Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MAL-2026-6536 Vulnerability in @krentzen/buffer-reverse (MAL-2026-6536)
vulnerability in @krentzen/buffer-reverse (MAL-2026-6536). Risk of unauthorized operations or information disclosure.
GHSA-jqc5-2p7q-fqfc Vulnerability in github.com/apernet/hysteria (GHSA-jqc5-2p7q-fqfc)
vulnerability in github.com/apernet/hysteria (GHSA-jqc5-2p7q-fqfc). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.2` or later.
CVE-2026-55838 Vulnerability in CVE-2026-55838 (CVE-2026-55838)
vulnerability in CVE-2026-55838 (CVE-2026-55838). Risk of unauthorized operations or information disclosure.
CVE-2026-55189 Vulnerability in CVE-2026-55189 (CVE-2026-55189)
vulnerability in CVE-2026-55189 (CVE-2026-55189). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.0-beta.9` or later.
CVE-2026-55188 Information Disclosure in CVE-2026-55188 (CVE-2026-55188)
vulnerability in CVE-2026-55188 (CVE-2026-55188). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.0-beta.9` or later.
CVE-2026-52785 SQL Injection in sqli (CVE-2026-52785)
SQL injection in sqli (CVE-2026-52785). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-52784 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-52784)
vulnerability in csrf (CVE-2026-52784). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-52783 Vulnerability in rails (CVE-2026-52783)
vulnerability in rails (CVE-2026-52783). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-52782 Vulnerability in CVE-2026-52782 (CVE-2026-52782)
vulnerability in CVE-2026-52782 (CVE-2026-52782). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-52781 Cross-Site Scripting (XSS) in CVE-2026-52781 (CVE-2026-52781)
cross-site scripting in CVE-2026-52781 (CVE-2026-52781). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-52780 Vulnerability in CVE-2026-52780 (CVE-2026-52780)
vulnerability in CVE-2026-52780 (CVE-2026-52780). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-52779 Vulnerability in CVE-2026-52779 (CVE-2026-52779)
vulnerability in CVE-2026-52779 (CVE-2026-52779). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-49991 Path Traversal in path-traversal (CVE-2026-49991)
path traversal in path-traversal (CVE-2026-49991). Data can be tampered with by attackers.
CVE-2026-49355 Information Disclosure in CVE-2026-49355 (CVE-2026-49355)
vulnerability in CVE-2026-49355 (CVE-2026-49355). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v3/meetings/`. Mitigation: upgrade to `17.4.0` or later.
CVE-2026-47193 Information Disclosure in CVE-2026-47193 (CVE-2026-47193)
vulnerability in CVE-2026-47193 (CVE-2026-47193). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-46386 Unsafe Deserialization in rails (CVE-2026-46386)
vulnerability in rails (CVE-2026-46386). Successful exploitation can lead to full system takeover.
CVE-2026-44736 Information Disclosure in CVE-2026-44736 (CVE-2026-44736)
vulnerability in CVE-2026-44736 (CVE-2026-44736). Confidential information can be exposed externally. Exploitable via `GET /api/v3/relations`. Mitigation: upgrade to `17.4.0` or later.
CVE-2026-44735 Authorization Flaw in CVE-2026-44735 (CVE-2026-44735)
vulnerability in CVE-2026-44735 (CVE-2026-44735). Confidential information can be exposed externally. Exploitable via `GET /api/v3/shares`. Mitigation: upgrade to `17.3.2` or later.
CVE-2026-44734 Vulnerability in CVE-2026-44734 (CVE-2026-44734)
vulnerability in CVE-2026-44734 (CVE-2026-44734). Data can be tampered with by attackers. Mitigation: upgrade to `17.3.2` or later.
CVE-2026-44733 Vulnerability in CVE-2026-44733 (CVE-2026-44733)
vulnerability in CVE-2026-44733 (CVE-2026-44733). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.2` or later.
CVE-2026-44732 Vulnerability in CVE-2026-44732 (CVE-2026-44732)
vulnerability in CVE-2026-44732 (CVE-2026-44732). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `17.3.2` or later.
CVE-2026-44731 Vulnerability in CVE-2026-44731 (CVE-2026-44731)
vulnerability in CVE-2026-44731 (CVE-2026-44731). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `17.3.2` or later.
CVE-2026-44696 Cross-Site Scripting (XSS) in CVE-2026-44696 (CVE-2026-44696)
cross-site scripting in CVE-2026-44696 (CVE-2026-44696). Data can be tampered with by attackers. Mitigation: upgrade to `17.4.0` or later.
UBUNTU-CVE-2026-29509 Vulnerability in patool (UBUNTU-CVE-2026-29509)
vulnerability in patool (UBUNTU-CVE-2026-29509). Risk of unauthorized operations or information disclosure.
MAL-2026-6537 Vulnerability in gptmini (MAL-2026-6537)
vulnerability in gptmini (MAL-2026-6537). Risk of unauthorized operations or information disclosure. Exploitable via ``gptmini``.
GHSA-qh5x-rfwf-rvfv Vulnerability in github.com/apernet/hysteria (GHSA-qh5x-rfwf-rvfv)
vulnerability in github.com/apernet/hysteria (GHSA-qh5x-rfwf-rvfv). Risk of unauthorized operations or information disclosure. Exploitable via ``max_datagram_frame_size``. Mitigation: upgrade to `2.9.2` or later.
GHSA-vgrc-hq28-p3xp Vulnerability in github.com/apernet/hysteria/core/v2 (GHSA-vgrc-hq28-p3xp)
vulnerability in github.com/apernet/hysteria/core/v2 (GHSA-vgrc-hq28-p3xp). Risk of unauthorized operations or information disclosure. Exploitable via ``UDPMessage``. Mitigation: upgrade to `2.9.2` or later.
GHSA-5vwr-qchf-q4pf OS Command Injection in @cyclonedx/cdxgen (GHSA-5vwr-qchf-q4pf)
OS command injection in @cyclonedx/cdxgen (GHSA-5vwr-qchf-q4pf). Risk of unauthorized operations or information disclosure. Exploitable via `POST /sbom`. Mitigation: upgrade to `12.4.3` or later.
MINI-gxj8-qv8r-h4xv MINI-gxj8-qv8r-h4xv
MINI-67h6-gpvm-pq64 MINI-67h6-gpvm-pq64
MINI-xqq5-v2v4-9jf6 MINI-xqq5-v2v4-9jf6
MINI-vw44-gv9g-26gr MINI-vw44-gv9g-26gr
MINI-q6v8-8p88-92vv MINI-q6v8-8p88-92vv
MINI-p53p-wjwc-xpr3 MINI-p53p-wjwc-xpr3
MINI-g267-3v3j-qpmr MINI-g267-3v3j-qpmr
MINI-555h-cxrg-4cxr MINI-555h-cxrg-4cxr
MINI-3rhr-43m2-qqg3 MINI-3rhr-43m2-qqg3
MINI-vx24-9595-qwjm MINI-vx24-9595-qwjm
MINI-w9c8-ww72-hfmw MINI-w9c8-ww72-hfmw
MINI-rqph-6rfq-rjgw MINI-rqph-6rfq-rjgw
MINI-cmcf-hjv7-q5xg MINI-cmcf-hjv7-q5xg
MINI-72xq-5jc4-xgg7 MINI-72xq-5jc4-xgg7
MINI-69wr-3rvq-xqm6 MINI-69wr-3rvq-xqm6
MINI-2vjj-rrmx-4v4x MINI-2vjj-rrmx-4v4x
MINI-q3vx-9p54-mvh5 MINI-q3vx-9p54-mvh5
MINI-275j-p7hj-632x MINI-275j-p7hj-632x
MINI-3mhh-h84c-ghpx MINI-3mhh-h84c-ghpx
MINI-h2f8-jmhh-q69q MINI-h2f8-jmhh-q69q
MINI-5fx3-55wr-fff8 MINI-5fx3-55wr-fff8
MINI-vwvf-8jrj-c529 MINI-vwvf-8jrj-c529

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →