Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39833 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39833)
vulnerability in golang.org/x/crypto (CVE-2026-39833). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39832 |
|
Unsafe Deserialization in golang.org/x/crypto (CVE-2026-39832)
vulnerability in golang.org/x/crypto (CVE-2026-39832). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39831 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39831)
vulnerability in golang.org/x/crypto (CVE-2026-39831). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39830 |
|
Buffer Overflow in golang.org/x/crypto (CVE-2026-39830)
vulnerability in golang.org/x/crypto (CVE-2026-39830). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39829 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39829)
vulnerability in golang.org/x/crypto (CVE-2026-39829). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39828 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39828)
vulnerability in golang.org/x/crypto (CVE-2026-39828). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.52.0` or later.
|
| DEBIAN-CVE-2026-39827 |
|
Vulnerability in golang-go.crypto (DEBIAN-CVE-2026-39827)
vulnerability in golang-go.crypto (DEBIAN-CVE-2026-39827). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.52.0-1` or later.
|
| CVE-2026-39827 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39827)
vulnerability in golang.org/x/crypto (CVE-2026-39827). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.52.0` or later.
|
| MAL-2026-4474 |
|
Vulnerability in acc-document-editing (MAL-2026-4474)
vulnerability in acc-document-editing (MAL-2026-4474). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4774 |
|
Vulnerability in vulndify-mcp-server (MAL-2026-4774)
vulnerability in vulndify-mcp-server (MAL-2026-4774). Risk of unauthorized operations or information disclosure. Exploitable via ``hello``.
|
| MINI-rfqg-j66w-rp59 |
|
MINI-rfqg-j66w-rp59 |
| MINI-49qh-748m-3pqh |
|
MINI-49qh-748m-3pqh |
| MINI-m57c-2q32-j32g |
|
MINI-m57c-2q32-j32g |
| MINI-rg84-wx5g-m55w |
|
MINI-rg84-wx5g-m55w |
| MINI-w5m4-3m79-c42g |
|
MINI-w5m4-3m79-c42g |
| MAL-2026-4444 |
|
Vulnerability in @shwfed/nuxt (MAL-2026-4444)
vulnerability in @shwfed/nuxt (MAL-2026-4444). Risk of unauthorized operations or information disclosure. Exploitable via ``access_token``.
|
| CVE-2026-42506 |
|
Cross-Site Scripting (XSS) in golang.org/x/net (CVE-2026-42506)
cross-site scripting in golang.org/x/net (CVE-2026-42506). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.55.0` or later.
|
| CVE-2026-27136 |
|
Vulnerability in golang.org/x/net (CVE-2026-27136)
vulnerability in golang.org/x/net (CVE-2026-27136). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.55.0` or later.
|
| CVE-2026-39821 |
|
Vulnerability in golang.org/x/net (CVE-2026-39821)
vulnerability in golang.org/x/net (CVE-2026-39821). Confidential information can be exposed externally. Mitigation: upgrade to `0.55.0` or later.
|
| CVE-2026-25680 |
|
Vulnerability in golang.org/x/net (CVE-2026-25680)
vulnerability in golang.org/x/net (CVE-2026-25680). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.55.0` or later.
|
| CVE-2026-25681 |
|
Vulnerability in golang.org/x/net (CVE-2026-25681)
vulnerability in golang.org/x/net (CVE-2026-25681). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.55.0` or later.
|
| CVE-2026-42502 |
|
Vulnerability in golang.org/x/net (CVE-2026-42502)
vulnerability in golang.org/x/net (CVE-2026-42502). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.55.0` or later.
|
| GHSA-xxq2-p383-26rc |
|
Vulnerability in dependency-audit-tool (GHSA-xxq2-p383-26rc)
vulnerability in dependency-audit-tool (GHSA-xxq2-p383-26rc). Risk of unauthorized operations or information disclosure. Exploitable via ``main``.
|
| GHSA-wpr6-96j5-4p35 |
|
Vulnerability in deploy-guard-check (GHSA-wpr6-96j5-4p35)
vulnerability in deploy-guard-check (GHSA-wpr6-96j5-4p35). Risk of unauthorized operations or information disclosure.
|
| GHSA-c7hj-r4xg-q237 |
|
Vulnerability in credential-verification-cli (GHSA-c7hj-r4xg-q237)
vulnerability in credential-verification-cli (GHSA-c7hj-r4xg-q237). Risk of unauthorized operations or information disclosure. Exploitable via ``latest``.
|
| GHSA-9gxp-rrm3-qh48 |
|
Vulnerability in compliance-check-runner (GHSA-9gxp-rrm3-qh48)
vulnerability in compliance-check-runner (GHSA-9gxp-rrm3-qh48). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| GHSA-39mh-vrfq-8hx7 |
|
Vulnerability in build-integrity-verify (GHSA-39mh-vrfq-8hx7)
vulnerability in build-integrity-verify (GHSA-39mh-vrfq-8hx7). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| GHSA-jq6x-r6vm-vwrx |
|
Vulnerability in wallet-backup-verifier (GHSA-jq6x-r6vm-vwrx)
vulnerability in wallet-backup-verifier (GHSA-jq6x-r6vm-vwrx). Risk of unauthorized operations or information disclosure. Exploitable via ``oast.fun``.
|
| GHSA-939m-5vr8-382c |
|
Vulnerability in python-env-auditor (GHSA-939m-5vr8-382c)
vulnerability in python-env-auditor (GHSA-939m-5vr8-382c). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| GHSA-4gg7-p7xj-789q |
|
Vulnerability in pypi-build-verifier (GHSA-4gg7-p7xj-789q)
vulnerability in pypi-build-verifier (GHSA-4gg7-p7xj-789q). Risk of unauthorized operations or information disclosure.
|
| GHSA-437g-626p-h8fm |
|
Vulnerability in env-security-scanner (GHSA-437g-626p-h8fm)
vulnerability in env-security-scanner (GHSA-437g-626p-h8fm). Risk of unauthorized operations or information disclosure.
|
| GHSA-88p4-x24p-x2j9 |
|
Vulnerability in chainlink-price-feed-aggregator (GHSA-88p4-x24p-x2j9)
vulnerability in chainlink-price-feed-aggregator (GHSA-88p4-x24p-x2j9). Risk of unauthorized operations or information disclosure.
|
| GHSA-q8c8-9p2m-f4v7 |
|
Vulnerability in truffle-config-helper (GHSA-q8c8-9p2m-f4v7)
vulnerability in truffle-config-helper (GHSA-q8c8-9p2m-f4v7). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| GHSA-39j5-93x5-73hc |
|
Vulnerability in solna-web3 (GHSA-39j5-93x5-73hc)
vulnerability in solna-web3 (GHSA-39j5-93x5-73hc). Risk of unauthorized operations or information disclosure.
|
| GHSA-jrx8-mvj8-9gq2 |
|
Vulnerability in solana-pda-helper (GHSA-jrx8-mvj8-9gq2)
vulnerability in solana-pda-helper (GHSA-jrx8-mvj8-9gq2). Risk of unauthorized operations or information disclosure. Exploitable via ``index.js``.
|
| GHSA-xhp8-r3hh-j47p |
|
Vulnerability in foundry-deploy-helper (GHSA-xhp8-r3hh-j47p)
vulnerability in foundry-deploy-helper (GHSA-xhp8-r3hh-j47p). Risk of unauthorized operations or information disclosure.
|
| GHSA-w4rg-p3x5-fv42 |
|
Vulnerability in hardhat-gas-profiler-plugin (GHSA-w4rg-p3x5-fv42)
vulnerability in hardhat-gas-profiler-plugin (GHSA-w4rg-p3x5-fv42). Risk of unauthorized operations or information disclosure. Exploitable via ``index.js``.
|
| GHSA-3c7w-4xp2-7963 |
|
Vulnerability in etherjs-utils (GHSA-3c7w-4xp2-7963)
vulnerability in etherjs-utils (GHSA-3c7w-4xp2-7963). Risk of unauthorized operations or information disclosure.
|
| GHSA-hfp4-5fx7-5mwm |
|
Vulnerability in ganache-cli-provider (GHSA-hfp4-5fx7-5mwm)
vulnerability in ganache-cli-provider (GHSA-hfp4-5fx7-5mwm). Risk of unauthorized operations or information disclosure.
|
| GHSA-r83q-qx5h-cjqm |
|
Vulnerability in ethers-multicall-utils (GHSA-r83q-qx5h-cjqm)
vulnerability in ethers-multicall-utils (GHSA-r83q-qx5h-cjqm). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| GHSA-48f2-rw49-vgx3 |
|
Vulnerability in foundy-toolkit (GHSA-48f2-rw49-vgx3)
vulnerability in foundy-toolkit (GHSA-48f2-rw49-vgx3). Risk of unauthorized operations or information disclosure. Exploitable via ``telemetry``.
|
| CVE-2026-9264 |
|
Code Injection in CVE-2026-9264 (CVE-2026-9264)
code injection in CVE-2026-9264 (CVE-2026-9264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34911 |
|
Path Traversal in path-traversal (CVE-2026-34911)
path traversal in path-traversal (CVE-2026-34911). Confidential information can be exposed externally.
|
| CVE-2026-34910 KEV |
|
[KEV] Vulnerability in Ubiquiti ui (CVE-2026-34910)
vulnerability in Ubiquiti ui (CVE-2026-34910). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34909 KEV |
|
[KEV] Path Traversal in Ubiquiti path-traversal (CVE-2026-34909)
path traversal in Ubiquiti path-traversal (CVE-2026-34909). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34908 KEV |
|
[KEV] Vulnerability in Ubiquiti ui (CVE-2026-34908)
vulnerability in Ubiquiti ui (CVE-2026-34908). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-33000 |
|
Vulnerability in ui (CVE-2026-33000)
vulnerability in ui (CVE-2026-33000). Successful exploitation can lead to full system takeover.
|
| ECHO-aa57-a866-13b0 |
|
ECHO-aa57-a866-13b0 |
| ECHO-2da3-fd4f-7f6d |
|
ECHO-2da3-fd4f-7f6d |
| ECHO-0d78-6c28-581d |
|
ECHO-0d78-6c28-581d |