Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| DEBIAN-CVE-2025-71313 |
|
Vulnerability in linux (DEBIAN-CVE-2025-71313)
vulnerability in linux (DEBIAN-CVE-2025-71313). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.19.6-1` or later.
|
| SUSE-SU-2026:2265-1 |
|
Vulnerability in SUSE-SU-2026:2265-1 (SUSE-SU-2026:2265-1)
vulnerability in SUSE-SU-2026:2265-1 (SUSE-SU-2026:2265-1). Risk of unauthorized operations or information disclosure.
|
| openSUSE-SU-2026:20902-1 |
|
Vulnerability in openSUSE-SU-2026:20902-1 (openSUSE-SU-2026:20902-1)
vulnerability in openSUSE-SU-2026:20902-1 (openSUSE-SU-2026:20902-1). Risk of unauthorized operations or information disclosure.
|
| USN-8382-1 |
|
Vulnerability in exim4 (USN-8382-1)
vulnerability in exim4 (USN-8382-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.82-3ubuntu2.4+esm9` or later.
|
| GHSA-q398-93fh-ghmj |
|
Vulnerability in nodemon-webpatch (GHSA-q398-93fh-ghmj)
vulnerability in nodemon-webpatch (GHSA-q398-93fh-ghmj). Risk of unauthorized operations or information disclosure.
|
| GHSA-qq87-jvv3-6c7r |
|
Vulnerability in chai-midpatch (GHSA-qq87-jvv3-6c7r)
vulnerability in chai-midpatch (GHSA-qq87-jvv3-6c7r). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20175 |
|
Vulnerability in cisco (CVE-2026-20175)
vulnerability in cisco (CVE-2026-20175). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20230 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Cisco ssrf (CVE-2026-20230)
SSRF in Cisco ssrf (CVE-2026-20230). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
|
| CVE-2026-20233 |
|
Cross-Site Scripting (XSS) in Cisco webex-meetings (CVE-2026-20233)
cross-site scripting in Cisco webex-meetings (CVE-2026-20233). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5181 |
|
Vulnerability in tronlabpy3 (MAL-2026-5181)
vulnerability in tronlabpy3 (MAL-2026-5181). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-6657 |
|
Vulnerability in jupyter-server (DEBIAN-CVE-2026-6657)
vulnerability in jupyter-server (DEBIAN-CVE-2026-6657). Risk of unauthorized operations or information disclosure. Exploitable via ``allow_origin_pat``.
|
| CVE-2026-6657 |
|
Vulnerability in jupyter-server (CVE-2026-6657)
vulnerability in jupyter-server (CVE-2026-6657). Successful exploitation can lead to full system takeover. Exploitable via ``allow_origin_pat``.
|
| CVE-2026-44281 |
|
Vulnerability in CVE-2026-44281 (CVE-2026-44281)
vulnerability in CVE-2026-44281 (CVE-2026-44281). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42321 |
|
Cross-Site Scripting (XSS) in CVE-2026-42321 (CVE-2026-42321)
cross-site scripting in CVE-2026-42321 (CVE-2026-42321). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-37462 |
|
Vulnerability in gobgp (DEBIAN-CVE-2026-37462)
vulnerability in gobgp (DEBIAN-CVE-2026-37462). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.4.0-1` or later.
|
| DEBIAN-CVE-2026-3276 |
|
Vulnerability in pypy3 (DEBIAN-CVE-2026-3276)
vulnerability in pypy3 (DEBIAN-CVE-2026-3276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42320 |
|
Vulnerability in CVE-2026-42320 (CVE-2026-42320)
vulnerability in CVE-2026-42320 (CVE-2026-42320). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42318 |
|
Vulnerability in CVE-2026-42318 (CVE-2026-42318)
vulnerability in CVE-2026-42318 (CVE-2026-42318). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42317 |
|
Vulnerability in CVE-2026-42317 (CVE-2026-42317)
vulnerability in CVE-2026-42317 (CVE-2026-42317). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3276 |
|
Vulnerability in libpython (CVE-2026-3276)
vulnerability in libpython (CVE-2026-3276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37462 |
|
Vulnerability in github.com/osrg/gobgp/v4 (CVE-2026-37462)
vulnerability in github.com/osrg/gobgp/v4 (CVE-2026-37462). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.4.0` or later.
|
| CVE-2026-36748 |
|
Cross-Site Scripting (XSS) in CVE-2026-36748 (CVE-2026-36748)
cross-site scripting in CVE-2026-36748 (CVE-2026-36748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36576 |
|
OS Command Injection in CVE-2026-36576 (CVE-2026-36576)
OS command injection in CVE-2026-36576 (CVE-2026-36576). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36574 |
|
Vulnerability in CVE-2026-36574 (CVE-2026-36574)
vulnerability in CVE-2026-36574 (CVE-2026-36574). Successful exploitation can lead to full system takeover.
|
| CVE-2022-31114 |
|
Cross-Site Scripting (XSS) in backpack/crud (CVE-2022-31114)
cross-site scripting in backpack/crud (CVE-2022-31114). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.0.63` or later.
|
| CVE-2026-10770 |
|
Cross-Site Scripting (XSS) in drupal/cleantalk (CVE-2026-10770)
cross-site scripting in drupal/cleantalk (CVE-2026-10770). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-10769 |
|
Cross-Site Scripting (XSS) in drupal/commerce (CVE-2026-10769)
cross-site scripting in drupal/commerce (CVE-2026-10769). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.6` or later.
|
| DRUPAL-CONTRIB-2026-040 |
|
Vulnerability in drupal/tacjs (DRUPAL-CONTRIB-2026-040)
vulnerability in drupal/tacjs (DRUPAL-CONTRIB-2026-040). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.8.0` or later.
|
| CVE-2026-10768 |
|
Vulnerability in drupal/localgov_workflows (CVE-2026-10768)
vulnerability in drupal/localgov_workflows (CVE-2026-10768). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.6.0` or later.
|
| SUSE-SU-2026:2261-1 |
|
Security update for python-pyOpenSSL
Security update for python-pyOpenSSL
|
| SUSE-SU-2026:2260-1 |
|
Vulnerability in SUSE-SU-2026:2260-1 (SUSE-SU-2026:2260-1)
vulnerability in SUSE-SU-2026:2260-1 (SUSE-SU-2026:2260-1). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:2259-1 |
|
Vulnerability in SUSE-SU-2026:2259-1 (SUSE-SU-2026:2259-1)
vulnerability in SUSE-SU-2026:2259-1 (SUSE-SU-2026:2259-1). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5177 |
|
Vulnerability in fia-signals (MAL-2026-5177)
vulnerability in fia-signals (MAL-2026-5177). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5178 |
|
Vulnerability in tronlab (MAL-2026-5178)
vulnerability in tronlab (MAL-2026-5178). Risk of unauthorized operations or information disclosure.
|
| ROOT-APP-PYPI-CVE-2025-34291 |
|
Vulnerability in rootio-langflow (ROOT-APP-PYPI-CVE-2025-34291)
vulnerability in rootio-langflow (ROOT-APP-PYPI-CVE-2025-34291). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.9+root.io.1` or later.
|
| ECHO-c67b-44b0-ff31 |
|
ECHO-c67b-44b0-ff31 |
| ROOT-APP-PYPI-CVE-2025-68675 |
|
Vulnerability in rootio-apache-airflow (ROOT-APP-PYPI-CVE-2025-68675)
vulnerability in rootio-apache-airflow (ROOT-APP-PYPI-CVE-2025-68675). Confidential information can be exposed externally. Mitigation: upgrade to `2.10.5+root.io.1, 2.11.0+root.io.1, 2.3.3+root.io.5, 2.11.0+root.io.2, 2.10.5+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2025-66416 |
|
Vulnerability in rootio-mcp (ROOT-APP-PYPI-CVE-2025-66416)
vulnerability in rootio-mcp (ROOT-APP-PYPI-CVE-2025-66416). Confidential information can be exposed externally. Mitigation: upgrade to `1.13.0+root.io.1, 1.12.0+root.io.1, 1.12.0+root.io.2, 1.21.2+root.io.1, 1.10.1+root.io.1, 1.11.0+root.io.1, 1.21.0+root.io.1, 1.6.0+root.io.2, 1.12.4+root.io.1, 1.22.0+root.io.1, 1.16.0+root.io.1, 1.21.1+root.io.1, 1.2.0+root.io.2, 1.13.1+root.io.1, 1.17.0+root.io.1, 1.1.2+root.io.2, 1.2.0+root.io.3, 1.1.2+root.io.3, 1.6.0+root.io.3, 1.1.2+root.io.4, 1.2.0+root.io.4, 1.11.0+root.io.2, 1.10.1+root.io.2, 1.13.0+root.io.2, 1.21.0+root.io.2, 1.12.4+root.io.2, 1.13.1+root.io.2, 1.21.1+root.io.2, 1.6.0+root.io.4, 1.16.0+root.io.2, 1.22.0+root.io.2, 1.21.2+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2024-26130 |
|
Vulnerability in rootio-cryptography (ROOT-APP-PYPI-CVE-2024-26130)
vulnerability in rootio-cryptography (ROOT-APP-PYPI-CVE-2024-26130). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `41.0.7+root.io.1, 41.0.7+root.io.2, 41.0.7+root.io.3` or later.
|
| ROOT-APP-PYPI-GHSA-747p-wmpv-9c78 |
|
Vulnerability in rootio-awscli (ROOT-APP-PYPI-GHSA-747p-wmpv-9c78)
vulnerability in rootio-awscli (ROOT-APP-PYPI-GHSA-747p-wmpv-9c78). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.43.13+root.io.1, 1.43.13+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2025-53366 |
|
Vulnerability in rootio-mcp (ROOT-APP-PYPI-CVE-2025-53366)
vulnerability in rootio-mcp (ROOT-APP-PYPI-CVE-2025-53366). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1+root.io.1, 1.0.0+root.io.1, 1.2.0+root.io.1, 1.6.0+root.io.1, 1.8.1+root.io.1, 1.1.0+root.io.1, 1.1.2+root.io.1, 1.6.0+root.io.2, 1.2.0+root.io.2, 1.1.2+root.io.2, 1.2.0+root.io.3, 1.1.2+root.io.3, 1.6.0+root.io.3, 1.0.0+root.io.2, 1.1.2+root.io.4, 1.0.0+root.io.3, 1.1.0+root.io.2, 1.2.0+root.io.4, 1.8.1+root.io.2, 1.6.0+root.io.4, 1.9.1+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2023-0286 |
|
Vulnerability in rootio-cryptography (ROOT-APP-PYPI-CVE-2023-0286)
vulnerability in rootio-cryptography (ROOT-APP-PYPI-CVE-2023-0286). Confidential information can be exposed externally. Mitigation: upgrade to `36.0.2+root.io.1, 36.0.2+root.io.2, 36.0.1+root.io.1` or later.
|
| ROOT-APP-PYPI-CVE-2025-53365 |
|
Vulnerability in rootio-mcp (ROOT-APP-PYPI-CVE-2025-53365)
vulnerability in rootio-mcp (ROOT-APP-PYPI-CVE-2025-53365). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1+root.io.1, 1.0.0+root.io.1, 1.2.0+root.io.1, 1.6.0+root.io.1, 1.8.1+root.io.1, 1.1.0+root.io.1, 1.9.4+root.io.1, 1.1.2+root.io.1, 1.6.0+root.io.2, 1.2.0+root.io.2, 1.1.2+root.io.2, 1.2.0+root.io.3, 1.1.2+root.io.3, 1.6.0+root.io.3, 1.0.0+root.io.2, 1.1.2+root.io.4, 1.0.0+root.io.3, 1.1.0+root.io.2, 1.2.0+root.io.4, 1.8.1+root.io.2, 1.6.0+root.io.4, 1.9.4+root.io.2, 1.9.1+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2026-28356 |
|
Vulnerability in rootio-multipart (ROOT-APP-PYPI-CVE-2026-28356)
vulnerability in rootio-multipart (ROOT-APP-PYPI-CVE-2026-28356). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.1+root.io.1, 1.2.1+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2024-6827 |
|
Vulnerability in rootio-gunicorn (ROOT-APP-PYPI-CVE-2024-6827)
vulnerability in rootio-gunicorn (ROOT-APP-PYPI-CVE-2024-6827). Confidential information can be exposed externally. Mitigation: upgrade to `21.2.0+root.io.1, 20.1.0+root.io.1, 20.1.0+root.io.2, 21.2.0+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2024-1135 |
|
Vulnerability in rootio-gunicorn (ROOT-APP-PYPI-CVE-2024-1135)
vulnerability in rootio-gunicorn (ROOT-APP-PYPI-CVE-2024-1135). Data can be tampered with by attackers. Mitigation: upgrade to `21.2.0+root.io.1, 20.1.0+root.io.1, 20.1.0+root.io.2, 21.2.0+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2025-69534 |
|
Vulnerability in rootio-Markdown (ROOT-APP-PYPI-CVE-2025-69534)
vulnerability in rootio-Markdown (ROOT-APP-PYPI-CVE-2025-69534). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.7+root.io.1, 3.3.7+root.io.2, 3.4.4+root.io.1` or later.
|
| ROOT-APP-PYPI-CVE-2024-25128 |
|
Vulnerability in rootio-Flask-AppBuilder (ROOT-APP-PYPI-CVE-2024-25128)
vulnerability in rootio-Flask-AppBuilder (ROOT-APP-PYPI-CVE-2024-25128). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2+root.io.3, 4.1.2+root.io.1, 4.1.2+root.io.2, 4.3.10+root.io.1, 4.1.2+root.io.4, 4.3.10+root.io.2` or later.
|
| ROOT-APP-PYPI-CVE-2023-34110 |
|
Vulnerability in rootio-Flask-AppBuilder (ROOT-APP-PYPI-CVE-2023-34110)
vulnerability in rootio-Flask-AppBuilder (ROOT-APP-PYPI-CVE-2023-34110). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.2+root.io.3, 4.1.2+root.io.4` or later.
|
| ROOT-APP-PYPI-CVE-2025-58065 |
|
Vulnerability in rootio-Flask-AppBuilder (ROOT-APP-PYPI-CVE-2025-58065)
vulnerability in rootio-Flask-AppBuilder (ROOT-APP-PYPI-CVE-2025-58065). Data can be tampered with by attackers. Mitigation: upgrade to `4.1.2+root.io.3, 4.1.2+root.io.2, 4.1.2+root.io.4` or later.
|