Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-33560 |
|
Unrestricted File Upload in daktronics (CVE-2026-33560)
vulnerability in daktronics (CVE-2026-33560). Data can be tampered with by attackers.
|
| CVE-2026-31928 |
|
Vulnerability in daktronics (CVE-2026-31928)
vulnerability in daktronics (CVE-2026-31928). Confidential information can be exposed externally.
|
| CVE-2026-28701 |
|
Path Traversal in daktronics (CVE-2026-28701)
path traversal in daktronics (CVE-2026-28701). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50765 |
|
Cross-Site Scripting (XSS) in koha (CVE-2026-50765)
cross-site scripting in koha (CVE-2026-50765). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36908 |
|
Vulnerability in dos (CVE-2026-36908)
vulnerability in dos (CVE-2026-36908). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50767 |
|
Cross-Site Scripting (XSS) in koha (CVE-2026-50767)
cross-site scripting in koha (CVE-2026-50767). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36907 |
|
Vulnerability in dos (CVE-2026-36907)
vulnerability in dos (CVE-2026-36907). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50766 |
|
Cross-Site Scripting (XSS) in koha (CVE-2026-50766)
cross-site scripting in koha (CVE-2026-50766). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36478 |
|
Vulnerability in csharp (CVE-2026-36478)
vulnerability in csharp (CVE-2026-36478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38571 |
|
Vulnerability in CVE-2026-38571 (CVE-2026-38571)
vulnerability in CVE-2026-38571 (CVE-2026-38571). Confidential information can be exposed externally.
|
| OSV-2026-981 |
|
Vulnerability in grok (OSV-2026-981)
vulnerability in grok (OSV-2026-981). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `f76c6e85fcf629f7dc5b961e37f4fefb00ce7c7e` or later.
|
| GHSA-qrv3-253h-g69c |
|
Path Traversal in pnpm (GHSA-qrv3-253h-g69c)
path traversal in pnpm (GHSA-qrv3-253h-g69c). Risk of unauthorized operations or information disclosure. Exploitable via ``pnpm``. Mitigation: upgrade to `11.8.0` or later.
|
| GHSA-72r4-9c5j-mj57 |
|
Path Traversal in pnpm (GHSA-72r4-9c5j-mj57)
path traversal in pnpm (GHSA-72r4-9c5j-mj57). Risk of unauthorized operations or information disclosure. Exploitable via ``patchedDependencies``. Mitigation: upgrade to `10.34.4` or later.
|
| OSV-2026-974 |
|
Vulnerability in ogre (OSV-2026-974)
vulnerability in ogre (OSV-2026-974). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4b066d6e8f340bc92f935a6d2161872413e4a460` or later.
|
| OSV-2026-973 |
|
Vulnerability in binutils (OSV-2026-973)
vulnerability in binutils (OSV-2026-973). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11f57b156514211af29b93588c0fee2f8b3e66e4` or later.
|
| GHSA-fr4h-3cph-29xv |
|
Path Traversal in pnpm (GHSA-fr4h-3cph-29xv)
path traversal in pnpm (GHSA-fr4h-3cph-29xv). Risk of unauthorized operations or information disclosure. Exploitable via ``node_modules``. Mitigation: upgrade to `11.7.0` or later.
|
| OSV-2026-970 |
|
Vulnerability in open5gs (OSV-2026-970)
vulnerability in open5gs (OSV-2026-970). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `76d2237c0e99dd8cd01f03351a375a4c21d003c0` or later.
|
| RLSA-2023:6976 |
|
Vulnerability in libfastjson (RLSA-2023:6976)
vulnerability in libfastjson (RLSA-2023:6976). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:0.99.9-2.el8` or later.
|
| RLSA-2023:2786 |
|
Vulnerability in wayland (RLSA-2023:2786)
vulnerability in wayland (RLSA-2023:2786). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:1.21.0-1.el8` or later.
|
| openSUSE-SU-2026:11136-1 |
|
Vulnerability in ocaml (openSUSE-SU-2026:11136-1)
vulnerability in ocaml (openSUSE-SU-2026:11136-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.14.4-1.1` or later.
|
| openSUSE-SU-2026:11138-1 |
|
Vulnerability in python-jupyterlab-templates (openSUSE-SU-2026:11138-1)
vulnerability in python-jupyterlab-templates (openSUSE-SU-2026:11138-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.5.3-2.1` or later.
|
| openSUSE-SU-2026:11131-1 |
|
Vulnerability in hydra (openSUSE-SU-2026:11131-1)
vulnerability in hydra (openSUSE-SU-2026:11131-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.7+git20.gbccaea1-1.1` or later.
|
| openSUSE-SU-2026:11137-1 |
|
Vulnerability in python-jupyter-ydoc (openSUSE-SU-2026:11137-1)
vulnerability in python-jupyter-ydoc (openSUSE-SU-2026:11137-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.0-1.1` or later.
|
| openSUSE-SU-2026:11129-1 |
|
Vulnerability in assimp (openSUSE-SU-2026:11129-1)
vulnerability in assimp (openSUSE-SU-2026:11129-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.5-4.1` or later.
|
| openSUSE-SU-2026:11130-1 |
|
Vulnerability in calibre (openSUSE-SU-2026:11130-1)
vulnerability in calibre (openSUSE-SU-2026:11130-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.10.0-1.1` or later.
|
| openSUSE-SU-2026:11132-1 |
|
Vulnerability in jackson-databind (openSUSE-SU-2026:11132-1)
vulnerability in jackson-databind (openSUSE-SU-2026:11132-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.18.8-2.1` or later.
|
| openSUSE-SU-2026:11135-1 |
|
Vulnerability in logback (openSUSE-SU-2026:11135-1)
vulnerability in logback (openSUSE-SU-2026:11135-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.36-1.1` or later.
|
| openSUSE-SU-2026:11134-1 |
|
Vulnerability in libslirp (openSUSE-SU-2026:11134-1)
vulnerability in libslirp (openSUSE-SU-2026:11134-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.9.3+4-1.1` or later.
|
| openSUSE-SU-2026:11128-1 |
|
Vulnerability in agama-web-ui (openSUSE-SU-2026:11128-1)
vulnerability in agama-web-ui (openSUSE-SU-2026:11128-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22+143.ee15dea20-46.1` or later.
|
| openSUSE-SU-2026:11133-1 |
|
Vulnerability in jq (openSUSE-SU-2026:11133-1)
vulnerability in jq (openSUSE-SU-2026:11133-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.2-1.1` or later.
|
| openSUSE-SU-2026:11127-1 |
|
Vulnerability in ImageMagick (openSUSE-SU-2026:11127-1)
vulnerability in ImageMagick (openSUSE-SU-2026:11127-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.1.2.25-3.1` or later.
|
| GHSA-ww5p-j6cj-6mqq |
|
Information Disclosure in github.com/nezhahq/nezha (GHSA-ww5p-j6cj-6mqq)
vulnerability in github.com/nezhahq/nezha (GHSA-ww5p-j6cj-6mqq). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/ddns`. Mitigation: upgrade to `2.2.5` or later.
|
| CVE-2026-55700 |
|
Path Traversal in pnpm (CVE-2026-55700)
path traversal in pnpm (CVE-2026-55700). Data can be tampered with by attackers. Exploitable via ``main``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-55699 |
|
Path Traversal in pnpm (CVE-2026-55699)
path traversal in pnpm (CVE-2026-55699). Risk of unauthorized operations or information disclosure. Exploitable via ``a93449314f398cf4bdf2e28d033c02d37395ad22``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-55698 |
|
Vulnerability in pnpm (CVE-2026-55698)
vulnerability in pnpm (CVE-2026-55698). Successful exploitation can lead to full system takeover. Exploitable via ``a93449314f398cf4bdf2e28d033c02d37395ad22``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-55697 |
|
OS Command Injection in pnpm (CVE-2026-55697)
OS command injection in pnpm (CVE-2026-55697). Successful exploitation can lead to full system takeover. Exploitable via ``a93449314f398cf4bdf2e28d033c02d37395ad22``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-55487 |
|
Vulnerability in pnpm (CVE-2026-55487)
vulnerability in pnpm (CVE-2026-55487). Successful exploitation can lead to full system takeover. Exploitable via ``bf1b731ee6``. Mitigation: upgrade to `10.34.2` or later.
|
| CVE-2026-55180 |
|
Information Disclosure in pnpm (CVE-2026-55180)
vulnerability in pnpm (CVE-2026-55180). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-54244 |
|
Authorization Flaw in statamic/cms (CVE-2026-54244)
vulnerability in statamic/cms (CVE-2026-54244). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.0` or later.
|
| CVE-2026-54243 |
|
Vulnerability in statamic/cms (CVE-2026-54243)
vulnerability in statamic/cms (CVE-2026-54243). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.73.24` or later.
|
| CVE-2026-54242 |
|
Vulnerability in statamic/cms (CVE-2026-54242)
vulnerability in statamic/cms (CVE-2026-54242). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.73.24` or later.
|
| CVE-2026-50015 |
|
Path Traversal in pnpm (CVE-2026-50015)
path traversal in pnpm (CVE-2026-50015). Data can be tampered with by attackers. Exploitable via ``patchedDependencies``. Mitigation: upgrade to `11.4.0` or later.
|
| CVE-2026-50017 |
|
Information Disclosure in pnpm (CVE-2026-50017)
vulnerability in pnpm (CVE-2026-50017). Confidential information can be exposed externally. Exploitable via ``_authToken``. Mitigation: upgrade to `11.4.0` or later.
|
| CVE-2026-50016 |
|
Vulnerability in pnpm (CVE-2026-50016)
vulnerability in pnpm (CVE-2026-50016). Successful exploitation can lead to full system takeover. Exploitable via ``node_modules``. Mitigation: upgrade to `11.4.0` or later.
|
| CVE-2026-50014 |
|
Vulnerability in pnpm (CVE-2026-50014)
vulnerability in pnpm (CVE-2026-50014). Confidential information can be exposed externally. Exploitable via ``resolution.commit``. Mitigation: upgrade to `11.4.0` or later.
|
| CVE-2026-50021 |
|
Vulnerability in pnpm (CVE-2026-50021)
vulnerability in pnpm (CVE-2026-50021). Confidential information can be exposed externally. Exploitable via ``integrity``. Mitigation: upgrade to `10.34.1` or later.
|
| CVE-2026-50573 |
|
Vulnerability in pnpm (CVE-2026-50573)
vulnerability in pnpm (CVE-2026-50573). Confidential information can be exposed externally. Exploitable via ``integrity``. Mitigation: upgrade to `11.4.0` or later.
|
| GHSA-8jgf-23q5-x7xx |
|
Vulnerability in ex_aws_sns (GHSA-8jgf-23q5-x7xx)
vulnerability in ex_aws_sns (GHSA-8jgf-23q5-x7xx). Risk of unauthorized operations or information disclosure. Exploitable via ``SigningCertURL``. Mitigation: upgrade to `2.3.5` or later.
|
| CVE-2026-50029 |
|
Vulnerability in js-toml (CVE-2026-50029)
vulnerability in js-toml (CVE-2026-50029). Risk of unauthorized operations or information disclosure. Exploitable via ``false``. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-49349 |
|
Vulnerability in github.com/regclient/regclient (CVE-2026-49349)
vulnerability in github.com/regclient/regclient (CVE-2026-49349). Confidential information can be exposed externally. Exploitable via ``urls``. Mitigation: upgrade to `0.11.5` or later.
|