Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-8g7g-hmwm-6rv2 |
|
Path Traversal in n8n-mcp (GHSA-8g7g-hmwm-6rv2)
path traversal in n8n-mcp (GHSA-8g7g-hmwm-6rv2). Risk of unauthorized operations or information disclosure. Exploitable via ``DISABLED_TOOLS``. Mitigation: upgrade to `2.50.1` or later.
|
| CVE-2026-44212 |
|
Cross-Site Scripting (XSS) in prestashop/prestashop (CVE-2026-44212)
cross-site scripting in prestashop/prestashop (CVE-2026-44212). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.1.1` or later.
|
| CVE-2026-44670 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-44670)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-44670). Risk of unauthorized operations or information disclosure. Exploitable via ``outerHTML``.
|
| GHSA-52cq-7v8r-62c6 |
|
Vulnerability in gmaps-mcp (GHSA-52cq-7v8r-62c6)
vulnerability in gmaps-mcp (GHSA-52cq-7v8r-62c6). Risk of unauthorized operations or information disclosure. Exploitable via `X-API-Key header`. Mitigation: upgrade to `0.1.3` or later.
|
| CVE-2026-44665 |
|
XXE (XML External Entity) in fast-xml-builder (CVE-2026-44665)
vulnerability in fast-xml-builder (CVE-2026-44665). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.7` or later.
|
| CVE-2026-44664 |
|
Vulnerability in fast-xml-builder (CVE-2026-44664)
vulnerability in fast-xml-builder (CVE-2026-44664). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.6` or later.
|
| GHSA-2cm2-m3w5-gp2f |
|
Vulnerability in vm2 (GHSA-2cm2-m3w5-gp2f)
vulnerability in vm2 (GHSA-2cm2-m3w5-gp2f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.11.2` or later.
|
| CVE-2026-44009 |
|
Vulnerability in vm2 (CVE-2026-44009)
vulnerability in vm2 (CVE-2026-44009). Risk of unauthorized operations or information disclosure. Exploitable via ``handleException``. Mitigation: upgrade to `3.11.2` or later.
|
| CVE-2026-44499 |
|
Vulnerability in zebrad (CVE-2026-44499)
vulnerability in zebrad (CVE-2026-44499). Risk of unauthorized operations or information disclosure. Exploitable via ``inv``. Mitigation: upgrade to `4.4.0` or later.
|
| CVE-2026-43967 |
|
Vulnerability in dos (CVE-2026-43967)
vulnerability in dos (CVE-2026-43967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42794 |
|
Cross-Site Scripting (XSS) in CVE-2026-42794 (CVE-2026-42794)
cross-site scripting in CVE-2026-42794 (CVE-2026-42794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42793 |
|
Vulnerability in dos (CVE-2026-42793)
vulnerability in dos (CVE-2026-42793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42353 |
|
Path Traversal in express (CVE-2026-42353)
path traversal in express (CVE-2026-42353). Confidential information can be exposed externally.
|
| CVE-2026-41886 |
|
Cross-Site Scripting (XSS) in CVE-2026-41886 (CVE-2026-41886)
cross-site scripting in CVE-2026-41886 (CVE-2026-41886). Data can be tampered with by attackers.
|
| CVE-2026-41885 |
|
Path Traversal in CVE-2026-41885 (CVE-2026-41885)
path traversal in CVE-2026-41885 (CVE-2026-41885). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41883 |
|
Vulnerability in CVE-2026-41883 (CVE-2026-41883)
vulnerability in CVE-2026-41883 (CVE-2026-41883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41693 |
|
Path Traversal in CVE-2026-41693 (CVE-2026-41693)
path traversal in CVE-2026-41693 (CVE-2026-41693). Confidential information can be exposed externally.
|
| CVE-2026-41690 |
|
Path Traversal in express (CVE-2026-41690)
path traversal in express (CVE-2026-41690). Data can be tampered with by attackers.
|
| CVE-2026-41683 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-41683)
cross-site scripting in express (CVE-2026-41683). Data can be tampered with by attackers.
|
| CVE-2026-41591 |
|
Cross-Site Scripting (XSS) in CVE-2026-41591 (CVE-2026-41591)
cross-site scripting in CVE-2026-41591 (CVE-2026-41591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41070 |
|
Authentication Bypass in openvpn (CVE-2026-41070)
authentication bypass in openvpn (CVE-2026-41070). Confidential information can be exposed externally. Exploitable via ``plugin``.
|
| CVE-2026-34354 |
|
Vulnerability in privilege-escalation (CVE-2026-34354)
vulnerability in privilege-escalation (CVE-2026-34354). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29975 |
|
Vulnerability in c (CVE-2026-29975)
vulnerability in c (CVE-2026-29975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29974 |
|
Vulnerability in CVE-2026-29974 (CVE-2026-29974)
vulnerability in CVE-2026-29974 (CVE-2026-29974). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29972 |
|
Vulnerability in c (CVE-2026-29972)
vulnerability in c (CVE-2026-29972). Risk of unauthorized operations or information disclosure.
|
| MINI-hxqr-h27v-43q5 |
|
MINI-hxqr-h27v-43q5 |
| CVE-2026-44008 |
|
Vulnerability in vm2 (CVE-2026-44008)
vulnerability in vm2 (CVE-2026-44008). Risk of unauthorized operations or information disclosure. Exploitable via ``neutralizeArraySpeciesBatch``. Mitigation: upgrade to `3.11.2` or later.
|
| MINI-r4j3-4vcp-gwcq |
|
MINI-r4j3-4vcp-gwcq |
| MINI-v3g3-qh4c-jxp7 |
|
MINI-v3g3-qh4c-jxp7 |
| MINI-33rx-2crx-cv3w |
|
MINI-33rx-2crx-cv3w |
| CVE-2026-40295 |
|
Open Redirect in devise (CVE-2026-40295)
vulnerability in devise (CVE-2026-40295). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `5.0.4` or later.
|
| CVE-2026-44500 |
|
Vulnerability in deserialization (CVE-2026-44500)
vulnerability in deserialization (CVE-2026-44500). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44498 |
|
Vulnerability in zfnd (CVE-2026-44498)
vulnerability in zfnd (CVE-2026-44498). Data can be tampered with by attackers.
|
| CVE-2026-44497 |
|
Vulnerability in zfnd (CVE-2026-44497)
vulnerability in zfnd (CVE-2026-44497). Data can be tampered with by attackers. Exploitable via ``zcashd``. Mitigation: upgrade to `4.4.0` or later.
|
| CVE-2026-43475 |
|
Vulnerability in CVE-2026-43475 (CVE-2026-43475)
vulnerability in CVE-2026-43475 (CVE-2026-43475). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43474 |
|
Vulnerability in c (CVE-2026-43474)
vulnerability in c (CVE-2026-43474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43473 |
|
Vulnerability in CVE-2026-43473 (CVE-2026-43473)
vulnerability in CVE-2026-43473 (CVE-2026-43473). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43472 |
|
Vulnerability in CVE-2026-43472 (CVE-2026-43472)
vulnerability in CVE-2026-43472 (CVE-2026-43472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43471 |
|
Vulnerability in CVE-2026-43471 (CVE-2026-43471)
vulnerability in CVE-2026-43471 (CVE-2026-43471). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43470 |
|
Vulnerability in CVE-2026-43470 (CVE-2026-43470)
vulnerability in CVE-2026-43470 (CVE-2026-43470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43469 |
|
Vulnerability in CVE-2026-43469 (CVE-2026-43469)
vulnerability in CVE-2026-43469 (CVE-2026-43469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43468 |
|
Vulnerability in CVE-2026-43468 (CVE-2026-43468)
vulnerability in CVE-2026-43468 (CVE-2026-43468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43467 |
|
Vulnerability in c (CVE-2026-43467)
vulnerability in c (CVE-2026-43467). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43466 |
|
Vulnerability in c (CVE-2026-43466)
vulnerability in c (CVE-2026-43466). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43465 |
|
Vulnerability in CVE-2026-43465 (CVE-2026-43465)
vulnerability in CVE-2026-43465 (CVE-2026-43465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43464 |
|
Vulnerability in CVE-2026-43464 (CVE-2026-43464)
vulnerability in CVE-2026-43464 (CVE-2026-43464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43463 |
|
Vulnerability in CVE-2026-43463 (CVE-2026-43463)
vulnerability in CVE-2026-43463 (CVE-2026-43463). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43462 |
|
Vulnerability in CVE-2026-43462 (CVE-2026-43462)
vulnerability in CVE-2026-43462 (CVE-2026-43462). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43461 |
|
Vulnerability in CVE-2026-43461 (CVE-2026-43461)
vulnerability in CVE-2026-43461 (CVE-2026-43461). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43460 |
|
Vulnerability in CVE-2026-43460 (CVE-2026-43460)
vulnerability in CVE-2026-43460 (CVE-2026-43460). Risk of unauthorized operations or information disclosure.
|