Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-4gg8-gxpx-9rph |
|
Path Traversal in uv (GHSA-4gg8-gxpx-9rph)
path traversal in uv (GHSA-4gg8-gxpx-9rph). Risk of unauthorized operations or information disclosure. Exploitable via ``console_scripts``. Mitigation: upgrade to `0.11.15` or later.
|
| CVE-2026-47255 |
|
Vulnerability in @agenticmail/api (CVE-2026-47255)
vulnerability in @agenticmail/api (CVE-2026-47255). Data can be tampered with by attackers. Mitigation: upgrade to `0.9.32` or later.
|
| CVE-2026-47248 |
|
Vulnerability in parse-server (CVE-2026-47248)
vulnerability in parse-server (CVE-2026-47248). Risk of unauthorized operations or information disclosure. Exploitable via ``IntrospectionControlPlugin``. Mitigation: upgrade to `8.6.78` or later.
|
| CVE-2026-9051 |
|
Vulnerability in privilege-escalation (CVE-2026-9051)
vulnerability in privilege-escalation (CVE-2026-9051). Confidential information can be exposed externally.
|
| CVE-2026-49386 |
|
Vulnerability in jetbrains (CVE-2026-49386)
vulnerability in jetbrains (CVE-2026-49386). Confidential information can be exposed externally.
|
| CVE-2026-49385 |
|
Vulnerability in jetbrains (CVE-2026-49385)
vulnerability in jetbrains (CVE-2026-49385). Data can be tampered with by attackers.
|
| CVE-2026-49384 |
|
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
|
| CVE-2026-49383 |
|
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
|
| CVE-2026-49382 |
|
Vulnerability in jetbrains (CVE-2026-49382)
vulnerability in jetbrains (CVE-2026-49382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49381 |
|
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
|
| CVE-2026-49380 |
|
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
|
| CVE-2026-49379 |
|
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
|
| CVE-2026-49378 |
|
Vulnerability in jetbrains (CVE-2026-49378)
vulnerability in jetbrains (CVE-2026-49378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49377 |
|
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
|
| CVE-2026-49376 |
|
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
|
| CVE-2026-49375 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-49375)
cross-site scripting in jetbrains (CVE-2026-49375). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49374 |
|
Vulnerability in jetbrains (CVE-2026-49374)
vulnerability in jetbrains (CVE-2026-49374). Confidential information can be exposed externally.
|
| CVE-2026-49373 |
|
Vulnerability in jetbrains (CVE-2026-49373)
vulnerability in jetbrains (CVE-2026-49373). Confidential information can be exposed externally.
|
| CVE-2026-49372 |
|
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
|
| CVE-2026-49371 |
|
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
|
| CVE-2026-49370 |
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
|
| CVE-2026-49369 |
|
Authorization Flaw in jetbrains (CVE-2026-49369)
vulnerability in jetbrains (CVE-2026-49369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49368 |
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
|
| CVE-2026-49367 |
|
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
|
| CVE-2026-49366 |
|
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
|
| CVE-2026-47745 |
|
Vulnerability in shopper/framework (CVE-2026-47745)
vulnerability in shopper/framework (CVE-2026-47745). Data can be tampered with by attackers. Exploitable via ``PaymentMethods``. Mitigation: upgrade to `2.8.0` or later.
|
| CVE-2026-47744 |
|
Privilege Escalation in shopper/framework (CVE-2026-47744)
vulnerability in shopper/framework (CVE-2026-47744). Successful exploitation can lead to full system takeover. Exploitable via ``view_users``. Mitigation: upgrade to `2.8.0` or later.
|
| CVE-2026-47742 |
|
Vulnerability in shopper/framework (CVE-2026-47742)
vulnerability in shopper/framework (CVE-2026-47742). Data can be tampered with by attackers. Exploitable via ``Edit``. Mitigation: upgrade to `2.8.0` or later.
|
| CVE-2026-47741 |
|
Vulnerability in shopper/cart (CVE-2026-47741)
vulnerability in shopper/cart (CVE-2026-47741). Data can be tampered with by attackers. Exploitable via ``Order``. Mitigation: upgrade to `2.8.0` or later.
|
| CVE-2026-47740 |
|
shopper/framework: Authorization bypass in multiple Livewire admin components
shopper/framework: Authorization bypass in multiple Livewire admin components
|
| CVE-2026-46344 |
|
Out-of-Bounds Read in c (CVE-2026-46344)
vulnerability in c (CVE-2026-46344). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.16.0` or later.
|
| CVE-2026-44611 |
|
Vulnerability in macgregor (CVE-2026-44611)
vulnerability in macgregor (CVE-2026-44611). Confidential information can be exposed externally.
|
| CVE-2026-44518 |
|
Vulnerability in c (CVE-2026-44518)
vulnerability in c (CVE-2026-44518). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.16.0` or later.
|
| CVE-2026-42951 |
|
Vulnerability in macgregor (CVE-2026-42951)
vulnerability in macgregor (CVE-2026-42951). Confidential information can be exposed externally.
|
| CVE-2026-42929 |
|
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
|
| CVE-2026-40425 |
|
Vulnerability in macgregor (CVE-2026-40425)
vulnerability in macgregor (CVE-2026-40425). Confidential information can be exposed externally.
|
| GHSA-3pv8-6f4r-ffg2 |
|
Vulnerability in tar (GHSA-3pv8-6f4r-ffg2)
vulnerability in tar (GHSA-3pv8-6f4r-ffg2). Risk of unauthorized operations or information disclosure. Exploitable via ``file``. Mitigation: upgrade to `0.4.46` or later.
|
| CVE-2026-38739 |
|
SQL Injection in ezsystems/ezpublish-legacy (CVE-2026-38739)
SQL injection in ezsystems/ezpublish-legacy (CVE-2026-38739). Confidential information can be exposed externally. Exploitable via ``_getFileList``.
|
| CVE-2026-46690 |
|
Out-of-Bounds Read in unbounded-spsc (CVE-2026-46690)
vulnerability in unbounded-spsc (CVE-2026-46690). Risk of unauthorized operations or information disclosure. Exploitable via ``unsafe``.
|
| GHSA-rf84-wr5g-m3rp |
|
Authorization Flaw in github.com/metal3-io/cluster-api-provider-metal3 (GHSA-rf84-wr5g-m3rp)
vulnerability in github.com/metal3-io/cluster-api-provider-metal3 (GHSA-rf84-wr5g-m3rp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.12.5` or later.
|
| CVE-2026-5768 |
|
Vulnerability in CVE-2026-5768 (CVE-2026-5768)
vulnerability in CVE-2026-5768 (CVE-2026-5768). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10108 |
|
Path Traversal in xiaomusic (CVE-2026-10108)
path traversal in xiaomusic (CVE-2026-10108). Confidential information can be exposed externally. Exploitable via `GET /music/{file_path`. Mitigation: upgrade to `0.5.8` or later.
|
| CVE-2026-10107 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-10107 (CVE-2026-10107)
SSRF in CVE-2026-10107 (CVE-2026-10107). Confidential information can be exposed externally.
|
| CVE-2026-10070 |
|
Vulnerability in CVE-2026-10070 (CVE-2026-10070)
vulnerability in CVE-2026-10070 (CVE-2026-10070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10105 |
|
SQL Injection in agno (CVE-2026-10105)
SQL injection in agno (CVE-2026-10105). Confidential information can be exposed externally.
|
| GHSA-hx4v-668p-g2qr |
|
Vulnerability in openclaw (GHSA-hx4v-668p-g2qr)
vulnerability in openclaw (GHSA-hx4v-668p-g2qr). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-47190 |
|
Vulnerability in github.com/metal3-io/ip-address-manager (CVE-2026-47190)
vulnerability in github.com/metal3-io/ip-address-manager (CVE-2026-47190). Confidential information can be exposed externally. Mitigation: upgrade to `1.12.4` or later.
|
| GHSA-hfc8-w5f4-3x6m |
|
Vulnerability in github.com/metal3-io/ironic-standalone-operator (GHSA-hfc8-w5f4-3x6m)
vulnerability in github.com/metal3-io/ironic-standalone-operator (GHSA-hfc8-w5f4-3x6m). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
|
| GHSA-7cwm-fpfh-rrch |
|
Vulnerability in github.com/metal3-io/ironic-standalone-operator (GHSA-7cwm-fpfh-rrch)
vulnerability in github.com/metal3-io/ironic-standalone-operator (GHSA-7cwm-fpfh-rrch). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-47141 |
|
Vulnerability in vm2 (CVE-2026-47141)
vulnerability in vm2 (CVE-2026-47141). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `3.11.4` or later.
|