Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
openSUSE-SU-2026:10770-1 Vulnerability in glibc (openSUSE-SU-2026:10770-1)
vulnerability in glibc (openSUSE-SU-2026:10770-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.43-3.1` or later.
openSUSE-SU-2026:10765-1 Vulnerability in amazon-ssm-agent (openSUSE-SU-2026:10765-1)
vulnerability in amazon-ssm-agent (openSUSE-SU-2026:10765-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.4268.0-2.1` or later.
openSUSE-SU-2026:10766-1 Vulnerability in dovecot24 (openSUSE-SU-2026:10766-1)
vulnerability in dovecot24 (openSUSE-SU-2026:10766-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.4-1.1` or later.
ALSA-2026:16875 Vulnerability in git-lfs (ALSA-2026:16875)
vulnerability in git-lfs (ALSA-2026:16875). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.1-10.el8_10` or later.
ALSA-2026:16799 Vulnerability in krb5-devel (ALSA-2026:16799)
vulnerability in krb5-devel (ALSA-2026:16799). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.18.2-34.el8_10` or later.
MAL-2026-3651 Vulnerability in ms-graph-types (MAL-2026-3651)
vulnerability in ms-graph-types (MAL-2026-3651). Risk of unauthorized operations or information disclosure. Exploitable via ``micresoft``.
MAL-2026-3650 Vulnerability in microsoft-applicationinsights-common (MAL-2026-3650)
vulnerability in microsoft-applicationinsights-common (MAL-2026-3650). Risk of unauthorized operations or information disclosure. Exploitable via ``micresoft``.
MAL-2026-3649 Vulnerability in iceberg-javascript (MAL-2026-3649)
vulnerability in iceberg-javascript (MAL-2026-3649). Risk of unauthorized operations or information disclosure. Exploitable via ``superbase``.
MAL-2026-3652 Vulnerability in supabase-javascript (MAL-2026-3652)
vulnerability in supabase-javascript (MAL-2026-3652). Risk of unauthorized operations or information disclosure. Exploitable via ``superbase``.
MAL-2026-3648 Vulnerability in auth-javascript (MAL-2026-3648)
vulnerability in auth-javascript (MAL-2026-3648). Risk of unauthorized operations or information disclosure. Exploitable via ``superbase``.
ROOT-APP-PYPI-CVE-2023-25956 Vulnerability in rootio-apache-airflow-providers-amazon (ROOT-APP-PYPI-CVE-2023-25956)
vulnerability in rootio-apache-airflow-providers-amazon (ROOT-APP-PYPI-CVE-2023-25956). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.0+root.io.1, 4.0.0+root.io.2, 4.0.0+root.io.3` or later.
BELL-CVE-2026-45130 BELL-CVE-2026-45130
CVE-2026-5371 Vulnerability in wordpress (CVE-2026-5371)
vulnerability in wordpress (CVE-2026-5371). Confidential information can be exposed externally.
CVE-2026-44548 Cross-Site Request Forgery (CSRF) in CVE-2026-44548 (CVE-2026-44548)
vulnerability in CVE-2026-44548 (CVE-2026-44548). Data can be tampered with by attackers. Mitigation: upgrade to `7.3.2` or later.
CVE-2026-44547 Authentication Bypass in CVE-2026-44547 (CVE-2026-44547)
authentication bypass in CVE-2026-44547 (CVE-2026-44547). Confidential information can be exposed externally. Mitigation: upgrade to `7.3.1` or later.
CVE-2026-44352 Vulnerability in CVE-2026-44352 (CVE-2026-44352)
vulnerability in CVE-2026-44352 (CVE-2026-44352). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.3` or later.
CVE-2026-44347 Cross-Site Request Forgery (CSRF) in warpgate-project (CVE-2026-44347)
vulnerability in warpgate-project (CVE-2026-44347). Data can be tampered with by attackers. Mitigation: upgrade to `0.23.3` or later.
CVE-2026-44341 Vulnerability in CVE-2026-44341 (CVE-2026-44341)
vulnerability in CVE-2026-44341 (CVE-2026-44341). Risk of unauthorized operations or information disclosure.
CVE-2026-44245 Cross-Site Scripting (XSS) in github.com/kyverno/policy-reporter-ui (CVE-2026-44245)
cross-site scripting in github.com/kyverno/policy-reporter-ui (CVE-2026-44245). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.2+incompatible` or later.
CVE-2026-43685 OS Command Injection in claris (CVE-2026-43685)
OS command injection in claris (CVE-2026-43685). Successful exploitation can lead to full system takeover.
CVE-2026-43680 Code Injection in claris (CVE-2026-43680)
code injection in claris (CVE-2026-43680). Successful exploitation can lead to full system takeover.
CVE-2026-42289 Privilege Escalation in csrf (CVE-2026-42289)
vulnerability in csrf (CVE-2026-42289). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.3.2` or later.
CVE-2026-42288 Code Injection in CVE-2026-42288 (CVE-2026-42288)
code injection in CVE-2026-42288 (CVE-2026-42288). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.3.2` or later.
CVE-2026-42158 Vulnerability in CVE-2026-42158 (CVE-2026-42158)
vulnerability in CVE-2026-42158 (CVE-2026-42158). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.3` or later.
CVE-2026-42157 Cross-Site Scripting (XSS) in CVE-2026-42157 (CVE-2026-42157)
cross-site scripting in CVE-2026-42157 (CVE-2026-42157). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.3` or later.
CVE-2026-42156 Vulnerability in CVE-2026-42156 (CVE-2026-42156)
vulnerability in CVE-2026-42156 (CVE-2026-42156). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.3` or later.
CVE-2026-41901 Vulnerability in org.thymeleaf:thymeleaf (CVE-2026-41901)
vulnerability in org.thymeleaf:thymeleaf (CVE-2026-41901). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.5.RELEASE` or later.
CVE-2026-1250 SQL Injection in wordpress (CVE-2026-1250)
SQL injection in wordpress (CVE-2026-1250). Confidential information can be exposed externally.
CVE-2025-15463 Code Injection in wordpress (CVE-2025-15463)
code injection in wordpress (CVE-2025-15463). Risk of unauthorized operations or information disclosure.
CVE-2026-44660 Vulnerability in ujson (CVE-2026-44660)
vulnerability in ujson (CVE-2026-44660). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.12.1` or later.
CVE-2026-44652 SSRF (Server-Side Request Forgery) in sillytavern (CVE-2026-44652)
SSRF in sillytavern (CVE-2026-44652). Risk of unauthorized operations or information disclosure. Exploitable via `GET /proxy/`. Mitigation: upgrade to `1.18.0` or later.
CVE-2026-44651 Cross-Site Scripting (XSS) in sillytavern (CVE-2026-44651)
cross-site scripting in sillytavern (CVE-2026-44651). Risk of unauthorized operations or information disclosure. Exploitable via `GET /proxy/`. Mitigation: upgrade to `1.18.0` or later.
CVE-2026-44650 Path Traversal in sillytavern (CVE-2026-44650)
path traversal in sillytavern (CVE-2026-44650). Data can be tampered with by attackers. Exploitable via `POST /api/extensions/delete`. Mitigation: upgrade to `1.18.0` or later.
CVE-2026-44649 Vulnerability in sillytavern (CVE-2026-44649)
vulnerability in sillytavern (CVE-2026-44649). Successful exploitation can lead to full system takeover. Exploitable via ``config.yaml``. Mitigation: upgrade to `1.18.0` or later.
CVE-2026-44648 Vulnerability in sillytavern (CVE-2026-44648)
vulnerability in sillytavern (CVE-2026-44648). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/users/change-password`. Mitigation: upgrade to `1.18.0` or later.
CVE-2026-44594 Path Traversal in github.com/esm-dev/esm.sh (CVE-2026-44594)
path traversal in github.com/esm-dev/esm.sh (CVE-2026-44594). Confidential information can be exposed externally. Exploitable via ``browser``. Mitigation: upgrade to `0.0.0-20250616164159-0593516c4cfa` or later.
CVE-2026-44593 Path Traversal in github.com/esm-dev/esm.sh (CVE-2026-44593)
path traversal in github.com/esm-dev/esm.sh (CVE-2026-44593). Risk of unauthorized operations or information disclosure. Exploitable via ``legacyServer``. Mitigation: upgrade to `0.0.0-20260508100112-1960055e1d53` or later.
CVE-2026-8449 Out-of-Bounds Read in privilege-escalation (CVE-2026-8449)
vulnerability in privilege-escalation (CVE-2026-8449). Successful exploitation can lead to full system takeover.
CVE-2026-45227 Vulnerability in CVE-2026-45227 (CVE-2026-45227)
vulnerability in CVE-2026-45227 (CVE-2026-45227). Successful exploitation can lead to full system takeover.
CVE-2026-45226 Authorization Flaw in CVE-2026-45226 (CVE-2026-45226)
vulnerability in CVE-2026-45226 (CVE-2026-45226). Confidential information can be exposed externally.
CVE-2026-45225 Path Traversal in path-traversal (CVE-2026-45225)
path traversal in path-traversal (CVE-2026-45225). Data can be tampered with by attackers.
CVE-2026-44871 Command Injection in arubanetworks (CVE-2026-44871)
command injection in arubanetworks (CVE-2026-44871). Successful exploitation can lead to full system takeover.
CVE-2026-44307 Path Traversal in Mako (CVE-2026-44307)
path traversal in Mako (CVE-2026-44307). Risk of unauthorized operations or information disclosure. Exploitable via ``Template.__init__``. Mitigation: upgrade to `1.3.12` or later.
CVE-2026-44306 Vulnerability in statamic/cms (CVE-2026-44306)
vulnerability in statamic/cms (CVE-2026-44306). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.73.21` or later.
CVE-2026-44305 Vulnerability in lemur (CVE-2026-44305)
vulnerability in lemur (CVE-2026-44305). Confidential information can be exposed externally. Exploitable via ``ldap``. Mitigation: upgrade to `1.9.0` or later.
CVE-2026-44304 Vulnerability in lemur (CVE-2026-44304)
vulnerability in lemur (CVE-2026-44304). Confidential information can be exposed externally. Exploitable via `POST /auth/login`. Mitigation: upgrade to `1.9.0` or later.
DEBIAN-CVE-2026-44296 Vulnerability in deskflow (DEBIAN-CVE-2026-44296)
vulnerability in deskflow (DEBIAN-CVE-2026-44296). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.26.0.167` or later.
DEBIAN-CVE-2026-44301 Vulnerability in hugo (DEBIAN-CVE-2026-44301)
vulnerability in hugo (DEBIAN-CVE-2026-44301). Confidential information can be exposed externally. Mitigation: upgrade to `0.161.0` or later.
CVE-2026-44302 Vulnerability in Snappier (CVE-2026-44302)
vulnerability in Snappier (CVE-2026-44302). Risk of unauthorized operations or information disclosure. Exploitable via ``Snappier.SnappyStream``. Mitigation: upgrade to `1.3.1` or later.
CVE-2026-44301 Path Traversal in github.com/gohugoio/hugo (CVE-2026-44301)
path traversal in github.com/gohugoio/hugo (CVE-2026-44301). Confidential information can be exposed externally. Mitigation: upgrade to `0.161.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →