Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15186 |
|
Vulnerability in CVE-2026-15186 (CVE-2026-15186)
vulnerability in CVE-2026-15186 (CVE-2026-15186). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4256 |
|
Vulnerability in CVE-2026-4256 (CVE-2026-4256)
vulnerability in CVE-2026-4256 (CVE-2026-4256). Confidential information can be exposed externally.
|
| MAL-2026-10044 |
|
Vulnerability in chai-as-serialized (MAL-2026-10044)
vulnerability in chai-as-serialized (MAL-2026-10044). Risk of unauthorized operations or information disclosure. Exploitable via ``node``.
|
| CVE-2026-15185 |
|
Buffer Overflow in c (CVE-2026-15185)
vulnerability in c (CVE-2026-15185). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14261 |
|
Vulnerability in CVE-2026-14261 (CVE-2026-14261)
vulnerability in CVE-2026-14261 (CVE-2026-14261). Confidential information can be exposed externally.
|
| CVE-2026-12879 |
|
Vulnerability in CVE-2026-12879 (CVE-2026-12879)
vulnerability in CVE-2026-12879 (CVE-2026-12879). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12593 |
|
Vulnerability in CVE-2026-12593 (CVE-2026-12593)
vulnerability in CVE-2026-12593 (CVE-2026-12593). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/users/`.
|
| CVE-2026-15184 |
|
Vulnerability in c (CVE-2026-15184)
vulnerability in c (CVE-2026-15184). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12116 |
|
Vulnerability in CVE-2026-12116 (CVE-2026-12116)
vulnerability in CVE-2026-12116 (CVE-2026-12116). Successful exploitation can lead to full system takeover.
|
| MAL-2026-10040 |
|
Vulnerability in chai-as-balanced (MAL-2026-10040)
vulnerability in chai-as-balanced (MAL-2026-10040). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
|
| MAL-2026-10051 |
|
Vulnerability in chai-deflect (MAL-2026-10051)
vulnerability in chai-deflect (MAL-2026-10051). Risk of unauthorized operations or information disclosure. Exploitable via ``token``.
|
| MAL-2026-10045 |
|
Vulnerability in chai-as-sharpened (MAL-2026-10045)
vulnerability in chai-as-sharpened (MAL-2026-10045). Risk of unauthorized operations or information disclosure. Exploitable via ``node``.
|
| MAL-2026-10053 |
|
Vulnerability in chai-secure (MAL-2026-10053)
vulnerability in chai-secure (MAL-2026-10053). Risk of unauthorized operations or information disclosure. Exploitable via ``token``.
|
| MAL-2026-10054 |
|
Vulnerability in chai-smart (MAL-2026-10054)
vulnerability in chai-smart (MAL-2026-10054). Risk of unauthorized operations or information disclosure. Exploitable via ``node``.
|
| MAL-2026-10042 |
|
Vulnerability in chai-as-disarmed (MAL-2026-10042)
vulnerability in chai-as-disarmed (MAL-2026-10042). Risk of unauthorized operations or information disclosure. Exploitable via ``pino``.
|
| GHSA-hqh4-jccw-jxg6 |
|
Vulnerability in chai-defender (GHSA-hqh4-jccw-jxg6)
vulnerability in chai-defender (GHSA-hqh4-jccw-jxg6). Risk of unauthorized operations or information disclosure.
|
| GHSA-rh36-94jf-9566 |
|
Vulnerability in tailwind-animate-v4 (GHSA-rh36-94jf-9566)
vulnerability in tailwind-animate-v4 (GHSA-rh36-94jf-9566). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-10046 |
|
Vulnerability in chai-as-smart (MAL-2026-10046)
vulnerability in chai-as-smart (MAL-2026-10046). Risk of unauthorized operations or information disclosure. Exploitable via ``require``.
|
| MINI-g399-jhx6-775w |
|
MINI-g399-jhx6-775w |
| USN-8524-1 |
|
Vulnerability in python2.7 (USN-8524-1)
vulnerability in python2.7 (USN-8524-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.12-1ubuntu0~16.04.18+esm20` or later.
|
| MINI-33hh-hmhw-833f |
|
MINI-33hh-hmhw-833f |
| MINI-44cf-p77m-rfjh |
|
MINI-44cf-p77m-rfjh |
| MINI-jq69-mpp9-fj75 |
|
MINI-jq69-mpp9-fj75 |
| MINI-mhhm-7jmj-4w98 |
|
MINI-mhhm-7jmj-4w98 |
| MINI-927r-r45v-92m9 |
|
MINI-927r-r45v-92m9 |
| MINI-679f-74m6-2rwc |
|
MINI-679f-74m6-2rwc |
| MINI-8q3r-pq72-vw5h |
|
MINI-8q3r-pq72-vw5h |
| MINI-p36w-wq5q-whmm |
|
MINI-p36w-wq5q-whmm |
| MINI-426m-qrvg-v8j2 |
|
MINI-426m-qrvg-v8j2 |
| MINI-v8qh-mwfq-jf7j |
|
MINI-v8qh-mwfq-jf7j |
| MINI-5m62-567q-vrqx |
|
MINI-5m62-567q-vrqx |
| MINI-f72h-ph8r-6gg7 |
|
MINI-f72h-ph8r-6gg7 |
| MINI-3vwr-5pmx-wpgf |
|
MINI-3vwr-5pmx-wpgf |
| MINI-54r6-pr23-wcr5 |
|
MINI-54r6-pr23-wcr5 |
| MINI-qq4x-pv86-gfcw |
|
MINI-qq4x-pv86-gfcw |
| MINI-pwqw-3293-fcg9 |
|
MINI-pwqw-3293-fcg9 |
| BELL-CVE-2026-33630 |
|
BELL-CVE-2026-33630 |
| GHSA-r4hr-3frr-jgjv |
|
Vulnerability in txs-builder-lib (GHSA-r4hr-3frr-jgjv)
vulnerability in txs-builder-lib (GHSA-r4hr-3frr-jgjv). Risk of unauthorized operations or information disclosure.
|
| USN-8523-1 |
|
Vulnerability in libsoup2.4 (USN-8523-1)
vulnerability in libsoup2.4 (USN-8523-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.52.2-1ubuntu0.3+esm6` or later.
|
| GHSA-382c-vx95-w3p5 |
|
Vulnerability in @jsonbored/gittensory-mcp (GHSA-382c-vx95-w3p5)
vulnerability in @jsonbored/gittensory-mcp (GHSA-382c-vx95-w3p5). Confidential information can be exposed externally. Exploitable via `GET /v1/contributors/`.
|
| CVE-2026-53760 |
|
Cross-Site Request Forgery (CSRF) in admidio/admidio (CVE-2026-53760)
vulnerability in admidio/admidio (CVE-2026-53760). Data can be tampered with by attackers. Exploitable via ``mode``.
|
| GHSA-86vw-x4ww-x467 |
|
Code Injection in craftcms/cms (GHSA-86vw-x4ww-x467)
code injection in craftcms/cms (GHSA-86vw-x4ww-x467). Risk of unauthorized operations or information disclosure. Exploitable via `POST /admin/actions/fields/render-card-preview`. Mitigation: upgrade to `5.9.14` or later.
|
| GHSA-c43v-4cr8-6mvp |
|
Path Traversal in craftcms/cms (GHSA-c43v-4cr8-6mvp)
path traversal in craftcms/cms (GHSA-c43v-4cr8-6mvp). Risk of unauthorized operations or information disclosure. Exploitable via ``extension``. Mitigation: upgrade to `5.9.13` or later.
|
| CVE-2026-53727 |
|
SSRF (Server-Side Request Forgery) in css_parser (CVE-2026-53727)
SSRF in css_parser (CVE-2026-53727). Confidential information can be exposed externally. Exploitable via ``css_parser``. Mitigation: upgrade to `3.0.0` or later.
|
| CVE-2026-49485 |
|
Vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-49485)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-49485). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.9.4.2` or later.
|
| CVE-2026-53720 |
|
Vulnerability in pymonocypher (CVE-2026-53720)
vulnerability in pymonocypher (CVE-2026-53720). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.0.2.8` or later.
|
| CVE-2026-50553 |
|
Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-50553)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-50553). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/books`. Mitigation: upgrade to `0.0.0-20260601210719-67b7de04308a` or later.
|
| CVE-2026-50554 |
|
Information Disclosure in github.com/enchant97/note-mark/backend (CVE-2026-50554)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-50554). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/books/{bookID}/notes`. Mitigation: upgrade to `0.0.0-20260601210758-9c9b72740f22` or later.
|
| CVE-2026-49477 |
|
Vulnerability in soupsieve (CVE-2026-49477)
vulnerability in soupsieve (CVE-2026-49477). Risk of unauthorized operations or information disclosure. Exploitable via ``VALUE``. Mitigation: upgrade to `2.8.4` or later.
|
| CVE-2026-49476 |
|
Vulnerability in soupsieve (CVE-2026-49476)
vulnerability in soupsieve (CVE-2026-49476). Risk of unauthorized operations or information disclosure. Exploitable via ``CSSSelector``. Mitigation: upgrade to `2.8.4` or later.
|