Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MINI-9gfq-m5gj-wchj MINI-9gfq-m5gj-wchj
MINI-6gjw-744p-5m9w MINI-6gjw-744p-5m9w
MINI-gpv4-8rw4-w95x MINI-gpv4-8rw4-w95x
MINI-fj8c-8w53-hcjg MINI-fj8c-8w53-hcjg
MINI-frh2-wp3p-mqqv MINI-frh2-wp3p-mqqv
MINI-x43v-83vv-5j3p MINI-x43v-83vv-5j3p
MINI-f5pj-vj8v-x78x MINI-f5pj-vj8v-x78x
MINI-hm4x-rqpg-m64r MINI-hm4x-rqpg-m64r
MINI-hg56-58w7-g4f9 MINI-hg56-58w7-g4f9
MINI-94xx-x8xj-v349 MINI-94xx-x8xj-v349
MINI-96f9-wgqx-c6r3 MINI-96f9-wgqx-c6r3
MINI-7m36-c7r3-79mc MINI-7m36-c7r3-79mc
MINI-8fw9-fc44-57p4 MINI-8fw9-fc44-57p4
MINI-9rvv-9gwj-hf2f MINI-9rvv-9gwj-hf2f
MINI-8fv9-4h35-vq4m MINI-8fv9-4h35-vq4m
MINI-73wp-fq7j-cvwg MINI-73wp-fq7j-cvwg
MINI-7485-9ww2-j5hc MINI-7485-9ww2-j5hc
MINI-6v9p-5cgr-r32x MINI-6v9p-5cgr-r32x
MINI-9px7-35jp-fhgf MINI-9px7-35jp-fhgf
MINI-59r7-vhjf-rr23 MINI-59r7-vhjf-rr23
MINI-rcq5-2wpp-cv2w MINI-rcq5-2wpp-cv2w
MAL-2026-3615 Vulnerability in ai-spellcheckers (MAL-2026-3615)
vulnerability in ai-spellcheckers (MAL-2026-3615). Risk of unauthorized operations or information disclosure.
CVE-2026-44343 Vulnerability in wgdashboard (CVE-2026-44343)
vulnerability in wgdashboard (CVE-2026-44343). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.3.2` or later.
DEBIAN-CVE-2026-44167 Vulnerability in php-phpseclib (DEBIAN-CVE-2026-44167)
vulnerability in php-phpseclib (DEBIAN-CVE-2026-44167). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.29` or later.
CVE-2026-44204 Vulnerability in sqli (CVE-2026-44204)
vulnerability in sqli (CVE-2026-44204). Confidential information can be exposed externally. Mitigation: upgrade to `1.20.1` or later.
CVE-2026-44196 Authentication Bypass in CVE-2026-44196 (CVE-2026-44196)
authentication bypass in CVE-2026-44196 (CVE-2026-44196). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.3` or later.
CVE-2026-44184 Vulnerability in CVE-2026-44184 (CVE-2026-44184)
vulnerability in CVE-2026-44184 (CVE-2026-44184). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.9.10` or later.
CVE-2026-44183 Vulnerability in CVE-2026-44183 (CVE-2026-44183)
vulnerability in CVE-2026-44183 (CVE-2026-44183). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.9.10` or later.
CVE-2026-44166 Authentication Bypass in github.com/pocketbase/pocketbase (CVE-2026-44166)
authentication bypass in github.com/pocketbase/pocketbase (CVE-2026-44166). Data can be tampered with by attackers. Mitigation: upgrade to `0.37.4` or later.
CVE-2026-43929 Vulnerability in ssrfcheck (CVE-2026-43929)
vulnerability in ssrfcheck (CVE-2026-43929). Confidential information can be exposed externally. Exploitable via ``ssrfcheck``.
CVE-2026-43892 Cross-Site Scripting (XSS) in CVE-2026-43892 (CVE-2026-43892)
cross-site scripting in CVE-2026-43892 (CVE-2026-43892). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.16` or later.
CVE-2026-43891 Vulnerability in changedetection.io (CVE-2026-43891)
vulnerability in changedetection.io (CVE-2026-43891). Confidential information can be exposed externally. Exploitable via ``history.txt``. Mitigation: upgrade to `0.55.1` or later.
CVE-2026-42899 Vulnerability in dotnet (CVE-2026-42899)
vulnerability in dotnet (CVE-2026-42899). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.27, 9.0.16, 10.0.8` or later.
DEBIAN-CVE-2026-42177 Vulnerability in linux-entra-sso (DEBIAN-CVE-2026-42177)
vulnerability in linux-entra-sso (DEBIAN-CVE-2026-42177). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.1` or later.
CVE-2026-42541 Vulnerability in github.com/kubewarden/kubewarden-controller (CVE-2026-42541)
vulnerability in github.com/kubewarden/kubewarden-controller (CVE-2026-42541). Risk of unauthorized operations or information disclosure. Exploitable via ``can_i``. Mitigation: upgrade to `1.35.0` or later.
CVE-2026-42348 Vulnerability in OpenTelemetry.OpAmp.Client (CVE-2026-42348)
vulnerability in OpenTelemetry.OpAmp.Client (CVE-2026-42348). Risk of unauthorized operations or information disclosure. Exploitable via ``ReadAsByteArrayAsync``. Mitigation: upgrade to `0.2.0-alpha.1` or later.
CVE-2026-42303 Vulnerability in ethyca-fides (CVE-2026-42303)
vulnerability in ethyca-fides (CVE-2026-42303). Risk of unauthorized operations or information disclosure. Exploitable via ``true``. Mitigation: upgrade to `2.83.2` or later.
CVE-2026-42300 Vulnerability in github.com/l3montree-dev/devguard (CVE-2026-42300)
vulnerability in github.com/l3montree-dev/devguard (CVE-2026-42300). Risk of unauthorized operations or information disclosure. Exploitable via ``SessionMiddleware``. Mitigation: upgrade to `1.2.2` or later.
CVE-2026-42177 Vulnerability in CVE-2026-42177 (CVE-2026-42177)
vulnerability in CVE-2026-42177 (CVE-2026-42177). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.1` or later.
CVE-2026-42175 SSRF (Server-Side Request Forgery) in requests-hardened (CVE-2026-42175)
SSRF in requests-hardened (CVE-2026-42175). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.1` or later.
CVE-2026-42141 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-42141)
SSRF in ssrf (CVE-2026-42141). Confidential information can be exposed externally. Mitigation: upgrade to `4.4.1` or later.
CVE-2026-42048 Path Traversal in langflow (CVE-2026-42048)
path traversal in langflow (CVE-2026-42048). Data can be tampered with by attackers. Exploitable via `DELETE /api/v1/knowledge_bases`. Mitigation: upgrade to `1.9.0` or later.
CVE-2026-42045 Cross-Site Scripting (XSS) in @lobehub/lobehub (CVE-2026-42045)
cross-site scripting in @lobehub/lobehub (CVE-2026-42045). Confidential information can be exposed externally. Exploitable via ``runCommand``.
CVE-2026-41613 OS Command Injection in microsoft (CVE-2026-41613)
OS command injection in microsoft (CVE-2026-41613). Successful exploitation can lead to full system takeover.
CVE-2026-41612 Path Traversal in path-traversal (CVE-2026-41612)
path traversal in path-traversal (CVE-2026-41612). Confidential information can be exposed externally.
CVE-2026-41611 Command Injection in microsoft (CVE-2026-41611)
command injection in microsoft (CVE-2026-41611). Successful exploitation can lead to full system takeover.
CVE-2026-41610 Vulnerability in microsoft (CVE-2026-41610)
vulnerability in microsoft (CVE-2026-41610). Confidential information can be exposed externally.
CVE-2026-41513 Open Redirect in CVE-2026-41513 (CVE-2026-41513)
vulnerability in CVE-2026-41513 (CVE-2026-41513). Risk of unauthorized operations or information disclosure.
CVE-2026-41109 Vulnerability in microsoft (CVE-2026-41109)
vulnerability in microsoft (CVE-2026-41109). Successful exploitation can lead to full system takeover.
CVE-2026-35433 Vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-35433)
vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-35433). Confidential information can be exposed externally. Mitigation: upgrade to `10.0.8` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →