Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9716 |
|
Vulnerability in schneider-electric (CVE-2026-9716)
vulnerability in schneider-electric (CVE-2026-9716). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9650 |
|
Vulnerability in schneider-electric (CVE-2026-9650)
vulnerability in schneider-electric (CVE-2026-9650). Confidential information can be exposed externally.
|
| CVE-2026-9717 |
|
OS Command Injection in schneider-electric (CVE-2026-9717)
OS command injection in schneider-electric (CVE-2026-9717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48944 |
|
Path Traversal in joomlaworks (CVE-2026-48944)
path traversal in joomlaworks (CVE-2026-48944). Confidential information can be exposed externally. Exploitable via ``configuration.php``.
|
| CVE-2026-48946 |
|
Unrestricted File Upload in apache (CVE-2026-48946)
vulnerability in apache (CVE-2026-48946). Risk of unauthorized operations or information disclosure. Exploitable via ``shell.php``.
|
| CVE-2026-48943 |
|
Vulnerability in c (CVE-2026-48943)
vulnerability in c (CVE-2026-48943). Risk of unauthorized operations or information disclosure. Exploitable via ``plg_user_k2``.
|
| CVE-2026-48941 |
|
Vulnerability in joomlaworks (CVE-2026-48941)
vulnerability in joomlaworks (CVE-2026-48941). Risk of unauthorized operations or information disclosure. Exploitable via ``item.checkin``.
|
| CVE-2026-48945 |
|
Unrestricted File Upload in joomlaworks (CVE-2026-48945)
vulnerability in joomlaworks (CVE-2026-48945). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4522 |
|
Vulnerability in CVE-2026-4522 (CVE-2026-4522)
vulnerability in CVE-2026-4522 (CVE-2026-4522). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48942 |
|
Cross-Site Scripting (XSS) in joomlaworks (CVE-2026-48942)
cross-site scripting in joomlaworks (CVE-2026-48942). Risk of unauthorized operations or information disclosure. Exploitable via ``src``.
|
| CVE-2026-48940 |
|
Cross-Site Scripting (XSS) in joomlaworks (CVE-2026-48940)
cross-site scripting in joomlaworks (CVE-2026-48940). Risk of unauthorized operations or information disclosure. Exploitable via ``embedVideo``.
|
| CVE-2026-12844 |
|
Vulnerability in CVE-2026-12844 (CVE-2026-12844)
vulnerability in CVE-2026-12844 (CVE-2026-12844). Risk of unauthorized operations or information disclosure.
|
| GHSA-6447-269v-g68m |
|
Vulnerability in github.com/mezo-org/mezod (GHSA-6447-269v-g68m)
vulnerability in github.com/mezo-org/mezod (GHSA-6447-269v-g68m). Risk of unauthorized operations or information disclosure. Exploitable via ``bridgeOut``. Mitigation: upgrade to `8.0.0` or later.
|
| CVE-2026-35606 |
|
Vulnerability in github.com/filebrowser/filebrowser (CVE-2026-35606)
vulnerability in github.com/filebrowser/filebrowser (CVE-2026-35606). Risk of unauthorized operations or information disclosure. Exploitable via ``resourceGetHandler``. Mitigation: upgrade to `2.63.1` or later.
|
| CVE-2026-34529 |
|
Cross-Site Scripting (XSS) in github.com/filebrowser/filebrowser (CVE-2026-34529)
cross-site scripting in github.com/filebrowser/filebrowser (CVE-2026-34529). Confidential information can be exposed externally. Mitigation: upgrade to `2.62.2` or later.
|
| CVE-2026-24661 |
|
Vulnerability in github.com/mattermost/mattermost-plugin-msteams (CVE-2026-24661)
vulnerability in github.com/mattermost/mattermost-plugin-msteams (CVE-2026-24661). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.15.1-0.20260213190728-6fe4d295592e` or later.
|
| CVE-2026-40193 |
|
Vulnerability in github.com/foxcpp/maddy (CVE-2026-40193)
vulnerability in github.com/foxcpp/maddy (CVE-2026-40193). Confidential information can be exposed externally. Exploitable via ``auth.ldap``. Mitigation: upgrade to `0.9.3` or later.
|
| CVE-2026-35605 |
|
Path Traversal in github.com/filebrowser/filebrowser (CVE-2026-35605)
path traversal in github.com/filebrowser/filebrowser (CVE-2026-35605). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.63.1` or later.
|
| CVE-2026-40943 |
|
Vulnerability in github.com/oxia-db/oxia (CVE-2026-40943)
vulnerability in github.com/oxia-db/oxia (CVE-2026-40943). Risk of unauthorized operations or information disclosure. Exploitable via ``KeepAlive``. Mitigation: upgrade to `0.16.2` or later.
|
| CVE-2026-40077 |
|
Vulnerability in github.com/henrygd/beszel (CVE-2026-40077)
vulnerability in github.com/henrygd/beszel (CVE-2026-40077). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/beszel/containers/logs`. Mitigation: upgrade to `0.18.7` or later.
|
| CVE-2026-40876 |
|
Path Traversal in github.com/patrickhener/goshs (CVE-2026-40876)
path traversal in github.com/patrickhener/goshs (CVE-2026-40876). Successful exploitation can lead to full system takeover. Exploitable via `put /tmp/local_upload.txt`. Mitigation: upgrade to `2.0.0` or later.
|
| CVE-2026-42238 |
|
Code Injection in github.com/0xJacky/nginx-ui (CVE-2026-42238)
code injection in github.com/0xJacky/nginx-ui (CVE-2026-42238). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/restore`. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-3113 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3113)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3113). Confidential information can be exposed externally. Mitigation: upgrade to `8.0.0-20260217110922-b7d4a1f1f59b` or later.
|
| CVE-2026-40302 |
|
Vulnerability in github.com/openziti/zrok (CVE-2026-40302)
vulnerability in github.com/openziti/zrok (CVE-2026-40302). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.1` or later.
|
| CVE-2026-35598 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-35598)
vulnerability in code.vikunja.io/api (CVE-2026-35598). Risk of unauthorized operations or information disclosure. Exploitable via ``GetResource``. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-35600 |
|
Cross-Site Scripting (XSS) in code.vikunja.io/api (CVE-2026-35600)
cross-site scripting in code.vikunja.io/api (CVE-2026-35600). Risk of unauthorized operations or information disclosure. Exploitable via ``notifications.go``. Mitigation: upgrade to `2.3.0` or later.
|
| GHSA-3m6q-h5gj-7mrw |
|
Vulnerability in code.gitea.io/gitea (GHSA-3m6q-h5gj-7mrw)
vulnerability in code.gitea.io/gitea (GHSA-3m6q-h5gj-7mrw). Risk of unauthorized operations or information disclosure. Exploitable via ``fail``. Mitigation: upgrade to `1.25.0` or later.
|
| CVE-2026-3112 |
|
Path Traversal in github.com/mattermost/mattermost-server (CVE-2026-3112)
path traversal in github.com/mattermost/mattermost-server (CVE-2026-3112). Confidential information can be exposed externally. Mitigation: upgrade to `10.11.12+incompatible, 11.2.4+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
|
| CVE-2026-40304 |
|
Vulnerability in github.com/openziti/zrok (CVE-2026-40304)
vulnerability in github.com/openziti/zrok (CVE-2026-40304). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/v2/unaccess`. Mitigation: upgrade to `2.0.1` or later.
|
| CVE-2026-41572 |
|
Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-41572)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-41572). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/books/{bookID}`. Mitigation: upgrade to `0.0.0-20260417132843-d1bf845a2a2d` or later.
|
| CVE-2026-25996 |
|
Vulnerability in github.com/inspektor-gadget/inspektor-gadget (CVE-2026-25996)
vulnerability in github.com/inspektor-gadget/inspektor-gadget (CVE-2026-25996). Risk of unauthorized operations or information disclosure. Exploitable via ``columns``. Mitigation: upgrade to `0.49.1` or later.
|
| CVE-2026-3108 |
|
Vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3108)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-3108). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.11+incompatible, 11.2.3+incompatible, 11.3.2+incompatible, 11.4.1+incompatible` or later.
|
| GHSA-3fxj-6jh8-hvhx |
|
Vulnerability in github.com/go-chi/chi/v5/middleware (GHSA-3fxj-6jh8-hvhx)
vulnerability in github.com/go-chi/chi/v5/middleware (GHSA-3fxj-6jh8-hvhx). Risk of unauthorized operations or information disclosure. Exploitable via ``RealIP``. Mitigation: upgrade to `5.3.0` or later.
|
| GHSA-rjr7-jggh-pgcp |
|
Vulnerability in github.com/go-chi/chi/middleware (GHSA-rjr7-jggh-pgcp)
vulnerability in github.com/go-chi/chi/middleware (GHSA-rjr7-jggh-pgcp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.3.0` or later.
|
| GHSA-9g5q-2w5x-hmxf |
|
Vulnerability in github.com/go-chi/chi/middleware (GHSA-9g5q-2w5x-hmxf)
vulnerability in github.com/go-chi/chi/middleware (GHSA-9g5q-2w5x-hmxf). Risk of unauthorized operations or information disclosure. Exploitable via ``Request.RemoteAddr``. Mitigation: upgrade to `5.3.0` or later.
|
| GHSA-r4v7-6wcg-ghj5 |
|
Vulnerability in github.com/gtsteffaniak/filebrowser (GHSA-r4v7-6wcg-ghj5)
vulnerability in github.com/gtsteffaniak/filebrowser (GHSA-r4v7-6wcg-ghj5). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.0-20260522161427-fa5abc8c67f3a` or later.
|
| CVE-2026-54679 |
|
Vulnerability in jqlang (CVE-2026-54679)
vulnerability in jqlang (CVE-2026-54679). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.2` or later.
|
| CVE-2026-49839 |
|
Out-of-Bounds Write in jqlang (CVE-2026-49839)
out-of-bounds write in jqlang (CVE-2026-49839). Data can be tampered with by attackers. Mitigation: upgrade to `1.8.2` or later.
|
| CVE-2026-47770 |
|
Vulnerability in c (CVE-2026-47770)
vulnerability in c (CVE-2026-47770). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.2` or later.
|
| UBUNTU-CVE-2026-6091 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-6091)
vulnerability in wolfssl (UBUNTU-CVE-2026-6091). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-6291 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-6291)
vulnerability in wolfssl (UBUNTU-CVE-2026-6291). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-6094 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-6094)
vulnerability in wolfssl (UBUNTU-CVE-2026-6094). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-55961 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-55961)
vulnerability in wolfssl (UBUNTU-CVE-2026-55961). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-55967 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-55967)
vulnerability in wolfssl (UBUNTU-CVE-2026-55967). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-54679 |
|
Vulnerability in jq (UBUNTU-CVE-2026-54679)
vulnerability in jq (UBUNTU-CVE-2026-54679). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.2` or later.
|
| UBUNTU-CVE-2026-11999 |
|
Vulnerability in wolfssl (UBUNTU-CVE-2026-11999)
vulnerability in wolfssl (UBUNTU-CVE-2026-11999). Data can be tampered with by attackers.
|
| GHSA-xr76-fgrm-h52p |
|
Vulnerability in ts-opus (GHSA-xr76-fgrm-h52p)
vulnerability in ts-opus (GHSA-xr76-fgrm-h52p). Risk of unauthorized operations or information disclosure. Exploitable via ``big.mjs``.
|
| GHSA-fq3w-p4fg-mw73 |
|
Vulnerability in fixurjavainstall (GHSA-fq3w-p4fg-mw73)
vulnerability in fixurjavainstall (GHSA-fq3w-p4fg-mw73). Risk of unauthorized operations or information disclosure. Exploitable via ``dev``. Mitigation: upgrade to `0.8.1` or later.
|
| GHSA-wrr4-782v-jhwh |
|
Vulnerability in neotoma (GHSA-wrr4-782v-jhwh)
vulnerability in neotoma (GHSA-wrr4-782v-jhwh). Risk of unauthorized operations or information disclosure. Exploitable via ``getAuthenticatedUserId``. Mitigation: upgrade to `0.14.0` or later.
|
| GHSA-jf6w-2mvx-633j |
|
Cross-Site Scripting (XSS) in justhtml (GHSA-jf6w-2mvx-633j)
cross-site scripting in justhtml (GHSA-jf6w-2mvx-633j). Risk of unauthorized operations or information disclosure. Exploitable via ``justhtml``. Mitigation: upgrade to `1.22.0` or later.
|