Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MAL-2026-4375 |
|
Vulnerability in @citely/mcp-server (MAL-2026-4375)
vulnerability in @citely/mcp-server (MAL-2026-4375). Risk of unauthorized operations or information disclosure.
|
| GHSA-hwr7-qq29-qrf2 |
|
Vulnerability in prettier-sdk (GHSA-hwr7-qq29-qrf2)
vulnerability in prettier-sdk (GHSA-hwr7-qq29-qrf2). Risk of unauthorized operations or information disclosure. Exploitable via ``prettier``.
|
| MAL-2026-4645 |
|
Vulnerability in prettier-sdk (MAL-2026-4645)
vulnerability in prettier-sdk (MAL-2026-4645). Risk of unauthorized operations or information disclosure. Exploitable via ``prettier``.
|
| SUSE-SU-2026:21735-1 |
|
Vulnerability in SUSE-SU-2026:21735-1 (SUSE-SU-2026:21735-1)
vulnerability in SUSE-SU-2026:21735-1 (SUSE-SU-2026:21735-1). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4518 |
|
Vulnerability in cheaty-sync-bot (MAL-2026-4518)
vulnerability in cheaty-sync-bot (MAL-2026-4518). Risk of unauthorized operations or information disclosure.
|
| MGASA-2026-0152 |
|
Vulnerability in bind (MGASA-2026-0152)
vulnerability in bind (MGASA-2026-0152). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.18.47-1.mga9` or later.
|
| GHSA-x73m-hgh7-64q2 |
|
Vulnerability in bytecore (GHSA-x73m-hgh7-64q2)
vulnerability in bytecore (GHSA-x73m-hgh7-64q2). Risk of unauthorized operations or information disclosure. Exploitable via ``pino``.
|
| MAL-2026-4503 |
|
Vulnerability in bytecore (MAL-2026-4503)
vulnerability in bytecore (MAL-2026-4503). Risk of unauthorized operations or information disclosure. Exploitable via ``pino``.
|
| MAL-2026-4174 |
|
Vulnerability in durabletask (MAL-2026-4174)
vulnerability in durabletask (MAL-2026-4174). Risk of unauthorized operations or information disclosure. Exploitable via ``durabletask``.
|
| SUSE-SU-2026:21743-1 |
|
Vulnerability in SUSE-SU-2026:21743-1 (SUSE-SU-2026:21743-1)
vulnerability in SUSE-SU-2026:21743-1 (SUSE-SU-2026:21743-1). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:21723-1 |
|
Vulnerability in SUSE-SU-2026:21723-1 (SUSE-SU-2026:21723-1)
vulnerability in SUSE-SU-2026:21723-1 (SUSE-SU-2026:21723-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46341 |
|
Vulnerability in @apify/actors-mcp-server (CVE-2026-46341)
vulnerability in @apify/actors-mcp-server (CVE-2026-46341). Risk of unauthorized operations or information disclosure. Exploitable via ``startsWith``. Mitigation: upgrade to `0.9.21` or later.
|
| CVE-2026-46426 |
|
Unrestricted File Upload in budibase (CVE-2026-46426)
vulnerability in budibase (CVE-2026-46426). Confidential information can be exposed externally. Exploitable via `POST /api/attachments/process`. Mitigation: upgrade to `3.38.2` or later.
|
| CVE-2026-8598 |
|
Vulnerability in cisa (CVE-2026-8598)
vulnerability in cisa (CVE-2026-8598). Confidential information can be exposed externally.
|
| CVE-2026-8602 |
|
Vulnerability in cisa (CVE-2026-8602)
vulnerability in cisa (CVE-2026-8602). Data can be tampered with by attackers.
|
| CVE-2026-46424 |
|
Privilege Escalation in @budibase/backend-core (CVE-2026-46424)
vulnerability in @budibase/backend-core (CVE-2026-46424). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/public/v1/roles/unassign`. Mitigation: upgrade to `3.38.2` or later.
|
| CVE-2026-46337 |
|
Path Traversal in WWBN/AVideo (CVE-2026-46337)
path traversal in WWBN/AVideo (CVE-2026-46337). Risk of unauthorized operations or information disclosure. Exploitable via `GET /view/img/image404Raw.php`.
|
| MINI-h5cj-3v23-h75q |
|
MINI-h5cj-3v23-h75q |
| MINI-xwf6-q668-j772 |
|
MINI-xwf6-q668-j772 |
| MINI-7rhx-9jg5-4w84 |
|
MINI-7rhx-9jg5-4w84 |
| MINI-f776-342p-hvqx |
|
MINI-f776-342p-hvqx |
| MINI-6v4c-prqg-897f |
|
MINI-6v4c-prqg-897f |
| MINI-rwmh-f8hv-vpjf |
|
MINI-rwmh-f8hv-vpjf |
| GHSA-fhvh-vw7h-9xf3 |
|
Vulnerability in libcrux-ml-dsa (GHSA-fhvh-vw7h-9xf3)
vulnerability in libcrux-ml-dsa (GHSA-fhvh-vw7h-9xf3). Risk of unauthorized operations or information disclosure. Exploitable via ``use_hint``. Mitigation: upgrade to `0.0.9` or later.
|
| GHSA-hc3c-63hc-2r9f |
|
Vulnerability in libcrux-chacha20poly1305 (GHSA-hc3c-63hc-2r9f)
vulnerability in libcrux-chacha20poly1305 (GHSA-hc3c-63hc-2r9f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.8` or later.
|
| MINI-cxhw-hjh4-3mxw |
|
MINI-cxhw-hjh4-3mxw |
| MINI-qvjw-fh2g-m25x |
|
MINI-qvjw-fh2g-m25x |
| MINI-7wx7-g3vj-vpf3 |
|
MINI-7wx7-g3vj-vpf3 |
| MINI-crv9-2g4r-wp65 |
|
MINI-crv9-2g4r-wp65 |
| MINI-fc4c-fg5v-xf28 |
|
MINI-fc4c-fg5v-xf28 |
| MINI-3fj4-33q6-3f6r |
|
MINI-3fj4-33q6-3f6r |
| GHSA-4gph-2hhr-5mwg |
|
Vulnerability in github.com/envoyproxy/ai-gateway (GHSA-4gph-2hhr-5mwg)
vulnerability in github.com/envoyproxy/ai-gateway (GHSA-4gph-2hhr-5mwg). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mcp`. Mitigation: upgrade to `0.6.0` or later.
|
| openSUSE-SU-2026:20773-1 |
|
Vulnerability in openSUSE-SU-2026:20773-1 (openSUSE-SU-2026:20773-1)
vulnerability in openSUSE-SU-2026:20773-1 (openSUSE-SU-2026:20773-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45793 |
|
Information Disclosure in composer/composer (CVE-2026-45793)
vulnerability in composer/composer (CVE-2026-45793). Confidential information can be exposed externally. Exploitable via ``GITHUB_TOKEN``. Mitigation: upgrade to `1.10.28` or later.
|
| MINI-r4rh-pp8m-vhmm |
|
MINI-r4rh-pp8m-vhmm |
| MINI-j7j6-hp54-w9x8 |
|
MINI-j7j6-hp54-w9x8 |
| MINI-98r8-rj3h-ww47 |
|
MINI-98r8-rj3h-ww47 |
| MINI-rmq5-697q-xmc6 |
|
MINI-rmq5-697q-xmc6 |
| MINI-gqq3-5785-chcr |
|
MINI-gqq3-5785-chcr |
| MINI-33fj-6rgw-45j9 |
|
MINI-33fj-6rgw-45j9 |
| CVE-2026-56348 |
|
SSRF (Server-Side Request Forgery) in n8n (CVE-2026-56348)
SSRF in n8n (CVE-2026-56348). Confidential information can be exposed externally. Exploitable via `POST /rest/dynamic-node-parameters/options`. Mitigation: upgrade to `2.20.0` or later.
|
| MINI-j6cv-hpxv-vmxx |
|
MINI-j6cv-hpxv-vmxx |
| MINI-v9qm-cqmv-r9xr |
|
MINI-v9qm-cqmv-r9xr |
| MINI-rrxv-3rj4-2786 |
|
MINI-rrxv-3rj4-2786 |
| MINI-fc5h-2wgf-ffjv |
|
MINI-fc5h-2wgf-ffjv |
| MINI-hw3v-jx5f-37pf |
|
MINI-hw3v-jx5f-37pf |
| MINI-9mmf-hm45-p85q |
|
MINI-9mmf-hm45-p85q |
| CVE-2026-8706 |
|
Information Disclosure in mozilla (CVE-2026-8706)
vulnerability in mozilla (CVE-2026-8706). Confidential information can be exposed externally.
|
| CVE-2026-5804 |
|
Vulnerability in CVE-2026-5804 (CVE-2026-5804)
vulnerability in CVE-2026-5804 (CVE-2026-5804). Confidential information can be exposed externally.
|
| CVE-2026-37281 |
|
OS Command Injection in express (CVE-2026-37281)
OS command injection in express (CVE-2026-37281). Successful exploitation can lead to full system takeover.
|