Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
ROOT-OS-DEBIAN-13-CVE-2025-15366 Vulnerability in rootio-python3.13 (ROOT-OS-DEBIAN-13-CVE-2025-15366)
vulnerability in rootio-python3.13 (ROOT-OS-DEBIAN-13-CVE-2025-15366). Data can be tampered with by attackers. Mitigation: upgrade to `3.13.5-2+deb13u2.root.io.17, 3.13.5-2+deb13u2.root.io.18, 3.13.5-2+deb13u2.root.io.19` or later.
ROOT-OS-DEBIAN-13-CVE-2026-3479 Vulnerability in rootio-python3.13 (ROOT-OS-DEBIAN-13-CVE-2026-3479)
vulnerability in rootio-python3.13 (ROOT-OS-DEBIAN-13-CVE-2026-3479). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.13.5-2+deb13u2.root.io.17, 3.13.5-2+deb13u2.root.io.18, 3.13.5-2+deb13u2.root.io.19` or later.
ROOT-APP-GOBINARY-CVE-2026-44973 Vulnerability in rootio-github.com/go-git/go-billy/v5 (ROOT-APP-GOBINARY-CVE-2026-44973)
vulnerability in rootio-github.com/go-git/go-billy/v5 (ROOT-APP-GOBINARY-CVE-2026-44973). Confidential information can be exposed externally. Mitigation: upgrade to `v5.6.0-root.io.1, v5.6.0-root.io.3` or later.
ROOT-APP-PYPI-CVE-2026-41314 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41314)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41314). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-41312 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41312)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41312). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-41313 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41313)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-41313). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-GHSA-7gw9-cf7v-778f Vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-7gw9-cf7v-778f)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-7gw9-cf7v-778f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.1, 6.6.0+root.io.6, 6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-GHSA-x284-j5p8-9c5p Vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-x284-j5p8-9c5p)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-x284-j5p8-9c5p). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.3, 6.10.1+root.io.1, 6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-GHSA-4pxv-j86v-mhcw Vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-4pxv-j86v-mhcw)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-4pxv-j86v-mhcw). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.10.1+root.io.1, 6.6.0+root.io.6, 6.10.1+root.io.2, 6.6.0+root.io.7, 6.10.1+root.io.3, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
MAL-2026-4255 Vulnerability in cdk-sagemaker-notebook-workflow (MAL-2026-4255)
vulnerability in cdk-sagemaker-notebook-workflow (MAL-2026-4255). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
SUSE-SU-2026:21827-1 Vulnerability in SUSE-SU-2026:21827-1 (SUSE-SU-2026:21827-1)
vulnerability in SUSE-SU-2026:21827-1 (SUSE-SU-2026:21827-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:21756-1 Vulnerability in SUSE-SU-2026:21756-1 (SUSE-SU-2026:21756-1)
vulnerability in SUSE-SU-2026:21756-1 (SUSE-SU-2026:21756-1). Risk of unauthorized operations or information disclosure.
openSUSE-SU-2026:20788-1 Vulnerability in openSUSE-SU-2026:20788-1 (openSUSE-SU-2026:20788-1)
vulnerability in openSUSE-SU-2026:20788-1 (openSUSE-SU-2026:20788-1). Risk of unauthorized operations or information disclosure.
GHSA-j689-8wf2-2rj9 Vulnerability in @tmecontinue/claude (GHSA-j689-8wf2-2rj9)
vulnerability in @tmecontinue/claude (GHSA-j689-8wf2-2rj9). Risk of unauthorized operations or information disclosure.
MAL-2026-4457 Vulnerability in @tmecontinue/claude (MAL-2026-4457)
vulnerability in @tmecontinue/claude (MAL-2026-4457). Risk of unauthorized operations or information disclosure.
MAL-2026-4533 Vulnerability in codebuff-cli (MAL-2026-4533)
vulnerability in codebuff-cli (MAL-2026-4533). Risk of unauthorized operations or information disclosure. Exploitable via ``codebuff``.
ROOT-APP-NPM-CVE-2026-32630 Vulnerability in @rootio/file-type (ROOT-APP-NPM-CVE-2026-32630)
vulnerability in @rootio/file-type (ROOT-APP-NPM-CVE-2026-32630). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `21.0.0-root.io.1, 21.0.0-root.io.2, 20.4.1-root.io.1, 21.0.0-root.io.3, 20.4.1-root.io.2, 20.5.0-root.io.1, 21.1.0-root.io.1, 21.1.1-root.io.1` or later.
ROOT-APP-NPM-CVE-2026-31808 Vulnerability in @rootio/file-type (ROOT-APP-NPM-CVE-2026-31808)
vulnerability in @rootio/file-type (ROOT-APP-NPM-CVE-2026-31808). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `21.0.0-root.io.2, 20.4.1-root.io.1, 21.0.0-root.io.3, 20.4.1-root.io.2, 16.5.4-root.io.1, 20.5.0-root.io.1, 21.1.0-root.io.1, 21.1.1-root.io.1` or later.
SUSE-SU-2026:21786-1 Vulnerability in SUSE-SU-2026:21786-1 (SUSE-SU-2026:21786-1)
vulnerability in SUSE-SU-2026:21786-1 (SUSE-SU-2026:21786-1). Risk of unauthorized operations or information disclosure.
ROOT-APP-MAVEN-CVE-2026-40466 Vulnerability in io.root.org.apache.activemq:activemq-all (ROOT-APP-MAVEN-CVE-2026-40466)
vulnerability in io.root.org.apache.activemq:activemq-all (ROOT-APP-MAVEN-CVE-2026-40466). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.3-root.io.1, 6.1.3-root.io.2, 6.1.3-root.io.3, 6.1.3-root.io.4` or later.
MAL-2026-4563 Vulnerability in finkrouter (MAL-2026-4563)
vulnerability in finkrouter (MAL-2026-4563). Risk of unauthorized operations or information disclosure.
MAL-2026-4346 Vulnerability in logger-draft (MAL-2026-4346)
vulnerability in logger-draft (MAL-2026-4346). Risk of unauthorized operations or information disclosure. Exploitable via ``toskypi``.
BELL-CVE-2026-46680 BELL-CVE-2026-46680
CVE-2026-25608 Vulnerability in CVE-2026-25608 (CVE-2026-25608)
vulnerability in CVE-2026-25608 (CVE-2026-25608). Risk of unauthorized operations or information disclosure.
CVE-2026-25607 Vulnerability in CVE-2026-25607 (CVE-2026-25607)
vulnerability in CVE-2026-25607 (CVE-2026-25607). Risk of unauthorized operations or information disclosure.
CVE-2026-25606 SQL Injection in sqli (CVE-2026-25606)
SQL injection in sqli (CVE-2026-25606). Risk of unauthorized operations or information disclosure.
RHSA-2026:7412 Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
RHSA-2026:20334 Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
RHSA-2026:20299 Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
RHSA-2026:20130 Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
RHSA-2026:20129 Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
RHSA-2026:20074 Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
RHSA-2026:20054 Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update
SUSE-SU-2026:21867-1 Vulnerability in SUSE-SU-2026:21867-1 (SUSE-SU-2026:21867-1)
vulnerability in SUSE-SU-2026:21867-1 (SUSE-SU-2026:21867-1). Risk of unauthorized operations or information disclosure.
MAL-2026-4455 Vulnerability in @thebros/create-benjamin (MAL-2026-4455)
vulnerability in @thebros/create-benjamin (MAL-2026-4455). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env.OPENAI_API_KEY``.
SUSE-SU-2026:21785-1 Vulnerability in SUSE-SU-2026:21785-1 (SUSE-SU-2026:21785-1)
vulnerability in SUSE-SU-2026:21785-1 (SUSE-SU-2026:21785-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:21897-1 Vulnerability in SUSE-SU-2026:21897-1 (SUSE-SU-2026:21897-1)
vulnerability in SUSE-SU-2026:21897-1 (SUSE-SU-2026:21897-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `20260512` or later.
MAL-2026-4254 Vulnerability in reactive-cdk-app (MAL-2026-4254)
vulnerability in reactive-cdk-app (MAL-2026-4254). Risk of unauthorized operations or information disclosure.
ROOT-APP-MAVEN-CVE-2026-43512 Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43512)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43512). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.0.20-root.io.9, 10.1.30-root.io.1, 10.1.34-root.io.2, 10.1.53-root.io.3, 10.1.53-root.io.4, 10.1.16-root.io.3, 10.1.16-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 10.1.30-root.io.2, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.53-root.io.5, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
ROOT-APP-MAVEN-CVE-2026-42498 Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-42498)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-42498). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.1.16-root.io.1, 10.1.34-root.io.2, 10.1.53-root.io.3, 10.1.39-root.io.13, 10.1.53-root.io.4, 10.1.16-root.io.2, 10.1.16-root.io.3, 10.1.16-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 10.1.30-root.io.2, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.53-root.io.5, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
ROOT-APP-MAVEN-CVE-2026-43513 Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43513)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43513). Confidential information can be exposed externally. Mitigation: upgrade to `11.0.20-root.io.9, 10.1.34-root.io.2, 10.1.53-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.53-root.io.5, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
ROOT-APP-MAVEN-CVE-2026-41293 Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-41293)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-41293). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.0.20-root.io.9, 10.1.34-root.io.2, 10.1.16-root.io.3, 10.1.16-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
ROOT-APP-MAVEN-CVE-2026-41284 Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-41284)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-41284). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.20-root.io.9, 10.1.30-root.io.1, 10.1.16-root.io.1, 10.1.34-root.io.2, 10.1.16-root.io.2, 10.1.16-root.io.3, 10.1.16-root.io.4, 10.1.39-root.io.14, 10.1.16-root.io.5, 10.1.30-root.io.2, 11.0.20-root.io.10, 10.1.30-root.io.3, 10.1.16-root.io.6, 10.1.53-root.io.6, 10.1.30-root.io.4, 10.1.16-root.io.7, 10.1.39-root.io.15, 11.0.20-root.io.11, 10.1.34-root.io.3, 10.1.53-root.io.7, 10.1.53-root.io.8, 10.1.53-root.io.1781516532` or later.
GHSA-ppjp-2h29-66pv Vulnerability in reactive-cdk-app (GHSA-ppjp-2h29-66pv)
vulnerability in reactive-cdk-app (GHSA-ppjp-2h29-66pv). Risk of unauthorized operations or information disclosure.
CVE-2026-9011 Vulnerability in wordpress (CVE-2026-9011)
vulnerability in wordpress (CVE-2026-9011). Confidential information can be exposed externally.
CVE-2026-8692 Vulnerability in wordpress (CVE-2026-8692)
vulnerability in wordpress (CVE-2026-8692). Risk of unauthorized operations or information disclosure.
CVE-2026-8684 Vulnerability in wordpress (CVE-2026-8684)
vulnerability in wordpress (CVE-2026-8684). Risk of unauthorized operations or information disclosure.
CVE-2026-7798 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-7798)
SSRF in wordpress (CVE-2026-7798). Risk of unauthorized operations or information disclosure.
CVE-2026-8679 Vulnerability in wordpress (CVE-2026-8679)
vulnerability in wordpress (CVE-2026-8679). Confidential information can be exposed externally.
CVE-2026-8381 Vulnerability in CVE-2026-8381 (CVE-2026-8381)
vulnerability in CVE-2026-8381 (CVE-2026-8381). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →