Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CLSA-2026-1778874422 Vulnerability in postfix (CLSA-2026-1778874422)
vulnerability in postfix (CLSA-2026-1778874422). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:3.5.9-19.el9.tuxcare.els2` or later.
CLSA-2026-1778873714 mod_http2: Fix of CVE-2023-45802
mod_http2: Fix of CVE-2023-45802
DEBIAN-CVE-2026-8700 Vulnerability in libcrypt-dsa-perl (DEBIAN-CVE-2026-8700)
vulnerability in libcrypt-dsa-perl (DEBIAN-CVE-2026-8700). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.20-1` or later.
CVE-2026-8700 Vulnerability in CVE-2026-8700 (CVE-2026-8700)
vulnerability in CVE-2026-8700 (CVE-2026-8700). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-8700 Vulnerability in libcrypt-dsa-perl (UBUNTU-CVE-2026-8700)
vulnerability in libcrypt-dsa-perl (UBUNTU-CVE-2026-8700). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:1876-1 Vulnerability in SUSE-SU-2026:1876-1 (SUSE-SU-2026:1876-1)
vulnerability in SUSE-SU-2026:1876-1 (SUSE-SU-2026:1876-1). Risk of unauthorized operations or information disclosure.
CVE-2026-8696 Use-After-Free in dos (CVE-2026-8696)
vulnerability in dos (CVE-2026-8696). Risk of unauthorized operations or information disclosure.
GHSA-cqrw-j4qc-7f9w Authorization Flaw in thorsten/phpmyfaq (GHSA-cqrw-j4qc-7f9w)
vulnerability in thorsten/phpmyfaq (GHSA-cqrw-j4qc-7f9w). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2` or later.
GHSA-478m-mrw4-qf2w Cross-Site Scripting (XSS) in thorsten/phpmyfaq (GHSA-478m-mrw4-qf2w)
cross-site scripting in thorsten/phpmyfaq (GHSA-478m-mrw4-qf2w). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2` or later.
GHSA-6626-79jh-5ccr Vulnerability in thorsten/phpmyfaq (GHSA-6626-79jh-5ccr)
vulnerability in thorsten/phpmyfaq (GHSA-6626-79jh-5ccr). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2` or later.
GHSA-p26v-fx3x-r2rp Vulnerability in thorsten/phpmyfaq (GHSA-p26v-fx3x-r2rp)
vulnerability in thorsten/phpmyfaq (GHSA-p26v-fx3x-r2rp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.2` or later.
GHSA-p9wc-4pjv-rg82 SQL Injection in thorsten/phpmyfaq (GHSA-p9wc-4pjv-rg82)
SQL injection in thorsten/phpmyfaq (GHSA-p9wc-4pjv-rg82). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.2` or later.
GHSA-w9mj-gfrm-hj5x Authorization Flaw in thorsten/phpmyfaq (GHSA-w9mj-gfrm-hj5x)
vulnerability in thorsten/phpmyfaq (GHSA-w9mj-gfrm-hj5x). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.2` or later.
GHSA-ch9q-c9mp-j5gq SQL Injection in thorsten/phpmyfaq (GHSA-ch9q-c9mp-j5gq)
SQL injection in thorsten/phpmyfaq (GHSA-ch9q-c9mp-j5gq). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/captcha`. Mitigation: upgrade to `4.1.2` or later.
UBUNTU-CVE-2026-8696 Vulnerability in radare2 (UBUNTU-CVE-2026-8696)
vulnerability in radare2 (UBUNTU-CVE-2026-8696). Risk of unauthorized operations or information disclosure.
MINI-x8mf-vv94-9wp6 MINI-x8mf-vv94-9wp6
CGA-w2fm-mfcc-5r46 CGA-w2fm-mfcc-5r46
CGA-w99c-3vgh-qrg5 CGA-w99c-3vgh-qrg5
CGA-q6rr-v9r6-c9xm CGA-q6rr-v9r6-c9xm
CGA-qr6c-w2fv-52jm CGA-qr6c-w2fv-52jm
CGA-v9pj-2c78-79r8 CGA-v9pj-2c78-79r8
CGA-mwq7-hh94-fjqp CGA-mwq7-hh94-fjqp
CGA-m8ww-4pg5-7jr3 CGA-m8ww-4pg5-7jr3
CGA-mc7p-cj26-v5p2 CGA-mc7p-cj26-v5p2
CGA-j59r-9gfm-mm3c CGA-j59r-9gfm-mm3c
CGA-grwh-gq6r-8w4c CGA-grwh-gq6r-8w4c
CGA-gx43-hg5j-6mw2 CGA-gx43-hg5j-6mw2
CGA-g745-8989-65mc CGA-g745-8989-65mc
CGA-f4rw-4pgf-xfrg CGA-f4rw-4pgf-xfrg
CGA-f8r5-9q74-2mw5 CGA-f8r5-9q74-2mw5
CGA-9xm3-x84m-gh3c CGA-9xm3-x84m-gh3c
CGA-9fp4-3r9w-7wgx CGA-9fp4-3r9w-7wgx
CGA-88cp-vrcc-j2x5 CGA-88cp-vrcc-j2x5
CGA-7mhh-g294-2422 CGA-7mhh-g294-2422
CGA-g2cc-p4h9-4m44 CGA-g2cc-p4h9-4m44
CGA-774j-r4wh-gwm2 CGA-774j-r4wh-gwm2
CGA-cq3m-32gg-3c26 CGA-cq3m-32gg-3c26
CGA-56jx-ghqp-6r7v CGA-56jx-ghqp-6r7v
CGA-4qr5-xjpg-v4jw CGA-4qr5-xjpg-v4jw
CGA-5hw3-vrqw-q7j4 CGA-5hw3-vrqw-q7j4
CGA-3ccp-gf5g-46gp CGA-3ccp-gf5g-46gp
CGA-89gg-3pm3-r673 CGA-89gg-3pm3-r673
CGA-3453-2rpm-pjgh CGA-3453-2rpm-pjgh
CGA-2x5h-rf7r-xxfx CGA-2x5h-rf7r-xxfx
CGA-47mf-3rqq-x4f3 CGA-47mf-3rqq-x4f3
CVE-2025-67031 Code Injection in CVE-2025-67031 (CVE-2025-67031)
code injection in CVE-2025-67031 (CVE-2025-67031). Risk of unauthorized operations or information disclosure.
CVE-2026-8686 Out-of-Bounds Read in Amazon aws (CVE-2026-8686)
vulnerability in Amazon aws (CVE-2026-8686). Risk of unauthorized operations or information disclosure.
CVE-2026-4054 Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4054)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4054). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.4.4` or later.
CVE-2026-4053 Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4053)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4053). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.0-20260414103857-b21ef302025e` or later.
CVE-2026-46408 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter t...
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter the payment flow without verifying cart ownership. A logged-in attacker can therefore reuse another u...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →