Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42887 |
|
Cross-Site Scripting (XSS) in CVE-2026-42887 (CVE-2026-42887)
cross-site scripting in CVE-2026-42887 (CVE-2026-42887). Confidential information can be exposed externally. Mitigation: upgrade to `2.33.0` or later.
|
| CVE-2026-42886 |
|
Vulnerability in CVE-2026-42886 (CVE-2026-42886)
vulnerability in CVE-2026-42886 (CVE-2026-42886). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/backups/upload`. Mitigation: upgrade to `2.32.2` or later.
|
| CVE-2026-42885 |
|
Path Traversal in CVE-2026-42885 (CVE-2026-42885)
path traversal in CVE-2026-42885 (CVE-2026-42885). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/filesystem/pathexists`. Mitigation: upgrade to `2.32.2` or later.
|
| CVE-2026-42884 |
|
Authorization Flaw in CVE-2026-42884 (CVE-2026-42884)
vulnerability in CVE-2026-42884 (CVE-2026-42884). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/collections`. Mitigation: upgrade to `2.32.2` or later.
|
| CVE-2026-42883 |
|
Authorization Flaw in CVE-2026-42883 (CVE-2026-42883)
vulnerability in CVE-2026-42883 (CVE-2026-42883). Confidential information can be exposed externally. Exploitable via `GET /api/libraries/`. Mitigation: upgrade to `2.32.2` or later.
|
| CVE-2026-42882 |
|
Path Traversal in github.com/oxyno-zeta/s3-proxy (CVE-2026-42882)
path traversal in github.com/oxyno-zeta/s3-proxy (CVE-2026-42882). Confidential information can be exposed externally. Exploitable via `PUT /upload/foo/drafts/../restricted/`. Mitigation: upgrade to `0.0.0-20260424211602-1320e4abd46a` or later.
|
| CVE-2026-42875 |
|
Vulnerability in github.com/external-secrets/external-secrets (CVE-2026-42875)
vulnerability in github.com/external-secrets/external-secrets (CVE-2026-42875). Risk of unauthorized operations or information disclosure. Exploitable via ``ConfigMap``. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-42874 |
|
Vulnerability in microdot (CVE-2026-42874)
vulnerability in microdot (CVE-2026-42874). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2026-42873 |
|
Information Disclosure in CVE-2026-42873 (CVE-2026-42873)
vulnerability in CVE-2026-42873 (CVE-2026-42873). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.10` or later.
|
| CVE-2026-42872 |
|
Cross-Site Scripting (XSS) in CVE-2026-42872 (CVE-2026-42872)
cross-site scripting in CVE-2026-42872 (CVE-2026-42872). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.0` or later.
|
| CVE-2026-42870 |
|
Cross-Site Scripting (XSS) in CVE-2026-42870 (CVE-2026-42870)
cross-site scripting in CVE-2026-42870 (CVE-2026-42870). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.7.0` or later.
|
| CVE-2026-42869 |
|
Authentication Bypass in CVE-2026-42869 (CVE-2026-42869)
authentication bypass in CVE-2026-42869 (CVE-2026-42869). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.57` or later.
|
| DEBIAN-CVE-2026-42050 |
|
Vulnerability in imagemagick (DEBIAN-CVE-2026-42050)
vulnerability in imagemagick (DEBIAN-CVE-2026-42050). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.1.2-21` or later.
|
| CVE-2026-42565 |
|
Open Redirect in @workos/authkit-session (CVE-2026-42565)
vulnerability in @workos/authkit-session (CVE-2026-42565). Risk of unauthorized operations or information disclosure. Exploitable via ``AuthService.handleCallback``. Mitigation: upgrade to `0.5.1` or later.
|
| CVE-2026-42050 |
|
Vulnerability in imagemagick (CVE-2026-42050)
vulnerability in imagemagick (CVE-2026-42050). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.1.2-21` or later.
|
| CVE-2026-36734 |
|
Command Injection in CVE-2026-36734 (CVE-2026-36734)
command injection in CVE-2026-36734 (CVE-2026-36734). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2614 |
|
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
MLflow allows an unauthenticated remote attacker to read arbitrary files from the server's filesystem
|
| CVE-2022-4988 |
|
Vulnerability in CVE-2022-4988 (CVE-2022-4988)
vulnerability in CVE-2022-4988 (CVE-2022-4988). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44657 |
|
Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-44657)
cross-site scripting in mantisbt/mantisbt (CVE-2026-44657). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
|
| CVE-2026-44655 |
|
Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-44655)
cross-site scripting in mantisbt/mantisbt (CVE-2026-44655). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
|
| CVE-2026-44635 |
|
Vulnerability in kysely (CVE-2026-44635)
vulnerability in kysely (CVE-2026-44635). Confidential information can be exposed externally. Exploitable via ``DefaultQueryCompiler.visitJSONPathLeg``. Mitigation: upgrade to `0.28.17` or later.
|
| CVE-2026-43979 |
|
Cross-Site Scripting (XSS) in local-deep-research (CVE-2026-43979)
cross-site scripting in local-deep-research (CVE-2026-43979). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/start_research`. Mitigation: upgrade to `1.6.0` or later.
|
| CVE-2026-43898 |
|
Code Injection in @nyariv/sandboxjs (CVE-2026-43898)
code injection in @nyariv/sandboxjs (CVE-2026-43898). Successful exploitation can lead to full system takeover. Exploitable via ``Function.caller``. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-42071 |
|
Vulnerability in mantisbt/mantisbt (CVE-2026-42071)
vulnerability in mantisbt/mantisbt (CVE-2026-42071). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/rest/issues/{id}/files`. Mitigation: upgrade to `2.28.2` or later.
|
| CVE-2026-42070 |
|
Authorization Flaw in mantisbt/mantisbt (CVE-2026-42070)
vulnerability in mantisbt/mantisbt (CVE-2026-42070). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
|
| CVE-2026-41897 |
|
Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-41897)
cross-site scripting in mantisbt/mantisbt (CVE-2026-41897). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
|
| CVE-2026-41159 |
|
Code Injection in mermaid (CVE-2026-41159)
code injection in mermaid (CVE-2026-41159). Risk of unauthorized operations or information disclosure. Exploitable via ``fontFamily``. Mitigation: upgrade to `10.9.6` or later.
|
| CVE-2026-41150 |
|
Vulnerability in mermaid (CVE-2026-41150)
vulnerability in mermaid (CVE-2026-41150). Risk of unauthorized operations or information disclosure. Exploitable via ``excludes``. Mitigation: upgrade to `10.9.6` or later.
|
| CVE-2026-41149 |
|
Code Injection in mermaid (CVE-2026-41149)
code injection in mermaid (CVE-2026-41149). Risk of unauthorized operations or information disclosure. Exploitable via ``classDef``. Mitigation: upgrade to `10.9.6` or later.
|
| CVE-2026-41148 |
|
Code Injection in mermaid (CVE-2026-41148)
code injection in mermaid (CVE-2026-41148). Risk of unauthorized operations or information disclosure. Exploitable via ``classDef``. Mitigation: upgrade to `10.9.6` or later.
|
| CVE-2026-40607 |
|
Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-40607)
cross-site scripting in mantisbt/mantisbt (CVE-2026-40607). Risk of unauthorized operations or information disclosure. Exploitable via ``g_stored_query_create_threshold``. Mitigation: upgrade to `2.28.2` or later.
|
| CVE-2026-40598 |
|
Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-40598)
cross-site scripting in mantisbt/mantisbt (CVE-2026-40598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
|
| CVE-2026-40597 |
|
Vulnerability in mantisbt/mantisbt (CVE-2026-40597)
vulnerability in mantisbt/mantisbt (CVE-2026-40597). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.2` or later.
|
| MINI-p6hc-r4jw-p2v9 |
|
MINI-p6hc-r4jw-p2v9 |
| MINI-p8jw-x2gr-p59v |
|
MINI-p8jw-x2gr-p59v |
| MINI-xv6r-jgpv-57c5 |
|
MINI-xv6r-jgpv-57c5 |
| MINI-p658-fx3g-g5m9 |
|
MINI-p658-fx3g-g5m9 |
| MINI-xrq4-xqwj-vjc6 |
|
MINI-xrq4-xqwj-vjc6 |
| MINI-xxcr-fp3x-hg88 |
|
MINI-xxcr-fp3x-hg88 |
| MINI-xw9w-966h-7hmr |
|
MINI-xw9w-966h-7hmr |
| MINI-xr7j-2532-r2rw |
|
MINI-xr7j-2532-r2rw |
| MINI-xrr4-qg46-3vqg |
|
MINI-xrr4-qg46-3vqg |
| MINI-xp55-q9j6-2955 |
|
MINI-xp55-q9j6-2955 |
| MINI-xr5p-mrrg-q5v2 |
|
MINI-xr5p-mrrg-q5v2 |
| MINI-xqq7-gp7m-xm7x |
|
MINI-xqq7-gp7m-xm7x |
| MINI-p4h6-rrc3-q89c |
|
MINI-p4h6-rrc3-q89c |
| MINI-xqwf-crxv-24mw |
|
MINI-xqwf-crxv-24mw |
| MINI-xqjg-r8mv-p626 |
|
MINI-xqjg-r8mv-p626 |
| MINI-xqcg-h8mr-g2q6 |
|
MINI-xqcg-h8mr-g2q6 |
| MINI-xqrf-gr6q-rrvc |
|
MINI-xqrf-gr6q-rrvc |