade to `2.50.1` or later.
CVE-2026-44212 Cross-Site Scripting (XSS) in prestashop/prestashop (CVE-2026-44212)
cross-site scripting in prestashop/prestashop (CVE-2026-44212). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.1.1` or later.
CVE-2026-44670 Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-44670)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-44670). Risk of unauthorized operations or information disclosure. Exploitable via ``outerHTML``.
GHSA-52cq-7v8r-62c6 Vulnerability in gmaps-mcp (GHSA-52cq-7v8r-62c6)
vulnerability in gmaps-mcp (GHSA-52cq-7v8r-62c6). Risk of unauthorized operations or information disclosure. Exploitable via `X-API-Key header`. Mitigation: upgrade to `0.1.3` or later.
CVE-2026-44665 XXE (XML External Entity) in fast-xml-builder (CVE-2026-44665)
vulnerability in fast-xml-builder (CVE-2026-44665). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.7` or later.
CVE-2026-44664 Vulnerability in fast-xml-builder (CVE-2026-44664)
vulnerability in fast-xml-builder (CVE-2026-44664). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.6` or later.
GHSA-2cm2-m3w5-gp2f Vulnerability in vm2 (GHSA-2cm2-m3w5-gp2f)
vulnerability in vm2 (GHSA-2cm2-m3w5-gp2f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.11.2` or later.
CVE-2026-44009 Vulnerability in vm2 (CVE-2026-44009)
vulnerability in vm2 (CVE-2026-44009). Risk of unauthorized operations or information disclosure. Exploitable via ``handleException``. Mitigation: upgrade to `3.11.2` or later.
CVE-2026-44499 Vulnerability in zebrad (CVE-2026-44499)
vulnerability in zebrad (CVE-2026-44499). Risk of unauthorized operations or information disclosure. Exploitable via ``inv``. Mitigation: upgrade to `4.4.0` or later.
CVE-2026-43967 Vulnerability in dos (CVE-2026-43967)
vulnerability in dos (CVE-2026-43967). Risk of unauthorized operations or information disclosure.
CVE-2026-42794 Cross-Site Scripting (XSS) in CVE-2026-42794 (CVE-2026-42794)
cross-site scripting in CVE-2026-42794 (CVE-2026-42794). Risk of unauthorized operations or information disclosure.
CVE-2026-42793 Vulnerability in dos (CVE-2026-42793)
vulnerability in dos (CVE-2026-42793). Risk of unauthorized operations or information disclosure.
CVE-2026-42353 Path Traversal in express (CVE-2026-42353)
path traversal in express (CVE-2026-42353). Confidential information can be exposed externally.
CVE-2026-41886 Cross-Site Scripting (XSS) in CVE-2026-41886 (CVE-2026-41886)
cross-site scripting in CVE-2026-41886 (CVE-2026-41886). Data can be tampered with by attackers.
CVE-2026-41885 Path Traversal in CVE-2026-41885 (CVE-2026-41885)
path traversal in CVE-2026-41885 (CVE-2026-41885). Risk of unauthorized operations or information disclosure.
CVE-2026-41883 Vulnerability in CVE-2026-41883 (CVE-2026-41883)
vulnerability in CVE-2026-41883 (CVE-2026-41883). Successful exploitation can lead to full system takeover.
CVE-2026-41693 Path Traversal in CVE-2026-41693 (CVE-2026-41693)
path traversal in CVE-2026-41693 (CVE-2026-41693). Confidential information can be exposed externally.
CVE-2026-41690 Path Traversal in express (CVE-2026-41690)
path traversal in express (CVE-2026-41690). Data can be tampered with by attackers.
CVE-2026-41683 Cross-Site Scripting (XSS) in express (CVE-2026-41683)
cross-site scripting in express (CVE-2026-41683). Data can be tampered with by attackers.
CVE-2026-41591 Cross-Site Scripting (XSS) in CVE-2026-41591 (CVE-2026-41591)
cross-site scripting in CVE-2026-41591 (CVE-2026-41591). Risk of unauthorized operations or information disclosure.
CVE-2026-41070 Authentication Bypass in openvpn (CVE-2026-41070)
authentication bypass in openvpn (CVE-2026-41070). Confidential information can be exposed externally. Exploitable via ``plugin``.
CVE-2026-34354 Vulnerability in privilege-escalation (CVE-2026-34354)
vulnerability in privilege-escalation (CVE-2026-34354). Successful exploitation can lead to full system takeover.
CVE-2026-29975 Vulnerability in c (CVE-2026-29975)
vulnerability in c (CVE-2026-29975). Risk of unauthorized operations or information disclosure.
CVE-2026-29974 Vulnerability in CVE-2026-29974 (CVE-2026-29974)
vulnerability in CVE-2026-29974 (CVE-2026-29974). Risk of unauthorized operations or information disclosure.
CVE-2026-29972 Vulnerability in c (CVE-2026-29972)
vulnerability in c (CVE-2026-29972). Risk of unauthorized operations or information disclosure.
MINI-hxqr-h27v-43q5 MINI-hxqr-h27v-43q5
CVE-2026-44008 Vulnerability in vm2 (CVE-2026-44008)
vulnerability in vm2 (CVE-2026-44008). Risk of unauthorized operations or information disclosure. Exploitable via ``neutralizeArraySpeciesBatch``. Mitigation: upgrade to `3.11.2` or later.
MINI-r4j3-4vcp-gwcq MINI-r4j3-4vcp-gwcq
MINI-v3g3-qh4c-jxp7 MINI-v3g3-qh4c-jxp7
MINI-33rx-2crx-cv3w MINI-33rx-2crx-cv3w
CVE-2026-40295 Open Redirect in devise (CVE-2026-40295)
vulnerability in devise (CVE-2026-40295). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `5.0.4` or later.
CVE-2026-44500 Vulnerability in deserialization (CVE-2026-44500)
vulnerability in deserialization (CVE-2026-44500). Risk of unauthorized operations or information disclosure.
CVE-2026-44498 Vulnerability in zfnd (CVE-2026-44498)
vulnerability in zfnd (CVE-2026-44498). Data can be tampered with by attackers.
CVE-2026-44497 Vulnerability in zfnd (CVE-2026-44497)
vulnerability in zfnd (CVE-2026-44497). Data can be tampered with by attackers. Exploitable via ``zcashd``. Mitigation: upgrade to `4.4.0` or later.
CVE-2026-43475 Vulnerability in CVE-2026-43475 (CVE-2026-43475)
vulnerability in CVE-2026-43475 (CVE-2026-43475). Risk of unauthorized operations or information disclosure.
CVE-2026-43474 Vulnerability in c (CVE-2026-43474)
vulnerability in c (CVE-2026-43474). Risk of unauthorized operations or information disclosure.
CVE-2026-43473 Vulnerability in CVE-2026-43473 (CVE-2026-43473)
vulnerability in CVE-2026-43473 (CVE-2026-43473). Risk of unauthorized operations or information disclosure.
CVE-2026-43472 Vulnerability in CVE-2026-43472 (CVE-2026-43472)
vulnerability in CVE-2026-43472 (CVE-2026-43472). Risk of unauthorized operations or information disclosure.
CVE-2026-43471 Vulnerability in CVE-2026-43471 (CVE-2026-43471)
vulnerability in CVE-2026-43471 (CVE-2026-43471). Risk of unauthorized operations or information disclosure.
CVE-2026-43470 Vulnerability in CVE-2026-43470 (CVE-2026-43470)
vulnerability in CVE-2026-43470 (CVE-2026-43470). Risk of unauthorized operations or information disclosure.
CVE-2026-43469 Vulnerability in CVE-2026-43469 (CVE-2026-43469)
vulnerability in CVE-2026-43469 (CVE-2026-43469). Risk of unauthorized operations or information disclosure.
CVE-2026-43468 Vulnerability in CVE-2026-43468 (CVE-2026-43468)
vulnerability in CVE-2026-43468 (CVE-2026-43468). Risk of unauthorized operations or information disclosure.
CVE-2026-43467 Vulnerability in c (CVE-2026-43467)
vulnerability in c (CVE-2026-43467). Risk of unauthorized operations or information disclosure.
CVE-2026-43466 Vulnerability in c (CVE-2026-43466)
vulnerability in c (CVE-2026-43466). Risk of unauthorized operations or information disclosure.
CVE-2026-43465 Vulnerability in CVE-2026-43465 (CVE-2026-43465)
vulnerability in CVE-2026-43465 (CVE-2026-43465). Risk of unauthorized operations or information disclosure.
CVE-2026-43464 Vulnerability in CVE-2026-43464 (CVE-2026-43464)
vulnerability in CVE-2026-43464 (CVE-2026-43464). Risk of unauthorized operations or information disclosure.
CVE-2026-43463 Vulnerability in CVE-2026-43463 (CVE-2026-43463)
vulnerability in CVE-2026-43463 (CVE-2026-43463). Risk of unauthorized operations or information disclosure.
CVE-2026-43462 Vulnerability in CVE-2026-43462 (CVE-2026-43462)
vulnerability in CVE-2026-43462 (CVE-2026-43462). Risk of unauthorized operations or information disclosure.
CVE-2026-43461 Vulnerability in CVE-2026-43461 (CVE-2026-43461)
vulnerability in CVE-2026-43461 (CVE-2026-43461). Risk of unauthorized operations or information disclosure.
CVE-2026-43460 Vulnerability in CVE-2026-43460 (CVE-2026-43460)
vulnerability in CVE-2026-43460 (CVE-2026-43460). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →