Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
GHSA-vx8x-rr42-fwhx Vulnerability in hexo-deployer-wrangler (GHSA-vx8x-rr42-fwhx)
vulnerability in hexo-deployer-wrangler (GHSA-vx8x-rr42-fwhx). Risk of unauthorized operations or information disclosure.
CVE-2026-43920 Vulnerability in csrf (CVE-2026-43920)
vulnerability in csrf (CVE-2026-43920). Risk of unauthorized operations or information disclosure.
OSV-2026-969 Vulnerability in ogre (OSV-2026-969)
vulnerability in ogre (OSV-2026-969). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4b066d6e8f340bc92f935a6d2161872413e4a460` or later.
RLSA-2026:29898 Vulnerability in libpng (RLSA-2026:29898)
vulnerability in libpng (RLSA-2026:29898). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2:1.6.34-11.el8_10` or later.
UBUNTU-CVE-2026-55520 [Unknown description]
UBUNTU-CVE-2026-54548 [Unknown description]
CVE-2026-40941 Vulnerability in cacti (CVE-2026-40941)
vulnerability in cacti (CVE-2026-40941). Data can be tampered with by attackers.
CVE-2026-40084 Path Traversal in path-traversal (CVE-2026-40084)
path traversal in path-traversal (CVE-2026-40084). Confidential information can be exposed externally.
CVE-2026-40083 SQL Injection in sqli (CVE-2026-40083)
SQL injection in sqli (CVE-2026-40083). Successful exploitation can lead to full system takeover.
CVE-2026-40082 Vulnerability in cacti (CVE-2026-40082)
vulnerability in cacti (CVE-2026-40082). Risk of unauthorized operations or information disclosure.
CVE-2026-40080 Open Redirect in cacti (CVE-2026-40080)
vulnerability in cacti (CVE-2026-40080). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-40941 Vulnerability in cacti (UBUNTU-CVE-2026-40941)
vulnerability in cacti (UBUNTU-CVE-2026-40941). Data can be tampered with by attackers.
UBUNTU-CVE-2026-40083 Vulnerability in cacti (UBUNTU-CVE-2026-40083)
vulnerability in cacti (UBUNTU-CVE-2026-40083). Successful exploitation can lead to full system takeover.
UBUNTU-CVE-2026-40082 Vulnerability in cacti (UBUNTU-CVE-2026-40082)
vulnerability in cacti (UBUNTU-CVE-2026-40082). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-40080 Vulnerability in cacti (UBUNTU-CVE-2026-40080)
vulnerability in cacti (UBUNTU-CVE-2026-40080). Risk of unauthorized operations or information disclosure.
UBUNTU-CVE-2026-40084 Vulnerability in cacti (UBUNTU-CVE-2026-40084)
vulnerability in cacti (UBUNTU-CVE-2026-40084). Confidential information can be exposed externally.
GHSA-jp8q-gmj4-fx77 Vulnerability in random-string-64 (GHSA-jp8q-gmj4-fx77)
vulnerability in random-string-64 (GHSA-jp8q-gmj4-fx77). Risk of unauthorized operations or information disclosure. Exploitable via ``globalThis.eval``.
MAL-2026-6489 Vulnerability in extra-huggingface (MAL-2026-6489)
vulnerability in extra-huggingface (MAL-2026-6489). Risk of unauthorized operations or information disclosure. Exploitable via ``run_agent``.
MAL-2026-6488 Vulnerability in pyext6cc8cd (MAL-2026-6488)
vulnerability in pyext6cc8cd (MAL-2026-6488). Risk of unauthorized operations or information disclosure. Exploitable via ``subprocess.Popen``.
CVE-2026-34530 Cross-Site Scripting (XSS) in github.com/filebrowser/filebrowser (CVE-2026-34530)
cross-site scripting in github.com/filebrowser/filebrowser (CVE-2026-34530). Confidential information can be exposed externally. Exploitable via `PUT /api/settings`. Mitigation: upgrade to `2.62.2` or later.
CVE-2026-41174 Vulnerability in github.com/traefik/traefik (CVE-2026-41174)
vulnerability in github.com/traefik/traefik (CVE-2026-41174). Risk of unauthorized operations or information disclosure. Exploitable via ``IngressRoute``. Mitigation: upgrade to `2.11.43` or later.
CVE-2026-4531 Vulnerability in github.com/free5gc/amf (CVE-2026-4531)
vulnerability in github.com/free5gc/amf (CVE-2026-4531). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.4.3-0.20260306074636-52e9386401ce` or later.
GHSA-xhj4-g6w8-2xjw Vulnerability in github.com/woven-planet/go-zserio (GHSA-xhj4-g6w8-2xjw)
vulnerability in github.com/woven-planet/go-zserio (GHSA-xhj4-g6w8-2xjw). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.9.1` or later.
GHSA-x3f4-v83f-7wp2 Open Redirect in github.com/authorizerdev/authorizer (GHSA-x3f4-v83f-7wp2)
vulnerability in github.com/authorizerdev/authorizer (GHSA-x3f4-v83f-7wp2). Risk of unauthorized operations or information disclosure. Exploitable via ``redirect_uri``. Mitigation: upgrade to `0.0.0-20260329085140-6d9bef1aaba3` or later.
CVE-2026-33031 Vulnerability in github.com/0xJacky/Nginx-UI (CVE-2026-33031)
vulnerability in github.com/0xJacky/Nginx-UI (CVE-2026-33031). Confidential information can be exposed externally. Exploitable via ``user.Status``. Mitigation: upgrade to `1.9.10-0.20260314152518-7b66578adb47` or later.
CVE-2026-34528 Privilege Escalation in github.com/filebrowser/filebrowser (CVE-2026-34528)
vulnerability in github.com/filebrowser/filebrowser (CVE-2026-34528). Successful exploitation can lead to full system takeover. Exploitable via ``signupHandler``. Mitigation: upgrade to `2.62.2` or later.
CVE-2026-40247 Vulnerability in github.com/free5gc/udr (CVE-2026-40247)
vulnerability in github.com/free5gc/udr (CVE-2026-40247). Confidential information can be exposed externally. Exploitable via `GET /nudr-dr/v2/application-data/influenceData/{influenceId}/{subscriptionId}`.
CVE-2026-40189 Vulnerability in github.com/patrickhener/goshs (CVE-2026-40189)
vulnerability in github.com/patrickhener/goshs (CVE-2026-40189). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload`.
CVE-2026-21388 Vulnerability in github.com/mattermost/mattermost-plugin-msteams (CVE-2026-21388)
vulnerability in github.com/mattermost/mattermost-plugin-msteams (CVE-2026-21388). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.15.1-0.20260213190728-6fe4d295592e` or later.
CVE-2026-35036 SSRF (Server-Side Request Forgery) in github.com/lin-snow/ech0 (CVE-2026-35036)
SSRF in github.com/lin-snow/ech0 (CVE-2026-35036). Confidential information can be exposed externally. Exploitable via `GET /api/website/title`. Mitigation: upgrade to `1.4.8-0.20260401031029-4ca56fea5ba4` or later.
CVE-2026-40107 SSRF (Server-Side Request Forgery) in github.com/siyuan-note/siyuan/kernel (CVE-2026-40107)
SSRF in github.com/siyuan-note/siyuan/kernel (CVE-2026-40107). Risk of unauthorized operations or information disclosure. Exploitable via ``src``. Mitigation: upgrade to `0.0.0-20260407035653-2f416e5253f1` or later.
GHSA-vjgj-42f6-7997 Vulnerability in github.com/tinfoil-factory/netfoil (GHSA-vjgj-42f6-7997)
vulnerability in github.com/tinfoil-factory/netfoil (GHSA-vjgj-42f6-7997). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.1` or later.
CVE-2026-35604 Authorization Flaw in github.com/filebrowser/filebrowser (CVE-2026-35604)
vulnerability in github.com/filebrowser/filebrowser (CVE-2026-35604). Risk of unauthorized operations or information disclosure. Exploitable via ``withHashFile``. Mitigation: upgrade to `2.63.1` or later.
CVE-2026-40481 Vulnerability in github.com/monetr/monetr (CVE-2026-40481)
vulnerability in github.com/monetr/monetr (CVE-2026-40481). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.12.4` or later.
GHSA-v5mh-h5hx-7v92 Vulnerability in github.com/cloudnativelabs/kube-router (GHSA-v5mh-h5hx-7v92)
vulnerability in github.com/cloudnativelabs/kube-router (GHSA-v5mh-h5hx-7v92). Risk of unauthorized operations or information disclosure. Exploitable via ``ROUTE_ACTION_REJECT``. Mitigation: upgrade to `2.9.0` or later.
GHSA-rxmp-8h9v-56cx Vulnerability in github.com/netbirdio/netbird (GHSA-rxmp-8h9v-56cx)
vulnerability in github.com/netbirdio/netbird (GHSA-rxmp-8h9v-56cx). Data can be tampered with by attackers. Exploitable via `PUT /api/users/{OLD_ADMIN_USERID}`. Mitigation: upgrade to `0.65.3` or later.
CVE-2026-40103 Vulnerability in code.vikunja.io/api (CVE-2026-40103)
vulnerability in code.vikunja.io/api (CVE-2026-40103). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/projects/`. Mitigation: upgrade to `2.3.0` or later.
CVE-2026-40245 Information Disclosure in github.com/free5gc/udr (CVE-2026-40245)
vulnerability in github.com/free5gc/udr (CVE-2026-40245). Confidential information can be exposed externally. Exploitable via `GET /nudr-dr/v2/application-data/influenceData/subs-to-notify`.
CVE-2026-40263 Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-40263)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-40263). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/auth/token`. Mitigation: upgrade to `0.19.2-0.20260411145025-cf4c6f6acf70` or later.
CVE-2026-5412 Vulnerability in github.com/juju/juju (CVE-2026-5412)
vulnerability in github.com/juju/juju (CVE-2026-5412). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.0-20260408003526-d395054dc2c3` or later.
CVE-2026-40318 Vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-40318)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-40318). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/av/removeUnusedAttributeView`. Mitigation: upgrade to `3.6.40.0.0-20260407035653-2f416e5253f1` or later.
CVE-2026-3114 Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3114)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3114). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.12+incompatible, 11.2.4+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
GHSA-rp7v-4384-hfrp Vulnerability in github.com/k8sgpt-ai/k8sgpt (GHSA-rp7v-4384-hfrp)
vulnerability in github.com/k8sgpt-ai/k8sgpt (GHSA-rp7v-4384-hfrp). Risk of unauthorized operations or information disclosure. Exploitable via ``object_to_execution.go``. Mitigation: upgrade to `0.4.32` or later.
CVE-2026-34984 Information Disclosure in github.com/external-secrets/external-secrets (CVE-2026-34984)
vulnerability in github.com/external-secrets/external-secrets (CVE-2026-34984). Confidential information can be exposed externally. Exploitable via ``env``.
CVE-2026-41136 Vulnerability in github.com/free5gc/amf (CVE-2026-41136)
vulnerability in github.com/free5gc/amf (CVE-2026-41136). Risk of unauthorized operations or information disclosure. Exploitable via ``HTTPUEContextTransfer``.
GHSA-rh99-wc69-c255 Vulnerability in github.com/edgelesssys/contrast (GHSA-rh99-wc69-c255)
vulnerability in github.com/edgelesssys/contrast (GHSA-rh99-wc69-c255). Confidential information can be exposed externally. Exploitable via ``CopyFile``. Mitigation: upgrade to `1.19.1` or later.
CVE-2026-35599 Vulnerability in code.vikunja.io/api (CVE-2026-35599)
vulnerability in code.vikunja.io/api (CVE-2026-35599). Risk of unauthorized operations or information disclosure. Exploitable via ``addRepeatIntervalToTime``. Mitigation: upgrade to `2.3.0` or later.
GHSA-qmwh-9m9c-h36m Vulnerability in github.com/gotenberg/gotenberg/v7 (GHSA-qmwh-9m9c-h36m)
vulnerability in github.com/gotenberg/gotenberg/v7 (GHSA-qmwh-9m9c-h36m). Risk of unauthorized operations or information disclosure. Exploitable via ``HardLink``. Mitigation: upgrade to `8.30.0` or later.
CVE-2026-34992 Vulnerability in antrea.io/antrea (CVE-2026-34992)
vulnerability in antrea.io/antrea (CVE-2026-34992). Confidential information can be exposed externally. Mitigation: upgrade to `1.11.0-alpha.0.0.20260225185322-738bad662b20` or later.
CVE-2026-41571 Authentication Bypass in github.com/enchant97/note-mark/backend (CVE-2026-41571)
authentication bypass in github.com/enchant97/note-mark/backend (CVE-2026-41571). Confidential information can be exposed externally. Exploitable via `POST /api/auth/token`. Mitigation: upgrade to `0.0.0-20260417132909-dea5530cc989` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →