Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CLSA-2026-1779129626 |
|
Vulnerability in httpd (CLSA-2026-1779129626)
vulnerability in httpd (CLSA-2026-1779129626). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.6-99.0.5.el7_9.1.tuxcare.els11` or later.
|
| CLSA-2026-1779129500 |
|
Vulnerability in libpng15 (CLSA-2026-1779129500)
vulnerability in libpng15 (CLSA-2026-1779129500). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.30-14.el9.tuxcare.els3` or later.
|
| CLSA-2026-1779129362 |
|
Vulnerability in expat (CLSA-2026-1779129362)
vulnerability in expat (CLSA-2026-1779129362). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.2.5-3ubuntu0.9+tuxcare.els6` or later.
|
| CLSA-2026-1779129222 |
|
Vulnerability in expat (CLSA-2026-1779129222)
vulnerability in expat (CLSA-2026-1779129222). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.1.0-7ubuntu0.16.04.5+tuxcare.els9` or later.
|
| CVE-2026-45495 |
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
| CVE-2026-45494 |
|
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
|
| CVE-2026-45492 |
|
Vulnerability in microsoft (CVE-2026-45492)
vulnerability in microsoft (CVE-2026-45492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45230 |
|
Path Traversal in path-traversal (CVE-2026-45230)
path traversal in path-traversal (CVE-2026-45230). Data can be tampered with by attackers. Exploitable via `POST /api/delete-file`.
|
| CVE-2026-32848 |
|
Vulnerability in CVE-2026-32848 (CVE-2026-32848)
vulnerability in CVE-2026-32848 (CVE-2026-32848). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-24215 |
|
Vulnerability in CVE-2023-24215 (CVE-2023-24215)
vulnerability in CVE-2023-24215 (CVE-2023-24215). Confidential information can be exposed externally.
|
| CVE-2026-32849 |
|
Vulnerability in c (CVE-2026-32849)
vulnerability in c (CVE-2026-32849). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29963 |
|
Path Traversal in path-traversal (CVE-2026-29963)
path traversal in path-traversal (CVE-2026-29963). Confidential information can be exposed externally.
|
| CVE-2026-29965 |
|
Cross-Site Scripting (XSS) in hsclabs (CVE-2026-29965)
cross-site scripting in hsclabs (CVE-2026-29965). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42822 |
|
Authentication Bypass in microsoft (CVE-2026-42822)
authentication bypass in microsoft (CVE-2026-42822). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29964 |
|
Cross-Site Scripting (XSS) in hsclabs (CVE-2026-29964)
cross-site scripting in hsclabs (CVE-2026-29964). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29962 |
|
Vulnerability in path-traversal (CVE-2026-29962)
vulnerability in path-traversal (CVE-2026-29962). Confidential information can be exposed externally.
|
| CGA-mr59-cwrg-jqx9 |
|
CGA-mr59-cwrg-jqx9 |
| CLSA-2026-1779129021 |
|
Vulnerability in imagemagick (CLSA-2026-1779129021)
vulnerability in imagemagick (CLSA-2026-1779129021). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8:6.8.9.9-7ubuntu5.17+tuxcare.els47` or later.
|
| MINI-q7pv-hhfw-v3gg |
|
MINI-q7pv-hhfw-v3gg |
| MINI-g9c6-7g6w-7x9g |
|
MINI-g9c6-7g6w-7x9g |
| MINI-7fc7-55jr-vqf9 |
|
MINI-7fc7-55jr-vqf9 |
| CGA-grcv-9jqv-f3v4 |
|
CGA-grcv-9jqv-f3v4 |
| CLSA-2026-1779128088 |
|
Vulnerability in ImageMagick (CLSA-2026-1779128088)
vulnerability in ImageMagick (CLSA-2026-1779128088). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.9.13.25-1.el8_4.tuxcare.els30` or later.
|
| CLSA-2026-1779127797 |
|
Vulnerability in libpng15 (CLSA-2026-1779127797)
vulnerability in libpng15 (CLSA-2026-1779127797). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.30-14.el9.tuxcare.els3` or later.
|
| CLSA-2026-1779127684 |
|
Vulnerability in ImageMagick (CLSA-2026-1779127684)
vulnerability in ImageMagick (CLSA-2026-1779127684). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.9.13.25-1.el8.tuxcare.els30` or later.
|
| RLSA-2026:18030 |
|
Vulnerability in rubygem-mysql2 (RLSA-2026:18030)
vulnerability in rubygem-mysql2 (RLSA-2026:18030). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:0.5.5-3.module+el9.7.0+40032+36e56d0d` or later.
|
| CLSA-2026-1779127347 |
|
Vulnerability in imagemagick (CLSA-2026-1779127347)
vulnerability in imagemagick (CLSA-2026-1779127347). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8:6.9.7.4+dfsg-16ubuntu6.15+tuxcare.els36` or later.
|
| RLSA-2026:18041 |
|
Vulnerability in nginx (RLSA-2026:18041)
vulnerability in nginx (RLSA-2026:18041). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1:1.24.0-3.module+el8.10.0+40144+38158758` or later.
|
| CVE-2026-45678 |
|
Vulnerability in go.opentelemetry.io/obi (CVE-2026-45678)
vulnerability in go.opentelemetry.io/obi (CVE-2026-45678). Risk of unauthorized operations or information disclosure. Exploitable via ``BIND``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45679 |
|
Vulnerability in go.opentelemetry.io/obi (CVE-2026-45679)
vulnerability in go.opentelemetry.io/obi (CVE-2026-45679). Risk of unauthorized operations or information disclosure. Exploitable via ``getRedisError``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45676 |
|
Vulnerability in go.opentelemetry.io/obi (CVE-2026-45676)
vulnerability in go.opentelemetry.io/obi (CVE-2026-45676). Risk of unauthorized operations or information disclosure. Exploitable via ``GetCStringUnsafe``. Mitigation: upgrade to `0.9.0` or later.
|
| GHSA-jgg6-4rpr-wfh7 |
|
Vulnerability in @mistralai/mistralai (GHSA-jgg6-4rpr-wfh7)
vulnerability in @mistralai/mistralai (GHSA-jgg6-4rpr-wfh7). Risk of unauthorized operations or information disclosure. Exploitable via ``setup.mjs``.
|
| GHSA-wx9m-wx4f-4cmg |
|
Vulnerability in mistralai (GHSA-wx9m-wx4f-4cmg)
vulnerability in mistralai (GHSA-wx9m-wx4f-4cmg). Successful exploitation can lead to full system takeover. Exploitable via ``mistralai``.
|
| CLSA-2026-1779126860 |
|
Vulnerability in nginx (CLSA-2026-1779126860)
vulnerability in nginx (CLSA-2026-1779126860). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:1.20.1-22.el9_6.3.alma.2.tuxcare.els4` or later.
|
| CVE-2026-45031 |
|
Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-45031)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-45031). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.13.1` or later.
|
| CVE-2026-42306 |
|
Vulnerability in github.com/docker/docker (CVE-2026-42306)
vulnerability in github.com/docker/docker (CVE-2026-42306). Data can be tampered with by attackers. Exploitable via `PUT /containers/{id}/archive`. Mitigation: upgrade to `2.0.0-beta.14` or later.
|
| CVE-2026-41568 |
|
Vulnerability in github.com/docker/docker (CVE-2026-41568)
vulnerability in github.com/docker/docker (CVE-2026-41568). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /containers/{id}/archive`. Mitigation: upgrade to `2.0.0-beta.14` or later.
|
| CVE-2026-45727 |
|
Path Traversal in cloakbrowser (CVE-2026-45727)
path traversal in cloakbrowser (CVE-2026-45727). Risk of unauthorized operations or information disclosure. Exploitable via ``cloakserve``. Mitigation: upgrade to `0.3.28` or later.
|
| CVE-2026-45358 |
|
Out-of-Bounds Read in Magick.NET-Q16-AnyCPU (CVE-2026-45358)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-45358). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.13.1` or later.
|
| CVE-2026-45359 |
|
Out-of-Bounds Read in Magick.NET-Q16-AnyCPU (CVE-2026-45359)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-45359). Confidential information can be exposed externally. Mitigation: upgrade to `14.13.1` or later.
|
| CVE-2026-45719 |
|
Code Injection in @budibase/server (CVE-2026-45719)
code injection in @budibase/server (CVE-2026-45719). Confidential information can be exposed externally. Exploitable via `POST /api/views`. Mitigation: upgrade to `3.38.1` or later.
|
| CVE-2026-41567 |
|
Vulnerability in github.com/moby/moby/v2 (CVE-2026-41567)
vulnerability in github.com/moby/moby/v2 (CVE-2026-41567). Confidential information can be exposed externally. Exploitable via `PUT /containers/{id}/archive`. Mitigation: upgrade to `2.0.0-beta.14` or later.
|
| CVE-2026-45718 |
|
Authorization Flaw in budibase (CVE-2026-45718)
vulnerability in budibase (CVE-2026-45718). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/tables/`. Mitigation: upgrade to `3.38.1` or later.
|
| CLSA-2026-1779126256 |
|
Vulnerability in nginx (CLSA-2026-1779126256)
vulnerability in nginx (CLSA-2026-1779126256). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.10.3-0ubuntu0.16.04.8+tuxcare.els6` or later.
|
| CVE-2026-45716 |
|
Privilege Escalation in @budibase/worker (CVE-2026-45716)
vulnerability in @budibase/worker (CVE-2026-45716). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/global/users/onboard`. Mitigation: upgrade to `3.38.1` or later.
|
| CVE-2026-45707 |
|
Vulnerability in n8n-mcp (CVE-2026-45707)
vulnerability in n8n-mcp (CVE-2026-45707). Confidential information can be exposed externally. Exploitable via ``N8N_API_URL``. Mitigation: upgrade to `2.51.2` or later.
|
| CLSA-2026-1779125894 |
|
Vulnerability in php (CLSA-2026-1779125894)
vulnerability in php (CLSA-2026-1779125894). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.30-3.el9_6.tuxcare.els5` or later.
|
| GHSA-9m6v-8fxc-4r44 |
|
Vulnerability in sulu/sulu (GHSA-9m6v-8fxc-4r44)
vulnerability in sulu/sulu (GHSA-9m6v-8fxc-4r44). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.23` or later.
|
| CGA-fhfv-929f-5w7g |
|
CGA-fhfv-929f-5w7g |
| CGA-5w26-4q7h-mpgm |
|
CGA-5w26-4q7h-mpgm |