Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-8515 |
|
Use-After-Free in google (CVE-2026-8515)
vulnerability in google (CVE-2026-8515). Successful exploitation can lead to full system takeover.
|
| MINI-29wq-fgj2-h8jx |
|
MINI-29wq-fgj2-h8jx |
| MINI-3xvq-c82h-xw78 |
|
MINI-3xvq-c82h-xw78 |
| CVE-2026-8509 |
|
Vulnerability in Google chrome (CVE-2026-8509)
vulnerability in Google chrome (CVE-2026-8509). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45781 |
|
Vulnerability in github.com/modelcontextprotocol/registry (CVE-2026-45781)
vulnerability in github.com/modelcontextprotocol/registry (CVE-2026-45781). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.9` or later.
|
| DEBIAN-CVE-2026-44673 |
|
Vulnerability in libyang (DEBIAN-CVE-2026-44673)
vulnerability in libyang (DEBIAN-CVE-2026-44673). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-44662 |
|
Vulnerability in rust-openssl (DEBIAN-CVE-2026-44662)
vulnerability in rust-openssl (DEBIAN-CVE-2026-44662). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.79` or later.
|
| CVE-2026-44679 |
|
Vulnerability in CVE-2026-44679 (CVE-2026-44679)
vulnerability in CVE-2026-44679 (CVE-2026-44679). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.180.10` or later.
|
| CVE-2026-44678 |
|
Vulnerability in CVE-2026-44678 (CVE-2026-44678)
vulnerability in CVE-2026-44678 (CVE-2026-44678). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/projects/{account_handle}/{project_handle}/previews/{preview_id}`.
|
| CVE-2026-44673 |
|
Vulnerability in c (CVE-2026-44673)
vulnerability in c (CVE-2026-44673). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44666 |
|
OS Command Injection in CVE-2026-44666 (CVE-2026-44666)
OS command injection in CVE-2026-44666 (CVE-2026-44666). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.8` or later.
|
| CVE-2026-44661 |
|
SSRF (Server-Side Request Forgery) in utcp-http (CVE-2026-44661)
SSRF in utcp-http (CVE-2026-44661). Risk of unauthorized operations or information disclosure. Exploitable via ``tool_call_template.url``. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-44647 |
|
Path Traversal in CVE-2026-44647 (CVE-2026-44647)
path traversal in CVE-2026-44647 (CVE-2026-44647). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `15.0.2` or later.
|
| CVE-2026-42847 |
|
SQL Injection in sqli (CVE-2026-42847)
SQL injection in sqli (CVE-2026-42847). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5.3` or later.
|
| DEBIAN-CVE-2026-42327 |
|
Vulnerability in rust-openssl (DEBIAN-CVE-2026-42327)
vulnerability in rust-openssl (DEBIAN-CVE-2026-42327). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.79` or later.
|
| CVE-2026-42327 |
|
Vulnerability in openssl (CVE-2026-42327)
vulnerability in openssl (CVE-2026-42327). Risk of unauthorized operations or information disclosure. Exploitable via ``OpensslString``. Mitigation: upgrade to `0.10.79` or later.
|
| UBUNTU-CVE-2026-44673 |
|
Vulnerability in libyang (UBUNTU-CVE-2026-44673)
vulnerability in libyang (UBUNTU-CVE-2026-44673). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-44662 |
|
Vulnerability in rust-openssl (UBUNTU-CVE-2026-44662)
vulnerability in rust-openssl (UBUNTU-CVE-2026-44662). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.79` or later.
|
| UBUNTU-CVE-2026-42327 |
|
Vulnerability in rust-openssl (UBUNTU-CVE-2026-42327)
vulnerability in rust-openssl (UBUNTU-CVE-2026-42327). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.10.79` or later.
|
| MINI-r4h2-mq56-wx5p |
|
MINI-r4h2-mq56-wx5p |
| MINI-743v-37p9-j24w |
|
MINI-743v-37p9-j24w |
| MINI-w4qq-57c5-qfm4 |
|
MINI-w4qq-57c5-qfm4 |
| MINI-f5rf-8c7q-32h7 |
|
MINI-f5rf-8c7q-32h7 |
| MINI-wc8g-wj5w-876c |
|
MINI-wc8g-wj5w-876c |
| MINI-3mgf-26wj-5gmw |
|
MINI-3mgf-26wj-5gmw |
| MINI-rx32-4mc8-88p4 |
|
MINI-rx32-4mc8-88p4 |
| MINI-crq7-rw96-pf6c |
|
MINI-crq7-rw96-pf6c |
| MINI-6xfv-8rwh-33rv |
|
MINI-6xfv-8rwh-33rv |
| MINI-7r6r-wxhm-x27j |
|
MINI-7r6r-wxhm-x27j |
| MINI-3rq9-8j76-hgc3 |
|
MINI-3rq9-8j76-hgc3 |
| MINI-qf7r-wqv6-83cv |
|
MINI-qf7r-wqv6-83cv |
| MINI-ff6q-hr9q-93jh |
|
MINI-ff6q-hr9q-93jh |
| MINI-2mw8-876p-rm68 |
|
MINI-2mw8-876p-rm68 |
| MINI-582r-c4wm-wwmj |
|
MINI-582r-c4wm-wwmj |
| DEBIAN-CVE-2026-43961 |
|
DEBIAN-CVE-2026-43961 |
| MINI-ppp8-6mv3-r3r3 |
|
MINI-ppp8-6mv3-r3r3 |
| MINI-926w-xc7v-h43c |
|
MINI-926w-xc7v-h43c |
| MINI-5gm6-q5h6-gq5m |
|
MINI-5gm6-q5h6-gq5m |
| MINI-8xj4-mphp-86qr |
|
MINI-8xj4-mphp-86qr |
| MINI-hg2m-hw7w-r3m9 |
|
MINI-hg2m-hw7w-r3m9 |
| MINI-68h2-8pv2-96rg |
|
MINI-68h2-8pv2-96rg |
| MINI-6qx4-f79q-g2mr |
|
MINI-6qx4-f79q-g2mr |
| MINI-3vpv-7q6v-v632 |
|
MINI-3vpv-7q6v-v632 |
| MINI-66jr-8wh7-prm7 |
|
MINI-66jr-8wh7-prm7 |
| MINI-69qg-mjg3-hr5v |
|
MINI-69qg-mjg3-hr5v |
| MINI-5j53-mrjg-697x |
|
MINI-5j53-mrjg-697x |
| CVE-2026-45370 |
|
Vulnerability in utcp-cli (CVE-2026-45370)
vulnerability in utcp-cli (CVE-2026-45370). Confidential information can be exposed externally. Exploitable via ``cli_communication_protocol.py``. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-45369 |
|
OS Command Injection in utcp-cli (CVE-2026-45369)
OS command injection in utcp-cli (CVE-2026-45369). Successful exploitation can lead to full system takeover. Exploitable via ``_substitute_utcp_args``. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-46509 |
|
Vulnerability in @ranfdev/deepobj (CVE-2026-46509)
vulnerability in @ranfdev/deepobj (CVE-2026-46509). Data can be tampered with by attackers. Exploitable via ``__proto__``. Mitigation: upgrade to `1.0.3` or later.
|
| CVE-2026-45366 |
|
SSRF (Server-Side Request Forgery) in @utcp/http (CVE-2026-45366)
SSRF in @utcp/http (CVE-2026-45366). Risk of unauthorized operations or information disclosure. Exploitable via ``toolCallTemplate.url``. Mitigation: upgrade to `1.1.2` or later.
|