Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MAL-2026-4413 Vulnerability in @onerjs/serializers (MAL-2026-4413)
vulnerability in @onerjs/serializers (MAL-2026-4413). Risk of unauthorized operations or information disclosure. Exploitable via ``homepage``.
MAL-2026-4410 Vulnerability in @onerjs/addons (MAL-2026-4410)
vulnerability in @onerjs/addons (MAL-2026-4410). Risk of unauthorized operations or information disclosure. Exploitable via ``homepage``.
MAL-2026-4415 Vulnerability in @onerjs/smart-filters-blocks (MAL-2026-4415)
vulnerability in @onerjs/smart-filters-blocks (MAL-2026-4415). Risk of unauthorized operations or information disclosure.
MINI-h376-c7fg-2cq5 MINI-h376-c7fg-2cq5
MINI-rcp9-fr94-3gjq MINI-rcp9-fr94-3gjq
MINI-6jpm-q6fw-qmxc MINI-6jpm-q6fw-qmxc
MINI-892j-rh7g-9fcc MINI-892j-rh7g-9fcc
MINI-vmr8-h46v-fxhr MINI-vmr8-h46v-fxhr
MINI-m3rp-mxc2-jx26 MINI-m3rp-mxc2-jx26
CGA-4pmp-f695-fjm9 CGA-4pmp-f695-fjm9
MAL-2026-4264 Vulnerability in dds-js-idl (MAL-2026-4264)
vulnerability in dds-js-idl (MAL-2026-4264). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
GHSA-c7hc-8fj8-hjr6 Vulnerability in dds-js-idl-types (GHSA-c7hc-8fj8-hjr6)
vulnerability in dds-js-idl-types (GHSA-c7hc-8fj8-hjr6). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
MAL-2026-4548 Vulnerability in dds-js-idl-types (MAL-2026-4548)
vulnerability in dds-js-idl-types (MAL-2026-4548). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
MAL-2026-4683 Vulnerability in tax4all-components (MAL-2026-4683)
vulnerability in tax4all-components (MAL-2026-4683). Risk of unauthorized operations or information disclosure.
MAL-2026-4369 Vulnerability in @blckrose/baileys (MAL-2026-4369)
vulnerability in @blckrose/baileys (MAL-2026-4369). Risk of unauthorized operations or information disclosure.
CLSA-2026-1779497454 Vulnerability in tigervnc (CLSA-2026-1779497454)
vulnerability in tigervnc (CLSA-2026-1779497454). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.14.1-9.el9_6.tuxcare.els3` or later.
CLSA-2026-1779496075 vim: Fix of CVE-2026-45130
vim: Fix of CVE-2026-45130
CVE-2026-47124 Information Disclosure in github.com/nezhahq/nezha (CVE-2026-47124)
vulnerability in github.com/nezhahq/nezha (CVE-2026-47124). Confidential information can be exposed externally. Exploitable via `GET /api/v1/server`. Mitigation: upgrade to `1.14.15-0.20260517034128-05e5da253519` or later.
CVE-2026-46716 Privilege Escalation in github.com/nezhahq/nezha (CVE-2026-46716)
vulnerability in github.com/nezhahq/nezha (CVE-2026-46716). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/cron`. Mitigation: upgrade to `1.14.15-0.20260517022419-d7526351cf97` or later.
CVE-2026-47125 Vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-47125)
vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-47125). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/environments/{id}/templates/variables`. Mitigation: upgrade to `1.19.2` or later.
GHSA-7vwr-8v2c-gjvr Vulnerability in loading-session (GHSA-7vwr-8v2c-gjvr)
vulnerability in loading-session (GHSA-7vwr-8v2c-gjvr). Risk of unauthorized operations or information disclosure. Exploitable via ``DEV_API_KEY``.
MAL-2026-4600 Vulnerability in loading-session (MAL-2026-4600)
vulnerability in loading-session (MAL-2026-4600). Risk of unauthorized operations or information disclosure. Exploitable via ``DEV_API_KEY``.
GHSA-ggxf-37hm-9wqf SSRF (Server-Side Request Forgery) in instagrapi (GHSA-ggxf-37hm-9wqf)
SSRF in instagrapi (GHSA-ggxf-37hm-9wqf). Confidential information can be exposed externally. Mitigation: upgrade to `2.6.9` or later.
CVE-2026-47157 SSRF (Server-Side Request Forgery) in aiograpi (CVE-2026-47157)
SSRF in aiograpi (CVE-2026-47157). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.10` or later.
CVE-2026-47138 Vulnerability in parse-server (CVE-2026-47138)
vulnerability in parse-server (CVE-2026-47138). Risk of unauthorized operations or information disclosure. Exploitable via ``clientSDK``. Mitigation: upgrade to `8.6.77` or later.
CLSA-2026-1779495062 vim: Fix of CVE-2026-45130
vim: Fix of CVE-2026-45130
CVE-2026-47120 Vulnerability in github.com/nezhahq/nezha (CVE-2026-47120)
vulnerability in github.com/nezhahq/nezha (CVE-2026-47120). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/alert-rule`. Mitigation: upgrade to `1.14.15-0.20260517022419-d7526351cf97` or later.
CVE-2026-46717 Authorization Flaw in github.com/nezhahq/nezha (CVE-2026-46717)
vulnerability in github.com/nezhahq/nezha (CVE-2026-46717). Confidential information can be exposed externally. Exploitable via `POST /api/v1/notification`. Mitigation: upgrade to `1.14.15-0.20260517022419-d06d539d34c1` or later.
GHSA-hgq8-x9x4-jfpr Vulnerability in async-pipeline-builder (GHSA-hgq8-x9x4-jfpr)
vulnerability in async-pipeline-builder (GHSA-hgq8-x9x4-jfpr). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-p8hf-5qq9-8g8h Vulnerability in workspace-config-loader (GHSA-p8hf-5qq9-8g8h)
vulnerability in workspace-config-loader (GHSA-p8hf-5qq9-8g8h). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-fxc5-vwp2-3c24 Vulnerability in build-scripts-utils (GHSA-fxc5-vwp2-3c24)
vulnerability in build-scripts-utils (GHSA-fxc5-vwp2-3c24). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-65j3-6fx4-8q2j Vulnerability in llm-context-compressor (GHSA-65j3-6fx4-8q2j)
vulnerability in llm-context-compressor (GHSA-65j3-6fx4-8q2j). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-gc4v-cqp6-5672 Vulnerability in dev-env-bootstrapper (GHSA-gc4v-cqp6-5672)
vulnerability in dev-env-bootstrapper (GHSA-gc4v-cqp6-5672). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-5frg-fmcq-p9cg Vulnerability in prompt-engineering-toolkit (GHSA-5frg-fmcq-p9cg)
vulnerability in prompt-engineering-toolkit (GHSA-5frg-fmcq-p9cg). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-6fxh-5965-3xf4 Vulnerability in token-usage-tracker (GHSA-6fxh-5965-3xf4)
vulnerability in token-usage-tracker (GHSA-6fxh-5965-3xf4). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-95m4-gh9m-px5h Vulnerability in project-init-tools (GHSA-95m4-gh9m-px5h)
vulnerability in project-init-tools (GHSA-95m4-gh9m-px5h). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-vxfv-w8fq-239r Vulnerability in node-setup-helpers (GHSA-vxfv-w8fq-239r)
vulnerability in node-setup-helpers (GHSA-vxfv-w8fq-239r). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
GHSA-vvr8-673r-w4j2 Vulnerability in model-switch-router (GHSA-vvr8-673r-w4j2)
vulnerability in model-switch-router (GHSA-vvr8-673r-w4j2). Risk of unauthorized operations or information disclosure. Exploitable via ``asdxzxc``.
openSUSE-SU-2026:10842-1 Vulnerability in apptainer (openSUSE-SU-2026:10842-1)
vulnerability in apptainer (openSUSE-SU-2026:10842-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.5-5.1` or later.
openSUSE-SU-2026:10843-1 Vulnerability in hauler (openSUSE-SU-2026:10843-1)
vulnerability in hauler (openSUSE-SU-2026:10843-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.3-3.1` or later.
openSUSE-SU-2026:10844-1 Vulnerability in jfrog-cli (openSUSE-SU-2026:10844-1)
vulnerability in jfrog-cli (openSUSE-SU-2026:10844-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.104.1-1.1` or later.
openSUSE-SU-2026:10845-1 Vulnerability in mcphost (openSUSE-SU-2026:10845-1)
vulnerability in mcphost (openSUSE-SU-2026:10845-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.34.0-5.1` or later.
openSUSE-SU-2026:10847-1 Vulnerability in rqlite (openSUSE-SU-2026:10847-1)
vulnerability in rqlite (openSUSE-SU-2026:10847-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.1.0-1.1` or later.
openSUSE-SU-2026:10846-1 Vulnerability in perl-YAML-Syck (openSUSE-SU-2026:10846-1)
vulnerability in perl-YAML-Syck (openSUSE-SU-2026:10846-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.450.0-4.1` or later.
GHSA-fpr5-4jhx-2qw9 Vulnerability in chai-as-repaired (GHSA-fpr5-4jhx-2qw9)
vulnerability in chai-as-repaired (GHSA-fpr5-4jhx-2qw9). Risk of unauthorized operations or information disclosure. Exploitable via ``DEV_API_KEY``.
MAL-2026-4512 Vulnerability in chai-as-repaired (MAL-2026-4512)
vulnerability in chai-as-repaired (MAL-2026-4512). Risk of unauthorized operations or information disclosure. Exploitable via ``DEV_API_KEY``.
CLSA-2026-1779494089 Vulnerability in libecpg-compat3 (CLSA-2026-1779494089)
vulnerability in libecpg-compat3 (CLSA-2026-1779494089). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.22-0ubuntu0.20.04.4+tuxcare.els1` or later.
CLSA-2026-1779493861 Vulnerability in postgresql (CLSA-2026-1779493861)
vulnerability in postgresql (CLSA-2026-1779493861). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `13.23-1.el9_6.tuxcare.els6` or later.
DEBIAN-CVE-2026-41149 Vulnerability in node-mermaid (DEBIAN-CVE-2026-41149)
vulnerability in node-mermaid (DEBIAN-CVE-2026-41149). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-41148 Vulnerability in node-mermaid (DEBIAN-CVE-2026-41148)
vulnerability in node-mermaid (DEBIAN-CVE-2026-41148). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →