Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-8654 OS Command Injection in CVE-2026-8654 (CVE-2026-8654)
OS command injection in CVE-2026-8654 (CVE-2026-8654). Risk of unauthorized operations or information disclosure.
CVE-2026-6646 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6646)
cross-site scripting in wordpress (CVE-2026-6646). Risk of unauthorized operations or information disclosure.
CVE-2026-4094 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
CVE-2026-41702 VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
ROOT-APP-MAVEN-CVE-2025-48924 Vulnerability in io.root.org.apache.commons:commons-lang3 (ROOT-APP-MAVEN-CVE-2025-48924)
vulnerability in io.root.org.apache.commons:commons-lang3 (ROOT-APP-MAVEN-CVE-2025-48924). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.12.0-root.io.1, 3.9-root.io.1, 3.12.0-root.io.2, 3.9-root.io.2, 3.9-root.io.3, 3.12.0-root.io.3` or later.
CVE-2026-0481 Vulnerability in CVE-2026-0481 (CVE-2026-0481)
vulnerability in CVE-2026-0481 (CVE-2026-0481). Risk of unauthorized operations or information disclosure.
CVE-2026-28761 Cross-Site Request Forgery (CSRF) in CVE-2026-28761 (CVE-2026-28761)
vulnerability in CVE-2026-28761 (CVE-2026-28761). Confidential information can be exposed externally.
CVE-2024-21950 Out-of-Bounds Read in CVE-2024-21950 (CVE-2024-21950)
vulnerability in CVE-2024-21950 (CVE-2024-21950). Risk of unauthorized operations or information disclosure.
CVE-2026-43490 Out-of-Bounds Write in linux (CVE-2026-43490)
out-of-bounds write in linux (CVE-2026-43490). Successful exploitation can lead to full system takeover.
CVE-2024-36323 Vulnerability in CVE-2024-36323 (CVE-2024-36323)
vulnerability in CVE-2024-36323 (CVE-2024-36323). Risk of unauthorized operations or information disclosure.
CVE-2026-24662 Cross-Site Scripting (XSS) in jvn (CVE-2026-24662)
cross-site scripting in jvn (CVE-2026-24662). Risk of unauthorized operations or information disclosure.
CVE-2025-52532 Vulnerability in CVE-2025-52532 (CVE-2025-52532)
vulnerability in CVE-2025-52532 (CVE-2025-52532). Risk of unauthorized operations or information disclosure.
CVE-2024-36334 Vulnerability in CVE-2024-36334 (CVE-2024-36334)
vulnerability in CVE-2024-36334 (CVE-2024-36334). Risk of unauthorized operations or information disclosure.
CVE-2025-54518 Vulnerability in privilege-escalation (CVE-2025-54518)
vulnerability in privilege-escalation (CVE-2025-54518). Successful exploitation can lead to full system takeover.
CVE-2024-36333 Vulnerability in privilege-escalation (CVE-2024-36333)
vulnerability in privilege-escalation (CVE-2024-36333). Successful exploitation can lead to full system takeover.
MGASA-2026-0140 Vulnerability in perl-HTTP-Tiny (MGASA-2026-0140)
vulnerability in perl-HTTP-Tiny (MGASA-2026-0140). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.82.0-1.2.mga9` or later.
MGASA-2026-0141 Updated libreoffice packages fix security vulnerability
Updated libreoffice packages fix security vulnerability
MGASA-2026-0138 Updated awstats packages fix security vulnerability
Updated awstats packages fix security vulnerability
MGASA-2026-0139 Vulnerability in tomcat (MGASA-2026-0139)
vulnerability in tomcat (MGASA-2026-0139). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.118-1.mga9` or later.
DEBIAN-CVE-2026-43490 Vulnerability in linux (DEBIAN-CVE-2026-43490)
vulnerability in linux (DEBIAN-CVE-2026-43490). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.88-1` or later.
UBUNTU-CVE-2026-43490 Vulnerability in linux-hwe-edge (UBUNTU-CVE-2026-43490)
vulnerability in linux-hwe-edge (UBUNTU-CVE-2026-43490). Successful exploitation can lead to full system takeover.
ECHO-1e9d-9cbe-8622 ECHO-1e9d-9cbe-8622
ROOT-APP-MAVEN-CVE-2023-6378 Vulnerability in io.root.ch.qos.logback:logback-classic (ROOT-APP-MAVEN-CVE-2023-6378)
vulnerability in io.root.ch.qos.logback:logback-classic (ROOT-APP-MAVEN-CVE-2023-6378). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.11-root.io.1, 1.4.11-root.io.2, 1.1.3-root.io.1, 1.4.11-root.io.4, 1.4.11-root.io.5, 1.1.3-root.io.2` or later.
ROOT-APP-MAVEN-CVE-2017-5929 Vulnerability in io.root.ch.qos.logback:logback-classic (ROOT-APP-MAVEN-CVE-2017-5929)
vulnerability in io.root.ch.qos.logback:logback-classic (ROOT-APP-MAVEN-CVE-2017-5929). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.3-root.io.1, 1.1.3-root.io.2, 1.1.3-root.io.3, 1.0.12-root.io.1` or later.
BELL-CVE-2026-43895 BELL-CVE-2026-43895
BELL-CVE-2026-41256 BELL-CVE-2026-41256
BELL-CVE-2026-42945 BELL-CVE-2026-42945
ROOT-APP-MAVEN-CVE-2026-34359 Vulnerability in io.root.ca.uhn.hapi.fhir:org.hl7.fhir.utilities (ROOT-APP-MAVEN-CVE-2026-34359)
vulnerability in io.root.ca.uhn.hapi.fhir:org.hl7.fhir.utilities (ROOT-APP-MAVEN-CVE-2026-34359). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.9.0-root.io.3, 6.9.0-root.io.4, 6.7.9-root.io.1, 6.7.9-root.io.2, 6.7.9-root.io.4, 6.9.0-root.io.5, 6.9.0-root.io.6, 6.7.9-root.io.5, 6.9.0-root.io.7` or later.
ROOT-APP-MAVEN-CVE-2026-34361 Vulnerability in io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation (ROOT-APP-MAVEN-CVE-2026-34361)
vulnerability in io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation (ROOT-APP-MAVEN-CVE-2026-34361). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.9.0-root.io.3, 6.9.0-root.io.4, 6.7.9-root.io.1, 6.7.9-root.io.2, 6.7.9-root.io.4, 6.9.0-root.io.5, 6.9.0-root.io.6, 6.7.9-root.io.5, 6.9.0-root.io.7` or later.
ALPINE-CVE-2025-54518 Vulnerability in xen (ALPINE-CVE-2025-54518)
vulnerability in xen (ALPINE-CVE-2025-54518). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.18.5-r8` or later.
ROOT-APP-NPM-CVE-2026-44990 Vulnerability in @rootio/sanitize-html (ROOT-APP-NPM-CVE-2026-44990)
vulnerability in @rootio/sanitize-html (ROOT-APP-NPM-CVE-2026-44990). Confidential information can be exposed externally. Mitigation: upgrade to `2.17.2-root.io.1, 2.12.1-root.io.1, 2.12.1-root.io.2, 2.17.2-root.io.2` or later.
ROOT-OS-DEBIAN-13-CVE-2026-46300 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-46300)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-46300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
ROOT-OS-DEBIAN-12-CVE-2026-46300 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-12-CVE-2026-46300)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-12-CVE-2026-46300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.174-1.root.io.138, 6.1.174-1.root.io.139, 6.1.174-1.root.io.140, 6.1.174-1.root.io.141, 6.1.174-1.root.io.142, 6.1.174-1.root.io.143, 6.1.174-1.root.io.145, 6.1.174-1.root.io.144` or later.
ROOT-OS-DEBIAN-11-CVE-2026-46300 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2026-46300)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2026-46300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.10.257-1.root.io.92, 5.10.257-1.root.io.93, 5.10.257-1.root.io.94, 5.10.257-1.root.io.95, 5.10.257-1.root.io.96, 5.10.257-1.root.io.97, 5.10.257-1.root.io.98, 5.10.257-1.root.io.99` or later.
MINI-8wr2-q2hh-5gr8 MINI-8wr2-q2hh-5gr8
MINI-rmpr-92wq-x9pp MINI-rmpr-92wq-x9pp
MINI-4x6j-9r77-w862 MINI-4x6j-9r77-w862
MINI-xq5g-hc7g-x6rh MINI-xq5g-hc7g-x6rh
MINI-hm7c-h3r6-893v MINI-hm7c-h3r6-893v
MINI-qwcg-7g94-jrv9 MINI-qwcg-7g94-jrv9
MINI-7pfw-97v3-2372 MINI-7pfw-97v3-2372
MINI-7jvq-vcpq-xrwr MINI-7jvq-vcpq-xrwr
CVE-2025-29944 Vulnerability in dos (CVE-2025-29944)
vulnerability in dos (CVE-2025-29944). Risk of unauthorized operations or information disclosure.
CVE-2025-54517 Out-of-Bounds Write in CVE-2025-54517 (CVE-2025-54517)
out-of-bounds write in CVE-2025-54517 (CVE-2025-54517). Risk of unauthorized operations or information disclosure.
CVE-2025-54511 Vulnerability in CVE-2025-54511 (CVE-2025-54511)
vulnerability in CVE-2025-54511 (CVE-2025-54511). Risk of unauthorized operations or information disclosure.
CVE-2025-66660 Vulnerability in CVE-2025-66660 (CVE-2025-66660)
vulnerability in CVE-2025-66660 (CVE-2025-66660). Risk of unauthorized operations or information disclosure.
CVE-2025-48513 Vulnerability in CVE-2025-48513 (CVE-2025-48513)
vulnerability in CVE-2025-48513 (CVE-2025-48513). Risk of unauthorized operations or information disclosure.
CVE-2026-7373 Vulnerability in privilege-escalation (CVE-2026-7373)
vulnerability in privilege-escalation (CVE-2026-7373). Risk of unauthorized operations or information disclosure.
CVE-2025-0040 Vulnerability in CVE-2025-0040 (CVE-2025-0040)
vulnerability in CVE-2025-0040 (CVE-2025-0040). Risk of unauthorized operations or information disclosure.
CVE-2025-66664 Out-of-Bounds Read in CVE-2025-66664 (CVE-2025-66664)
vulnerability in CVE-2025-66664 (CVE-2025-66664). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →