Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-42887 Cross-Site Scripting (XSS) in CVE-2026-42887 (CVE-2026-42887)
cross-site scripting in CVE-2026-42887 (CVE-2026-42887). Confidential information can be exposed externally. Mitigation: upgrade to `2.33.0` or later.
CVE-2026-42886 Vulnerability in CVE-2026-42886 (CVE-2026-42886)
vulnerability in CVE-2026-42886 (CVE-2026-42886). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/backups/upload`. Mitigation: upgrade to `2.32.2` or later.
CVE-2026-42885 Path Traversal in CVE-2026-42885 (CVE-2026-42885)
path traversal in CVE-2026-42885 (CVE-2026-42885). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/filesystem/pathexists`. Mitigation: upgrade to `2.32.2` or later.
CVE-2026-42884 Authorization Flaw in CVE-2026-42884 (CVE-2026-42884)
vulnerability in CVE-2026-42884 (CVE-2026-42884). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/collections`. Mitigation: upgrade to `2.32.2` or later.
CVE-2026-42883 Authorization Flaw in CVE-2026-42883 (CVE-2026-42883)
vulnerability in CVE-2026-42883 (CVE-2026-42883). Confidential information can be exposed externally. Exploitable via `GET /api/libraries/`. Mitigation: upgrade to `2.32.2` or later.
CVE-2026-42882 Path Traversal in github.com/oxyno-zeta/s3-proxy (CVE-2026-42882)
path traversal in github.com/oxyno-zeta/s3-proxy (CVE-2026-42882). Confidential information can be exposed externally. Exploitable via `PUT /upload/foo/drafts/../restricted/`. Mitigation: upgrade to `0.0.0-20260424211602-1320e4abd46a` or later.
CVE-2026-42875 Vulnerability in github.com/external-secrets/external-secrets (CVE-2026-42875)
vulnerability in github.com/external-secrets/external-secrets (CVE-2026-42875). Risk of unauthorized operations or information disclosure. Exploitable via ``ConfigMap``. Mitigation: upgrade to `2.4.0` or later.
CVE-2026-42874 Vulnerability in microdot (CVE-2026-42874)
vulnerability in microdot (CVE-2026-42874). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.1` or later.
CVE-2026-42873 Information Disclosure in CVE-2026-42873 (CVE-2026-42873)
vulnerability in CVE-2026-42873 (CVE-2026-42873). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.10` or later.
CVE-2026-42872 Cross-Site Scripting (XSS) in CVE-2026-42872 (CVE-2026-42872)
cross-site scripting in CVE-2026-42872 (CVE-2026-42872). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.0` or later.
CVE-2026-42870 Cross-Site Scripting (XSS) in CVE-2026-42870 (CVE-2026-42870)
cross-site scripting in CVE-2026-42870 (CVE-2026-42870). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.0` or later.
CVE-2026-42869 Authentication Bypass in CVE-2026-42869 (CVE-2026-42869)
authentication bypass in CVE-2026-42869 (CVE-2026-42869). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.57` or later.
DEBIAN-CVE-2026-42050 Vulnerability in imagemagick (DEBIAN-CVE-2026-42050)
vulnerability in imagemagick (DEBIAN-CVE-2026-42050). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.1.2-21` or later.
CVE-2026-42565 Open Redirect in @workos/authkit-session (CVE-2026-42565)
vulnerability in @workos/authkit-session (CVE-2026-42565). Risk of unauthorized operations or information disclosure. Exploitable via ``AuthService.handleCallback``. Mitigation: upgrade to `0.5.1` or later.
CVE-2026-42050 Vulnerability in imagemagick (CVE-2026-42050)
vulnerability in imagemagick (CVE-2026-42050). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.1.2-21` or later.
CVE-2026-36734 Command Injection in CVE-2026-36734 (CVE-2026-36734)
command injection in CVE-2026-36734 (CVE-2026-36734). Successful exploitation can lead to full system takeover.
CVE-2026-2614 MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
CVE-2022-4988 Vulnerability in CVE-2022-4988 (CVE-2022-4988)
vulnerability in CVE-2022-4988 (CVE-2022-4988). Risk of unauthorized operations or information disclosure.
CVE-2026-44657 Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-44657)
cross-site scripting in mantisbt/mantisbt (CVE-2026-44657). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
CVE-2026-44655 Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-44655)
cross-site scripting in mantisbt/mantisbt (CVE-2026-44655). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
CVE-2026-44635 Vulnerability in kysely (CVE-2026-44635)
vulnerability in kysely (CVE-2026-44635). Confidential information can be exposed externally. Exploitable via ``DefaultQueryCompiler.visitJSONPathLeg``. Mitigation: upgrade to `0.28.17` or later.
CVE-2026-43979 Cross-Site Scripting (XSS) in local-deep-research (CVE-2026-43979)
cross-site scripting in local-deep-research (CVE-2026-43979). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/start_research`. Mitigation: upgrade to `1.6.0` or later.
CVE-2026-43898 Code Injection in @nyariv/sandboxjs (CVE-2026-43898)
code injection in @nyariv/sandboxjs (CVE-2026-43898). Successful exploitation can lead to full system takeover. Exploitable via ``Function.caller``. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-42071 Vulnerability in mantisbt/mantisbt (CVE-2026-42071)
vulnerability in mantisbt/mantisbt (CVE-2026-42071). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/rest/issues/{id}/files`. Mitigation: upgrade to `2.28.2` or later.
CVE-2026-42070 Authorization Flaw in mantisbt/mantisbt (CVE-2026-42070)
vulnerability in mantisbt/mantisbt (CVE-2026-42070). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
CVE-2026-41897 Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-41897)
cross-site scripting in mantisbt/mantisbt (CVE-2026-41897). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
CVE-2026-41159 Code Injection in mermaid (CVE-2026-41159)
code injection in mermaid (CVE-2026-41159). Risk of unauthorized operations or information disclosure. Exploitable via ``fontFamily``. Mitigation: upgrade to `10.9.6` or later.
CVE-2026-41150 Vulnerability in mermaid (CVE-2026-41150)
vulnerability in mermaid (CVE-2026-41150). Risk of unauthorized operations or information disclosure. Exploitable via ``excludes``. Mitigation: upgrade to `10.9.6` or later.
CVE-2026-41149 Code Injection in mermaid (CVE-2026-41149)
code injection in mermaid (CVE-2026-41149). Risk of unauthorized operations or information disclosure. Exploitable via ``classDef``. Mitigation: upgrade to `10.9.6` or later.
CVE-2026-41148 Code Injection in mermaid (CVE-2026-41148)
code injection in mermaid (CVE-2026-41148). Risk of unauthorized operations or information disclosure. Exploitable via ``classDef``. Mitigation: upgrade to `10.9.6` or later.
CVE-2026-40607 Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-40607)
cross-site scripting in mantisbt/mantisbt (CVE-2026-40607). Risk of unauthorized operations or information disclosure. Exploitable via ``g_stored_query_create_threshold``. Mitigation: upgrade to `2.28.2` or later.
CVE-2026-40598 Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-40598)
cross-site scripting in mantisbt/mantisbt (CVE-2026-40598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
CVE-2026-40597 Vulnerability in mantisbt/mantisbt (CVE-2026-40597)
vulnerability in mantisbt/mantisbt (CVE-2026-40597). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
MINI-p6hc-r4jw-p2v9 MINI-p6hc-r4jw-p2v9
MINI-p8jw-x2gr-p59v MINI-p8jw-x2gr-p59v
MINI-xv6r-jgpv-57c5 MINI-xv6r-jgpv-57c5
MINI-p658-fx3g-g5m9 MINI-p658-fx3g-g5m9
MINI-xrq4-xqwj-vjc6 MINI-xrq4-xqwj-vjc6
MINI-xxcr-fp3x-hg88 MINI-xxcr-fp3x-hg88
MINI-xw9w-966h-7hmr MINI-xw9w-966h-7hmr
MINI-xr7j-2532-r2rw MINI-xr7j-2532-r2rw
MINI-xrr4-qg46-3vqg MINI-xrr4-qg46-3vqg
MINI-xp55-q9j6-2955 MINI-xp55-q9j6-2955
MINI-xr5p-mrrg-q5v2 MINI-xr5p-mrrg-q5v2
MINI-xqq7-gp7m-xm7x MINI-xqq7-gp7m-xm7x
MINI-p4h6-rrc3-q89c MINI-p4h6-rrc3-q89c
MINI-xqwf-crxv-24mw MINI-xqwf-crxv-24mw
MINI-xqjg-r8mv-p626 MINI-xqjg-r8mv-p626
MINI-xqcg-h8mr-g2q6 MINI-xqcg-h8mr-g2q6
MINI-xqrf-gr6q-rrvc MINI-xqrf-gr6q-rrvc

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →