Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-9gfq-m5gj-wchj |
|
MINI-9gfq-m5gj-wchj |
| MINI-6gjw-744p-5m9w |
|
MINI-6gjw-744p-5m9w |
| MINI-gpv4-8rw4-w95x |
|
MINI-gpv4-8rw4-w95x |
| MINI-fj8c-8w53-hcjg |
|
MINI-fj8c-8w53-hcjg |
| MINI-frh2-wp3p-mqqv |
|
MINI-frh2-wp3p-mqqv |
| MINI-x43v-83vv-5j3p |
|
MINI-x43v-83vv-5j3p |
| MINI-f5pj-vj8v-x78x |
|
MINI-f5pj-vj8v-x78x |
| MINI-hm4x-rqpg-m64r |
|
MINI-hm4x-rqpg-m64r |
| MINI-hg56-58w7-g4f9 |
|
MINI-hg56-58w7-g4f9 |
| MINI-94xx-x8xj-v349 |
|
MINI-94xx-x8xj-v349 |
| MINI-96f9-wgqx-c6r3 |
|
MINI-96f9-wgqx-c6r3 |
| MINI-7m36-c7r3-79mc |
|
MINI-7m36-c7r3-79mc |
| MINI-8fw9-fc44-57p4 |
|
MINI-8fw9-fc44-57p4 |
| MINI-9rvv-9gwj-hf2f |
|
MINI-9rvv-9gwj-hf2f |
| MINI-8fv9-4h35-vq4m |
|
MINI-8fv9-4h35-vq4m |
| MINI-73wp-fq7j-cvwg |
|
MINI-73wp-fq7j-cvwg |
| MINI-7485-9ww2-j5hc |
|
MINI-7485-9ww2-j5hc |
| MINI-6v9p-5cgr-r32x |
|
MINI-6v9p-5cgr-r32x |
| MINI-9px7-35jp-fhgf |
|
MINI-9px7-35jp-fhgf |
| MINI-59r7-vhjf-rr23 |
|
MINI-59r7-vhjf-rr23 |
| MINI-rcq5-2wpp-cv2w |
|
MINI-rcq5-2wpp-cv2w |
| MAL-2026-3615 |
|
Vulnerability in ai-spellcheckers (MAL-2026-3615)
vulnerability in ai-spellcheckers (MAL-2026-3615). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44343 |
|
Vulnerability in wgdashboard (CVE-2026-44343)
vulnerability in wgdashboard (CVE-2026-44343). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.3.2` or later.
|
| DEBIAN-CVE-2026-44167 |
|
Vulnerability in php-phpseclib (DEBIAN-CVE-2026-44167)
vulnerability in php-phpseclib (DEBIAN-CVE-2026-44167). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.29` or later.
|
| CVE-2026-44204 |
|
Vulnerability in sqli (CVE-2026-44204)
vulnerability in sqli (CVE-2026-44204). Confidential information can be exposed externally. Mitigation: upgrade to `1.20.1` or later.
|
| CVE-2026-44196 |
|
Authentication Bypass in CVE-2026-44196 (CVE-2026-44196)
authentication bypass in CVE-2026-44196 (CVE-2026-44196). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.3` or later.
|
| CVE-2026-44184 |
|
Vulnerability in CVE-2026-44184 (CVE-2026-44184)
vulnerability in CVE-2026-44184 (CVE-2026-44184). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.9.10` or later.
|
| CVE-2026-44183 |
|
Vulnerability in CVE-2026-44183 (CVE-2026-44183)
vulnerability in CVE-2026-44183 (CVE-2026-44183). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.9.10` or later.
|
| CVE-2026-44166 |
|
Authentication Bypass in github.com/pocketbase/pocketbase (CVE-2026-44166)
authentication bypass in github.com/pocketbase/pocketbase (CVE-2026-44166). Data can be tampered with by attackers. Mitigation: upgrade to `0.37.4` or later.
|
| CVE-2026-43929 |
|
Vulnerability in ssrfcheck (CVE-2026-43929)
vulnerability in ssrfcheck (CVE-2026-43929). Confidential information can be exposed externally. Exploitable via ``ssrfcheck``.
|
| CVE-2026-43892 |
|
Cross-Site Scripting (XSS) in CVE-2026-43892 (CVE-2026-43892)
cross-site scripting in CVE-2026-43892 (CVE-2026-43892). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.16` or later.
|
| CVE-2026-43891 |
|
Vulnerability in changedetection.io (CVE-2026-43891)
vulnerability in changedetection.io (CVE-2026-43891). Confidential information can be exposed externally. Exploitable via ``history.txt``. Mitigation: upgrade to `0.55.1` or later.
|
| CVE-2026-42899 |
|
Vulnerability in dotnet (CVE-2026-42899)
vulnerability in dotnet (CVE-2026-42899). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.27, 9.0.16, 10.0.8` or later.
|
| DEBIAN-CVE-2026-42177 |
|
Vulnerability in linux-entra-sso (DEBIAN-CVE-2026-42177)
vulnerability in linux-entra-sso (DEBIAN-CVE-2026-42177). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.1` or later.
|
| CVE-2026-42541 |
|
Vulnerability in github.com/kubewarden/kubewarden-controller (CVE-2026-42541)
vulnerability in github.com/kubewarden/kubewarden-controller (CVE-2026-42541). Risk of unauthorized operations or information disclosure. Exploitable via ``can_i``. Mitigation: upgrade to `1.35.0` or later.
|
| CVE-2026-42348 |
|
Vulnerability in OpenTelemetry.OpAmp.Client (CVE-2026-42348)
vulnerability in OpenTelemetry.OpAmp.Client (CVE-2026-42348). Risk of unauthorized operations or information disclosure. Exploitable via ``ReadAsByteArrayAsync``. Mitigation: upgrade to `0.2.0-alpha.1` or later.
|
| CVE-2026-42303 |
|
Vulnerability in ethyca-fides (CVE-2026-42303)
vulnerability in ethyca-fides (CVE-2026-42303). Risk of unauthorized operations or information disclosure. Exploitable via ``true``. Mitigation: upgrade to `2.83.2` or later.
|
| CVE-2026-42300 |
|
Vulnerability in github.com/l3montree-dev/devguard (CVE-2026-42300)
vulnerability in github.com/l3montree-dev/devguard (CVE-2026-42300). Risk of unauthorized operations or information disclosure. Exploitable via ``SessionMiddleware``. Mitigation: upgrade to `1.2.2` or later.
|
| CVE-2026-42177 |
|
Vulnerability in CVE-2026-42177 (CVE-2026-42177)
vulnerability in CVE-2026-42177 (CVE-2026-42177). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.1` or later.
|
| CVE-2026-42175 |
|
SSRF (Server-Side Request Forgery) in requests-hardened (CVE-2026-42175)
SSRF in requests-hardened (CVE-2026-42175). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.1` or later.
|
| CVE-2026-42141 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-42141)
SSRF in ssrf (CVE-2026-42141). Confidential information can be exposed externally. Mitigation: upgrade to `4.4.1` or later.
|
| CVE-2026-42048 |
|
Path Traversal in langflow (CVE-2026-42048)
path traversal in langflow (CVE-2026-42048). Data can be tampered with by attackers. Exploitable via `DELETE /api/v1/knowledge_bases`. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2026-42045 |
|
Cross-Site Scripting (XSS) in @lobehub/lobehub (CVE-2026-42045)
cross-site scripting in @lobehub/lobehub (CVE-2026-42045). Confidential information can be exposed externally. Exploitable via ``runCommand``.
|
| CVE-2026-41613 |
|
OS Command Injection in microsoft (CVE-2026-41613)
OS command injection in microsoft (CVE-2026-41613). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41612 |
|
Path Traversal in path-traversal (CVE-2026-41612)
path traversal in path-traversal (CVE-2026-41612). Confidential information can be exposed externally.
|
| CVE-2026-41611 |
|
Command Injection in microsoft (CVE-2026-41611)
command injection in microsoft (CVE-2026-41611). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41610 |
|
Vulnerability in microsoft (CVE-2026-41610)
vulnerability in microsoft (CVE-2026-41610). Confidential information can be exposed externally.
|
| CVE-2026-41513 |
|
Open Redirect in CVE-2026-41513 (CVE-2026-41513)
vulnerability in CVE-2026-41513 (CVE-2026-41513). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41109 |
|
Vulnerability in microsoft (CVE-2026-41109)
vulnerability in microsoft (CVE-2026-41109). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35433 |
|
Vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-35433)
vulnerability in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-35433). Confidential information can be exposed externally. Mitigation: upgrade to `10.0.8` or later.
|