Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-46599 |
|
Vulnerability in golang.org/x/image (CVE-2026-46599)
vulnerability in golang.org/x/image (CVE-2026-46599). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.41.0` or later.
|
| CVE-2026-46527 |
|
Vulnerability in c (CVE-2026-46527)
vulnerability in c (CVE-2026-46527). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.44.0` or later.
|
| DEBIAN-CVE-2026-45700 |
|
Vulnerability in freerdp2 (DEBIAN-CVE-2026-45700)
vulnerability in freerdp2 (DEBIAN-CVE-2026-45700). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-45700 |
|
Out-of-Bounds Write in c (CVE-2026-45700)
out-of-bounds write in c (CVE-2026-45700). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
|
| DEBIAN-CVE-2026-45372 |
|
Vulnerability in cpp-httplib (DEBIAN-CVE-2026-45372)
vulnerability in cpp-httplib (DEBIAN-CVE-2026-45372). Data can be tampered with by attackers. Mitigation: upgrade to `0.44.0` or later.
|
| DEBIAN-CVE-2026-45352 |
|
Vulnerability in cpp-httplib (DEBIAN-CVE-2026-45352)
vulnerability in cpp-httplib (DEBIAN-CVE-2026-45352). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.43.4` or later.
|
| CVE-2026-45613 |
|
Out-of-Bounds Read in c (CVE-2026-45613)
vulnerability in c (CVE-2026-45613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45372 |
|
Vulnerability in c (CVE-2026-45372)
vulnerability in c (CVE-2026-45372). Data can be tampered with by attackers. Mitigation: upgrade to `0.44.0` or later.
|
| CVE-2026-45352 |
|
Vulnerability in c (CVE-2026-45352)
vulnerability in c (CVE-2026-45352). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.43.4` or later.
|
| DEBIAN-CVE-2026-45149 |
|
Vulnerability in node-brace-expansion (DEBIAN-CVE-2026-45149)
vulnerability in node-brace-expansion (DEBIAN-CVE-2026-45149). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.6` or later.
|
| CVE-2026-45324 |
|
Vulnerability in c (CVE-2026-45324)
vulnerability in c (CVE-2026-45324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45294 |
|
Vulnerability in laravel (CVE-2026-45294)
vulnerability in laravel (CVE-2026-45294). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.219` or later.
|
| CVE-2026-45151 |
|
Vulnerability in c (CVE-2026-45151)
vulnerability in c (CVE-2026-45151). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-44422 |
|
Vulnerability in freerdp2 (DEBIAN-CVE-2026-44422)
vulnerability in freerdp2 (DEBIAN-CVE-2026-44422). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
|
| DEBIAN-CVE-2026-44421 |
|
Vulnerability in freerdp2 (DEBIAN-CVE-2026-44421)
vulnerability in freerdp2 (DEBIAN-CVE-2026-44421). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
|
| DEBIAN-CVE-2026-44420 |
|
Vulnerability in freerdp2 (DEBIAN-CVE-2026-44420)
vulnerability in freerdp2 (DEBIAN-CVE-2026-44420). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-44640 |
|
Vulnerability in CVE-2026-44640 (CVE-2026-44640)
vulnerability in CVE-2026-44640 (CVE-2026-44640). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.24.14` or later.
|
| CVE-2026-44422 |
|
Vulnerability in freerdp (CVE-2026-44422)
vulnerability in freerdp (CVE-2026-44422). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-44421 |
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs....
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX...
|
| CVE-2026-44420 |
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel b...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process...
|
| CVE-2026-44287 |
|
Code Injection in CVE-2026-44287 (CVE-2026-44287)
code injection in CVE-2026-44287 (CVE-2026-44287). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.15.0-beta1` or later.
|
| CVE-2026-44285 |
|
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network prot...
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploi...
|
| DEBIAN-CVE-2026-42500 |
|
Vulnerability in golang-golang-x-image (DEBIAN-CVE-2026-42500)
vulnerability in golang-golang-x-image (DEBIAN-CVE-2026-42500). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42500 |
|
Vulnerability in golang.org/x/image (CVE-2026-42500)
vulnerability in golang.org/x/image (CVE-2026-42500). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.41.0` or later.
|
| CVE-2026-34127 |
|
Cross-Site Scripting (XSS) in tp-link (CVE-2026-34127)
cross-site scripting in tp-link (CVE-2026-34127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47183 |
|
Vulnerability in zeroconf (CVE-2026-47183)
vulnerability in zeroconf (CVE-2026-47183). Risk of unauthorized operations or information disclosure. Exploitable via ``DNSIncoming._log_exception_debug``. Mitigation: upgrade to `0.149.6` or later.
|
| CVE-2026-47180 |
|
Vulnerability in zeroconf (CVE-2026-47180)
vulnerability in zeroconf (CVE-2026-47180). Risk of unauthorized operations or information disclosure. Exploitable via ``DNSIncoming._decode_labels_at_offset``. Mitigation: upgrade to `0.149.5` or later.
|
| GHSA-92vj-hp7m-gwcj |
|
Vulnerability in Nerdbank.MessagePack (GHSA-92vj-hp7m-gwcj)
vulnerability in Nerdbank.MessagePack (GHSA-92vj-hp7m-gwcj). Risk of unauthorized operations or information disclosure. Exploitable via ``ExpandoObject``. Mitigation: upgrade to `1.2.4` or later.
|
| CVE-2026-47260 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-47260)
SSRF in phanan/koel (CVE-2026-47260). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.3.5` or later.
|
| GHSA-qjvr-435c-5fjh |
|
Vulnerability in Nerdbank.MessagePack (GHSA-qjvr-435c-5fjh)
vulnerability in Nerdbank.MessagePack (GHSA-qjvr-435c-5fjh). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonNode``. Mitigation: upgrade to `1.1.78` or later.
|
| CGA-whq7-q9g8-x68m |
|
CGA-whq7-q9g8-x68m |
| CGA-p59r-5wgp-4vc2 |
|
CGA-p59r-5wgp-4vc2 |
| CGA-3p7f-hq5m-7xw9 |
|
CGA-3p7f-hq5m-7xw9 |
| CGA-95fg-wrf4-6xpj |
|
CGA-95fg-wrf4-6xpj |
| CGA-2h86-cwq8-j7xx |
|
CGA-2h86-cwq8-j7xx |
| CGA-qq6w-wjqv-49x9 |
|
CGA-qq6w-wjqv-49x9 |
| CGA-m9mf-rg9r-rpmx |
|
CGA-m9mf-rg9r-rpmx |
| CGA-j5pq-cx57-5gmx |
|
CGA-j5pq-cx57-5gmx |
| CGA-7wm3-x6qx-j573 |
|
CGA-7wm3-x6qx-j573 |
| CGA-m4f8-7c43-hhvm |
|
CGA-m4f8-7c43-hhvm |
| USN-8344-2 |
|
Vulnerability in python-pip (USN-8344-2)
vulnerability in python-pip (USN-8344-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.0.2+dfsg-1ubuntu0.7+esm2` or later.
|
| CVE-2026-47122 |
|
Vulnerability in github.com/sparkle-project/Sparkle (CVE-2026-47122)
vulnerability in github.com/sparkle-project/Sparkle (CVE-2026-47122). Risk of unauthorized operations or information disclosure. Exploitable via ``SPUSentUpdateAppcastItemData``.
|
| CVE-2026-47121 |
|
Path Traversal in github.com/sparkle-project/Sparkle (CVE-2026-47121)
path traversal in github.com/sparkle-project/Sparkle (CVE-2026-47121). Data can be tampered with by attackers. Exploitable via ``Extract``. Mitigation: upgrade to `2.9.2` or later.
|
| GHSA-w5pp-99ch-qj29 |
|
Vulnerability in github.com/go-git/go-git/v5 (GHSA-w5pp-99ch-qj29)
vulnerability in github.com/go-git/go-git/v5 (GHSA-w5pp-99ch-qj29). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.1` or later.
|
| CVE-2026-46705 |
|
Authentication Bypass in russh (CVE-2026-46705)
authentication bypass in russh (CVE-2026-46705). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.0` or later.
|
| CVE-2026-46702 |
|
Vulnerability in russh (CVE-2026-46702)
vulnerability in russh (CVE-2026-46702). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.1` or later.
|
| CGA-4cq4-55wr-cwx5 |
|
CGA-4cq4-55wr-cwx5 |
| CGA-ff5g-mxhg-xrp4 |
|
CGA-ff5g-mxhg-xrp4 |
| CGA-8mr3-jxrj-55xw |
|
CGA-8mr3-jxrj-55xw |
| CGA-gqp7-q28g-vxqv |
|
CGA-gqp7-q28g-vxqv |