Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-gxhx-2686-5h9g |
|
Vulnerability in github.com/slack-go/slack (GHSA-gxhx-2686-5h9g)
vulnerability in github.com/slack-go/slack (GHSA-gxhx-2686-5h9g). Risk of unauthorized operations or information disclosure. Exploitable via ``SecretsVerifier``. Mitigation: upgrade to `0.23.1` or later.
|
| CVE-2026-45288 |
|
SQL Injection in Marten (CVE-2026-45288)
SQL injection in Marten (CVE-2026-45288). Successful exploitation can lead to full system takeover. Exploitable via ``regConfig``. Mitigation: upgrade to `8.37.0` or later.
|
| MINI-q63h-6xrg-f42w |
|
MINI-q63h-6xrg-f42w |
| MINI-5488-h8vx-jg8x |
|
MINI-5488-h8vx-jg8x |
| MINI-f6wv-p938-9gvf |
|
MINI-f6wv-p938-9gvf |
| MINI-w9f3-pwp2-74h2 |
|
MINI-w9f3-pwp2-74h2 |
| MINI-3m5x-fm49-44p3 |
|
MINI-3m5x-fm49-44p3 |
| MINI-wgv2-jxpc-x9pc |
|
MINI-wgv2-jxpc-x9pc |
| MINI-9524-4vwp-pfm2 |
|
MINI-9524-4vwp-pfm2 |
| GHSA-wf8q-wvv8-p8jf |
|
Vulnerability in @samanhappy/mcphub (GHSA-wf8q-wvv8-p8jf)
vulnerability in @samanhappy/mcphub (GHSA-wf8q-wvv8-p8jf). Confidential information can be exposed externally. Exploitable via ``sseUserContextMiddleware``. Mitigation: upgrade to `0.12.15` or later.
|
| MAL-2026-3743 |
|
Vulnerability in sol-batch-transfer-sdk (MAL-2026-3743)
vulnerability in sol-batch-transfer-sdk (MAL-2026-3743). Risk of unauthorized operations or information disclosure.
|
| MINI-vh5p-vc4p-ph5v |
|
MINI-vh5p-vc4p-ph5v |
| MINI-fp7c-9852-9mqf |
|
MINI-fp7c-9852-9mqf |
| MINI-qh32-frhv-8gqq |
|
MINI-qh32-frhv-8gqq |
| MINI-w624-qg29-9v23 |
|
MINI-w624-qg29-9v23 |
| MINI-pvgq-q9qg-2wp2 |
|
MINI-pvgq-q9qg-2wp2 |
| MINI-qrfm-chff-q8m6 |
|
MINI-qrfm-chff-q8m6 |
| MINI-cfmg-jpcr-7q7m |
|
MINI-cfmg-jpcr-7q7m |
| MINI-q3c8-jwfj-vh59 |
|
MINI-q3c8-jwfj-vh59 |
| MINI-jqw7-rhh8-pr3w |
|
MINI-jqw7-rhh8-pr3w |
| MINI-54pw-jcp9-qjv2 |
|
MINI-54pw-jcp9-qjv2 |
| MINI-9wgm-74m9-p5r2 |
|
MINI-9wgm-74m9-p5r2 |
| MINI-fh2f-77f6-jhv7 |
|
MINI-fh2f-77f6-jhv7 |
| MINI-4f7g-vrj8-7542 |
|
MINI-4f7g-vrj8-7542 |
| MINI-f29x-4pj4-746w |
|
MINI-f29x-4pj4-746w |
| MINI-f9f6-4rxf-mfcj |
|
MINI-f9f6-4rxf-mfcj |
| MINI-v4fh-v5gm-3pmq |
|
MINI-v4fh-v5gm-3pmq |
| MINI-cvmh-mhf7-29c6 |
|
MINI-cvmh-mhf7-29c6 |
| MINI-3pw3-frhj-pv3p |
|
MINI-3pw3-frhj-pv3p |
| MINI-9m2m-m449-7wpg |
|
MINI-9m2m-m449-7wpg |
| MINI-35vj-ghhj-773q |
|
MINI-35vj-ghhj-773q |
| MINI-8vxv-3rj4-v7xr |
|
MINI-8vxv-3rj4-v7xr |
| GHSA-f3cj-j4f6-wq85 |
|
Cross-Site Scripting (XSS) in svelte (GHSA-f3cj-j4f6-wq85)
cross-site scripting in svelte (GHSA-f3cj-j4f6-wq85). Risk of unauthorized operations or information disclosure. Exploitable via ``hydratable``. Mitigation: upgrade to `5.55.7` or later.
|
| CVE-2026-45787 |
|
Vulnerability in electerm (CVE-2026-45787)
vulnerability in electerm (CVE-2026-45787). Confidential information can be exposed externally. Mitigation: upgrade to `3.9.5` or later.
|
| CVE-2026-45353 |
|
Vulnerability in electerm (CVE-2026-45353)
vulnerability in electerm (CVE-2026-45353). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.0` or later.
|
| CVE-2026-45374 |
|
Code Injection in deepseek-tui (CVE-2026-45374)
code injection in deepseek-tui (CVE-2026-45374). Successful exploitation can lead to full system takeover. Exploitable via ``task_create``. Mitigation: upgrade to `0.8.26` or later.
|
| CVE-2026-45373 |
|
SSRF (Server-Side Request Forgery) in deepseek-tui (CVE-2026-45373)
SSRF in deepseek-tui (CVE-2026-45373). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.26` or later.
|
| CVE-2026-45311 |
|
Code Injection in deepseek-tui (CVE-2026-45311)
code injection in deepseek-tui (CVE-2026-45311). Successful exploitation can lead to full system takeover. Exploitable via ``run_tests``. Mitigation: upgrade to `0.8.23` or later.
|
| CVE-2026-45310 |
|
SSRF (Server-Side Request Forgery) in deepseek-tui (CVE-2026-45310)
SSRF in deepseek-tui (CVE-2026-45310). Confidential information can be exposed externally. Exploitable via ``fetch_url``. Mitigation: upgrade to `0.8.22` or later.
|
| CVE-2026-42573 |
|
Cross-Site Scripting (XSS) in svelte (CVE-2026-42573)
cross-site scripting in svelte (CVE-2026-42573). Risk of unauthorized operations or information disclosure. Exploitable via ``name``. Mitigation: upgrade to `5.55.7` or later.
|
| CVE-2026-42567 |
|
Vulnerability in svelte (CVE-2026-42567)
vulnerability in svelte (CVE-2026-42567). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.55.7` or later.
|
| CVE-2026-45675 |
|
Privilege Escalation in open-webui (CVE-2026-45675)
vulnerability in open-webui (CVE-2026-45675). Successful exploitation can lead to full system takeover. Exploitable via ``signup_handler``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45672 |
|
Authorization Flaw in open-webui (CVE-2026-45672)
vulnerability in open-webui (CVE-2026-45672). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.12` or later.
|
| CVE-2026-45671 |
|
Vulnerability in open-webui (CVE-2026-45671)
vulnerability in open-webui (CVE-2026-45671). Successful exploitation can lead to full system takeover. Exploitable via `DELETE /api/v1/files/{id}`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45667 |
|
Vulnerability in open-webui (CVE-2026-45667)
vulnerability in open-webui (CVE-2026-45667). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2026-45666 |
|
Vulnerability in open-webui (CVE-2026-45666)
vulnerability in open-webui (CVE-2026-45666). Confidential information can be exposed externally. Exploitable via `GET /api/config.`. Mitigation: upgrade to `0.8.11` or later.
|
| CVE-2026-45665 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-45665)
cross-site scripting in open-webui (CVE-2026-45665). Confidential information can be exposed externally. Exploitable via ``marked.parse``. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2026-45402 |
|
Vulnerability in open-webui (CVE-2026-45402)
vulnerability in open-webui (CVE-2026-45402). Confidential information can be exposed externally. Exploitable via `POST /api/v1/folders/{id}/update`. Mitigation: upgrade to `0.9.5` or later.
|
| GHSA-3wgj-c2hg-vm6q |
|
Vulnerability in open-webui (GHSA-3wgj-c2hg-vm6q)
vulnerability in open-webui (GHSA-3wgj-c2hg-vm6q). Confidential information can be exposed externally. Exploitable via `GET /api/v1/users/{id}/profile/image`. Mitigation: upgrade to `0.9.5` or later.
|
| CVE-2026-45401 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-45401)
SSRF in open-webui (CVE-2026-45401). Confidential information can be exposed externally. Exploitable via ``requests``. Mitigation: upgrade to `0.9.5` or later.
|