Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MAL-2026-4743 Vulnerability in buddyme (MAL-2026-4743)
vulnerability in buddyme (MAL-2026-4743). Risk of unauthorized operations or information disclosure.
MAL-2026-4765 Vulnerability in qontract-reconcile (MAL-2026-4765)
vulnerability in qontract-reconcile (MAL-2026-4765). Risk of unauthorized operations or information disclosure. Exploitable via ``pagerduty``.
GHSA-g53w-w6mj-hrpp Authentication Bypass in github.com/Kuadrant/mcp-gateway (GHSA-g53w-w6mj-hrpp)
authentication bypass in github.com/Kuadrant/mcp-gateway (GHSA-g53w-w6mj-hrpp). Risk of unauthorized operations or information disclosure.
MAL-2026-4746 Vulnerability in crw (MAL-2026-4746)
vulnerability in crw (MAL-2026-4746). Risk of unauthorized operations or information disclosure.
GHSA-m9p2-fxp5-v3fp Vulnerability in diesel (GHSA-m9p2-fxp5-v3fp)
vulnerability in diesel (GHSA-m9p2-fxp5-v3fp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.8` or later.
GHSA-q8x8-jrhj-fh9p Vulnerability in diesel (GHSA-q8x8-jrhj-fh9p)
vulnerability in diesel (GHSA-q8x8-jrhj-fh9p). Risk of unauthorized operations or information disclosure. Exploitable via ``SqliteAggregate``. Mitigation: upgrade to `2.3.8` or later.
GHSA-gx7w-56w6-g48x Authorization Flaw in github.com/caddyserver/caddy/v2 (GHSA-gx7w-56w6-g48x)
vulnerability in github.com/caddyserver/caddy/v2 (GHSA-gx7w-56w6-g48x). Risk of unauthorized operations or information disclosure. Exploitable via `GET /pki/ca/prod`. Mitigation: upgrade to `2.11.3` or later.
GHSA-wwhq-w58m-w29c Vulnerability in github.com/caddyserver/caddy/v2 (GHSA-wwhq-w58m-w29c)
vulnerability in github.com/caddyserver/caddy/v2 (GHSA-wwhq-w58m-w29c). Risk of unauthorized operations or information disclosure. Exploitable via ``vars_regexp``.
CLSA-2026-1779219098 grub2: Fix of CVE-2023-4692
grub2: Fix of CVE-2023-4692
GHSA-m23h-6mwm-39m8 Information Disclosure in github.com/kong/kubernetes-ingress-controller/v3 (GHSA-m23h-6mwm-39m8)
vulnerability in github.com/kong/kubernetes-ingress-controller/v3 (GHSA-m23h-6mwm-39m8). Risk of unauthorized operations or information disclosure. Exploitable via ``GatewayClass``. Mitigation: upgrade to `3.4.14` or later.
CGA-ccx5-m7vf-qvf2 CGA-ccx5-m7vf-qvf2
GHSA-3278-c88v-xrh4 Vulnerability in github.com/kong/kubernetes-ingress-controller/v3 (GHSA-3278-c88v-xrh4)
vulnerability in github.com/kong/kubernetes-ingress-controller/v3 (GHSA-3278-c88v-xrh4). Risk of unauthorized operations or information disclosure. Exploitable via ``Plugins``. Mitigation: upgrade to `3.5.7` or later.
CLSA-2026-1779218750 Vulnerability in cpp (CLSA-2026-1779218750)
vulnerability in cpp (CLSA-2026-1779218750). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.5.0-5.el9_5.tuxcare.els1` or later.
MAL-2026-4701 Vulnerability in venturo-playwright-runner (MAL-2026-4701)
vulnerability in venturo-playwright-runner (MAL-2026-4701). Risk of unauthorized operations or information disclosure. Exploitable via ``index.js``.
CVE-2026-46339 OS Command Injection in 9router (CVE-2026-46339)
OS command injection in 9router (CVE-2026-46339). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/cli-tools/cowork-settings`. Mitigation: upgrade to `0.4.37` or later.
CVE-2026-45695 OS Command Injection in github.com/kopia/kopia (CVE-2026-45695)
OS command injection in github.com/kopia/kopia (CVE-2026-45695). Successful exploitation can lead to full system takeover. Exploitable via ``blob.NewStorage``. Mitigation: upgrade to `0.23.0` or later.
CVE-2026-8370 Vulnerability in privilege-escalation (CVE-2026-8370)
vulnerability in privilege-escalation (CVE-2026-8370). Risk of unauthorized operations or information disclosure.
CVE-2026-8096 Vulnerability in wordpress (CVE-2026-8096)
vulnerability in wordpress (CVE-2026-8096). Confidential information can be exposed externally.
CVE-2026-8073 Vulnerability in wordpress (CVE-2026-8073)
vulnerability in wordpress (CVE-2026-8073). Confidential information can be exposed externally.
CVE-2026-41470 Authorization Flaw in CVE-2026-41470 (CVE-2026-41470)
vulnerability in CVE-2026-41470 (CVE-2026-41470). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-33637 Vulnerability in ruby-faraday (DEBIAN-CVE-2026-33637)
vulnerability in ruby-faraday (DEBIAN-CVE-2026-33637). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
DEBIAN-CVE-2026-33642 Vulnerability in kitty (DEBIAN-CVE-2026-33642)
vulnerability in kitty (DEBIAN-CVE-2026-33642). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.41.1-2+deb13u1` or later.
CVE-2026-34154 Vulnerability in discourse (CVE-2026-34154)
vulnerability in discourse (CVE-2026-34154). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
CVE-2026-33741 Cross-Site Scripting (XSS) in CVE-2026-33741 (CVE-2026-33741)
cross-site scripting in CVE-2026-33741 (CVE-2026-33741). Confidential information can be exposed externally.
CVE-2026-33642 Out-of-Bounds Read in c (CVE-2026-33642)
vulnerability in c (CVE-2026-33642). Risk of unauthorized operations or information disclosure.
ALPINE-CVE-2026-32738 Vulnerability in libheif (ALPINE-CVE-2026-32738)
vulnerability in libheif (ALPINE-CVE-2026-32738). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.23.0-r0` or later.
DEBIAN-CVE-2026-32738 Vulnerability in libheif (DEBIAN-CVE-2026-32738)
vulnerability in libheif (DEBIAN-CVE-2026-32738). Risk of unauthorized operations or information disclosure.
CVE-2026-32738 Out-of-Bounds Read in dos (CVE-2026-32738)
vulnerability in dos (CVE-2026-32738). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-32738 Vulnerability in libheif (UBUNTU-CVE-2026-32738)
vulnerability in libheif (UBUNTU-CVE-2026-32738). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.20.2-1ubuntu0.4` or later.
UBUNTU-CVE-2026-33637 Vulnerability in ruby-faraday (UBUNTU-CVE-2026-33637)
vulnerability in ruby-faraday (UBUNTU-CVE-2026-33637). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
UBUNTU-CVE-2026-33642 Vulnerability in kitty (UBUNTU-CVE-2026-33642)
vulnerability in kitty (UBUNTU-CVE-2026-33642). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.41.1-2+deb13u1build0.25.10.1` or later.
GHSA-9j37-8wjm-pcxq Vulnerability in collected-forms-embed-js (GHSA-9j37-8wjm-pcxq)
vulnerability in collected-forms-embed-js (GHSA-9j37-8wjm-pcxq). Risk of unauthorized operations or information disclosure.
MAL-2026-4175 Vulnerability in collected-forms-embed-js (MAL-2026-4175)
vulnerability in collected-forms-embed-js (MAL-2026-4175). Risk of unauthorized operations or information disclosure.
MAL-2026-4700 Vulnerability in venturo-playwright (MAL-2026-4700)
vulnerability in venturo-playwright (MAL-2026-4700). Risk of unauthorized operations or information disclosure.
MAL-2026-4362 Vulnerability in @arbocollab/arbo-web-people (MAL-2026-4362)
vulnerability in @arbocollab/arbo-web-people (MAL-2026-4362). Risk of unauthorized operations or information disclosure. Exploitable via ``npmjs.npmrc``.
MAL-2026-4383 Vulnerability in @dknzo/soonex-ai (MAL-2026-4383)
vulnerability in @dknzo/soonex-ai (MAL-2026-4383). Risk of unauthorized operations or information disclosure.
MAL-2026-4453 Vulnerability in @tarojs/cli (MAL-2026-4453)
vulnerability in @tarojs/cli (MAL-2026-4453). Risk of unauthorized operations or information disclosure. Exploitable via ``TARO_GLOBAL_CONFIG_DIR``.
GHSA-8jmh-pvvx-wjrf Vulnerability in clsx-js (GHSA-8jmh-pvvx-wjrf)
vulnerability in clsx-js (GHSA-8jmh-pvvx-wjrf). Risk of unauthorized operations or information disclosure. Exploitable via ``data.content``.
MAL-2026-4531 Vulnerability in clsx-js (MAL-2026-4531)
vulnerability in clsx-js (MAL-2026-4531). Risk of unauthorized operations or information disclosure. Exploitable via ``data.content``.
CGA-rpph-6g68-r735 CGA-rpph-6g68-r735
CLSA-2026-1779217317 systemd: Fix of CVE-2026-29111
systemd: Fix of CVE-2026-29111
MAL-2026-4732 Vulnerability in workrally (MAL-2026-4732)
vulnerability in workrally (MAL-2026-4732). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
MAL-2026-4176 Vulnerability in dabrius-utils (MAL-2026-4176)
vulnerability in dabrius-utils (MAL-2026-4176). Risk of unauthorized operations or information disclosure.
CGA-g58r-4qjr-879w CGA-g58r-4qjr-879w
CGA-v62c-9pg8-2fcp CGA-v62c-9pg8-2fcp
CGA-29pj-3xwv-q47c CGA-29pj-3xwv-q47c
CGA-j3q7-84qp-4ff7 CGA-j3q7-84qp-4ff7
CGA-43cg-jgv8-2vmh CGA-43cg-jgv8-2vmh
GHSA-m4m6-q4p8-3vjv Vulnerability in btd-smart (GHSA-m4m6-q4p8-3vjv)
vulnerability in btd-smart (GHSA-m4m6-q4p8-3vjv). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
MAL-2026-4501 Vulnerability in btd-smart (MAL-2026-4501)
vulnerability in btd-smart (MAL-2026-4501). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →