Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-27769 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-27769)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-27769). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.0-20260316060126-bc1a2b34b1f9` or later.
|
| CVE-2026-42223 |
|
Information Disclosure in github.com/0xJacky/nginx-ui (CVE-2026-42223)
vulnerability in github.com/0xJacky/nginx-ui (CVE-2026-42223). Confidential information can be exposed externally. Exploitable via `GET /api/settings`. Mitigation: upgrade to `2.3.8` or later.
|
| GHSA-prxj-3gcv-cqrh |
|
Vulnerability in github.com/teslamotors/fleet-telemetry (GHSA-prxj-3gcv-cqrh)
vulnerability in github.com/teslamotors/fleet-telemetry (GHSA-prxj-3gcv-cqrh). Data can be tampered with by attackers. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-27659 |
|
Cross-Site Request Forgery (CSRF) in github.com/mattermost/mattermost-server (CVE-2026-27659)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-27659). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.11+incompatible, 11.2.3+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
|
| CVE-2026-29051 |
|
Path Traversal in chainguard.dev/melange (CVE-2026-29051)
path traversal in chainguard.dev/melange (CVE-2026-29051). Risk of unauthorized operations or information disclosure. Exploitable via ``arch``. Mitigation: upgrade to `0.43.4` or later.
|
| CVE-2026-35602 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-35602)
vulnerability in code.vikunja.io/api (CVE-2026-35602). Risk of unauthorized operations or information disclosure. Exploitable via ``Size``. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-40910 |
|
Authentication Bypass in github.com/fatedier/frp (CVE-2026-40910)
authentication bypass in github.com/fatedier/frp (CVE-2026-40910). Confidential information can be exposed externally. Exploitable via ``routeByHTTPUser``. Mitigation: upgrade to `0.68.1` or later.
|
| CVE-2026-40945 |
|
Vulnerability in github.com/oxia-db/oxia (CVE-2026-40945)
vulnerability in github.com/oxia-db/oxia (CVE-2026-40945). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.16.2` or later.
|
| CVE-2026-40265 |
|
Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-40265)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-40265). Confidential information can be exposed externally. Exploitable via ``notes``. Mitigation: upgrade to `0.0.0-20260411145023-6593898855ad` or later.
|
| CVE-2026-42222 |
|
Vulnerability in github.com/0xJacky/nginx-ui (CVE-2026-42222)
vulnerability in github.com/0xJacky/nginx-ui (CVE-2026-42222). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/install`.
|
| CVE-2026-3115 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-3115)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3115). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.11+incompatible, 11.2.3+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
|
| GHSA-mmpx-jh39-wrv6 |
|
Cross-Site Scripting (XSS) in github.com/gtsteffaniak/filebrowser (GHSA-mmpx-jh39-wrv6)
cross-site scripting in github.com/gtsteffaniak/filebrowser (GHSA-mmpx-jh39-wrv6). Risk of unauthorized operations or information disclosure. Exploitable via `GET /public/api/resources/download`. Mitigation: upgrade to `0.0.0-20260501184955-6bfc3974192e` or later.
|
| CVE-2026-28741 |
|
Cross-Site Request Forgery (CSRF) in github.com/mattermost/mattermost-server (CVE-2026-28741)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-28741). Confidential information can be exposed externally. Mitigation: upgrade to `11.3.3+incompatible, 11.4.3+incompatible, 11.5.0+incompatible` or later.
|
| CVE-2026-40883 |
|
Cross-Site Request Forgery (CSRF) in github.com/patrickhener/goshs (CVE-2026-40883)
vulnerability in github.com/patrickhener/goshs (CVE-2026-40883). Data can be tampered with by attackers. Exploitable via ``Origin``. Mitigation: upgrade to `2.0.0-beta.6` or later.
|
| CVE-2026-40343 |
|
Vulnerability in github.com/free5gc/udr (CVE-2026-40343)
vulnerability in github.com/free5gc/udr (CVE-2026-40343). Risk of unauthorized operations or information disclosure. Exploitable via `POST /nudr-dr/v2/policy-data/subs-to-notify`.
|
| GHSA-jfwg-rxf3-p7r9 |
|
Vulnerability in github.com/authorizerdev/authorizer (GHSA-jfwg-rxf3-p7r9)
vulnerability in github.com/authorizerdev/authorizer (GHSA-jfwg-rxf3-p7r9). Risk of unauthorized operations or information disclosure. Exploitable via ``fmt.Sprintf``. Mitigation: upgrade to `0.0.0-20260327055742-73679faa53cd` or later.
|
| GHSA-h829-5cg7-6hff |
|
Vulnerability in github.com/supply-chain-tools/gitverify (GHSA-h829-5cg7-6hff)
vulnerability in github.com/supply-chain-tools/gitverify (GHSA-h829-5cg7-6hff). Risk of unauthorized operations or information disclosure. Exploitable via ``requireSignedTags``. Mitigation: upgrade to `0.0.0-20260421124901-c2c60da05d5c` or later.
|
| CVE-2026-6290 |
|
Authorization Flaw in www.velocidex.com/golang/velociraptor (CVE-2026-6290)
vulnerability in www.velocidex.com/golang/velociraptor (CVE-2026-6290). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40248 |
|
Vulnerability in github.com/free5gc/udr (CVE-2026-40248)
vulnerability in github.com/free5gc/udr (CVE-2026-40248). Data can be tampered with by attackers. Exploitable via `PUT /nudr-dr/v2/application-data/influenceData/{influenceId}/{subscriptionId}`.
|
| CVE-2026-39972 |
|
Vulnerability in github.com/dunglas/mercure (CVE-2026-39972)
vulnerability in github.com/dunglas/mercure (CVE-2026-39972). Risk of unauthorized operations or information disclosure. Exploitable via ``TopicSelectorStore``. Mitigation: upgrade to `0.22.0` or later.
|
| GHSA-hw5x-4r37-72w7 |
|
Vulnerability in github.com/opentofu/opentofu (GHSA-hw5x-4r37-72w7)
vulnerability in github.com/opentofu/opentofu (GHSA-hw5x-4r37-72w7). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.11.6` or later.
|
| CVE-2026-41894 |
|
Path Traversal in github.com/siyuan-note/siyuan/kernel (CVE-2026-41894)
path traversal in github.com/siyuan-note/siyuan/kernel (CVE-2026-41894). Risk of unauthorized operations or information disclosure. Exploitable via `GET /export/`. Mitigation: upgrade to `3.6.5` or later.
|
| CVE-2026-40109 |
|
Authentication Bypass in github.com/fluxcd/notification-controller (CVE-2026-40109)
authentication bypass in github.com/fluxcd/notification-controller (CVE-2026-40109). Risk of unauthorized operations or information disclosure. Exploitable via ``gcr``. Mitigation: upgrade to `1.8.3` or later.
|
| CVE-2026-3590 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3590)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3590). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.3.3` or later.
|
| GHSA-mhc4-qq83-fmrr |
|
Vulnerability in github.com/getaxonflow/axonflow-sdk-go (GHSA-mhc4-qq83-fmrr)
vulnerability in github.com/getaxonflow/axonflow-sdk-go (GHSA-mhc4-qq83-fmrr). Data can be tampered with by attackers. Exploitable via ``WebhookSubscription``. Mitigation: upgrade to `5.7.0` or later.
|
| CVE-2026-42221 |
|
Vulnerability in github.com/0xJacky/Nginx-UI (CVE-2026-42221)
vulnerability in github.com/0xJacky/Nginx-UI (CVE-2026-42221). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/install`. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-4370 |
|
Vulnerability in github.com/juju/juju (CVE-2026-4370)
vulnerability in github.com/juju/juju (CVE-2026-4370). Risk of unauthorized operations or information disclosure.
|
| GHSA-h9mw-h4qc-f5jf |
|
Vulnerability in github.com/platform-mesh/kubernetes-graphql-gateway (GHSA-h9mw-h4qc-f5jf)
vulnerability in github.com/platform-mesh/kubernetes-graphql-gateway (GHSA-h9mw-h4qc-f5jf). Risk of unauthorized operations or information disclosure. Exploitable via ``registry.go``. Mitigation: upgrade to `1.2.9` or later.
|
| GHSA-h5fq-653g-gxrm |
|
Vulnerability in github.com/Luzifer/ots (GHSA-h5fq-653g-gxrm)
vulnerability in github.com/Luzifer/ots (GHSA-h5fq-653g-gxrm). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.21.5` or later.
|
| CVE-2026-40249 |
|
Vulnerability in github.com/free5gc/udr (CVE-2026-40249)
vulnerability in github.com/free5gc/udr (CVE-2026-40249). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /nudr-dr/v2/policy-data/subs-to-notify/{subsId}`.
|
| GHSA-wcmr-4783-pq3p |
|
Vulnerability in gx-npm-lib (GHSA-wcmr-4783-pq3p)
vulnerability in gx-npm-lib (GHSA-wcmr-4783-pq3p). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| GHSA-5jpv-9x2f-72jj |
|
Vulnerability in gx-npm-ui (GHSA-5jpv-9x2f-72jj)
vulnerability in gx-npm-ui (GHSA-5jpv-9x2f-72jj). Risk of unauthorized operations or information disclosure. Exploitable via ``d8uectoqtvskhftsa940pm3kth3ahdxn4.oast.me``.
|
| GHSA-2736-v5cj-q9x5 |
|
Vulnerability in velocityfix (GHSA-2736-v5cj-q9x5)
vulnerability in velocityfix (GHSA-2736-v5cj-q9x5). Risk of unauthorized operations or information disclosure. Exploitable via ``username``.
|
| MAL-2026-6483 |
|
Vulnerability in log-update-ts (MAL-2026-6483)
vulnerability in log-update-ts (MAL-2026-6483). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6479 |
|
Vulnerability in @salem_jalal/osc-components (MAL-2026-6479)
vulnerability in @salem_jalal/osc-components (MAL-2026-6479). Risk of unauthorized operations or information disclosure.
|
| GHSA-4gj3-wx83-w2hr |
|
Vulnerability in unsafe-malicious-package (GHSA-4gj3-wx83-w2hr)
vulnerability in unsafe-malicious-package (GHSA-4gj3-wx83-w2hr). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-6331 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-6331)
vulnerability in wolfssl (UBUNTU-CVE-2026-6331). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-6329 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-6329)
vulnerability in wolfssl (UBUNTU-CVE-2026-6329). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-6330 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-6330)
vulnerability in wolfssl (UBUNTU-CVE-2026-6330). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-8720 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-8720)
vulnerability in wolfssl (UBUNTU-CVE-2026-8720). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-7532 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-7532)
vulnerability in wolfssl (UBUNTU-CVE-2026-7532). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-7511 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-7511)
vulnerability in wolfssl (UBUNTU-CVE-2026-7511). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-6325 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-6325)
vulnerability in wolfssl (UBUNTU-CVE-2026-6325). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-6092 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-6092)
vulnerability in wolfssl (UBUNTU-CVE-2026-6092). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-55962 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-55962)
vulnerability in wolfssl (UBUNTU-CVE-2026-55962). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-22879 |
|
vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability |
| UBUNTU-CVE-2026-11703 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-11703)
vulnerability in wolfssl (UBUNTU-CVE-2026-11703). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-10098 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-10098)
vulnerability in wolfssl (UBUNTU-CVE-2026-10098). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6485 |
|
Vulnerability in starship-timeline (MAL-2026-6485)
vulnerability in starship-timeline (MAL-2026-6485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55166 |
|
Vulnerability in lemur (CVE-2026-55166)
vulnerability in lemur (CVE-2026-55166). Confidential information can be exposed externally. Exploitable via `POST /api/1/authorities`. Mitigation: upgrade to `1.9.2` or later.
|