Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-44447 SQL Injection in sqli (CVE-2026-44447)
SQL injection in sqli (CVE-2026-44447). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `16.9.0` or later.
CVE-2026-44446 SQL Injection in sqli (CVE-2026-44446)
SQL injection in sqli (CVE-2026-44446). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `15.104.3` or later.
CVE-2026-44445 XXE (XML External Entity) in frappe (CVE-2026-44445)
vulnerability in frappe (CVE-2026-44445). Confidential information can be exposed externally. Mitigation: upgrade to `15.104.3` or later.
CVE-2026-44442 Vulnerability in frappe (CVE-2026-44442)
vulnerability in frappe (CVE-2026-44442). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `16.9.1` or later.
CVE-2026-44441 SSRF (Server-Side Request Forgery) in frappe (CVE-2026-44441)
SSRF in frappe (CVE-2026-44441). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `15.106.0` or later.
CVE-2026-44440 Path Traversal in path-traversal (CVE-2026-44440)
path traversal in path-traversal (CVE-2026-44440). Confidential information can be exposed externally. Mitigation: upgrade to `15.101.1` or later.
CVE-2026-44439 SSRF (Server-Side Request Forgery) in PlaywrightCapture (CVE-2026-44439)
SSRF in PlaywrightCapture (CVE-2026-44439). Confidential information can be exposed externally. Mitigation: upgrade to `1.39.6` or later.
CVE-2026-44437 Path Traversal in @angular/ssr (CVE-2026-44437)
path traversal in @angular/ssr (CVE-2026-44437). Risk of unauthorized operations or information disclosure. Exploitable via ``redirectTo``. Mitigation: upgrade to `19.2.25` or later.
CVE-2026-44426 Vulnerability in github.com/shellhub-io/shellhub (CVE-2026-44426)
vulnerability in github.com/shellhub-io/shellhub (CVE-2026-44426). Confidential information can be exposed externally. Exploitable via `GET /api/namespaces/`. Mitigation: upgrade to `0.24.2` or later.
CVE-2026-44425 Vulnerability in github.com/shellhub-io/shellhub (CVE-2026-44425)
vulnerability in github.com/shellhub-io/shellhub (CVE-2026-44425). Risk of unauthorized operations or information disclosure. Exploitable via ``name``. Mitigation: upgrade to `0.24.2` or later.
CVE-2026-44424 Vulnerability in github.com/shellhub-io/shellhub (CVE-2026-44424)
vulnerability in github.com/shellhub-io/shellhub (CVE-2026-44424). Confidential information can be exposed externally. Exploitable via `GET /api/devices/`. Mitigation: upgrade to `0.24.2` or later.
CVE-2026-44423 Vulnerability in github.com/shellhub-io/shellhub (CVE-2026-44423)
vulnerability in github.com/shellhub-io/shellhub (CVE-2026-44423). Confidential information can be exposed externally. Exploitable via `GET /api/sessions/`. Mitigation: upgrade to `0.24.2` or later.
CVE-2026-44369 Vulnerability in CVE-2026-44369 (CVE-2026-44369)
vulnerability in CVE-2026-44369 (CVE-2026-44369). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.64.0` or later.
CVE-2026-44195 Vulnerability in opnsense (CVE-2026-44195)
vulnerability in opnsense (CVE-2026-44195). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.1.7` or later.
CVE-2026-44194 OS Command Injection in opnsense (CVE-2026-44194)
OS command injection in opnsense (CVE-2026-44194). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `26.1.8` or later.
CVE-2026-44193 Vulnerability in opnsense (CVE-2026-44193)
vulnerability in opnsense (CVE-2026-44193). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `26.1.7` or later.
CVE-2026-42463 Vulnerability in fit2cloud (CVE-2026-42463)
vulnerability in fit2cloud (CVE-2026-42463). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.0` or later.
CVE-2026-40328 Rejected reason: This CVE is a duplicate of another CVE.
Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-40327 Rejected reason: This CVE is a duplicate of another CVE.
Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-32993 Vulnerability in CVE-2026-32993 (CVE-2026-32993)
vulnerability in CVE-2026-32993 (CVE-2026-32993). Risk of unauthorized operations or information disclosure. Exploitable via ``status``.
CVE-2026-32992 Vulnerability in cpanel (CVE-2026-32992)
vulnerability in cpanel (CVE-2026-32992). Confidential information can be exposed externally.
CVE-2026-29205 Vulnerability in cpanel (CVE-2026-29205)
vulnerability in cpanel (CVE-2026-29205). Confidential information can be exposed externally.
UBUNTU-CVE-2026-44471 Vulnerability in rust-gix-fs (UBUNTU-CVE-2026-44471)
vulnerability in rust-gix-fs (UBUNTU-CVE-2026-44471). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.21.1` or later.
MINI-x9fc-c5p8-vw58 MINI-x9fc-c5p8-vw58
MINI-vh94-hrgj-fwcf MINI-vh94-hrgj-fwcf
MINI-9h77-3r6m-pm4x MINI-9h77-3r6m-pm4x
MINI-xr6x-v28h-8fj5 MINI-xr6x-v28h-8fj5
MINI-69gg-v7w5-385x MINI-69gg-v7w5-385x
MINI-pgj3-fqcv-94fr MINI-pgj3-fqcv-94fr
MINI-6f56-g8r5-xj8w MINI-6f56-g8r5-xj8w
MINI-phqc-4h5c-jvg5 MINI-phqc-4h5c-jvg5
MINI-hq82-j8mh-gfx6 MINI-hq82-j8mh-gfx6
MINI-9g68-wcrv-2hw2 MINI-9g68-wcrv-2hw2
MINI-984x-x66q-v4wx MINI-984x-x66q-v4wx
MINI-h488-6jc3-m9cv MINI-h488-6jc3-m9cv
MINI-fw8v-4v89-2w8r MINI-fw8v-4v89-2w8r
MINI-f8r8-m946-23p8 MINI-f8r8-m946-23p8
MINI-2fp6-mmww-742p MINI-2fp6-mmww-742p
MINI-94hm-8w4m-2p2j MINI-94hm-8w4m-2p2j
MINI-88w8-4677-8wjr MINI-88w8-4677-8wjr
MINI-542v-rph9-xw93 MINI-542v-rph9-xw93
MINI-6hx5-xc42-gg23 MINI-6hx5-xc42-gg23
MINI-567h-hx5c-f869 MINI-567h-hx5c-f869
MINI-9p7c-wqg5-h7fc MINI-9p7c-wqg5-h7fc
MINI-4h8w-gp74-xwff MINI-4h8w-gp74-xwff
MINI-w8v3-grxw-93hp MINI-w8v3-grxw-93hp
MINI-f6cj-2grp-cjf4 MINI-f6cj-2grp-cjf4
MINI-8jch-q9pj-8f96 MINI-8jch-q9pj-8f96
CVE-2026-45228 Cross-Site Scripting (XSS) in vue (CVE-2026-45228)
cross-site scripting in vue (CVE-2026-45228). Risk of unauthorized operations or information disclosure. Exploitable via `POST /update`.
CVE-2026-8328 SSRF (Server-Side Request Forgery) in libpython (CVE-2026-8328)
SSRF in libpython (CVE-2026-8328). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.5` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →