Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
GHSA-cpff-p65h-24c4 Vulnerability in searchresults (GHSA-cpff-p65h-24c4)
vulnerability in searchresults (GHSA-cpff-p65h-24c4). Risk of unauthorized operations or information disclosure.
openSUSE-SU-2026:21276-1 Vulnerability in apptainer (openSUSE-SU-2026:21276-1)
vulnerability in apptainer (openSUSE-SU-2026:21276-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.1-bp160.2.1` or later.
openSUSE-SU-2026:21277-1 Vulnerability in go-sendxmpp (openSUSE-SU-2026:21277-1)
vulnerability in go-sendxmpp (openSUSE-SU-2026:21277-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.16.0-bp160.1.1` or later.
MAL-2026-7004 Vulnerability in thunder-rony (MAL-2026-7004)
vulnerability in thunder-rony (MAL-2026-7004). Risk of unauthorized operations or information disclosure.
MAL-2026-7002 Vulnerability in ronyfortest (MAL-2026-7002)
vulnerability in ronyfortest (MAL-2026-7002). Risk of unauthorized operations or information disclosure.
MAL-2026-7001 Vulnerability in rony-test (MAL-2026-7001)
vulnerability in rony-test (MAL-2026-7001). Risk of unauthorized operations or information disclosure.
GHSA-6c7j-c4j8-rgq3 Vulnerability in higherlogic-ocfe (GHSA-6c7j-c4j8-rgq3)
vulnerability in higherlogic-ocfe (GHSA-6c7j-c4j8-rgq3). Risk of unauthorized operations or information disclosure. Exploitable via ``index.js``.
GHSA-xr98-72p4-pwg2 Vulnerability in babel-eslint-parser-legacy (GHSA-xr98-72p4-pwg2)
vulnerability in babel-eslint-parser-legacy (GHSA-xr98-72p4-pwg2). Risk of unauthorized operations or information disclosure. Exploitable via ``main``.
GHSA-p9cr-rm9c-q8mg Vulnerability in ag-charts-test (GHSA-p9cr-rm9c-q8mg)
vulnerability in ag-charts-test (GHSA-p9cr-rm9c-q8mg). Risk of unauthorized operations or information disclosure. Exploitable via ``ltidisafe``.
GHSA-jx6g-7h69-4334 Vulnerability in visa-cli-tools (GHSA-jx6g-7h69-4334)
vulnerability in visa-cli-tools (GHSA-jx6g-7h69-4334). Risk of unauthorized operations or information disclosure.
MAL-2026-6990 Vulnerability in ai-gen-ai-opt-in (MAL-2026-6990)
vulnerability in ai-gen-ai-opt-in (MAL-2026-6990). Risk of unauthorized operations or information disclosure.
GHSA-p92p-63h9-qrvc Vulnerability in @luminarycloudinternal/frodo (GHSA-p92p-63h9-qrvc)
vulnerability in @luminarycloudinternal/frodo (GHSA-p92p-63h9-qrvc). Risk of unauthorized operations or information disclosure.
CVE-2026-9074 SQL Injection in sqli (CVE-2026-9074)
SQL injection in sqli (CVE-2026-9074). Confidential information can be exposed externally.
CVE-2026-59880 Vulnerability in immutable (CVE-2026-59880)
vulnerability in immutable (CVE-2026-59880). Risk of unauthorized operations or information disclosure. Exploitable via ``Immutable.Map``. Mitigation: upgrade to `5.1.8` or later.
CVE-2026-59877 Vulnerability in protobufjs (CVE-2026-59877)
vulnerability in protobufjs (CVE-2026-59877). Risk of unauthorized operations or information disclosure. Exploitable via ``parse``. Mitigation: upgrade to `8.6.6` or later.
CVE-2026-59876 Vulnerability in protobufjs (CVE-2026-59876)
vulnerability in protobufjs (CVE-2026-59876). Risk of unauthorized operations or information disclosure. Exploitable via ``__proto__``. Mitigation: upgrade to `8.6.5` or later.
CVE-2026-59875 Vulnerability in tar (CVE-2026-59875)
vulnerability in tar (CVE-2026-59875). Risk of unauthorized operations or information disclosure. Exploitable via ``NUL``. Mitigation: upgrade to `7.5.17` or later.
CVE-2026-59874 Vulnerability in tar (CVE-2026-59874)
vulnerability in tar (CVE-2026-59874). Risk of unauthorized operations or information disclosure. Exploitable via ``poc.mjs``. Mitigation: upgrade to `7.5.18` or later.
CVE-2026-59873 Vulnerability in tar (CVE-2026-59873)
vulnerability in tar (CVE-2026-59873). Risk of unauthorized operations or information disclosure. Exploitable via ``maxReadSize``. Mitigation: upgrade to `7.5.19` or later.
CVE-2026-59871 Vulnerability in tar (CVE-2026-59871)
vulnerability in tar (CVE-2026-59871). Risk of unauthorized operations or information disclosure. Exploitable via ``pax.ts``. Mitigation: upgrade to `7.5.18` or later.
CVE-2026-59870 Vulnerability in js-yaml (CVE-2026-59870)
vulnerability in js-yaml (CVE-2026-59870). Risk of unauthorized operations or information disclosure. Exploitable via ``YAML11_SCHEMA``. Mitigation: upgrade to `5.2.1` or later.
CVE-2026-59869 Vulnerability in js-yaml (CVE-2026-59869)
vulnerability in js-yaml (CVE-2026-59869). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.3.0` or later.
CVE-2026-59868 Vulnerability in js-yaml (CVE-2026-59868)
vulnerability in js-yaml (CVE-2026-59868). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.2.0` or later.
CVE-2026-59725 Vulnerability in engine.io (CVE-2026-59725)
vulnerability in engine.io (CVE-2026-59725). Risk of unauthorized operations or information disclosure. Exploitable via ``POST``. Mitigation: upgrade to `6.6.7` or later.
CVE-2026-59724 Vulnerability in dos (CVE-2026-59724)
vulnerability in dos (CVE-2026-59724). Risk of unauthorized operations or information disclosure.
CVE-2026-59702 SSRF (Server-Side Request Forgery) in CVE-2026-59702 (CVE-2026-59702)
SSRF in CVE-2026-59702 (CVE-2026-59702). Confidential information can be exposed externally. Exploitable via `POST /api/pack`.
CVE-2026-59262 Vulnerability in CVE-2026-59262 (CVE-2026-59262)
vulnerability in CVE-2026-59262 (CVE-2026-59262). Confidential information can be exposed externally.
CVE-2026-57439 Cross-Site Scripting (XSS) in CVE-2026-57439 (CVE-2026-57439)
cross-site scripting in CVE-2026-57439 (CVE-2026-57439). Risk of unauthorized operations or information disclosure.
CVE-2026-55761 Authentication Bypass in github.com/portainer/portainer (CVE-2026-55761)
authentication bypass in github.com/portainer/portainer (CVE-2026-55761). Data can be tampered with by attackers. Exploitable via ``bouncer.PublicAccess``. Mitigation: upgrade to `2.43.0` or later.
CVE-2026-54344 OS Command Injection in tooljet (CVE-2026-54344)
OS command injection in tooljet (CVE-2026-54344). Risk of unauthorized operations or information disclosure.
CVE-2026-53951 Path Traversal in copier (CVE-2026-53951)
path traversal in copier (CVE-2026-53951). Risk of unauthorized operations or information disclosure. Exploitable via ``trust``. Mitigation: upgrade to `9.15.2` or later.
CVE-2026-49946 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49945 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49944 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-3144 Vulnerability in ibm (CVE-2026-3144)
vulnerability in ibm (CVE-2026-3144). Successful exploitation can lead to full system takeover.
CVE-2026-15063 Vulnerability in CVE-2026-15063 (CVE-2026-15063)
vulnerability in CVE-2026-15063 (CVE-2026-15063). Confidential information can be exposed externally.
CVE-2026-14967 Path Traversal in blacklanternsecurity (CVE-2026-14967)
path traversal in blacklanternsecurity (CVE-2026-14967). Risk of unauthorized operations or information disclosure. Exploitable via ``github_workflows``.
CVE-2026-14966 Vulnerability in dos (CVE-2026-14966)
vulnerability in dos (CVE-2026-14966). Risk of unauthorized operations or information disclosure.
GHSA-mvg5-c69w-jg7r Vulnerability in promo-helper (GHSA-mvg5-c69w-jg7r)
vulnerability in promo-helper (GHSA-mvg5-c69w-jg7r). Risk of unauthorized operations or information disclosure.
MAL-2026-7007 Vulnerability in manom (MAL-2026-7007)
vulnerability in manom (MAL-2026-7007). Risk of unauthorized operations or information disclosure.
MAL-2026-7006 Vulnerability in manik (MAL-2026-7006)
vulnerability in manik (MAL-2026-7006). Risk of unauthorized operations or information disclosure.
CGA-23h4-ww2p-gfpp CGA-23h4-ww2p-gfpp
CGA-6hrx-9cj4-59h7 CGA-6hrx-9cj4-59h7
CGA-m5ww-jfp3-9662 CGA-m5ww-jfp3-9662
CGA-8pcp-6v8x-3c72 CGA-8pcp-6v8x-3c72
CGA-xh79-5f4m-4w3c CGA-xh79-5f4m-4w3c
CGA-j62p-ggp9-r2jg CGA-j62p-ggp9-r2jg
CVE-2026-49145 Vulnerability in CVE-2026-49145 (CVE-2026-49145)
vulnerability in CVE-2026-49145 (CVE-2026-49145). Risk of unauthorized operations or information disclosure.
CVE-2026-56374 Out-of-Bounds Read in Magick.NET-Q16-AnyCPU (CVE-2026-56374)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-56374). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.12.0` or later.
CVE-2026-56776 Vulnerability in n8n (CVE-2026-56776)
vulnerability in n8n (CVE-2026-56776). Risk of unauthorized operations or information disclosure. Exploitable via `POST /workflows/{workflowId}/test-runs/new`. Mitigation: upgrade to `2.25.7` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →