Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MAL-2026-6711 Vulnerability in twrap-tool (MAL-2026-6711)
vulnerability in twrap-tool (MAL-2026-6711). Risk of unauthorized operations or information disclosure.
GHSA-q8qp-67f9-wr3f Vulnerability in surrealdb (GHSA-q8qp-67f9-wr3f)
vulnerability in surrealdb (GHSA-q8qp-67f9-wr3f). Risk of unauthorized operations or information disclosure. Exploitable via ``parse_concrete_kind``. Mitigation: upgrade to `3.1.0` or later.
GHSA-wjjj-24cx-f28g Vulnerability in surrealdb (GHSA-wjjj-24cx-f28g)
vulnerability in surrealdb (GHSA-wjjj-24cx-f28g). Risk of unauthorized operations or information disclosure. Exploitable via ``use``. Mitigation: upgrade to `3.1.0` or later.
GHSA-q729-696q-g9pq Vulnerability in surrealdb (GHSA-q729-696q-g9pq)
vulnerability in surrealdb (GHSA-q729-696q-g9pq). Risk of unauthorized operations or information disclosure. Exploitable via ``parse_value``. Mitigation: upgrade to `3.1.0` or later.
GHSA-4vgr-h27g-cf9p Vulnerability in surrealdb (GHSA-4vgr-h27g-cf9p)
vulnerability in surrealdb (GHSA-4vgr-h27g-cf9p). Successful exploitation can lead to full system takeover. Exploitable via `POST /rpc`. Mitigation: upgrade to `3.1.0` or later.
GHSA-5qfp-32cf-69jh Vulnerability in surrealdb (GHSA-5qfp-32cf-69jh)
vulnerability in surrealdb (GHSA-5qfp-32cf-69jh). Successful exploitation can lead to full system takeover. Exploitable via `POST /rpc`. Mitigation: upgrade to `1` or later.
CVE-2026-48815 Vulnerability in sigstore (CVE-2026-48815)
vulnerability in sigstore (CVE-2026-48815). Data can be tampered with by attackers. Exploitable via ``certificateOIDs``. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-48816 Vulnerability in @sigstore/verify (CVE-2026-48816)
vulnerability in @sigstore/verify (CVE-2026-48816). Data can be tampered with by attackers. Exploitable via ``timestampThreshold``. Mitigation: upgrade to `3.1.1` or later.
CVE-2026-49989 Authorization Flaw in io.crate:crate (CVE-2026-49989)
vulnerability in io.crate:crate (CVE-2026-49989). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /_blobs/{table}/{digest}`. Mitigation: upgrade to `6.3.2` or later.
GHSA-m492-gv72-xvxj Vulnerability in kimai/kimai (GHSA-m492-gv72-xvxj)
vulnerability in kimai/kimai (GHSA-m492-gv72-xvxj). Risk of unauthorized operations or information disclosure. Exploitable via ``password``. Mitigation: upgrade to `2.58.0` or later.
CVE-2026-13760 OS Command Injection in Amazon aws-cdk-lib (CVE-2026-13760)
OS command injection in Amazon aws-cdk-lib (CVE-2026-13760). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.260.0` or later.
CVE-2026-13769 Vulnerability in Amazon awscli (CVE-2026-13769)
vulnerability in Amazon awscli (CVE-2026-13769). Confidential information can be exposed externally. Mitigation: upgrade to `1.44.78` or later.
PYSEC-2026-605 Vulnerability in nucbox (PYSEC-2026-605)
vulnerability in nucbox (PYSEC-2026-605). Risk of unauthorized operations or information disclosure.
CVE-2026-55628 Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-55628)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-55628). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.15.0` or later.
CVE-2026-55597 Vulnerability in imagemagick (CVE-2026-55597)
vulnerability in imagemagick (CVE-2026-55597). Risk of unauthorized operations or information disclosure.
CVE-2026-55595 Vulnerability in imagemagick (CVE-2026-55595)
vulnerability in imagemagick (CVE-2026-55595). Risk of unauthorized operations or information disclosure.
CVE-2026-55594 Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-55594)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-55594). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.15.0` or later.
CVE-2026-55577 Vulnerability in imagemagick (CVE-2026-55577)
vulnerability in imagemagick (CVE-2026-55577). Risk of unauthorized operations or information disclosure.
CVE-2026-55510 Use-After-Free in Magick.NET-Q16-AnyCPU (CVE-2026-55510)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-55510). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.15.0` or later.
CVE-2026-53467 Information Disclosure in Magick.NET-Q16-AnyCPU (CVE-2026-53467)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-53467). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.15.0` or later.
CVE-2026-53466 Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-53466)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-53466). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.15.0` or later.
CVE-2026-50160 Vulnerability in hoppscotch (CVE-2026-50160)
vulnerability in hoppscotch (CVE-2026-50160). Confidential information can be exposed externally. Exploitable via `POST /v1/onboarding/config`.
UBUNTU-CVE-2026-58451 Vulnerability in php-horde-imp (UBUNTU-CVE-2026-58451)
vulnerability in php-horde-imp (UBUNTU-CVE-2026-58451). Confidential information can be exposed externally.
GHSA-w2r4-4x6j-3h5x Vulnerability in vitest-agent (GHSA-w2r4-4x6j-3h5x)
vulnerability in vitest-agent (GHSA-w2r4-4x6j-3h5x). Risk of unauthorized operations or information disclosure. Exploitable via ``main``.
PYSEC-2026-604 Vulnerability in napari-ufish (PYSEC-2026-604)
vulnerability in napari-ufish (PYSEC-2026-604). Risk of unauthorized operations or information disclosure.
CVE-2026-49988 Information Disclosure in repomix (CVE-2026-49988)
vulnerability in repomix (CVE-2026-49988). Confidential information can be exposed externally. Exploitable via ``attach_packed_output``. Mitigation: upgrade to `1.14.1` or later.
CVE-2026-49826 Open Redirect in github.com/concourse/concourse (CVE-2026-49826)
vulnerability in github.com/concourse/concourse (CVE-2026-49826). Risk of unauthorized operations or information disclosure. Exploitable via ``url``. Mitigation: upgrade to `8.2.3` or later.
CVE-2026-49987 Vulnerability in repomix (CVE-2026-49987)
vulnerability in repomix (CVE-2026-49987). Successful exploitation can lead to full system takeover. Exploitable via ``execGitShallowClone``. Mitigation: upgrade to `1.14.1` or later.
GHSA-mjgf-xj26-9qf9 Vulnerability in pay (GHSA-mjgf-xj26-9qf9)
vulnerability in pay (GHSA-mjgf-xj26-9qf9). Confidential information can be exposed externally. Exploitable via `POST /pay/webhooks/paddle_billing`.
CVE-2026-49981 Vulnerability in twig/twig (CVE-2026-49981)
vulnerability in twig/twig (CVE-2026-49981). Confidential information can be exposed externally. Exploitable via ``Template``. Mitigation: upgrade to `3.27.0` or later.
MINI-fmxx-8r4m-478w MINI-fmxx-8r4m-478w
MINI-j67c-5h88-29mj MINI-j67c-5h88-29mj
MINI-vq49-3w87-26vh MINI-vq49-3w87-26vh
MINI-hmx4-qf7r-vj78 MINI-hmx4-qf7r-vj78
MINI-64cg-gpxc-w6vm MINI-64cg-gpxc-w6vm
MINI-ffmj-967w-w75h MINI-ffmj-967w-w75h
MINI-x45p-c9v5-h8x7 MINI-x45p-c9v5-h8x7
MINI-6253-f64c-vqhm MINI-6253-f64c-vqhm
MINI-2cxq-vc6r-8fxg MINI-2cxq-vc6r-8fxg
MINI-7fmq-v75f-gqm3 MINI-7fmq-v75f-gqm3
MINI-62jh-54gg-hx3r MINI-62jh-54gg-hx3r
MINI-q839-2mv9-jm37 MINI-q839-2mv9-jm37
MINI-r3jh-6mpr-47rv MINI-r3jh-6mpr-47rv
MINI-7cqx-pcq2-4wr4 MINI-7cqx-pcq2-4wr4
MINI-56jx-333m-82p7 MINI-56jx-333m-82p7
MINI-rj5g-fxxv-6mqv MINI-rj5g-fxxv-6mqv
MINI-mx5f-8qq3-8qvc MINI-mx5f-8qq3-8qvc
MINI-j4w4-xj42-89q6 MINI-j4w4-xj42-89q6
MINI-p3fm-q9ph-vjwh MINI-p3fm-q9ph-vjwh
MINI-3w4v-wc8m-6vpm MINI-3w4v-wc8m-6vpm

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →