Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-46560 |
|
Vulnerability in org.openidentityplatform.openam:openam-radius (CVE-2026-46560)
vulnerability in org.openidentityplatform.openam:openam-radius (CVE-2026-46560). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `16.1.1` or later.
|
| GHSA-43r2-9cx9-pv7f |
|
Vulnerability in @vpms/design-system (GHSA-43r2-9cx9-pv7f)
vulnerability in @vpms/design-system (GHSA-43r2-9cx9-pv7f). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-56123 |
|
Vulnerability in socat (UBUNTU-CVE-2026-56123)
vulnerability in socat (UBUNTU-CVE-2026-56123). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.8.0.0-4ubuntu0.1` or later.
|
| CVE-2026-55439 |
|
Path Traversal in path-traversal (CVE-2026-55439)
path traversal in path-traversal (CVE-2026-55439). Confidential information can be exposed externally. Exploitable via `GET /apis/console.api.migration.halo.run/v1alpha1/backups/{name}/files/{filename}`. Mitigation: upgrade to `2.24.3` or later.
|
| CVE-2026-55413 |
|
Code Injection in CVE-2026-55413 (CVE-2026-55413)
code injection in CVE-2026-55413 (CVE-2026-55413). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.20.178-lts` or later.
|
| CVE-2026-55412 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55412)
SSRF in ssrf (CVE-2026-55412). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.20.178-lts` or later.
|
| CVE-2026-55411 |
|
Vulnerability in CVE-2026-55411 (CVE-2026-55411)
vulnerability in CVE-2026-55411 (CVE-2026-55411). Confidential information can be exposed externally. Exploitable via `POST /api/data-sources/decrypt`. Mitigation: upgrade to `3.20.1780-lts` or later.
|
| CVE-2026-55092 |
|
Path Traversal in github.com/aquasecurity/trivy (CVE-2026-55092)
path traversal in github.com/aquasecurity/trivy (CVE-2026-55092). Data can be tampered with by attackers. Exploitable via ``org.opencontainers.image.title``. Mitigation: upgrade to `0.71.1` or later.
|
| CVE-2026-54573 |
|
Authorization Flaw in privilege-escalation (CVE-2026-54573)
vulnerability in privilege-escalation (CVE-2026-54573). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.0` or later.
|
| CVE-2026-54448 |
|
Vulnerability in github.com/aquasecurity/trivy (CVE-2026-54448)
vulnerability in github.com/aquasecurity/trivy (CVE-2026-54448). Risk of unauthorized operations or information disclosure. Exploitable via ``archive.LoadArchiveFiles``. Mitigation: upgrade to `0.71.0` or later.
|
| CVE-2026-54040 |
|
Vulnerability in librechat (CVE-2026-54040)
vulnerability in librechat (CVE-2026-54040). Data can be tampered with by attackers. Exploitable via `POST /api/auth/2fa/backup/regenerate`. Mitigation: upgrade to `0.8.4-rc1` or later.
|
| CVE-2026-54037 |
|
Vulnerability in librechat (CVE-2026-54037)
vulnerability in librechat (CVE-2026-54037). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/convos/fork`. Mitigation: upgrade to `0.8.4-rc1` or later.
|
| CVE-2026-54033 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-54033)
SSRF in ssrf (CVE-2026-54033). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.4-rc1` or later.
|
| CVE-2026-54030 |
|
Vulnerability in librechat (CVE-2026-54030)
vulnerability in librechat (CVE-2026-54030). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.5` or later.
|
| CVE-2026-54029 |
|
Vulnerability in librechat (CVE-2026-54029)
vulnerability in librechat (CVE-2026-54029). Data can be tampered with by attackers. Exploitable via `DELETE /api/messages/`. Mitigation: upgrade to `0.8.4-rc1` or later.
|
| CVE-2026-54027 |
|
Vulnerability in librechat (CVE-2026-54027)
vulnerability in librechat (CVE-2026-54027). Data can be tampered with by attackers. Exploitable via `POST /api/files/images`. Mitigation: upgrade to `0.8.4-rc1` or later.
|
| CVE-2026-54025 |
|
Cross-Site Scripting (XSS) in librechat (CVE-2026-54025)
cross-site scripting in librechat (CVE-2026-54025). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.4-rc1` or later.
|
| CVE-2026-54024 |
|
Vulnerability in librechat (CVE-2026-54024)
vulnerability in librechat (CVE-2026-54024). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/convos/import`. Mitigation: upgrade to `0.8.4-rc1` or later.
|
| CVE-2026-13351 |
|
Vulnerability in dos (CVE-2026-13351)
vulnerability in dos (CVE-2026-13351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13350 |
|
Vulnerability in CVE-2026-13350 (CVE-2026-13350)
vulnerability in CVE-2026-13350 (CVE-2026-13350). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6465 |
|
Vulnerability in chai-as-built (MAL-2026-6465)
vulnerability in chai-as-built (MAL-2026-6465). Risk of unauthorized operations or information disclosure. Exploitable via ``node``.
|
| CVE-2026-46498 |
|
Vulnerability in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-46498)
vulnerability in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-46498). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| GHSA-hhw7-23r7-qwj7 |
|
Vulnerability in gx-npm-feature-flags (GHSA-hhw7-23r7-qwj7)
vulnerability in gx-npm-feature-flags (GHSA-hhw7-23r7-qwj7). Risk of unauthorized operations or information disclosure. Exploitable via ``process.env.USER``.
|
| MAL-2026-6464 |
|
Vulnerability in @colibri-event-types/megamarket-ru-web (MAL-2026-6464)
vulnerability in @colibri-event-types/megamarket-ru-web (MAL-2026-6464). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| CGA-7h27-2jf5-crx8 |
|
CGA-7h27-2jf5-crx8 |
| CGA-9p8v-q7j8-x8x2 |
|
CGA-9p8v-q7j8-x8x2 |
| CVE-2026-46406 |
|
Information Disclosure in @anthropic-ai/claude-code (CVE-2026-46406)
vulnerability in @anthropic-ai/claude-code (CVE-2026-46406). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.1.128` or later.
|
| CGA-m33w-fcq7-wmg3 |
|
CGA-m33w-fcq7-wmg3 |
| CGA-qrcf-92jm-xh4v |
|
CGA-qrcf-92jm-xh4v |
| CGA-73rh-q5gp-5hcc |
|
CGA-73rh-q5gp-5hcc |
| CGA-h7v8-hvr6-mf5p |
|
CGA-h7v8-hvr6-mf5p |
| CGA-rcqm-hp8r-w5g8 |
|
CGA-rcqm-hp8r-w5g8 |
| CGA-gfjg-cf9q-j562 |
|
CGA-gfjg-cf9q-j562 |
| CGA-m8gp-7j98-46w8 |
|
CGA-m8gp-7j98-46w8 |
| CGA-3m3q-fmhw-rjm8 |
|
CGA-3m3q-fmhw-rjm8 |
| CGA-mh8m-j2c9-658m |
|
CGA-mh8m-j2c9-658m |
| CGA-jv7j-68v7-7gj6 |
|
CGA-jv7j-68v7-7gj6 |
| CGA-35pc-8gq9-64f7 |
|
CGA-35pc-8gq9-64f7 |
| CVE-2026-45794 |
|
Unsafe Deserialization in org.openidentityplatform.openam:openam-push-notification (CVE-2026-45794)
vulnerability in org.openidentityplatform.openam:openam-push-notification (CVE-2026-45794). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| CGA-83v4-g6cp-6wf4 |
|
CGA-83v4-g6cp-6wf4 |
| CGA-872m-7xj4-h457 |
|
CGA-872m-7xj4-h457 |
| CGA-rjwr-43v6-f337 |
|
CGA-rjwr-43v6-f337 |
| CGA-qr78-9fg9-c676 |
|
CGA-qr78-9fg9-c676 |
| CGA-p9wh-4mxh-99fj |
|
CGA-p9wh-4mxh-99fj |
| CGA-gjp2-qvw3-j4qm |
|
CGA-gjp2-qvw3-j4qm |
| CGA-9x2h-jjvc-66mh |
|
CGA-9x2h-jjvc-66mh |
| CGA-g475-xr4q-qf74 |
|
CGA-g475-xr4q-qf74 |
| CGA-6gw2-65p5-m27x |
|
CGA-6gw2-65p5-m27x |
| CVE-2026-57456 |
|
Code Injection in vim (CVE-2026-57456)
code injection in vim (CVE-2026-57456). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.2.0699` or later.
|
| CVE-2026-57455 |
|
Out-of-Bounds Write in c (CVE-2026-57455)
out-of-bounds write in c (CVE-2026-57455). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.2.0698` or later.
|