Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2025-69443 Code Injection in CVE-2025-69443 (CVE-2025-69443)
code injection in CVE-2025-69443 (CVE-2025-69443). Risk of unauthorized operations or information disclosure.
CVE-2025-62628 Vulnerability in CVE-2025-62628 (CVE-2025-62628)
vulnerability in CVE-2025-62628 (CVE-2025-62628). Risk of unauthorized operations or information disclosure.
CVE-2026-24710 Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.
CVE-2026-6476 SQL Injection in postgresql (CVE-2026-6476)
SQL injection in postgresql (CVE-2026-6476). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.10.0, 18.4.0` or later.
CVE-2026-21730 Cross-Site Scripting (XSS) in verint (CVE-2026-21730)
cross-site scripting in verint (CVE-2026-21730). Risk of unauthorized operations or information disclosure.
CVE-2026-41932 Cross-Site Scripting (XSS) in CVE-2026-41932 (CVE-2026-41932)
cross-site scripting in CVE-2026-41932 (CVE-2026-41932). Risk of unauthorized operations or information disclosure.
CVE-2026-6472 Vulnerability in postgresql (CVE-2026-6472)
vulnerability in postgresql (CVE-2026-6472). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
CVE-2026-41933 Vulnerability in CVE-2026-41933 (CVE-2026-41933)
vulnerability in CVE-2026-41933 (CVE-2026-41933). Risk of unauthorized operations or information disclosure.
CVE-2026-6473 Vulnerability in postgresql (CVE-2026-6473)
vulnerability in postgresql (CVE-2026-6473). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
CVE-2026-6479 Vulnerability in postgresql (CVE-2026-6479)
vulnerability in postgresql (CVE-2026-6479). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
CVE-2026-24712 Command Injection in northerntech (CVE-2026-24712)
command injection in northerntech (CVE-2026-24712). Risk of unauthorized operations or information disclosure.
CVE-2026-6478 Vulnerability in postgresql (CVE-2026-6478)
vulnerability in postgresql (CVE-2026-6478). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
CVE-2026-6474 Vulnerability in postgresql (CVE-2026-6474)
vulnerability in postgresql (CVE-2026-6474). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
CVE-2025-62625 Privilege Escalation in CVE-2025-62625 (CVE-2025-62625)
vulnerability in CVE-2025-62625 (CVE-2025-62625). Risk of unauthorized operations or information disclosure.
CVE-2026-6475 Vulnerability in postgresql (CVE-2026-6475)
vulnerability in postgresql (CVE-2026-6475). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
CVE-2025-15025 Vulnerability in CVE-2025-15025 (CVE-2025-15025)
vulnerability in CVE-2025-15025 (CVE-2025-15025). Successful exploitation can lead to full system takeover.
CVE-2026-6477 Vulnerability in postgresql (CVE-2026-6477)
vulnerability in postgresql (CVE-2026-6477). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
CVE-2026-1630 Cross-Site Scripting (XSS) in CVE-2026-1630 (CVE-2026-1630)
cross-site scripting in CVE-2026-1630 (CVE-2026-1630). Risk of unauthorized operations or information disclosure.
CVE-2026-24711 Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.
CVE-2026-6575 Vulnerability in postgresql (CVE-2026-6575)
vulnerability in postgresql (CVE-2026-6575). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.4.0` or later.
CVE-2026-6637 SQL Injection in postgresql (CVE-2026-6637)
SQL injection in postgresql (CVE-2026-6637). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
openSUSE-SU-2026:20753-1 Vulnerability in openSUSE-SU-2026:20753-1 (openSUSE-SU-2026:20753-1)
vulnerability in openSUSE-SU-2026:20753-1 (openSUSE-SU-2026:20753-1). Risk of unauthorized operations or information disclosure.
MINI-g782-frwr-hfcg MINI-g782-frwr-hfcg
MINI-mw6m-prxp-35m3 MINI-mw6m-prxp-35m3
MINI-jc8h-ghv9-fpw8 MINI-jc8h-ghv9-fpw8
MINI-fqrh-g4q5-767x MINI-fqrh-g4q5-767x
MINI-g5w6-7mf5-53j4 MINI-g5w6-7mf5-53j4
CVE-2026-44482 Vulnerability in CVE-2026-44482 (CVE-2026-44482)
vulnerability in CVE-2026-44482 (CVE-2026-44482). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.8` or later.
CVE-2026-44375 Vulnerability in Nerdbank.MessagePack (CVE-2026-44375)
vulnerability in Nerdbank.MessagePack (CVE-2026-44375). Risk of unauthorized operations or information disclosure. Exploitable via ``StackOverflowException``. Mitigation: upgrade to `1.1.62` or later.
CVE-2026-44374 Authorization Flaw in @backstage/plugin-catalog-unprocessed-entities-common (CVE-2026-44374)
vulnerability in @backstage/plugin-catalog-unprocessed-entities-common (CVE-2026-44374). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.15` or later.
CVE-2026-44371 Cross-Site Scripting (XSS) in CVE-2026-44371 (CVE-2026-44371)
cross-site scripting in CVE-2026-44371 (CVE-2026-44371). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.0.11` or later.
DEBIAN-CVE-2026-44216 Vulnerability in rust-wasmtime (DEBIAN-CVE-2026-44216)
vulnerability in rust-wasmtime (DEBIAN-CVE-2026-44216). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `36.0.8` or later.
CVE-2026-44308 Vulnerability in io.awspring.cloud:spring-cloud-aws-sns (CVE-2026-44308)
vulnerability in io.awspring.cloud:spring-cloud-aws-sns (CVE-2026-44308). Risk of unauthorized operations or information disclosure.
CVE-2026-44216 Vulnerability in wasmtime (CVE-2026-44216)
vulnerability in wasmtime (CVE-2026-44216). Risk of unauthorized operations or information disclosure. Exploitable via ``memory64``. Mitigation: upgrade to `43.0.2` or later.
CVE-2026-42881 Path Traversal in CVE-2026-42881 (CVE-2026-42881)
path traversal in CVE-2026-42881 (CVE-2026-42881). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.
CVE-2026-42457 Cross-Site Scripting (XSS) in CVE-2026-42457 (CVE-2026-42457)
cross-site scripting in CVE-2026-42457 (CVE-2026-42457). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.4.3` or later.
CVE-2026-42186 Vulnerability in github.com/openbao/openbao (CVE-2026-42186)
vulnerability in github.com/openbao/openbao (CVE-2026-42186). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.0-20260420173541-6d2e0506e2b4` or later.
DEBIAN-CVE-2026-24712 Vulnerability in cfengine3 (DEBIAN-CVE-2026-24712)
vulnerability in cfengine3 (DEBIAN-CVE-2026-24712). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-44216 Vulnerability in rust-wasmtime (UBUNTU-CVE-2026-44216)
vulnerability in rust-wasmtime (UBUNTU-CVE-2026-44216). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `36.0.8` or later.
MINI-wcq8-gww5-3rv3 MINI-wcq8-gww5-3rv3
MINI-f736-9qrg-gr68 MINI-f736-9qrg-gr68
MINI-m888-vqp5-9wp4 MINI-m888-vqp5-9wp4
MINI-r3c7-gm5x-r96q MINI-r3c7-gm5x-r96q
MINI-g9qm-f2hc-qh24 MINI-g9qm-f2hc-qh24
MINI-rjxq-w348-rvqr MINI-rjxq-w348-rvqr
MINI-r322-2h7p-xvc2 MINI-r322-2h7p-xvc2
MINI-64qr-mf4m-q9gx MINI-64qr-mf4m-q9gx
MINI-pv9h-8j4q-wgw8 MINI-pv9h-8j4q-wgw8
MINI-2x2j-5j56-gjjw MINI-2x2j-5j56-gjjw
MINI-hp2q-gvcj-gqgq MINI-hp2q-gvcj-gqgq

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →