Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| ROOT-OS-DEBIAN-11-CVE-2026-31763 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2026-31763)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2026-31763). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2025-39970 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-39970)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-39970). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2025-71191 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-71191)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-71191). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2022-50500 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2022-50500)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2022-50500). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2024-35863 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-35863)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-35863). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2024-38541 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-38541)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-38541). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2024-43832 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-43832)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2024-43832). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2025-38497 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38497)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38497). Confidential information can be exposed externally. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2025-38529 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38529)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38529). Confidential information can be exposed externally. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2025-38622 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38622)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38622). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2025-22104 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-22104)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-22104). Confidential information can be exposed externally. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| ROOT-OS-DEBIAN-11-CVE-2025-38424 |
|
Vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38424)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-11-CVE-2025-38424). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.251-4.root.io.80` or later.
|
| CVE-2026-8209 |
|
Vulnerability in path-traversal (CVE-2026-8209)
vulnerability in path-traversal (CVE-2026-8209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8208 |
|
Vulnerability in CVE-2026-8208 (CVE-2026-8208)
vulnerability in CVE-2026-8208 (CVE-2026-8208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42461 |
|
Vulnerability in CVE-2026-42461 (CVE-2026-42461)
vulnerability in CVE-2026-42461 (CVE-2026-42461). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42301 |
|
Vulnerability in CVE-2026-42301 (CVE-2026-42301)
vulnerability in CVE-2026-42301 (CVE-2026-42301). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42297 |
|
Vulnerability in CVE-2026-42297 (CVE-2026-42297)
vulnerability in CVE-2026-42297 (CVE-2026-42297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42296 |
|
Authorization Flaw in CVE-2026-42296 (CVE-2026-42296)
vulnerability in CVE-2026-42296 (CVE-2026-42296). Confidential information can be exposed externally.
|
| CVE-2026-42295 |
|
Vulnerability in CVE-2026-42295 (CVE-2026-42295)
vulnerability in CVE-2026-42295 (CVE-2026-42295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42294 |
|
Vulnerability in dos (CVE-2026-42294)
vulnerability in dos (CVE-2026-42294). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42183 |
|
Vulnerability in dos (CVE-2026-42183)
vulnerability in dos (CVE-2026-42183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42174 |
|
Vulnerability in CVE-2026-42174 (CVE-2026-42174)
vulnerability in CVE-2026-42174 (CVE-2026-42174). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42137 |
|
Vulnerability in CVE-2026-42137 (CVE-2026-42137)
vulnerability in CVE-2026-42137 (CVE-2026-42137). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42069 |
|
Vulnerability in CVE-2026-42069 (CVE-2026-42069)
vulnerability in CVE-2026-42069 (CVE-2026-42069). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42051 |
|
Vulnerability in CVE-2026-42051 (CVE-2026-42051)
vulnerability in CVE-2026-42051 (CVE-2026-42051). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41311 |
|
Vulnerability in dos (CVE-2026-41311)
vulnerability in dos (CVE-2026-41311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41163 |
|
Privilege Escalation in CVE-2026-41163 (CVE-2026-41163)
vulnerability in CVE-2026-41163 (CVE-2026-41163). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8207 |
|
SQL Injection in sqli (CVE-2026-8207)
SQL injection in sqli (CVE-2026-8207). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7652 |
|
Vulnerability in wordpress (CVE-2026-7652)
vulnerability in wordpress (CVE-2026-7652). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6667 |
|
Vulnerability in CVE-2026-6667 (CVE-2026-6667)
vulnerability in CVE-2026-6667 (CVE-2026-6667). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6666 |
|
Vulnerability in CVE-2026-6666 (CVE-2026-6666)
vulnerability in CVE-2026-6666 (CVE-2026-6666). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6665 |
|
Vulnerability in CVE-2026-6665 (CVE-2026-6665)
vulnerability in CVE-2026-6665 (CVE-2026-6665). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6664 |
|
Vulnerability in CVE-2026-6664 (CVE-2026-6664)
vulnerability in CVE-2026-6664 (CVE-2026-6664). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41705 |
|
Vulnerability in CVE-2026-41705 (CVE-2026-41705)
vulnerability in CVE-2026-41705 (CVE-2026-41705). Confidential information can be exposed externally.
|
| CVE-2026-44458 |
|
Vulnerability in hono (CVE-2026-44458)
vulnerability in hono (CVE-2026-44458). Risk of unauthorized operations or information disclosure. Exploitable via ``style``. Mitigation: upgrade to `4.12.18` or later.
|
| CVE-2026-44459 |
|
Vulnerability in hono (CVE-2026-44459)
vulnerability in hono (CVE-2026-44459). Risk of unauthorized operations or information disclosure. Exploitable via ``exp``. Mitigation: upgrade to `4.12.18` or later.
|
| GHSA-v6wj-c83f-v46x |
|
OS Command Injection in @profullstack/mcp-server (GHSA-v6wj-c83f-v46x)
OS command injection in @profullstack/mcp-server (GHSA-v6wj-c83f-v46x). Risk of unauthorized operations or information disclosure. Exploitable via `POST /domain-lookup/check`.
|
| CVE-2026-44966 |
|
Vulnerability in velocityjs (CVE-2026-44966)
vulnerability in velocityjs (CVE-2026-44966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6860 |
|
Vulnerability in io.vertx:vertx-core (CVE-2026-6860)
vulnerability in io.vertx:vertx-core (CVE-2026-6860). Risk of unauthorized operations or information disclosure. Exploitable via ``SslContext``.
|
| CVE-2026-44457 |
|
Vulnerability in hono (CVE-2026-44457)
vulnerability in hono (CVE-2026-44457). Risk of unauthorized operations or information disclosure. Exploitable via ``private``. Mitigation: upgrade to `4.12.18` or later.
|
| CVE-2026-44313 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44313)
SSRF in ssrf (CVE-2026-44313). Confidential information can be exposed externally. Exploitable via `GET /api/v1/archives/{linkId}`.
|
| CVE-2026-42455 |
|
Cross-Site Scripting (XSS) in CVE-2026-42455 (CVE-2026-42455)
cross-site scripting in CVE-2026-42455 (CVE-2026-42455). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/archives/`.
|
| CVE-2026-44897 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-44897)
cross-site scripting in mistune (CVE-2026-44897). Risk of unauthorized operations or information disclosure. Exploitable via ``toc_1``. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-44895 |
|
Vulnerability in @yoda.digital/gitlab-mcp-server (CVE-2026-44895)
vulnerability in @yoda.digital/gitlab-mcp-server (CVE-2026-44895). Risk of unauthorized operations or information disclosure. Exploitable via `GET /sse`. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-44983 |
|
Vulnerability in smallbitvec (CVE-2026-44983)
vulnerability in smallbitvec (CVE-2026-44983). Risk of unauthorized operations or information disclosure. Exploitable via ``smallbitvec``.
|
| CVE-2026-44788 |
|
Path Traversal in SharpCompress (CVE-2026-44788)
path traversal in SharpCompress (CVE-2026-44788). Risk of unauthorized operations or information disclosure. Exploitable via ``WriteToDirectoryInternal``.
|
| CVE-2026-44900 |
|
Vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-44900)
vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-44900). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.1` or later.
|
| CVE-2026-44896 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-44896)
cross-site scripting in mistune (CVE-2026-44896). Risk of unauthorized operations or information disclosure. Exploitable via ``figclass``.
|
| CVE-2026-44708 |
|
Cross-Site Scripting (XSS) in mistune (CVE-2026-44708)
cross-site scripting in mistune (CVE-2026-44708). Risk of unauthorized operations or information disclosure. Exploitable via ``_escape``.
|
| CVE-2026-44837 |
|
Path Traversal in view_component (CVE-2026-44837)
path traversal in view_component (CVE-2026-44837). Risk of unauthorized operations or information disclosure. Exploitable via `GET /_system_test_entrypoint`. Mitigation: upgrade to `4.9.0` or later.
|