Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CLSA-2026-1778874422 |
|
Vulnerability in postfix (CLSA-2026-1778874422)
vulnerability in postfix (CLSA-2026-1778874422). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:3.5.9-19.el9.tuxcare.els2` or later.
|
| CLSA-2026-1778873714 |
|
mod_http2: Fix of CVE-2023-45802
mod_http2: Fix of CVE-2023-45802
|
| DEBIAN-CVE-2026-8700 |
|
Vulnerability in libcrypt-dsa-perl (DEBIAN-CVE-2026-8700)
vulnerability in libcrypt-dsa-perl (DEBIAN-CVE-2026-8700). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.20-1` or later.
|
| CVE-2026-8700 |
|
Vulnerability in CVE-2026-8700 (CVE-2026-8700)
vulnerability in CVE-2026-8700 (CVE-2026-8700). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-8700 |
|
Vulnerability in libcrypt-dsa-perl (UBUNTU-CVE-2026-8700)
vulnerability in libcrypt-dsa-perl (UBUNTU-CVE-2026-8700). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:1876-1 |
|
Vulnerability in SUSE-SU-2026:1876-1 (SUSE-SU-2026:1876-1)
vulnerability in SUSE-SU-2026:1876-1 (SUSE-SU-2026:1876-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8696 |
|
Use-After-Free in dos (CVE-2026-8696)
vulnerability in dos (CVE-2026-8696). Risk of unauthorized operations or information disclosure.
|
| GHSA-cqrw-j4qc-7f9w |
|
Authorization Flaw in thorsten/phpmyfaq (GHSA-cqrw-j4qc-7f9w)
vulnerability in thorsten/phpmyfaq (GHSA-cqrw-j4qc-7f9w). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2` or later.
|
| GHSA-478m-mrw4-qf2w |
|
Cross-Site Scripting (XSS) in thorsten/phpmyfaq (GHSA-478m-mrw4-qf2w)
cross-site scripting in thorsten/phpmyfaq (GHSA-478m-mrw4-qf2w). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2` or later.
|
| GHSA-6626-79jh-5ccr |
|
Vulnerability in thorsten/phpmyfaq (GHSA-6626-79jh-5ccr)
vulnerability in thorsten/phpmyfaq (GHSA-6626-79jh-5ccr). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2` or later.
|
| GHSA-p26v-fx3x-r2rp |
|
Vulnerability in thorsten/phpmyfaq (GHSA-p26v-fx3x-r2rp)
vulnerability in thorsten/phpmyfaq (GHSA-p26v-fx3x-r2rp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.2` or later.
|
| GHSA-p9wc-4pjv-rg82 |
|
SQL Injection in thorsten/phpmyfaq (GHSA-p9wc-4pjv-rg82)
SQL injection in thorsten/phpmyfaq (GHSA-p9wc-4pjv-rg82). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.2` or later.
|
| GHSA-w9mj-gfrm-hj5x |
|
Authorization Flaw in thorsten/phpmyfaq (GHSA-w9mj-gfrm-hj5x)
vulnerability in thorsten/phpmyfaq (GHSA-w9mj-gfrm-hj5x). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2` or later.
|
| GHSA-ch9q-c9mp-j5gq |
|
SQL Injection in thorsten/phpmyfaq (GHSA-ch9q-c9mp-j5gq)
SQL injection in thorsten/phpmyfaq (GHSA-ch9q-c9mp-j5gq). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/captcha`. Mitigation: upgrade to `4.1.2` or later.
|
| UBUNTU-CVE-2026-8696 |
|
Vulnerability in radare2 (UBUNTU-CVE-2026-8696)
vulnerability in radare2 (UBUNTU-CVE-2026-8696). Risk of unauthorized operations or information disclosure.
|
| MINI-x8mf-vv94-9wp6 |
|
MINI-x8mf-vv94-9wp6 |
| CGA-w2fm-mfcc-5r46 |
|
CGA-w2fm-mfcc-5r46 |
| CGA-w99c-3vgh-qrg5 |
|
CGA-w99c-3vgh-qrg5 |
| CGA-q6rr-v9r6-c9xm |
|
CGA-q6rr-v9r6-c9xm |
| CGA-qr6c-w2fv-52jm |
|
CGA-qr6c-w2fv-52jm |
| CGA-v9pj-2c78-79r8 |
|
CGA-v9pj-2c78-79r8 |
| CGA-mwq7-hh94-fjqp |
|
CGA-mwq7-hh94-fjqp |
| CGA-m8ww-4pg5-7jr3 |
|
CGA-m8ww-4pg5-7jr3 |
| CGA-mc7p-cj26-v5p2 |
|
CGA-mc7p-cj26-v5p2 |
| CGA-j59r-9gfm-mm3c |
|
CGA-j59r-9gfm-mm3c |
| CGA-grwh-gq6r-8w4c |
|
CGA-grwh-gq6r-8w4c |
| CGA-gx43-hg5j-6mw2 |
|
CGA-gx43-hg5j-6mw2 |
| CGA-g745-8989-65mc |
|
CGA-g745-8989-65mc |
| CGA-f4rw-4pgf-xfrg |
|
CGA-f4rw-4pgf-xfrg |
| CGA-f8r5-9q74-2mw5 |
|
CGA-f8r5-9q74-2mw5 |
| CGA-9xm3-x84m-gh3c |
|
CGA-9xm3-x84m-gh3c |
| CGA-9fp4-3r9w-7wgx |
|
CGA-9fp4-3r9w-7wgx |
| CGA-88cp-vrcc-j2x5 |
|
CGA-88cp-vrcc-j2x5 |
| CGA-7mhh-g294-2422 |
|
CGA-7mhh-g294-2422 |
| CGA-g2cc-p4h9-4m44 |
|
CGA-g2cc-p4h9-4m44 |
| CGA-774j-r4wh-gwm2 |
|
CGA-774j-r4wh-gwm2 |
| CGA-cq3m-32gg-3c26 |
|
CGA-cq3m-32gg-3c26 |
| CGA-56jx-ghqp-6r7v |
|
CGA-56jx-ghqp-6r7v |
| CGA-4qr5-xjpg-v4jw |
|
CGA-4qr5-xjpg-v4jw |
| CGA-5hw3-vrqw-q7j4 |
|
CGA-5hw3-vrqw-q7j4 |
| CGA-3ccp-gf5g-46gp |
|
CGA-3ccp-gf5g-46gp |
| CGA-89gg-3pm3-r673 |
|
CGA-89gg-3pm3-r673 |
| CGA-3453-2rpm-pjgh |
|
CGA-3453-2rpm-pjgh |
| CGA-2x5h-rf7r-xxfx |
|
CGA-2x5h-rf7r-xxfx |
| CGA-47mf-3rqq-x4f3 |
|
CGA-47mf-3rqq-x4f3 |
| CVE-2025-67031 |
|
Code Injection in CVE-2025-67031 (CVE-2025-67031)
code injection in CVE-2025-67031 (CVE-2025-67031). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8686 |
|
Out-of-Bounds Read in Amazon aws (CVE-2026-8686)
vulnerability in Amazon aws (CVE-2026-8686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4054 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4054)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4054). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.4.4` or later.
|
| CVE-2026-4053 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4053)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4053). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.0-20260414103857-b21ef302025e` or later.
|
| CVE-2026-46408 |
|
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter t...
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter the payment flow without verifying cart ownership. A logged-in attacker can therefore reuse another u...
|