Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MINI-2p68-vhm4-8pcg MINI-2p68-vhm4-8pcg
MINI-8v9g-g6jg-qwf7 MINI-8v9g-g6jg-qwf7
MINI-7gf2-38jv-fq3w MINI-7gf2-38jv-fq3w
MINI-27pg-c34w-ph63 MINI-27pg-c34w-ph63
MINI-qcm2-r5qc-cm2v MINI-qcm2-r5qc-cm2v
MINI-r86c-6r24-5jpr MINI-r86c-6r24-5jpr
MINI-xvwc-c6gq-6p73 MINI-xvwc-c6gq-6p73
MINI-r3jj-9rr2-77wv MINI-r3jj-9rr2-77wv
MINI-3q3m-f8vh-fcc8 MINI-3q3m-f8vh-fcc8
MINI-r6qh-c4px-w4x6 MINI-r6qh-c4px-w4x6
MINI-rr29-98m4-63r4 MINI-rr29-98m4-63r4
MINI-882j-m4hh-wh75 MINI-882j-m4hh-wh75
MINI-9262-f6w4-qw2c MINI-9262-f6w4-qw2c
CVE-2026-42073 Cross-Site Request Forgery (CSRF) in @gitlawb/openclaude (CVE-2026-42073)
vulnerability in @gitlawb/openclaude (CVE-2026-42073). Risk of unauthorized operations or information disclosure. Exploitable via ``error``. Mitigation: upgrade to `0.5.1` or later.
MINI-8rvf-5pc5-x5pj MINI-8rvf-5pc5-x5pj
ROOT-APP-PYPI-CVE-2025-69277 Vulnerability in rootio-PyNaCl (ROOT-APP-PYPI-CVE-2025-69277)
vulnerability in rootio-PyNaCl (ROOT-APP-PYPI-CVE-2025-69277). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.0+root.io.1, 1.5.0+root.io.2, 1.5.0+root.io.3, 1.5.0+root.io.4` or later.
MINI-2945-rqgx-7j7m MINI-2945-rqgx-7j7m
MINI-825m-prhp-vm83 MINI-825m-prhp-vm83
MINI-2m37-c3m5-69h9 MINI-2m37-c3m5-69h9
MINI-23f8-g2rh-6hx2 MINI-23f8-g2rh-6hx2
MINI-79r2-9ggm-q4j6 MINI-79r2-9ggm-q4j6
MINI-8c78-7m57-j7hx MINI-8c78-7m57-j7hx
CLSA-2026-1778599722 Vulnerability in libcap-dev (CLSA-2026-1778599722)
vulnerability in libcap-dev (CLSA-2026-1778599722). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:2.25-1.2+tuxcare.els2` or later.
CLSA-2026-1778599539 Vulnerability in libcap-dev (CLSA-2026-1778599539)
vulnerability in libcap-dev (CLSA-2026-1778599539). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:2.24-12+tuxcare.els2` or later.
CVE-2026-8108 Vulnerability in cisa (CVE-2026-8108)
vulnerability in cisa (CVE-2026-8108). Successful exploitation can lead to full system takeover.
CVE-2025-2595 Vulnerability in cisa (CVE-2025-2595)
vulnerability in cisa (CVE-2025-2595). Risk of unauthorized operations or information disclosure.
USN-8269-1 Vulnerability in avahi (USN-8269-1)
vulnerability in avahi (USN-8269-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.31-4ubuntu1.3+esm5` or later.
DEBIAN-CVE-2026-8401 Vulnerability in firefox-esr (DEBIAN-CVE-2026-8401)
vulnerability in firefox-esr (DEBIAN-CVE-2026-8401). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `140.11.0esr-1~deb11u1` or later.
CVE-2026-8401 Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3.
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3.
DEBIAN-CVE-2026-8368 Vulnerability in libwww-perl (DEBIAN-CVE-2026-8368)
vulnerability in libwww-perl (DEBIAN-CVE-2026-8368). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `6.83-1` or later.
CVE-2026-8368 Vulnerability in CVE-2026-8368 (CVE-2026-8368)
vulnerability in CVE-2026-8368 (CVE-2026-8368). Confidential information can be exposed externally. Exploitable via `Authorization header`.
CVE-2026-8111 SQL Injection in sqli (CVE-2026-8111)
SQL injection in sqli (CVE-2026-8111). Successful exploitation can lead to full system takeover.
CVE-2026-8110 Vulnerability in ivanti (CVE-2026-8110)
vulnerability in ivanti (CVE-2026-8110). Successful exploitation can lead to full system takeover.
CVE-2026-8109 Vulnerability in ivanti (CVE-2026-8109)
vulnerability in ivanti (CVE-2026-8109). Confidential information can be exposed externally.
CVE-2026-8051 OS Command Injection in ivanti (CVE-2026-8051)
OS command injection in ivanti (CVE-2026-8051). Successful exploitation can lead to full system takeover.
CVE-2026-8043 Vulnerability in ivanti (CVE-2026-8043)
vulnerability in ivanti (CVE-2026-8043). Confidential information can be exposed externally.
CVE-2026-7432 Vulnerability in ivanti (CVE-2026-7432)
vulnerability in ivanti (CVE-2026-7432). Successful exploitation can lead to full system takeover.
CVE-2026-7431 Vulnerability in ivanti (CVE-2026-7431)
vulnerability in ivanti (CVE-2026-7431). Risk of unauthorized operations or information disclosure.
CVE-2026-6866 Vulnerability in schneider-electric (CVE-2026-6866)
vulnerability in schneider-electric (CVE-2026-6866). Confidential information can be exposed externally.
CVE-2026-5061 Vulnerability in consul (CVE-2026-5061)
vulnerability in consul (CVE-2026-5061). Confidential information can be exposed externally. Mitigation: upgrade to `0.42.0` or later.
CVE-2026-43983 Vulnerability in github.com/pocket-id/pocket-id/backend (CVE-2026-43983)
vulnerability in github.com/pocket-id/pocket-id/backend (CVE-2026-43983). Confidential information can be exposed externally. Exploitable via ``createTokenFromRefreshToken``. Mitigation: upgrade to `0.0.0-20260419162744-978ac87deffe` or later.
CVE-2026-43939 Vulnerability in YAFNET.Core (CVE-2026-43939)
vulnerability in YAFNET.Core (CVE-2026-43939). Confidential information can be exposed externally. Exploitable via ``onerror``. Mitigation: upgrade to `3.2.12` or later.
CVE-2026-43938 Vulnerability in YAFNET.Core (CVE-2026-43938)
vulnerability in YAFNET.Core (CVE-2026-43938). Confidential information can be exposed externally. Exploitable via `GET /api/Attachments/GetAttachment`. Mitigation: upgrade to `3.2.12` or later.
CVE-2026-43937 Vulnerability in YAFNET.Core (CVE-2026-43937)
vulnerability in YAFNET.Core (CVE-2026-43937). Successful exploitation can lead to full system takeover. Exploitable via ``PageSecurityCheckAttribute``. Mitigation: upgrade to `4.0.5` or later.
CVE-2026-42260 SSRF (Server-Side Request Forgery) in open-websearch (CVE-2026-42260)
SSRF in open-websearch (CVE-2026-42260). Confidential information can be exposed externally. Exploitable via `GET /internal`. Mitigation: upgrade to `2.1.7` or later.
CVE-2026-32687 SQL Injection in postgrex (CVE-2026-32687)
SQL injection in postgrex (CVE-2026-32687). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.22.2` or later.
CVE-2025-70842 Cross-Site Scripting (XSS) in CVE-2025-70842 (CVE-2025-70842)
cross-site scripting in CVE-2025-70842 (CVE-2025-70842). Risk of unauthorized operations or information disclosure.
openSUSE-SU-2026:20743-1 Vulnerability in openSUSE-SU-2026:20743-1 (openSUSE-SU-2026:20743-1)
vulnerability in openSUSE-SU-2026:20743-1 (openSUSE-SU-2026:20743-1). Risk of unauthorized operations or information disclosure.
CVE-2026-45091 Information Disclosure in sealed-env (CVE-2026-45091)
vulnerability in sealed-env (CVE-2026-45091). Confidential information can be exposed externally. Mitigation: upgrade to `0.1.0-alpha.4` or later.
CVE-2026-45090 Vulnerability in github.com/hahwul/dalfox/v2 (CVE-2026-45090)
vulnerability in github.com/hahwul/dalfox/v2 (CVE-2026-45090). Risk of unauthorized operations or information disclosure. Exploitable via ``ParameterAnalysis``. Mitigation: upgrade to `2.13.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →