Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CLEANSTART-2026-CH17958 |
|
Vulnerability in apache-zookeeper (CLEANSTART-2026-CH17958)
vulnerability in apache-zookeeper (CLEANSTART-2026-CH17958). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.9.5-r0` or later.
|
| CLEANSTART-2026-SZ14466 |
|
Vulnerability in apache-zookeeper (CLEANSTART-2026-SZ14466)
vulnerability in apache-zookeeper (CLEANSTART-2026-SZ14466). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.2-r6` or later.
|
| CLEANSTART-2026-HZ03319 |
|
Vulnerability in apache-zookeeper (CLEANSTART-2026-HZ03319)
vulnerability in apache-zookeeper (CLEANSTART-2026-HZ03319). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.9.4-r6` or later.
|
| CLEANSTART-2026-KN33052 |
|
Vulnerability in apache-zookeeper (CLEANSTART-2026-KN33052)
vulnerability in apache-zookeeper (CLEANSTART-2026-KN33052). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.8.6-r0` or later.
|
| CLEANSTART-2026-OD76369 |
|
Vulnerability in apache-zookeeper (CLEANSTART-2026-OD76369)
vulnerability in apache-zookeeper (CLEANSTART-2026-OD76369). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.4-r4` or later.
|
| CLEANSTART-2026-SE90004 |
|
Vulnerability in metacontroller (CLEANSTART-2026-SE90004)
vulnerability in metacontroller (CLEANSTART-2026-SE90004). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.13-r0` or later.
|
| CLEANSTART-2026-PX23055 |
|
Vulnerability in metacontroller (CLEANSTART-2026-PX23055)
vulnerability in metacontroller (CLEANSTART-2026-PX23055). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.13.1-r0` or later.
|
| CLEANSTART-2026-KD85000 |
|
Vulnerability in metacontroller (CLEANSTART-2026-KD85000)
vulnerability in metacontroller (CLEANSTART-2026-KD85000). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.15.0-r0` or later.
|
| CLEANSTART-2026-PL75416 |
|
Vulnerability in metacontroller (CLEANSTART-2026-PL75416)
vulnerability in metacontroller (CLEANSTART-2026-PL75416). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.14.0-r0` or later.
|
| GHSA-5vfv-hpg7-77hj |
|
Vulnerability in @tiledesk/tiledesk-server (GHSA-5vfv-hpg7-77hj)
vulnerability in @tiledesk/tiledesk-server (GHSA-5vfv-hpg7-77hj). Risk of unauthorized operations or information disclosure. Exploitable via ``printenv``.
|
| MAL-2026-4458 |
|
Vulnerability in @toni77777/aora (MAL-2026-4458)
vulnerability in @toni77777/aora (MAL-2026-4458). Risk of unauthorized operations or information disclosure. Exploitable via ``bin``.
|
| ROOT-APP-PYPI-CVE-2025-69223 |
|
Vulnerability in rootio-aiohttp (ROOT-APP-PYPI-CVE-2025-69223)
vulnerability in rootio-aiohttp (ROOT-APP-PYPI-CVE-2025-69223). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.10.11+root.io.1, 3.10.11+root.io.2, 3.10.11+root.io.3, 3.12.14+root.io.1, 3.12.15+root.io.1, 3.12.15+root.io.2, 3.10.11+root.io.4, 3.8.6+root.io.1` or later.
|
| ROOT-APP-PYPI-CVE-2025-53643 |
|
Vulnerability in rootio-aiohttp (ROOT-APP-PYPI-CVE-2025-53643)
vulnerability in rootio-aiohttp (ROOT-APP-PYPI-CVE-2025-53643). Data can be tampered with by attackers. Mitigation: upgrade to `3.9.1+root.io.4, 3.9.1+root.io.5, 3.9.1+root.io.6, 3.12.13+root.io.1, 3.12.13+root.io.2, 3.10.11+root.io.1, 3.10.11+root.io.2, 3.10.11+root.io.3, 3.9.1+root.io.7, 3.12.13+root.io.3, 3.10.11+root.io.4, 3.8.6+root.io.1` or later.
|
| ROOT-APP-PYPI-CVE-2025-69227 |
|
Vulnerability in rootio-aiohttp (ROOT-APP-PYPI-CVE-2025-69227)
vulnerability in rootio-aiohttp (ROOT-APP-PYPI-CVE-2025-69227). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.9.1+root.io.2, 3.9.1+root.io.3, 3.9.1+root.io.4, 3.9.1+root.io.5, 3.9.1+root.io.6, 3.10.11+root.io.1, 3.10.11+root.io.2, 3.10.11+root.io.3, 3.9.1+root.io.7, 3.10.11+root.io.4, 3.8.6+root.io.1` or later.
|
| ROOT-APP-PYPI-CVE-2025-69228 |
|
Vulnerability in rootio-aiohttp (ROOT-APP-PYPI-CVE-2025-69228)
vulnerability in rootio-aiohttp (ROOT-APP-PYPI-CVE-2025-69228). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.10.11+root.io.1, 3.10.11+root.io.2, 3.10.11+root.io.3, 3.10.11+root.io.4, 3.8.6+root.io.1` or later.
|
| ROOT-APP-NPM-GHSA-w5hq-g745-h8pq |
|
Vulnerability in @rootio/uuid (ROOT-APP-NPM-GHSA-w5hq-g745-h8pq)
vulnerability in @rootio/uuid (ROOT-APP-NPM-GHSA-w5hq-g745-h8pq). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.0.0-root.io.1, 11.0.3-root.io.1, 9.0.1-root.io.1, 11.1.0-root.io.2, 8.3.2-root.io.1, 8.3.2-root.io.2, 10.0.0-root.io.2, 9.0.1-root.io.2, 8.0.0-root.io.1, 11.0.3-root.io.2, 13.0.0-root.io.2, 11.1.1-root.io.1, 10.0.0-root.io.3, 11.1.0-root.io.3, 8.3.2-root.io.3, 11.0.3-root.io.3, 8.0.0-root.io.2, 8.3.2-root.io.4, 8.3.2-root.io.5, 11.1.0-root.io.4, 8.0.0-root.io.3, 10.0.0-root.io.4, 9.0.1-root.io.3, 9.0.1-root.io.4` or later.
|
| MAL-2026-4775 |
|
Vulnerability in wdt-erpmcp (MAL-2026-4775)
vulnerability in wdt-erpmcp (MAL-2026-4775). Risk of unauthorized operations or information disclosure. Exploitable via ``ruoxi2``.
|
| MAL-2026-4696 |
|
Vulnerability in turing-sdk (MAL-2026-4696)
vulnerability in turing-sdk (MAL-2026-4696). Risk of unauthorized operations or information disclosure. Exploitable via ``turing``.
|
| ROOT-OS-DEBIAN-13-CVE-2026-32777 |
|
Vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-32777)
vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-32777). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.1-2.root.io.10, 2.7.1-2.root.io.8, 2.7.1-2.root.io.9` or later.
|
| ROOT-OS-DEBIAN-13-CVE-2026-25210 |
|
Vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-25210)
vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-25210). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.7.1-2.root.io.7, 2.7.1-2.root.io.10, 2.7.1-2.root.io.8, 2.7.1-2.root.io.9` or later.
|
| ROOT-OS-DEBIAN-13-CVE-2026-24515 |
|
Vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-24515)
vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-24515). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.1-2.root.io.6, 2.7.1-2.root.io.7, 2.7.1-2.root.io.10, 2.7.1-2.root.io.8, 2.7.1-2.root.io.9` or later.
|
| ROOT-OS-DEBIAN-13-CVE-2026-45186 |
|
Vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-45186)
vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-45186). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.1-2.root.io.10` or later.
|
| ROOT-OS-DEBIAN-13-CVE-2025-59375 |
|
Vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2025-59375)
vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2025-59375). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.1-2.root.io.6, 2.7.1-2.root.io.7, 2.7.1-2.root.io.10, 2.7.1-2.root.io.2, 2.7.1-2.root.io.3, 2.7.1-2.root.io.4, 2.7.1-2.root.io.8, 2.7.1-2.root.io.1, 2.7.1-2.root.io.5, 2.7.1-2.root.io.9` or later.
|
| ROOT-OS-DEBIAN-13-CVE-2026-32776 |
|
Vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-32776)
vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-32776). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.1-2.root.io.10, 2.7.1-2.root.io.8, 2.7.1-2.root.io.9` or later.
|
| ROOT-OS-DEBIAN-13-CVE-2026-32778 |
|
Vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-32778)
vulnerability in rootio-expat (ROOT-OS-DEBIAN-13-CVE-2026-32778). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.1-2.root.io.10, 2.7.1-2.root.io.8, 2.7.1-2.root.io.9` or later.
|
| ROOT-APP-PYPI-GHSA-jj8c-mmj3-mmgv |
|
Vulnerability in rootio-Authlib (ROOT-APP-PYPI-GHSA-jj8c-mmj3-mmgv)
vulnerability in rootio-Authlib (ROOT-APP-PYPI-GHSA-jj8c-mmj3-mmgv). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.10+root.io.1, 1.6.6+root.io.4, 1.6.6+root.io.5, 1.6.10+root.io.2, 1.6.6+root.io.6, 1.6.10+root.io.3, 1.6.10+root.io.4, 1.6.6+root.io.7` or later.
|
| CVE-2026-1543 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-1543)
cross-site scripting in wordpress (CVE-2026-1543). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6279 |
|
Vulnerability in wordpress (CVE-2026-6279)
vulnerability in wordpress (CVE-2026-6279). Successful exploitation can lead to full system takeover. Exploitable via ``wp_conditional_tags``.
|
| CVE-2026-2734 |
|
Vulnerability in mlflow (CVE-2026-2734)
vulnerability in mlflow (CVE-2026-2734). Confidential information can be exposed externally. Exploitable via ``SearchModelVersions``. Mitigation: upgrade to `3.10.0` or later.
|
| ROOT-APP-MAVEN-CVE-2025-68384 |
|
Vulnerability in io.root.org.elasticsearch.plugin:x-pack-security (ROOT-APP-MAVEN-CVE-2025-68384)
vulnerability in io.root.org.elasticsearch.plugin:x-pack-security (ROOT-APP-MAVEN-CVE-2025-68384). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0-root.io.1, 9.1.3-root.io.1, 9.1.3-root.io.2, 9.2.2-root.io.1, 9.2.0-root.io.2, 9.1.3-root.io.3, 9.2.2-root.io.2` or later.
|
| BELL-CVE-2026-8368 |
|
BELL-CVE-2026-8368 |
| BELL-CVE-2026-7010 |
|
BELL-CVE-2026-7010 |
| BELL-CVE-2026-7210 |
|
BELL-CVE-2026-7210 |
| BELL-CVE-2026-7263 |
|
CVE-2026-7263 does not affect BellSoft software
CVE-2026-7263 does not affect BellSoft software
|
| BELL-CVE-2026-5950 |
|
BELL-CVE-2026-5950 |
| BELL-CVE-2026-5947 |
|
BELL-CVE-2026-5947 |
| BELL-CVE-2026-5946 |
|
BELL-CVE-2026-5946 |
| BELL-CVE-2026-6104 |
|
CVE-2026-6104 does not affect BellSoft software
CVE-2026-6104 does not affect BellSoft software
|
| BELL-CVE-2026-5089 |
|
BELL-CVE-2026-5089 |
| BELL-CVE-2026-44307 |
|
CVE-2026-44307 does not affect BellSoft software
CVE-2026-44307 does not affect BellSoft software
|
| BELL-CVE-2026-45232 |
|
BELL-CVE-2026-45232 |
| BELL-CVE-2026-43460 |
|
BELL-CVE-2026-43460
CVE-2026-43460 does not affect BellSoft software
|
| BELL-CVE-2026-43620 |
|
BELL-CVE-2026-43620 |
| BELL-CVE-2026-43618 |
|
BELL-CVE-2026-43618 |
| BELL-CVE-2026-43617 |
|
BELL-CVE-2026-43617 |
| BELL-CVE-2026-43619 |
|
BELL-CVE-2026-43619 |
| BELL-CVE-2026-43455 |
|
BELL-CVE-2026-43455 |
| BELL-CVE-2026-43444 |
|
BELL-CVE-2026-43444 |
| BELL-CVE-2026-43482 |
|
BELL-CVE-2026-43482 |
| BELL-CVE-2026-43480 |
|
BELL-CVE-2026-43480 |