Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42609 |
|
Privilege Escalation in getgrav/grav (CVE-2026-42609)
vulnerability in getgrav/grav (CVE-2026-42609). Data can be tampered with by attackers. Exploitable via ``d904efc33``. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-42608 |
|
Path Traversal in getgrav/grav (CVE-2026-42608)
path traversal in getgrav/grav (CVE-2026-42608). Confidential information can be exposed externally. Exploitable via `POST /contact`. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-42607 |
|
Code Injection in getgrav/grav (CVE-2026-42607)
code injection in getgrav/grav (CVE-2026-42607). Successful exploitation can lead to full system takeover. Exploitable via ``directInstall``. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-3320 |
|
Cross-Site Scripting (XSS) in CVE-2026-3320 (CVE-2026-3320)
cross-site scripting in CVE-2026-3320 (CVE-2026-3320). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-34091 |
|
Vulnerability in mediawiki (DEBIAN-CVE-2026-34091)
vulnerability in mediawiki (DEBIAN-CVE-2026-34091). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.43.8+dfsg-1~deb13u1` or later.
|
| DEBIAN-CVE-2026-34092 |
|
Vulnerability in mediawiki (DEBIAN-CVE-2026-34092)
vulnerability in mediawiki (DEBIAN-CVE-2026-34092). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.39.17-1+deb12u2` or later.
|
| DEBIAN-CVE-2026-34088 |
|
Vulnerability in mediawiki (DEBIAN-CVE-2026-34088)
vulnerability in mediawiki (DEBIAN-CVE-2026-34088). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.39.17-1+deb12u2` or later.
|
| DEBIAN-CVE-2026-34087 |
|
Vulnerability in mediawiki (DEBIAN-CVE-2026-34087)
vulnerability in mediawiki (DEBIAN-CVE-2026-34087). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.39.17-1+deb12u2` or later.
|
| CVE-2026-3319 |
|
Cross-Site Scripting (XSS) in CVE-2026-3319 (CVE-2026-3319)
cross-site scripting in CVE-2026-3319 (CVE-2026-3319). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34092 |
|
Information Disclosure in CVE-2026-34092 (CVE-2026-34092)
vulnerability in CVE-2026-34092 (CVE-2026-34092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34091 |
|
Information Disclosure in CVE-2026-34091 (CVE-2026-34091)
vulnerability in CVE-2026-34091 (CVE-2026-34091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34090 |
|
Information Disclosure in CVE-2026-34090 (CVE-2026-34090)
vulnerability in CVE-2026-34090 (CVE-2026-34090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34089 |
|
Cross-Site Scripting (XSS) in CVE-2026-34089 (CVE-2026-34089)
cross-site scripting in CVE-2026-34089 (CVE-2026-34089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34088 |
|
Information Disclosure in CVE-2026-34088 (CVE-2026-34088)
vulnerability in CVE-2026-34088 (CVE-2026-34088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34087 |
|
Information Disclosure in CVE-2026-34087 (CVE-2026-34087)
vulnerability in CVE-2026-34087 (CVE-2026-34087). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-34086 |
|
Vulnerability in mediawiki (DEBIAN-CVE-2026-34086)
vulnerability in mediawiki (DEBIAN-CVE-2026-34086). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.43.8+dfsg-1~deb13u1` or later.
|
| CVE-2026-34086 |
|
Vulnerability in CVE-2026-34086 (CVE-2026-34086)
vulnerability in CVE-2026-34086 (CVE-2026-34086). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31247 |
|
Vulnerability in dos (CVE-2026-31247)
vulnerability in dos (CVE-2026-31247). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31246 |
|
OS Command Injection in CVE-2026-31246 (CVE-2026-31246)
OS command injection in CVE-2026-31246 (CVE-2026-31246). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65418 |
|
Path Traversal in path-traversal (CVE-2025-65418)
path traversal in path-traversal (CVE-2025-65418). Confidential information can be exposed externally.
|
| CVE-2025-65417 |
|
Cross-Site Scripting (XSS) in CVE-2025-65417 (CVE-2025-65417)
cross-site scripting in CVE-2025-65417 (CVE-2025-65417). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65416 |
|
Unrestricted File Upload in CVE-2025-65416 (CVE-2025-65416)
vulnerability in CVE-2025-65416 (CVE-2025-65416). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-65415 |
|
Vulnerability in CVE-2025-65415 (CVE-2025-65415)
vulnerability in CVE-2025-65415 (CVE-2025-65415). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-63750 |
|
Vulnerability in CVE-2025-63750 (CVE-2025-63750)
vulnerability in CVE-2025-63750 (CVE-2025-63750). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61314 |
|
Cross-Site Scripting (XSS) in CVE-2025-61314 (CVE-2025-61314)
cross-site scripting in CVE-2025-61314 (CVE-2025-61314). Confidential information can be exposed externally.
|
| CVE-2025-61313 |
|
Cross-Site Scripting (XSS) in CVE-2025-61313 (CVE-2025-61313)
cross-site scripting in CVE-2025-61313 (CVE-2025-61313). Confidential information can be exposed externally.
|
| CVE-2025-61312 |
|
Cross-Site Scripting (XSS) in CVE-2025-61312 (CVE-2025-61312)
cross-site scripting in CVE-2025-61312 (CVE-2025-61312). Confidential information can be exposed externally.
|
| CVE-2025-61311 |
|
Cross-Site Scripting (XSS) in CVE-2025-61311 (CVE-2025-61311)
cross-site scripting in CVE-2025-61311 (CVE-2025-61311). Confidential information can be exposed externally.
|
| CVE-2025-61310 |
|
Cross-Site Scripting (XSS) in CVE-2025-61310 (CVE-2025-61310)
cross-site scripting in CVE-2025-61310 (CVE-2025-61310). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61309 |
|
Cross-Site Scripting (XSS) in CVE-2025-61309 (CVE-2025-61309)
cross-site scripting in CVE-2025-61309 (CVE-2025-61309). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61308 |
|
Cross-Site Scripting (XSS) in CVE-2025-61308 (CVE-2025-61308)
cross-site scripting in CVE-2025-61308 (CVE-2025-61308). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61307 |
|
Cross-Site Scripting (XSS) in CVE-2025-61307 (CVE-2025-61307)
cross-site scripting in CVE-2025-61307 (CVE-2025-61307). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61306 |
|
Cross-Site Scripting (XSS) in CVE-2025-61306 (CVE-2025-61306)
cross-site scripting in CVE-2025-61306 (CVE-2025-61306). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61305 |
|
Cross-Site Scripting (XSS) in CVE-2025-61305 (CVE-2025-61305)
cross-site scripting in CVE-2025-61305 (CVE-2025-61305). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40217 |
|
Vulnerability in litellm (CVE-2026-40217)
vulnerability in litellm (CVE-2026-40217). Successful exploitation can lead to full system takeover. Exploitable via `POST /guardrails/test_custom_code`. Mitigation: upgrade to `1.83.10` or later.
|
| CVE-2026-45033 |
|
Vulnerability in @github/copilot (CVE-2026-45033)
vulnerability in @github/copilot (CVE-2026-45033). Risk of unauthorized operations or information disclosure. Exploitable via ``core.fsmonitor``. Mitigation: upgrade to `1.0.43` or later.
|
| CVE-2026-44543 |
|
Vulnerability in github.com/rancher/local-path-provisioner (CVE-2026-44543)
vulnerability in github.com/rancher/local-path-provisioner (CVE-2026-44543). Confidential information can be exposed externally. Exploitable via ``helperPod.yaml``. Mitigation: upgrade to `0.0.36` or later.
|
| CVE-2026-44572 |
|
Vulnerability in next (CVE-2026-44572)
vulnerability in next (CVE-2026-44572). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `16.2.5` or later.
|
| CVE-2026-44521 |
|
SQL Injection in studio-42/elfinder (CVE-2026-44521)
SQL injection in studio-42/elfinder (CVE-2026-44521). Successful exploitation can lead to full system takeover. Exploitable via ``elFinderVolumeMySQL``. Mitigation: upgrade to `2.1.68` or later.
|
| CVE-2026-44516 |
|
Vulnerability in com.ritense.valtimo:web (CVE-2026-44516)
vulnerability in com.ritense.valtimo:web (CVE-2026-44516). Confidential information can be exposed externally. Exploitable via ``LoggingRestClientCustomizer``. Mitigation: upgrade to `13.26.0` or later.
|
| GHSA-mhwj-73qx-jqxm |
|
Vulnerability in @theecryptochad/merge-guard (GHSA-mhwj-73qx-jqxm)
vulnerability in @theecryptochad/merge-guard (GHSA-mhwj-73qx-jqxm). Data can be tampered with by attackers. Exploitable via ``__proto__``. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-44483 |
|
Vulnerability in @rvf/set-get (CVE-2026-44483)
vulnerability in @rvf/set-get (CVE-2026-44483). Data can be tampered with by attackers. Exploitable via ``setPath``. Mitigation: upgrade to `6.0.4` or later.
|
| MAL-2026-3427 |
|
Vulnerability in @cplace-workflow-fe/cf-workflow (MAL-2026-3427)
vulnerability in @cplace-workflow-fe/cf-workflow (MAL-2026-3427). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44477 |
|
Vulnerability in github.com/cloudnative-pg/cloudnative-pg (CVE-2026-44477)
vulnerability in github.com/cloudnative-pg/cloudnative-pg (CVE-2026-44477). Risk of unauthorized operations or information disclosure. Exploitable via ``postgres``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-44581 |
|
Cross-Site Scripting (XSS) in next (CVE-2026-44581)
cross-site scripting in next (CVE-2026-44581). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.5` or later.
|
| CVE-2026-44582 |
|
Vulnerability in next (CVE-2026-44582)
vulnerability in next (CVE-2026-44582). Risk of unauthorized operations or information disclosure. Exploitable via ``_rsc``. Mitigation: upgrade to `16.2.5` or later.
|
| CVE-2026-44580 |
|
Cross-Site Scripting (XSS) in next (CVE-2026-44580)
cross-site scripting in next (CVE-2026-44580). Risk of unauthorized operations or information disclosure. Exploitable via ``beforeInteractive``. Mitigation: upgrade to `16.2.5` or later.
|
| CVE-2026-44579 |
|
Vulnerability in next (CVE-2026-44579)
vulnerability in next (CVE-2026-44579). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.5` or later.
|
| CVE-2026-44577 |
|
Vulnerability in next (CVE-2026-44577)
vulnerability in next (CVE-2026-44577). Risk of unauthorized operations or information disclosure. Exploitable via ``images.localPatterns``. Mitigation: upgrade to `16.2.5` or later.
|
| CVE-2026-44578 |
|
SSRF (Server-Side Request Forgery) in next (CVE-2026-44578)
SSRF in next (CVE-2026-44578). Confidential information can be exposed externally. Mitigation: upgrade to `16.2.5` or later.
|