Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-5434 Vulnerability in CVE-2026-5434 (CVE-2026-5434)
vulnerability in CVE-2026-5434 (CVE-2026-5434). Confidential information can be exposed externally.
CVE-2026-44074 Vulnerability in CVE-2026-44074 (CVE-2026-44074)
vulnerability in CVE-2026-44074 (CVE-2026-44074). Risk of unauthorized operations or information disclosure.
CVE-2026-27393 Vulnerability in CVE-2026-27393 (CVE-2026-27393)
vulnerability in CVE-2026-27393 (CVE-2026-27393). Risk of unauthorized operations or information disclosure.
CVE-2026-5433 Command Injection in CVE-2026-5433 (CVE-2026-5433)
command injection in CVE-2026-5433 (CVE-2026-5433). Successful exploitation can lead to full system takeover.
CVE-2026-4858 Path Traversal in github.com/mattermost/mattermost-server (CVE-2026-4858)
path traversal in github.com/mattermost/mattermost-server (CVE-2026-4858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.15` or later.
CVE-2026-45250 Vulnerability in freebsd (CVE-2026-45250)
vulnerability in freebsd (CVE-2026-45250). Successful exploitation can lead to full system takeover.
CVE-2026-44075 Vulnerability in CVE-2026-44075 (CVE-2026-44075)
vulnerability in CVE-2026-44075 (CVE-2026-44075). Risk of unauthorized operations or information disclosure.
CVE-2026-9157 Vulnerability in CVE-2026-9157 (CVE-2026-9157)
vulnerability in CVE-2026-9157 (CVE-2026-9157). Successful exploitation can lead to full system takeover.
CVE-2026-44071 Vulnerability in dos (CVE-2026-44071)
vulnerability in dos (CVE-2026-44071). Risk of unauthorized operations or information disclosure.
CVE-2026-44057 Vulnerability in CVE-2026-44057 (CVE-2026-44057)
vulnerability in CVE-2026-44057 (CVE-2026-44057). Risk of unauthorized operations or information disclosure.
CVE-2026-27349 Vulnerability in CVE-2026-27349 (CVE-2026-27349)
vulnerability in CVE-2026-27349 (CVE-2026-27349). Risk of unauthorized operations or information disclosure.
CVE-2026-22880 Cross-Site Request Forgery (CSRF) in mattermost (CVE-2026-22880)
vulnerability in mattermost (CVE-2026-22880). Confidential information can be exposed externally.
CLSA-2026-1779351595 Vulnerability in redis (CLSA-2026-1779351595)
vulnerability in redis (CLSA-2026-1779351595). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5:5.0.14-1+deb10u5+tuxcare.els3` or later.
SUSE-SU-2026:21725-1 Vulnerability in SUSE-SU-2026:21725-1 (SUSE-SU-2026:21725-1)
vulnerability in SUSE-SU-2026:21725-1 (SUSE-SU-2026:21725-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `20260512` or later.
CLSA-2026-1779355613 Vulnerability in gnutls-bin (CLSA-2026-1779355613)
vulnerability in gnutls-bin (CLSA-2026-1779355613). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.10-4ubuntu1.9+tuxcare.els2` or later.
ROOT-APP-PYPI-CVE-2026-27025 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27025)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27025). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-28351 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-28351)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-28351). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-GHSA-jj6c-8h6c-hppx Vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-jj6c-8h6c-hppx)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-GHSA-jj6c-8h6c-hppx). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-27888 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27888)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27888). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.2, 6.6.0+root.io.3, 6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-31826 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-31826)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-31826). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-27026 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27026)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27026). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-28804 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-28804)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-28804). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-33699 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-33699)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-33699). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.1, 6.6.0+root.io.2, 6.6.0+root.io.3, 6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-40260 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-40260)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-40260). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-24688 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-24688)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-24688). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-33123 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-33123)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-33123). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-27024 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27024)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27024). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
ROOT-APP-PYPI-CVE-2026-27628 Vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27628)
vulnerability in rootio-pypdf (ROOT-APP-PYPI-CVE-2026-27628). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.6.0+root.io.2, 6.6.0+root.io.3, 6.6.0+root.io.4, 6.6.0+root.io.5, 6.6.0+root.io.6, 6.6.0+root.io.7, 6.6.0+root.io.8, 6.6.0+root.io.9` or later.
CLSA-2026-1779355433 Vulnerability in gnutls-bin (CLSA-2026-1779355433)
vulnerability in gnutls-bin (CLSA-2026-1779355433). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.18-1ubuntu1.6+tuxcare.els3` or later.
BELL-CVE-2026-41054 BELL-CVE-2026-41054
CLSA-2026-1779354817 Vulnerability in ctdb (CLSA-2026-1779354817)
vulnerability in ctdb (CLSA-2026-1779354817). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.10.16-25.0.9.el7_9.tuxcare.els8` or later.
MAL-2026-4392 Vulnerability in @hanssoft/baileys (MAL-2026-4392)
vulnerability in @hanssoft/baileys (MAL-2026-4392). Risk of unauthorized operations or information disclosure.
CLSA-2026-1779354447 shadow-utils: Fix of CVE-2023-4641
shadow-utils: Fix of CVE-2023-4641
GHSA-4cmw-88qw-qcpr Vulnerability in http-uploader-dev (GHSA-4cmw-88qw-qcpr)
vulnerability in http-uploader-dev (GHSA-4cmw-88qw-qcpr). Risk of unauthorized operations or information disclosure. Exploitable via ``calc.exe``.
MAL-2026-4580 Vulnerability in http-uploader-dev (MAL-2026-4580)
vulnerability in http-uploader-dev (MAL-2026-4580). Risk of unauthorized operations or information disclosure. Exploitable via ``calc.exe``.
ROOT-APP-PYPI-GHSA-fv5p-p927-qmxr Vulnerability in rootio-langchain-text-splitters (ROOT-APP-PYPI-GHSA-fv5p-p927-qmxr)
vulnerability in rootio-langchain-text-splitters (ROOT-APP-PYPI-GHSA-fv5p-p927-qmxr). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.1+root.io.1, 0.3.11+root.io.1, 1.1.0+root.io.1, 1.1.1+root.io.2, 1.1.0+root.io.2, 1.1.0+root.io.3, 1.1.1+root.io.3, 0.3.11+root.io.2, 0.3.11+root.io.3` or later.
ROOT-APP-PYPI-CVE-2026-23949 Vulnerability in rootio-jaraco.context (ROOT-APP-PYPI-CVE-2026-23949)
vulnerability in rootio-jaraco.context (ROOT-APP-PYPI-CVE-2026-23949). Confidential information can be exposed externally. Mitigation: upgrade to `6.0.1+root.io.2, 5.3.0+root.io.2, 5.3.0+root.io.3, 5.3.0+root.io.4, 6.0.1+root.io.3, 5.3.0+root.io.5` or later.
ROOT-APP-PYPI-GHSA-58pv-8j8x-9vj2 Vulnerability in rootio-jaraco.context (ROOT-APP-PYPI-GHSA-58pv-8j8x-9vj2)
vulnerability in rootio-jaraco.context (ROOT-APP-PYPI-GHSA-58pv-8j8x-9vj2). Confidential information can be exposed externally. Mitigation: upgrade to `5.3.0+root.io.1, 6.0.1+root.io.1, 5.3.0+root.io.2, 5.3.0+root.io.3, 5.3.0+root.io.4, 5.3.0+root.io.5` or later.
ROOT-APP-PYPI-CVE-2025-8869 Vulnerability in rootio-pip (ROOT-APP-PYPI-CVE-2025-8869)
vulnerability in rootio-pip (ROOT-APP-PYPI-CVE-2025-8869). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `25.0+root.io.1, 25.0.1+root.io.1, 25.2+root.io.1, 23.2.1+root.io.1, 23.2.1+root.io.2, 23.0.1+root.io.2, 22.2.1+root.io.2, 24.2+root.io.1, 21.2.4+root.io.1, 21.2.4+root.io.2, 24.0+root.io.1, 23.3.1+root.io.1, 23.1.2+root.io.1, 22.0.4+root.io.1, 22.0.4+root.io.2, 22.0.4+root.io.3, 23.0.1+root.io.3, 24.0+root.io.2, 25.0.1+root.io.2, 24.0+root.io.3, 23.1.2+root.io.2, 23.0.1+root.io.4, 25.2+root.io.2, 23.1.2+root.io.3, 25.2+root.io.3, 25.0.1+root.io.3, 25.2+root.io.4, 24.2+root.io.2, 25.0+root.io.2, 21.2.4+root.io.3, 22.2.1+root.io.3, 23.2.1+root.io.3, 23.1.2+root.io.4, 23.3.1+root.io.2, 23.0.1+root.io.5, 24.0+root.io.4, 22.0.4+root.io.4, 25.0.1+root.io.4, 23.2.1+root.io.4, 22.3.1+root.io.4` or later.
MAL-2026-4393 Vulnerability in @hanssoft/libsignal-node (MAL-2026-4393)
vulnerability in @hanssoft/libsignal-node (MAL-2026-4393). Risk of unauthorized operations or information disclosure. Exploitable via ``index.js``.
SUSE-SU-2026:21738-1 Vulnerability in SUSE-SU-2026:21738-1 (SUSE-SU-2026:21738-1)
vulnerability in SUSE-SU-2026:21738-1 (SUSE-SU-2026:21738-1). Risk of unauthorized operations or information disclosure.
ROOT-APP-PYPI-CVE-2026-32597 Vulnerability in rootio-PyJWT (ROOT-APP-PYPI-CVE-2026-32597)
vulnerability in rootio-PyJWT (ROOT-APP-PYPI-CVE-2026-32597). Data can be tampered with by attackers. Mitigation: upgrade to `2.9.0+root.io.1, 2.4.0+root.io.1, 2.10.1+root.io.1, 2.4.0+root.io.2, 2.10.1+root.io.2, 2.9.0+root.io.2, 2.8.0+root.io.1, 2.5.0+root.io.1, 2.4.0+root.io.3, 2.10.1+root.io.3, 2.9.0+root.io.3, 2.5.0+root.io.2, 2.8.0+root.io.2` or later.
MAL-2026-4588 Vulnerability in ionic-insta-api-wrapper (MAL-2026-4588)
vulnerability in ionic-insta-api-wrapper (MAL-2026-4588). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
MAL-2026-4361 Vulnerability in @amswf/huoke (MAL-2026-4361)
vulnerability in @amswf/huoke (MAL-2026-4361). Risk of unauthorized operations or information disclosure. Exploitable via ``SKILL.md``.
MAL-2026-4373 Vulnerability in @budetzz/libsignal-node (MAL-2026-4373)
vulnerability in @budetzz/libsignal-node (MAL-2026-4373). Risk of unauthorized operations or information disclosure. Exploitable via ``libsignal``.
MAL-2026-4625 Vulnerability in oh-langfuse (MAL-2026-4625)
vulnerability in oh-langfuse (MAL-2026-4625). Risk of unauthorized operations or information disclosure. Exploitable via ``langfuse_hook.py``.
CVE-2026-7836 Vulnerability in CVE-2026-7836 (CVE-2026-7836)
vulnerability in CVE-2026-7836 (CVE-2026-7836). Risk of unauthorized operations or information disclosure.
CVE-2026-7835 Vulnerability in dos (CVE-2026-7835)
vulnerability in dos (CVE-2026-7835). Risk of unauthorized operations or information disclosure.
CVE-2026-4055 Authorization Flaw in github.com/mattermost/mattermost/server/v8 (CVE-2026-4055)
vulnerability in github.com/mattermost/mattermost/server/v8 (CVE-2026-4055). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.0-20260320113102-f2b3d1c6a945` or later.
CVE-2026-44076 OS Command Injection in CVE-2026-44076 (CVE-2026-44076)
OS command injection in CVE-2026-44076 (CVE-2026-44076). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →