Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-49452 |
|
Vulnerability in weasyprint (CVE-2026-49452)
vulnerability in weasyprint (CVE-2026-49452). Risk of unauthorized operations or information disclosure. Exploitable via ``background``.
|
| CVE-2026-40257 |
|
Out-of-Bounds Write in trustedfirmware (CVE-2026-40257)
out-of-bounds write in trustedfirmware (CVE-2026-40257). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-53831 |
|
Cross-Site Scripting (XSS) in CVE-2025-53831 (CVE-2025-53831)
cross-site scripting in CVE-2025-53831 (CVE-2025-53831). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-40257 |
|
Vulnerability in optee-os (UBUNTU-CVE-2026-40257)
vulnerability in optee-os (UBUNTU-CVE-2026-40257). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-43825 |
|
Vulnerability in apache-opennlp (UBUNTU-CVE-2026-43825)
vulnerability in apache-opennlp (UBUNTU-CVE-2026-43825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49445 |
|
Vulnerability in github.com/cilium/cilium (CVE-2026-49445)
vulnerability in github.com/cilium/cilium (CVE-2026-49445). Confidential information can be exposed externally. Mitigation: upgrade to `1.17.14` or later.
|
| CVE-2026-49439 |
|
Vulnerability in io.openremote:openremote-manager (CVE-2026-49439)
vulnerability in io.openremote:openremote-manager (CVE-2026-49439). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}`. Mitigation: upgrade to `1.24.1` or later.
|
| CVE-2026-52889 |
|
Vulnerability in verbb/formie (CVE-2026-52889)
vulnerability in verbb/formie (CVE-2026-52889). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.27` or later.
|
| CVE-2022-46292 |
|
Buffer Overflow in openbabel (CVE-2022-46292)
vulnerability in openbabel (CVE-2022-46292). Successful exploitation can lead to full system takeover. Exploitable via ``obabel``. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-5268 |
|
Vulnerability in CVE-2026-5268 (CVE-2026-5268)
vulnerability in CVE-2026-5268 (CVE-2026-5268). Confidential information can be exposed externally.
|
| CVE-2026-59196 |
|
Path Traversal in pnpm (CVE-2026-59196)
path traversal in pnpm (CVE-2026-59196). Data can be tampered with by attackers. Exploitable via ``node_modules``. Mitigation: upgrade to `11.7.0` or later.
|
| CVE-2026-59195 |
|
Path Traversal in pnpm (CVE-2026-59195)
path traversal in pnpm (CVE-2026-59195). Data can be tampered with by attackers. Exploitable via ``pnpm``. Mitigation: upgrade to `11.8.0` or later.
|
| CVE-2026-59194 |
|
Path Traversal in pnpm (CVE-2026-59194)
path traversal in pnpm (CVE-2026-59194). Data can be tampered with by attackers. Exploitable via ``patchedDependencies``. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-59152 |
|
Path Traversal in langsmith (CVE-2026-59152)
path traversal in langsmith (CVE-2026-59152). Confidential information can be exposed externally. Exploitable via ``TracingMiddleware``. Mitigation: upgrade to `0.8.18` or later.
|
| CVE-2026-58203 |
|
Path Traversal in pydantic-settings (CVE-2026-58203)
path traversal in pydantic-settings (CVE-2026-58203). Risk of unauthorized operations or information disclosure. Exploitable via ``NestedSecretsSettingsSource``. Mitigation: upgrade to `2.14.2` or later.
|
| CVE-2026-13122 |
|
Vulnerability in dos (CVE-2026-13122)
vulnerability in dos (CVE-2026-13122). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-53830 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-53830)
SSRF in ssrf (CVE-2025-53830). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53829 |
|
Vulnerability in path-traversal (CVE-2025-53829)
vulnerability in path-traversal (CVE-2025-53829). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53828 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-53828)
SSRF in ssrf (CVE-2025-53828). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53827 |
|
Vulnerability in CVE-2025-53827 (CVE-2025-53827)
vulnerability in CVE-2025-53827 (CVE-2025-53827). Successful exploitation can lead to full system takeover.
|
| UBUNTU-CVE-2026-58203 |
|
Vulnerability in pydantic-settings (UBUNTU-CVE-2026-58203)
vulnerability in pydantic-settings (UBUNTU-CVE-2026-58203). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.14.2` or later.
|
| openSUSE-SU-2026:21265-1 |
|
Vulnerability in cadvisor (openSUSE-SU-2026:21265-1)
vulnerability in cadvisor (openSUSE-SU-2026:21265-1). Risk of unauthorized operations or information disclosure. Exploitable via ``gcr.io``. Mitigation: upgrade to `0.60.3-bp160.1.1` or later.
|
| openSUSE-SU-2026:21244-1 |
|
Vulnerability in podman (openSUSE-SU-2026:21244-1)
vulnerability in podman (openSUSE-SU-2026:21244-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.4.2-160000.5.1` or later.
|
| CVE-2026-7185 |
|
Path Traversal in CVE-2026-7185 (CVE-2026-7185)
path traversal in CVE-2026-7185 (CVE-2026-7185). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13698 |
|
Vulnerability in dos (CVE-2026-13698)
vulnerability in dos (CVE-2026-13698). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58380 |
|
Vulnerability in dos (CVE-2026-58380)
vulnerability in dos (CVE-2026-58380). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54893 |
|
Vulnerability in CVE-2026-54893 (CVE-2026-54893)
vulnerability in CVE-2026-54893 (CVE-2026-54893). Risk of unauthorized operations or information disclosure.
|
| CGA-fmcc-4647-hmc7 |
|
CGA-fmcc-4647-hmc7 |
| CGA-qqfq-7945-wx5c |
|
CGA-qqfq-7945-wx5c |
| CGA-rpfj-2ggx-58h7 |
|
CGA-rpfj-2ggx-58h7 |
| ECHO-0d27-ed35-8289 |
|
ECHO-0d27-ed35-8289 |
| ECHO-472d-c4a6-c1f9 |
|
ECHO-472d-c4a6-c1f9 |
| ECHO-9424-03b0-16ec |
|
ECHO-9424-03b0-16ec |
| ECHO-e69f-bf97-7e4d |
|
ECHO-e69f-bf97-7e4d |
| ECHO-919a-a239-ae70 |
|
ECHO-919a-a239-ae70 |
| ECHO-eef9-a5b3-0486 |
|
ECHO-eef9-a5b3-0486 |
| ECHO-67ce-6f25-3b6d |
|
ECHO-67ce-6f25-3b6d |
| ECHO-b32d-0d77-f517 |
|
ECHO-b32d-0d77-f517 |
| ECHO-f3ad-64af-b0a6 |
|
ECHO-f3ad-64af-b0a6 |
| ECHO-aed2-d0ee-eb0a |
|
ECHO-aed2-d0ee-eb0a |
| ECHO-d8b1-4397-2a2e |
|
ECHO-d8b1-4397-2a2e |
| ECHO-bf99-96ee-af6b |
|
ECHO-bf99-96ee-af6b |
| ECHO-5eeb-eaaf-9357 |
|
ECHO-5eeb-eaaf-9357 |
| ECHO-6d1e-5c87-d38e |
|
ECHO-6d1e-5c87-d38e |
| ECHO-1725-20a6-4751 |
|
ECHO-1725-20a6-4751 |
| ECHO-f3a8-c570-0651 |
|
ECHO-f3a8-c570-0651 |
| ECHO-e539-f67b-c9c9 |
|
ECHO-e539-f67b-c9c9 |
| ECHO-a7a1-bdcd-ae94 |
|
ECHO-a7a1-bdcd-ae94 |
| ECHO-d6cd-cd8e-da88 |
|
ECHO-d6cd-cd8e-da88 |
| ECHO-3143-27bf-6ffe |
|
ECHO-3143-27bf-6ffe |