Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CLSA-2026-1778786567 Vulnerability in curl (CLSA-2026-1778786567)
vulnerability in curl (CLSA-2026-1778786567). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.19.7-59.el6.tuxcare.els16` or later.
CLSA-2026-1778745959 Vulnerability in libssh2 (CLSA-2026-1778745959)
vulnerability in libssh2 (CLSA-2026-1778745959). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.2-3.0.1.el6_10.1.tuxcare.els4` or later.
CLSA-2026-1778493573 Vulnerability in libsmbclient (CLSA-2026-1778493573)
vulnerability in libsmbclient (CLSA-2026-1778493573). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.23-53.el6_10.tuxcare.els5` or later.
CVE-2026-8621 Authentication Bypass in github.com/openclaw/crabbox (CVE-2026-8621)
authentication bypass in github.com/openclaw/crabbox (CVE-2026-8621). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.12.0` or later.
CVE-2026-44633 Authorization Flaw in CVE-2026-44633 (CVE-2026-44633)
vulnerability in CVE-2026-44633 (CVE-2026-44633). Confidential information can be exposed externally.
CVE-2026-44592 Vulnerability in CVE-2026-44592 (CVE-2026-44592)
vulnerability in CVE-2026-44592 (CVE-2026-44592). Data can be tampered with by attackers. Mitigation: upgrade to `1.1.1` or later.
CVE-2026-44589 SSRF (Server-Side Request Forgery) in nuxt-og-image (CVE-2026-44589)
SSRF in nuxt-og-image (CVE-2026-44589). Risk of unauthorized operations or information disclosure. Exploitable via ``isBlockedUrl``. Mitigation: upgrade to `6.4.9` or later.
CVE-2026-44586 Cross-Site Scripting (XSS) in CVE-2026-44586 (CVE-2026-44586)
cross-site scripting in CVE-2026-44586 (CVE-2026-44586). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.7.0` or later.
CVE-2026-44523 Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44523)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44523). Confidential information can be exposed externally. Exploitable via ``JWT_SECRET``. Mitigation: upgrade to `0.0.0-20260501152247-18b587758667` or later.
CVE-2026-44522 Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44522)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44522). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/notes/{noteID}/assets`. Mitigation: upgrade to `0.0.0-20260501152243-db3f72bff780` or later.
CVE-2026-41315 OS Command Injection in midoks (CVE-2026-41315)
OS command injection in midoks (CVE-2026-41315). Successful exploitation can lead to full system takeover.
CVE-2026-38740 Vulnerability in CVE-2026-38740 (CVE-2026-38740)
vulnerability in CVE-2026-38740 (CVE-2026-38740). Risk of unauthorized operations or information disclosure.
CVE-2026-27680 Vulnerability in sap (CVE-2026-27680)
vulnerability in sap (CVE-2026-27680). Risk of unauthorized operations or information disclosure.
CLSA-2026-1778769697 Vulnerability in bpftool (CLSA-2026-1778769697)
vulnerability in bpftool (CLSA-2026-1778769697). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.0-284.1101.el9_2.tuxcare.7.els32` or later.
CLSA-2026-1778760144 Vulnerability in openexr (CLSA-2026-1778760144)
vulnerability in openexr (CLSA-2026-1778760144). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1-3.el9.tuxcare.els6` or later.
CVE-2026-44541 Cross-Site Scripting (XSS) in ethyca-fides (CVE-2026-44541)
cross-site scripting in ethyca-fides (CVE-2026-44541). Risk of unauthorized operations or information disclosure. Exploitable via ``fides.js``. Mitigation: upgrade to `2.84.5` or later.
CLSA-2026-1778756042 Vulnerability in openexr (CLSA-2026-1778756042)
vulnerability in openexr (CLSA-2026-1778756042). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1-3.el9.tuxcare.els6` or later.
MAL-2026-3742 Vulnerability in tronpath (MAL-2026-3742)
vulnerability in tronpath (MAL-2026-3742). Risk of unauthorized operations or information disclosure.
ECHO-4544-3b20-7e41 ECHO-4544-3b20-7e41
CLSA-2026-1778767103 Vulnerability in imagemagick (CLSA-2026-1778767103)
vulnerability in imagemagick (CLSA-2026-1778767103). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8:6.9.10.23+dfsg-2.1ubuntu11.11+tuxcare.els26` or later.
CLSA-2026-1778757276 Vulnerability in bpftool (CLSA-2026-1778757276)
vulnerability in bpftool (CLSA-2026-1778757276). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.10.0-1160.144.1.el7.tuxcare.els5` or later.
CVE-2026-42897 KEV [KEV] Cross-Site Scripting (XSS) in Microsoft exchange-server (CVE-2026-42897)
cross-site scripting in Microsoft exchange-server (CVE-2026-42897). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-6332 Vulnerability in c (CVE-2026-6332)
vulnerability in c (CVE-2026-6332). Confidential information can be exposed externally.
CVE-2026-46470 Vulnerability in dos (CVE-2026-46470)
vulnerability in dos (CVE-2026-46470). Risk of unauthorized operations or information disclosure.
CVE-2026-41615 Information Disclosure in microsoft (CVE-2026-41615)
vulnerability in microsoft (CVE-2026-41615). Successful exploitation can lead to full system takeover.
CVE-2025-15023 Authorization Flaw in CVE-2025-15023 (CVE-2025-15023)
vulnerability in CVE-2025-15023 (CVE-2025-15023). Successful exploitation can lead to full system takeover.
CVE-2026-46469 Vulnerability in dos (CVE-2026-46469)
vulnerability in dos (CVE-2026-46469). Risk of unauthorized operations or information disclosure.
CVE-2025-15024 Code Injection in CVE-2025-15024 (CVE-2025-15024)
code injection in CVE-2025-15024 (CVE-2025-15024). Successful exploitation can lead to full system takeover.
MAL-2026-3747 Vulnerability in @aiscene/aiserver (MAL-2026-3747)
vulnerability in @aiscene/aiserver (MAL-2026-3747). Risk of unauthorized operations or information disclosure. Exploitable via ``naturalLanguage``.
CLSA-2026-1778783464 Update of kernel
Update of kernel
CVE-2026-45011 Cross-Site Scripting (XSS) in apostrophe (CVE-2026-45011)
cross-site scripting in apostrophe (CVE-2026-45011). Confidential information can be exposed externally.
CVE-2026-45013 Vulnerability in apostrophe (CVE-2026-45013)
vulnerability in apostrophe (CVE-2026-45013). Confidential information can be exposed externally. Exploitable via `POST /api/v1/login/reset-request`.
CLSA-2026-1778783204 Update of kernel
Update of kernel
CVE-2026-45012 SSRF (Server-Side Request Forgery) in apostrophe (CVE-2026-45012)
SSRF in apostrophe (CVE-2026-45012). Confidential information can be exposed externally. Exploitable via `POST /api/v1/`.
CVE-2026-44990 Cross-Site Scripting (XSS) in sanitize-html (CVE-2026-44990)
cross-site scripting in sanitize-html (CVE-2026-44990). Confidential information can be exposed externally. Exploitable via ``xmp``. Mitigation: upgrade to `2.17.4` or later.
GHSA-7rx4-c5vx-g8w3 SSRF (Server-Side Request Forgery) in @karakeep/sdk (GHSA-7rx4-c5vx-g8w3)
SSRF in @karakeep/sdk (GHSA-7rx4-c5vx-g8w3). Risk of unauthorized operations or information disclosure. Exploitable via ``href``. Mitigation: upgrade to `0.32.0` or later.
CVE-2026-44973 Path Traversal in github.com/go-git/go-billy/v5 (CVE-2026-44973)
path traversal in github.com/go-git/go-billy/v5 (CVE-2026-44973). Confidential information can be exposed externally. Exploitable via ``osfs.ChrootOS``. Mitigation: upgrade to `5.9.0` or later.
CVE-2026-44970 Vulnerability in dbt-mcp (CVE-2026-44970)
vulnerability in dbt-mcp (CVE-2026-44970). Risk of unauthorized operations or information disclosure. Exploitable via ``arguments``. Mitigation: upgrade to `1.17.1` or later.
CVE-2026-44969 Vulnerability in dbt-mcp (CVE-2026-44969)
vulnerability in dbt-mcp (CVE-2026-44969). Risk of unauthorized operations or information disclosure. Exploitable via ``arguments``. Mitigation: upgrade to `1.17.1` or later.
CVE-2026-44968 Vulnerability in dbt-mcp (CVE-2026-44968)
vulnerability in dbt-mcp (CVE-2026-44968). Confidential information can be exposed externally. Exploitable via ``node_selection``. Mitigation: upgrade to `1.17.1` or later.
MINI-c5v7-9w9g-cx92 MINI-c5v7-9w9g-cx92
CLSA-2026-1778773906 Vulnerability in PackageKit (CLSA-2026-1778773906)
vulnerability in PackageKit (CLSA-2026-1778773906). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.6-1.el9.tuxcare.els1` or later.
DEBIAN-CVE-2026-46470 Vulnerability in gst-plugins-good1.0 (DEBIAN-CVE-2026-46470)
vulnerability in gst-plugins-good1.0 (DEBIAN-CVE-2026-46470). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.2-1+deb13u1` or later.
DEBIAN-CVE-2026-44544 Vulnerability in gittuf (DEBIAN-CVE-2026-44544)
vulnerability in gittuf (DEBIAN-CVE-2026-44544). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.14.0` or later.
DEBIAN-CVE-2026-46469 Vulnerability in gst-plugins-good1.0 (DEBIAN-CVE-2026-46469)
vulnerability in gst-plugins-good1.0 (DEBIAN-CVE-2026-46469). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.26.2-1+deb13u1` or later.
CVE-2026-44544 Vulnerability in github.com/gittuf/gittuf (CVE-2026-44544)
vulnerability in github.com/gittuf/gittuf (CVE-2026-44544). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.14.0` or later.
CVE-2026-44542 Path Traversal in github.com/gtsteffaniak/filebrowser (CVE-2026-44542)
path traversal in github.com/gtsteffaniak/filebrowser (CVE-2026-44542). Data can be tampered with by attackers. Exploitable via `DELETE /public/api/resources`. Mitigation: upgrade to `0.0.0-20260501183844-112740bdd41d` or later.
CVE-2026-44520 Open Redirect in docling-graph (CVE-2026-44520)
vulnerability in docling-graph (CVE-2026-44520). Confidential information can be exposed externally. Exploitable via ``URLInputHandler``. Mitigation: upgrade to `1.5.1` or later.
DEBIAN-CVE-2026-44283 Vulnerability in etcd (DEBIAN-CVE-2026-44283)
vulnerability in etcd (DEBIAN-CVE-2026-44283). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.44` or later.
CVE-2026-42598 Path Traversal in c (CVE-2026-42598)
path traversal in c (CVE-2026-42598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.13.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →