Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-22w9-f6jr-qjx9 |
|
MINI-22w9-f6jr-qjx9 |
| MINI-423p-w8wm-xrj2 |
|
MINI-423p-w8wm-xrj2 |
| GHSA-qxvm-r42f-5p8j |
|
Vulnerability in WWBN/AVideo (GHSA-qxvm-r42f-5p8j)
vulnerability in WWBN/AVideo (GHSA-qxvm-r42f-5p8j). Successful exploitation can lead to full system takeover. Exploitable via ``name``.
|
| GHSA-rc6v-5rmx-w5mv |
|
Vulnerability in github.com/arnika-project/arnika (GHSA-rc6v-5rmx-w5mv)
vulnerability in github.com/arnika-project/arnika (GHSA-rc6v-5rmx-w5mv). Risk of unauthorized operations or information disclosure. Exploitable via ``ackPkt.Timestamp``. Mitigation: upgrade to `1.0.1` or later.
|
| GHSA-vfvv-c25p-m7mm |
|
Vulnerability in rkyv (GHSA-vfvv-c25p-m7mm)
vulnerability in rkyv (GHSA-vfvv-c25p-m7mm). Risk of unauthorized operations or information disclosure. Exploitable via ``rkyv``. Mitigation: upgrade to `0.8.16` or later.
|
| CVE-2026-46491 |
|
Path Traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491)
path traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491). Data can be tampered with by attackers. Exploitable via ``ticket``. Mitigation: upgrade to `7.0.3` or later.
|
| CVE-2026-44692 |
|
Vulnerability in code16/sharp (CVE-2026-44692)
vulnerability in code16/sharp (CVE-2026-44692). Confidential information can be exposed externally. Exploitable via `GET /sharp/{globalFilter}/download/{entityKey}/{instanceId`. Mitigation: upgrade to `9.22.0` or later.
|
| RLSA-2026:17481 |
|
Vulnerability in rsync (RLSA-2026:17481)
vulnerability in rsync (RLSA-2026:17481). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:3.1.3-25.el8_10` or later.
|
| CVE-2026-45717 |
|
Vulnerability in @budibase/server (CVE-2026-45717)
vulnerability in @budibase/server (CVE-2026-45717). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/datasources/`. Mitigation: upgrade to `3.38.1` or later.
|
| CLSA-2026-1778867412 |
|
Vulnerability in bpftool (CLSA-2026-1778867412)
vulnerability in bpftool (CLSA-2026-1778867412). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.0-284.1101.el9_2.tuxcare.7.els34` or later.
|
| CVE-2026-45715 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-45715)
SSRF in @budibase/server (CVE-2026-45715). Confidential information can be exposed externally. Exploitable via `POST /api/queries/preview`. Mitigation: upgrade to `3.38.1` or later.
|
| CVE-2026-45548 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-45548)
SSRF in @budibase/server (CVE-2026-45548). Confidential information can be exposed externally. Exploitable via ``processUrlFile``. Mitigation: upgrade to `3.34.8` or later.
|
| CVE-2026-45364 |
|
Vulnerability in better-auth (CVE-2026-45364)
vulnerability in better-auth (CVE-2026-45364). Risk of unauthorized operations or information disclosure. Exploitable via ``normalizeIP``. Mitigation: upgrade to `1.5.0-beta.9` or later.
|
| GHSA-wxw3-q3m9-c3jr |
|
Authentication Bypass in better-auth (GHSA-wxw3-q3m9-c3jr)
authentication bypass in better-auth (GHSA-wxw3-q3m9-c3jr). Data can be tampered with by attackers. Exploitable via ``getToken``. Mitigation: upgrade to `1.6.2` or later.
|
| GHSA-mxg3-432p-mr72 |
|
Vulnerability in goshs.de/goshs/v2 (GHSA-mxg3-432p-mr72)
vulnerability in goshs.de/goshs/v2 (GHSA-mxg3-432p-mr72). Confidential information can be exposed externally. Exploitable via ``localhost.run``. Mitigation: upgrade to `2.0.7` or later.
|
| CVE-2026-45539 |
|
Information Disclosure in apm (CVE-2026-45539)
vulnerability in apm (CVE-2026-45539). Confidential information can be exposed externally. Exploitable via ``content_hash``. Mitigation: upgrade to `0.13.0` or later.
|
| CVE-2026-45038 |
|
Vulnerability in tabby (CVE-2026-45038)
vulnerability in tabby (CVE-2026-45038). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.233` or later.
|
| CVE-2026-45037 |
|
Vulnerability in tabby (CVE-2026-45037)
vulnerability in tabby (CVE-2026-45037). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.232` or later.
|
| CVE-2026-45036 |
|
OS Command Injection in tabby (CVE-2026-45036)
OS command injection in tabby (CVE-2026-45036). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.233` or later.
|
| CVE-2026-45035 |
|
OS Command Injection in tabby (CVE-2026-45035)
OS command injection in tabby (CVE-2026-45035). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.233` or later.
|
| CVE-2026-44717 |
|
Code Injection in CVE-2026-44717 (CVE-2026-44717)
code injection in CVE-2026-44717 (CVE-2026-44717). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.1` or later.
|
| DEBIAN-CVE-2026-44699 |
|
Vulnerability in libjwt3 (DEBIAN-CVE-2026-44699)
vulnerability in libjwt3 (DEBIAN-CVE-2026-44699). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.3` or later.
|
| DEBIAN-CVE-2026-44310 |
|
Vulnerability in gitsign (DEBIAN-CVE-2026-44310)
vulnerability in gitsign (DEBIAN-CVE-2026-44310). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.15.0` or later.
|
| DEBIAN-CVE-2026-44309 |
|
Vulnerability in gitsign (DEBIAN-CVE-2026-44309)
vulnerability in gitsign (DEBIAN-CVE-2026-44309). Data can be tampered with by attackers. Mitigation: upgrade to `0.16.0` or later.
|
| CVE-2026-44699 |
|
Vulnerability in c (CVE-2026-44699)
vulnerability in c (CVE-2026-44699). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.3` or later.
|
| CVE-2026-44641 |
|
Path Traversal in apm-cli (CVE-2026-44641)
path traversal in apm-cli (CVE-2026-44641). Confidential information can be exposed externally. Exploitable via ``agents``. Mitigation: upgrade to `0.8.12` or later.
|
| CVE-2026-42458 |
|
Vulnerability in openmage/magento-lts (CVE-2026-42458)
vulnerability in openmage/magento-lts (CVE-2026-42458). Risk of unauthorized operations or information disclosure. Exploitable via ``Import``. Mitigation: upgrade to `20.18.0` or later.
|
| CVE-2026-42207 |
|
Open Redirect in openmage/magento-lts (CVE-2026-42207)
vulnerability in openmage/magento-lts (CVE-2026-42207). Risk of unauthorized operations or information disclosure. Exploitable via `GET /productalert/add/stock/`. Mitigation: upgrade to `20.18.0` or later.
|
| CVE-2026-42155 |
|
Vulnerability in openmage/magento-lts (CVE-2026-42155)
vulnerability in openmage/magento-lts (CVE-2026-42155). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/xmlrpc/`. Mitigation: upgrade to `20.18.0` or later.
|
| CVE-2026-41258 |
|
Code Injection in org.openmrs.api:openmrs-api (CVE-2026-41258)
code injection in org.openmrs.api:openmrs-api (CVE-2026-41258). Successful exploitation can lead to full system takeover. Exploitable via ``VelocityEngine``. Mitigation: upgrade to `2.8.6` or later.
|
| CVE-2026-41181 |
|
Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-41181)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-41181). Risk of unauthorized operations or information disclosure. Exploitable via ``errors``. Mitigation: upgrade to `2.11.44` or later.
|
| UBUNTU-CVE-2026-8695 |
|
Vulnerability in radare2 (UBUNTU-CVE-2026-8695)
vulnerability in radare2 (UBUNTU-CVE-2026-8695). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-44699 |
|
Vulnerability in libjwt (UBUNTU-CVE-2026-44699)
vulnerability in libjwt (UBUNTU-CVE-2026-44699). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.3` or later.
|
| UBUNTU-CVE-2026-44309 |
|
Vulnerability in gitsign (UBUNTU-CVE-2026-44309)
vulnerability in gitsign (UBUNTU-CVE-2026-44309). Data can be tampered with by attackers. Mitigation: upgrade to `0.16.0` or later.
|
| UBUNTU-CVE-2026-44310 |
|
Vulnerability in gitsign (UBUNTU-CVE-2026-44310)
vulnerability in gitsign (UBUNTU-CVE-2026-44310). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.15.0` or later.
|
| CVE-2026-45106 |
|
Cross-Site Scripting (XSS) in weblate (CVE-2026-45106)
cross-site scripting in weblate (CVE-2026-45106). Risk of unauthorized operations or information disclosure. Exploitable via ``source``. Mitigation: upgrade to `2026.5` or later.
|
| CVE-2026-45062 |
|
Vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062)
vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062). Successful exploitation can lead to full system takeover. Exploitable via ``cgi.go``. Mitigation: upgrade to `1.12.3` or later.
|
| CVE-2026-44716 |
|
Path Traversal in pipecat-ai (CVE-2026-44716)
path traversal in pipecat-ai (CVE-2026-44716). Confidential information can be exposed externally. Exploitable via `GET /files/{filename`. Mitigation: upgrade to `1.2.0` or later.
|
| openSUSE-SU-2026:20758-1 |
|
Vulnerability in openSUSE-SU-2026:20758-1 (openSUSE-SU-2026:20758-1)
vulnerability in openSUSE-SU-2026:20758-1 (openSUSE-SU-2026:20758-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41147 |
|
Cross-Site Scripting (XSS) in nukeviet/nukeviet (CVE-2026-41147)
cross-site scripting in nukeviet/nukeviet (CVE-2026-41147). Confidential information can be exposed externally. Exploitable via ``srcdoc``.
|
| SUSE-SU-2026:21684-1 |
|
Vulnerability in SUSE-SU-2026:21684-1 (SUSE-SU-2026:21684-1)
vulnerability in SUSE-SU-2026:21684-1 (SUSE-SU-2026:21684-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40092 |
|
Vulnerability in nimiq-keys (CVE-2026-40092)
vulnerability in nimiq-keys (CVE-2026-40092). Risk of unauthorized operations or information disclosure. Exploitable via ``TaggedPublicKey``.
|
| CVE-2026-22810 |
|
Vulnerability in @joplin/onenote-converter (CVE-2026-22810)
vulnerability in @joplin/onenote-converter (CVE-2026-22810). Successful exploitation can lead to full system takeover. Exploitable via ``embedded_file.rs``. Mitigation: upgrade to `3.5.7` or later.
|
| CLSA-2026-1778856286 |
|
Vulnerability in vim-X11 (CLSA-2026-1778856286)
vulnerability in vim-X11 (CLSA-2026-1778856286). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:8.2.2637-22.el9_6.1.tuxcare.els27` or later.
|
| CVE-2025-65954 |
|
Open Redirect in simplesamlphp/simplesamlphp-module-casserver (CVE-2025-65954)
vulnerability in simplesamlphp/simplesamlphp-module-casserver (CVE-2025-65954). Risk of unauthorized operations or information disclosure. Exploitable via ``url``. Mitigation: upgrade to `6.3.1` or later.
|
| CLSA-2026-1778847162 |
|
Vulnerability in httpd (CLSA-2026-1778847162)
vulnerability in httpd (CLSA-2026-1778847162). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.53-11.el9_2.5.tuxcare.els13` or later.
|
| DEBIAN-CVE-2026-45803 |
|
Vulnerability in gh (DEBIAN-CVE-2026-45803)
vulnerability in gh (DEBIAN-CVE-2026-45803). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.92.0` or later.
|
| CVE-2026-46508 |
|
Command Injection in vercel (CVE-2026-46508)
command injection in vercel (CVE-2026-46508). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.9.14000` or later.
|
| CVE-2026-45803 |
|
Vulnerability in github.com/cli/cli/v2 (CVE-2026-45803)
vulnerability in github.com/cli/cli/v2 (CVE-2026-45803). Risk of unauthorized operations or information disclosure. Exploitable via ``screen``. Mitigation: upgrade to `2.92.0` or later.
|
| CVE-2026-45773 |
|
Cross-Site Request Forgery (CSRF) in turbo (CVE-2026-45773)
vulnerability in turbo (CVE-2026-45773). Data can be tampered with by attackers. Exploitable via ``turbo``. Mitigation: upgrade to `2.9.14` or later.
|