Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15374 |
|
Vulnerability in CVE-2026-15374 (CVE-2026-15374)
vulnerability in CVE-2026-15374 (CVE-2026-15374). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15373 |
|
Vulnerability in CVE-2026-15373 (CVE-2026-15373)
vulnerability in CVE-2026-15373 (CVE-2026-15373). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15143 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15143 (CVE-2026-15143)
SSRF in CVE-2026-15143 (CVE-2026-15143). Confidential information can be exposed externally.
|
| MAL-2026-10132 |
|
Vulnerability in react-jsonwebtoken (MAL-2026-10132)
vulnerability in react-jsonwebtoken (MAL-2026-10132). Risk of unauthorized operations or information disclosure.
|
| GHSA-w572-cxjv-46jc |
|
Vulnerability in mdb-vite (GHSA-w572-cxjv-46jc)
vulnerability in mdb-vite (GHSA-w572-cxjv-46jc). Risk of unauthorized operations or information disclosure. Exploitable via ``getPlugin``.
|
| GHSA-hg4h-mv37-7x88 |
|
Vulnerability in polygon-gamma-apis (GHSA-hg4h-mv37-7x88)
vulnerability in polygon-gamma-apis (GHSA-hg4h-mv37-7x88). Risk of unauthorized operations or information disclosure. Exploitable via ``getPlugin``.
|
| GHSA-pvwq-8chv-g96r |
|
Vulnerability in polygon-gama-apis (GHSA-pvwq-8chv-g96r)
vulnerability in polygon-gama-apis (GHSA-pvwq-8chv-g96r). Risk of unauthorized operations or information disclosure.
|
| GHSA-59wg-mh66-248p |
|
Vulnerability in polymarket-gamma-apis (GHSA-59wg-mh66-248p)
vulnerability in polymarket-gamma-apis (GHSA-59wg-mh66-248p). Risk of unauthorized operations or information disclosure.
|
| GHSA-hwmr-cmgq-wr7x |
|
Vulnerability in marked-prettier (GHSA-hwmr-cmgq-wr7x)
vulnerability in marked-prettier (GHSA-hwmr-cmgq-wr7x). Risk of unauthorized operations or information disclosure. Exploitable via ``marked``.
|
| GHSA-m3v6-5prj-x7rp |
|
Vulnerability in eslint-jest (GHSA-m3v6-5prj-x7rp)
vulnerability in eslint-jest (GHSA-m3v6-5prj-x7rp). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49977 |
|
Vulnerability in tarteaucitronjs (CVE-2026-49977)
vulnerability in tarteaucitronjs (CVE-2026-49977). Risk of unauthorized operations or information disclosure. Exploitable via ``purgeBtn``. Mitigation: upgrade to `1.33.0` or later.
|
| CVE-2026-49865 |
|
SSRF (Server-Side Request Forgery) in kimai/kimai (CVE-2026-49865)
SSRF in kimai/kimai (CVE-2026-49865). Risk of unauthorized operations or information disclosure. Exploitable via ``Customer.invoiceText``. Mitigation: upgrade to `2.58.0` or later.
|
| MAL-2026-10139 |
|
Vulnerability in turbocalc (MAL-2026-10139)
vulnerability in turbocalc (MAL-2026-10139). Risk of unauthorized operations or information disclosure.
|
| GHSA-v8j2-pw9x-xx7p |
|
Vulnerability in express-session-kit (GHSA-v8j2-pw9x-xx7p)
vulnerability in express-session-kit (GHSA-v8j2-pw9x-xx7p). Risk of unauthorized operations or information disclosure. Exploitable via ``node``.
|
| MGASA-2026-0240 |
|
Vulnerability in vim (MGASA-2026-0240)
vulnerability in vim (MGASA-2026-0240). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.782-1.mga10` or later.
|
| ROOT-APP-NPM-CVE-2026-27148 |
|
Vulnerability in @rootio/storybook (ROOT-APP-NPM-CVE-2026-27148)
vulnerability in @rootio/storybook (ROOT-APP-NPM-CVE-2026-27148). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.1.15-root.io.1` or later.
|
| ROOT-APP-NPM-CVE-2025-68429 |
|
Vulnerability in @rootio/storybook (ROOT-APP-NPM-CVE-2025-68429)
vulnerability in @rootio/storybook (ROOT-APP-NPM-CVE-2025-68429). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.1.15-root.io.1` or later.
|
| CVE-2026-61456 |
|
Cross-Site Scripting (XSS) in CVE-2026-61456 (CVE-2026-61456)
cross-site scripting in CVE-2026-61456 (CVE-2026-61456). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/media`.
|
| CVE-2026-61492 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-61492)
cross-site scripting in jetbrains (CVE-2026-61492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61434 |
|
OS Command Injection in CVE-2026-61434 (CVE-2026-61434)
OS command injection in CVE-2026-61434 (CVE-2026-61434). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61455 |
|
Vulnerability in dos (CVE-2026-61455)
vulnerability in dos (CVE-2026-61455). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61441 |
|
Vulnerability in CVE-2026-61441 (CVE-2026-61441)
vulnerability in CVE-2026-61441 (CVE-2026-61441). Data can be tampered with by attackers.
|
| CVE-2026-61450 |
|
Code Injection in CVE-2026-61450 (CVE-2026-61450)
code injection in CVE-2026-61450 (CVE-2026-61450). Confidential information can be exposed externally.
|
| CVE-2026-61444 |
|
Code Injection in CVE-2026-61444 (CVE-2026-61444)
code injection in CVE-2026-61444 (CVE-2026-61444). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61437 |
|
Vulnerability in CVE-2026-61437 (CVE-2026-61437)
vulnerability in CVE-2026-61437 (CVE-2026-61437). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61432 |
|
Path Traversal in path-traversal (CVE-2026-61432)
path traversal in path-traversal (CVE-2026-61432). Confidential information can be exposed externally.
|
| CVE-2026-60091 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-60091)
SSRF in ssrf (CVE-2026-60091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59794 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-59794)
cross-site scripting in jetbrains (CVE-2026-59794). Confidential information can be exposed externally.
|
| CVE-2026-61431 |
|
Path Traversal in path-traversal (CVE-2026-61431)
path traversal in path-traversal (CVE-2026-61431). Confidential information can be exposed externally.
|
| CVE-2026-59793 |
|
Vulnerability in jetbrains (CVE-2026-59793)
vulnerability in jetbrains (CVE-2026-59793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60089 |
|
Path Traversal in CVE-2026-60089 (CVE-2026-60089)
path traversal in CVE-2026-60089 (CVE-2026-60089). Data can be tampered with by attackers.
|
| CVE-2026-60086 |
|
Vulnerability in CVE-2026-60086 (CVE-2026-60086)
vulnerability in CVE-2026-60086 (CVE-2026-60086). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59792 |
|
Vulnerability in path-traversal (CVE-2026-59792)
vulnerability in path-traversal (CVE-2026-59792). Confidential information can be exposed externally.
|
| CVE-2026-59796 |
|
Vulnerability in jetbrains (CVE-2026-59796)
vulnerability in jetbrains (CVE-2026-59796). Confidential information can be exposed externally.
|
| CVE-2026-59795 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-59795)
cross-site scripting in jetbrains (CVE-2026-59795). Confidential information can be exposed externally.
|
| CVE-2026-58661 |
|
Vulnerability in n8n (CVE-2026-58661)
vulnerability in n8n (CVE-2026-58661). Risk of unauthorized operations or information disclosure. Exploitable via ``uploadMaxFileSize``. Mitigation: upgrade to `1.123.58` or later.
|
| CVE-2026-59791 |
|
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
|
| CVE-2026-56366 |
|
Vulnerability in dos (CVE-2026-56366)
vulnerability in dos (CVE-2026-56366). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57994 |
|
Information Disclosure in CVE-2026-57994 (CVE-2026-57994)
vulnerability in CVE-2026-57994 (CVE-2026-57994). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v3.1/faq/{categoryId}/{faqId}`.
|
| CVE-2026-56373 |
|
Use-After-Free in Magick.NET-Q16-AnyCPU (CVE-2026-56373)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-56373). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.10.3` or later.
|
| CVE-2026-56765 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-56765)
vulnerability in code.vikunja.io/api (CVE-2026-56765). Confidential information can be exposed externally.
|
| CVE-2026-57961 |
|
Path Traversal in path-traversal (CVE-2026-57961)
path traversal in path-traversal (CVE-2026-57961). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56354 |
|
Open Redirect in n8n (CVE-2026-56354)
vulnerability in n8n (CVE-2026-56354). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `1.123.24` or later.
|
| CVE-2026-56329 |
|
Vulnerability in CVE-2026-56329 (CVE-2026-56329)
vulnerability in CVE-2026-56329 (CVE-2026-56329). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56335 |
|
Vulnerability in CVE-2026-56335 (CVE-2026-56335)
vulnerability in CVE-2026-56335 (CVE-2026-56335). Data can be tampered with by attackers.
|
| CVE-2026-56279 |
|
Vulnerability in CVE-2026-56279 (CVE-2026-56279)
vulnerability in CVE-2026-56279 (CVE-2026-56279). Confidential information can be exposed externally.
|
| CVE-2026-56261 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-56261)
SSRF in ssrf (CVE-2026-56261). Confidential information can be exposed externally.
|
| CVE-2026-56254 |
|
Vulnerability in CVE-2026-56254 (CVE-2026-56254)
vulnerability in CVE-2026-56254 (CVE-2026-56254). Data can be tampered with by attackers.
|
| CVE-2026-56309 |
|
Vulnerability in CVE-2026-56309 (CVE-2026-56309)
vulnerability in CVE-2026-56309 (CVE-2026-56309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38057 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-38057)
vulnerability in csrf (CVE-2026-38057). Data can be tampered with by attackers.
|