Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MAL-2026-3878 |
|
Vulnerability in @antv/dw-util (MAL-2026-3878)
vulnerability in @antv/dw-util (MAL-2026-3878). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3877 |
|
Vulnerability in @antv/dw-transform (MAL-2026-3877)
vulnerability in @antv/dw-transform (MAL-2026-3877). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-q9w3-3q3j-cmcw |
|
Vulnerability in @antv/event-emitter (GHSA-q9w3-3q3j-cmcw)
vulnerability in @antv/event-emitter (GHSA-q9w3-3q3j-cmcw). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3876 |
|
Vulnerability in @antv/dw-random (MAL-2026-3876)
vulnerability in @antv/dw-random (MAL-2026-3876). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-f5cv-h987-mvvf |
|
Vulnerability in @antv/dumi-theme-antv (GHSA-f5cv-h987-mvvf)
vulnerability in @antv/dumi-theme-antv (GHSA-f5cv-h987-mvvf). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3873 |
|
Vulnerability in @antv/dom-util (MAL-2026-3873)
vulnerability in @antv/dom-util (MAL-2026-3873). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3875 |
|
Vulnerability in @antv/dw-analyzer (MAL-2026-3875)
vulnerability in @antv/dw-analyzer (MAL-2026-3875). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3872 |
|
Vulnerability in @antv/dipper-map (MAL-2026-3872)
vulnerability in @antv/dipper-map (MAL-2026-3872). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3871 |
|
Vulnerability in @antv/dipper-hooks (MAL-2026-3871)
vulnerability in @antv/dipper-hooks (MAL-2026-3871). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3870 |
|
Vulnerability in @antv/dipper-component (MAL-2026-3870)
vulnerability in @antv/dipper-component (MAL-2026-3870). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3869 |
|
Vulnerability in @antv/data-wizard (MAL-2026-3869)
vulnerability in @antv/data-wizard (MAL-2026-3869). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3868 |
|
Vulnerability in @antv/data-set (MAL-2026-3868)
vulnerability in @antv/data-set (MAL-2026-3868). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3867 |
|
Vulnerability in @antv/data-samples (MAL-2026-3867)
vulnerability in @antv/data-samples (MAL-2026-3867). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3866 |
|
Vulnerability in @antv/d3-interpolate (MAL-2026-3866)
vulnerability in @antv/d3-interpolate (MAL-2026-3866). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-64h3-x3fh-6m3v |
|
Vulnerability in @antv/d3-color (GHSA-64h3-x3fh-6m3v)
vulnerability in @antv/d3-color (GHSA-64h3-x3fh-6m3v). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3859 |
|
Vulnerability in @antv/chart-visualization-skills (MAL-2026-3859)
vulnerability in @antv/chart-visualization-skills (MAL-2026-3859). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-84cc-wx9h-mh2c |
|
Vulnerability in @antv/expr (GHSA-84cc-wx9h-mh2c)
vulnerability in @antv/expr (GHSA-84cc-wx9h-mh2c). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3857 |
|
Vulnerability in @antv/chart-linter (MAL-2026-3857)
vulnerability in @antv/chart-linter (MAL-2026-3857). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-6vch-5wrx-6pmp |
|
Vulnerability in @antv/component (GHSA-6vch-5wrx-6pmp)
vulnerability in @antv/component (GHSA-6vch-5wrx-6pmp). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-rh6v-hwr4-6jcp |
|
Vulnerability in @antv/color-util (GHSA-rh6v-hwr4-6jcp)
vulnerability in @antv/color-util (GHSA-rh6v-hwr4-6jcp). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-px5p-fr46-56q3 |
|
Vulnerability in @antv/color-schema (GHSA-px5p-fr46-56q3)
vulnerability in @antv/color-schema (GHSA-px5p-fr46-56q3). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-rx57-h637-696p |
|
Vulnerability in @antv/ckb (GHSA-rx57-h637-696p)
vulnerability in @antv/ckb (GHSA-rx57-h637-696p). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-2qrw-8mg6-hjhv |
|
Vulnerability in @antv/chart-node-g6 (GHSA-2qrw-8mg6-hjhv)
vulnerability in @antv/chart-node-g6 (GHSA-2qrw-8mg6-hjhv). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3856 |
|
Vulnerability in @antv/calendar-heatmap (MAL-2026-3856)
vulnerability in @antv/calendar-heatmap (MAL-2026-3856). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3855 |
|
Vulnerability in @antv/awards (MAL-2026-3855)
vulnerability in @antv/awards (MAL-2026-3855). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-x9px-j6fm-r9pc |
|
Vulnerability in @antv/ava (GHSA-x9px-j6fm-r9pc)
vulnerability in @antv/ava (GHSA-x9px-j6fm-r9pc). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3854 |
|
Vulnerability in @antv/ava-react (MAL-2026-3854)
vulnerability in @antv/ava-react (MAL-2026-3854). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| GHSA-67gw-xqjm-h2mx |
|
Vulnerability in @antv/attr (GHSA-67gw-xqjm-h2mx)
vulnerability in @antv/attr (GHSA-67gw-xqjm-h2mx). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3848 |
|
Vulnerability in @antv/a8 (MAL-2026-3848)
vulnerability in @antv/a8 (MAL-2026-3848). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3898 |
|
Vulnerability in @antv/f2-wordcloud (MAL-2026-3898)
vulnerability in @antv/f2-wordcloud (MAL-2026-3898). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3849 |
|
Vulnerability in @antv/adjust (MAL-2026-3849)
vulnerability in @antv/adjust (MAL-2026-3849). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3851 |
|
Vulnerability in @antv/async-hook (MAL-2026-3851)
vulnerability in @antv/async-hook (MAL-2026-3851). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3850 |
|
Vulnerability in @antv/algorithm (MAL-2026-3850)
vulnerability in @antv/algorithm (MAL-2026-3850). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| MAL-2026-3864 |
|
Vulnerability in @antv/coord (MAL-2026-3864)
vulnerability in @antv/coord (MAL-2026-3864). Risk of unauthorized operations or information disclosure. Exploitable via ``atool``.
|
| CVE-2026-30950 |
|
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijack...
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijacking via IDOR. If an authenticated attacker can determine the session_id of another user's session, t...
|
| CVE-2026-27964 |
|
Cross-Site Scripting (XSS) in facturascripts/facturascripts (CVE-2026-27964)
cross-site scripting in facturascripts/facturascripts (CVE-2026-27964). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27892 |
|
Information Disclosure in facturascripts/facturascripts (CVE-2026-27892)
vulnerability in facturascripts/facturascripts (CVE-2026-27892). Confidential information can be exposed externally. Exploitable via ``exiftool``.
|
| CVE-2026-27891 |
|
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the f...
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leadin...
|
| CVE-2026-27737 |
|
Cross-Site Scripting (XSS) in CVE-2026-27737 (CVE-2026-27737)
cross-site scripting in CVE-2026-27737 (CVE-2026-27737). Data can be tampered with by attackers.
|
| CVE-2026-8851 |
|
SQL Injection in sqli (CVE-2026-8851)
SQL injection in sqli (CVE-2026-8851). Confidential information can be exposed externally.
|
| CVE-2026-4137 |
|
Vulnerability in mlflow (CVE-2026-4137)
vulnerability in mlflow (CVE-2026-4137). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.0` or later.
|
| CVE-2026-47092 |
|
Vulnerability in jarrodwatts (CVE-2026-47092)
vulnerability in jarrodwatts (CVE-2026-47092). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45246 |
|
Vulnerability in steipete (CVE-2026-45246)
vulnerability in steipete (CVE-2026-45246). Confidential information can be exposed externally.
|
| CVE-2026-45244 |
|
Vulnerability in @steipete/summarize (CVE-2026-45244)
vulnerability in @steipete/summarize (CVE-2026-45244). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.15.0` or later.
|
| CVE-2026-21789 |
|
Authorization Flaw in CVE-2026-21789 (CVE-2026-21789)
vulnerability in CVE-2026-21789 (CVE-2026-21789). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45245 |
|
SSRF (Server-Side Request Forgery) in @steipete/summarize (CVE-2026-45245)
SSRF in @steipete/summarize (CVE-2026-45245). Confidential information can be exposed externally. Mitigation: upgrade to `0.15.1` or later.
|
| CVE-2026-47091 |
|
Path Traversal in path-traversal (CVE-2026-47091)
path traversal in path-traversal (CVE-2026-47091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47090 |
|
Vulnerability in jarrodwatts (CVE-2026-47090)
vulnerability in jarrodwatts (CVE-2026-47090). Risk of unauthorized operations or information disclosure.
|
| CGA-rxxj-chcq-9wfp |
|
CGA-rxxj-chcq-9wfp |
| CGA-cgw9-chqf-gxmh |
|
CGA-cgw9-chqf-gxmh |