Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-29gp-jq4v-52xv |
|
MINI-29gp-jq4v-52xv |
| MINI-9239-94jq-89wm |
|
MINI-9239-94jq-89wm |
| MINI-2hjq-jmjw-w87v |
|
MINI-2hjq-jmjw-w87v |
| MINI-wx7q-w6m2-6236 |
|
MINI-wx7q-w6m2-6236 |
| MINI-x747-54xf-pvv6 |
|
MINI-x747-54xf-pvv6 |
| MINI-f672-9c99-jx4f |
|
MINI-f672-9c99-jx4f |
| MINI-m54m-rqhx-46g9 |
|
MINI-m54m-rqhx-46g9 |
| MINI-w3r7-2c85-94hc |
|
MINI-w3r7-2c85-94hc |
| MINI-vq6r-2v38-vmr2 |
|
MINI-vq6r-2v38-vmr2 |
| MINI-7xgp-g26j-67f7 |
|
MINI-7xgp-g26j-67f7 |
| MINI-q9cx-cc7h-w885 |
|
MINI-q9cx-cc7h-w885 |
| MINI-hfjr-vfxw-6c9x |
|
MINI-hfjr-vfxw-6c9x |
| MINI-w3rv-59j8-cmm9 |
|
MINI-w3rv-59j8-cmm9 |
| GHSA-q4rm-m6xh-5pv7 |
|
Vulnerability in froxlor/froxlor (GHSA-q4rm-m6xh-5pv7)
vulnerability in froxlor/froxlor (GHSA-q4rm-m6xh-5pv7). Risk of unauthorized operations or information disclosure. Exploitable via ``Mysqls.add``. Mitigation: upgrade to `2.3.7` or later.
|
| GHSA-mr9h-45p9-fg8h |
|
Information Disclosure in froxlor/froxlor (GHSA-mr9h-45p9-fg8h)
vulnerability in froxlor/froxlor (GHSA-mr9h-45p9-fg8h). Risk of unauthorized operations or information disclosure. Exploitable via ``mail.enable_allow_sender``. Mitigation: upgrade to `2.3.7` or later.
|
| CVE-2026-49255 |
|
OS Command Injection in electerm (CVE-2026-49255)
OS command injection in electerm (CVE-2026-49255). Successful exploitation can lead to full system takeover. Exploitable via ``rmrf``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-49254 |
|
Information Disclosure in d7y.io/dragonfly/v2 (CVE-2026-49254)
vulnerability in d7y.io/dragonfly/v2 (CVE-2026-49254). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/oauth`. Mitigation: upgrade to `2.4.4` or later.
|
| CVE-2026-49253 |
|
Path Traversal in electerm (CVE-2026-49253)
path traversal in electerm (CVE-2026-49253). Data can be tampered with by attackers. Exploitable via ``savedFilePaths``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-49250 |
|
Vulnerability in @conform-to/dom (CVE-2026-49250)
vulnerability in @conform-to/dom (CVE-2026-49250). Risk of unauthorized operations or information disclosure. Exploitable via ``parseSubmission``. Mitigation: upgrade to `1.19.4` or later.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|
| CVE-2026-58465 |
|
Vulnerability in c (CVE-2026-58465)
vulnerability in c (CVE-2026-58465). Risk of unauthorized operations or information disclosure.
|
| GHSA-vv65-f55v-xm6g |
|
OS Command Injection in @grackle-ai/runtime-sdk (GHSA-vv65-f55v-xm6g)
OS command injection in @grackle-ai/runtime-sdk (GHSA-vv65-f55v-xm6g). Risk of unauthorized operations or information disclosure. Exploitable via ``git``.
|
| MINI-4h52-hvvq-f4pq |
|
MINI-4h52-hvvq-f4pq |
| MINI-2hh2-x2gh-f3j2 |
|
MINI-2hh2-x2gh-f3j2 |
| MINI-qv6q-fv83-8732 |
|
MINI-qv6q-fv83-8732 |
| MINI-hrmp-qfwg-h782 |
|
MINI-hrmp-qfwg-h782 |
| MINI-wf56-7pp6-3gfr |
|
MINI-wf56-7pp6-3gfr |
| MINI-rm77-hpxh-jw9f |
|
MINI-rm77-hpxh-jw9f |
| MINI-v6wh-6pjc-26fj |
|
MINI-v6wh-6pjc-26fj |
| MINI-r224-j68w-6m47 |
|
MINI-r224-j68w-6m47 |
| MINI-fwrh-qwqp-f6q8 |
|
MINI-fwrh-qwqp-f6q8 |
| MINI-cfp5-87q2-f4hp |
|
MINI-cfp5-87q2-f4hp |
| MINI-2vhg-rc47-c7mf |
|
MINI-2vhg-rc47-c7mf |
| CVE-2026-49852 |
|
Authentication Bypass in joserfc (CVE-2026-49852)
authentication bypass in joserfc (CVE-2026-49852). Risk of unauthorized operations or information disclosure. Exploitable via ``joserfc.jwt.decode``. Mitigation: upgrade to `1.6.8` or later.
|
| MINI-g7qr-f579-xpgq |
|
MINI-g7qr-f579-xpgq |
| MINI-c8h3-65w4-cvm7 |
|
MINI-c8h3-65w4-cvm7 |
| MINI-rcv8-w337-8f7h |
|
MINI-rcv8-w337-8f7h |
| MINI-rjqq-wvvh-wv8q |
|
MINI-rjqq-wvvh-wv8q |
| MINI-2qj9-4j2f-7928 |
|
MINI-2qj9-4j2f-7928 |
| MINI-4497-2x62-4fx9 |
|
MINI-4497-2x62-4fx9 |
| MINI-m3xq-62w8-8rf4 |
|
MINI-m3xq-62w8-8rf4 |
| MINI-cw32-j3fw-5gjr |
|
MINI-cw32-j3fw-5gjr |
| CVE-2026-49245 |
|
Cross-Site Scripting (XSS) in github.com/drakkan/sftpgo/v2 (CVE-2026-49245)
cross-site scripting in github.com/drakkan/sftpgo/v2 (CVE-2026-49245). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.3` or later.
|
| CVE-2026-49244 |
|
Path Traversal in github.com/drakkan/sftpgo/v2 (CVE-2026-49244)
path traversal in github.com/drakkan/sftpgo/v2 (CVE-2026-49244). Confidential information can be exposed externally. Mitigation: upgrade to `2.7.3` or later.
|
| CVE-2026-50290 |
|
Cross-Site Scripting (XSS) in @asymmetric-effort/specifyjs (CVE-2026-50290)
cross-site scripting in @asymmetric-effort/specifyjs (CVE-2026-50290). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.136` or later.
|
| GHSA-j5qp-p44g-2m49 |
|
SSRF (Server-Side Request Forgery) in @asymmetric-effort/specifyjs (GHSA-j5qp-p44g-2m49)
SSRF in @asymmetric-effort/specifyjs (GHSA-j5qp-p44g-2m49). Risk of unauthorized operations or information disclosure. Exploitable via ``assertSecureUrl``. Mitigation: upgrade to `0.2.136` or later.
|
| GHSA-2944-57xv-2682 |
|
SSRF (Server-Side Request Forgery) in @asymmetric-effort/specifyjs (GHSA-2944-57xv-2682)
SSRF in @asymmetric-effort/specifyjs (GHSA-2944-57xv-2682). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.136` or later.
|
| GHSA-xw57-23p8-9wc5 |
|
SSRF (Server-Side Request Forgery) in @asymmetric-effort/specifyjs (GHSA-xw57-23p8-9wc5)
SSRF in @asymmetric-effort/specifyjs (GHSA-xw57-23p8-9wc5). Risk of unauthorized operations or information disclosure. Exploitable via ``localhost``. Mitigation: upgrade to `0.2.136` or later.
|
| GHSA-qcr8-x557-7cp3 |
|
Vulnerability in @asymmetric-effort/specifyjs (GHSA-qcr8-x557-7cp3)
vulnerability in @asymmetric-effort/specifyjs (GHSA-qcr8-x557-7cp3). Risk of unauthorized operations or information disclosure. Exploitable via ``console.warn``. Mitigation: upgrade to `0.2.140` or later.
|
| MINI-cgwm-8wg3-6php |
|
MINI-cgwm-8wg3-6php |