Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-67cf-2jr7-8qjv |
|
MINI-67cf-2jr7-8qjv |
| MINI-wh2c-qh2x-prrx |
|
MINI-wh2c-qh2x-prrx |
| MINI-wjh3-rmh4-245j |
|
MINI-wjh3-rmh4-245j |
| MINI-wrfr-vrx6-32w2 |
|
MINI-wrfr-vrx6-32w2 |
| MINI-m8v3-6qxc-86vj |
|
MINI-m8v3-6qxc-86vj |
| MINI-mcmp-c5rf-hw95 |
|
MINI-mcmp-c5rf-hw95 |
| MINI-c9hj-vf4f-37q8 |
|
MINI-c9hj-vf4f-37q8 |
| MINI-874p-q2xv-hpv9 |
|
MINI-874p-q2xv-hpv9 |
| MINI-3jwh-wpcf-h4wm |
|
MINI-3jwh-wpcf-h4wm |
| MINI-7jgg-hgh8-x4c7 |
|
MINI-7jgg-hgh8-x4c7 |
| MINI-4r9v-m6xj-wm88 |
|
MINI-4r9v-m6xj-wm88 |
| MINI-3v38-6x52-529m |
|
MINI-3v38-6x52-529m |
| MINI-2whr-j866-5c6v |
|
MINI-2whr-j866-5c6v |
| MINI-2x49-7w79-mq44 |
|
MINI-2x49-7w79-mq44 |
| MINI-mcfh-89qj-x438 |
|
MINI-mcfh-89qj-x438 |
| MINI-x5mf-247p-88qr |
|
MINI-x5mf-247p-88qr |
| MINI-376p-pfm9-63mr |
|
MINI-376p-pfm9-63mr |
| MINI-77hh-56q6-2628 |
|
MINI-77hh-56q6-2628 |
| SUSE-SU-2026:22369-1 |
|
Vulnerability in libaom (SUSE-SU-2026:22369-1)
vulnerability in libaom (SUSE-SU-2026:22369-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.11.0-160000.3.1` or later.
|
| openSUSE-SU-2026:21061-1 |
|
Vulnerability in libaom (openSUSE-SU-2026:21061-1)
vulnerability in libaom (openSUSE-SU-2026:21061-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.11.0-160000.3.1` or later.
|
| CVE-2026-55667 |
|
Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55667)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55667). Data can be tampered with by attackers. Exploitable via `GET /api/raw/link/secret.txt`. Mitigation: upgrade to `2.63.16` or later.
|
| CVE-2026-54917 |
|
Path Traversal in github.com/seaweedfs/seaweedfs (CVE-2026-54917)
path traversal in github.com/seaweedfs/seaweedfs (CVE-2026-54917). Confidential information can be exposed externally. Exploitable via `GET /bucket-A/../evil-bucket/key`. Mitigation: upgrade to `0.0.0-20260526080459-dd1b4287899e` or later.
|
| CVE-2026-54250 |
|
Path Traversal in github.com/k3s-io/k3s (CVE-2026-54250)
path traversal in github.com/k3s-io/k3s (CVE-2026-54250). Data can be tampered with by attackers. Exploitable via ``GODEBUG``. Mitigation: upgrade to `1.33.10` or later.
|
| CVE-2026-54089 |
|
Authentication Bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089)
authentication bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089). Confidential information can be exposed externally. Exploitable via `POST /api/login`.
|
| CVE-2026-54088 |
|
OS Command Injection in github.com/filebrowser/filebrowser/v2 (CVE-2026-54088)
OS command injection in github.com/filebrowser/filebrowser/v2 (CVE-2026-54088). Risk of unauthorized operations or information disclosure. Exploitable via ``os.Expand``. Mitigation: upgrade to `2.63.6` or later.
|
| CVE-2026-50549 |
|
Vulnerability in anysphere (CVE-2026-50549)
vulnerability in anysphere (CVE-2026-50549). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.0` or later.
|
| CVE-2026-50548 |
|
Path Traversal in anysphere (CVE-2026-50548)
path traversal in anysphere (CVE-2026-50548). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.0` or later.
|
| UBUNTU-CVE-2026-56789 |
|
Vulnerability in rtklib (UBUNTU-CVE-2026-56789)
vulnerability in rtklib (UBUNTU-CVE-2026-56789). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-56786 |
|
Vulnerability in rtklib (UBUNTU-CVE-2026-56786)
vulnerability in rtklib (UBUNTU-CVE-2026-56786). Successful exploitation can lead to full system takeover.
|
| UBUNTU-CVE-2026-56787 |
|
Vulnerability in rtklib (UBUNTU-CVE-2026-56787)
vulnerability in rtklib (UBUNTU-CVE-2026-56787). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-56788 |
|
Vulnerability in rtklib (UBUNTU-CVE-2026-56788)
vulnerability in rtklib (UBUNTU-CVE-2026-56788). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-56770 |
|
Vulnerability in python-libais (UBUNTU-CVE-2026-56770)
vulnerability in python-libais (UBUNTU-CVE-2026-56770). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-56766 |
|
Vulnerability in hydra (UBUNTU-CVE-2026-56766)
vulnerability in hydra (UBUNTU-CVE-2026-56766). Successful exploitation can lead to full system takeover.
|
| UBUNTU-CVE-2026-53925 |
|
Vulnerability in glances (UBUNTU-CVE-2026-53925)
vulnerability in glances (UBUNTU-CVE-2026-53925). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.5` or later.
|
| UBUNTU-CVE-2026-46611 |
|
Vulnerability in glances (UBUNTU-CVE-2026-46611)
vulnerability in glances (UBUNTU-CVE-2026-46611). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `4.5.5` or later.
|
| UBUNTU-CVE-2026-46606 |
|
Vulnerability in glances (UBUNTU-CVE-2026-46606)
vulnerability in glances (UBUNTU-CVE-2026-46606). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.5` or later.
|
| UBUNTU-CVE-2026-46607 |
|
Vulnerability in glances (UBUNTU-CVE-2026-46607)
vulnerability in glances (UBUNTU-CVE-2026-46607). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.5.5` or later.
|
| UBUNTU-CVE-2026-46608 |
|
Vulnerability in glances (UBUNTU-CVE-2026-46608)
vulnerability in glances (UBUNTU-CVE-2026-46608). Confidential information can be exposed externally. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-48508 |
|
Authorization Flaw in lemur (CVE-2026-48508)
vulnerability in lemur (CVE-2026-48508). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/1/authorities`. Mitigation: upgrade to `1.9.1` or later.
|
| MAL-2026-6471 |
|
Vulnerability in tailwind-color-shades (MAL-2026-6471)
vulnerability in tailwind-color-shades (MAL-2026-6471). Risk of unauthorized operations or information disclosure. Exploitable via ``index.ts``.
|
| GHSA-5xpc-q26w-px3q |
|
Vulnerability in tailwindcss-effector (GHSA-5xpc-q26w-px3q)
vulnerability in tailwindcss-effector (GHSA-5xpc-q26w-px3q). Risk of unauthorized operations or information disclosure. Exploitable via ``eth_call``.
|
| CVE-2026-40246 |
|
Vulnerability in github.com/free5gc/udr (CVE-2026-40246)
vulnerability in github.com/free5gc/udr (CVE-2026-40246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35458 |
|
Vulnerability in github.com/gotenberg/gotenberg/v7 (CVE-2026-35458)
vulnerability in github.com/gotenberg/gotenberg/v7 (CVE-2026-35458). Risk of unauthorized operations or information disclosure. Exploitable via ``extraHttpHeaders``. Mitigation: upgrade to `8.30.0` or later.
|
| CVE-2026-34969 |
|
Information Disclosure in github.com/nhost/nhost (CVE-2026-34969)
vulnerability in github.com/nhost/nhost (CVE-2026-34969). Confidential information can be exposed externally. Exploitable via `GET /signin/provider/github`. Mitigation: upgrade to `0.0.0-20260330133707-294954e0fc3a` or later.
|
| CVE-2026-4274 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-4274)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-4274). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.11+incompatible, 11.2.3+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
|
| GHSA-fcmh-qfxc-w685 |
|
Vulnerability in github.com/cloudnativelabs/kube-router (GHSA-fcmh-qfxc-w685)
vulnerability in github.com/cloudnativelabs/kube-router (GHSA-fcmh-qfxc-w685). Confidential information can be exposed externally. Exploitable via ``node.Annotations``.
|
| CVE-2026-34585 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-34585)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-34585). Successful exploitation can lead to full system takeover. Exploitable via ``escapeNodeAttributeValues``. Mitigation: upgrade to `0.0.0-20260329142331-918d1bd9f967` or later.
|
| CVE-2026-35597 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-35597)
vulnerability in code.vikunja.io/api (CVE-2026-35597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40242 |
|
Vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-40242)
vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-40242). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.17.3` or later.
|
| CVE-2026-27656 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-27656)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-27656). Confidential information can be exposed externally. Mitigation: upgrade to `10.11.12` or later.
|