Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-42609 Privilege Escalation in getgrav/grav (CVE-2026-42609)
vulnerability in getgrav/grav (CVE-2026-42609). Data can be tampered with by attackers. Exploitable via ``d904efc33``. Mitigation: upgrade to `2.0.0-beta.2` or later.
CVE-2026-42608 Path Traversal in getgrav/grav (CVE-2026-42608)
path traversal in getgrav/grav (CVE-2026-42608). Confidential information can be exposed externally. Exploitable via `POST /contact`. Mitigation: upgrade to `2.0.0-beta.2` or later.
CVE-2026-42607 Code Injection in getgrav/grav (CVE-2026-42607)
code injection in getgrav/grav (CVE-2026-42607). Successful exploitation can lead to full system takeover. Exploitable via ``directInstall``. Mitigation: upgrade to `2.0.0-beta.2` or later.
CVE-2026-3320 Cross-Site Scripting (XSS) in CVE-2026-3320 (CVE-2026-3320)
cross-site scripting in CVE-2026-3320 (CVE-2026-3320). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-34091 Vulnerability in mediawiki (DEBIAN-CVE-2026-34091)
vulnerability in mediawiki (DEBIAN-CVE-2026-34091). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.43.8+dfsg-1~deb13u1` or later.
DEBIAN-CVE-2026-34092 Vulnerability in mediawiki (DEBIAN-CVE-2026-34092)
vulnerability in mediawiki (DEBIAN-CVE-2026-34092). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.39.17-1+deb12u2` or later.
DEBIAN-CVE-2026-34088 Vulnerability in mediawiki (DEBIAN-CVE-2026-34088)
vulnerability in mediawiki (DEBIAN-CVE-2026-34088). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.39.17-1+deb12u2` or later.
DEBIAN-CVE-2026-34087 Vulnerability in mediawiki (DEBIAN-CVE-2026-34087)
vulnerability in mediawiki (DEBIAN-CVE-2026-34087). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.39.17-1+deb12u2` or later.
CVE-2026-3319 Cross-Site Scripting (XSS) in CVE-2026-3319 (CVE-2026-3319)
cross-site scripting in CVE-2026-3319 (CVE-2026-3319). Risk of unauthorized operations or information disclosure.
CVE-2026-34092 Information Disclosure in CVE-2026-34092 (CVE-2026-34092)
vulnerability in CVE-2026-34092 (CVE-2026-34092). Risk of unauthorized operations or information disclosure.
CVE-2026-34091 Information Disclosure in CVE-2026-34091 (CVE-2026-34091)
vulnerability in CVE-2026-34091 (CVE-2026-34091). Risk of unauthorized operations or information disclosure.
CVE-2026-34090 Information Disclosure in CVE-2026-34090 (CVE-2026-34090)
vulnerability in CVE-2026-34090 (CVE-2026-34090). Risk of unauthorized operations or information disclosure.
CVE-2026-34089 Cross-Site Scripting (XSS) in CVE-2026-34089 (CVE-2026-34089)
cross-site scripting in CVE-2026-34089 (CVE-2026-34089). Risk of unauthorized operations or information disclosure.
CVE-2026-34088 Information Disclosure in CVE-2026-34088 (CVE-2026-34088)
vulnerability in CVE-2026-34088 (CVE-2026-34088). Risk of unauthorized operations or information disclosure.
CVE-2026-34087 Information Disclosure in CVE-2026-34087 (CVE-2026-34087)
vulnerability in CVE-2026-34087 (CVE-2026-34087). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-34086 Vulnerability in mediawiki (DEBIAN-CVE-2026-34086)
vulnerability in mediawiki (DEBIAN-CVE-2026-34086). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.43.8+dfsg-1~deb13u1` or later.
CVE-2026-34086 Vulnerability in CVE-2026-34086 (CVE-2026-34086)
vulnerability in CVE-2026-34086 (CVE-2026-34086). Risk of unauthorized operations or information disclosure.
CVE-2026-31247 Vulnerability in dos (CVE-2026-31247)
vulnerability in dos (CVE-2026-31247). Risk of unauthorized operations or information disclosure.
CVE-2026-31246 OS Command Injection in CVE-2026-31246 (CVE-2026-31246)
OS command injection in CVE-2026-31246 (CVE-2026-31246). Risk of unauthorized operations or information disclosure.
CVE-2025-65418 Path Traversal in path-traversal (CVE-2025-65418)
path traversal in path-traversal (CVE-2025-65418). Confidential information can be exposed externally.
CVE-2025-65417 Cross-Site Scripting (XSS) in CVE-2025-65417 (CVE-2025-65417)
cross-site scripting in CVE-2025-65417 (CVE-2025-65417). Risk of unauthorized operations or information disclosure.
CVE-2025-65416 Unrestricted File Upload in CVE-2025-65416 (CVE-2025-65416)
vulnerability in CVE-2025-65416 (CVE-2025-65416). Risk of unauthorized operations or information disclosure.
CVE-2025-65415 Vulnerability in CVE-2025-65415 (CVE-2025-65415)
vulnerability in CVE-2025-65415 (CVE-2025-65415). Risk of unauthorized operations or information disclosure.
CVE-2025-63750 Vulnerability in CVE-2025-63750 (CVE-2025-63750)
vulnerability in CVE-2025-63750 (CVE-2025-63750). Risk of unauthorized operations or information disclosure.
CVE-2025-61314 Cross-Site Scripting (XSS) in CVE-2025-61314 (CVE-2025-61314)
cross-site scripting in CVE-2025-61314 (CVE-2025-61314). Confidential information can be exposed externally.
CVE-2025-61313 Cross-Site Scripting (XSS) in CVE-2025-61313 (CVE-2025-61313)
cross-site scripting in CVE-2025-61313 (CVE-2025-61313). Confidential information can be exposed externally.
CVE-2025-61312 Cross-Site Scripting (XSS) in CVE-2025-61312 (CVE-2025-61312)
cross-site scripting in CVE-2025-61312 (CVE-2025-61312). Confidential information can be exposed externally.
CVE-2025-61311 Cross-Site Scripting (XSS) in CVE-2025-61311 (CVE-2025-61311)
cross-site scripting in CVE-2025-61311 (CVE-2025-61311). Confidential information can be exposed externally.
CVE-2025-61310 Cross-Site Scripting (XSS) in CVE-2025-61310 (CVE-2025-61310)
cross-site scripting in CVE-2025-61310 (CVE-2025-61310). Risk of unauthorized operations or information disclosure.
CVE-2025-61309 Cross-Site Scripting (XSS) in CVE-2025-61309 (CVE-2025-61309)
cross-site scripting in CVE-2025-61309 (CVE-2025-61309). Risk of unauthorized operations or information disclosure.
CVE-2025-61308 Cross-Site Scripting (XSS) in CVE-2025-61308 (CVE-2025-61308)
cross-site scripting in CVE-2025-61308 (CVE-2025-61308). Risk of unauthorized operations or information disclosure.
CVE-2025-61307 Cross-Site Scripting (XSS) in CVE-2025-61307 (CVE-2025-61307)
cross-site scripting in CVE-2025-61307 (CVE-2025-61307). Risk of unauthorized operations or information disclosure.
CVE-2025-61306 Cross-Site Scripting (XSS) in CVE-2025-61306 (CVE-2025-61306)
cross-site scripting in CVE-2025-61306 (CVE-2025-61306). Risk of unauthorized operations or information disclosure.
CVE-2025-61305 Cross-Site Scripting (XSS) in CVE-2025-61305 (CVE-2025-61305)
cross-site scripting in CVE-2025-61305 (CVE-2025-61305). Risk of unauthorized operations or information disclosure.
CVE-2026-40217 Vulnerability in litellm (CVE-2026-40217)
vulnerability in litellm (CVE-2026-40217). Successful exploitation can lead to full system takeover. Exploitable via `POST /guardrails/test_custom_code`. Mitigation: upgrade to `1.83.10` or later.
CVE-2026-45033 Vulnerability in @github/copilot (CVE-2026-45033)
vulnerability in @github/copilot (CVE-2026-45033). Risk of unauthorized operations or information disclosure. Exploitable via ``core.fsmonitor``. Mitigation: upgrade to `1.0.43` or later.
CVE-2026-44543 Vulnerability in github.com/rancher/local-path-provisioner (CVE-2026-44543)
vulnerability in github.com/rancher/local-path-provisioner (CVE-2026-44543). Confidential information can be exposed externally. Exploitable via ``helperPod.yaml``. Mitigation: upgrade to `0.0.36` or later.
CVE-2026-44572 Vulnerability in next (CVE-2026-44572)
vulnerability in next (CVE-2026-44572). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `16.2.5` or later.
CVE-2026-44521 SQL Injection in studio-42/elfinder (CVE-2026-44521)
SQL injection in studio-42/elfinder (CVE-2026-44521). Successful exploitation can lead to full system takeover. Exploitable via ``elFinderVolumeMySQL``. Mitigation: upgrade to `2.1.68` or later.
CVE-2026-44516 Vulnerability in com.ritense.valtimo:web (CVE-2026-44516)
vulnerability in com.ritense.valtimo:web (CVE-2026-44516). Confidential information can be exposed externally. Exploitable via ``LoggingRestClientCustomizer``. Mitigation: upgrade to `13.26.0` or later.
GHSA-mhwj-73qx-jqxm Vulnerability in @theecryptochad/merge-guard (GHSA-mhwj-73qx-jqxm)
vulnerability in @theecryptochad/merge-guard (GHSA-mhwj-73qx-jqxm). Data can be tampered with by attackers. Exploitable via ``__proto__``. Mitigation: upgrade to `1.0.1` or later.
CVE-2026-44483 Vulnerability in @rvf/set-get (CVE-2026-44483)
vulnerability in @rvf/set-get (CVE-2026-44483). Data can be tampered with by attackers. Exploitable via ``setPath``. Mitigation: upgrade to `6.0.4` or later.
MAL-2026-3427 Vulnerability in @cplace-workflow-fe/cf-workflow (MAL-2026-3427)
vulnerability in @cplace-workflow-fe/cf-workflow (MAL-2026-3427). Risk of unauthorized operations or information disclosure.
CVE-2026-44477 Vulnerability in github.com/cloudnative-pg/cloudnative-pg (CVE-2026-44477)
vulnerability in github.com/cloudnative-pg/cloudnative-pg (CVE-2026-44477). Risk of unauthorized operations or information disclosure. Exploitable via ``postgres``. Mitigation: upgrade to `1.29.1` or later.
CVE-2026-44581 Cross-Site Scripting (XSS) in next (CVE-2026-44581)
cross-site scripting in next (CVE-2026-44581). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.5` or later.
CVE-2026-44582 Vulnerability in next (CVE-2026-44582)
vulnerability in next (CVE-2026-44582). Risk of unauthorized operations or information disclosure. Exploitable via ``_rsc``. Mitigation: upgrade to `16.2.5` or later.
CVE-2026-44580 Cross-Site Scripting (XSS) in next (CVE-2026-44580)
cross-site scripting in next (CVE-2026-44580). Risk of unauthorized operations or information disclosure. Exploitable via ``beforeInteractive``. Mitigation: upgrade to `16.2.5` or later.
CVE-2026-44579 Vulnerability in next (CVE-2026-44579)
vulnerability in next (CVE-2026-44579). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.5` or later.
CVE-2026-44577 Vulnerability in next (CVE-2026-44577)
vulnerability in next (CVE-2026-44577). Risk of unauthorized operations or information disclosure. Exploitable via ``images.localPatterns``. Mitigation: upgrade to `16.2.5` or later.
CVE-2026-44578 SSRF (Server-Side Request Forgery) in next (CVE-2026-44578)
SSRF in next (CVE-2026-44578). Confidential information can be exposed externally. Mitigation: upgrade to `16.2.5` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →