Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-8654 |
|
OS Command Injection in CVE-2026-8654 (CVE-2026-8654)
OS command injection in CVE-2026-8654 (CVE-2026-8654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6646 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6646)
cross-site scripting in wordpress (CVE-2026-6646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4094 |
|
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
|
| CVE-2026-41702 |
|
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
|
| ROOT-APP-MAVEN-CVE-2025-48924 |
|
Vulnerability in io.root.org.apache.commons:commons-lang3 (ROOT-APP-MAVEN-CVE-2025-48924)
vulnerability in io.root.org.apache.commons:commons-lang3 (ROOT-APP-MAVEN-CVE-2025-48924). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.12.0-root.io.1, 3.9-root.io.1, 3.12.0-root.io.2, 3.9-root.io.2, 3.9-root.io.3, 3.12.0-root.io.3` or later.
|
| CVE-2026-0481 |
|
Vulnerability in CVE-2026-0481 (CVE-2026-0481)
vulnerability in CVE-2026-0481 (CVE-2026-0481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28761 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-28761 (CVE-2026-28761)
vulnerability in CVE-2026-28761 (CVE-2026-28761). Confidential information can be exposed externally.
|
| CVE-2024-21950 |
|
Out-of-Bounds Read in CVE-2024-21950 (CVE-2024-21950)
vulnerability in CVE-2024-21950 (CVE-2024-21950). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43490 |
|
Out-of-Bounds Write in linux (CVE-2026-43490)
out-of-bounds write in linux (CVE-2026-43490). Successful exploitation can lead to full system takeover.
|
| CVE-2024-36323 |
|
Vulnerability in CVE-2024-36323 (CVE-2024-36323)
vulnerability in CVE-2024-36323 (CVE-2024-36323). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24662 |
|
Cross-Site Scripting (XSS) in jvn (CVE-2026-24662)
cross-site scripting in jvn (CVE-2026-24662). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-52532 |
|
Vulnerability in CVE-2025-52532 (CVE-2025-52532)
vulnerability in CVE-2025-52532 (CVE-2025-52532). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-36334 |
|
Vulnerability in CVE-2024-36334 (CVE-2024-36334)
vulnerability in CVE-2024-36334 (CVE-2024-36334). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54518 |
|
Vulnerability in privilege-escalation (CVE-2025-54518)
vulnerability in privilege-escalation (CVE-2025-54518). Successful exploitation can lead to full system takeover.
|
| CVE-2024-36333 |
|
Vulnerability in privilege-escalation (CVE-2024-36333)
vulnerability in privilege-escalation (CVE-2024-36333). Successful exploitation can lead to full system takeover.
|
| MGASA-2026-0140 |
|
Vulnerability in perl-HTTP-Tiny (MGASA-2026-0140)
vulnerability in perl-HTTP-Tiny (MGASA-2026-0140). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.82.0-1.2.mga9` or later.
|
| MGASA-2026-0141 |
|
Updated libreoffice packages fix security vulnerability
Updated libreoffice packages fix security vulnerability
|
| MGASA-2026-0138 |
|
Updated awstats packages fix security vulnerability
Updated awstats packages fix security vulnerability
|
| MGASA-2026-0139 |
|
Vulnerability in tomcat (MGASA-2026-0139)
vulnerability in tomcat (MGASA-2026-0139). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.118-1.mga9` or later.
|
| DEBIAN-CVE-2026-43490 |
|
Vulnerability in linux (DEBIAN-CVE-2026-43490)
vulnerability in linux (DEBIAN-CVE-2026-43490). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.88-1` or later.
|
| UBUNTU-CVE-2026-43490 |
|
Vulnerability in linux-hwe-edge (UBUNTU-CVE-2026-43490)
vulnerability in linux-hwe-edge (UBUNTU-CVE-2026-43490). Successful exploitation can lead to full system takeover.
|
| ECHO-1e9d-9cbe-8622 |
|
ECHO-1e9d-9cbe-8622 |
| ROOT-APP-MAVEN-CVE-2023-6378 |
|
Vulnerability in io.root.ch.qos.logback:logback-classic (ROOT-APP-MAVEN-CVE-2023-6378)
vulnerability in io.root.ch.qos.logback:logback-classic (ROOT-APP-MAVEN-CVE-2023-6378). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.11-root.io.1, 1.4.11-root.io.2, 1.1.3-root.io.1, 1.4.11-root.io.4, 1.4.11-root.io.5, 1.1.3-root.io.2` or later.
|
| ROOT-APP-MAVEN-CVE-2017-5929 |
|
Vulnerability in io.root.ch.qos.logback:logback-classic (ROOT-APP-MAVEN-CVE-2017-5929)
vulnerability in io.root.ch.qos.logback:logback-classic (ROOT-APP-MAVEN-CVE-2017-5929). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.3-root.io.1, 1.1.3-root.io.2, 1.1.3-root.io.3, 1.0.12-root.io.1` or later.
|
| BELL-CVE-2026-43895 |
|
BELL-CVE-2026-43895 |
| BELL-CVE-2026-41256 |
|
BELL-CVE-2026-41256 |
| BELL-CVE-2026-42945 |
|
BELL-CVE-2026-42945 |
| ROOT-APP-MAVEN-CVE-2026-34359 |
|
Vulnerability in io.root.ca.uhn.hapi.fhir:org.hl7.fhir.utilities (ROOT-APP-MAVEN-CVE-2026-34359)
vulnerability in io.root.ca.uhn.hapi.fhir:org.hl7.fhir.utilities (ROOT-APP-MAVEN-CVE-2026-34359). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.9.0-root.io.3, 6.9.0-root.io.4, 6.7.9-root.io.1, 6.7.9-root.io.2, 6.7.9-root.io.4, 6.9.0-root.io.5, 6.9.0-root.io.6, 6.7.9-root.io.5, 6.9.0-root.io.7` or later.
|
| ROOT-APP-MAVEN-CVE-2026-34361 |
|
Vulnerability in io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation (ROOT-APP-MAVEN-CVE-2026-34361)
vulnerability in io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation (ROOT-APP-MAVEN-CVE-2026-34361). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.9.0-root.io.3, 6.9.0-root.io.4, 6.7.9-root.io.1, 6.7.9-root.io.2, 6.7.9-root.io.4, 6.9.0-root.io.5, 6.9.0-root.io.6, 6.7.9-root.io.5, 6.9.0-root.io.7` or later.
|
| ALPINE-CVE-2025-54518 |
|
Vulnerability in xen (ALPINE-CVE-2025-54518)
vulnerability in xen (ALPINE-CVE-2025-54518). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.18.5-r8` or later.
|
| ROOT-APP-NPM-CVE-2026-44990 |
|
Vulnerability in @rootio/sanitize-html (ROOT-APP-NPM-CVE-2026-44990)
vulnerability in @rootio/sanitize-html (ROOT-APP-NPM-CVE-2026-44990). Confidential information can be exposed externally. Mitigation: upgrade to `2.17.2-root.io.1, 2.12.1-root.io.1, 2.12.1-root.io.2, 2.17.2-root.io.2` or later.
|
| ROOT-OS-DEBIAN-13-CVE-2026-46300 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-46300)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2026-46300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.90-2.root.io.130, 6.12.90-2.root.io.131, 6.12.90-2.root.io.132, 6.12.90-2.root.io.133, 6.12.90-2.root.io.134, 6.12.90-2.root.io.135, 6.12.90-2.root.io.136, 6.12.90-2.root.io.137, 6.12.90-2.root.io.138` or later.
|
| ROOT-OS-DEBIAN-12-CVE-2026-46300 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-12-CVE-2026-46300)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-12-CVE-2026-46300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.174-1.root.io.138, 6.1.174-1.root.io.139, 6.1.174-1.root.io.140, 6.1.174-1.root.io.141, 6.1.174-1.root.io.142, 6.1.174-1.root.io.143, 6.1.174-1.root.io.145, 6.1.174-1.root.io.144` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2026-46300 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2026-46300)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2026-46300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.10.257-1.root.io.92, 5.10.257-1.root.io.93, 5.10.257-1.root.io.94, 5.10.257-1.root.io.95, 5.10.257-1.root.io.96, 5.10.257-1.root.io.97, 5.10.257-1.root.io.98, 5.10.257-1.root.io.99` or later.
|
| MINI-8wr2-q2hh-5gr8 |
|
MINI-8wr2-q2hh-5gr8 |
| MINI-rmpr-92wq-x9pp |
|
MINI-rmpr-92wq-x9pp |
| MINI-4x6j-9r77-w862 |
|
MINI-4x6j-9r77-w862 |
| MINI-xq5g-hc7g-x6rh |
|
MINI-xq5g-hc7g-x6rh |
| MINI-hm7c-h3r6-893v |
|
MINI-hm7c-h3r6-893v |
| MINI-qwcg-7g94-jrv9 |
|
MINI-qwcg-7g94-jrv9 |
| MINI-7pfw-97v3-2372 |
|
MINI-7pfw-97v3-2372 |
| MINI-7jvq-vcpq-xrwr |
|
MINI-7jvq-vcpq-xrwr |
| CVE-2025-29944 |
|
Vulnerability in dos (CVE-2025-29944)
vulnerability in dos (CVE-2025-29944). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54517 |
|
Out-of-Bounds Write in CVE-2025-54517 (CVE-2025-54517)
out-of-bounds write in CVE-2025-54517 (CVE-2025-54517). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-54511 |
|
Vulnerability in CVE-2025-54511 (CVE-2025-54511)
vulnerability in CVE-2025-54511 (CVE-2025-54511). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-66660 |
|
Vulnerability in CVE-2025-66660 (CVE-2025-66660)
vulnerability in CVE-2025-66660 (CVE-2025-66660). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-48513 |
|
Vulnerability in CVE-2025-48513 (CVE-2025-48513)
vulnerability in CVE-2025-48513 (CVE-2025-48513). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7373 |
|
Vulnerability in privilege-escalation (CVE-2026-7373)
vulnerability in privilege-escalation (CVE-2026-7373). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-0040 |
|
Vulnerability in CVE-2025-0040 (CVE-2025-0040)
vulnerability in CVE-2025-0040 (CVE-2025-0040). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-66664 |
|
Out-of-Bounds Read in CVE-2025-66664 (CVE-2025-66664)
vulnerability in CVE-2025-66664 (CVE-2025-66664). Risk of unauthorized operations or information disclosure.
|