Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-2p68-vhm4-8pcg |
|
MINI-2p68-vhm4-8pcg |
| MINI-8v9g-g6jg-qwf7 |
|
MINI-8v9g-g6jg-qwf7 |
| MINI-7gf2-38jv-fq3w |
|
MINI-7gf2-38jv-fq3w |
| MINI-27pg-c34w-ph63 |
|
MINI-27pg-c34w-ph63 |
| MINI-qcm2-r5qc-cm2v |
|
MINI-qcm2-r5qc-cm2v |
| MINI-r86c-6r24-5jpr |
|
MINI-r86c-6r24-5jpr |
| MINI-xvwc-c6gq-6p73 |
|
MINI-xvwc-c6gq-6p73 |
| MINI-r3jj-9rr2-77wv |
|
MINI-r3jj-9rr2-77wv |
| MINI-3q3m-f8vh-fcc8 |
|
MINI-3q3m-f8vh-fcc8 |
| MINI-r6qh-c4px-w4x6 |
|
MINI-r6qh-c4px-w4x6 |
| MINI-rr29-98m4-63r4 |
|
MINI-rr29-98m4-63r4 |
| MINI-882j-m4hh-wh75 |
|
MINI-882j-m4hh-wh75 |
| MINI-9262-f6w4-qw2c |
|
MINI-9262-f6w4-qw2c |
| CVE-2026-42073 |
|
Cross-Site Request Forgery (CSRF) in @gitlawb/openclaude (CVE-2026-42073)
vulnerability in @gitlawb/openclaude (CVE-2026-42073). Risk of unauthorized operations or information disclosure. Exploitable via ``error``. Mitigation: upgrade to `0.5.1` or later.
|
| MINI-8rvf-5pc5-x5pj |
|
MINI-8rvf-5pc5-x5pj |
| ROOT-APP-PYPI-CVE-2025-69277 |
|
Vulnerability in rootio-PyNaCl (ROOT-APP-PYPI-CVE-2025-69277)
vulnerability in rootio-PyNaCl (ROOT-APP-PYPI-CVE-2025-69277). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.0+root.io.1, 1.5.0+root.io.2, 1.5.0+root.io.3, 1.5.0+root.io.4` or later.
|
| MINI-2945-rqgx-7j7m |
|
MINI-2945-rqgx-7j7m |
| MINI-825m-prhp-vm83 |
|
MINI-825m-prhp-vm83 |
| MINI-2m37-c3m5-69h9 |
|
MINI-2m37-c3m5-69h9 |
| MINI-23f8-g2rh-6hx2 |
|
MINI-23f8-g2rh-6hx2 |
| MINI-79r2-9ggm-q4j6 |
|
MINI-79r2-9ggm-q4j6 |
| MINI-8c78-7m57-j7hx |
|
MINI-8c78-7m57-j7hx |
| CLSA-2026-1778599722 |
|
Vulnerability in libcap-dev (CLSA-2026-1778599722)
vulnerability in libcap-dev (CLSA-2026-1778599722). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:2.25-1.2+tuxcare.els2` or later.
|
| CLSA-2026-1778599539 |
|
Vulnerability in libcap-dev (CLSA-2026-1778599539)
vulnerability in libcap-dev (CLSA-2026-1778599539). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:2.24-12+tuxcare.els2` or later.
|
| CVE-2026-8108 |
|
Vulnerability in cisa (CVE-2026-8108)
vulnerability in cisa (CVE-2026-8108). Successful exploitation can lead to full system takeover.
|
| CVE-2025-2595 |
|
Vulnerability in cisa (CVE-2025-2595)
vulnerability in cisa (CVE-2025-2595). Risk of unauthorized operations or information disclosure.
|
| USN-8269-1 |
|
Vulnerability in avahi (USN-8269-1)
vulnerability in avahi (USN-8269-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.31-4ubuntu1.3+esm5` or later.
|
| DEBIAN-CVE-2026-8401 |
|
Vulnerability in firefox-esr (DEBIAN-CVE-2026-8401)
vulnerability in firefox-esr (DEBIAN-CVE-2026-8401). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `140.11.0esr-1~deb11u1` or later.
|
| CVE-2026-8401 |
|
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3.
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3.
|
| DEBIAN-CVE-2026-8368 |
|
Vulnerability in libwww-perl (DEBIAN-CVE-2026-8368)
vulnerability in libwww-perl (DEBIAN-CVE-2026-8368). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `6.83-1` or later.
|
| CVE-2026-8368 |
|
Vulnerability in CVE-2026-8368 (CVE-2026-8368)
vulnerability in CVE-2026-8368 (CVE-2026-8368). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-8111 |
|
SQL Injection in sqli (CVE-2026-8111)
SQL injection in sqli (CVE-2026-8111). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8110 |
|
Vulnerability in ivanti (CVE-2026-8110)
vulnerability in ivanti (CVE-2026-8110). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8109 |
|
Vulnerability in ivanti (CVE-2026-8109)
vulnerability in ivanti (CVE-2026-8109). Confidential information can be exposed externally.
|
| CVE-2026-8051 |
|
OS Command Injection in ivanti (CVE-2026-8051)
OS command injection in ivanti (CVE-2026-8051). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8043 |
|
Vulnerability in ivanti (CVE-2026-8043)
vulnerability in ivanti (CVE-2026-8043). Confidential information can be exposed externally.
|
| CVE-2026-7432 |
|
Vulnerability in ivanti (CVE-2026-7432)
vulnerability in ivanti (CVE-2026-7432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7431 |
|
Vulnerability in ivanti (CVE-2026-7431)
vulnerability in ivanti (CVE-2026-7431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6866 |
|
Vulnerability in schneider-electric (CVE-2026-6866)
vulnerability in schneider-electric (CVE-2026-6866). Confidential information can be exposed externally.
|
| CVE-2026-5061 |
|
Vulnerability in consul (CVE-2026-5061)
vulnerability in consul (CVE-2026-5061). Confidential information can be exposed externally. Mitigation: upgrade to `0.42.0` or later.
|
| CVE-2026-43983 |
|
Vulnerability in github.com/pocket-id/pocket-id/backend (CVE-2026-43983)
vulnerability in github.com/pocket-id/pocket-id/backend (CVE-2026-43983). Confidential information can be exposed externally. Exploitable via ``createTokenFromRefreshToken``. Mitigation: upgrade to `0.0.0-20260419162744-978ac87deffe` or later.
|
| CVE-2026-43939 |
|
Vulnerability in YAFNET.Core (CVE-2026-43939)
vulnerability in YAFNET.Core (CVE-2026-43939). Confidential information can be exposed externally. Exploitable via ``onerror``. Mitigation: upgrade to `3.2.12` or later.
|
| CVE-2026-43938 |
|
Vulnerability in YAFNET.Core (CVE-2026-43938)
vulnerability in YAFNET.Core (CVE-2026-43938). Confidential information can be exposed externally. Exploitable via `GET /api/Attachments/GetAttachment`. Mitigation: upgrade to `3.2.12` or later.
|
| CVE-2026-43937 |
|
Vulnerability in YAFNET.Core (CVE-2026-43937)
vulnerability in YAFNET.Core (CVE-2026-43937). Successful exploitation can lead to full system takeover. Exploitable via ``PageSecurityCheckAttribute``. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-42260 |
|
SSRF (Server-Side Request Forgery) in open-websearch (CVE-2026-42260)
SSRF in open-websearch (CVE-2026-42260). Confidential information can be exposed externally. Exploitable via `GET /internal`. Mitigation: upgrade to `2.1.7` or later.
|
| CVE-2026-32687 |
|
SQL Injection in postgrex (CVE-2026-32687)
SQL injection in postgrex (CVE-2026-32687). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.22.2` or later.
|
| CVE-2025-70842 |
|
Cross-Site Scripting (XSS) in CVE-2025-70842 (CVE-2025-70842)
cross-site scripting in CVE-2025-70842 (CVE-2025-70842). Risk of unauthorized operations or information disclosure.
|
| openSUSE-SU-2026:20743-1 |
|
Vulnerability in openSUSE-SU-2026:20743-1 (openSUSE-SU-2026:20743-1)
vulnerability in openSUSE-SU-2026:20743-1 (openSUSE-SU-2026:20743-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45091 |
|
Information Disclosure in sealed-env (CVE-2026-45091)
vulnerability in sealed-env (CVE-2026-45091). Confidential information can be exposed externally. Mitigation: upgrade to `0.1.0-alpha.4` or later.
|
| CVE-2026-45090 |
|
Vulnerability in github.com/hahwul/dalfox/v2 (CVE-2026-45090)
vulnerability in github.com/hahwul/dalfox/v2 (CVE-2026-45090). Risk of unauthorized operations or information disclosure. Exploitable via ``ParameterAnalysis``. Mitigation: upgrade to `2.13.0` or later.
|