Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CLSA-2026-1778786567 |
|
Vulnerability in curl (CLSA-2026-1778786567)
vulnerability in curl (CLSA-2026-1778786567). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.19.7-59.el6.tuxcare.els16` or later.
|
| CLSA-2026-1778745959 |
|
Vulnerability in libssh2 (CLSA-2026-1778745959)
vulnerability in libssh2 (CLSA-2026-1778745959). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.2-3.0.1.el6_10.1.tuxcare.els4` or later.
|
| CLSA-2026-1778493573 |
|
Vulnerability in libsmbclient (CLSA-2026-1778493573)
vulnerability in libsmbclient (CLSA-2026-1778493573). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.23-53.el6_10.tuxcare.els5` or later.
|
| CVE-2026-8621 |
|
Authentication Bypass in github.com/openclaw/crabbox (CVE-2026-8621)
authentication bypass in github.com/openclaw/crabbox (CVE-2026-8621). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.12.0` or later.
|
| CVE-2026-44633 |
|
Authorization Flaw in CVE-2026-44633 (CVE-2026-44633)
vulnerability in CVE-2026-44633 (CVE-2026-44633). Confidential information can be exposed externally.
|
| CVE-2026-44592 |
|
Vulnerability in CVE-2026-44592 (CVE-2026-44592)
vulnerability in CVE-2026-44592 (CVE-2026-44592). Data can be tampered with by attackers. Mitigation: upgrade to `1.1.1` or later.
|
| CVE-2026-44589 |
|
SSRF (Server-Side Request Forgery) in nuxt-og-image (CVE-2026-44589)
SSRF in nuxt-og-image (CVE-2026-44589). Risk of unauthorized operations or information disclosure. Exploitable via ``isBlockedUrl``. Mitigation: upgrade to `6.4.9` or later.
|
| CVE-2026-44586 |
|
Cross-Site Scripting (XSS) in CVE-2026-44586 (CVE-2026-44586)
cross-site scripting in CVE-2026-44586 (CVE-2026-44586). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.7.0` or later.
|
| CVE-2026-44523 |
|
Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44523)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44523). Confidential information can be exposed externally. Exploitable via ``JWT_SECRET``. Mitigation: upgrade to `0.0.0-20260501152247-18b587758667` or later.
|
| CVE-2026-44522 |
|
Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44522)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44522). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/notes/{noteID}/assets`. Mitigation: upgrade to `0.0.0-20260501152243-db3f72bff780` or later.
|
| CVE-2026-41315 |
|
OS Command Injection in midoks (CVE-2026-41315)
OS command injection in midoks (CVE-2026-41315). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38740 |
|
Vulnerability in CVE-2026-38740 (CVE-2026-38740)
vulnerability in CVE-2026-38740 (CVE-2026-38740). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27680 |
|
Vulnerability in sap (CVE-2026-27680)
vulnerability in sap (CVE-2026-27680). Risk of unauthorized operations or information disclosure.
|
| CLSA-2026-1778769697 |
|
Vulnerability in bpftool (CLSA-2026-1778769697)
vulnerability in bpftool (CLSA-2026-1778769697). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.0-284.1101.el9_2.tuxcare.7.els32` or later.
|
| CLSA-2026-1778760144 |
|
Vulnerability in openexr (CLSA-2026-1778760144)
vulnerability in openexr (CLSA-2026-1778760144). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1-3.el9.tuxcare.els6` or later.
|
| CVE-2026-44541 |
|
Cross-Site Scripting (XSS) in ethyca-fides (CVE-2026-44541)
cross-site scripting in ethyca-fides (CVE-2026-44541). Risk of unauthorized operations or information disclosure. Exploitable via ``fides.js``. Mitigation: upgrade to `2.84.5` or later.
|
| CLSA-2026-1778756042 |
|
Vulnerability in openexr (CLSA-2026-1778756042)
vulnerability in openexr (CLSA-2026-1778756042). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1-3.el9.tuxcare.els6` or later.
|
| MAL-2026-3742 |
|
Vulnerability in tronpath (MAL-2026-3742)
vulnerability in tronpath (MAL-2026-3742). Risk of unauthorized operations or information disclosure.
|
| ECHO-4544-3b20-7e41 |
|
ECHO-4544-3b20-7e41 |
| CLSA-2026-1778767103 |
|
Vulnerability in imagemagick (CLSA-2026-1778767103)
vulnerability in imagemagick (CLSA-2026-1778767103). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8:6.9.10.23+dfsg-2.1ubuntu11.11+tuxcare.els26` or later.
|
| CLSA-2026-1778757276 |
|
Vulnerability in bpftool (CLSA-2026-1778757276)
vulnerability in bpftool (CLSA-2026-1778757276). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.10.0-1160.144.1.el7.tuxcare.els5` or later.
|
| CVE-2026-42897 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Microsoft exchange-server (CVE-2026-42897)
cross-site scripting in Microsoft exchange-server (CVE-2026-42897). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-6332 |
|
Vulnerability in c (CVE-2026-6332)
vulnerability in c (CVE-2026-6332). Confidential information can be exposed externally.
|
| CVE-2026-46470 |
|
Vulnerability in dos (CVE-2026-46470)
vulnerability in dos (CVE-2026-46470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41615 |
|
Information Disclosure in microsoft (CVE-2026-41615)
vulnerability in microsoft (CVE-2026-41615). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15023 |
|
Authorization Flaw in CVE-2025-15023 (CVE-2025-15023)
vulnerability in CVE-2025-15023 (CVE-2025-15023). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46469 |
|
Vulnerability in dos (CVE-2026-46469)
vulnerability in dos (CVE-2026-46469). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15024 |
|
Code Injection in CVE-2025-15024 (CVE-2025-15024)
code injection in CVE-2025-15024 (CVE-2025-15024). Successful exploitation can lead to full system takeover.
|
| MAL-2026-3747 |
|
Vulnerability in @aiscene/aiserver (MAL-2026-3747)
vulnerability in @aiscene/aiserver (MAL-2026-3747). Risk of unauthorized operations or information disclosure. Exploitable via ``naturalLanguage``.
|
| CLSA-2026-1778783464 |
|
Update of kernel
Update of kernel
|
| CVE-2026-45011 |
|
Cross-Site Scripting (XSS) in apostrophe (CVE-2026-45011)
cross-site scripting in apostrophe (CVE-2026-45011). Confidential information can be exposed externally.
|
| CVE-2026-45013 |
|
Vulnerability in apostrophe (CVE-2026-45013)
vulnerability in apostrophe (CVE-2026-45013). Confidential information can be exposed externally. Exploitable via `POST /api/v1/login/reset-request`.
|
| CLSA-2026-1778783204 |
|
Update of kernel
Update of kernel
|
| CVE-2026-45012 |
|
SSRF (Server-Side Request Forgery) in apostrophe (CVE-2026-45012)
SSRF in apostrophe (CVE-2026-45012). Confidential information can be exposed externally. Exploitable via `POST /api/v1/`.
|
| CVE-2026-44990 |
|
Cross-Site Scripting (XSS) in sanitize-html (CVE-2026-44990)
cross-site scripting in sanitize-html (CVE-2026-44990). Confidential information can be exposed externally. Exploitable via ``xmp``. Mitigation: upgrade to `2.17.4` or later.
|
| GHSA-7rx4-c5vx-g8w3 |
|
SSRF (Server-Side Request Forgery) in @karakeep/sdk (GHSA-7rx4-c5vx-g8w3)
SSRF in @karakeep/sdk (GHSA-7rx4-c5vx-g8w3). Risk of unauthorized operations or information disclosure. Exploitable via ``href``. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-44973 |
|
Path Traversal in github.com/go-git/go-billy/v5 (CVE-2026-44973)
path traversal in github.com/go-git/go-billy/v5 (CVE-2026-44973). Confidential information can be exposed externally. Exploitable via ``osfs.ChrootOS``. Mitigation: upgrade to `5.9.0` or later.
|
| CVE-2026-44970 |
|
Vulnerability in dbt-mcp (CVE-2026-44970)
vulnerability in dbt-mcp (CVE-2026-44970). Risk of unauthorized operations or information disclosure. Exploitable via ``arguments``. Mitigation: upgrade to `1.17.1` or later.
|
| CVE-2026-44969 |
|
Vulnerability in dbt-mcp (CVE-2026-44969)
vulnerability in dbt-mcp (CVE-2026-44969). Risk of unauthorized operations or information disclosure. Exploitable via ``arguments``. Mitigation: upgrade to `1.17.1` or later.
|
| CVE-2026-44968 |
|
Vulnerability in dbt-mcp (CVE-2026-44968)
vulnerability in dbt-mcp (CVE-2026-44968). Confidential information can be exposed externally. Exploitable via ``node_selection``. Mitigation: upgrade to `1.17.1` or later.
|
| MINI-c5v7-9w9g-cx92 |
|
MINI-c5v7-9w9g-cx92 |
| CLSA-2026-1778773906 |
|
Vulnerability in PackageKit (CLSA-2026-1778773906)
vulnerability in PackageKit (CLSA-2026-1778773906). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.6-1.el9.tuxcare.els1` or later.
|
| DEBIAN-CVE-2026-46470 |
|
Vulnerability in gst-plugins-good1.0 (DEBIAN-CVE-2026-46470)
vulnerability in gst-plugins-good1.0 (DEBIAN-CVE-2026-46470). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.2-1+deb13u1` or later.
|
| DEBIAN-CVE-2026-44544 |
|
Vulnerability in gittuf (DEBIAN-CVE-2026-44544)
vulnerability in gittuf (DEBIAN-CVE-2026-44544). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.14.0` or later.
|
| DEBIAN-CVE-2026-46469 |
|
Vulnerability in gst-plugins-good1.0 (DEBIAN-CVE-2026-46469)
vulnerability in gst-plugins-good1.0 (DEBIAN-CVE-2026-46469). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.26.2-1+deb13u1` or later.
|
| CVE-2026-44544 |
|
Vulnerability in github.com/gittuf/gittuf (CVE-2026-44544)
vulnerability in github.com/gittuf/gittuf (CVE-2026-44544). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.14.0` or later.
|
| CVE-2026-44542 |
|
Path Traversal in github.com/gtsteffaniak/filebrowser (CVE-2026-44542)
path traversal in github.com/gtsteffaniak/filebrowser (CVE-2026-44542). Data can be tampered with by attackers. Exploitable via `DELETE /public/api/resources`. Mitigation: upgrade to `0.0.0-20260501183844-112740bdd41d` or later.
|
| CVE-2026-44520 |
|
Open Redirect in docling-graph (CVE-2026-44520)
vulnerability in docling-graph (CVE-2026-44520). Confidential information can be exposed externally. Exploitable via ``URLInputHandler``. Mitigation: upgrade to `1.5.1` or later.
|
| DEBIAN-CVE-2026-44283 |
|
Vulnerability in etcd (DEBIAN-CVE-2026-44283)
vulnerability in etcd (DEBIAN-CVE-2026-44283). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.44` or later.
|
| CVE-2026-42598 |
|
Path Traversal in c (CVE-2026-42598)
path traversal in c (CVE-2026-42598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.13.0` or later.
|