Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MINI-22w9-f6jr-qjx9 MINI-22w9-f6jr-qjx9
MINI-423p-w8wm-xrj2 MINI-423p-w8wm-xrj2
GHSA-qxvm-r42f-5p8j Vulnerability in WWBN/AVideo (GHSA-qxvm-r42f-5p8j)
vulnerability in WWBN/AVideo (GHSA-qxvm-r42f-5p8j). Successful exploitation can lead to full system takeover. Exploitable via ``name``.
GHSA-rc6v-5rmx-w5mv Vulnerability in github.com/arnika-project/arnika (GHSA-rc6v-5rmx-w5mv)
vulnerability in github.com/arnika-project/arnika (GHSA-rc6v-5rmx-w5mv). Risk of unauthorized operations or information disclosure. Exploitable via ``ackPkt.Timestamp``. Mitigation: upgrade to `1.0.1` or later.
GHSA-vfvv-c25p-m7mm Vulnerability in rkyv (GHSA-vfvv-c25p-m7mm)
vulnerability in rkyv (GHSA-vfvv-c25p-m7mm). Risk of unauthorized operations or information disclosure. Exploitable via ``rkyv``. Mitigation: upgrade to `0.8.16` or later.
CVE-2026-46491 Path Traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491)
path traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491). Data can be tampered with by attackers. Exploitable via ``ticket``. Mitigation: upgrade to `7.0.3` or later.
CVE-2026-44692 Vulnerability in code16/sharp (CVE-2026-44692)
vulnerability in code16/sharp (CVE-2026-44692). Confidential information can be exposed externally. Exploitable via `GET /sharp/{globalFilter}/download/{entityKey}/{instanceId`. Mitigation: upgrade to `9.22.0` or later.
RLSA-2026:17481 Vulnerability in rsync (RLSA-2026:17481)
vulnerability in rsync (RLSA-2026:17481). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:3.1.3-25.el8_10` or later.
CVE-2026-45717 Vulnerability in @budibase/server (CVE-2026-45717)
vulnerability in @budibase/server (CVE-2026-45717). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/datasources/`. Mitigation: upgrade to `3.38.1` or later.
CLSA-2026-1778867412 Vulnerability in bpftool (CLSA-2026-1778867412)
vulnerability in bpftool (CLSA-2026-1778867412). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.0-284.1101.el9_2.tuxcare.7.els34` or later.
CVE-2026-45715 SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-45715)
SSRF in @budibase/server (CVE-2026-45715). Confidential information can be exposed externally. Exploitable via `POST /api/queries/preview`. Mitigation: upgrade to `3.38.1` or later.
CVE-2026-45548 SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-45548)
SSRF in @budibase/server (CVE-2026-45548). Confidential information can be exposed externally. Exploitable via ``processUrlFile``. Mitigation: upgrade to `3.34.8` or later.
CVE-2026-45364 Vulnerability in better-auth (CVE-2026-45364)
vulnerability in better-auth (CVE-2026-45364). Risk of unauthorized operations or information disclosure. Exploitable via ``normalizeIP``. Mitigation: upgrade to `1.5.0-beta.9` or later.
GHSA-wxw3-q3m9-c3jr Authentication Bypass in better-auth (GHSA-wxw3-q3m9-c3jr)
authentication bypass in better-auth (GHSA-wxw3-q3m9-c3jr). Data can be tampered with by attackers. Exploitable via ``getToken``. Mitigation: upgrade to `1.6.2` or later.
GHSA-mxg3-432p-mr72 Vulnerability in goshs.de/goshs/v2 (GHSA-mxg3-432p-mr72)
vulnerability in goshs.de/goshs/v2 (GHSA-mxg3-432p-mr72). Confidential information can be exposed externally. Exploitable via ``localhost.run``. Mitigation: upgrade to `2.0.7` or later.
CVE-2026-45539 Information Disclosure in apm (CVE-2026-45539)
vulnerability in apm (CVE-2026-45539). Confidential information can be exposed externally. Exploitable via ``content_hash``. Mitigation: upgrade to `0.13.0` or later.
CVE-2026-45038 Vulnerability in tabby (CVE-2026-45038)
vulnerability in tabby (CVE-2026-45038). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.233` or later.
CVE-2026-45037 Vulnerability in tabby (CVE-2026-45037)
vulnerability in tabby (CVE-2026-45037). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.232` or later.
CVE-2026-45036 OS Command Injection in tabby (CVE-2026-45036)
OS command injection in tabby (CVE-2026-45036). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.233` or later.
CVE-2026-45035 OS Command Injection in tabby (CVE-2026-45035)
OS command injection in tabby (CVE-2026-45035). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.233` or later.
CVE-2026-44717 Code Injection in CVE-2026-44717 (CVE-2026-44717)
code injection in CVE-2026-44717 (CVE-2026-44717). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.1` or later.
DEBIAN-CVE-2026-44699 Vulnerability in libjwt3 (DEBIAN-CVE-2026-44699)
vulnerability in libjwt3 (DEBIAN-CVE-2026-44699). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.3` or later.
DEBIAN-CVE-2026-44310 Vulnerability in gitsign (DEBIAN-CVE-2026-44310)
vulnerability in gitsign (DEBIAN-CVE-2026-44310). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.15.0` or later.
DEBIAN-CVE-2026-44309 Vulnerability in gitsign (DEBIAN-CVE-2026-44309)
vulnerability in gitsign (DEBIAN-CVE-2026-44309). Data can be tampered with by attackers. Mitigation: upgrade to `0.16.0` or later.
CVE-2026-44699 Vulnerability in c (CVE-2026-44699)
vulnerability in c (CVE-2026-44699). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.3` or later.
CVE-2026-44641 Path Traversal in apm-cli (CVE-2026-44641)
path traversal in apm-cli (CVE-2026-44641). Confidential information can be exposed externally. Exploitable via ``agents``. Mitigation: upgrade to `0.8.12` or later.
CVE-2026-42458 Vulnerability in openmage/magento-lts (CVE-2026-42458)
vulnerability in openmage/magento-lts (CVE-2026-42458). Risk of unauthorized operations or information disclosure. Exploitable via ``Import``. Mitigation: upgrade to `20.18.0` or later.
CVE-2026-42207 Open Redirect in openmage/magento-lts (CVE-2026-42207)
vulnerability in openmage/magento-lts (CVE-2026-42207). Risk of unauthorized operations or information disclosure. Exploitable via `GET /productalert/add/stock/`. Mitigation: upgrade to `20.18.0` or later.
CVE-2026-42155 Vulnerability in openmage/magento-lts (CVE-2026-42155)
vulnerability in openmage/magento-lts (CVE-2026-42155). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/xmlrpc/`. Mitigation: upgrade to `20.18.0` or later.
CVE-2026-41258 Code Injection in org.openmrs.api:openmrs-api (CVE-2026-41258)
code injection in org.openmrs.api:openmrs-api (CVE-2026-41258). Successful exploitation can lead to full system takeover. Exploitable via ``VelocityEngine``. Mitigation: upgrade to `2.8.6` or later.
CVE-2026-41181 Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-41181)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-41181). Risk of unauthorized operations or information disclosure. Exploitable via ``errors``. Mitigation: upgrade to `2.11.44` or later.
UBUNTU-CVE-2026-8695 Vulnerability in radare2 (UBUNTU-CVE-2026-8695)
vulnerability in radare2 (UBUNTU-CVE-2026-8695). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-44699 Vulnerability in libjwt (UBUNTU-CVE-2026-44699)
vulnerability in libjwt (UBUNTU-CVE-2026-44699). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.3` or later.
UBUNTU-CVE-2026-44309 Vulnerability in gitsign (UBUNTU-CVE-2026-44309)
vulnerability in gitsign (UBUNTU-CVE-2026-44309). Data can be tampered with by attackers. Mitigation: upgrade to `0.16.0` or later.
UBUNTU-CVE-2026-44310 Vulnerability in gitsign (UBUNTU-CVE-2026-44310)
vulnerability in gitsign (UBUNTU-CVE-2026-44310). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.15.0` or later.
CVE-2026-45106 Cross-Site Scripting (XSS) in weblate (CVE-2026-45106)
cross-site scripting in weblate (CVE-2026-45106). Risk of unauthorized operations or information disclosure. Exploitable via ``source``. Mitigation: upgrade to `2026.5` or later.
CVE-2026-45062 Vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062)
vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062). Successful exploitation can lead to full system takeover. Exploitable via ``cgi.go``. Mitigation: upgrade to `1.12.3` or later.
CVE-2026-44716 Path Traversal in pipecat-ai (CVE-2026-44716)
path traversal in pipecat-ai (CVE-2026-44716). Confidential information can be exposed externally. Exploitable via `GET /files/{filename`. Mitigation: upgrade to `1.2.0` or later.
openSUSE-SU-2026:20758-1 Vulnerability in openSUSE-SU-2026:20758-1 (openSUSE-SU-2026:20758-1)
vulnerability in openSUSE-SU-2026:20758-1 (openSUSE-SU-2026:20758-1). Risk of unauthorized operations or information disclosure.
CVE-2026-41147 Cross-Site Scripting (XSS) in nukeviet/nukeviet (CVE-2026-41147)
cross-site scripting in nukeviet/nukeviet (CVE-2026-41147). Confidential information can be exposed externally. Exploitable via ``srcdoc``.
SUSE-SU-2026:21684-1 Vulnerability in SUSE-SU-2026:21684-1 (SUSE-SU-2026:21684-1)
vulnerability in SUSE-SU-2026:21684-1 (SUSE-SU-2026:21684-1). Risk of unauthorized operations or information disclosure.
CVE-2026-40092 Vulnerability in nimiq-keys (CVE-2026-40092)
vulnerability in nimiq-keys (CVE-2026-40092). Risk of unauthorized operations or information disclosure. Exploitable via ``TaggedPublicKey``.
CVE-2026-22810 Vulnerability in @joplin/onenote-converter (CVE-2026-22810)
vulnerability in @joplin/onenote-converter (CVE-2026-22810). Successful exploitation can lead to full system takeover. Exploitable via ``embedded_file.rs``. Mitigation: upgrade to `3.5.7` or later.
CLSA-2026-1778856286 Vulnerability in vim-X11 (CLSA-2026-1778856286)
vulnerability in vim-X11 (CLSA-2026-1778856286). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:8.2.2637-22.el9_6.1.tuxcare.els27` or later.
CVE-2025-65954 Open Redirect in simplesamlphp/simplesamlphp-module-casserver (CVE-2025-65954)
vulnerability in simplesamlphp/simplesamlphp-module-casserver (CVE-2025-65954). Risk of unauthorized operations or information disclosure. Exploitable via ``url``. Mitigation: upgrade to `6.3.1` or later.
CLSA-2026-1778847162 Vulnerability in httpd (CLSA-2026-1778847162)
vulnerability in httpd (CLSA-2026-1778847162). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.53-11.el9_2.5.tuxcare.els13` or later.
DEBIAN-CVE-2026-45803 Vulnerability in gh (DEBIAN-CVE-2026-45803)
vulnerability in gh (DEBIAN-CVE-2026-45803). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.92.0` or later.
CVE-2026-46508 Command Injection in vercel (CVE-2026-46508)
command injection in vercel (CVE-2026-46508). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.9.14000` or later.
CVE-2026-45803 Vulnerability in github.com/cli/cli/v2 (CVE-2026-45803)
vulnerability in github.com/cli/cli/v2 (CVE-2026-45803). Risk of unauthorized operations or information disclosure. Exploitable via ``screen``. Mitigation: upgrade to `2.92.0` or later.
CVE-2026-45773 Cross-Site Request Forgery (CSRF) in turbo (CVE-2026-45773)
vulnerability in turbo (CVE-2026-45773). Data can be tampered with by attackers. Exploitable via ``turbo``. Mitigation: upgrade to `2.9.14` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →