Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73414 |
|
OS Command Injection in shescape (CVE-2026-73414)
OS command injection in shescape (CVE-2026-73414). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73412 |
|
OS Command Injection in shescape (CVE-2026-73412)
OS command injection in shescape (CVE-2026-73412). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-69160 |
|
Vulnerability in github.com/OpenListTeam/OpenList/v4 (CVE-2026-69160)
vulnerability in github.com/OpenListTeam/OpenList/v4 (CVE-2026-69160). Confidential information can be exposed externally. Exploitable via `POST /api/share/create`. Mitigation: upgrade to `4.2.4` or later.
|
| GHSA-p6ph-3jx2-3337 |
|
Information Disclosure in github.com/OpenListTeam/OpenList/v4 (GHSA-p6ph-3jx2-3337)
vulnerability in github.com/OpenListTeam/OpenList/v4 (GHSA-p6ph-3jx2-3337). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/fs/search`. Mitigation: upgrade to `4.2.4` or later.
|
| CVE-2026-73509 |
|
Path Traversal in github.com/OpenListTeam/OpenList/v4 (CVE-2026-73509)
path traversal in github.com/OpenListTeam/OpenList/v4 (CVE-2026-73509). Data can be tampered with by attackers. Exploitable via ``new_name``. Mitigation: upgrade to `4.2.4` or later.
|
| CVE-2026-73493 |
|
Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `1.0.0-M42` or later.
|
| CVE-2026-73495 |
|
Vulnerability in org.http4s:blaze-http_2.13 (CVE-2026-73495)
vulnerability in org.http4s:blaze-http_2.13 (CVE-2026-73495). Confidential information can be exposed externally. Exploitable via ``Request.headers``. Mitigation: upgrade to `1.0.0-M42` or later.
|
| CVE-2026-73494 |
|
Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73494)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73494). Risk of unauthorized operations or information disclosure. Exploitable via ``BlazeServerBuilder``. Mitigation: upgrade to `0.23.18` or later.
|
| CVE-2026-55985 |
|
Vulnerability in CVE-2026-55985 (CVE-2026-55985)
vulnerability in CVE-2026-55985 (CVE-2026-55985). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71408 |
|
Vulnerability in nltk (CVE-2025-71408)
vulnerability in nltk (CVE-2025-71408). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.3` or later.
|
| GHSA-cmwh-g2h8-c222 |
|
Authentication Bypass in poweradmin/poweradmin (GHSA-cmwh-g2h8-c222)
authentication bypass in poweradmin/poweradmin (GHSA-cmwh-g2h8-c222). Risk of unauthorized operations or information disclosure. Exploitable via `GET /oidc/login`. Mitigation: upgrade to `4.2.5` or later.
|
| GHSA-rm67-g9ch-vxff |
|
Vulnerability in poweradmin/poweradmin (GHSA-rm67-g9ch-vxff)
vulnerability in poweradmin/poweradmin (GHSA-rm67-g9ch-vxff). Risk of unauthorized operations or information disclosure. Exploitable via `POST /zones/3/edit`. Mitigation: upgrade to `4.3.4` or later.
|
| GHSA-h4hf-v6w5-897x |
|
Vulnerability in poweradmin/poweradmin (GHSA-h4hf-v6w5-897x)
vulnerability in poweradmin/poweradmin (GHSA-h4hf-v6w5-897x). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/v2/users/{id}`. Mitigation: upgrade to `4.3.4` or later.
|
| GHSA-f25v-x6vr-962g |
|
Vulnerability in pheditor/pheditor (GHSA-f25v-x6vr-962g)
vulnerability in pheditor/pheditor (GHSA-f25v-x6vr-962g). Risk of unauthorized operations or information disclosure. Exploitable via ``admin``. Mitigation: upgrade to `2.0.7` or later.
|
| CVE-2026-73567 |
|
Vulnerability in sm-crypto (CVE-2026-73567)
vulnerability in sm-crypto (CVE-2026-73567). Confidential information can be exposed externally. Exploitable via ``SecureRandom``. Mitigation: upgrade to `0.5.0` or later.
|
| GHSA-v6w6-358x-2433 |
|
Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (GHSA-v6w6-358x-2433)
vulnerability in github.com/cloudreve/Cloudreve/v4 (GHSA-v6w6-358x-2433). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v4/admin/node`. Mitigation: upgrade to `4.0.0-20260626022735-332a9d800205` or later.
|
| CVE-2026-73652 |
|
Authorization Flaw in vantage6 (CVE-2026-73652)
vulnerability in vantage6 (CVE-2026-73652). Risk of unauthorized operations or information disclosure.
|
| GHSA-2625-rw7m-5q5x |
|
Vulnerability in hubuum_client (GHSA-2625-rw7m-5q5x)
vulnerability in hubuum_client (GHSA-2625-rw7m-5q5x). Risk of unauthorized operations or information disclosure. Exploitable via ``hubuum_client``. Mitigation: upgrade to `0.6.1` or later.
|
| GHSA-qqc3-94qv-7fw3 |
|
Vulnerability in hubuum_client (GHSA-qqc3-94qv-7fw3)
vulnerability in hubuum_client (GHSA-qqc3-94qv-7fw3). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.1` or later.
|
| GHSA-f45q-w629-wr25 |
|
Information Disclosure in hubuum_client (GHSA-f45q-w629-wr25)
vulnerability in hubuum_client (GHSA-f45q-w629-wr25). Risk of unauthorized operations or information disclosure. Exploitable via ``BaseUrl``. Mitigation: upgrade to `0.6.1` or later.
|
| CVE-2026-73564 |
|
Vulnerability in github.com/fatedier/frp (CVE-2026-73564)
vulnerability in github.com/fatedier/frp (CVE-2026-73564). Risk of unauthorized operations or information disclosure. Exploitable via ``frps``. Mitigation: upgrade to `0.70.1` or later.
|
| CVE-2026-73561 |
|
Vulnerability in @anephenix/hub (CVE-2026-73561)
vulnerability in @anephenix/hub (CVE-2026-73561). Risk of unauthorized operations or information disclosure. Exploitable via ``setInterval``. Mitigation: upgrade to `0.2.16` or later.
|
| GHSA-c534-2w9c-x7fm |
|
Vulnerability in github.com/zxh326/kite (GHSA-c534-2w9c-x7fm)
vulnerability in github.com/zxh326/kite (GHSA-c534-2w9c-x7fm). Risk of unauthorized operations or information disclosure. Exploitable via ``get``. Mitigation: upgrade to `0.14.1` or later.
|
| CVE-2026-73644 |
|
Vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644)
vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644). Confidential information can be exposed externally. Mitigation: upgrade to `5.1.2` or later.
|
| GHSA-68r5-9hpg-7qw9 |
|
Vulnerability in org.openidentityplatform.opendj:opendj-dsml-servlet (GHSA-68r5-9hpg-7qw9)
vulnerability in org.openidentityplatform.opendj:opendj-dsml-servlet (GHSA-68r5-9hpg-7qw9). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.1.2` or later.
|
| GHSA-g3hq-hphg-8fhh |
|
OS Command Injection in pheditor/pheditor (GHSA-g3hq-hphg-8fhh)
OS command injection in pheditor/pheditor (GHSA-g3hq-hphg-8fhh). Risk of unauthorized operations or information disclosure. Exploitable via ``TERMINAL_COMMANDS``. Mitigation: upgrade to `2.0.7` or later.
|
| GHSA-94p4-4cq8-9g67 |
|
Information Disclosure in GitPython (GHSA-94p4-4cq8-9g67)
vulnerability in GitPython (GHSA-94p4-4cq8-9g67). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `3.1.55` or later.
|
| CVE-2026-73307 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-73307)
SSRF in @budibase/server (CVE-2026-73307). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73410 |
|
Vulnerability in @budibase/server (CVE-2026-73410)
vulnerability in @budibase/server (CVE-2026-73410). Successful exploitation can lead to full system takeover. Exploitable via ``fetchWithBlacklist``.
|
| GHSA-pmpg-2mxq-6xwr |
|
SQL Injection in @budibase/server (GHSA-pmpg-2mxq-6xwr)
SQL injection in @budibase/server (GHSA-pmpg-2mxq-6xwr). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/queries/`.
|
| CVE-2026-73306 |
|
Vulnerability in @budibase/server (CVE-2026-73306)
vulnerability in @budibase/server (CVE-2026-73306). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/global/auth/`.
|
| GHSA-pvcr-8mvp-w8qr |
|
Vulnerability in @budibase/server (GHSA-pvcr-8mvp-w8qr)
vulnerability in @budibase/server (GHSA-pvcr-8mvp-w8qr). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/chat-links/`.
|
| GHSA-2xgg-r2wc-c5r2 |
|
SQL Injection in @budibase/server (GHSA-2xgg-r2wc-c5r2)
SQL injection in @budibase/server (GHSA-2xgg-r2wc-c5r2). Risk of unauthorized operations or information disclosure. Exploitable via ``INFORMATION_SCHEMA.TABLES``.
|
| GHSA-qw6m-8fw2-2v64 |
|
Vulnerability in @budibase/server (GHSA-qw6m-8fw2-2v64)
vulnerability in @budibase/server (GHSA-qw6m-8fw2-2v64). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v2/queries/`.
|
| CVE-2026-73308 |
|
Information Disclosure in @budibase/server (CVE-2026-73308)
vulnerability in @budibase/server (CVE-2026-73308). Confidential information can be exposed externally. Exploitable via `GET /api/automations/`.
|
| CVE-2026-73406 |
|
Information Disclosure in @budibase/server (CVE-2026-73406)
vulnerability in @budibase/server (CVE-2026-73406). Confidential information can be exposed externally. Exploitable via `GET /api/global/users/tenant/`.
|
| GHSA-mqhr-6j6h-74p5 |
|
Information Disclosure in @budibase/server (GHSA-mqhr-6j6h-74p5)
vulnerability in @budibase/server (GHSA-mqhr-6j6h-74p5). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v2/queries/`.
|
| CVE-2026-62323 |
|
Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-62323)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-62323). Data can be tampered with by attackers. Exploitable via `PUT /api/v4/file/viewerSession`. Mitigation: upgrade to `4.0.0-20260626022433-f3347130ac48` or later.
|
| CVE-2026-73302 |
|
Authentication Bypass in @budibase/server (CVE-2026-73302)
authentication bypass in @budibase/server (CVE-2026-73302). Risk of unauthorized operations or information disclosure. Exploitable via `POST /realms/budi/protocol/openid-connect/token`.
|
| GHSA-xg5g-26x8-cvf4 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (GHSA-xg5g-26x8-cvf4)
SSRF in @budibase/server (GHSA-xg5g-26x8-cvf4). Risk of unauthorized operations or information disclosure. Exploitable via ``fetchFn``.
|
| GHSA-xcx6-4f2g-hhgx |
|
Authorization Flaw in @budibase/server (GHSA-xcx6-4f2g-hhgx)
vulnerability in @budibase/server (GHSA-xcx6-4f2g-hhgx). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/attachments/`.
|
| CVE-2026-73409 |
|
Vulnerability in @budibase/server (CVE-2026-73409)
vulnerability in @budibase/server (CVE-2026-73409). Risk of unauthorized operations or information disclosure. Exploitable via ``tlsCertificateKeyFile``.
|
| GHSA-q6x4-v3qx-85qw |
|
SQL Injection in @budibase/server (GHSA-q6x4-v3qx-85qw)
SQL injection in @budibase/server (GHSA-q6x4-v3qx-85qw). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73303 |
|
Vulnerability in @budibase/server (CVE-2026-73303)
vulnerability in @budibase/server (CVE-2026-73303). Confidential information can be exposed externally. Exploitable via `POST /api/v2/email`.
|
| CVE-2026-73304 |
|
Information Disclosure in @budibase/server (CVE-2026-73304)
vulnerability in @budibase/server (CVE-2026-73304). Confidential information can be exposed externally. Exploitable via `GET /api/users/metadata`. Mitigation: upgrade to `3.39.25` or later.
|
| CVE-2026-73301 |
|
Vulnerability in @budibase/server (CVE-2026-73301)
vulnerability in @budibase/server (CVE-2026-73301). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/global/groups`.
|
| CVE-2026-73305 |
|
Privilege Escalation in @budibase/server (CVE-2026-73305)
vulnerability in @budibase/server (CVE-2026-73305). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/public/v1/roles/assign`.
|
| CVE-2026-62379 |
|
Code Injection in org.openidentityplatform.openam:openam-core (CVE-2026-62379)
code injection in org.openidentityplatform.openam:openam-core (CVE-2026-62379). Risk of unauthorized operations or information disclosure. Exploitable via ``DSAMECallbackInterface``. Mitigation: upgrade to `16.1.2` or later.
|
| CVE-2026-62280 |
|
Cross-Site Scripting (XSS) in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-62280)
cross-site scripting in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-62280). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.2` or later.
|
| CVE-2026-62263 |
|
Unsafe Deserialization in org.openidentityplatform.openam:openam-auth-webauthn (CVE-2026-62263)
vulnerability in org.openidentityplatform.openam:openam-auth-webauthn (CVE-2026-62263). Risk of unauthorized operations or information disclosure. Exploitable via ``ObjectInputFilter``. Mitigation: upgrade to `16.1.2` or later.
|