Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
ECHO-095f-9212-0d42 ECHO-095f-9212-0d42
ECHO-aa60-5448-7b0c ECHO-aa60-5448-7b0c
ECHO-a00d-7885-9ea7 ECHO-a00d-7885-9ea7
ECHO-c36c-fe72-e4f8 ECHO-c36c-fe72-e4f8
GHSA-75cr-ggc5-8h7g Vulnerability in tw-style-utils (GHSA-75cr-ggc5-8h7g)
vulnerability in tw-style-utils (GHSA-75cr-ggc5-8h7g). Risk of unauthorized operations or information disclosure.
GHSA-64m4-w85f-wrjj Vulnerability in pump-stream-logger (GHSA-64m4-w85f-wrjj)
vulnerability in pump-stream-logger (GHSA-64m4-w85f-wrjj). Risk of unauthorized operations or information disclosure.
GHSA-j7hj-qc4f-x92f Vulnerability in pino-zod (GHSA-j7hj-qc4f-x92f)
vulnerability in pino-zod (GHSA-j7hj-qc4f-x92f). Risk of unauthorized operations or information disclosure.
GHSA-cwr6-c222-8hwf Vulnerability in pump-laserstream-parser (GHSA-cwr6-c222-8hwf)
vulnerability in pump-laserstream-parser (GHSA-cwr6-c222-8hwf). Risk of unauthorized operations or information disclosure.
MAL-2026-6511 Vulnerability in hydanlabs (MAL-2026-6511)
vulnerability in hydanlabs (MAL-2026-6511). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
MAL-2026-6504 Vulnerability in openblox (MAL-2026-6504)
vulnerability in openblox (MAL-2026-6504). Risk of unauthorized operations or information disclosure. Exploitable via ``mshta``.
MAL-2026-6503 Vulnerability in js-price-client-node (MAL-2026-6503)
vulnerability in js-price-client-node (MAL-2026-6503). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
ROOT-APP-MAVEN-CVE-2024-38829 Vulnerability in io.root.org.springframework.ldap:spring-ldap-core (ROOT-APP-MAVEN-CVE-2024-38829)
vulnerability in io.root.org.springframework.ldap:spring-ldap-core (ROOT-APP-MAVEN-CVE-2024-38829). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.0-root.io.1, 3.2.6-root.io.1` or later.
CVE-2026-8661 Cross-Site Scripting (XSS) in CVE-2026-8661 (CVE-2026-8661)
cross-site scripting in CVE-2026-8661 (CVE-2026-8661). Risk of unauthorized operations or information disclosure.
CVE-2026-50739 Vulnerability in revive-adserver (CVE-2026-50739)
vulnerability in revive-adserver (CVE-2026-50739). Risk of unauthorized operations or information disclosure.
CVE-2026-50744 Vulnerability in c (CVE-2026-50744)
vulnerability in c (CVE-2026-50744). Risk of unauthorized operations or information disclosure.
CVE-2026-50740 Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50740)
cross-site scripting in revive-adserver (CVE-2026-50740). Risk of unauthorized operations or information disclosure.
CVE-2026-48935 Vulnerability in node (CVE-2026-48935)
vulnerability in node (CVE-2026-48935). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-50745 Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50745)
cross-site scripting in revive-adserver (CVE-2026-50745). Risk of unauthorized operations or information disclosure.
CVE-2026-48936 Vulnerability in node (CVE-2026-48936)
vulnerability in node (CVE-2026-48936). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.3.1` or later.
CVE-2026-50742 Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50742)
cross-site scripting in revive-adserver (CVE-2026-50742). Risk of unauthorized operations or information disclosure.
CVE-2026-50741 Code Injection in revive-adserver (CVE-2026-50741)
code injection in revive-adserver (CVE-2026-50741). Successful exploitation can lead to full system takeover. Exploitable via ``type``.
CVE-2026-48934 Vulnerability in node (CVE-2026-48934)
vulnerability in node (CVE-2026-48934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48930 Vulnerability in node (CVE-2026-48930)
vulnerability in node (CVE-2026-48930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48618 Vulnerability in nodejs (CVE-2026-48618)
vulnerability in nodejs (CVE-2026-48618). Confidential information can be exposed externally.
CVE-2026-13226 SQL Injection in wordpress (CVE-2026-13226)
SQL injection in wordpress (CVE-2026-13226). Confidential information can be exposed externally.
CVE-2026-48933 Vulnerability in nodejs (CVE-2026-48933)
vulnerability in nodejs (CVE-2026-48933). Risk of unauthorized operations or information disclosure.
CVE-2026-48619 Vulnerability in node (CVE-2026-48619)
vulnerability in node (CVE-2026-48619). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48615 Vulnerability in node (CVE-2026-48615)
vulnerability in node (CVE-2026-48615). Confidential information can be exposed externally. Exploitable via ``ERR_PROXY_TUNNEL``. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
CVE-2026-48928 Vulnerability in node (CVE-2026-48928)
vulnerability in node (CVE-2026-48928). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
MAL-2026-6498 Vulnerability in dttfdsdee (MAL-2026-6498)
vulnerability in dttfdsdee (MAL-2026-6498). Risk of unauthorized operations or information disclosure.
MINI-83pq-jpr4-894f MINI-83pq-jpr4-894f
MINI-vp35-hv43-3vpx MINI-vp35-hv43-3vpx
MINI-vc29-73c8-8v9r MINI-vc29-73c8-8v9r
MINI-wrgh-rgp4-6vhx MINI-wrgh-rgp4-6vhx
MINI-m3hw-g7gx-pwcx MINI-m3hw-g7gx-pwcx
MINI-hrh3-5m37-6c9w MINI-hrh3-5m37-6c9w
MINI-j52g-483r-5h8f MINI-j52g-483r-5h8f
MINI-4x8v-8qr3-w846 MINI-4x8v-8qr3-w846
MINI-99w2-w55j-2cgq MINI-99w2-w55j-2cgq
MINI-q6gg-pfc2-c773 MINI-q6gg-pfc2-c773
MINI-qwmp-33x6-x3r5 MINI-qwmp-33x6-x3r5
MINI-g5hc-m3hw-vqx5 MINI-g5hc-m3hw-vqx5
MINI-467v-q45c-9x7x MINI-467v-q45c-9x7x
MINI-jwxw-j396-7rx8 MINI-jwxw-j396-7rx8
MAL-2026-6500 Vulnerability in set-cookie-ease (MAL-2026-6500)
vulnerability in set-cookie-ease (MAL-2026-6500). Risk of unauthorized operations or information disclosure. Exploitable via ``Cookies.set``.
GHSA-8fxp-pghh-7w6w Vulnerability in mongoose-json-format (GHSA-8fxp-pghh-7w6w)
vulnerability in mongoose-json-format (GHSA-8fxp-pghh-7w6w). Risk of unauthorized operations or information disclosure. Exploitable via ``await``.
UBUNTU-CVE-2026-48933 Vulnerability in nodejs (UBUNTU-CVE-2026-48933)
vulnerability in nodejs (UBUNTU-CVE-2026-48933). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-48930 Vulnerability in nodejs (UBUNTU-CVE-2026-48930)
vulnerability in nodejs (UBUNTU-CVE-2026-48930). Successful exploitation can lead to full system takeover.
UBUNTU-CVE-2026-48928 Vulnerability in nodejs (UBUNTU-CVE-2026-48928)
vulnerability in nodejs (UBUNTU-CVE-2026-48928). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-48615 Vulnerability in nodejs (UBUNTU-CVE-2026-48615)
vulnerability in nodejs (UBUNTU-CVE-2026-48615). Confidential information can be exposed externally. Exploitable via ``ERR_PROXY_TUNNEL``.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →