Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
ROOT-OS-DEBIAN-11-CVE-2026-31763 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2026-31763)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2026-31763). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2025-39970 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-39970)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-39970). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2025-71191 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-71191)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-71191). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2022-50500 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2022-50500)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2022-50500). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2024-35863 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-35863)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-35863). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2024-38541 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-38541)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-38541). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2024-43832 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-43832)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-43832). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2025-38497 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38497)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38497). Confidential information can be exposed externally. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2025-38529 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38529)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38529). Confidential information can be exposed externally. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2025-38622 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38622)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38622). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2025-22104 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-22104)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-22104). Confidential information can be exposed externally. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
ROOT-OS-DEBIAN-11-CVE-2025-38424 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38424)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38424). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
CVE-2026-8209 Vulnerability in path-traversal (CVE-2026-8209)
vulnerability in path-traversal (CVE-2026-8209). Risk of unauthorized operations or information disclosure.
CVE-2026-8208 Vulnerability in CVE-2026-8208 (CVE-2026-8208)
vulnerability in CVE-2026-8208 (CVE-2026-8208). Risk of unauthorized operations or information disclosure.
CVE-2026-42461 Vulnerability in CVE-2026-42461 (CVE-2026-42461)
vulnerability in CVE-2026-42461 (CVE-2026-42461). Risk of unauthorized operations or information disclosure.
CVE-2026-42301 Vulnerability in CVE-2026-42301 (CVE-2026-42301)
vulnerability in CVE-2026-42301 (CVE-2026-42301). Successful exploitation can lead to full system takeover.
CVE-2026-42297 Vulnerability in CVE-2026-42297 (CVE-2026-42297)
vulnerability in CVE-2026-42297 (CVE-2026-42297). Risk of unauthorized operations or information disclosure.
CVE-2026-42296 Authorization Flaw in CVE-2026-42296 (CVE-2026-42296)
vulnerability in CVE-2026-42296 (CVE-2026-42296). Confidential information can be exposed externally.
CVE-2026-42295 Vulnerability in CVE-2026-42295 (CVE-2026-42295)
vulnerability in CVE-2026-42295 (CVE-2026-42295). Risk of unauthorized operations or information disclosure.
CVE-2026-42294 Vulnerability in dos (CVE-2026-42294)
vulnerability in dos (CVE-2026-42294). Risk of unauthorized operations or information disclosure.
CVE-2026-42183 Vulnerability in dos (CVE-2026-42183)
vulnerability in dos (CVE-2026-42183). Risk of unauthorized operations or information disclosure.
CVE-2026-42174 Vulnerability in CVE-2026-42174 (CVE-2026-42174)
vulnerability in CVE-2026-42174 (CVE-2026-42174). Risk of unauthorized operations or information disclosure.
CVE-2026-42137 Vulnerability in CVE-2026-42137 (CVE-2026-42137)
vulnerability in CVE-2026-42137 (CVE-2026-42137). Risk of unauthorized operations or information disclosure.
CVE-2026-42069 Vulnerability in CVE-2026-42069 (CVE-2026-42069)
vulnerability in CVE-2026-42069 (CVE-2026-42069). Risk of unauthorized operations or information disclosure.
CVE-2026-42051 Vulnerability in CVE-2026-42051 (CVE-2026-42051)
vulnerability in CVE-2026-42051 (CVE-2026-42051). Risk of unauthorized operations or information disclosure.
CVE-2026-41311 Vulnerability in dos (CVE-2026-41311)
vulnerability in dos (CVE-2026-41311). Risk of unauthorized operations or information disclosure.
CVE-2026-41163 Privilege Escalation in CVE-2026-41163 (CVE-2026-41163)
vulnerability in CVE-2026-41163 (CVE-2026-41163). Risk of unauthorized operations or information disclosure.
CVE-2026-8207 SQL Injection in sqli (CVE-2026-8207)
SQL injection in sqli (CVE-2026-8207). Risk of unauthorized operations or information disclosure.
CVE-2026-7652 Vulnerability in wordpress (CVE-2026-7652)
vulnerability in wordpress (CVE-2026-7652). Risk of unauthorized operations or information disclosure.
CVE-2026-6667 Vulnerability in CVE-2026-6667 (CVE-2026-6667)
vulnerability in CVE-2026-6667 (CVE-2026-6667). Risk of unauthorized operations or information disclosure.
CVE-2026-6666 Vulnerability in CVE-2026-6666 (CVE-2026-6666)
vulnerability in CVE-2026-6666 (CVE-2026-6666). Risk of unauthorized operations or information disclosure.
CVE-2026-6665 Vulnerability in CVE-2026-6665 (CVE-2026-6665)
vulnerability in CVE-2026-6665 (CVE-2026-6665). Successful exploitation can lead to full system takeover.
CVE-2026-6664 Vulnerability in CVE-2026-6664 (CVE-2026-6664)
vulnerability in CVE-2026-6664 (CVE-2026-6664). Risk of unauthorized operations or information disclosure.
CVE-2026-41705 Vulnerability in CVE-2026-41705 (CVE-2026-41705)
vulnerability in CVE-2026-41705 (CVE-2026-41705). Confidential information can be exposed externally.
CVE-2026-44458 Vulnerability in hono (CVE-2026-44458)
vulnerability in hono (CVE-2026-44458). Risk of unauthorized operations or information disclosure. Exploitable via ``style``. Mitigation: upgrade to `4.12.18` or later.
CVE-2026-44459 Vulnerability in hono (CVE-2026-44459)
vulnerability in hono (CVE-2026-44459). Risk of unauthorized operations or information disclosure. Exploitable via ``exp``. Mitigation: upgrade to `4.12.18` or later.
GHSA-v6wj-c83f-v46x OS Command Injection in @profullstack/mcp-server (GHSA-v6wj-c83f-v46x)
OS command injection in @profullstack/mcp-server (GHSA-v6wj-c83f-v46x). Risk of unauthorized operations or information disclosure. Exploitable via `POST /domain-lookup/check`.
CVE-2026-44966 Vulnerability in velocityjs (CVE-2026-44966)
vulnerability in velocityjs (CVE-2026-44966). Risk of unauthorized operations or information disclosure.
CVE-2026-6860 Vulnerability in io.vertx:vertx-core (CVE-2026-6860)
vulnerability in io.vertx:vertx-core (CVE-2026-6860). Risk of unauthorized operations or information disclosure. Exploitable via ``SslContext``.
CVE-2026-44457 Vulnerability in hono (CVE-2026-44457)
vulnerability in hono (CVE-2026-44457). Risk of unauthorized operations or information disclosure. Exploitable via ``private``. Mitigation: upgrade to `4.12.18` or later.
CVE-2026-44313 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44313)
SSRF in ssrf (CVE-2026-44313). Confidential information can be exposed externally. Exploitable via `GET /api/v1/archives/{linkId}`.
CVE-2026-42455 Cross-Site Scripting (XSS) in CVE-2026-42455 (CVE-2026-42455)
cross-site scripting in CVE-2026-42455 (CVE-2026-42455). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/archives/`.
CVE-2026-44897 Cross-Site Scripting (XSS) in mistune (CVE-2026-44897)
cross-site scripting in mistune (CVE-2026-44897). Risk of unauthorized operations or information disclosure. Exploitable via ``toc_1``. Mitigation: upgrade to `3.2.1` or later.
CVE-2026-44895 Vulnerability in @yoda.digital/gitlab-mcp-server (CVE-2026-44895)
vulnerability in @yoda.digital/gitlab-mcp-server (CVE-2026-44895). Risk of unauthorized operations or information disclosure. Exploitable via `GET /sse`. Mitigation: upgrade to `0.6.0` or later.
CVE-2026-44983 Vulnerability in smallbitvec (CVE-2026-44983)
vulnerability in smallbitvec (CVE-2026-44983). Risk of unauthorized operations or information disclosure. Exploitable via ``smallbitvec``.
CVE-2026-44788 Path Traversal in SharpCompress (CVE-2026-44788)
path traversal in SharpCompress (CVE-2026-44788). Risk of unauthorized operations or information disclosure. Exploitable via ``WriteToDirectoryInternal``.
CVE-2026-44900 Vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-44900)
vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-44900). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.1` or later.
CVE-2026-44896 Cross-Site Scripting (XSS) in mistune (CVE-2026-44896)
cross-site scripting in mistune (CVE-2026-44896). Risk of unauthorized operations or information disclosure. Exploitable via ``figclass``.
CVE-2026-44708 Cross-Site Scripting (XSS) in mistune (CVE-2026-44708)
cross-site scripting in mistune (CVE-2026-44708). Risk of unauthorized operations or information disclosure. Exploitable via ``_escape``.
CVE-2026-44837 Path Traversal in view_component (CVE-2026-44837)
path traversal in view_component (CVE-2026-44837). Risk of unauthorized operations or information disclosure. Exploitable via `GET /_system_test_entrypoint`. Mitigation: upgrade to `4.9.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →