Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| ROOT-OS-DEBIAN-13-CVE-2025-15366 |
|
Vulnerability in rootio-python3.13 (ROOT-OS-DEBIAN-13-CVE-2025-15366)
vulnerability in rootio-python3.13 (ROOT-OS-DEBIAN-13-CVE-2025-15366). Data can be tampered with by attackers. Mitigation: upgrade to `3.13.5-2+deb13u2.root.io.17, 3.13.5-2+deb13u2.root.io.18, 3.13.5-2+deb13u2.root.io.19` or later.
|
| ROOT-OS-DEBIAN-13-CVE-2026-3479 |
|
Vulnerability in rootio-python3.13 (ROOT-OS-DEBIAN-13-CVE-2026-3479)
vulnerability in rootio-python3.13 (ROOT-OS-DEBIAN-13-CVE-2026-3479). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.13.5-2+deb13u2.root.io.17, 3.13.5-2+deb13u2.root.io.18, 3.13.5-2+deb13u2.root.io.19` or later.
|
| ROOT-APP-GOBINARY-CVE-2026-44973 |
|
Vulnerability in rootio-github.com/go-git/go-billy/v5 (ROOT-APP-GOBINARY-CVE-2026-44973)
vulnerability in rootio-github.com/go-git/go-billy/v5 (ROOT-APP-GOBINARY-CVE-2026-44973). Confidential information can be exposed externally. Mitigation: upgrade to `v5.6.0-root.io.1, v5.6.0-root.io.3` or later.
|
| ROOT-APP-PYPI-CVE-2026-41314 |
|
Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41314)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41314). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
|
| ROOT-APP-PYPI-CVE-2026-41312 |
|
Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41312)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41312). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
|
| ROOT-APP-PYPI-CVE-2026-41313 |
|
Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41313)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41313). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
|
| ROOT-APP-PYPI-GHSA-7gw9-cf7v-778f |
|
Vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-7gw9-cf7v-778f)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-7gw9-cf7v-778f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.1, 6.6.0+root.io.6, 6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
|
| ROOT-APP-PYPI-GHSA-x284-j5p8-9c5p |
|
Vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-x284-j5p8-9c5p)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-x284-j5p8-9c5p). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.3, 6.10.1+root.io.1, 6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
|
| ROOT-APP-PYPI-GHSA-4pxv-j86v-mhcw |
|
Vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-4pxv-j86v-mhcw)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-4pxv-j86v-mhcw). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.1, 6.6.0+root.io.6, 6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
|
| MAL-2026-4255 |
|
Vulnerability in cdk-sagemaker-notebook-workflow (MAL-2026-4255)
vulnerability in cdk-sagemaker-notebook-workflow (MAL-2026-4255). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
|
| SUSE-SU-2026:21827-1 |
|
Vulnerability in SUSE-SU-2026:21827-1 (SUSE-SU-2026:21827-1)
vulnerability in SUSE-SU-2026:21827-1 (SUSE-SU-2026:21827-1). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:21756-1 |
|
Vulnerability in SUSE-SU-2026:21756-1 (SUSE-SU-2026:21756-1)
vulnerability in SUSE-SU-2026:21756-1 (SUSE-SU-2026:21756-1). Risk of unauthorized operations or information disclosure.
|
| openSUSE-SU-2026:20788-1 |
|
Vulnerability in openSUSE-SU-2026:20788-1 (openSUSE-SU-2026:20788-1)
vulnerability in openSUSE-SU-2026:20788-1 (openSUSE-SU-2026:20788-1). Risk of unauthorized operations or information disclosure.
|
| GHSA-j689-8wf2-2rj9 |
|
Vulnerability in @tmecontinue/claude (GHSA-j689-8wf2-2rj9)
vulnerability in @tmecontinue/claude (GHSA-j689-8wf2-2rj9). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4457 |
|
Vulnerability in @tmecontinue/claude (MAL-2026-4457)
vulnerability in @tmecontinue/claude (MAL-2026-4457). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4533 |
|
Vulnerability in codebuff-cli (MAL-2026-4533)
vulnerability in codebuff-cli (MAL-2026-4533). Risk of unauthorized operations or information disclosure. Exploitable via ``codebuff``.
|
| ROOT-APP-NPM-CVE-2026-32630 |
|
Vulnerability in @rootio/file-type (ROOT-APP-NPM-CVE-2026-32630)
vulnerability in @rootio/file-type (ROOT-APP-NPM-CVE-2026-32630). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `21.0.0-root.io.1, 21.0.0-root.io.2, 20.4.1-root.io.1, 21.0.0-root.io.3, 20.4.1-root.io.2, 20.5.0-root.io.1, 21.1.0-root.io.1, 21.1.1-root.io.1` or later.
|
| ROOT-APP-NPM-CVE-2026-31808 |
|
Vulnerability in @rootio/file-type (ROOT-APP-NPM-CVE-2026-31808)
vulnerability in @rootio/file-type (ROOT-APP-NPM-CVE-2026-31808). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `21.0.0-root.io.2, 20.4.1-root.io.1, 21.0.0-root.io.3, 20.4.1-root.io.2, 16.5.4-root.io.1, 20.5.0-root.io.1, 21.1.0-root.io.1, 21.1.1-root.io.1` or later.
|
| SUSE-SU-2026:21786-1 |
|
Vulnerability in SUSE-SU-2026:21786-1 (SUSE-SU-2026:21786-1)
vulnerability in SUSE-SU-2026:21786-1 (SUSE-SU-2026:21786-1). Risk of unauthorized operations or information disclosure.
|
| ROOT-APP-MAVEN-CVE-2026-40466 |
|
Vulnerability in io.root.org.apache.activemq:activemq-all (ROOT-APP-MAVEN-CVE-2026-40466)
vulnerability in io.root.org.apache.activemq:activemq-all (ROOT-APP-MAVEN-CVE-2026-40466). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.3-root.io.1, 6.1.3-root.io.2, 6.1.3-root.io.3, 6.1.3-root.io.4` or later.
|
| MAL-2026-4563 |
|
Vulnerability in finkrouter (MAL-2026-4563)
vulnerability in finkrouter (MAL-2026-4563). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4346 |
|
Vulnerability in logger-draft (MAL-2026-4346)
vulnerability in logger-draft (MAL-2026-4346). Risk of unauthorized operations or information disclosure. Exploitable via ``toskypi``.
|
| BELL-CVE-2026-46680 |
|
BELL-CVE-2026-46680 |
| CVE-2026-25608 |
|
Vulnerability in CVE-2026-25608 (CVE-2026-25608)
vulnerability in CVE-2026-25608 (CVE-2026-25608). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25607 |
|
Vulnerability in CVE-2026-25607 (CVE-2026-25607)
vulnerability in CVE-2026-25607 (CVE-2026-25607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25606 |
|
SQL Injection in sqli (CVE-2026-25606)
SQL injection in sqli (CVE-2026-25606). Risk of unauthorized operations or information disclosure.
|
| RHSA-2026:7412 |
|
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
|
| RHSA-2026:20334 |
|
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
|
| RHSA-2026:20299 |
|
Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
|
| RHSA-2026:20130 |
|
Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
|
| RHSA-2026:20129 |
|
Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
|
| RHSA-2026:20074 |
|
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
|
| RHSA-2026:20054 |
|
Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
|
| SUSE-SU-2026:21867-1 |
|
Vulnerability in SUSE-SU-2026:21867-1 (SUSE-SU-2026:21867-1)
vulnerability in SUSE-SU-2026:21867-1 (SUSE-SU-2026:21867-1). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4455 |
|
Vulnerability in @thebros/create-benjamin (MAL-2026-4455)
vulnerability in @thebros/create-benjamin (MAL-2026-4455). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env.OPENAI_API_KEY``.
|
| SUSE-SU-2026:21785-1 |
|
Vulnerability in SUSE-SU-2026:21785-1 (SUSE-SU-2026:21785-1)
vulnerability in SUSE-SU-2026:21785-1 (SUSE-SU-2026:21785-1). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:21897-1 |
|
Vulnerability in SUSE-SU-2026:21897-1 (SUSE-SU-2026:21897-1)
vulnerability in SUSE-SU-2026:21897-1 (SUSE-SU-2026:21897-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `20260512` or later.
|
| MAL-2026-4254 |
|
Vulnerability in reactive-cdk-app (MAL-2026-4254)
vulnerability in reactive-cdk-app (MAL-2026-4254). Risk of unauthorized operations or information disclosure.
|
| ROOT-APP-MAVEN-CVE-2026-43512 |
|
Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43512)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43512). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.0.20-root.io.9, 10.1.30-root.io.1, 10.1.34-root.io.2, 10.1.53-root.io.3, 10.1.53-root.io.4, 10.1.16-root.io.3, 10.1.16-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 10.1.30-root.io.2, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.53-root.io.5, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
|
| ROOT-APP-MAVEN-CVE-2026-42498 |
|
Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-42498)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-42498). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.1.16-root.io.1, 10.1.34-root.io.2, 10.1.53-root.io.3, 10.1.39-root.io.13, 10.1.53-root.io.4, 10.1.16-root.io.2, 10.1.16-root.io.3, 10.1.16-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 10.1.30-root.io.2, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.53-root.io.5, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
|
| ROOT-APP-MAVEN-CVE-2026-43513 |
|
Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43513)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43513). Confidential information can be exposed externally. Mitigation: upgrade to `11.0.20-root.io.9, 10.1.34-root.io.2, 10.1.53-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.53-root.io.5, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
|
| ROOT-APP-MAVEN-CVE-2026-41293 |
|
Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-41293)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-41293). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.0.20-root.io.9, 10.1.34-root.io.2, 10.1.16-root.io.3, 10.1.16-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
|
| ROOT-APP-MAVEN-CVE-2026-41284 |
|
Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-41284)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-41284). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.20-root.io.9, 10.1.30-root.io.1, 10.1.16-root.io.1, 10.1.34-root.io.2, 10.1.16-root.io.2, 10.1.16-root.io.3, 10.1.16-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 10.1.30-root.io.2, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
|
| GHSA-ppjp-2h29-66pv |
|
Vulnerability in reactive-cdk-app (GHSA-ppjp-2h29-66pv)
vulnerability in reactive-cdk-app (GHSA-ppjp-2h29-66pv). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9011 |
|
Vulnerability in wordpress (CVE-2026-9011)
vulnerability in wordpress (CVE-2026-9011). Confidential information can be exposed externally.
|
| CVE-2026-8692 |
|
Vulnerability in wordpress (CVE-2026-8692)
vulnerability in wordpress (CVE-2026-8692). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8684 |
|
Vulnerability in wordpress (CVE-2026-8684)
vulnerability in wordpress (CVE-2026-8684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7798 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-7798)
SSRF in wordpress (CVE-2026-7798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8679 |
|
Vulnerability in wordpress (CVE-2026-8679)
vulnerability in wordpress (CVE-2026-8679). Confidential information can be exposed externally.
|
| CVE-2026-8381 |
|
Vulnerability in CVE-2026-8381 (CVE-2026-8381)
vulnerability in CVE-2026-8381 (CVE-2026-8381). Risk of unauthorized operations or information disclosure.
|