Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MAL-2026-4375 Vulnerability in @citely/mcp-server (MAL-2026-4375)
vulnerability in @citely/mcp-server (MAL-2026-4375). Risk of unauthorized operations or information disclosure.
GHSA-hwr7-qq29-qrf2 Vulnerability in prettier-sdk (GHSA-hwr7-qq29-qrf2)
vulnerability in prettier-sdk (GHSA-hwr7-qq29-qrf2). Risk of unauthorized operations or information disclosure. Exploitable via ``prettier``.
MAL-2026-4645 Vulnerability in prettier-sdk (MAL-2026-4645)
vulnerability in prettier-sdk (MAL-2026-4645). Risk of unauthorized operations or information disclosure. Exploitable via ``prettier``.
SUSE-SU-2026:21735-1 Vulnerability in SUSE-SU-2026:21735-1 (SUSE-SU-2026:21735-1)
vulnerability in SUSE-SU-2026:21735-1 (SUSE-SU-2026:21735-1). Risk of unauthorized operations or information disclosure.
MAL-2026-4518 Vulnerability in cheaty-sync-bot (MAL-2026-4518)
vulnerability in cheaty-sync-bot (MAL-2026-4518). Risk of unauthorized operations or information disclosure.
MGASA-2026-0152 Vulnerability in bind (MGASA-2026-0152)
vulnerability in bind (MGASA-2026-0152). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.18.47-1.mga9` or later.
GHSA-x73m-hgh7-64q2 Vulnerability in bytecore (GHSA-x73m-hgh7-64q2)
vulnerability in bytecore (GHSA-x73m-hgh7-64q2). Risk of unauthorized operations or information disclosure. Exploitable via ``pino``.
MAL-2026-4503 Vulnerability in bytecore (MAL-2026-4503)
vulnerability in bytecore (MAL-2026-4503). Risk of unauthorized operations or information disclosure. Exploitable via ``pino``.
MAL-2026-4174 Vulnerability in durabletask (MAL-2026-4174)
vulnerability in durabletask (MAL-2026-4174). Risk of unauthorized operations or information disclosure. Exploitable via ``durabletask``.
SUSE-SU-2026:21743-1 Vulnerability in SUSE-SU-2026:21743-1 (SUSE-SU-2026:21743-1)
vulnerability in SUSE-SU-2026:21743-1 (SUSE-SU-2026:21743-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:21723-1 Vulnerability in SUSE-SU-2026:21723-1 (SUSE-SU-2026:21723-1)
vulnerability in SUSE-SU-2026:21723-1 (SUSE-SU-2026:21723-1). Risk of unauthorized operations or information disclosure.
CVE-2026-46341 Vulnerability in @apify/actors-mcp-server (CVE-2026-46341)
vulnerability in @apify/actors-mcp-server (CVE-2026-46341). Risk of unauthorized operations or information disclosure. Exploitable via ``startsWith``. Mitigation: upgrade to `0.9.21` or later.
CVE-2026-46426 Unrestricted File Upload in budibase (CVE-2026-46426)
vulnerability in budibase (CVE-2026-46426). Confidential information can be exposed externally. Exploitable via `POST /api/attachments/process`. Mitigation: upgrade to `3.38.2` or later.
CVE-2026-8598 Vulnerability in cisa (CVE-2026-8598)
vulnerability in cisa (CVE-2026-8598). Confidential information can be exposed externally.
CVE-2026-8602 Vulnerability in cisa (CVE-2026-8602)
vulnerability in cisa (CVE-2026-8602). Data can be tampered with by attackers.
CVE-2026-46424 Privilege Escalation in @budibase/backend-core (CVE-2026-46424)
vulnerability in @budibase/backend-core (CVE-2026-46424). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/public/v1/roles/unassign`. Mitigation: upgrade to `3.38.2` or later.
CVE-2026-46337 Path Traversal in WWBN/AVideo (CVE-2026-46337)
path traversal in WWBN/AVideo (CVE-2026-46337). Risk of unauthorized operations or information disclosure. Exploitable via `GET /view/img/image404Raw.php`.
MINI-h5cj-3v23-h75q MINI-h5cj-3v23-h75q
MINI-xwf6-q668-j772 MINI-xwf6-q668-j772
MINI-7rhx-9jg5-4w84 MINI-7rhx-9jg5-4w84
MINI-f776-342p-hvqx MINI-f776-342p-hvqx
MINI-6v4c-prqg-897f MINI-6v4c-prqg-897f
MINI-rwmh-f8hv-vpjf MINI-rwmh-f8hv-vpjf
GHSA-fhvh-vw7h-9xf3 Vulnerability in libcrux-ml-dsa (GHSA-fhvh-vw7h-9xf3)
vulnerability in libcrux-ml-dsa (GHSA-fhvh-vw7h-9xf3). Risk of unauthorized operations or information disclosure. Exploitable via ``use_hint``. Mitigation: upgrade to `0.0.9` or later.
GHSA-hc3c-63hc-2r9f Vulnerability in libcrux-chacha20poly1305 (GHSA-hc3c-63hc-2r9f)
vulnerability in libcrux-chacha20poly1305 (GHSA-hc3c-63hc-2r9f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.8` or later.
MINI-cxhw-hjh4-3mxw MINI-cxhw-hjh4-3mxw
MINI-qvjw-fh2g-m25x MINI-qvjw-fh2g-m25x
MINI-7wx7-g3vj-vpf3 MINI-7wx7-g3vj-vpf3
MINI-crv9-2g4r-wp65 MINI-crv9-2g4r-wp65
MINI-fc4c-fg5v-xf28 MINI-fc4c-fg5v-xf28
MINI-3fj4-33q6-3f6r MINI-3fj4-33q6-3f6r
GHSA-4gph-2hhr-5mwg Vulnerability in github.com/envoyproxy/ai-gateway (GHSA-4gph-2hhr-5mwg)
vulnerability in github.com/envoyproxy/ai-gateway (GHSA-4gph-2hhr-5mwg). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mcp`. Mitigation: upgrade to `0.6.0` or later.
openSUSE-SU-2026:20773-1 Vulnerability in openSUSE-SU-2026:20773-1 (openSUSE-SU-2026:20773-1)
vulnerability in openSUSE-SU-2026:20773-1 (openSUSE-SU-2026:20773-1). Risk of unauthorized operations or information disclosure.
CVE-2026-45793 Information Disclosure in composer/composer (CVE-2026-45793)
vulnerability in composer/composer (CVE-2026-45793). Confidential information can be exposed externally. Exploitable via ``GITHUB_TOKEN``. Mitigation: upgrade to `1.10.28` or later.
MINI-r4rh-pp8m-vhmm MINI-r4rh-pp8m-vhmm
MINI-j7j6-hp54-w9x8 MINI-j7j6-hp54-w9x8
MINI-98r8-rj3h-ww47 MINI-98r8-rj3h-ww47
MINI-rmq5-697q-xmc6 MINI-rmq5-697q-xmc6
MINI-gqq3-5785-chcr MINI-gqq3-5785-chcr
MINI-33fj-6rgw-45j9 MINI-33fj-6rgw-45j9
CVE-2026-56348 SSRF (Server-Side Request Forgery) in n8n (CVE-2026-56348)
SSRF in n8n (CVE-2026-56348). Confidential information can be exposed externally. Exploitable via `POST /rest/dynamic-node-parameters/options`. Mitigation: upgrade to `2.20.0` or later.
MINI-j6cv-hpxv-vmxx MINI-j6cv-hpxv-vmxx
MINI-v9qm-cqmv-r9xr MINI-v9qm-cqmv-r9xr
MINI-rrxv-3rj4-2786 MINI-rrxv-3rj4-2786
MINI-fc5h-2wgf-ffjv MINI-fc5h-2wgf-ffjv
MINI-hw3v-jx5f-37pf MINI-hw3v-jx5f-37pf
MINI-9mmf-hm45-p85q MINI-9mmf-hm45-p85q
CVE-2026-8706 Information Disclosure in mozilla (CVE-2026-8706)
vulnerability in mozilla (CVE-2026-8706). Confidential information can be exposed externally.
CVE-2026-5804 Vulnerability in CVE-2026-5804 (CVE-2026-5804)
vulnerability in CVE-2026-5804 (CVE-2026-5804). Confidential information can be exposed externally.
CVE-2026-37281 OS Command Injection in express (CVE-2026-37281)
OS command injection in express (CVE-2026-37281). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →