Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-h72c-2gpg-4mmw |
|
MINI-h72c-2gpg-4mmw |
| MINI-8qh5-r8h3-45gp |
|
MINI-8qh5-r8h3-45gp |
| MINI-747q-74mv-gm5f |
|
MINI-747q-74mv-gm5f |
| MINI-w5hm-hgf2-3g65 |
|
MINI-w5hm-hgf2-3g65 |
| MINI-f4cg-9c2m-w7fg |
|
MINI-f4cg-9c2m-w7fg |
| MINI-6qm9-m8jr-m4mh |
|
MINI-6qm9-m8jr-m4mh |
| MINI-c6ph-q4m5-73mg |
|
MINI-c6ph-q4m5-73mg |
| MINI-x2qr-64x8-3mr5 |
|
MINI-x2qr-64x8-3mr5 |
| MINI-cc95-c348-9h7q |
|
MINI-cc95-c348-9h7q |
| GHSA-2vx9-7wpg-88jq |
|
Path Traversal in n8n (GHSA-2vx9-7wpg-88jq)
path traversal in n8n (GHSA-2vx9-7wpg-88jq). Risk of unauthorized operations or information disclosure. Exploitable via ``ExecuteWorkflow``. Mitigation: upgrade to `2.19.3` or later.
|
| CVE-2026-45739 |
|
Information Disclosure in strawberry-graphql (CVE-2026-45739)
vulnerability in strawberry-graphql (CVE-2026-45739). Risk of unauthorized operations or information disclosure. Exploitable via ``parameters``. Mitigation: upgrade to `0.315.4` or later.
|
| CVE-2026-45738 |
|
Cross-Site Scripting (XSS) in github.com/argoproj/argo-cd/v3 (CVE-2026-45738)
cross-site scripting in github.com/argoproj/argo-cd/v3 (CVE-2026-45738). Confidential information can be exposed externally. Exploitable via ``href``. Mitigation: upgrade to `3.4.2` or later.
|
| CVE-2026-45737 |
|
Information Disclosure in github.com/argoproj/argo-cd/v3 (CVE-2026-45737)
vulnerability in github.com/argoproj/argo-cd/v3 (CVE-2026-45737). Confidential information can be exposed externally. Mitigation: upgrade to `3.4.2` or later.
|
| CVE-2026-45713 |
|
Vulnerability in github.com/axllent/mailpit (CVE-2026-45713)
vulnerability in github.com/axllent/mailpit (CVE-2026-45713). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/send`. Mitigation: upgrade to `1.30.0` or later.
|
| CVE-2026-45712 |
|
Vulnerability in github.com/axllent/mailpit (CVE-2026-45712)
vulnerability in github.com/axllent/mailpit (CVE-2026-45712). Risk of unauthorized operations or information disclosure. Exploitable via `GET /proxy`. Mitigation: upgrade to `1.30.0` or later.
|
| CVE-2026-45711 |
|
Path Traversal in github.com/axllent/mailpit (CVE-2026-45711)
path traversal in github.com/axllent/mailpit (CVE-2026-45711). Data can be tampered with by attackers. Mitigation: upgrade to `1.30.0` or later.
|
| CVE-2026-45709 |
|
SSRF (Server-Side Request Forgery) in github.com/axllent/mailpit (CVE-2026-45709)
SSRF in github.com/axllent/mailpit (CVE-2026-45709). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/message/{id}/html-check`. Mitigation: upgrade to `1.30.0` or later.
|
| CVE-2026-45692 |
|
Vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-45692)
vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-45692). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.11.3` or later.
|
| CVE-2026-45670 |
|
Vulnerability in @nuxt/rspack-builder (CVE-2026-45670)
vulnerability in @nuxt/rspack-builder (CVE-2026-45670). Risk of unauthorized operations or information disclosure. Exploitable via ``script.src``. Mitigation: upgrade to `4.4.6` or later.
|
| SUSE-SU-2026:21721-1 |
|
Vulnerability in SUSE-SU-2026:21721-1 (SUSE-SU-2026:21721-1)
vulnerability in SUSE-SU-2026:21721-1 (SUSE-SU-2026:21721-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45669 |
|
Vulnerability in nuxt (CVE-2026-45669)
vulnerability in nuxt (CVE-2026-45669). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `4.4.6` or later.
|
| DEBIAN-CVE-2026-41054 |
|
Vulnerability in haveged (DEBIAN-CVE-2026-41054)
vulnerability in haveged (DEBIAN-CVE-2026-41054). Successful exploitation can lead to full system takeover. Exploitable via ``socket_handler``. Mitigation: upgrade to `1.9.14-1+deb11u1` or later.
|
| GHSA-xm96-gfjx-jcrc |
|
Path Traversal in land.oras:oras-java-sdk (GHSA-xm96-gfjx-jcrc)
path traversal in land.oras:oras-java-sdk (GHSA-xm96-gfjx-jcrc). Data can be tampered with by attackers. Exploitable via ``pullArtifact``. Mitigation: upgrade to `0.6.2` or later.
|
| GHSA-hv85-774v-26fg |
|
SSRF (Server-Side Request Forgery) in auth-fetch-mcp (GHSA-hv85-774v-26fg)
SSRF in auth-fetch-mcp (GHSA-hv85-774v-26fg). Confidential information can be exposed externally. Exploitable via ``download_media``. Mitigation: upgrade to `3.0.1` or later.
|
| GHSA-jvrm-qr5x-5wfx |
|
Vulnerability in @piewasm/pie-web-npm-package (GHSA-jvrm-qr5x-5wfx)
vulnerability in @piewasm/pie-web-npm-package (GHSA-jvrm-qr5x-5wfx). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-4172 |
|
Vulnerability in @piewasm/pie-web-npm-package (MAL-2026-4172)
vulnerability in @piewasm/pie-web-npm-package (MAL-2026-4172). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45758 |
|
Vulnerability in guardrails-ai (CVE-2026-45758)
vulnerability in guardrails-ai (CVE-2026-45758). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45581 |
|
Vulnerability in org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim (CVE-2026-45581)
vulnerability in org.hyperledger.fabric-chaincode-java:fabric-chaincode-shim (CVE-2026-45581). Confidential information can be exposed externally. Mitigation: upgrade to `2.5.10` or later.
|
| CVE-2026-45576 |
|
Path Traversal in github.com/openziti/zrok/v2 (CVE-2026-45576)
path traversal in github.com/openziti/zrok/v2 (CVE-2026-45576). Data can be tampered with by attackers. Exploitable via ``href``. Mitigation: upgrade to `2.0.3` or later.
|
| CVE-2026-45571 |
|
Path Traversal in github.com/go-git/go-git/v5 (CVE-2026-45571)
path traversal in github.com/go-git/go-git/v5 (CVE-2026-45571). Risk of unauthorized operations or information disclosure. Exploitable via ``Storer``. Mitigation: upgrade to `5.19.1` or later.
|
| CVE-2026-47100 |
|
Vulnerability in CVE-2026-47100 (CVE-2026-47100)
vulnerability in CVE-2026-47100 (CVE-2026-47100). Data can be tampered with by attackers.
|
| CVE-2026-8711 |
|
Vulnerability in nginx (CVE-2026-8711)
vulnerability in nginx (CVE-2026-8711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45557 |
|
Vulnerability in CVE-2026-45557 (CVE-2026-45557)
vulnerability in CVE-2026-45557 (CVE-2026-45557). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `15.0` or later.
|
| CVE-2026-44159 |
|
Vulnerability in CVE-2026-44159 (CVE-2026-44159)
vulnerability in CVE-2026-44159 (CVE-2026-44159). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43634 |
|
Vulnerability in CVE-2026-43634 (CVE-2026-43634)
vulnerability in CVE-2026-43634 (CVE-2026-43634). Data can be tampered with by attackers.
|
| CVE-2025-70950 |
|
Path Traversal in github.com/itang/gohttp (CVE-2025-70950)
path traversal in github.com/itang/gohttp (CVE-2025-70950). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34883 |
|
Vulnerability in c (CVE-2026-34883)
vulnerability in c (CVE-2026-34883). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2587 |
|
Vulnerability in org.glassfish.main.admingui:admingui (CVE-2026-2587)
vulnerability in org.glassfish.main.admingui:admingui (CVE-2026-2587). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.2` or later.
|
| CVE-2026-2586 |
|
Code Injection in org.glassfish.main.admingui:console-common (CVE-2026-2586)
code injection in org.glassfish.main.admingui:console-common (CVE-2026-2586). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.2` or later.
|
| CVE-2025-51427 |
|
Code Injection in modelscope (CVE-2025-51427)
code injection in modelscope (CVE-2025-51427). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.27.0` or later.
|
| CLSA-2026-1779204531 |
|
Vulnerability in gdk-pixbuf2 (CLSA-2026-1779204531)
vulnerability in gdk-pixbuf2 (CLSA-2026-1779204531). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.36.12-3.el7.tuxcare.els2` or later.
|
| GHSA-jjv2-fjq3-2ggj |
|
Vulnerability in is-really-odd (GHSA-jjv2-fjq3-2ggj)
vulnerability in is-really-odd (GHSA-jjv2-fjq3-2ggj). Risk of unauthorized operations or information disclosure.
|
| CLSA-2026-1779204267 |
|
Vulnerability in gdk-pixbuf2 (CLSA-2026-1779204267)
vulnerability in gdk-pixbuf2 (CLSA-2026-1779204267). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.36.12-3.el7.tuxcare.els2` or later.
|
| CLSA-2026-1779204107 |
|
Vulnerability in php (CLSA-2026-1779204107)
vulnerability in php (CLSA-2026-1779204107). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.4.19-1.module_el8.5.0+2407+c59885f4.tuxcare.els27` or later.
|
| CVE-2026-45570 |
|
Vulnerability in github.com/go-git/go-git/v5 (CVE-2026-45570)
vulnerability in github.com/go-git/go-git/v5 (CVE-2026-45570). Successful exploitation can lead to full system takeover. Exploitable via ``sq_quote_buf``. Mitigation: upgrade to `5.19.1` or later.
|
| CLSA-2026-1779204030 |
|
mod_jk: Fix of CVE-2024-46544
mod_jk: Fix of CVE-2024-46544
|
| ALPINE-CVE-2026-8711 |
|
Vulnerability in nginx (ALPINE-CVE-2026-8711)
vulnerability in nginx (ALPINE-CVE-2026-8711). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.30.2-r1` or later.
|
| DEBIAN-CVE-2026-8711 |
|
Vulnerability in libnginx-mod-js (DEBIAN-CVE-2026-8711)
vulnerability in libnginx-mod-js (DEBIAN-CVE-2026-8711). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.9.9-1` or later.
|
| CVE-2026-45568 |
|
Path Traversal in zrok (CVE-2026-45568)
path traversal in zrok (CVE-2026-45568). Confidential information can be exposed externally. Exploitable via ``ProxyShare``.
|
| UBUNTU-CVE-2026-8711 |
|
Vulnerability in libnginx-mod-js (UBUNTU-CVE-2026-8711)
vulnerability in libnginx-mod-js (UBUNTU-CVE-2026-8711). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.9.4-1ubuntu0.1~esm1` or later.
|