Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MINI-qf9g-22xx-36rv MINI-qf9g-22xx-36rv
MINI-mhxm-j472-pqv5 MINI-mhxm-j472-pqv5
MINI-97wh-58gq-9qpw MINI-97wh-58gq-9qpw
MINI-cx6f-hr3g-x9wg MINI-cx6f-hr3g-x9wg
MINI-9v3h-vpx2-5p5r MINI-9v3h-vpx2-5p5r
MINI-g5m6-gmf3-gw3v MINI-g5m6-gmf3-gw3v
MINI-75jm-jj7r-33qj MINI-75jm-jj7r-33qj
MINI-x239-2ffx-m95m MINI-x239-2ffx-m95m
MINI-qmrj-5hcv-gq7w MINI-qmrj-5hcv-gq7w
MINI-ff5f-x2fr-4vxm MINI-ff5f-x2fr-4vxm
MINI-qfm4-x8cx-pmh3 MINI-qfm4-x8cx-pmh3
MINI-3wxm-fw4c-rjv3 MINI-3wxm-fw4c-rjv3
MINI-3cwr-px67-24jf MINI-3cwr-px67-24jf
MINI-qr7m-rjfc-c5x9 MINI-qr7m-rjfc-c5x9
MINI-3h7v-3v3v-5ghr MINI-3h7v-3v3v-5ghr
MINI-cfrp-m7v5-xj48 MINI-cfrp-m7v5-xj48
MINI-ppgc-j463-xvpx MINI-ppgc-j463-xvpx
MINI-hj3v-gw86-q68h MINI-hj3v-gw86-q68h
MINI-xrf5-2xwg-567v MINI-xrf5-2xwg-567v
MINI-xhfj-qh2p-f3pf MINI-xhfj-qh2p-f3pf
MINI-7jjm-xmwf-hw2p MINI-7jjm-xmwf-hw2p
MINI-88mh-vgm8-jp29 MINI-88mh-vgm8-jp29
MINI-9437-p5pv-3556 MINI-9437-p5pv-3556
MINI-7673-jjcp-7pr3 MINI-7673-jjcp-7pr3
MINI-wqx2-5qh4-652m MINI-wqx2-5qh4-652m
CVE-2026-35675 Vulnerability in thorsten/phpmyfaq (CVE-2026-35675)
vulnerability in thorsten/phpmyfaq (CVE-2026-35675). Data can be tampered with by attackers. Mitigation: upgrade to `4.1.3` or later.
CVE-2026-35672 Vulnerability in thorsten/phpmyfaq (CVE-2026-35672)
vulnerability in thorsten/phpmyfaq (CVE-2026-35672). Data can be tampered with by attackers. Exploitable via `POST /api/v4.0/faq/create`. Mitigation: upgrade to `4.1.3` or later.
CVE-2026-35671 Vulnerability in thorsten/phpmyfaq (CVE-2026-35671)
vulnerability in thorsten/phpmyfaq (CVE-2026-35671). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.3` or later.
CVE-2026-35676 Vulnerability in thorsten/phpmyfaq (CVE-2026-35676)
vulnerability in thorsten/phpmyfaq (CVE-2026-35676). Data can be tampered with by attackers. Exploitable via `PUT /api/index.php/user/password/update`. Mitigation: upgrade to `4.1.3` or later.
CVE-2026-56268 Authorization Flaw in flowise (CVE-2026-56268)
vulnerability in flowise (CVE-2026-56268). Confidential information can be exposed externally. Exploitable via ``keyonly``. Mitigation: upgrade to `3.1.2` or later.
GHSA-59fh-9f3p-7m39 Vulnerability in flowise (GHSA-59fh-9f3p-7m39)
vulnerability in flowise (GHSA-59fh-9f3p-7m39). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v1/user`. Mitigation: upgrade to `3.1.2` or later.
GHSA-m837-xvxr-vqwg Vulnerability in flowise (GHSA-m837-xvxr-vqwg)
vulnerability in flowise (GHSA-m837-xvxr-vqwg). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.2` or later.
GHSA-mw8f-w6p8-xrf4 Vulnerability in wger (GHSA-mw8f-w6p8-xrf4)
vulnerability in wger (GHSA-mw8f-w6p8-xrf4). Successful exploitation can lead to full system takeover. Exploitable via `GET /en/user/3/deactivate`.
CGA-w4hj-m326-gghh CGA-w4hj-m326-gghh
CGA-h394-c8r4-pg4r CGA-h394-c8r4-pg4r
GHSA-pxh5-6rrc-8rjv Vulnerability in github.com/opentofu/opentofu (GHSA-pxh5-6rrc-8rjv)
vulnerability in github.com/opentofu/opentofu (GHSA-pxh5-6rrc-8rjv). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.11.8` or later.
CVE-2026-46431 Vulnerability in github.com/xyproto/algernon (CVE-2026-46431)
vulnerability in github.com/xyproto/algernon (CVE-2026-46431). Risk of unauthorized operations or information disclosure. Exploitable via ``Origin``. Mitigation: upgrade to `1.17.7` or later.
CGA-pr6x-rvp5-3vr3 CGA-pr6x-rvp5-3vr3
CVE-2026-46430 Vulnerability in github.com/xyproto/algernon (CVE-2026-46430)
vulnerability in github.com/xyproto/algernon (CVE-2026-46430). Risk of unauthorized operations or information disclosure. Exploitable via ``http.Server.Addr``. Mitigation: upgrade to `1.17.7` or later.
CVE-2026-46421 Vulnerability in @cap-js/sqlite (CVE-2026-46421)
vulnerability in @cap-js/sqlite (CVE-2026-46421). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.0` or later.
GHSA-5wxr-w449-57cm Vulnerability in shivammathur/setup-php (GHSA-5wxr-w449-57cm)
vulnerability in shivammathur/setup-php (GHSA-5wxr-w449-57cm). Confidential information can be exposed externally. Mitigation: upgrade to `2.37.1` or later.
CVE-2026-46420 OS Command Injection in shivammathur/setup-php (CVE-2026-46420)
OS command injection in shivammathur/setup-php (CVE-2026-46420). Risk of unauthorized operations or information disclosure. Exploitable via ``composer.lock``. Mitigation: upgrade to `2.37.1` or later.
CVE-2026-45804 Vulnerability in diffusers (CVE-2026-45804)
vulnerability in diffusers (CVE-2026-45804). Successful exploitation can lead to full system takeover. Exploitable via ``diffusers``. Mitigation: upgrade to `0.38.0` or later.
CVE-2026-45792 Vulnerability in rtk (CVE-2026-45792)
vulnerability in rtk (CVE-2026-45792). Data can be tampered with by attackers. Exploitable via ``strip_lines_matching``. Mitigation: upgrade to `0.32.0` or later.
CLSA-2026-1779290839 giflib: Fix of CVE-2026-26740
giflib: Fix of CVE-2026-26740
MAL-2026-4409 Vulnerability in @nutui/nutui-react-taro (MAL-2026-4409)
vulnerability in @nutui/nutui-react-taro (MAL-2026-4409). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall.js``.
CLSA-2026-1779289334 Update of kernel
Update of kernel
MAL-2026-4184 Vulnerability in stripe-internal-utils (MAL-2026-4184)
vulnerability in stripe-internal-utils (MAL-2026-4184). Risk of unauthorized operations or information disclosure.
ECHO-8072-9059-153b ECHO-8072-9059-153b
ECHO-2e68-a24f-d392 ECHO-2e68-a24f-d392

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →