Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48732 |
|
OS Command Injection in CVE-2026-48732 (CVE-2026-48732)
OS command injection in CVE-2026-48732 (CVE-2026-48732). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| CVE-2026-48731 |
|
OS Command Injection in CVE-2026-48731 (CVE-2026-48731)
OS command injection in CVE-2026-48731 (CVE-2026-48731). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| CVE-2026-48725 |
|
Vulnerability in CVE-2026-48725 (CVE-2026-48725)
vulnerability in CVE-2026-48725 (CVE-2026-48725). Confidential information can be exposed externally. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| CVE-2026-48721 |
|
Vulnerability in c (CVE-2026-48721)
vulnerability in c (CVE-2026-48721). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| CVE-2026-48720 |
|
Vulnerability in CVE-2026-48720 (CVE-2026-48720)
vulnerability in CVE-2026-48720 (CVE-2026-48720). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| CVE-2026-48719 |
|
OS Command Injection in CVE-2026-48719 (CVE-2026-48719)
OS command injection in CVE-2026-48719 (CVE-2026-48719). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| CVE-2026-48704 |
|
Vulnerability in CVE-2026-48704 (CVE-2026-48704)
vulnerability in CVE-2026-48704 (CVE-2026-48704). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| CVE-2026-48703 |
|
OS Command Injection in CVE-2026-48703 (CVE-2026-48703)
OS command injection in CVE-2026-48703 (CVE-2026-48703). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| UBUNTU-CVE-2026-49851 |
|
Vulnerability in mistune (UBUNTU-CVE-2026-49851)
vulnerability in mistune (UBUNTU-CVE-2026-49851). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.0` or later.
|
| GHSA-rr7c-77w4-j8c8 |
|
Vulnerability in @kl-dolphin/swim (GHSA-rr7c-77w4-j8c8)
vulnerability in @kl-dolphin/swim (GHSA-rr7c-77w4-j8c8). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6401 |
|
Vulnerability in zenith-utils (MAL-2026-6401)
vulnerability in zenith-utils (MAL-2026-6401). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
|
| RLSA-2026:28999 |
|
Vulnerability in pgaudit (RLSA-2026:28999)
vulnerability in pgaudit (RLSA-2026:28999). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:1.4.0-7.module+el8.9.0+1735+a332307b` or later.
|
| USN-8468-1 |
|
Vulnerability in imagemagick (USN-8468-1)
vulnerability in imagemagick (USN-8468-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8:6.7.7.10-6ubuntu3.13+esm22` or later.
|
| CVE-2026-53541 |
|
Vulnerability in github.com/OliveTin/OliveTin (CVE-2026-53541)
vulnerability in github.com/OliveTin/OliveTin (CVE-2026-53541). Risk of unauthorized operations or information disclosure. Exploitable via ``filterToDefinedArgumentsOnly``. Mitigation: upgrade to `0.0.0-20260531214440-ebffd9f040f7` or later.
|
| CVE-2026-45052 |
|
Vulnerability in org.openidentityplatform.openam:openam-federation-library (CVE-2026-45052)
vulnerability in org.openidentityplatform.openam:openam-federation-library (CVE-2026-45052). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| CVE-2026-45051 |
|
Unsafe Deserialization in org.openidentityplatform.openam:openam-auth-webauthn (CVE-2026-45051)
vulnerability in org.openidentityplatform.openam:openam-auth-webauthn (CVE-2026-45051). Risk of unauthorized operations or information disclosure. Exploitable via ``userAttribute``. Mitigation: upgrade to `16.1.1` or later.
|
| UBUNTU-CVE-2026-54297 |
|
Vulnerability in ruby-faraday (UBUNTU-CVE-2026-54297)
vulnerability in ruby-faraday (UBUNTU-CVE-2026-54297). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.10.6` or later.
|
| UBUNTU-CVE-2026-54906 |
|
Vulnerability in ruby-concurrent (UBUNTU-CVE-2026-54906)
vulnerability in ruby-concurrent (UBUNTU-CVE-2026-54906). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.3.7` or later.
|
| UBUNTU-CVE-2026-54904 |
|
Vulnerability in ruby-concurrent (UBUNTU-CVE-2026-54904)
vulnerability in ruby-concurrent (UBUNTU-CVE-2026-54904). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.3.7` or later.
|
| UBUNTU-CVE-2026-54905 |
|
Vulnerability in ruby-concurrent (UBUNTU-CVE-2026-54905)
vulnerability in ruby-concurrent (UBUNTU-CVE-2026-54905). Confidential information can be exposed externally. Mitigation: upgrade to `1.3.7` or later.
|
| MAL-2026-6400 |
|
Vulnerability in python-dateutil2 (MAL-2026-6400)
vulnerability in python-dateutil2 (MAL-2026-6400). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56121 |
|
Unsafe Deserialization in deserialization (CVE-2026-56121)
vulnerability in deserialization (CVE-2026-56121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56119 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-56118 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-56111 |
|
Vulnerability in c (CVE-2026-56111)
vulnerability in c (CVE-2026-56111). Data can be tampered with by attackers.
|
| CVE-2026-50712 |
|
Cross-Site Scripting (XSS) in CVE-2026-50712 (CVE-2026-50712)
cross-site scripting in CVE-2026-50712 (CVE-2026-50712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50711 |
|
Cross-Site Scripting (XSS) in CVE-2026-50711 (CVE-2026-50711)
cross-site scripting in CVE-2026-50711 (CVE-2026-50711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50710 |
|
Cross-Site Scripting (XSS) in CVE-2026-50710 (CVE-2026-50710)
cross-site scripting in CVE-2026-50710 (CVE-2026-50710). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50709 |
|
Cross-Site Scripting (XSS) in CVE-2026-50709 (CVE-2026-50709)
cross-site scripting in CVE-2026-50709 (CVE-2026-50709). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50708 |
|
Cross-Site Scripting (XSS) in CVE-2026-50708 (CVE-2026-50708)
cross-site scripting in CVE-2026-50708 (CVE-2026-50708). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50705 |
|
Cross-Site Scripting (XSS) in CVE-2026-50705 (CVE-2026-50705)
cross-site scripting in CVE-2026-50705 (CVE-2026-50705). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50704 |
|
Cross-Site Scripting (XSS) in CVE-2026-50704 (CVE-2026-50704)
cross-site scripting in CVE-2026-50704 (CVE-2026-50704). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50703 |
|
Cross-Site Scripting (XSS) in CVE-2026-50703 (CVE-2026-50703)
cross-site scripting in CVE-2026-50703 (CVE-2026-50703). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50701 |
|
Cross-Site Scripting (XSS) in CVE-2026-50701 (CVE-2026-50701)
cross-site scripting in CVE-2026-50701 (CVE-2026-50701). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50700 |
|
Cross-Site Scripting (XSS) in CVE-2026-50700 (CVE-2026-50700)
cross-site scripting in CVE-2026-50700 (CVE-2026-50700). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49269 |
|
Information Disclosure in CVE-2026-49269 (CVE-2026-49269)
vulnerability in CVE-2026-49269 (CVE-2026-49269). Confidential information can be exposed externally.
|
| USN-8469-1 |
|
Vulnerability in ffmpeg (USN-8469-1)
vulnerability in ffmpeg (USN-8469-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7:4.2.7-0ubuntu0.1+esm13` or later.
|
| SUSE-SU-2026:22423-1 |
|
Vulnerability in google-guest-agent (SUSE-SU-2026:22423-1)
vulnerability in google-guest-agent (SUSE-SU-2026:22423-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `20260529.00-1.1` or later.
|
| ROOT-APP-NPM-CVE-2025-8129 |
|
Vulnerability in @rootio/koa (ROOT-APP-NPM-CVE-2025-8129)
vulnerability in @rootio/koa (ROOT-APP-NPM-CVE-2025-8129). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.15.4-root.io.4` or later.
|
| ROOT-APP-NPM-CVE-2025-32379 |
|
Vulnerability in @rootio/koa (ROOT-APP-NPM-CVE-2025-32379)
vulnerability in @rootio/koa (ROOT-APP-NPM-CVE-2025-32379). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.15.4-root.io.4` or later.
|
| CVE-2026-50699 |
|
Cross-Site Scripting (XSS) in CVE-2026-50699 (CVE-2026-50699)
cross-site scripting in CVE-2026-50699 (CVE-2026-50699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11877 |
|
Vulnerability in microfocus (CVE-2026-11877)
vulnerability in microfocus (CVE-2026-11877). Data can be tampered with by attackers.
|
| CVE-2026-50698 |
|
Cross-Site Scripting (XSS) in CVE-2026-50698 (CVE-2026-50698)
cross-site scripting in CVE-2026-50698 (CVE-2026-50698). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12986 |
|
Cross-Site Request Forgery (CSRF) in ssrf (CVE-2026-12986)
vulnerability in ssrf (CVE-2026-12986). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11878 |
|
Cross-Site Scripting (XSS) in microfocus (CVE-2026-11878)
cross-site scripting in microfocus (CVE-2026-11878). Risk of unauthorized operations or information disclosure.
|
| GHSA-fr34-v6cp-fc49 |
|
Vulnerability in normalize-plus (GHSA-fr34-v6cp-fc49)
vulnerability in normalize-plus (GHSA-fr34-v6cp-fc49). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
|
| SUSE-SU-2026:22352-1 |
|
Vulnerability in openssh (SUSE-SU-2026:22352-1)
vulnerability in openssh (SUSE-SU-2026:22352-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.0p2-160000.6.1` or later.
|
| SUSE-SU-2026:22268-1 |
|
Vulnerability in openssh (SUSE-SU-2026:22268-1)
vulnerability in openssh (SUSE-SU-2026:22268-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.0p2-160000.6.1` or later.
|
| openSUSE-SU-2026:21044-1 |
|
Vulnerability in openssh (openSUSE-SU-2026:21044-1)
vulnerability in openssh (openSUSE-SU-2026:21044-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.0p2-160000.6.1` or later.
|
| MINI-ggpq-5r8v-q62j |
|
MINI-ggpq-5r8v-q62j |