Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-73414 OS Command Injection in shescape (CVE-2026-73414)
OS command injection in shescape (CVE-2026-73414). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-73412 OS Command Injection in shescape (CVE-2026-73412)
OS command injection in shescape (CVE-2026-73412). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-69160 Vulnerability in github.com/OpenListTeam/OpenList/v4 (CVE-2026-69160)
vulnerability in github.com/OpenListTeam/OpenList/v4 (CVE-2026-69160). Confidential information can be exposed externally. Exploitable via `POST /api/share/create`. Mitigation: upgrade to `4.2.4` or later.
GHSA-p6ph-3jx2-3337 Information Disclosure in github.com/OpenListTeam/OpenList/v4 (GHSA-p6ph-3jx2-3337)
vulnerability in github.com/OpenListTeam/OpenList/v4 (GHSA-p6ph-3jx2-3337). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/fs/search`. Mitigation: upgrade to `4.2.4` or later.
CVE-2026-73509 Path Traversal in github.com/OpenListTeam/OpenList/v4 (CVE-2026-73509)
path traversal in github.com/OpenListTeam/OpenList/v4 (CVE-2026-73509). Data can be tampered with by attackers. Exploitable via ``new_name``. Mitigation: upgrade to `4.2.4` or later.
CVE-2026-73493 Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `1.0.0-M42` or later.
CVE-2026-73495 Vulnerability in org.http4s:blaze-http_2.13 (CVE-2026-73495)
vulnerability in org.http4s:blaze-http_2.13 (CVE-2026-73495). Confidential information can be exposed externally. Exploitable via ``Request.headers``. Mitigation: upgrade to `1.0.0-M42` or later.
CVE-2026-73494 Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73494)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73494). Risk of unauthorized operations or information disclosure. Exploitable via ``BlazeServerBuilder``. Mitigation: upgrade to `0.23.18` or later.
CVE-2026-55985 Vulnerability in CVE-2026-55985 (CVE-2026-55985)
vulnerability in CVE-2026-55985 (CVE-2026-55985). Risk of unauthorized operations or information disclosure.
CVE-2025-71408 Vulnerability in nltk (CVE-2025-71408)
vulnerability in nltk (CVE-2025-71408). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.3` or later.
GHSA-cmwh-g2h8-c222 Authentication Bypass in poweradmin/poweradmin (GHSA-cmwh-g2h8-c222)
authentication bypass in poweradmin/poweradmin (GHSA-cmwh-g2h8-c222). Risk of unauthorized operations or information disclosure. Exploitable via `GET /oidc/login`. Mitigation: upgrade to `4.2.5` or later.
GHSA-rm67-g9ch-vxff Vulnerability in poweradmin/poweradmin (GHSA-rm67-g9ch-vxff)
vulnerability in poweradmin/poweradmin (GHSA-rm67-g9ch-vxff). Risk of unauthorized operations or information disclosure. Exploitable via `POST /zones/3/edit`. Mitigation: upgrade to `4.3.4` or later.
GHSA-h4hf-v6w5-897x Vulnerability in poweradmin/poweradmin (GHSA-h4hf-v6w5-897x)
vulnerability in poweradmin/poweradmin (GHSA-h4hf-v6w5-897x). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/v2/users/{id}`. Mitigation: upgrade to `4.3.4` or later.
GHSA-f25v-x6vr-962g Vulnerability in pheditor/pheditor (GHSA-f25v-x6vr-962g)
vulnerability in pheditor/pheditor (GHSA-f25v-x6vr-962g). Risk of unauthorized operations or information disclosure. Exploitable via ``admin``. Mitigation: upgrade to `2.0.7` or later.
CVE-2026-73567 Vulnerability in sm-crypto (CVE-2026-73567)
vulnerability in sm-crypto (CVE-2026-73567). Confidential information can be exposed externally. Exploitable via ``SecureRandom``. Mitigation: upgrade to `0.5.0` or later.
GHSA-v6w6-358x-2433 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (GHSA-v6w6-358x-2433)
vulnerability in github.com/cloudreve/Cloudreve/v4 (GHSA-v6w6-358x-2433). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v4/admin/node`. Mitigation: upgrade to `4.0.0-20260626022735-332a9d800205` or later.
CVE-2026-73652 Authorization Flaw in vantage6 (CVE-2026-73652)
vulnerability in vantage6 (CVE-2026-73652). Risk of unauthorized operations or information disclosure.
GHSA-2625-rw7m-5q5x Vulnerability in hubuum_client (GHSA-2625-rw7m-5q5x)
vulnerability in hubuum_client (GHSA-2625-rw7m-5q5x). Risk of unauthorized operations or information disclosure. Exploitable via ``hubuum_client``. Mitigation: upgrade to `0.6.1` or later.
GHSA-qqc3-94qv-7fw3 Vulnerability in hubuum_client (GHSA-qqc3-94qv-7fw3)
vulnerability in hubuum_client (GHSA-qqc3-94qv-7fw3). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.1` or later.
GHSA-f45q-w629-wr25 Information Disclosure in hubuum_client (GHSA-f45q-w629-wr25)
vulnerability in hubuum_client (GHSA-f45q-w629-wr25). Risk of unauthorized operations or information disclosure. Exploitable via ``BaseUrl``. Mitigation: upgrade to `0.6.1` or later.
CVE-2026-73564 Vulnerability in github.com/fatedier/frp (CVE-2026-73564)
vulnerability in github.com/fatedier/frp (CVE-2026-73564). Risk of unauthorized operations or information disclosure. Exploitable via ``frps``. Mitigation: upgrade to `0.70.1` or later.
CVE-2026-73561 Vulnerability in @anephenix/hub (CVE-2026-73561)
vulnerability in @anephenix/hub (CVE-2026-73561). Risk of unauthorized operations or information disclosure. Exploitable via ``setInterval``. Mitigation: upgrade to `0.2.16` or later.
GHSA-c534-2w9c-x7fm Vulnerability in github.com/zxh326/kite (GHSA-c534-2w9c-x7fm)
vulnerability in github.com/zxh326/kite (GHSA-c534-2w9c-x7fm). Risk of unauthorized operations or information disclosure. Exploitable via ``get``. Mitigation: upgrade to `0.14.1` or later.
CVE-2026-73644 Vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644)
vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644). Confidential information can be exposed externally. Mitigation: upgrade to `5.1.2` or later.
GHSA-68r5-9hpg-7qw9 Vulnerability in org.openidentityplatform.opendj:opendj-dsml-servlet (GHSA-68r5-9hpg-7qw9)
vulnerability in org.openidentityplatform.opendj:opendj-dsml-servlet (GHSA-68r5-9hpg-7qw9). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.1.2` or later.
GHSA-g3hq-hphg-8fhh OS Command Injection in pheditor/pheditor (GHSA-g3hq-hphg-8fhh)
OS command injection in pheditor/pheditor (GHSA-g3hq-hphg-8fhh). Risk of unauthorized operations or information disclosure. Exploitable via ``TERMINAL_COMMANDS``. Mitigation: upgrade to `2.0.7` or later.
GHSA-94p4-4cq8-9g67 Information Disclosure in GitPython (GHSA-94p4-4cq8-9g67)
vulnerability in GitPython (GHSA-94p4-4cq8-9g67). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `3.1.55` or later.
CVE-2026-73307 SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-73307)
SSRF in @budibase/server (CVE-2026-73307). Risk of unauthorized operations or information disclosure.
CVE-2026-73410 Vulnerability in @budibase/server (CVE-2026-73410)
vulnerability in @budibase/server (CVE-2026-73410). Successful exploitation can lead to full system takeover. Exploitable via ``fetchWithBlacklist``.
GHSA-pmpg-2mxq-6xwr SQL Injection in @budibase/server (GHSA-pmpg-2mxq-6xwr)
SQL injection in @budibase/server (GHSA-pmpg-2mxq-6xwr). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/queries/`.
CVE-2026-73306 Vulnerability in @budibase/server (CVE-2026-73306)
vulnerability in @budibase/server (CVE-2026-73306). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/global/auth/`.
GHSA-pvcr-8mvp-w8qr Vulnerability in @budibase/server (GHSA-pvcr-8mvp-w8qr)
vulnerability in @budibase/server (GHSA-pvcr-8mvp-w8qr). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/chat-links/`.
GHSA-2xgg-r2wc-c5r2 SQL Injection in @budibase/server (GHSA-2xgg-r2wc-c5r2)
SQL injection in @budibase/server (GHSA-2xgg-r2wc-c5r2). Risk of unauthorized operations or information disclosure. Exploitable via ``INFORMATION_SCHEMA.TABLES``.
GHSA-qw6m-8fw2-2v64 Vulnerability in @budibase/server (GHSA-qw6m-8fw2-2v64)
vulnerability in @budibase/server (GHSA-qw6m-8fw2-2v64). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v2/queries/`.
CVE-2026-73308 Information Disclosure in @budibase/server (CVE-2026-73308)
vulnerability in @budibase/server (CVE-2026-73308). Confidential information can be exposed externally. Exploitable via `GET /api/automations/`.
CVE-2026-73406 Information Disclosure in @budibase/server (CVE-2026-73406)
vulnerability in @budibase/server (CVE-2026-73406). Confidential information can be exposed externally. Exploitable via `GET /api/global/users/tenant/`.
GHSA-mqhr-6j6h-74p5 Information Disclosure in @budibase/server (GHSA-mqhr-6j6h-74p5)
vulnerability in @budibase/server (GHSA-mqhr-6j6h-74p5). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v2/queries/`.
CVE-2026-62323 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-62323)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-62323). Data can be tampered with by attackers. Exploitable via `PUT /api/v4/file/viewerSession`. Mitigation: upgrade to `4.0.0-20260626022433-f3347130ac48` or later.
CVE-2026-73302 Authentication Bypass in @budibase/server (CVE-2026-73302)
authentication bypass in @budibase/server (CVE-2026-73302). Risk of unauthorized operations or information disclosure. Exploitable via `POST /realms/budi/protocol/openid-connect/token`.
GHSA-xg5g-26x8-cvf4 SSRF (Server-Side Request Forgery) in @budibase/server (GHSA-xg5g-26x8-cvf4)
SSRF in @budibase/server (GHSA-xg5g-26x8-cvf4). Risk of unauthorized operations or information disclosure. Exploitable via ``fetchFn``.
GHSA-xcx6-4f2g-hhgx Authorization Flaw in @budibase/server (GHSA-xcx6-4f2g-hhgx)
vulnerability in @budibase/server (GHSA-xcx6-4f2g-hhgx). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/attachments/`.
CVE-2026-73409 Vulnerability in @budibase/server (CVE-2026-73409)
vulnerability in @budibase/server (CVE-2026-73409). Risk of unauthorized operations or information disclosure. Exploitable via ``tlsCertificateKeyFile``.
GHSA-q6x4-v3qx-85qw SQL Injection in @budibase/server (GHSA-q6x4-v3qx-85qw)
SQL injection in @budibase/server (GHSA-q6x4-v3qx-85qw). Risk of unauthorized operations or information disclosure.
CVE-2026-73303 Vulnerability in @budibase/server (CVE-2026-73303)
vulnerability in @budibase/server (CVE-2026-73303). Confidential information can be exposed externally. Exploitable via `POST /api/v2/email`.
CVE-2026-73304 Information Disclosure in @budibase/server (CVE-2026-73304)
vulnerability in @budibase/server (CVE-2026-73304). Confidential information can be exposed externally. Exploitable via `GET /api/users/metadata`. Mitigation: upgrade to `3.39.25` or later.
CVE-2026-73301 Vulnerability in @budibase/server (CVE-2026-73301)
vulnerability in @budibase/server (CVE-2026-73301). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/global/groups`.
CVE-2026-73305 Privilege Escalation in @budibase/server (CVE-2026-73305)
vulnerability in @budibase/server (CVE-2026-73305). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/public/v1/roles/assign`.
CVE-2026-62379 Code Injection in org.openidentityplatform.openam:openam-core (CVE-2026-62379)
code injection in org.openidentityplatform.openam:openam-core (CVE-2026-62379). Risk of unauthorized operations or information disclosure. Exploitable via ``DSAMECallbackInterface``. Mitigation: upgrade to `16.1.2` or later.
CVE-2026-62280 Cross-Site Scripting (XSS) in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-62280)
cross-site scripting in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-62280). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.2` or later.
CVE-2026-62263 Unsafe Deserialization in org.openidentityplatform.openam:openam-auth-webauthn (CVE-2026-62263)
vulnerability in org.openidentityplatform.openam:openam-auth-webauthn (CVE-2026-62263). Risk of unauthorized operations or information disclosure. Exploitable via ``ObjectInputFilter``. Mitigation: upgrade to `16.1.2` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →