Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-9716 Vulnerability in schneider-electric (CVE-2026-9716)
vulnerability in schneider-electric (CVE-2026-9716). Risk of unauthorized operations or information disclosure.
CVE-2026-9650 Vulnerability in schneider-electric (CVE-2026-9650)
vulnerability in schneider-electric (CVE-2026-9650). Confidential information can be exposed externally.
CVE-2026-9717 OS Command Injection in schneider-electric (CVE-2026-9717)
OS command injection in schneider-electric (CVE-2026-9717). Successful exploitation can lead to full system takeover.
CVE-2026-48944 Path Traversal in joomlaworks (CVE-2026-48944)
path traversal in joomlaworks (CVE-2026-48944). Confidential information can be exposed externally. Exploitable via ``configuration.php``.
CVE-2026-48946 Unrestricted File Upload in apache (CVE-2026-48946)
vulnerability in apache (CVE-2026-48946). Risk of unauthorized operations or information disclosure. Exploitable via ``shell.php``.
CVE-2026-48943 Vulnerability in c (CVE-2026-48943)
vulnerability in c (CVE-2026-48943). Risk of unauthorized operations or information disclosure. Exploitable via ``plg_user_k2``.
CVE-2026-48941 Vulnerability in joomlaworks (CVE-2026-48941)
vulnerability in joomlaworks (CVE-2026-48941). Risk of unauthorized operations or information disclosure. Exploitable via ``item.checkin``.
CVE-2026-48945 Unrestricted File Upload in joomlaworks (CVE-2026-48945)
vulnerability in joomlaworks (CVE-2026-48945). Risk of unauthorized operations or information disclosure.
CVE-2026-4522 Vulnerability in CVE-2026-4522 (CVE-2026-4522)
vulnerability in CVE-2026-4522 (CVE-2026-4522). Risk of unauthorized operations or information disclosure.
CVE-2026-48942 Cross-Site Scripting (XSS) in joomlaworks (CVE-2026-48942)
cross-site scripting in joomlaworks (CVE-2026-48942). Risk of unauthorized operations or information disclosure. Exploitable via ``src``.
CVE-2026-48940 Cross-Site Scripting (XSS) in joomlaworks (CVE-2026-48940)
cross-site scripting in joomlaworks (CVE-2026-48940). Risk of unauthorized operations or information disclosure. Exploitable via ``embedVideo``.
CVE-2026-12844 Vulnerability in CVE-2026-12844 (CVE-2026-12844)
vulnerability in CVE-2026-12844 (CVE-2026-12844). Risk of unauthorized operations or information disclosure.
GHSA-6447-269v-g68m Vulnerability in github.com/mezo-org/mezod (GHSA-6447-269v-g68m)
vulnerability in github.com/mezo-org/mezod (GHSA-6447-269v-g68m). Risk of unauthorized operations or information disclosure. Exploitable via ``bridgeOut``. Mitigation: upgrade to `8.0.0` or later.
CVE-2026-35606 Vulnerability in github.com/filebrowser/filebrowser (CVE-2026-35606)
vulnerability in github.com/filebrowser/filebrowser (CVE-2026-35606). Risk of unauthorized operations or information disclosure. Exploitable via ``resourceGetHandler``. Mitigation: upgrade to `2.63.1` or later.
CVE-2026-34529 Cross-Site Scripting (XSS) in github.com/filebrowser/filebrowser (CVE-2026-34529)
cross-site scripting in github.com/filebrowser/filebrowser (CVE-2026-34529). Confidential information can be exposed externally. Mitigation: upgrade to `2.62.2` or later.
CVE-2026-24661 Vulnerability in github.com/mattermost/mattermost-plugin-msteams (CVE-2026-24661)
vulnerability in github.com/mattermost/mattermost-plugin-msteams (CVE-2026-24661). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.15.1-0.20260213190728-6fe4d295592e` or later.
CVE-2026-40193 Vulnerability in github.com/foxcpp/maddy (CVE-2026-40193)
vulnerability in github.com/foxcpp/maddy (CVE-2026-40193). Confidential information can be exposed externally. Exploitable via ``auth.ldap``. Mitigation: upgrade to `0.9.3` or later.
CVE-2026-35605 Path Traversal in github.com/filebrowser/filebrowser (CVE-2026-35605)
path traversal in github.com/filebrowser/filebrowser (CVE-2026-35605). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.63.1` or later.
CVE-2026-40943 Vulnerability in github.com/oxia-db/oxia (CVE-2026-40943)
vulnerability in github.com/oxia-db/oxia (CVE-2026-40943). Risk of unauthorized operations or information disclosure. Exploitable via ``KeepAlive``. Mitigation: upgrade to `0.16.2` or later.
CVE-2026-40077 Vulnerability in github.com/henrygd/beszel (CVE-2026-40077)
vulnerability in github.com/henrygd/beszel (CVE-2026-40077). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/beszel/containers/logs`. Mitigation: upgrade to `0.18.7` or later.
CVE-2026-40876 Path Traversal in github.com/patrickhener/goshs (CVE-2026-40876)
path traversal in github.com/patrickhener/goshs (CVE-2026-40876). Successful exploitation can lead to full system takeover. Exploitable via `put /tmp/local_upload.txt`. Mitigation: upgrade to `2.0.0` or later.
CVE-2026-42238 Code Injection in github.com/0xJacky/nginx-ui (CVE-2026-42238)
code injection in github.com/0xJacky/nginx-ui (CVE-2026-42238). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/restore`. Mitigation: upgrade to `2.3.8` or later.
CVE-2026-3113 Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3113)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3113). Confidential information can be exposed externally. Mitigation: upgrade to `8.0.0-20260217110922-b7d4a1f1f59b` or later.
CVE-2026-40302 Vulnerability in github.com/openziti/zrok (CVE-2026-40302)
vulnerability in github.com/openziti/zrok (CVE-2026-40302). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.1` or later.
CVE-2026-35598 Vulnerability in code.vikunja.io/api (CVE-2026-35598)
vulnerability in code.vikunja.io/api (CVE-2026-35598). Risk of unauthorized operations or information disclosure. Exploitable via ``GetResource``. Mitigation: upgrade to `2.3.0` or later.
CVE-2026-35600 Cross-Site Scripting (XSS) in code.vikunja.io/api (CVE-2026-35600)
cross-site scripting in code.vikunja.io/api (CVE-2026-35600). Risk of unauthorized operations or information disclosure. Exploitable via ``notifications.go``. Mitigation: upgrade to `2.3.0` or later.
GHSA-3m6q-h5gj-7mrw Vulnerability in code.gitea.io/gitea (GHSA-3m6q-h5gj-7mrw)
vulnerability in code.gitea.io/gitea (GHSA-3m6q-h5gj-7mrw). Risk of unauthorized operations or information disclosure. Exploitable via ``fail``. Mitigation: upgrade to `1.25.0` or later.
CVE-2026-3112 Path Traversal in github.com/mattermost/mattermost-server (CVE-2026-3112)
path traversal in github.com/mattermost/mattermost-server (CVE-2026-3112). Confidential information can be exposed externally. Mitigation: upgrade to `10.11.12+incompatible, 11.2.4+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
CVE-2026-40304 Vulnerability in github.com/openziti/zrok (CVE-2026-40304)
vulnerability in github.com/openziti/zrok (CVE-2026-40304). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/v2/unaccess`. Mitigation: upgrade to `2.0.1` or later.
CVE-2026-41572 Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-41572)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-41572). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/books/{bookID}`. Mitigation: upgrade to `0.0.0-20260417132843-d1bf845a2a2d` or later.
CVE-2026-25996 Vulnerability in github.com/inspektor-gadget/inspektor-gadget (CVE-2026-25996)
vulnerability in github.com/inspektor-gadget/inspektor-gadget (CVE-2026-25996). Risk of unauthorized operations or information disclosure. Exploitable via ``columns``. Mitigation: upgrade to `0.49.1` or later.
CVE-2026-3108 Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3108)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3108). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.11+incompatible, 11.2.3+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
GHSA-3fxj-6jh8-hvhx Vulnerability in github.com/go-chi/chi/v5/middleware (GHSA-3fxj-6jh8-hvhx)
vulnerability in github.com/go-chi/chi/v5/middleware (GHSA-3fxj-6jh8-hvhx). Risk of unauthorized operations or information disclosure. Exploitable via ``RealIP``. Mitigation: upgrade to `5.3.0` or later.
GHSA-rjr7-jggh-pgcp Vulnerability in github.com/go-chi/chi/middleware (GHSA-rjr7-jggh-pgcp)
vulnerability in github.com/go-chi/chi/middleware (GHSA-rjr7-jggh-pgcp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.3.0` or later.
GHSA-9g5q-2w5x-hmxf Vulnerability in github.com/go-chi/chi/middleware (GHSA-9g5q-2w5x-hmxf)
vulnerability in github.com/go-chi/chi/middleware (GHSA-9g5q-2w5x-hmxf). Risk of unauthorized operations or information disclosure. Exploitable via ``Request.RemoteAddr``. Mitigation: upgrade to `5.3.0` or later.
GHSA-r4v7-6wcg-ghj5 Vulnerability in github.com/gtsteffaniak/filebrowser (GHSA-r4v7-6wcg-ghj5)
vulnerability in github.com/gtsteffaniak/filebrowser (GHSA-r4v7-6wcg-ghj5). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.0-20260522161427-fa5abc8c67f3a` or later.
CVE-2026-54679 Vulnerability in jqlang (CVE-2026-54679)
vulnerability in jqlang (CVE-2026-54679). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.2` or later.
CVE-2026-49839 Out-of-Bounds Write in jqlang (CVE-2026-49839)
out-of-bounds write in jqlang (CVE-2026-49839). Data can be tampered with by attackers. Mitigation: upgrade to `1.8.2` or later.
CVE-2026-47770 Vulnerability in c (CVE-2026-47770)
vulnerability in c (CVE-2026-47770). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.2` or later.
UBUNTU-CVE-2026-6091 Vulnerability in wolfssl (UBUNTU-CVE-2026-6091)
vulnerability in wolfssl (UBUNTU-CVE-2026-6091). Data can be tampered with by attackers.
UBUNTU-CVE-2026-6291 Vulnerability in wolfssl (UBUNTU-CVE-2026-6291)
vulnerability in wolfssl (UBUNTU-CVE-2026-6291). Confidential information can be exposed externally.
UBUNTU-CVE-2026-6094 Vulnerability in wolfssl (UBUNTU-CVE-2026-6094)
vulnerability in wolfssl (UBUNTU-CVE-2026-6094). Confidential information can be exposed externally.
UBUNTU-CVE-2026-55961 Vulnerability in wolfssl (UBUNTU-CVE-2026-55961)
vulnerability in wolfssl (UBUNTU-CVE-2026-55961). Data can be tampered with by attackers.
UBUNTU-CVE-2026-55967 Vulnerability in wolfssl (UBUNTU-CVE-2026-55967)
vulnerability in wolfssl (UBUNTU-CVE-2026-55967). Confidential information can be exposed externally.
UBUNTU-CVE-2026-54679 Vulnerability in jq (UBUNTU-CVE-2026-54679)
vulnerability in jq (UBUNTU-CVE-2026-54679). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.2` or later.
UBUNTU-CVE-2026-11999 Vulnerability in wolfssl (UBUNTU-CVE-2026-11999)
vulnerability in wolfssl (UBUNTU-CVE-2026-11999). Data can be tampered with by attackers.
GHSA-xr76-fgrm-h52p Vulnerability in ts-opus (GHSA-xr76-fgrm-h52p)
vulnerability in ts-opus (GHSA-xr76-fgrm-h52p). Risk of unauthorized operations or information disclosure. Exploitable via ``big.mjs``.
GHSA-fq3w-p4fg-mw73 Vulnerability in fixurjavainstall (GHSA-fq3w-p4fg-mw73)
vulnerability in fixurjavainstall (GHSA-fq3w-p4fg-mw73). Risk of unauthorized operations or information disclosure. Exploitable via ``dev``. Mitigation: upgrade to `0.8.1` or later.
GHSA-wrr4-782v-jhwh Vulnerability in neotoma (GHSA-wrr4-782v-jhwh)
vulnerability in neotoma (GHSA-wrr4-782v-jhwh). Risk of unauthorized operations or information disclosure. Exploitable via ``getAuthenticatedUserId``. Mitigation: upgrade to `0.14.0` or later.
GHSA-jf6w-2mvx-633j Cross-Site Scripting (XSS) in justhtml (GHSA-jf6w-2mvx-633j)
cross-site scripting in justhtml (GHSA-jf6w-2mvx-633j). Risk of unauthorized operations or information disclosure. Exploitable via ``justhtml``. Mitigation: upgrade to `1.22.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →