Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-46599 Vulnerability in golang.org/x/image (CVE-2026-46599)
vulnerability in golang.org/x/image (CVE-2026-46599). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.41.0` or later.
CVE-2026-46527 Vulnerability in c (CVE-2026-46527)
vulnerability in c (CVE-2026-46527). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.44.0` or later.
DEBIAN-CVE-2026-45700 Vulnerability in freerdp2 (DEBIAN-CVE-2026-45700)
vulnerability in freerdp2 (DEBIAN-CVE-2026-45700). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-45700 Out-of-Bounds Write in c (CVE-2026-45700)
out-of-bounds write in c (CVE-2026-45700). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
DEBIAN-CVE-2026-45372 Vulnerability in cpp-httplib (DEBIAN-CVE-2026-45372)
vulnerability in cpp-httplib (DEBIAN-CVE-2026-45372). Data can be tampered with by attackers. Mitigation: upgrade to `0.44.0` or later.
DEBIAN-CVE-2026-45352 Vulnerability in cpp-httplib (DEBIAN-CVE-2026-45352)
vulnerability in cpp-httplib (DEBIAN-CVE-2026-45352). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.43.4` or later.
CVE-2026-45613 Out-of-Bounds Read in c (CVE-2026-45613)
vulnerability in c (CVE-2026-45613). Risk of unauthorized operations or information disclosure.
CVE-2026-45372 Vulnerability in c (CVE-2026-45372)
vulnerability in c (CVE-2026-45372). Data can be tampered with by attackers. Mitigation: upgrade to `0.44.0` or later.
CVE-2026-45352 Vulnerability in c (CVE-2026-45352)
vulnerability in c (CVE-2026-45352). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.43.4` or later.
DEBIAN-CVE-2026-45149 Vulnerability in node-brace-expansion (DEBIAN-CVE-2026-45149)
vulnerability in node-brace-expansion (DEBIAN-CVE-2026-45149). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.6` or later.
CVE-2026-45324 Vulnerability in c (CVE-2026-45324)
vulnerability in c (CVE-2026-45324). Risk of unauthorized operations or information disclosure.
CVE-2026-45294 Vulnerability in laravel (CVE-2026-45294)
vulnerability in laravel (CVE-2026-45294). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.219` or later.
CVE-2026-45151 Vulnerability in c (CVE-2026-45151)
vulnerability in c (CVE-2026-45151). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-44422 Vulnerability in freerdp2 (DEBIAN-CVE-2026-44422)
vulnerability in freerdp2 (DEBIAN-CVE-2026-44422). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
DEBIAN-CVE-2026-44421 Vulnerability in freerdp2 (DEBIAN-CVE-2026-44421)
vulnerability in freerdp2 (DEBIAN-CVE-2026-44421). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
DEBIAN-CVE-2026-44420 Vulnerability in freerdp2 (DEBIAN-CVE-2026-44420)
vulnerability in freerdp2 (DEBIAN-CVE-2026-44420). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-44640 Vulnerability in CVE-2026-44640 (CVE-2026-44640)
vulnerability in CVE-2026-44640 (CVE-2026-44640). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.24.14` or later.
CVE-2026-44422 Vulnerability in freerdp (CVE-2026-44422)
vulnerability in freerdp (CVE-2026-44422). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-44421 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs....
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs. The bug is in gdi_CacheToSurface: it validates a destination rectangle that is clamped to UINT16_MAX...
CVE-2026-44420 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel b...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel by sending a CB_CLIP_CAPS PDU with a too-small capabilitySetLength. This can crash the server process...
CVE-2026-44287 Code Injection in CVE-2026-44287 (CVE-2026-44287)
code injection in CVE-2026-44287 (CVE-2026-44287). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.15.0-beta1` or later.
CVE-2026-44285 FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network prot...
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network protection and make arbitrary HTTP GET requests to internal network services. This is achieved by exploi...
DEBIAN-CVE-2026-42500 Vulnerability in golang-golang-x-image (DEBIAN-CVE-2026-42500)
vulnerability in golang-golang-x-image (DEBIAN-CVE-2026-42500). Risk of unauthorized operations or information disclosure.
CVE-2026-42500 Vulnerability in golang.org/x/image (CVE-2026-42500)
vulnerability in golang.org/x/image (CVE-2026-42500). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.41.0` or later.
CVE-2026-34127 Cross-Site Scripting (XSS) in tp-link (CVE-2026-34127)
cross-site scripting in tp-link (CVE-2026-34127). Risk of unauthorized operations or information disclosure.
CVE-2026-47183 Vulnerability in zeroconf (CVE-2026-47183)
vulnerability in zeroconf (CVE-2026-47183). Risk of unauthorized operations or information disclosure. Exploitable via ``DNSIncoming._log_exception_debug``. Mitigation: upgrade to `0.149.6` or later.
CVE-2026-47180 Vulnerability in zeroconf (CVE-2026-47180)
vulnerability in zeroconf (CVE-2026-47180). Risk of unauthorized operations or information disclosure. Exploitable via ``DNSIncoming._decode_labels_at_offset``. Mitigation: upgrade to `0.149.5` or later.
GHSA-92vj-hp7m-gwcj Vulnerability in Nerdbank.MessagePack (GHSA-92vj-hp7m-gwcj)
vulnerability in Nerdbank.MessagePack (GHSA-92vj-hp7m-gwcj). Risk of unauthorized operations or information disclosure. Exploitable via ``ExpandoObject``. Mitigation: upgrade to `1.2.4` or later.
CVE-2026-47260 SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-47260)
SSRF in phanan/koel (CVE-2026-47260). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.3.5` or later.
GHSA-qjvr-435c-5fjh Vulnerability in Nerdbank.MessagePack (GHSA-qjvr-435c-5fjh)
vulnerability in Nerdbank.MessagePack (GHSA-qjvr-435c-5fjh). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonNode``. Mitigation: upgrade to `1.1.78` or later.
CGA-whq7-q9g8-x68m CGA-whq7-q9g8-x68m
CGA-p59r-5wgp-4vc2 CGA-p59r-5wgp-4vc2
CGA-3p7f-hq5m-7xw9 CGA-3p7f-hq5m-7xw9
CGA-95fg-wrf4-6xpj CGA-95fg-wrf4-6xpj
CGA-2h86-cwq8-j7xx CGA-2h86-cwq8-j7xx
CGA-qq6w-wjqv-49x9 CGA-qq6w-wjqv-49x9
CGA-m9mf-rg9r-rpmx CGA-m9mf-rg9r-rpmx
CGA-j5pq-cx57-5gmx CGA-j5pq-cx57-5gmx
CGA-7wm3-x6qx-j573 CGA-7wm3-x6qx-j573
CGA-m4f8-7c43-hhvm CGA-m4f8-7c43-hhvm
USN-8344-2 Vulnerability in python-pip (USN-8344-2)
vulnerability in python-pip (USN-8344-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.0.2+dfsg-1ubuntu0.7+esm2` or later.
CVE-2026-47122 Vulnerability in github.com/sparkle-project/Sparkle (CVE-2026-47122)
vulnerability in github.com/sparkle-project/Sparkle (CVE-2026-47122). Risk of unauthorized operations or information disclosure. Exploitable via ``SPUSentUpdateAppcastItemData``.
CVE-2026-47121 Path Traversal in github.com/sparkle-project/Sparkle (CVE-2026-47121)
path traversal in github.com/sparkle-project/Sparkle (CVE-2026-47121). Data can be tampered with by attackers. Exploitable via ``Extract``. Mitigation: upgrade to `2.9.2` or later.
GHSA-w5pp-99ch-qj29 Vulnerability in github.com/go-git/go-git/v5 (GHSA-w5pp-99ch-qj29)
vulnerability in github.com/go-git/go-git/v5 (GHSA-w5pp-99ch-qj29). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.1` or later.
CVE-2026-46705 Authentication Bypass in russh (CVE-2026-46705)
authentication bypass in russh (CVE-2026-46705). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.0` or later.
CVE-2026-46702 Vulnerability in russh (CVE-2026-46702)
vulnerability in russh (CVE-2026-46702). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.1` or later.
CGA-4cq4-55wr-cwx5 CGA-4cq4-55wr-cwx5
CGA-ff5g-mxhg-xrp4 CGA-ff5g-mxhg-xrp4
CGA-8mr3-jxrj-55xw CGA-8mr3-jxrj-55xw
CGA-gqp7-q28g-vxqv CGA-gqp7-q28g-vxqv

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →