Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MINI-fj67-j3mv-gh75 MINI-fj67-j3mv-gh75
CVE-2026-47425 Path Traversal in rattler (CVE-2026-47425)
path traversal in rattler (CVE-2026-47425). Risk of unauthorized operations or information disclosure. Exploitable via ``rattler_conda_types``. Mitigation: upgrade to `0.43.2` or later.
MINI-wgqj-m2f7-6v48 MINI-wgqj-m2f7-6v48
CVE-2026-47428 Cross-Site Scripting (XSS) in @vitest/browser (CVE-2026-47428)
cross-site scripting in @vitest/browser (CVE-2026-47428). Successful exploitation can lead to full system takeover. Exploitable via ``otelCarrier``. Mitigation: upgrade to `5.0.0-beta.3` or later.
MINI-gc6r-hmgc-279p MINI-gc6r-hmgc-279p
CVE-2026-47429 Path Traversal in vitest (CVE-2026-47429)
path traversal in vitest (CVE-2026-47429). Successful exploitation can lead to full system takeover. Exploitable via ``api.host``. Mitigation: upgrade to `3.2.6` or later.
CVE-2026-47423 Cross-Site Scripting (XSS) in dompurify (CVE-2026-47423)
cross-site scripting in dompurify (CVE-2026-47423). Confidential information can be exposed externally. Exploitable via ``selectedcontent``. Mitigation: upgrade to `3.4.5` or later.
USN-8355-1 Vulnerability in sssd (USN-8355-1)
vulnerability in sssd (USN-8355-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.4-1.1ubuntu6.5` or later.
MINI-rjf4-hqg2-555r MINI-rjf4-hqg2-555r
CVE-2026-48119 Vulnerability in github.com/nezhahq/nezha (CVE-2026-48119)
vulnerability in github.com/nezhahq/nezha (CVE-2026-48119). Data can be tampered with by attackers. Exploitable via ``TaskResult``. Mitigation: upgrade to `2.0.12` or later.
CVE-2026-50287 Vulnerability in @agenticmail/mcp (CVE-2026-50287)
vulnerability in @agenticmail/mcp (CVE-2026-50287). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `0.9.27` or later.
USN-8354-1 Vulnerability in nginx (USN-8354-1)
vulnerability in nginx (USN-8354-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.18.0-6ubuntu14.12` or later.
SUSE-SU-2026:21883-1 Vulnerability in SUSE-SU-2026:21883-1 (SUSE-SU-2026:21883-1)
vulnerability in SUSE-SU-2026:21883-1 (SUSE-SU-2026:21883-1). Risk of unauthorized operations or information disclosure. Exploitable via ``virtio_snd_pcm_in_cb``.
USN-8353-1 Vulnerability in exim4 (USN-8353-1)
vulnerability in exim4 (USN-8353-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.95-4ubuntu2.9` or later.
ROOT-APP-NPM-CVE-2026-24842 Vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-24842)
vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-24842). Confidential information can be exposed externally. Mitigation: upgrade to `6.2.1-root.io.3, 7.5.1-root.io.3, 6.2.0-root.io.5, 7.5.1-root.io.4, 7.4.3-root.io.3, 6.2.1-root.io.4, 7.5.1-root.io.5, 7.4.3-root.io.4, 6.2.0-root.io.6, 6.2.1-root.io.5, 6.2.1-root.io.6, 6.2.0-root.io.7, 7.4.3-root.io.5, 7.5.1-root.io.6, 6.2.1-root.io.7, 7.4.3-root.io.6, 7.5.1-root.io.7, 6.2.0-root.io.8, 7.4.3-root.io.7, 7.5.1-root.io.8, 6.2.0-root.io.9, 6.1.11-root.io.3, 4.4.19-root.io.2, 4.4.19-root.io.3, 6.2.1-root.io.8, 7.4.3-root.io.8, 6.2.0-root.io.10, 6.1.11-root.io.4, 7.5.1-root.io.9` or later.
ROOT-APP-NPM-CVE-2026-29786 Vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-29786)
vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-29786). Data can be tampered with by attackers. Mitigation: upgrade to `6.2.1-root.io.6, 6.2.0-root.io.7, 7.4.3-root.io.5, 7.5.1-root.io.6, 6.2.1-root.io.7, 6.1.11-root.io.2, 7.4.3-root.io.6, 7.5.1-root.io.7, 6.2.0-root.io.8, 7.4.3-root.io.7, 7.5.1-root.io.8, 6.2.0-root.io.9, 6.1.13-root.io.2, 6.1.14-root.io.2, 7.5.9-root.io.1, 7.5.7-root.io.3, 6.1.11-root.io.3, 4.4.19-root.io.2, 7.5.7-root.io.4, 4.4.19-root.io.3, 6.2.1-root.io.8, 7.5.9-root.io.2, 7.4.3-root.io.8, 6.2.0-root.io.10, 6.1.13-root.io.3, 6.1.11-root.io.4, 7.5.1-root.io.9, 6.1.14-root.io.3` or later.
ROOT-APP-NPM-CVE-2026-26960 Vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-26960)
vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-26960). Confidential information can be exposed externally. Mitigation: upgrade to `6.2.1-root.io.4, 7.5.7-root.io.1, 7.5.1-root.io.5, 7.4.3-root.io.4, 6.2.0-root.io.6, 6.1.11-root.io.1, 6.1.13-root.io.1, 6.2.1-root.io.5, 6.1.14-root.io.1, 6.2.1-root.io.6, 6.2.0-root.io.7, 7.4.3-root.io.5, 7.5.1-root.io.6, 6.2.1-root.io.7, 7.5.7-root.io.2, 6.1.11-root.io.2, 7.4.3-root.io.6, 7.5.1-root.io.7, 6.2.0-root.io.8, 7.4.3-root.io.7, 7.5.1-root.io.8, 6.2.0-root.io.9, 6.1.13-root.io.2, 6.1.14-root.io.2, 7.5.7-root.io.3, 6.1.11-root.io.3, 4.4.19-root.io.2, 7.5.7-root.io.4, 4.4.19-root.io.3, 6.2.1-root.io.8, 7.4.3-root.io.8, 6.2.0-root.io.10, 6.1.13-root.io.3, 6.1.11-root.io.4, 7.5.1-root.io.9, 6.1.14-root.io.3` or later.
ROOT-APP-NPM-CVE-2026-31802 Vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-31802)
vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-31802). Data can be tampered with by attackers. Mitigation: upgrade to `6.2.1-root.io.7, 7.5.7-root.io.2, 7.4.3-root.io.6, 7.5.1-root.io.7, 6.2.0-root.io.8, 7.4.3-root.io.7, 7.5.1-root.io.8, 6.2.0-root.io.9, 7.5.9-root.io.1, 7.5.7-root.io.3, 4.4.19-root.io.2, 7.5.7-root.io.4, 4.4.19-root.io.3, 6.2.1-root.io.8, 7.5.9-root.io.2, 7.4.3-root.io.8, 6.2.0-root.io.10, 7.5.1-root.io.9` or later.
ROOT-APP-NPM-CVE-2026-23950 Vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-23950)
vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-23950). Data can be tampered with by attackers. Mitigation: upgrade to `6.2.1-root.io.2, 7.4.3-root.io.2, 6.2.0-root.io.4, 6.2.1-root.io.3, 6.2.0-root.io.5, 7.5.1-root.io.4, 7.4.3-root.io.3, 6.2.1-root.io.4, 7.5.1-root.io.5, 7.4.3-root.io.4, 6.2.0-root.io.6, 6.2.1-root.io.5, 6.2.1-root.io.6, 6.2.0-root.io.7, 7.4.3-root.io.5, 7.5.1-root.io.6, 6.2.1-root.io.7, 7.4.3-root.io.6, 7.5.1-root.io.7, 6.2.0-root.io.8, 7.4.3-root.io.7, 7.5.1-root.io.8, 6.2.0-root.io.9, 6.1.11-root.io.3, 4.4.19-root.io.2, 4.4.19-root.io.3, 6.2.1-root.io.8, 7.4.3-root.io.8, 6.2.0-root.io.10, 6.1.11-root.io.4, 7.5.1-root.io.9` or later.
ROOT-APP-NPM-CVE-2026-23745 Vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-23745)
vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2026-23745). Confidential information can be exposed externally. Mitigation: upgrade to `6.2.0-root.io.2, 7.4.3-root.io.1, 6.2.0-root.io.3, 6.2.1-root.io.1, 6.2.1-root.io.2, 7.4.3-root.io.2, 7.5.1-root.io.2, 6.2.0-root.io.4, 6.2.1-root.io.3, 7.5.1-root.io.3, 6.2.0-root.io.5, 7.5.1-root.io.4, 7.4.3-root.io.3, 6.2.1-root.io.4, 7.5.1-root.io.5, 7.4.3-root.io.4, 6.2.0-root.io.6, 6.2.1-root.io.5, 6.2.1-root.io.6, 6.2.0-root.io.7, 7.4.3-root.io.5, 7.5.1-root.io.6, 6.2.1-root.io.7, 7.4.3-root.io.6, 7.5.1-root.io.7, 6.2.0-root.io.8, 7.4.3-root.io.7, 7.5.1-root.io.8, 6.2.0-root.io.9, 6.1.11-root.io.3, 4.4.19-root.io.2, 4.4.19-root.io.3, 6.2.1-root.io.8, 7.4.3-root.io.8, 6.2.0-root.io.10, 6.1.11-root.io.4, 7.5.1-root.io.9` or later.
ROOT-APP-NPM-CVE-2024-28863 Vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2024-28863)
vulnerability in @rootio/tar (ROOT-APP-NPM-CVE-2024-28863). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.0-root.io.1, 4.4.19-root.io.1, 6.2.0-root.io.2, 6.2.0-root.io.3, 6.2.0-root.io.4, 6.2.0-root.io.5, 6.2.0-root.io.6, 6.2.0-root.io.7, 6.2.0-root.io.8, 6.2.0-root.io.9, 4.4.19-root.io.2, 4.4.19-root.io.3, 6.2.0-root.io.10` or later.
openSUSE-SU-2026:20864-1 Vulnerability in openSUSE-SU-2026:20864-1 (openSUSE-SU-2026:20864-1)
vulnerability in openSUSE-SU-2026:20864-1 (openSUSE-SU-2026:20864-1). Risk of unauthorized operations or information disclosure.
CVE-2026-9309 Cross-Site Scripting (XSS) in mozilla (CVE-2026-9309)
cross-site scripting in mozilla (CVE-2026-9309). Risk of unauthorized operations or information disclosure.
CVE-2026-9308 Cross-Site Scripting (XSS) in mozilla (CVE-2026-9308)
cross-site scripting in mozilla (CVE-2026-9308). Risk of unauthorized operations or information disclosure.
CVE-2026-34193 Vulnerability in imaginationtech (CVE-2026-34193)
vulnerability in imaginationtech (CVE-2026-34193). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-10532 Vulnerability in logback (DEBIAN-CVE-2026-10532)
vulnerability in logback (DEBIAN-CVE-2026-10532). Risk of unauthorized operations or information disclosure.
CVE-2026-10532 Unsafe Deserialization in ch.qos.logback:logback-core (CVE-2026-10532)
vulnerability in ch.qos.logback:logback-core (CVE-2026-10532). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.34` or later.
CVE-2026-10258 Vulnerability in sqli (CVE-2026-10258)
vulnerability in sqli (CVE-2026-10258). Risk of unauthorized operations or information disclosure.
CVE-2026-10257 Vulnerability in sqli (CVE-2026-10257)
vulnerability in sqli (CVE-2026-10257). Risk of unauthorized operations or information disclosure.
CVE-2026-10256 Vulnerability in sqli (CVE-2026-10256)
vulnerability in sqli (CVE-2026-10256). Risk of unauthorized operations or information disclosure.
CVE-2026-10255 Vulnerability in CVE-2026-10255 (CVE-2026-10255)
vulnerability in CVE-2026-10255 (CVE-2026-10255). Risk of unauthorized operations or information disclosure.
CVE-2026-10254 Information Disclosure in CVE-2026-10254 (CVE-2026-10254)
vulnerability in CVE-2026-10254 (CVE-2026-10254). Risk of unauthorized operations or information disclosure.
CVE-2026-10253 Vulnerability in sqli (CVE-2026-10253)
vulnerability in sqli (CVE-2026-10253). Risk of unauthorized operations or information disclosure.
CVE-2026-10252 Vulnerability in sqli (CVE-2026-10252)
vulnerability in sqli (CVE-2026-10252). Risk of unauthorized operations or information disclosure.
CVE-2026-10251 Vulnerability in sqli (CVE-2026-10251)
vulnerability in sqli (CVE-2026-10251). Risk of unauthorized operations or information disclosure.
MAL-2026-5120 Vulnerability in redteam-qxz7-utils (MAL-2026-5120)
vulnerability in redteam-qxz7-utils (MAL-2026-5120). Risk of unauthorized operations or information disclosure.
USN-8352-1 Vulnerability in libreoffice (USN-8352-1)
vulnerability in libreoffice (USN-8352-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4:25.8.7-0ubuntu0.25.10.1` or later.
SUSE-SU-2026:21946-1 Vulnerability in SUSE-SU-2026:21946-1 (SUSE-SU-2026:21946-1)
vulnerability in SUSE-SU-2026:21946-1 (SUSE-SU-2026:21946-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:21882-1 Vulnerability in SUSE-SU-2026:21882-1 (SUSE-SU-2026:21882-1)
vulnerability in SUSE-SU-2026:21882-1 (SUSE-SU-2026:21882-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:21945-1 Vulnerability in SUSE-SU-2026:21945-1 (SUSE-SU-2026:21945-1)
vulnerability in SUSE-SU-2026:21945-1 (SUSE-SU-2026:21945-1). Risk of unauthorized operations or information disclosure.
USN-8351-1 Vulnerability in linux-lowlatency (USN-8351-1)
vulnerability in linux-lowlatency (USN-8351-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.15.0-179.189` or later.
USN-8350-1 Vulnerability in linux-nvidia-tegra (USN-8350-1)
vulnerability in linux-nvidia-tegra (USN-8350-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.8.0-1025.25` or later.
GHSA-pc3j-w4f9-94hj Vulnerability in jingmeideshishi (GHSA-pc3j-w4f9-94hj)
vulnerability in jingmeideshishi (GHSA-pc3j-w4f9-94hj). Risk of unauthorized operations or information disclosure.
MINI-hh63-v6wr-3pxx MINI-hh63-v6wr-3pxx
RLSA-2026:22305 Vulnerability in libzip (RLSA-2026:22305)
vulnerability in libzip (RLSA-2026:22305). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:1.7.3-1.module+el8.10.0+1605+02e07af7` or later.
MINI-3283-fpf4-f8q2 MINI-3283-fpf4-f8q2
RUSTSEC-2026-0156 Vulnerability in metacall (RUSTSEC-2026-0156)
vulnerability in metacall (RUSTSEC-2026-0156). Risk of unauthorized operations or information disclosure. Exploitable via ``exception_struct``.
RUSTSEC-2026-0157 Vulnerability in metacall (RUSTSEC-2026-0157)
vulnerability in metacall (RUSTSEC-2026-0157). Risk of unauthorized operations or information disclosure. Exploitable via ``MetaCall``.
MINI-4jj6-pm5q-ghhf MINI-4jj6-pm5q-ghhf
MINI-6g84-mchh-6p52 MINI-6g84-mchh-6p52

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →