Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-45668 |
|
Path Traversal in path-traversal (CVE-2026-45668)
path traversal in path-traversal (CVE-2026-45668). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.102.2` or later.
|
| CVE-2026-45661 |
|
Path Traversal in path-traversal (CVE-2026-45661)
path traversal in path-traversal (CVE-2026-45661). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45633 |
|
OS Command Injection in CVE-2026-45633 (CVE-2026-45633)
OS command injection in CVE-2026-45633 (CVE-2026-45633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45632 |
|
OS Command Injection in CVE-2026-45632 (CVE-2026-45632)
OS command injection in CVE-2026-45632 (CVE-2026-45632). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45631 |
|
Vulnerability in CVE-2026-45631 (CVE-2026-45631)
vulnerability in CVE-2026-45631 (CVE-2026-45631). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.3` or later.
|
| CVE-2026-45630 |
|
OS Command Injection in CVE-2026-45630 (CVE-2026-45630)
OS command injection in CVE-2026-45630 (CVE-2026-45630). Confidential information can be exposed externally.
|
| CVE-2026-45629 |
|
OS Command Injection in CVE-2026-45629 (CVE-2026-45629)
OS command injection in CVE-2026-45629 (CVE-2026-45629). Confidential information can be exposed externally.
|
| CVE-2026-45628 |
|
Vulnerability in c (CVE-2026-45628)
vulnerability in c (CVE-2026-45628). Confidential information can be exposed externally.
|
| CVE-2026-43917 |
|
Vulnerability in CVE-2026-43917 (CVE-2026-43917)
vulnerability in CVE-2026-43917 (CVE-2026-43917). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47139 |
|
Vulnerability in vm2 (CVE-2026-47139)
vulnerability in vm2 (CVE-2026-47139). Confidential information can be exposed externally. Exploitable via ``NodeVM``. Mitigation: upgrade to `3.11.4` or later.
|
| RXSA-2024:3138 |
|
Vulnerability in kernel (RXSA-2024:3138)
vulnerability in kernel (RXSA-2024:3138). Confidential information can be exposed externally. Mitigation: upgrade to `0:4.18.0-553.123.1.el8_10.cloud.0.1` or later.
|
| RLSA-2025:11884 |
|
Vulnerability in unbound (RLSA-2025:11884)
vulnerability in unbound (RLSA-2025:11884). Data can be tampered with by attackers. Mitigation: upgrade to `0:1.16.2-5.9.el8` or later.
|
| RLSA-2024:8834 |
|
Vulnerability in python-gevent (RLSA-2024:8834)
vulnerability in python-gevent (RLSA-2024:8834). Confidential information can be exposed externally. Mitigation: upgrade to `0:1.2.2-5.el8` or later.
|
| CVE-2026-47140 |
|
Vulnerability in vm2 (CVE-2026-47140)
vulnerability in vm2 (CVE-2026-47140). Successful exploitation can lead to full system takeover. Exploitable via ``NodeVM``. Mitigation: upgrade to `3.11.4` or later.
|
| SUSE-SU-2026:21919-1 |
|
Vulnerability in SUSE-SU-2026:21919-1 (SUSE-SU-2026:21919-1)
vulnerability in SUSE-SU-2026:21919-1 (SUSE-SU-2026:21919-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47210 |
|
Vulnerability in vm2 (CVE-2026-47210)
vulnerability in vm2 (CVE-2026-47210). Successful exploitation can lead to full system takeover. Exploitable via ``vm2``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47137 |
|
Vulnerability in vm2 (CVE-2026-47137)
vulnerability in vm2 (CVE-2026-47137). Successful exploitation can lead to full system takeover. Exploitable via ``nodevm.js``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47209 |
|
Vulnerability in vm2 (CVE-2026-47209)
vulnerability in vm2 (CVE-2026-47209). Data can be tampered with by attackers. Exploitable via ``BaseHandler.set``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47135 |
|
Vulnerability in vm2 (CVE-2026-47135)
vulnerability in vm2 (CVE-2026-47135). Confidential information can be exposed externally. Exploitable via ``Symbol.for``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47208 |
|
Vulnerability in vm2 (CVE-2026-47208)
vulnerability in vm2 (CVE-2026-47208). Successful exploitation can lead to full system takeover. Exploitable via ``localPromise``. Mitigation: upgrade to `3.11.4` or later.
|
| GHSA-q3fm-4wcw-g57x |
|
Vulnerability in vm2 (GHSA-q3fm-4wcw-g57x)
vulnerability in vm2 (GHSA-q3fm-4wcw-g57x). Risk of unauthorized operations or information disclosure. Exploitable via ``defaultSandboxPrepareStackTrace``. Mitigation: upgrade to `3.11.4` or later.
|
| SUSE-SU-2026:21916-1 |
|
Vulnerability in SUSE-SU-2026:21916-1 (SUSE-SU-2026:21916-1)
vulnerability in SUSE-SU-2026:21916-1 (SUSE-SU-2026:21916-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47131 |
|
Vulnerability in vm2 (CVE-2026-47131)
vulnerability in vm2 (CVE-2026-47131). Successful exploitation can lead to full system takeover. Exploitable via ``ERR_INVALID_ARG_TYPE``. Mitigation: upgrade to `3.11.4` or later.
|
| CGA-jr7v-2rm5-rhv6 |
|
CGA-jr7v-2rm5-rhv6 |
| CGA-r4m7-8gc2-ch3p |
|
CGA-r4m7-8gc2-ch3p |
| CVE-2026-47200 |
|
Vulnerability in nuxt (CVE-2026-47200)
vulnerability in nuxt (CVE-2026-47200). Risk of unauthorized operations or information disclosure. Exploitable via ``experimental.componentIslands``. Mitigation: upgrade to `4.4.6` or later.
|
| CVE-2026-45742 |
|
Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45742)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45742). Risk of unauthorized operations or information disclosure. Exploitable via ``downloadFrom``. Mitigation: upgrade to `8.33.0` or later.
|
| CVE-2026-45741 |
|
Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45741)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45741). Confidential information can be exposed externally.
|
| CVE-2026-44829 |
|
Path Traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829)
path traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829). Data can be tampered with by attackers. Exploitable via ``filepath.Base``. Mitigation: upgrade to `8.33.0` or later.
|
| openSUSE-SU-2026:20847-1 |
|
Vulnerability in openSUSE-SU-2026:20847-1 (openSUSE-SU-2026:20847-1)
vulnerability in openSUSE-SU-2026:20847-1 (openSUSE-SU-2026:20847-1). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:21877-1 |
|
Vulnerability in SUSE-SU-2026:21877-1 (SUSE-SU-2026:21877-1)
vulnerability in SUSE-SU-2026:21877-1 (SUSE-SU-2026:21877-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9194 |
|
Vulnerability in CVE-2026-9194 (CVE-2026-9194)
vulnerability in CVE-2026-9194 (CVE-2026-9194). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-48501 |
|
Vulnerability in golang-github-cli-go-gh (DEBIAN-CVE-2026-48501)
vulnerability in golang-github-cli-go-gh (DEBIAN-CVE-2026-48501). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `2.93.0` or later.
|
| CVE-2026-45663 |
|
Command Injection in CVE-2026-45663 (CVE-2026-45663)
command injection in CVE-2026-45663 (CVE-2026-45663). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45662 |
|
OS Command Injection in CVE-2026-45662 (CVE-2026-45662)
OS command injection in CVE-2026-45662 (CVE-2026-45662). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44962 |
|
Vulnerability in privilege-escalation (CVE-2026-44962)
vulnerability in privilege-escalation (CVE-2026-44962). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39276 |
|
Path Traversal in path-traversal (CVE-2026-39276)
path traversal in path-traversal (CVE-2026-39276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39229 |
|
SQL Injection in sqli (CVE-2026-39229)
SQL injection in sqli (CVE-2026-39229). Confidential information can be exposed externally.
|
| CVE-2026-36324 |
|
Cross-Site Scripting (XSS) in CVE-2026-36324 (CVE-2026-36324)
cross-site scripting in CVE-2026-36324 (CVE-2026-36324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35674 |
|
Vulnerability in openclaw (CVE-2026-35674)
vulnerability in openclaw (CVE-2026-35674). Successful exploitation can lead to full system takeover. Exploitable via ``operator.approvals``. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-35673 |
|
Vulnerability in openclaw (CVE-2026-35673)
vulnerability in openclaw (CVE-2026-35673). Confidential information can be exposed externally. Mitigation: upgrade to `2026.4.29` or later.
|
| CVE-2026-35630 |
|
Vulnerability in openclaw (CVE-2026-35630)
vulnerability in openclaw (CVE-2026-35630). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-34507 |
|
Authorization Flaw in openclaw (CVE-2026-34507)
vulnerability in openclaw (CVE-2026-34507). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.4.29` or later.
|
| CVE-2026-33386 |
|
Cross-Site Scripting (XSS) in CVE-2026-33386 (CVE-2026-33386)
cross-site scripting in CVE-2026-33386 (CVE-2026-33386). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33384 |
|
Vulnerability in CVE-2026-33384 (CVE-2026-33384)
vulnerability in CVE-2026-33384 (CVE-2026-33384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32906 |
|
Authorization Flaw in openclaw (CVE-2026-32906)
vulnerability in openclaw (CVE-2026-32906). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.12` or later.
|
| CVE-2026-32905 |
|
Authorization Flaw in openclaw (CVE-2026-32905)
vulnerability in openclaw (CVE-2026-32905). Confidential information can be exposed externally. Mitigation: upgrade to `2026.5.4` or later.
|
| CVE-2026-10101 |
|
Vulnerability in CVE-2026-10101 (CVE-2026-10101)
vulnerability in CVE-2026-10101 (CVE-2026-10101). Confidential information can be exposed externally. Exploitable via ``view``.
|
| CVE-2026-10099 |
|
Vulnerability in CVE-2026-10099 (CVE-2026-10099)
vulnerability in CVE-2026-10099 (CVE-2026-10099). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10069 |
|
Vulnerability in CVE-2026-10069 (CVE-2026-10069)
vulnerability in CVE-2026-10069 (CVE-2026-10069). Risk of unauthorized operations or information disclosure.
|