Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| openSUSE-SU-2026:10770-1 |
|
Vulnerability in glibc (openSUSE-SU-2026:10770-1)
vulnerability in glibc (openSUSE-SU-2026:10770-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.43-3.1` or later.
|
| openSUSE-SU-2026:10765-1 |
|
Vulnerability in amazon-ssm-agent (openSUSE-SU-2026:10765-1)
vulnerability in amazon-ssm-agent (openSUSE-SU-2026:10765-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.4268.0-2.1` or later.
|
| openSUSE-SU-2026:10766-1 |
|
Vulnerability in dovecot24 (openSUSE-SU-2026:10766-1)
vulnerability in dovecot24 (openSUSE-SU-2026:10766-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.4-1.1` or later.
|
| ALSA-2026:16875 |
|
Vulnerability in git-lfs (ALSA-2026:16875)
vulnerability in git-lfs (ALSA-2026:16875). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.1-10.el8_10` or later.
|
| ALSA-2026:16799 |
|
Vulnerability in krb5-devel (ALSA-2026:16799)
vulnerability in krb5-devel (ALSA-2026:16799). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.18.2-34.el8_10` or later.
|
| MAL-2026-3651 |
|
Vulnerability in ms-graph-types (MAL-2026-3651)
vulnerability in ms-graph-types (MAL-2026-3651). Risk of unauthorized operations or information disclosure. Exploitable via ``micresoft``.
|
| MAL-2026-3650 |
|
Vulnerability in microsoft-applicationinsights-common (MAL-2026-3650)
vulnerability in microsoft-applicationinsights-common (MAL-2026-3650). Risk of unauthorized operations or information disclosure. Exploitable via ``micresoft``.
|
| MAL-2026-3649 |
|
Vulnerability in iceberg-javascript (MAL-2026-3649)
vulnerability in iceberg-javascript (MAL-2026-3649). Risk of unauthorized operations or information disclosure. Exploitable via ``superbase``.
|
| MAL-2026-3652 |
|
Vulnerability in supabase-javascript (MAL-2026-3652)
vulnerability in supabase-javascript (MAL-2026-3652). Risk of unauthorized operations or information disclosure. Exploitable via ``superbase``.
|
| MAL-2026-3648 |
|
Vulnerability in auth-javascript (MAL-2026-3648)
vulnerability in auth-javascript (MAL-2026-3648). Risk of unauthorized operations or information disclosure. Exploitable via ``superbase``.
|
| ROOT-APP-PYPI-CVE-2023-25956 |
|
Vulnerability in rootio-apache-airflow-providers-amazon (ROOT-APP-PYPI-CVE-2023-25956)
vulnerability in rootio-apache-airflow-providers-amazon (ROOT-APP-PYPI-CVE-2023-25956). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.0+root.io.1, 4.0.0+root.io.2, 4.0.0+root.io.3` or later.
|
| BELL-CVE-2026-45130 |
|
BELL-CVE-2026-45130 |
| CVE-2026-5371 |
|
Vulnerability in wordpress (CVE-2026-5371)
vulnerability in wordpress (CVE-2026-5371). Confidential information can be exposed externally.
|
| CVE-2026-44548 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-44548 (CVE-2026-44548)
vulnerability in CVE-2026-44548 (CVE-2026-44548). Data can be tampered with by attackers. Mitigation: upgrade to `7.3.2` or later.
|
| CVE-2026-44547 |
|
Authentication Bypass in CVE-2026-44547 (CVE-2026-44547)
authentication bypass in CVE-2026-44547 (CVE-2026-44547). Confidential information can be exposed externally. Mitigation: upgrade to `7.3.1` or later.
|
| CVE-2026-44352 |
|
Vulnerability in CVE-2026-44352 (CVE-2026-44352)
vulnerability in CVE-2026-44352 (CVE-2026-44352). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.3` or later.
|
| CVE-2026-44347 |
|
Cross-Site Request Forgery (CSRF) in warpgate-project (CVE-2026-44347)
vulnerability in warpgate-project (CVE-2026-44347). Data can be tampered with by attackers. Mitigation: upgrade to `0.23.3` or later.
|
| CVE-2026-44341 |
|
Vulnerability in CVE-2026-44341 (CVE-2026-44341)
vulnerability in CVE-2026-44341 (CVE-2026-44341). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44245 |
|
Cross-Site Scripting (XSS) in github.com/kyverno/policy-reporter-ui (CVE-2026-44245)
cross-site scripting in github.com/kyverno/policy-reporter-ui (CVE-2026-44245). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.2+incompatible` or later.
|
| CVE-2026-43685 |
|
OS Command Injection in claris (CVE-2026-43685)
OS command injection in claris (CVE-2026-43685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43680 |
|
Code Injection in claris (CVE-2026-43680)
code injection in claris (CVE-2026-43680). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42289 |
|
Privilege Escalation in csrf (CVE-2026-42289)
vulnerability in csrf (CVE-2026-42289). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.3.2` or later.
|
| CVE-2026-42288 |
|
Code Injection in CVE-2026-42288 (CVE-2026-42288)
code injection in CVE-2026-42288 (CVE-2026-42288). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.3.2` or later.
|
| CVE-2026-42158 |
|
Vulnerability in CVE-2026-42158 (CVE-2026-42158)
vulnerability in CVE-2026-42158 (CVE-2026-42158). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.3` or later.
|
| CVE-2026-42157 |
|
Cross-Site Scripting (XSS) in CVE-2026-42157 (CVE-2026-42157)
cross-site scripting in CVE-2026-42157 (CVE-2026-42157). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.3` or later.
|
| CVE-2026-42156 |
|
Vulnerability in CVE-2026-42156 (CVE-2026-42156)
vulnerability in CVE-2026-42156 (CVE-2026-42156). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.3` or later.
|
| CVE-2026-41901 |
|
Vulnerability in org.thymeleaf:thymeleaf (CVE-2026-41901)
vulnerability in org.thymeleaf:thymeleaf (CVE-2026-41901). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.5.RELEASE` or later.
|
| CVE-2026-1250 |
|
SQL Injection in wordpress (CVE-2026-1250)
SQL injection in wordpress (CVE-2026-1250). Confidential information can be exposed externally.
|
| CVE-2025-15463 |
|
Code Injection in wordpress (CVE-2025-15463)
code injection in wordpress (CVE-2025-15463). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44660 |
|
Vulnerability in ujson (CVE-2026-44660)
vulnerability in ujson (CVE-2026-44660). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.12.1` or later.
|
| CVE-2026-44652 |
|
SSRF (Server-Side Request Forgery) in sillytavern (CVE-2026-44652)
SSRF in sillytavern (CVE-2026-44652). Risk of unauthorized operations or information disclosure. Exploitable via `GET /proxy/`. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-44651 |
|
Cross-Site Scripting (XSS) in sillytavern (CVE-2026-44651)
cross-site scripting in sillytavern (CVE-2026-44651). Risk of unauthorized operations or information disclosure. Exploitable via `GET /proxy/`. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-44650 |
|
Path Traversal in sillytavern (CVE-2026-44650)
path traversal in sillytavern (CVE-2026-44650). Data can be tampered with by attackers. Exploitable via `POST /api/extensions/delete`. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-44649 |
|
Vulnerability in sillytavern (CVE-2026-44649)
vulnerability in sillytavern (CVE-2026-44649). Successful exploitation can lead to full system takeover. Exploitable via ``config.yaml``. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-44648 |
|
Vulnerability in sillytavern (CVE-2026-44648)
vulnerability in sillytavern (CVE-2026-44648). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/users/change-password`. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-44594 |
|
Path Traversal in github.com/esm-dev/esm.sh (CVE-2026-44594)
path traversal in github.com/esm-dev/esm.sh (CVE-2026-44594). Confidential information can be exposed externally. Exploitable via ``browser``. Mitigation: upgrade to `0.0.0-20250616164159-0593516c4cfa` or later.
|
| CVE-2026-44593 |
|
Path Traversal in github.com/esm-dev/esm.sh (CVE-2026-44593)
path traversal in github.com/esm-dev/esm.sh (CVE-2026-44593). Risk of unauthorized operations or information disclosure. Exploitable via ``legacyServer``. Mitigation: upgrade to `0.0.0-20260508100112-1960055e1d53` or later.
|
| CVE-2026-8449 |
|
Out-of-Bounds Read in privilege-escalation (CVE-2026-8449)
vulnerability in privilege-escalation (CVE-2026-8449). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45227 |
|
Vulnerability in CVE-2026-45227 (CVE-2026-45227)
vulnerability in CVE-2026-45227 (CVE-2026-45227). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45226 |
|
Authorization Flaw in CVE-2026-45226 (CVE-2026-45226)
vulnerability in CVE-2026-45226 (CVE-2026-45226). Confidential information can be exposed externally.
|
| CVE-2026-45225 |
|
Path Traversal in path-traversal (CVE-2026-45225)
path traversal in path-traversal (CVE-2026-45225). Data can be tampered with by attackers.
|
| CVE-2026-44871 |
|
Command Injection in arubanetworks (CVE-2026-44871)
command injection in arubanetworks (CVE-2026-44871). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44307 |
|
Path Traversal in Mako (CVE-2026-44307)
path traversal in Mako (CVE-2026-44307). Risk of unauthorized operations or information disclosure. Exploitable via ``Template.__init__``. Mitigation: upgrade to `1.3.12` or later.
|
| CVE-2026-44306 |
|
Vulnerability in statamic/cms (CVE-2026-44306)
vulnerability in statamic/cms (CVE-2026-44306). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.73.21` or later.
|
| CVE-2026-44305 |
|
Vulnerability in lemur (CVE-2026-44305)
vulnerability in lemur (CVE-2026-44305). Confidential information can be exposed externally. Exploitable via ``ldap``. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2026-44304 |
|
Vulnerability in lemur (CVE-2026-44304)
vulnerability in lemur (CVE-2026-44304). Confidential information can be exposed externally. Exploitable via `POST /auth/login`. Mitigation: upgrade to `1.9.0` or later.
|
| DEBIAN-CVE-2026-44296 |
|
Vulnerability in deskflow (DEBIAN-CVE-2026-44296)
vulnerability in deskflow (DEBIAN-CVE-2026-44296). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.26.0.167` or later.
|
| DEBIAN-CVE-2026-44301 |
|
Vulnerability in hugo (DEBIAN-CVE-2026-44301)
vulnerability in hugo (DEBIAN-CVE-2026-44301). Confidential information can be exposed externally. Mitigation: upgrade to `0.161.0` or later.
|
| CVE-2026-44302 |
|
Vulnerability in Snappier (CVE-2026-44302)
vulnerability in Snappier (CVE-2026-44302). Risk of unauthorized operations or information disclosure. Exploitable via ``Snappier.SnappyStream``. Mitigation: upgrade to `1.3.1` or later.
|
| CVE-2026-44301 |
|
Path Traversal in github.com/gohugoio/hugo (CVE-2026-44301)
path traversal in github.com/gohugoio/hugo (CVE-2026-44301). Confidential information can be exposed externally. Mitigation: upgrade to `0.161.0` or later.
|