Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
GHSA-4gg8-gxpx-9rph Path Traversal in uv (GHSA-4gg8-gxpx-9rph)
path traversal in uv (GHSA-4gg8-gxpx-9rph). Risk of unauthorized operations or information disclosure. Exploitable via ``console_scripts``. Mitigation: upgrade to `0.11.15` or later.
CVE-2026-47255 Vulnerability in @agenticmail/api (CVE-2026-47255)
vulnerability in @agenticmail/api (CVE-2026-47255). Data can be tampered with by attackers. Mitigation: upgrade to `0.9.32` or later.
CVE-2026-47248 Vulnerability in parse-server (CVE-2026-47248)
vulnerability in parse-server (CVE-2026-47248). Risk of unauthorized operations or information disclosure. Exploitable via ``IntrospectionControlPlugin``. Mitigation: upgrade to `8.6.78` or later.
CVE-2026-9051 Vulnerability in privilege-escalation (CVE-2026-9051)
vulnerability in privilege-escalation (CVE-2026-9051). Confidential information can be exposed externally.
CVE-2026-49386 Vulnerability in jetbrains (CVE-2026-49386)
vulnerability in jetbrains (CVE-2026-49386). Confidential information can be exposed externally.
CVE-2026-49385 Vulnerability in jetbrains (CVE-2026-49385)
vulnerability in jetbrains (CVE-2026-49385). Data can be tampered with by attackers.
CVE-2026-49384 In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
CVE-2026-49383 In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
CVE-2026-49382 Vulnerability in jetbrains (CVE-2026-49382)
vulnerability in jetbrains (CVE-2026-49382). Risk of unauthorized operations or information disclosure.
CVE-2026-49381 In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
CVE-2026-49380 In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
CVE-2026-49379 In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
CVE-2026-49378 Vulnerability in jetbrains (CVE-2026-49378)
vulnerability in jetbrains (CVE-2026-49378). Risk of unauthorized operations or information disclosure.
CVE-2026-49377 In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
CVE-2026-49376 In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
CVE-2026-49375 Cross-Site Scripting (XSS) in jetbrains (CVE-2026-49375)
cross-site scripting in jetbrains (CVE-2026-49375). Risk of unauthorized operations or information disclosure.
CVE-2026-49374 Vulnerability in jetbrains (CVE-2026-49374)
vulnerability in jetbrains (CVE-2026-49374). Confidential information can be exposed externally.
CVE-2026-49373 Vulnerability in jetbrains (CVE-2026-49373)
vulnerability in jetbrains (CVE-2026-49373). Confidential information can be exposed externally.
CVE-2026-49372 In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49371 In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-49370 In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
CVE-2026-49369 Authorization Flaw in jetbrains (CVE-2026-49369)
vulnerability in jetbrains (CVE-2026-49369). Risk of unauthorized operations or information disclosure.
CVE-2026-49368 In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
CVE-2026-49367 In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-49366 In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-47745 Vulnerability in shopper/framework (CVE-2026-47745)
vulnerability in shopper/framework (CVE-2026-47745). Data can be tampered with by attackers. Exploitable via ``PaymentMethods``. Mitigation: upgrade to `2.8.0` or later.
CVE-2026-47744 Privilege Escalation in shopper/framework (CVE-2026-47744)
vulnerability in shopper/framework (CVE-2026-47744). Successful exploitation can lead to full system takeover. Exploitable via ``view_users``. Mitigation: upgrade to `2.8.0` or later.
CVE-2026-47742 Vulnerability in shopper/framework (CVE-2026-47742)
vulnerability in shopper/framework (CVE-2026-47742). Data can be tampered with by attackers. Exploitable via ``Edit``. Mitigation: upgrade to `2.8.0` or later.
CVE-2026-47741 Vulnerability in shopper/cart (CVE-2026-47741)
vulnerability in shopper/cart (CVE-2026-47741). Data can be tampered with by attackers. Exploitable via ``Order``. Mitigation: upgrade to `2.8.0` or later.
CVE-2026-47740 shopper/framework: Authorization bypass in multiple Livewire admin components
shopper/framework: Authorization bypass in multiple Livewire admin components
CVE-2026-46344 Out-of-Bounds Read in c (CVE-2026-46344)
vulnerability in c (CVE-2026-46344). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.16.0` or later.
CVE-2026-44611 Vulnerability in macgregor (CVE-2026-44611)
vulnerability in macgregor (CVE-2026-44611). Confidential information can be exposed externally.
CVE-2026-44518 Vulnerability in c (CVE-2026-44518)
vulnerability in c (CVE-2026-44518). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.16.0` or later.
CVE-2026-42951 Vulnerability in macgregor (CVE-2026-42951)
vulnerability in macgregor (CVE-2026-42951). Confidential information can be exposed externally.
CVE-2026-42929 Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
CVE-2026-40425 Vulnerability in macgregor (CVE-2026-40425)
vulnerability in macgregor (CVE-2026-40425). Confidential information can be exposed externally.
GHSA-3pv8-6f4r-ffg2 Vulnerability in tar (GHSA-3pv8-6f4r-ffg2)
vulnerability in tar (GHSA-3pv8-6f4r-ffg2). Risk of unauthorized operations or information disclosure. Exploitable via ``file``. Mitigation: upgrade to `0.4.46` or later.
CVE-2026-38739 SQL Injection in ezsystems/ezpublish-legacy (CVE-2026-38739)
SQL injection in ezsystems/ezpublish-legacy (CVE-2026-38739). Confidential information can be exposed externally. Exploitable via ``_getFileList``.
CVE-2026-46690 Out-of-Bounds Read in unbounded-spsc (CVE-2026-46690)
vulnerability in unbounded-spsc (CVE-2026-46690). Risk of unauthorized operations or information disclosure. Exploitable via ``unsafe``.
GHSA-rf84-wr5g-m3rp Authorization Flaw in github.com/metal3-io/cluster-api-provider-metal3 (GHSA-rf84-wr5g-m3rp)
vulnerability in github.com/metal3-io/cluster-api-provider-metal3 (GHSA-rf84-wr5g-m3rp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.12.5` or later.
CVE-2026-5768 Vulnerability in CVE-2026-5768 (CVE-2026-5768)
vulnerability in CVE-2026-5768 (CVE-2026-5768). Successful exploitation can lead to full system takeover.
CVE-2026-10108 Path Traversal in xiaomusic (CVE-2026-10108)
path traversal in xiaomusic (CVE-2026-10108). Confidential information can be exposed externally. Exploitable via `GET /music/{file_path`. Mitigation: upgrade to `0.5.8` or later.
CVE-2026-10107 SSRF (Server-Side Request Forgery) in CVE-2026-10107 (CVE-2026-10107)
SSRF in CVE-2026-10107 (CVE-2026-10107). Confidential information can be exposed externally.
CVE-2026-10070 Vulnerability in CVE-2026-10070 (CVE-2026-10070)
vulnerability in CVE-2026-10070 (CVE-2026-10070). Risk of unauthorized operations or information disclosure.
CVE-2026-10105 SQL Injection in agno (CVE-2026-10105)
SQL injection in agno (CVE-2026-10105). Confidential information can be exposed externally.
GHSA-hx4v-668p-g2qr Vulnerability in openclaw (GHSA-hx4v-668p-g2qr)
vulnerability in openclaw (GHSA-hx4v-668p-g2qr). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
CVE-2026-47190 Vulnerability in github.com/metal3-io/ip-address-manager (CVE-2026-47190)
vulnerability in github.com/metal3-io/ip-address-manager (CVE-2026-47190). Confidential information can be exposed externally. Mitigation: upgrade to `1.12.4` or later.
GHSA-hfc8-w5f4-3x6m Vulnerability in github.com/metal3-io/ironic-standalone-operator (GHSA-hfc8-w5f4-3x6m)
vulnerability in github.com/metal3-io/ironic-standalone-operator (GHSA-hfc8-w5f4-3x6m). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
GHSA-7cwm-fpfh-rrch Vulnerability in github.com/metal3-io/ironic-standalone-operator (GHSA-7cwm-fpfh-rrch)
vulnerability in github.com/metal3-io/ironic-standalone-operator (GHSA-7cwm-fpfh-rrch). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-47141 Vulnerability in vm2 (CVE-2026-47141)
vulnerability in vm2 (CVE-2026-47141). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `3.11.4` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →