Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14362 |
|
Vulnerability in CVE-2026-14362 (CVE-2026-14362)
vulnerability in CVE-2026-14362 (CVE-2026-14362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59938 |
|
Vulnerability in pypdf (CVE-2026-59938)
vulnerability in pypdf (CVE-2026-59938). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.14.0` or later.
|
| CVE-2026-59937 |
|
Vulnerability in pypdf (CVE-2026-59937)
vulnerability in pypdf (CVE-2026-59937). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.14.0` or later.
|
| MAL-2026-7016 |
|
Vulnerability in @vraksha/gh-helper (MAL-2026-7016)
vulnerability in @vraksha/gh-helper (MAL-2026-7016). Risk of unauthorized operations or information disclosure.
|
| RLSA-2026:36639 |
|
Vulnerability in nginx (RLSA-2026:36639)
vulnerability in nginx (RLSA-2026:36639). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2:1.26.3-9.module+el9.8.0+40194+40adfc1b` or later.
|
| openSUSE-SU-2026:21273-1 |
|
Vulnerability in xorg-x11-server (openSUSE-SU-2026:21273-1)
vulnerability in xorg-x11-server (openSUSE-SU-2026:21273-1). Risk of unauthorized operations or information disclosure. Exploitable via ``glamor_font_get``. Mitigation: upgrade to `21.1.15-160000.6.1` or later.
|
| GHSA-pgcc-398f-7cv2 |
|
Vulnerability in crypto-promiser (GHSA-pgcc-398f-7cv2)
vulnerability in crypto-promiser (GHSA-pgcc-398f-7cv2). Risk of unauthorized operations or information disclosure. Exploitable via ``node``.
|
| GHSA-vm7q-854p-gw38 |
|
Vulnerability in vps-new-manager (GHSA-vm7q-854p-gw38)
vulnerability in vps-new-manager (GHSA-vm7q-854p-gw38). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-7011 |
|
Vulnerability in events-alias (MAL-2026-7011)
vulnerability in events-alias (MAL-2026-7011). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
|
| MAL-2026-7009 |
|
Vulnerability in configration (MAL-2026-7009)
vulnerability in configration (MAL-2026-7009). Risk of unauthorized operations or information disclosure. Exploitable via ``pino``.
|
| CVE-2026-60102 |
|
OS Command Injection in c (CVE-2026-60102)
OS command injection in c (CVE-2026-60102). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59930 |
|
Vulnerability in mistune (CVE-2026-59930)
vulnerability in mistune (CVE-2026-59930). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59929 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-59929)
cross-site scripting in mistune (CVE-2026-59929). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59928 |
|
Vulnerability in mistune (CVE-2026-59928)
vulnerability in mistune (CVE-2026-59928). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59927 |
|
Vulnerability in mistune (CVE-2026-59927)
vulnerability in mistune (CVE-2026-59927). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59926 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-59926)
cross-site scripting in mistune (CVE-2026-59926). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59925 |
|
Vulnerability in mistune (CVE-2026-59925)
vulnerability in mistune (CVE-2026-59925). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59924 |
|
Path Traversal in mistune (CVE-2026-59924)
path traversal in mistune (CVE-2026-59924). Confidential information can be exposed externally. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59923 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-59923)
cross-site scripting in mistune (CVE-2026-59923). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59922 |
|
Vulnerability in mistune (CVE-2026-59922)
vulnerability in mistune (CVE-2026-59922). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-59897 |
|
Vulnerability in hono (CVE-2026-59897)
vulnerability in hono (CVE-2026-59897). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-59896 |
|
Vulnerability in hono (CVE-2026-59896)
vulnerability in hono (CVE-2026-59896). Confidential information can be exposed externally. Exploitable via ``await``. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-59895 |
|
Cross-Site Scripting (XSS) in hono (CVE-2026-59895)
cross-site scripting in hono (CVE-2026-59895). Risk of unauthorized operations or information disclosure. Exploitable via ``class``. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-59892 |
|
Vulnerability in @opentelemetry/propagator-jaeger (CVE-2026-59892)
vulnerability in @opentelemetry/propagator-jaeger (CVE-2026-59892). Risk of unauthorized operations or information disclosure. Exploitable via ``URIError``. Mitigation: upgrade to `2.9.0` or later.
|
| CVE-2026-59890 |
|
Vulnerability in setuptools (CVE-2026-59890)
vulnerability in setuptools (CVE-2026-59890). Confidential information can be exposed externally. Exploitable via ``FileList``. Mitigation: upgrade to `83.0.0` or later.
|
| CVE-2026-59887 |
|
Vulnerability in linkify-it (CVE-2026-59887)
vulnerability in linkify-it (CVE-2026-59887). Risk of unauthorized operations or information disclosure. Exploitable via ``src_email_name``. Mitigation: upgrade to `5.0.2` or later.
|
| CVE-2026-59883 |
|
Information Disclosure in guzzlehttp/guzzle (CVE-2026-59883)
vulnerability in guzzlehttp/guzzle (CVE-2026-59883). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.12.3` or later.
|
| CVE-2026-59882 |
|
Vulnerability in guzzlehttp/psr7 (CVE-2026-59882)
vulnerability in guzzlehttp/psr7 (CVE-2026-59882). Risk of unauthorized operations or information disclosure. Exploitable via ``SERVER_NAME``. Mitigation: upgrade to `2.12.3` or later.
|
| CVE-2026-59879 |
|
Vulnerability in immutable (CVE-2026-59879)
vulnerability in immutable (CVE-2026-59879). Risk of unauthorized operations or information disclosure. Exploitable via ``set``. Mitigation: upgrade to `5.1.8` or later.
|
| CVE-2026-59731 |
|
Vulnerability in astro (CVE-2026-59731)
vulnerability in astro (CVE-2026-59731). Confidential information can be exposed externally. Mitigation: upgrade to `6.4.8` or later.
|
| CVE-2026-59261 |
|
Vulnerability in openclaw (CVE-2026-59261)
vulnerability in openclaw (CVE-2026-59261). Confidential information can be exposed externally.
|
| CVE-2026-42505 |
|
Vulnerability in golang (CVE-2026-42505)
vulnerability in golang (CVE-2026-42505). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39822 |
|
Vulnerability in golang (CVE-2026-39822)
vulnerability in golang (CVE-2026-39822). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29009 |
|
Vulnerability in c (CVE-2026-29009)
vulnerability in c (CVE-2026-29009). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29008 |
|
Vulnerability in c (CVE-2026-29008)
vulnerability in c (CVE-2026-29008). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29007 |
|
Out-of-Bounds Read in c (CVE-2026-29007)
vulnerability in c (CVE-2026-29007). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-3110 |
|
Vulnerability in openvpn (CVE-2025-3110)
vulnerability in openvpn (CVE-2025-3110). Data can be tampered with by attackers.
|
| USN-8518-1 |
|
Vulnerability in mailcap (USN-8518-1)
vulnerability in mailcap (USN-8518-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.70+nmu1ubuntu1.22.04.1` or later.
|
| MAL-2026-6988 |
|
Vulnerability in @vite-tab/tab (MAL-2026-6988)
vulnerability in @vite-tab/tab (MAL-2026-6988). Risk of unauthorized operations or information disclosure. Exploitable via ``vite``.
|
| MAL-2026-7015 |
|
Vulnerability in turbom (MAL-2026-7015)
vulnerability in turbom (MAL-2026-7015). Risk of unauthorized operations or information disclosure.
|
| MGASA-2026-0236 |
|
Vulnerability in openvpn (MGASA-2026-0236)
vulnerability in openvpn (MGASA-2026-0236). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.21-1.mga10` or later.
|
| MGASA-2026-0237 |
|
Vulnerability in vips (MGASA-2026-0237)
vulnerability in vips (MGASA-2026-0237). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.18.3-1.mga10` or later.
|
| MAL-2026-6996 |
|
Vulnerability in ec-checker (MAL-2026-6996)
vulnerability in ec-checker (MAL-2026-6996). Risk of unauthorized operations or information disclosure. Exploitable via ``dsn``.
|
| GHSA-89c7-5mf7-c86r |
|
Vulnerability in chai-redirection (GHSA-89c7-5mf7-c86r)
vulnerability in chai-redirection (GHSA-89c7-5mf7-c86r). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
|
| MAL-2026-6994 |
|
Vulnerability in chai-presentation (MAL-2026-6994)
vulnerability in chai-presentation (MAL-2026-6994). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
|
| GHSA-85x8-7x9f-f978 |
|
Vulnerability in airkey-mfa-react (GHSA-85x8-7x9f-f978)
vulnerability in airkey-mfa-react (GHSA-85x8-7x9f-f978). Risk of unauthorized operations or information disclosure. Exploitable via ``index.js``.
|
| MAL-2026-7000 |
|
Vulnerability in pipo-sdk (MAL-2026-7000)
vulnerability in pipo-sdk (MAL-2026-7000). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
|
| MAL-2026-6997 |
|
Vulnerability in goofy-sdk (MAL-2026-6997)
vulnerability in goofy-sdk (MAL-2026-6997). Risk of unauthorized operations or information disclosure.
|
| GHSA-pgh8-mm8r-r796 |
|
Vulnerability in @luminarycloudinternal/lcvis-st (GHSA-pgh8-mm8r-r796)
vulnerability in @luminarycloudinternal/lcvis-st (GHSA-pgh8-mm8r-r796). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6993 |
|
Vulnerability in bytefaas-sdk (MAL-2026-6993)
vulnerability in bytefaas-sdk (MAL-2026-6993). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
|