Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-25077 Code Injection in apache (CVE-2026-25077)
code injection in apache (CVE-2026-25077). Risk of unauthorized operations or information disclosure.
CVE-2025-69233 Vulnerability in apache (CVE-2025-69233)
vulnerability in apache (CVE-2025-69233). Risk of unauthorized operations or information disclosure.
CVE-2025-66467 Vulnerability in apache (CVE-2025-66467)
vulnerability in apache (CVE-2025-66467). Successful exploitation can lead to full system takeover.
CVE-2025-66172 Vulnerability in CVE-2025-66172 (CVE-2025-66172)
vulnerability in CVE-2025-66172 (CVE-2025-66172). Confidential information can be exposed externally.
CVE-2025-66171 Vulnerability in CVE-2025-66171 (CVE-2025-66171)
vulnerability in CVE-2025-66171 (CVE-2025-66171). Confidential information can be exposed externally.
CVE-2025-66170 Authorization Flaw in CVE-2025-66170 (CVE-2025-66170)
vulnerability in CVE-2025-66170 (CVE-2025-66170). Confidential information can be exposed externally.
CVE-2022-50994 OS Command Injection in CVE-2022-50994 (CVE-2022-50994)
OS command injection in CVE-2022-50994 (CVE-2022-50994). Successful exploitation can lead to full system takeover.
JLSEC-2026-491 Vulnerability in LittleCMS_jll (JLSEC-2026-491)
vulnerability in LittleCMS_jll (JLSEC-2026-491). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.19.0+0` or later.
JLSEC-2026-490 Vulnerability in LittleCMS_jll (JLSEC-2026-490)
vulnerability in LittleCMS_jll (JLSEC-2026-490). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.12.0+0` or later.
ROOT-APP-PYPI-CVE-2026-41182 Vulnerability in rootio-langsmith (ROOT-APP-PYPI-CVE-2026-41182)
vulnerability in rootio-langsmith (ROOT-APP-PYPI-CVE-2026-41182). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.7.10+root.io.1, 0.7.13+root.io.1` or later.
ROOT-APP-GOBINARY-CVE-2024-40635 Vulnerability in rootio-github.com/containerd/containerd (ROOT-APP-GOBINARY-CVE-2024-40635)
vulnerability in rootio-github.com/containerd/containerd (ROOT-APP-GOBINARY-CVE-2024-40635). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `v1.7.18-root.io.1` or later.
ROOT-APP-GOBINARY-CVE-2024-25621 Vulnerability in rootio-github.com/containerd/containerd (ROOT-APP-GOBINARY-CVE-2024-25621)
vulnerability in rootio-github.com/containerd/containerd (ROOT-APP-GOBINARY-CVE-2024-25621). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `v1.7.18-root.io.1` or later.
ROOT-APP-MAVEN-CVE-2026-40976 Vulnerability in io.root.org.springframework.boot:spring-boot (ROOT-APP-MAVEN-CVE-2026-40976)
vulnerability in io.root.org.springframework.boot:spring-boot (ROOT-APP-MAVEN-CVE-2026-40976). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.0.5-root.io.1` or later.
ROOT-APP-MAVEN-CVE-2026-40973 Vulnerability in io.root.org.springframework.boot:spring-boot (ROOT-APP-MAVEN-CVE-2026-40973)
vulnerability in io.root.org.springframework.boot:spring-boot (ROOT-APP-MAVEN-CVE-2026-40973). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.5-root.io.1` or later.
CVE-2026-8153 OS Command Injection in iot-embedded (CVE-2026-8153)
OS command injection in iot-embedded (CVE-2026-8153). Successful exploitation can lead to full system takeover.
CVE-2026-8076 Vulnerability in CVE-2026-8076 (CVE-2026-8076)
vulnerability in CVE-2026-8076 (CVE-2026-8076). Risk of unauthorized operations or information disclosure.
CVE-2026-3318 Open Redirect in CVE-2026-3318 (CVE-2026-3318)
vulnerability in CVE-2026-3318 (CVE-2026-3318). Risk of unauthorized operations or information disclosure.
RLSA-2026:14200 Vulnerability in git-lfs (RLSA-2026:14200)
vulnerability in git-lfs (RLSA-2026:14200). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:3.6.1-8.el9_7.1` or later.
ROOT-APP-NPM-CVE-2026-42033 Vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42033)
vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42033). Confidential information can be exposed externally. Mitigation: upgrade to `1.12.0-root.io.4, 1.12.0-root.io.5, 1.11.0-root.io.9, 1.13.2-root.io.3, 1.12.0-root.io.6, 1.13.2-root.io.4, 1.11.0-root.io.10, 1.13.5-root.io.4, 1.12.1-root.io.6, 1.13.2-root.io.5, 1.15.0-root.io.2` or later.
ROOT-APP-NPM-CVE-2026-42038 Vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42038)
vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42038). Confidential information can be exposed externally. Mitigation: upgrade to `1.13.5-root.io.3, 1.12.0-root.io.4, 1.12.0-root.io.5, 1.11.0-root.io.9, 1.13.2-root.io.3, 1.12.0-root.io.6, 1.13.2-root.io.4, 1.11.0-root.io.10, 1.13.5-root.io.4, 1.12.1-root.io.6, 1.13.2-root.io.5, 1.15.0-root.io.2` or later.
ROOT-APP-NPM-CVE-2026-42039 Vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42039)
vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42039). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.13.5-root.io.3, 1.12.0-root.io.4, 1.12.0-root.io.5, 1.11.0-root.io.9, 1.12.0-root.io.6, 1.11.0-root.io.10, 1.13.5-root.io.4, 1.12.1-root.io.6, 1.13.2-root.io.5, 1.15.0-root.io.2` or later.
ROOT-APP-NPM-CVE-2026-42043 Vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42043)
vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42043). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.11.0-root.io.8, 1.13.5-root.io.3, 1.11.0-root.io.9, 1.12.0-root.io.6, 1.13.2-root.io.4, 1.11.0-root.io.10, 1.15.0-root.io.1, 1.13.6-root.io.1, 1.12.1-root.io.5, 1.13.5-root.io.4, 1.12.1-root.io.6, 1.13.2-root.io.5, 1.15.0-root.io.2` or later.
ROOT-APP-NPM-CVE-2026-42264 Vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42264)
vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42264). Confidential information can be exposed externally. Mitigation: upgrade to `1.13.5-root.io.3, 1.12.0-root.io.4, 1.13.2-root.io.3, 1.12.0-root.io.6, 1.13.2-root.io.4, 1.11.0-root.io.10, 1.13.5-root.io.4, 1.12.1-root.io.6, 1.13.2-root.io.5, 1.15.0-root.io.2` or later.
ROOT-APP-NPM-CVE-2026-42035 Vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42035)
vulnerability in @rootio/axios (ROOT-APP-NPM-CVE-2026-42035). Confidential information can be exposed externally. Mitigation: upgrade to `1.13.5-root.io.3, 1.12.0-root.io.4, 1.12.0-root.io.5, 1.11.0-root.io.9, 1.13.2-root.io.3, 1.12.0-root.io.6, 1.13.2-root.io.4, 1.11.0-root.io.10, 1.13.5-root.io.4, 1.12.1-root.io.6, 1.13.2-root.io.5, 1.15.0-root.io.2` or later.
CVE-2025-13836 Vulnerability in python (CVE-2025-13836)
vulnerability in python (CVE-2025-13836). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.10.20, 3.11.15, 3.12.13, 3.13.11, 3.14.1` or later.
CVE-2025-12084 Vulnerability in python (CVE-2025-12084)
vulnerability in python (CVE-2025-12084). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.10.20, 3.11.15, 3.12.13, 3.13.11, 3.14.2` or later.
ROOT-APP-PYPI-GHSA-rr7j-v2q5-chgv Vulnerability in rootio-langsmith (ROOT-APP-PYPI-GHSA-rr7j-v2q5-chgv)
vulnerability in rootio-langsmith (ROOT-APP-PYPI-GHSA-rr7j-v2q5-chgv). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.4.30+root.io.1, 0.4.10+root.io.1, 0.4.11+root.io.1, 0.4.12+root.io.1, 0.4.17+root.io.1, 0.4.16+root.io.1, 0.4.13+root.io.1, 0.4.15+root.io.1, 0.4.18+root.io.1, 0.4.45+root.io.1, 0.4.25+root.io.1, 0.4.9+root.io.1, 0.4.14+root.io.1, 0.4.21+root.io.1, 0.4.19+root.io.1, 0.4.22+root.io.1, 0.4.26+root.io.1, 0.4.20+root.io.1, 0.4.23+root.io.1, 0.4.27+root.io.1, 0.4.28+root.io.1, 0.6.2+root.io.1, 0.4.29+root.io.1, 0.4.50+root.io.1, 0.4.31+root.io.1, 0.4.24+root.io.1, 0.4.35+root.io.1, 0.4.36+root.io.1, 0.4.34+root.io.1, 0.4.37+root.io.1, 0.4.33+root.io.1, 0.4.32+root.io.1, 0.4.43+root.io.1, 0.4.38+root.io.1, 0.4.41+root.io.1, 0.4.42+root.io.1, 0.4.49+root.io.1, 0.4.46+root.io.1, 0.4.47+root.io.1, 0.4.44+root.io.1, 0.4.48+root.io.1, 0.4.40+root.io.1, 0.4.39+root.io.1, 0.4.51+root.io.1, 0.4.53+root.io.1, 0.4.52+root.io.1, 0.4.54+root.io.1, 0.4.55+root.io.1, 0.4.56+root.io.1, 0.4.57+root.io.1, 0.4.58+root.io.1, 0.7.19+root.io.1, 0.6.0+root.io.1, 0.4.14+root.io.2, 0.7.18+root.io.1, 0.6.1+root.io.1, 0.7.17+root.io.1, 0.5.0+root.io.1, 0.5.2+root.io.1, 0.4.59+root.io.1, 0.5.1+root.io.1, 0.4.60+root.io.1, 0.6.4+root.io.1, 0.6.3+root.io.1, 0.7.24+root.io.1, 0.7.25+root.io.1, 0.7.29+root.io.1, 0.7.26+root.io.1, 0.7.28+root.io.1, 0.7.27+root.io.1, 0.7.17+root.io.2, 0.7.2+root.io.1, 0.7.3+root.io.1, 0.7.4+root.io.1, 0.7.1+root.io.1, 0.7.6+root.io.1, 0.7.0+root.io.1, 0.7.5+root.io.1, 0.7.7+root.io.1, 0.6.5+root.io.1, 0.6.8+root.io.1, 0.6.7+root.io.1, 0.6.6+root.io.1` or later.
CGA-9x29-c5cx-9r8f Vulnerability in uv (CGA-9x29-c5cx-9r8f)
vulnerability in uv (CGA-9x29-c5cx-9r8f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.11.5-r2` or later.
ROOT-APP-PYPI-CVE-2026-44307 Vulnerability in rootio-mako (ROOT-APP-PYPI-CVE-2026-44307)
vulnerability in rootio-mako (ROOT-APP-PYPI-CVE-2026-44307). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.3.11+root.io.1` or later.
CVE-2026-7650 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7650)
cross-site scripting in wordpress (CVE-2026-7650). Risk of unauthorized operations or information disclosure.
CVE-2026-7475 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7475)
cross-site scripting in wordpress (CVE-2026-7475). Risk of unauthorized operations or information disclosure. Exploitable via ``sky_script_content``.
CVE-2026-6213 Vulnerability in CVE-2026-6213 (CVE-2026-6213)
vulnerability in CVE-2026-6213 (CVE-2026-6213). Risk of unauthorized operations or information disclosure.
CVE-2026-5341 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5341)
cross-site scripting in wordpress (CVE-2026-5341). Risk of unauthorized operations or information disclosure. Exploitable via ``strava_nmr_connect``.
MAL-2026-3394 Vulnerability in @gaia-codesearch/gaia-api-typescript (MAL-2026-3394)
vulnerability in @gaia-codesearch/gaia-api-typescript (MAL-2026-3394). Risk of unauthorized operations or information disclosure.
RHSA-2026:14929 Vulnerability in mingw-libtiff (RHSA-2026:14929)
vulnerability in mingw-libtiff (RHSA-2026:14929). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:4.0.9-4.el8_10` or later.
RHSA-2026:14924 Vulnerability in openssh (RHSA-2026:14924)
vulnerability in openssh (RHSA-2026:14924). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:8.0p1-20.el8_8.3` or later.
RHSA-2026:14925 Vulnerability in bpftool (RHSA-2026:14925)
vulnerability in bpftool (RHSA-2026:14925). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:3.10.0-1160.149.1.el7` or later.
RHSA-2026:14926 Vulnerability in kernel (RHSA-2026:14926)
vulnerability in kernel (RHSA-2026:14926). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:6.12.0-211.6.el10nv` or later.
RHSA-2026:14874 Vulnerability in python-markdown (RHSA-2026:14874)
vulnerability in python-markdown (RHSA-2026:14874). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:3.8.2-1.el8pc` or later.
RHSA-2026:14873 Vulnerability in python-markdown (RHSA-2026:14873)
vulnerability in python-markdown (RHSA-2026:14873). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:3.8.2-1.el9pc` or later.
RHSA-2026:14869 Vulnerability in kernel-rt (RHSA-2026:14869)
vulnerability in kernel-rt (RHSA-2026:14869). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:3.10.0-1160.149.1.rt56.1301.el7` or later.
RHSA-2026:14868 Vulnerability in buildah (RHSA-2026:14868)
vulnerability in buildah (RHSA-2026:14868). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:1.39.8-1.el10_0` or later.
RHSA-2026:14858 Vulnerability in libxml2 (RHSA-2026:14858)
vulnerability in libxml2 (RHSA-2026:14858). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.9.7-16.el8_8.13` or later.
RHSA-2026:14836 Vulnerability in nginx (RHSA-2026:14836)
vulnerability in nginx (RHSA-2026:14836). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:1.20.1-14.el9_2.5` or later.
RHSA-2026:14835 Vulnerability in python3.12-django (RHSA-2026:14835)
vulnerability in python3.12-django (RHSA-2026:14835). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:4.2.30-1.el9pc` or later.
RHSA-2026:14823 Vulnerability in kernel (RHSA-2026:14823)
vulnerability in kernel (RHSA-2026:14823). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:2.6.32-754.60.1.el6` or later.
RHSA-2026:14832 Vulnerability in libxml2 (RHSA-2026:14832)
vulnerability in libxml2 (RHSA-2026:14832). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.9.7-9.el8_4.9` or later.
RHSA-2026:14791 Vulnerability in libpng (RHSA-2026:14791)
vulnerability in libpng (RHSA-2026:14791). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:1.6.37-12.el9_7.3` or later.
RHSA-2026:14819 Vulnerability in freeipmi (RHSA-2026:14819)
vulnerability in freeipmi (RHSA-2026:14819). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:1.6.17-1.el9_7` or later.
RHSA-2026:14790 Vulnerability in libpng (RHSA-2026:14790)
vulnerability in libpng (RHSA-2026:14790). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:1.6.40-8.el10_1.3` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →