Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
ROOT-APP-NPM-CVE-2020-15084 Vulnerability in @rootio/express-jwt (ROOT-APP-NPM-CVE-2020-15084)
vulnerability in @rootio/express-jwt (ROOT-APP-NPM-CVE-2020-15084). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.1.3-root.io.1, 0.1.3-root.io.2` or later.
ROOT-APP-NPM-CVE-2022-41940 Vulnerability in @rootio/engine.io (ROOT-APP-NPM-CVE-2022-41940)
vulnerability in @rootio/engine.io (ROOT-APP-NPM-CVE-2022-41940). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.2-root.io.1, 4.1.2-root.io.2` or later.
ROOT-APP-NPM-CVE-2023-46233 Vulnerability in @rootio/crypto-js (ROOT-APP-NPM-CVE-2023-46233)
vulnerability in @rootio/crypto-js (ROOT-APP-NPM-CVE-2023-46233). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0-root.io.1, 3.3.0-root.io.2` or later.
ROOT-APP-NPM-CVE-2025-13204 Vulnerability in @rootio/expr-eval (ROOT-APP-NPM-CVE-2025-13204)
vulnerability in @rootio/expr-eval (ROOT-APP-NPM-CVE-2025-13204). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.2-root.io.2, 2.0.2-root.io.3` or later.
ROOT-APP-NPM-CVE-2024-29041 Vulnerability in @rootio/express (ROOT-APP-NPM-CVE-2024-29041)
vulnerability in @rootio/express (ROOT-APP-NPM-CVE-2024-29041). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.18.2-root.io.2, 4.18.2-root.io.3` or later.
ROOT-APP-NPM-CVE-2025-12735 Vulnerability in @rootio/expr-eval (ROOT-APP-NPM-CVE-2025-12735)
vulnerability in @rootio/expr-eval (ROOT-APP-NPM-CVE-2025-12735). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.2-root.io.1, 2.0.2-root.io.2, 2.0.2-root.io.3` or later.
ROOT-APP-NPM-CVE-2024-43796 Vulnerability in @rootio/express (ROOT-APP-NPM-CVE-2024-43796)
vulnerability in @rootio/express (ROOT-APP-NPM-CVE-2024-43796). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.18.2-root.io.1, 4.18.2-root.io.2, 4.18.2-root.io.3` or later.
GHSA-jpvj-wpmj-h7rv Vulnerability in @cap-js/openapi (GHSA-jpvj-wpmj-h7rv)
vulnerability in @cap-js/openapi (GHSA-jpvj-wpmj-h7rv). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.4.2` or later.
CVE-2026-48013 SSRF (Server-Side Request Forgery) in shopware/core (CVE-2026-48013)
SSRF in shopware/core (CVE-2026-48013). Risk of unauthorized operations or information disclosure. Exploitable via ``uploadFromURL``. Mitigation: upgrade to `6.7.10.1` or later.
ROOT-APP-NPM-CVE-2022-38900 Vulnerability in @rootio/decode-uri-component (ROOT-APP-NPM-CVE-2022-38900)
vulnerability in @rootio/decode-uri-component (ROOT-APP-NPM-CVE-2022-38900). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.0-root.io.1, 0.2.0-root.io.2` or later.
CVE-2026-48015 Cross-Site Scripting (XSS) in shopware/core (CVE-2026-48015)
cross-site scripting in shopware/core (CVE-2026-48015). Confidential information can be exposed externally. Exploitable via ``allowed_extensions``. Mitigation: upgrade to `6.6.10.18` or later.
CVE-2026-48016 Vulnerability in shopware/platform (CVE-2026-48016)
vulnerability in shopware/platform (CVE-2026-48016). Risk of unauthorized operations or information disclosure. Exploitable via ``orderId``. Mitigation: upgrade to `6.6.10.18` or later.
CVE-2026-48014 Vulnerability in shopware/platform (CVE-2026-48014)
vulnerability in shopware/platform (CVE-2026-48014). Data can be tampered with by attackers. Exploitable via ``orderId``. Mitigation: upgrade to `6.6.10.18` or later.
CVE-2026-48012 Open Redirect in shopware/core (CVE-2026-48012)
vulnerability in shopware/core (CVE-2026-48012). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/oauth/sso/auth`. Mitigation: upgrade to `6.7.10.1` or later.
CVE-2026-48011 Vulnerability in shopware/platform (CVE-2026-48011)
vulnerability in shopware/platform (CVE-2026-48011). Risk of unauthorized operations or information disclosure. Exploitable via ``password_verify``. Mitigation: upgrade to `6.6.10.18` or later.
CVE-2026-48010 Privilege Escalation in shopware/platform (CVE-2026-48010)
vulnerability in shopware/platform (CVE-2026-48010). Confidential information can be exposed externally. Exploitable via ``SYSTEM_SCOPE``. Mitigation: upgrade to `6.6.10.18` or later.
CVE-2026-48009 Information Disclosure in shopware/platform (CVE-2026-48009)
vulnerability in shopware/platform (CVE-2026-48009). Confidential information can be exposed externally. Exploitable via `POST /api/search/user-recovery`. Mitigation: upgrade to `6.6.10.18` or later.
CVE-2026-48008 Vulnerability in shopware/platform (CVE-2026-48008)
vulnerability in shopware/platform (CVE-2026-48008). Confidential information can be exposed externally. Exploitable via `POST /api/_action/sync`. Mitigation: upgrade to `6.6.10.18` or later.
CVE-2026-48480 Vulnerability in io.netty.incubator:netty-incubator-codec-ohttp (CVE-2026-48480)
vulnerability in io.netty.incubator:netty-incubator-codec-ohttp (CVE-2026-48480). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.22.Final` or later.
DEBIAN-CVE-2026-36499 Vulnerability in openvswitch (DEBIAN-CVE-2026-36499)
vulnerability in openvswitch (DEBIAN-CVE-2026-36499). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-40898 Vulnerability in golang-github-lucas-clemente-quic-go (DEBIAN-CVE-2026-40898)
vulnerability in golang-github-lucas-clemente-quic-go (DEBIAN-CVE-2026-40898). Risk of unauthorized operations or information disclosure. Exploitable via ``http.Header``.
CVE-2026-36499 Vulnerability in dos (CVE-2026-36499)
vulnerability in dos (CVE-2026-36499). Risk of unauthorized operations or information disclosure.
CVE-2025-71316 Vulnerability in c (CVE-2025-71316)
vulnerability in c (CVE-2025-71316). Successful exploitation can lead to full system takeover.
CVE-2025-65640 Cross-Site Scripting (XSS) in CVE-2025-65640 (CVE-2025-65640)
cross-site scripting in CVE-2025-65640 (CVE-2025-65640). Confidential information can be exposed externally.
CVE-2026-54458 Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-54458)
cross-site scripting in WWBN/AVideo (CVE-2026-54458). Confidential information can be exposed externally. Exploitable via ``page_title``.
CVE-2026-50183 Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-50183)
cross-site scripting in WWBN/AVideo (CVE-2026-50183). Risk of unauthorized operations or information disclosure. Exploitable via ``snippet.title``.
CVE-2026-50182 Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-50182)
cross-site scripting in WWBN/AVideo (CVE-2026-50182). Risk of unauthorized operations or information disclosure. Exploitable via ``href``.
GHSA-x96m-c5fj-q75c Vulnerability in supabase (GHSA-x96m-c5fj-q75c)
vulnerability in supabase (GHSA-x96m-c5fj-q75c). Risk of unauthorized operations or information disclosure.
CVE-2026-49279 Cross-Site Scripting (XSS) in wwbn/avideo (CVE-2026-49279)
cross-site scripting in wwbn/avideo (CVE-2026-49279). Risk of unauthorized operations or information disclosure. Exploitable via ``autoEvalCodeOnHTML``.
GHSA-cw9v-v9rh-r449 Vulnerability in autotel-terminal (GHSA-cw9v-v9rh-r449)
vulnerability in autotel-terminal (GHSA-cw9v-v9rh-r449). Risk of unauthorized operations or information disclosure. Exploitable via ``binding.gyp``.
GHSA-6w7v-23mf-65g3 Vulnerability in @jagreehal/workflow (GHSA-6w7v-23mf-65g3)
vulnerability in @jagreehal/workflow (GHSA-6w7v-23mf-65g3). Risk of unauthorized operations or information disclosure. Exploitable via ``binding.gyp``.
MINI-xq85-vp7q-6g6c MINI-xq85-vp7q-6g6c
MINI-rwc8-jr42-hw72 MINI-rwc8-jr42-hw72
MINI-vh9g-hhcw-4948 MINI-vh9g-hhcw-4948
MINI-vcf6-gm2f-r2c4 MINI-vcf6-gm2f-r2c4
MINI-ffg4-4jq9-j6wm MINI-ffg4-4jq9-j6wm
MINI-m7pg-7xmx-3gc3 MINI-m7pg-7xmx-3gc3
MINI-h8qw-xgjh-hg6f MINI-h8qw-xgjh-hg6f
MINI-h5jx-jx9q-fr59 MINI-h5jx-jx9q-fr59
MINI-gw7q-mrgx-p5w4 MINI-gw7q-mrgx-p5w4
MINI-f33q-4m75-m8p4 MINI-f33q-4m75-m8p4
MINI-c2jc-xj93-m52q MINI-c2jc-xj93-m52q
MINI-x6gr-fcrh-pvvv MINI-x6gr-fcrh-pvvv
MINI-hq99-rx7j-cf8c MINI-hq99-rx7j-cf8c
MINI-mrh8-h673-w4w3 MINI-mrh8-h673-w4w3
MINI-j8hq-88x5-6x2g MINI-j8hq-88x5-6x2g
MINI-hxh6-jqwc-6wpf MINI-hxh6-jqwc-6wpf
MINI-h4rw-wp2q-wvxc MINI-h4rw-wp2q-wvxc
MINI-hgq5-m5wx-pcxm MINI-hgq5-m5wx-pcxm
MINI-gwj4-cpg8-87vm MINI-gwj4-cpg8-87vm

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →