Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-2ghv-fxh9-88hh |
|
MINI-2ghv-fxh9-88hh |
| MINI-3hr5-gg2q-83r2 |
|
MINI-3hr5-gg2q-83r2 |
| MINI-258g-8jww-vh9r |
|
MINI-258g-8jww-vh9r |
| MINI-2crj-xfx4-pmq6 |
|
MINI-2crj-xfx4-pmq6 |
| MINI-2cw2-54rw-9274 |
|
MINI-2cw2-54rw-9274 |
| MINI-vwcp-qw56-3cwm |
|
MINI-vwcp-qw56-3cwm |
| CVE-2026-54533 |
|
Vulnerability in vantage6 (CVE-2026-54533)
vulnerability in vantage6 (CVE-2026-54533). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.0` or later.
|
| CVE-2026-54445 |
|
Vulnerability in vantage6 (CVE-2026-54445)
vulnerability in vantage6 (CVE-2026-54445). Risk of unauthorized operations or information disclosure. Exploitable via ``root``. Mitigation: upgrade to `5.0.0` or later.
|
| CVE-2026-53926 |
|
Vulnerability in nocodb (CVE-2026-53926)
vulnerability in nocodb (CVE-2026-53926). Risk of unauthorized operations or information disclosure. Exploitable via ``revokeAllOAuthTokensByUser``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-52878 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-52878)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52878). Risk of unauthorized operations or information disclosure. Exploitable via `POST /transaction/send`. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2026-52880 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-52880)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52880). Risk of unauthorized operations or information disclosure. Exploitable via ``Engine.Run``. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2026-52879 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-52879)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52879). Risk of unauthorized operations or information disclosure. Exploitable via ``networkMessenger.directMessageHandler``. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2026-49343 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-49343)
vulnerability in github.com/klever-io/klever-go (CVE-2026-49343). Risk of unauthorized operations or information disclosure. Exploitable via ``NumGoRoutinesThrottler``. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2026-48017 |
|
Code Injection in dbgate-api (CVE-2026-48017)
code injection in dbgate-api (CVE-2026-48017). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/load-reader`. Mitigation: upgrade to `7.1.9` or later.
|
| ROOT-APP-NPM-CVE-2021-3795 |
|
Vulnerability in @rootio/semver-regex (ROOT-APP-NPM-CVE-2021-3795)
vulnerability in @rootio/semver-regex (ROOT-APP-NPM-CVE-2021-3795). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0-root.io.1` or later.
|
| ROOT-APP-NPM-CVE-2021-43307 |
|
Vulnerability in @rootio/semver-regex (ROOT-APP-NPM-CVE-2021-43307)
vulnerability in @rootio/semver-regex (ROOT-APP-NPM-CVE-2021-43307). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0-root.io.1` or later.
|
| ROOT-APP-NPM-CVE-2025-13466 |
|
Vulnerability in @rootio/body-parser (ROOT-APP-NPM-CVE-2025-13466)
vulnerability in @rootio/body-parser (ROOT-APP-NPM-CVE-2025-13466). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.2.0-root.io.1` or later.
|
| ROOT-APP-NPM-CVE-2021-23337 |
|
Vulnerability in @rootio/lodash.template (ROOT-APP-NPM-CVE-2021-23337)
vulnerability in @rootio/lodash.template (ROOT-APP-NPM-CVE-2021-23337). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.0-root.io.1, 4.5.0-root.io.2, 4.5.0-root.io.3, 4.5.0-root.io.4` or later.
|
| CVE-2026-47684 |
|
SSRF (Server-Side Request Forgery) in @sync-in/server (CVE-2026-47684)
SSRF in @sync-in/server (CVE-2026-47684). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-47680 |
|
Vulnerability in github.com/fluxcd/source-controller (CVE-2026-47680)
vulnerability in github.com/fluxcd/source-controller (CVE-2026-47680). Risk of unauthorized operations or information disclosure. Exploitable via ``Bucket``. Mitigation: upgrade to `1.8.5` or later.
|
| ROOT-APP-NPM-CVE-2026-2739 |
|
Vulnerability in @rootio/bn.js (ROOT-APP-NPM-CVE-2026-2739)
vulnerability in @rootio/bn.js (ROOT-APP-NPM-CVE-2026-2739). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.2-root.io.1, 4.11.9-root.io.1, 4.12.2-root.io.2, 4.11.9-root.io.2, 4.12.1-root.io.1, 5.2.1-root.io.1` or later.
|
| CVE-2026-47670 |
|
Command Injection in dbgate-api (CVE-2026-47670)
command injection in dbgate-api (CVE-2026-47670). Risk of unauthorized operations or information disclosure. Exploitable via ``functionName``. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47419 |
|
Vulnerability in praisonai-platform (CVE-2026-47419)
vulnerability in praisonai-platform (CVE-2026-47419). Confidential information can be exposed externally. Exploitable via `DELETE /workspaces/{workspace_id}/agents/{agent_id}`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47669 |
|
Path Traversal in dbgate (CVE-2026-47669)
path traversal in dbgate (CVE-2026-47669). Risk of unauthorized operations or information disclosure. Exploitable via `POST /auth/login`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47668 |
|
Vulnerability in dbgate-serve (CVE-2026-47668)
vulnerability in dbgate-serve (CVE-2026-47668). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/start`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47388 |
|
Vulnerability in nocodb (CVE-2026-47388)
vulnerability in nocodb (CVE-2026-47388). Risk of unauthorized operations or information disclosure. Exploitable via ``readAttachment``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47387 |
|
Cross-Site Scripting (XSS) in nocodb (CVE-2026-47387)
cross-site scripting in nocodb (CVE-2026-47387). Risk of unauthorized operations or information disclosure. Exploitable via ``redirect_url``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47386 |
|
Vulnerability in nocodb (CVE-2026-47386)
vulnerability in nocodb (CVE-2026-47386). Risk of unauthorized operations or information disclosure. Exploitable via ``is_used``. Mitigation: upgrade to `2026.05.1` or later.
|
| CGA-64rf-cq24-c88r |
|
CGA-64rf-cq24-c88r |
| CGA-47hv-vg4j-v3h9 |
|
CGA-47hv-vg4j-v3h9 |
| CGA-ww3c-xmh5-8c3p |
|
CGA-ww3c-xmh5-8c3p |
| CGA-3q8f-7g2w-5cjg |
|
CGA-3q8f-7g2w-5cjg |
| CGA-rmx5-mw5x-8m6w |
|
CGA-rmx5-mw5x-8m6w |
| CGA-gvv2-g9rg-w789 |
|
CGA-gvv2-g9rg-w789 |
| CGA-9689-x7j6-fpx6 |
|
CGA-9689-x7j6-fpx6 |
| CGA-wxp3-7xfv-4g68 |
|
CGA-wxp3-7xfv-4g68 |
| CGA-m6h3-357j-cf5c |
|
CGA-m6h3-357j-cf5c |
| CGA-c96c-c777-w5h2 |
|
CGA-c96c-c777-w5h2 |
| CGA-hcxf-7723-8928 |
|
CGA-hcxf-7723-8928 |
| CGA-cfxr-rh93-mwhj |
|
CGA-cfxr-rh93-mwhj |
| CGA-w3rv-jjfh-q7pf |
|
CGA-w3rv-jjfh-q7pf |
| CGA-c9r2-frx5-c2h8 |
|
CGA-c9r2-frx5-c2h8 |
| CGA-5gcf-pvpf-v5h8 |
|
CGA-5gcf-pvpf-v5h8 |
| CGA-3h8g-75wg-w4jv |
|
CGA-3h8g-75wg-w4jv |
| CGA-wqm5-2f4p-c5cx |
|
CGA-wqm5-2f4p-c5cx |
| CGA-qh4r-q3f3-5gh6 |
|
CGA-qh4r-q3f3-5gh6 |
| CGA-4f92-3x5p-jccw |
|
CGA-4f92-3x5p-jccw |
| CGA-q3gj-xq36-whxx |
|
CGA-q3gj-xq36-whxx |
| CGA-3v85-x865-6c22 |
|
CGA-3v85-x865-6c22 |
| CGA-6qjx-38pv-vp5w |
|
CGA-6qjx-38pv-vp5w |