Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-vjjr-3gh4-v7c4 |
|
MINI-vjjr-3gh4-v7c4 |
| MINI-8mp8-2ccg-jxvg |
|
MINI-8mp8-2ccg-jxvg |
| MINI-3pff-62pv-rvr5 |
|
MINI-3pff-62pv-rvr5 |
| MINI-2wv4-prc5-87pw |
|
MINI-2wv4-prc5-87pw |
| MINI-2j72-jrgh-qhqr |
|
MINI-2j72-jrgh-qhqr |
| MINI-9xqj-rj6g-22ff |
|
MINI-9xqj-rj6g-22ff |
| MINI-9fgx-f7w7-cp6q |
|
MINI-9fgx-f7w7-cp6q |
| MINI-cx7r-96p5-4pm2 |
|
MINI-cx7r-96p5-4pm2 |
| MINI-6r92-rghw-5h8h |
|
MINI-6r92-rghw-5h8h |
| MINI-mr42-xm4f-5p88 |
|
MINI-mr42-xm4f-5p88 |
| MINI-ph9p-r4v7-7hg5 |
|
MINI-ph9p-r4v7-7hg5 |
| MINI-42rg-2r2x-3q7p |
|
MINI-42rg-2r2x-3q7p |
| MINI-4vv9-9wv4-mv5r |
|
MINI-4vv9-9wv4-mv5r |
| CVE-2026-49094 |
|
Vulnerability in elk (CVE-2026-49094)
vulnerability in elk (CVE-2026-49094). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.19.16` or later.
|
| CVE-2026-9645 |
|
OS Command Injection in scadabr (CVE-2026-9645)
OS command injection in scadabr (CVE-2026-9645). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49093 |
|
SSRF (Server-Side Request Forgery) in elk (CVE-2026-49093)
SSRF in elk (CVE-2026-49093). Confidential information can be exposed externally. Mitigation: upgrade to `9.3.3` or later.
|
| CVE-2026-9646 |
|
A reflected cross-site scripting issue exists in URL handling.
A reflected cross-site scripting issue exists in URL handling.
|
| CVE-2026-46843 |
|
Vulnerability in c (CVE-2026-46843)
vulnerability in c (CVE-2026-46843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49095 |
|
Vulnerability in elk (CVE-2026-49095)
vulnerability in elk (CVE-2026-49095). Confidential information can be exposed externally. Mitigation: upgrade to `8.19.16, 9.3.5, 9.4.2` or later.
|
| CVE-2026-46839 |
|
Vulnerability in c (CVE-2026-46839)
vulnerability in c (CVE-2026-46839). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46841 |
|
Information Disclosure in c (CVE-2026-46841)
vulnerability in c (CVE-2026-46841). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46842 |
|
Vulnerability in c (CVE-2026-46842)
vulnerability in c (CVE-2026-46842). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46840 |
|
Vulnerability in c (CVE-2026-46840)
vulnerability in c (CVE-2026-46840). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46837 |
|
Privilege Escalation in c (CVE-2026-46837)
vulnerability in c (CVE-2026-46837). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46835 |
|
Vulnerability in c (CVE-2026-46835)
vulnerability in c (CVE-2026-46835). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46834 |
|
Vulnerability in c (CVE-2026-46834)
vulnerability in c (CVE-2026-46834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46828 |
|
Vulnerability in c (CVE-2026-46828)
vulnerability in c (CVE-2026-46828). Confidential information can be exposed externally.
|
| CVE-2026-46829 |
|
Vulnerability in c (CVE-2026-46829)
vulnerability in c (CVE-2026-46829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46830 |
|
Information Disclosure in c (CVE-2026-46830)
vulnerability in c (CVE-2026-46830). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46823 |
|
Authorization Flaw in c (CVE-2026-46823)
vulnerability in c (CVE-2026-46823). Confidential information can be exposed externally.
|
| CVE-2026-46833 |
|
Vulnerability in c (CVE-2026-46833)
vulnerability in c (CVE-2026-46833). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46826 |
|
Vulnerability in c (CVE-2026-46826)
vulnerability in c (CVE-2026-46826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46827 |
|
Privilege Escalation in c (CVE-2026-46827)
vulnerability in c (CVE-2026-46827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46819 |
|
Vulnerability in c (CVE-2026-46819)
vulnerability in c (CVE-2026-46819). Confidential information can be exposed externally.
|
| CVE-2026-46817 KEV |
|
[KEV] Privilege Escalation in Oracle c (CVE-2026-46817)
vulnerability in Oracle c (CVE-2026-46817). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-46818 |
|
Vulnerability in c (CVE-2026-46818)
vulnerability in c (CVE-2026-46818). Confidential information can be exposed externally.
|
| CVE-2026-46821 |
|
Vulnerability in c (CVE-2026-46821)
vulnerability in c (CVE-2026-46821). Confidential information can be exposed externally.
|
| CVE-2026-46824 |
|
Privilege Escalation in c (CVE-2026-46824)
vulnerability in c (CVE-2026-46824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42398 |
|
SSRF (Server-Side Request Forgery) in elk (CVE-2026-42398)
SSRF in elk (CVE-2026-42398). Confidential information can be exposed externally. Mitigation: upgrade to `9.2.8, 9.3.2` or later.
|
| CVE-2026-46822 |
|
Vulnerability in c (CVE-2026-46822)
vulnerability in c (CVE-2026-46822). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46775 |
|
Vulnerability in c (CVE-2026-46775)
vulnerability in c (CVE-2026-46775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46820 |
|
Vulnerability in c (CVE-2026-46820)
vulnerability in c (CVE-2026-46820). Confidential information can be exposed externally.
|
| CVE-2026-42400 |
|
Vulnerability in elk (CVE-2026-42400)
vulnerability in elk (CVE-2026-42400). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.19.16, 9.3.5, 9.4.2` or later.
|
| CVE-2026-42399 |
|
Vulnerability in elk (CVE-2026-42399)
vulnerability in elk (CVE-2026-42399). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.19.16, 9.3.5` or later.
|
| CVE-2026-34311 |
|
Vulnerability in c (CVE-2026-34311)
vulnerability in c (CVE-2026-34311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35266 |
|
Vulnerability in c (CVE-2026-35266)
vulnerability in c (CVE-2026-35266). Confidential information can be exposed externally.
|
| CVE-2026-35277 |
|
Vulnerability in c (CVE-2026-35277)
vulnerability in c (CVE-2026-35277). Confidential information can be exposed externally.
|
| CVE-2026-5394 |
|
SQL Injection in pimcore/pimcore (CVE-2026-5394)
SQL injection in pimcore/pimcore (CVE-2026-5394). Risk of unauthorized operations or information disclosure. Exploitable via `POST /pimcore-studio/api/class/definition/configuration-view/detail/1/import`. Mitigation: upgrade to `2026.1.3` or later.
|
| CVE-2026-47718 |
|
Authentication Bypass in fuxa-server (CVE-2026-47718)
authentication bypass in fuxa-server (CVE-2026-47718). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/project`. Mitigation: upgrade to `1.3.1` or later.
|
| MAL-2026-4861 |
|
Vulnerability in lib-1779997093-yjeeqn (MAL-2026-4861)
vulnerability in lib-1779997093-yjeeqn (MAL-2026-4861). Risk of unauthorized operations or information disclosure.
|