Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
DEBIAN-CVE-2026-42627 Vulnerability in armnn (DEBIAN-CVE-2026-42627)
vulnerability in armnn (DEBIAN-CVE-2026-42627). Risk of unauthorized operations or information disclosure.
CVE-2026-39965 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39965)
SSRF in ssrf (CVE-2026-39965). Confidential information can be exposed externally.
GHSA-3c6q-cfmj-gmcf Vulnerability in mmt-static (GHSA-3c6q-cfmj-gmcf)
vulnerability in mmt-static (GHSA-3c6q-cfmj-gmcf). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
MAL-2026-4612 Vulnerability in mmt-static (MAL-2026-4612)
vulnerability in mmt-static (MAL-2026-4612). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env``.
CGA-fg78-f8xv-6cr2 CGA-fg78-f8xv-6cr2
CLSA-2026-1779372929 Vulnerability in curl (CLSA-2026-1779372929)
vulnerability in curl (CLSA-2026-1779372929). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `7.76.1-31.el9_2.1.tuxcare.els12` or later.
CLSA-2026-1779372207 Vulnerability in curl (CLSA-2026-1779372207)
vulnerability in curl (CLSA-2026-1779372207). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `7.76.1-31.el9_6.1.tuxcare.els12` or later.
CVE-2026-46715 Authentication Bypass in Flask-Security-Too (CVE-2026-46715)
authentication bypass in Flask-Security-Too (CVE-2026-46715). Risk of unauthorized operations or information disclosure. Exploitable via `POST /change-username`. Mitigation: upgrade to `5.8.1` or later.
CVE-2026-9255 Vulnerability in Amazon aws (CVE-2026-9255)
vulnerability in Amazon aws (CVE-2026-9255). Successful exploitation can lead to full system takeover.
CVE-2026-70646 Vulnerability in aiosend (CVE-2026-70646)
vulnerability in aiosend (CVE-2026-70646). Risk of unauthorized operations or information disclosure. Exploitable via ``aiosend``. Mitigation: upgrade to `3.0.7` or later.
CVE-2026-48777 Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-48777)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-48777). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /public/api/resources`. Mitigation: upgrade to `0.0.0-20260518193514-28e9b81e438e` or later.
MAL-2026-4629 Vulnerability in openmct-couch-plugin (MAL-2026-4629)
vulnerability in openmct-couch-plugin (MAL-2026-4629). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
CVE-2026-34207 Vulnerability in ssrf (CVE-2026-34207)
vulnerability in ssrf (CVE-2026-34207). Confidential information can be exposed externally.
CVE-2026-33712 Vulnerability in ssrf (CVE-2026-33712)
vulnerability in ssrf (CVE-2026-33712). Confidential information can be exposed externally. Exploitable via `POST /api/v1/typebots/{typebotId}/preview/startChat`.
CVE-2026-32253 Authentication Bypass in cpp (CVE-2026-32253)
authentication bypass in cpp (CVE-2026-32253). Successful exploitation can lead to full system takeover.
CVE-2026-28444 Vulnerability in CVE-2026-28444 (CVE-2026-28444)
vulnerability in CVE-2026-28444 (CVE-2026-28444). Confidential information can be exposed externally.
MAL-2026-4555 Vulnerability in events-router (MAL-2026-4555)
vulnerability in events-router (MAL-2026-4555). Risk of unauthorized operations or information disclosure. Exploitable via ``events``.
MAL-2026-4646 Vulnerability in prisma-client-python (MAL-2026-4646)
vulnerability in prisma-client-python (MAL-2026-4646). Risk of unauthorized operations or information disclosure. Exploitable via ``finally``.
MAL-2026-4658 Vulnerability in rapyd-client (MAL-2026-4658)
vulnerability in rapyd-client (MAL-2026-4658). Risk of unauthorized operations or information disclosure. Exploitable via ``access_key``.
MAL-2026-4692 Vulnerability in thevoid (MAL-2026-4692)
vulnerability in thevoid (MAL-2026-4692). Risk of unauthorized operations or information disclosure.
CLSA-2026-1779467733 unbound: Fix of CVE-2026-33278
unbound: Fix of CVE-2026-33278
CLSA-2026-1779467653 Vulnerability in libssh (CLSA-2026-1779467653)
vulnerability in libssh (CLSA-2026-1779467653). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.4-15.el9_6.tuxcare.els8` or later.
MAL-2026-4508 Vulnerability in cdk-insights (MAL-2026-4508)
vulnerability in cdk-insights (MAL-2026-4508). Risk of unauthorized operations or information disclosure. Exploitable via ``writeFileSync``.
CLSA-2026-1779467038 unbound: Fix of CVE-2026-33278
unbound: Fix of CVE-2026-33278
DEBIAN-CVE-2026-42502 Vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-42502)
vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-42502). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.55.0-1` or later.
DEBIAN-CVE-2026-27136 Vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-27136)
vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-27136). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.55.0-1` or later.
DEBIAN-CVE-2026-42506 Vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-42506)
vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-42506). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.55.0-1` or later.
DEBIAN-CVE-2026-39821 Vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-39821)
vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-39821). Confidential information can be exposed externally. Mitigation: upgrade to `1:0.55.0-1` or later.
DEBIAN-CVE-2026-25681 Vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-25681)
vulnerability in golang-golang-x-net (DEBIAN-CVE-2026-25681). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.55.0-1` or later.
DEBIAN-CVE-2026-25680 Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
CLSA-2026-1779466465 Vulnerability in rsync (CLSA-2026-1779466465)
vulnerability in rsync (CLSA-2026-1779466465). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.5-3.el9_6.tuxcare.els3` or later.
CLSA-2026-1779465893 Vulnerability in postgresql (CLSA-2026-1779465893)
vulnerability in postgresql (CLSA-2026-1779465893). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.24-9.0.3.el7_9.tuxcare.els3` or later.
CLSA-2026-1779465604 Vulnerability in postgresql (CLSA-2026-1779465604)
vulnerability in postgresql (CLSA-2026-1779465604). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.24-9.0.3.el7_9.tuxcare.els3` or later.
ROOT-APP-PYPI-CVE-2026-40192 Vulnerability in rootio-pillow (ROOT-APP-PYPI-CVE-2026-40192)
vulnerability in rootio-pillow (ROOT-APP-PYPI-CVE-2026-40192). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.1.0+root.io.1, 12.1.0+root.io.2, 10.3.0+root.io.1, 10.3.0+root.io.2, 12.1.0+root.io.3, 12.1.0+root.io.4, 10.4.0+root.io.1, 10.4.0+root.io.2` or later.
ROOT-APP-PYPI-CVE-2026-42311 Vulnerability in rootio-pillow (ROOT-APP-PYPI-CVE-2026-42311)
vulnerability in rootio-pillow (ROOT-APP-PYPI-CVE-2026-42311). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `12.1.0+root.io.2, 10.3.0+root.io.1, 10.3.0+root.io.2, 12.1.0+root.io.3, 12.1.0+root.io.4, 10.4.0+root.io.2` or later.
ROOT-APP-PYPI-CVE-2026-25990 Vulnerability in rootio-pillow (ROOT-APP-PYPI-CVE-2026-25990)
vulnerability in rootio-pillow (ROOT-APP-PYPI-CVE-2026-25990). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.3.0+root.io.1, 12.1.0+root.io.1, 12.1.0+root.io.2, 10.3.0+root.io.1, 10.3.0+root.io.2, 11.3.0+root.io.2, 12.1.0+root.io.3, 12.1.0+root.io.4, 10.4.0+root.io.1, 10.4.0+root.io.2` or later.
CLSA-2026-1779465287 Vulnerability in tomcat (CLSA-2026-1779465287)
vulnerability in tomcat (CLSA-2026-1779465287). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:9.0.62-12.el9_2.1.tuxcare.els1` or later.
CLSA-2026-1778861508 Vulnerability in gimp (CLSA-2026-1778861508)
vulnerability in gimp (CLSA-2026-1778861508). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:2.99.8-4.el9_6.2.tuxcare.els11` or later.
CVE-2026-46670 SQL Injection in yeswiki/yeswiki (CVE-2026-46670)
SQL injection in yeswiki/yeswiki (CVE-2026-46670). Successful exploitation can lead to full system takeover. Exploitable via ``INSERT``. Mitigation: upgrade to `4.6.4` or later.
CLSA-2026-1778860714 Vulnerability in gimp (CLSA-2026-1778860714)
vulnerability in gimp (CLSA-2026-1778860714). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:2.99.8-4.el9.2.tuxcare.els11` or later.
CGA-j6q3-2q44-hhxx CGA-j6q3-2q44-hhxx
MAL-2026-4610 Vulnerability in midcorp (MAL-2026-4610)
vulnerability in midcorp (MAL-2026-4610). Risk of unauthorized operations or information disclosure. Exploitable via ``fast``.
MINI-cjxc-jwc7-rpvg MINI-cjxc-jwc7-rpvg
MINI-4gpf-9r4p-5q8h MINI-4gpf-9r4p-5q8h
MINI-jhj4-7cx6-9c58 MINI-jhj4-7cx6-9c58
MINI-xfwr-cq4j-fq93 MINI-xfwr-cq4j-fq93
MINI-wm42-phmr-7jgh MINI-wm42-phmr-7jgh
MINI-mqgh-vcc7-6v43 MINI-mqgh-vcc7-6v43
MINI-wqc9-8frf-9gmr MINI-wqc9-8frf-9gmr
MINI-g35w-pr87-fq2x MINI-g35w-pr87-fq2x

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →