Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-vx8x-rr42-fwhx |
|
Vulnerability in hexo-deployer-wrangler (GHSA-vx8x-rr42-fwhx)
vulnerability in hexo-deployer-wrangler (GHSA-vx8x-rr42-fwhx). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43920 |
|
Vulnerability in csrf (CVE-2026-43920)
vulnerability in csrf (CVE-2026-43920). Risk of unauthorized operations or information disclosure.
|
| OSV-2026-969 |
|
Vulnerability in ogre (OSV-2026-969)
vulnerability in ogre (OSV-2026-969). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4b066d6e8f340bc92f935a6d2161872413e4a460` or later.
|
| RLSA-2026:29898 |
|
Vulnerability in libpng (RLSA-2026:29898)
vulnerability in libpng (RLSA-2026:29898). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2:1.6.34-11.el8_10` or later.
|
| UBUNTU-CVE-2026-55520 |
|
[Unknown description] |
| UBUNTU-CVE-2026-54548 |
|
[Unknown description] |
| CVE-2026-40941 |
|
Vulnerability in cacti (CVE-2026-40941)
vulnerability in cacti (CVE-2026-40941). Data can be tampered with by attackers.
|
| CVE-2026-40084 |
|
Path Traversal in path-traversal (CVE-2026-40084)
path traversal in path-traversal (CVE-2026-40084). Confidential information can be exposed externally.
|
| CVE-2026-40083 |
|
SQL Injection in sqli (CVE-2026-40083)
SQL injection in sqli (CVE-2026-40083). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40082 |
|
Vulnerability in cacti (CVE-2026-40082)
vulnerability in cacti (CVE-2026-40082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40080 |
|
Open Redirect in cacti (CVE-2026-40080)
vulnerability in cacti (CVE-2026-40080). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-40941 |
|
Vulnerability in cacti (UBUNTU-CVE-2026-40941)
vulnerability in cacti (UBUNTU-CVE-2026-40941). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-40083 |
|
Vulnerability in cacti (UBUNTU-CVE-2026-40083)
vulnerability in cacti (UBUNTU-CVE-2026-40083). Successful exploitation can lead to full system takeover.
|
| UBUNTU-CVE-2026-40082 |
|
Vulnerability in cacti (UBUNTU-CVE-2026-40082)
vulnerability in cacti (UBUNTU-CVE-2026-40082). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-40080 |
|
Vulnerability in cacti (UBUNTU-CVE-2026-40080)
vulnerability in cacti (UBUNTU-CVE-2026-40080). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-40084 |
|
Vulnerability in cacti (UBUNTU-CVE-2026-40084)
vulnerability in cacti (UBUNTU-CVE-2026-40084). Confidential information can be exposed externally.
|
| GHSA-jp8q-gmj4-fx77 |
|
Vulnerability in random-string-64 (GHSA-jp8q-gmj4-fx77)
vulnerability in random-string-64 (GHSA-jp8q-gmj4-fx77). Risk of unauthorized operations or information disclosure. Exploitable via ``globalThis.eval``.
|
| MAL-2026-6489 |
|
Vulnerability in extra-huggingface (MAL-2026-6489)
vulnerability in extra-huggingface (MAL-2026-6489). Risk of unauthorized operations or information disclosure. Exploitable via ``run_agent``.
|
| MAL-2026-6488 |
|
Vulnerability in pyext6cc8cd (MAL-2026-6488)
vulnerability in pyext6cc8cd (MAL-2026-6488). Risk of unauthorized operations or information disclosure. Exploitable via ``subprocess.Popen``.
|
| CVE-2026-34530 |
|
Cross-Site Scripting (XSS) in github.com/filebrowser/filebrowser (CVE-2026-34530)
cross-site scripting in github.com/filebrowser/filebrowser (CVE-2026-34530). Confidential information can be exposed externally. Exploitable via `PUT /api/settings`. Mitigation: upgrade to `2.62.2` or later.
|
| CVE-2026-41174 |
|
Vulnerability in github.com/traefik/traefik (CVE-2026-41174)
vulnerability in github.com/traefik/traefik (CVE-2026-41174). Risk of unauthorized operations or information disclosure. Exploitable via ``IngressRoute``. Mitigation: upgrade to `2.11.43` or later.
|
| CVE-2026-4531 |
|
Vulnerability in github.com/free5gc/amf (CVE-2026-4531)
vulnerability in github.com/free5gc/amf (CVE-2026-4531). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.3-0.20260306074636-52e9386401ce` or later.
|
| GHSA-xhj4-g6w8-2xjw |
|
Vulnerability in github.com/woven-planet/go-zserio (GHSA-xhj4-g6w8-2xjw)
vulnerability in github.com/woven-planet/go-zserio (GHSA-xhj4-g6w8-2xjw). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.9.1` or later.
|
| GHSA-x3f4-v83f-7wp2 |
|
Open Redirect in github.com/authorizerdev/authorizer (GHSA-x3f4-v83f-7wp2)
vulnerability in github.com/authorizerdev/authorizer (GHSA-x3f4-v83f-7wp2). Risk of unauthorized operations or information disclosure. Exploitable via ``redirect_uri``. Mitigation: upgrade to `0.0.0-20260329085140-6d9bef1aaba3` or later.
|
| CVE-2026-33031 |
|
Vulnerability in github.com/0xJacky/Nginx-UI (CVE-2026-33031)
vulnerability in github.com/0xJacky/Nginx-UI (CVE-2026-33031). Confidential information can be exposed externally. Exploitable via ``user.Status``. Mitigation: upgrade to `1.9.10-0.20260314152518-7b66578adb47` or later.
|
| CVE-2026-34528 |
|
Privilege Escalation in github.com/filebrowser/filebrowser (CVE-2026-34528)
vulnerability in github.com/filebrowser/filebrowser (CVE-2026-34528). Successful exploitation can lead to full system takeover. Exploitable via ``signupHandler``. Mitigation: upgrade to `2.62.2` or later.
|
| CVE-2026-40247 |
|
Vulnerability in github.com/free5gc/udr (CVE-2026-40247)
vulnerability in github.com/free5gc/udr (CVE-2026-40247). Confidential information can be exposed externally. Exploitable via `GET /nudr-dr/v2/application-data/influenceData/{influenceId}/{subscriptionId}`.
|
| CVE-2026-40189 |
|
Vulnerability in github.com/patrickhener/goshs (CVE-2026-40189)
vulnerability in github.com/patrickhener/goshs (CVE-2026-40189). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload`.
|
| CVE-2026-21388 |
|
Vulnerability in github.com/mattermost/mattermost-plugin-msteams (CVE-2026-21388)
vulnerability in github.com/mattermost/mattermost-plugin-msteams (CVE-2026-21388). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.15.1-0.20260213190728-6fe4d295592e` or later.
|
| CVE-2026-35036 |
|
SSRF (Server-Side Request Forgery) in github.com/lin-snow/ech0 (CVE-2026-35036)
SSRF in github.com/lin-snow/ech0 (CVE-2026-35036). Confidential information can be exposed externally. Exploitable via `GET /api/website/title`. Mitigation: upgrade to `1.4.8-0.20260401031029-4ca56fea5ba4` or later.
|
| CVE-2026-40107 |
|
SSRF (Server-Side Request Forgery) in github.com/siyuan-note/siyuan/kernel (CVE-2026-40107)
SSRF in github.com/siyuan-note/siyuan/kernel (CVE-2026-40107). Risk of unauthorized operations or information disclosure. Exploitable via ``src``. Mitigation: upgrade to `0.0.0-20260407035653-2f416e5253f1` or later.
|
| GHSA-vjgj-42f6-7997 |
|
Vulnerability in github.com/tinfoil-factory/netfoil (GHSA-vjgj-42f6-7997)
vulnerability in github.com/tinfoil-factory/netfoil (GHSA-vjgj-42f6-7997). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.1` or later.
|
| CVE-2026-35604 |
|
Authorization Flaw in github.com/filebrowser/filebrowser (CVE-2026-35604)
vulnerability in github.com/filebrowser/filebrowser (CVE-2026-35604). Risk of unauthorized operations or information disclosure. Exploitable via ``withHashFile``. Mitigation: upgrade to `2.63.1` or later.
|
| CVE-2026-40481 |
|
Vulnerability in github.com/monetr/monetr (CVE-2026-40481)
vulnerability in github.com/monetr/monetr (CVE-2026-40481). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.12.4` or later.
|
| GHSA-v5mh-h5hx-7v92 |
|
Vulnerability in github.com/cloudnativelabs/kube-router (GHSA-v5mh-h5hx-7v92)
vulnerability in github.com/cloudnativelabs/kube-router (GHSA-v5mh-h5hx-7v92). Risk of unauthorized operations or information disclosure. Exploitable via ``ROUTE_ACTION_REJECT``. Mitigation: upgrade to `2.9.0` or later.
|
| GHSA-rxmp-8h9v-56cx |
|
Vulnerability in github.com/netbirdio/netbird (GHSA-rxmp-8h9v-56cx)
vulnerability in github.com/netbirdio/netbird (GHSA-rxmp-8h9v-56cx). Data can be tampered with by attackers. Exploitable via `PUT /api/users/{OLD_ADMIN_USERID}`. Mitigation: upgrade to `0.65.3` or later.
|
| CVE-2026-40103 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-40103)
vulnerability in code.vikunja.io/api (CVE-2026-40103). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/projects/`. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-40245 |
|
Information Disclosure in github.com/free5gc/udr (CVE-2026-40245)
vulnerability in github.com/free5gc/udr (CVE-2026-40245). Confidential information can be exposed externally. Exploitable via `GET /nudr-dr/v2/application-data/influenceData/subs-to-notify`.
|
| CVE-2026-40263 |
|
Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-40263)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-40263). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/auth/token`. Mitigation: upgrade to `0.19.2-0.20260411145025-cf4c6f6acf70` or later.
|
| CVE-2026-5412 |
|
Vulnerability in github.com/juju/juju (CVE-2026-5412)
vulnerability in github.com/juju/juju (CVE-2026-5412). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.0-20260408003526-d395054dc2c3` or later.
|
| CVE-2026-40318 |
|
Vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-40318)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-40318). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/av/removeUnusedAttributeView`. Mitigation: upgrade to `3.6.40.0.0-20260407035653-2f416e5253f1` or later.
|
| CVE-2026-3114 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3114)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3114). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.12+incompatible, 11.2.4+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
|
| GHSA-rp7v-4384-hfrp |
|
Vulnerability in github.com/k8sgpt-ai/k8sgpt (GHSA-rp7v-4384-hfrp)
vulnerability in github.com/k8sgpt-ai/k8sgpt (GHSA-rp7v-4384-hfrp). Risk of unauthorized operations or information disclosure. Exploitable via ``object_to_execution.go``. Mitigation: upgrade to `0.4.32` or later.
|
| CVE-2026-34984 |
|
Information Disclosure in github.com/external-secrets/external-secrets (CVE-2026-34984)
vulnerability in github.com/external-secrets/external-secrets (CVE-2026-34984). Confidential information can be exposed externally. Exploitable via ``env``.
|
| CVE-2026-41136 |
|
Vulnerability in github.com/free5gc/amf (CVE-2026-41136)
vulnerability in github.com/free5gc/amf (CVE-2026-41136). Risk of unauthorized operations or information disclosure. Exploitable via ``HTTPUEContextTransfer``.
|
| GHSA-rh99-wc69-c255 |
|
Vulnerability in github.com/edgelesssys/contrast (GHSA-rh99-wc69-c255)
vulnerability in github.com/edgelesssys/contrast (GHSA-rh99-wc69-c255). Confidential information can be exposed externally. Exploitable via ``CopyFile``. Mitigation: upgrade to `1.19.1` or later.
|
| CVE-2026-35599 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-35599)
vulnerability in code.vikunja.io/api (CVE-2026-35599). Risk of unauthorized operations or information disclosure. Exploitable via ``addRepeatIntervalToTime``. Mitigation: upgrade to `2.3.0` or later.
|
| GHSA-qmwh-9m9c-h36m |
|
Vulnerability in github.com/gotenberg/gotenberg/v7 (GHSA-qmwh-9m9c-h36m)
vulnerability in github.com/gotenberg/gotenberg/v7 (GHSA-qmwh-9m9c-h36m). Risk of unauthorized operations or information disclosure. Exploitable via ``HardLink``. Mitigation: upgrade to `8.30.0` or later.
|
| CVE-2026-34992 |
|
Vulnerability in antrea.io/antrea (CVE-2026-34992)
vulnerability in antrea.io/antrea (CVE-2026-34992). Confidential information can be exposed externally. Mitigation: upgrade to `1.11.0-alpha.0.0.20260225185322-738bad662b20` or later.
|
| CVE-2026-41571 |
|
Authentication Bypass in github.com/enchant97/note-mark/backend (CVE-2026-41571)
authentication bypass in github.com/enchant97/note-mark/backend (CVE-2026-41571). Confidential information can be exposed externally. Exploitable via `POST /api/auth/token`. Mitigation: upgrade to `0.0.0-20260417132909-dea5530cc989` or later.
|