Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CLSA-2026-1779371632 |
|
Fix CVE(s): CVE-2021-46848
Fix CVE(s): CVE-2021-46848
|
| CVE-2026-41076 |
|
Authentication Bypass in CVE-2026-41076 (CVE-2026-41076)
authentication bypass in CVE-2026-41076 (CVE-2026-41076). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41075 |
|
SQL Injection in sqli (CVE-2026-41075)
SQL injection in sqli (CVE-2026-41075). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41074 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-41074)
vulnerability in csrf (CVE-2026-41074). Data can be tampered with by attackers.
|
| CVE-2026-41073 |
|
Vulnerability in CVE-2026-41073 (CVE-2026-41073)
vulnerability in CVE-2026-41073 (CVE-2026-41073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41071 |
|
Out-of-Bounds Read in struktur (CVE-2026-41071)
vulnerability in struktur (CVE-2026-41071). Confidential information can be exposed externally.
|
| DEBIAN-CVE-2026-41071 |
|
Vulnerability in libheif (DEBIAN-CVE-2026-41071)
vulnerability in libheif (DEBIAN-CVE-2026-41071). Confidential information can be exposed externally.
|
| CGA-xq54-x354-r4ff |
|
CGA-xq54-x354-r4ff |
| CGA-8q5m-m4rj-ffrp |
|
CGA-8q5m-m4rj-ffrp |
| CGA-2q9x-7844-55fr |
|
CGA-2q9x-7844-55fr |
| CGA-xf66-qff9-38xj |
|
CGA-xf66-qff9-38xj |
| CGA-643p-7fr4-26v8 |
|
CGA-643p-7fr4-26v8 |
| CGA-wv5f-4rvf-m364 |
|
CGA-wv5f-4rvf-m364 |
| MAL-2026-4260 |
|
Vulnerability in defi-risk-scanner (MAL-2026-4260)
vulnerability in defi-risk-scanner (MAL-2026-4260). Risk of unauthorized operations or information disclosure. Exploitable via ``__init__.py``.
|
| MAL-2026-4259 |
|
Vulnerability in cryptowallet-safety (MAL-2026-4259)
vulnerability in cryptowallet-safety (MAL-2026-4259). Risk of unauthorized operations or information disclosure. Exploitable via ``__init__.py``.
|
| MAL-2026-4262 |
|
Vulnerability in solidity-build-guard (MAL-2026-4262)
vulnerability in solidity-build-guard (MAL-2026-4262). Risk of unauthorized operations or information disclosure. Exploitable via ``__init__.py``.
|
| MAL-2026-4261 |
|
Vulnerability in eth-security-auditor (MAL-2026-4261)
vulnerability in eth-security-auditor (MAL-2026-4261). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40864 |
|
Cross-Site Request Forgery (CSRF) in jupyterhub (CVE-2026-40864)
vulnerability in jupyterhub (CVE-2026-40864). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.4.5` or later.
|
| CVE-2026-41069 |
|
Out-of-Bounds Read in dos (CVE-2026-41069)
vulnerability in dos (CVE-2026-41069). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-41069 |
|
Vulnerability in libheif (DEBIAN-CVE-2026-41069)
vulnerability in libheif (DEBIAN-CVE-2026-41069). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-40864 |
|
Vulnerability in jupyterhub (DEBIAN-CVE-2026-40864)
vulnerability in jupyterhub (DEBIAN-CVE-2026-40864). Risk of unauthorized operations or information disclosure.
|
| USN-8279-2 |
|
Vulnerability in linux-gcp-5.15 (USN-8279-2)
vulnerability in linux-gcp-5.15 (USN-8279-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.15.0-1108.117~20.04.1` or later.
|
| USN-8297-1 |
|
Vulnerability in linux-gcp-5.15 (USN-8297-1)
vulnerability in linux-gcp-5.15 (USN-8297-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.15.0-1106.115~20.04.1` or later.
|
| CVE-2026-45390 |
|
Path Traversal in tar (CVE-2026-45390)
path traversal in tar (CVE-2026-45390). Confidential information can be exposed externally. Mitigation: upgrade to `3.5.0, 51ceb0a15982993503c169b9d84456fd50eabe99` or later.
|
| CGA-2p5w-fv6v-fcgr |
|
CGA-2p5w-fv6v-fcgr |
| CGA-h5hg-hj67-9gwx |
|
CGA-h5hg-hj67-9gwx |
| CGA-jx7f-g5vj-6w3g |
|
CGA-jx7f-g5vj-6w3g |
| CVE-2026-40610 |
|
Vulnerability in bentoml (CVE-2026-40610)
vulnerability in bentoml (CVE-2026-40610). Confidential information can be exposed externally. Exploitable via ``src_file``. Mitigation: upgrade to `1.4.39` or later.
|
| DEBIAN-CVE-2026-40295 |
|
Vulnerability in ruby-devise (DEBIAN-CVE-2026-40295)
vulnerability in ruby-devise (DEBIAN-CVE-2026-40295). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| MAL-2026-4258 |
|
Vulnerability in @engagehub/core (MAL-2026-4258)
vulnerability in @engagehub/core (MAL-2026-4258). Risk of unauthorized operations or information disclosure. Exploitable via ``engdocs.microsoft.com``.
|
| GHSA-5hgc-pmxv-3xh7 |
|
Vulnerability in @engagehub/core (GHSA-5hgc-pmxv-3xh7)
vulnerability in @engagehub/core (GHSA-5hgc-pmxv-3xh7). Risk of unauthorized operations or information disclosure. Exploitable via ``engdocs.microsoft.com``.
|
| MAL-2026-4639 |
|
Vulnerability in pg-expense-example (MAL-2026-4639)
vulnerability in pg-expense-example (MAL-2026-4639). Risk of unauthorized operations or information disclosure. Exploitable via ``chalk``.
|
| CVE-2026-9291 |
|
Unsafe Deserialization in amazon-braket-sdk (CVE-2026-9291)
vulnerability in amazon-braket-sdk (CVE-2026-9291). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.117.0` or later.
|
| CVE-2026-5289 |
|
Vulnerability in Google chrome (CVE-2026-5289)
vulnerability in Google chrome (CVE-2026-5289). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4632 |
|
Vulnerability in orca-website (MAL-2026-4632)
vulnerability in orca-website (MAL-2026-4632). Risk of unauthorized operations or information disclosure.
|
| USN-8280-2 |
|
Vulnerability in linux-azure-5.4 (USN-8280-2)
vulnerability in linux-azure-5.4 (USN-8280-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.4.0-1163.169~18.04.1` or later.
|
| USN-8281-2 |
|
Vulnerability in linux-azure-4.15 (USN-8281-2)
vulnerability in linux-azure-4.15 (USN-8281-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.15.0-1201.216` or later.
|
| DEBIAN-CVE-2026-48700 |
|
Vulnerability in pcmanfm-qt (DEBIAN-CVE-2026-48700)
vulnerability in pcmanfm-qt (DEBIAN-CVE-2026-48700). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39970 |
|
Cross-Site Scripting (XSS) in CVE-2026-39970 (CVE-2026-39970)
cross-site scripting in CVE-2026-39970 (CVE-2026-39970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39969 |
|
Authentication Bypass in CVE-2026-39969 (CVE-2026-39969)
authentication bypass in CVE-2026-39969 (CVE-2026-39969). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook`.
|
| CVE-2026-39966 |
|
Authorization Flaw in CVE-2026-39966 (CVE-2026-39966)
vulnerability in CVE-2026-39966 (CVE-2026-39966). Confidential information can be exposed externally.
|
| CVE-2026-39967 |
|
Vulnerability in CVE-2026-39967 (CVE-2026-39967)
vulnerability in CVE-2026-39967 (CVE-2026-39967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39968 |
|
Vulnerability in CVE-2026-39968 (CVE-2026-39968)
vulnerability in CVE-2026-39968 (CVE-2026-39968). Confidential information can be exposed externally.
|
| CGA-8485-f6gj-w4gv |
|
CGA-8485-f6gj-w4gv |
| CGA-26wq-6v5j-9p59 |
|
CGA-26wq-6v5j-9p59 |
| GHSA-4r2m-9mxx-rf7q |
|
Vulnerability in peertube-plugin-google-analytics-js (GHSA-4r2m-9mxx-rf7q)
vulnerability in peertube-plugin-google-analytics-js (GHSA-4r2m-9mxx-rf7q). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4636 |
|
Vulnerability in peertube-plugin-google-analytics-js (MAL-2026-4636)
vulnerability in peertube-plugin-google-analytics-js (MAL-2026-4636). Risk of unauthorized operations or information disclosure.
|
| GHSA-pv74-wmjg-4gp8 |
|
Vulnerability in tailwind-style-typography (GHSA-pv74-wmjg-4gp8)
vulnerability in tailwind-style-typography (GHSA-pv74-wmjg-4gp8). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4556 |
|
Vulnerability in express-enrouten-async (MAL-2026-4556)
vulnerability in express-enrouten-async (MAL-2026-4556). Risk of unauthorized operations or information disclosure. Exploitable via ``index.js``.
|
| CVE-2026-39824 |
|
Vulnerability in golang.org/x/sys (CVE-2026-39824)
vulnerability in golang.org/x/sys (CVE-2026-39824). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.44.0` or later.
|