Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-2235-3r6g-h998 |
|
MINI-2235-3r6g-h998 |
| MINI-5m8c-6cx6-qx94 |
|
MINI-5m8c-6cx6-qx94 |
| MINI-58rp-4g2j-8hc5 |
|
MINI-58rp-4g2j-8hc5 |
| MINI-28jj-6jvq-7qf8 |
|
MINI-28jj-6jvq-7qf8 |
| MINI-2822-883x-pcjx |
|
MINI-2822-883x-pcjx |
| MINI-2g69-466x-2966 |
|
MINI-2g69-466x-2966 |
| MINI-32f4-g8fq-8pjm |
|
MINI-32f4-g8fq-8pjm |
| MINI-43mc-6f83-62ph |
|
MINI-43mc-6f83-62ph |
| MINI-3p3p-c2r4-w594 |
|
MINI-3p3p-c2r4-w594 |
| MINI-2254-pv5g-7hw6 |
|
MINI-2254-pv5g-7hw6 |
| MINI-5pc5-vc7x-rr39 |
|
MINI-5pc5-vc7x-rr39 |
| MINI-79gx-4fr4-48cm |
|
MINI-79gx-4fr4-48cm |
| MINI-2934-vwjq-86c6 |
|
MINI-2934-vwjq-86c6 |
| GHSA-3q49-cfcf-g5fm |
|
Vulnerability in @mistralai/mistralai (GHSA-3q49-cfcf-g5fm)
vulnerability in @mistralai/mistralai (GHSA-3q49-cfcf-g5fm). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3921 |
|
Vulnerability in Google chrome (CVE-2026-3921)
vulnerability in Google chrome (CVE-2026-3921). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-7010 |
|
Vulnerability in libhttp-tiny-perl (DEBIAN-CVE-2026-7010)
vulnerability in libhttp-tiny-perl (DEBIAN-CVE-2026-7010). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.092-2` or later.
|
| CVE-2026-8344 |
|
Vulnerability in dlink (CVE-2026-8344)
vulnerability in dlink (CVE-2026-8344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7010 |
|
Vulnerability in CVE-2026-7010 (CVE-2026-7010)
vulnerability in CVE-2026-7010 (CVE-2026-7010). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44695 |
|
Cross-Site Request Forgery (CSRF) in getoutline (CVE-2026-44695)
vulnerability in getoutline (CVE-2026-44695). Confidential information can be exposed externally. Exploitable via `GET /auth/slack.post`. Mitigation: upgrade to `1.7.1` or later.
|
| CVE-2026-43897 |
|
SSRF (Server-Side Request Forgery) in link-preview-js (CVE-2026-43897)
SSRF in link-preview-js (CVE-2026-43897). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.0.1` or later.
|
| CVE-2026-43893 |
|
Vulnerability in exiftool-vendored (CVE-2026-43893)
vulnerability in exiftool-vendored (CVE-2026-43893). Data can be tampered with by attackers. Exploitable via ``WriteTask``. Mitigation: upgrade to `35.19.0` or later.
|
| CVE-2026-43890 |
|
Vulnerability in CVE-2026-43890 (CVE-2026-43890)
vulnerability in CVE-2026-43890 (CVE-2026-43890). Confidential information can be exposed externally. Mitigation: upgrade to `1.7.1` or later.
|
| CVE-2026-43889 |
|
Authorization Flaw in CVE-2026-43889 (CVE-2026-43889)
vulnerability in CVE-2026-43889 (CVE-2026-43889). Confidential information can be exposed externally. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-43888 |
|
Path Traversal in CVE-2026-43888 (CVE-2026-43888)
path traversal in CVE-2026-43888 (CVE-2026-43888). Data can be tampered with by attackers. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-43887 |
|
Cross-Site Scripting (XSS) in CVE-2026-43887 (CVE-2026-43887)
cross-site scripting in CVE-2026-43887 (CVE-2026-43887). Confidential information can be exposed externally. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-43886 |
|
Privilege Escalation in CVE-2026-43886 (CVE-2026-43886)
vulnerability in CVE-2026-43886 (CVE-2026-43886). Data can be tampered with by attackers. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-43885 |
|
Information Disclosure in wwbn/avideo (CVE-2026-43885)
vulnerability in wwbn/avideo (CVE-2026-43885). Risk of unauthorized operations or information disclosure. Exploitable via ``APISecret``.
|
| CVE-2026-43884 |
|
SSRF (Server-Side Request Forgery) in wwbn/avideo (CVE-2026-43884)
SSRF in wwbn/avideo (CVE-2026-43884). Confidential information can be exposed externally. Exploitable via `POST /plugin/AI/receiveAsync.json.php`.
|
| CVE-2026-43883 |
|
Vulnerability in wwbn/avideo (CVE-2026-43883)
vulnerability in wwbn/avideo (CVE-2026-43883). Risk of unauthorized operations or information disclosure. Exploitable via ``agreement``.
|
| CVE-2026-43881 |
|
Vulnerability in wwbn/avideo (CVE-2026-43881)
vulnerability in wwbn/avideo (CVE-2026-43881). Risk of unauthorized operations or information disclosure. Exploitable via ``isCompany``.
|
| CVE-2026-43880 |
|
Vulnerability in wwbn/avideo (CVE-2026-43880)
vulnerability in wwbn/avideo (CVE-2026-43880). Risk of unauthorized operations or information disclosure. Exploitable via `POST /objects/sendEmail.json.php`.
|
| CVE-2026-43879 |
|
SSRF (Server-Side Request Forgery) in wwbn/avideo (CVE-2026-43879)
SSRF in wwbn/avideo (CVE-2026-43879). Risk of unauthorized operations or information disclosure. Exploitable via `POST /internal/admin/action`.
|
| CVE-2026-43878 |
|
Cross-Site Scripting (XSS) in wwbn/avideo (CVE-2026-43878)
cross-site scripting in wwbn/avideo (CVE-2026-43878). Risk of unauthorized operations or information disclosure. Exploitable via ``user``.
|
| CVE-2026-43877 |
|
Cross-Site Request Forgery (CSRF) in wwbn/avideo (CVE-2026-43877)
vulnerability in wwbn/avideo (CVE-2026-43877). Risk of unauthorized operations or information disclosure. Exploitable via ``autoCSRFGuard``.
|
| DEBIAN-CVE-2026-42046 |
|
Vulnerability in libcaca (DEBIAN-CVE-2026-42046)
vulnerability in libcaca (DEBIAN-CVE-2026-42046). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.99.beta20-7` or later.
|
| CVE-2026-43876 |
|
Cross-Site Scripting (XSS) in wwbn/avideo (CVE-2026-43876)
cross-site scripting in wwbn/avideo (CVE-2026-43876). Risk of unauthorized operations or information disclosure. Exploitable via ``message``.
|
| CVE-2026-43875 |
|
Vulnerability in wwbn/avideo (CVE-2026-43875)
vulnerability in wwbn/avideo (CVE-2026-43875). Confidential information can be exposed externally. Exploitable via `GET /plugin/MobileManager/oauth2.php`.
|
| CVE-2026-43873 |
|
Vulnerability in wwbn/avideo (CVE-2026-43873)
vulnerability in wwbn/avideo (CVE-2026-43873). Confidential information can be exposed externally. Exploitable via ``cloneSiteURL``.
|
| CVE-2026-42600 |
|
Path Traversal in github.com/minio/minio (CVE-2026-42600)
path traversal in github.com/minio/minio (CVE-2026-42600). Confidential information can be exposed externally. Exploitable via ``ReadMultiple``.
|
| CVE-2026-42564 |
|
Path Traversal in path-traversal (CVE-2026-42564)
path traversal in path-traversal (CVE-2026-42564). Confidential information can be exposed externally. Mitigation: upgrade to `1.22.0` or later.
|
| CVE-2026-42188 |
|
SSRF (Server-Side Request Forgery) in org.geysermc.geyser:core (CVE-2026-42188)
SSRF in org.geysermc.geyser:core (CVE-2026-42188). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.3` or later.
|
| CVE-2026-42046 |
|
Vulnerability in CVE-2026-42046 (CVE-2026-42046)
vulnerability in CVE-2026-42046 (CVE-2026-42046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34961 |
|
Out-of-Bounds Read in c (CVE-2026-34961)
vulnerability in c (CVE-2026-34961). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34960 |
|
Out-of-Bounds Read in pengutronix (CVE-2026-34960)
vulnerability in pengutronix (CVE-2026-34960). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-7010 |
|
Vulnerability in libhttp-tiny-perl (UBUNTU-CVE-2026-7010)
vulnerability in libhttp-tiny-perl (UBUNTU-CVE-2026-7010). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-42046 |
|
Vulnerability in libcaca (UBUNTU-CVE-2026-42046)
vulnerability in libcaca (UBUNTU-CVE-2026-42046). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.99.beta19-2.2ubuntu4.2` or later.
|
| ECHO-d531-9d26-ac4f |
|
ECHO-d531-9d26-ac4f |
| CLSA-2026-1778535928 |
|
Vulnerability in python (CLSA-2026-1778535928)
vulnerability in python (CLSA-2026-1778535928). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.5-94.0.1.el7_9.tuxcare.els8` or later.
|
| CVE-2026-43655 |
|
Out-of-Bounds Read in apple (CVE-2026-43655)
vulnerability in apple (CVE-2026-43655). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43652 |
|
Vulnerability in apple (CVE-2026-43652)
vulnerability in apple (CVE-2026-43652). Confidential information can be exposed externally.
|