Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-45701 Vulnerability in sulu/sulu (CVE-2026-45701)
vulnerability in sulu/sulu (CVE-2026-45701). Risk of unauthorized operations or information disclosure. Exploitable via ``User.php``. Mitigation: upgrade to `2.6.23` or later.
CVE-2026-45363 Vulnerability in jwt (CVE-2026-45363)
vulnerability in jwt (CVE-2026-45363). Confidential information can be exposed externally. Exploitable via ``enforce_hmac_key_length``. Mitigation: upgrade to `2.10.3` or later.
CLSA-2026-1779125079 Vulnerability in php (CLSA-2026-1779125079)
vulnerability in php (CLSA-2026-1779125079). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.2.24-1.module_el8+2405+28f8b298.tuxcare.els24` or later.
CVE-2026-45697 Code Injection in verbb/formie (CVE-2026-45697)
code injection in verbb/formie (CVE-2026-45697). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.2.20` or later.
CLSA-2026-1779124827 log4j: Fix of CVE-2026-34479
log4j: Fix of CVE-2026-34479
CVE-2026-45327 Vulnerability in github.com/DatanoiseTV/tinyice (CVE-2026-45327)
vulnerability in github.com/DatanoiseTV/tinyice (CVE-2026-45327). Data can be tampered with by attackers. Exploitable via `POST /webrtc/source-offer`. Mitigation: upgrade to `2.5.0` or later.
CVE-2026-8843 Vulnerability in CVE-2026-8843 (CVE-2026-8843)
vulnerability in CVE-2026-8843 (CVE-2026-8843). Risk of unauthorized operations or information disclosure.
CVE-2026-45829 Code Injection in chromadb (CVE-2026-45829)
code injection in chromadb (CVE-2026-45829). Successful exploitation can lead to full system takeover.
CVE-2026-41085 Privilege Escalation in privilege-escalation (CVE-2026-41085)
vulnerability in privilege-escalation (CVE-2026-41085). Successful exploitation can lead to full system takeover.
CVE-2026-38719 Out-of-Bounds Read in c (CVE-2026-38719)
vulnerability in c (CVE-2026-38719). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-8843 Vulnerability in mongodb (UBUNTU-CVE-2026-8843)
vulnerability in mongodb (UBUNTU-CVE-2026-8843). Risk of unauthorized operations or information disclosure.
CLSA-2026-1779124021 Vulnerability in firewall-applet (CLSA-2026-1779124021)
vulnerability in firewall-applet (CLSA-2026-1779124021). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.3.4-15.el9_6.tuxcare.els1` or later.
CVE-2026-45325 Vulnerability in @tmlmobilidade/utils (CVE-2026-45325)
vulnerability in @tmlmobilidade/utils (CVE-2026-45325). Data can be tampered with by attackers. Mitigation: upgrade to `20260509.0340.15` or later.
CLSA-2026-1779123668 Vulnerability in libapache2-mod-php7.4 (CLSA-2026-1779123668)
vulnerability in libapache2-mod-php7.4 (CLSA-2026-1779123668). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.4.3-4ubuntu2.29+tuxcare.els5` or later.
GHSA-fvh2-gm75-j4j7 Vulnerability in dynoxide-rs (GHSA-fvh2-gm75-j4j7)
vulnerability in dynoxide-rs (GHSA-fvh2-gm75-j4j7). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `0.9.13` or later.
CLSA-2026-1779123410 Vulnerability in jq (CLSA-2026-1779123410)
vulnerability in jq (CLSA-2026-1779123410). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6-14.el9.tuxcare.els6` or later.
CLSA-2026-1779122764 Vulnerability in nano (CLSA-2026-1779122764)
vulnerability in nano (CLSA-2026-1779122764). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.6.1-5.el9.tuxcare.els1` or later.
CVE-2026-45302 Vulnerability in parse-nested-form-data (CVE-2026-45302)
vulnerability in parse-nested-form-data (CVE-2026-45302). Data can be tampered with by attackers. Exploitable via ``__proto__``. Mitigation: upgrade to `1.0.1` or later.
CVE-2026-45300 Information Disclosure in org.asynchttpclient:async-http-client (CVE-2026-45300)
vulnerability in org.asynchttpclient:async-http-client (CVE-2026-45300). Confidential information can be exposed externally. Exploitable via ``Cookie``. Mitigation: upgrade to `2.15.0` or later.
CVE-2026-45298 SSRF (Server-Side Request Forgery) in github.com/amir20/dozzle (CVE-2026-45298)
SSRF in github.com/amir20/dozzle (CVE-2026-45298). Confidential information can be exposed externally. Exploitable via `POST /api/notifications/test-webhook`.
GHSA-9rh9-hf3w-9fgg Vulnerability in shopper/cart (GHSA-9rh9-hf3w-9fgg)
vulnerability in shopper/cart (GHSA-9rh9-hf3w-9fgg). Data can be tampered with by attackers. Exploitable via ``Order``. Mitigation: upgrade to `2.8.0` or later.
CLSA-2026-1779122132 expat: Fix of CVE-2026-45186
expat: Fix of CVE-2026-45186
GHSA-f946-9qp6-vgch Vulnerability in shopper/framework (GHSA-f946-9qp6-vgch)
vulnerability in shopper/framework (GHSA-f946-9qp6-vgch). Confidential information can be exposed externally. Exploitable via ``read_orders``. Mitigation: upgrade to `2.8.0` or later.
MINI-8gj7-9jg5-vpqg MINI-8gj7-9jg5-vpqg
MINI-x8pp-f5f4-73xx MINI-x8pp-f5f4-73xx
MINI-j25r-6c8c-hc93 MINI-j25r-6c8c-hc93
MINI-8xwv-xjr2-36pm MINI-8xwv-xjr2-36pm
MINI-9gq8-rwr8-j8vx MINI-9gq8-rwr8-j8vx
MINI-79m3-25gj-89gh MINI-79m3-25gj-89gh
MINI-qx63-27jx-pp87 MINI-qx63-27jx-pp87
MINI-w47h-pfm5-4c65 MINI-w47h-pfm5-4c65
SUSE-SU-2026:1997-1 Vulnerability in SUSE-SU-2026:1997-1 (SUSE-SU-2026:1997-1)
vulnerability in SUSE-SU-2026:1997-1 (SUSE-SU-2026:1997-1). Risk of unauthorized operations or information disclosure.
MINI-3w8p-f4fh-m6c6 MINI-3w8p-f4fh-m6c6
MINI-53pf-cvxp-h8jj MINI-53pf-cvxp-h8jj
MINI-xm8j-pxff-9p4v MINI-xm8j-pxff-9p4v
CVE-2026-46385 Vulnerability in github.com/iskorotkov/avro/v2 (CVE-2026-46385)
vulnerability in github.com/iskorotkov/avro/v2 (CVE-2026-46385). Risk of unauthorized operations or information disclosure. Exploitable via ``Reader.ReadBlockHeader``. Mitigation: upgrade to `2.33.0` or later.
MINI-pvhf-8cj3-f7p5 MINI-pvhf-8cj3-f7p5
MINI-7x3c-ch74-wfmj MINI-7x3c-ch74-wfmj
MINI-2q37-qh9f-464m MINI-2q37-qh9f-464m
MINI-684r-fwh4-v977 MINI-684r-fwh4-v977
CVE-2026-45270 Cross-Site Scripting (XSS) in ci4-cms-erp/ci4ms (CVE-2026-45270)
cross-site scripting in ci4-cms-erp/ci4ms (CVE-2026-45270). Confidential information can be exposed externally. Exploitable via ``Pages``. Mitigation: upgrade to `0.31.9.0` or later.
CVE-2026-46384 Vulnerability in github.com/iskorotkov/avro/v2 (CVE-2026-46384)
vulnerability in github.com/iskorotkov/avro/v2 (CVE-2026-46384). Risk of unauthorized operations or information disclosure. Exploitable via ``int``. Mitigation: upgrade to `2.33.0` or later.
CVE-2026-45149 Vulnerability in brace-expansion (CVE-2026-45149)
vulnerability in brace-expansion (CVE-2026-45149). Risk of unauthorized operations or information disclosure. Exploitable via ``max``. Mitigation: upgrade to `5.0.6` or later.
CVE-2026-45139 Vulnerability in ci4-cms-erp/ci4ms (CVE-2026-45139)
vulnerability in ci4-cms-erp/ci4ms (CVE-2026-45139). Data can be tampered with by attackers. Exploitable via ``saveFile``. Mitigation: upgrade to `0.31.9.0` or later.
CVE-2026-36438 Vulnerability in CVE-2026-36438 (CVE-2026-36438)
vulnerability in CVE-2026-36438 (CVE-2026-36438). Risk of unauthorized operations or information disclosure.
CVE-2026-20685 Vulnerability in apple (CVE-2026-20685)
vulnerability in apple (CVE-2026-20685). Confidential information can be exposed externally.
CVE-2025-57282 ngrok is Vulnerable to Command Injection
ngrok is Vulnerable to Command Injection
CVE-2025-56352 Vulnerability in dos (CVE-2025-56352)
vulnerability in dos (CVE-2025-56352). Risk of unauthorized operations or information disclosure.
MINI-hcxf-926w-6g9q MINI-hcxf-926w-6g9q
MINI-rvx2-542x-8h4h MINI-rvx2-542x-8h4h

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →