Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| ECHO-095f-9212-0d42 |
|
ECHO-095f-9212-0d42 |
| ECHO-aa60-5448-7b0c |
|
ECHO-aa60-5448-7b0c |
| ECHO-a00d-7885-9ea7 |
|
ECHO-a00d-7885-9ea7 |
| ECHO-c36c-fe72-e4f8 |
|
ECHO-c36c-fe72-e4f8 |
| GHSA-75cr-ggc5-8h7g |
|
Vulnerability in tw-style-utils (GHSA-75cr-ggc5-8h7g)
vulnerability in tw-style-utils (GHSA-75cr-ggc5-8h7g). Risk of unauthorized operations or information disclosure.
|
| GHSA-64m4-w85f-wrjj |
|
Vulnerability in pump-stream-logger (GHSA-64m4-w85f-wrjj)
vulnerability in pump-stream-logger (GHSA-64m4-w85f-wrjj). Risk of unauthorized operations or information disclosure.
|
| GHSA-j7hj-qc4f-x92f |
|
Vulnerability in pino-zod (GHSA-j7hj-qc4f-x92f)
vulnerability in pino-zod (GHSA-j7hj-qc4f-x92f). Risk of unauthorized operations or information disclosure.
|
| GHSA-cwr6-c222-8hwf |
|
Vulnerability in pump-laserstream-parser (GHSA-cwr6-c222-8hwf)
vulnerability in pump-laserstream-parser (GHSA-cwr6-c222-8hwf). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6511 |
|
Vulnerability in hydanlabs (MAL-2026-6511)
vulnerability in hydanlabs (MAL-2026-6511). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
|
| MAL-2026-6504 |
|
Vulnerability in openblox (MAL-2026-6504)
vulnerability in openblox (MAL-2026-6504). Risk of unauthorized operations or information disclosure. Exploitable via ``mshta``.
|
| MAL-2026-6503 |
|
Vulnerability in js-price-client-node (MAL-2026-6503)
vulnerability in js-price-client-node (MAL-2026-6503). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| ROOT-APP-MAVEN-CVE-2024-38829 |
|
Vulnerability in io.root.org.springframework.ldap:spring-ldap-core (ROOT-APP-MAVEN-CVE-2024-38829)
vulnerability in io.root.org.springframework.ldap:spring-ldap-core (ROOT-APP-MAVEN-CVE-2024-38829). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.0-root.io.1, 3.2.6-root.io.1` or later.
|
| CVE-2026-8661 |
|
Cross-Site Scripting (XSS) in CVE-2026-8661 (CVE-2026-8661)
cross-site scripting in CVE-2026-8661 (CVE-2026-8661). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50739 |
|
Vulnerability in revive-adserver (CVE-2026-50739)
vulnerability in revive-adserver (CVE-2026-50739). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50744 |
|
Vulnerability in c (CVE-2026-50744)
vulnerability in c (CVE-2026-50744). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50740 |
|
Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50740)
cross-site scripting in revive-adserver (CVE-2026-50740). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48935 |
|
Vulnerability in node (CVE-2026-48935)
vulnerability in node (CVE-2026-48935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-50745 |
|
Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50745)
cross-site scripting in revive-adserver (CVE-2026-50745). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48936 |
|
Vulnerability in node (CVE-2026-48936)
vulnerability in node (CVE-2026-48936). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.3.1` or later.
|
| CVE-2026-50742 |
|
Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50742)
cross-site scripting in revive-adserver (CVE-2026-50742). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50741 |
|
Code Injection in revive-adserver (CVE-2026-50741)
code injection in revive-adserver (CVE-2026-50741). Successful exploitation can lead to full system takeover. Exploitable via ``type``.
|
| CVE-2026-48934 |
|
Vulnerability in node (CVE-2026-48934)
vulnerability in node (CVE-2026-48934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48930 |
|
Vulnerability in node (CVE-2026-48930)
vulnerability in node (CVE-2026-48930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48618 |
|
Vulnerability in nodejs (CVE-2026-48618)
vulnerability in nodejs (CVE-2026-48618). Confidential information can be exposed externally.
|
| CVE-2026-13226 |
|
SQL Injection in wordpress (CVE-2026-13226)
SQL injection in wordpress (CVE-2026-13226). Confidential information can be exposed externally.
|
| CVE-2026-48933 |
|
Vulnerability in nodejs (CVE-2026-48933)
vulnerability in nodejs (CVE-2026-48933). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48619 |
|
Vulnerability in node (CVE-2026-48619)
vulnerability in node (CVE-2026-48619). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48615 |
|
Vulnerability in node (CVE-2026-48615)
vulnerability in node (CVE-2026-48615). Confidential information can be exposed externally. Exploitable via ``ERR_PROXY_TUNNEL``. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2026-48928 |
|
Vulnerability in node (CVE-2026-48928)
vulnerability in node (CVE-2026-48928). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| MAL-2026-6498 |
|
Vulnerability in dttfdsdee (MAL-2026-6498)
vulnerability in dttfdsdee (MAL-2026-6498). Risk of unauthorized operations or information disclosure.
|
| MINI-83pq-jpr4-894f |
|
MINI-83pq-jpr4-894f |
| MINI-vp35-hv43-3vpx |
|
MINI-vp35-hv43-3vpx |
| MINI-vc29-73c8-8v9r |
|
MINI-vc29-73c8-8v9r |
| MINI-wrgh-rgp4-6vhx |
|
MINI-wrgh-rgp4-6vhx |
| MINI-m3hw-g7gx-pwcx |
|
MINI-m3hw-g7gx-pwcx |
| MINI-hrh3-5m37-6c9w |
|
MINI-hrh3-5m37-6c9w |
| MINI-j52g-483r-5h8f |
|
MINI-j52g-483r-5h8f |
| MINI-4x8v-8qr3-w846 |
|
MINI-4x8v-8qr3-w846 |
| MINI-99w2-w55j-2cgq |
|
MINI-99w2-w55j-2cgq |
| MINI-q6gg-pfc2-c773 |
|
MINI-q6gg-pfc2-c773 |
| MINI-qwmp-33x6-x3r5 |
|
MINI-qwmp-33x6-x3r5 |
| MINI-g5hc-m3hw-vqx5 |
|
MINI-g5hc-m3hw-vqx5 |
| MINI-467v-q45c-9x7x |
|
MINI-467v-q45c-9x7x |
| MINI-jwxw-j396-7rx8 |
|
MINI-jwxw-j396-7rx8 |
| MAL-2026-6500 |
|
Vulnerability in set-cookie-ease (MAL-2026-6500)
vulnerability in set-cookie-ease (MAL-2026-6500). Risk of unauthorized operations or information disclosure. Exploitable via ``Cookies.set``.
|
| GHSA-8fxp-pghh-7w6w |
|
Vulnerability in mongoose-json-format (GHSA-8fxp-pghh-7w6w)
vulnerability in mongoose-json-format (GHSA-8fxp-pghh-7w6w). Risk of unauthorized operations or information disclosure. Exploitable via ``await``.
|
| UBUNTU-CVE-2026-48933 |
|
Vulnerability in nodejs (UBUNTU-CVE-2026-48933)
vulnerability in nodejs (UBUNTU-CVE-2026-48933). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-48930 |
|
Vulnerability in nodejs (UBUNTU-CVE-2026-48930)
vulnerability in nodejs (UBUNTU-CVE-2026-48930). Successful exploitation can lead to full system takeover.
|
| UBUNTU-CVE-2026-48928 |
|
Vulnerability in nodejs (UBUNTU-CVE-2026-48928)
vulnerability in nodejs (UBUNTU-CVE-2026-48928). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-48615 |
|
Vulnerability in nodejs (UBUNTU-CVE-2026-48615)
vulnerability in nodejs (UBUNTU-CVE-2026-48615). Confidential information can be exposed externally. Exploitable via ``ERR_PROXY_TUNNEL``.
|