Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-56371 |
|
Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-56371)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-56371). Risk of unauthorized operations or information disclosure. Exploitable via ``texture``. Mitigation: upgrade to `14.10.3` or later.
|
| CVE-2026-56322 |
|
Information Disclosure in CVE-2026-56322 (CVE-2026-56322)
vulnerability in CVE-2026-56322 (CVE-2026-56322). Confidential information can be exposed externally.
|
| CVE-2026-56315 |
|
Vulnerability in picklescan (CVE-2026-56315)
vulnerability in picklescan (CVE-2026-56315). Successful exploitation can lead to full system takeover. Exploitable via ``uuid``. Mitigation: upgrade to `1.0.4` or later.
|
| CVE-2026-56301 |
|
Vulnerability in nuxt (CVE-2026-56301)
vulnerability in nuxt (CVE-2026-56301). Confidential information can be exposed externally. Exploitable via ``module``. Mitigation: upgrade to `3.21.7` or later.
|
| CVE-2026-56275 |
|
SSRF (Server-Side Request Forgery) in flowise (CVE-2026-56275)
SSRF in flowise (CVE-2026-56275). Confidential information can be exposed externally. Exploitable via `POST /api/v1/prediction/d6739838-d3b3-43d9-86ff-911a3d757a7e`. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-56274 |
|
Vulnerability in flowise (CVE-2026-56274)
vulnerability in flowise (CVE-2026-56274). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/prediction/{chatflows_id}`. Mitigation: upgrade to `3.1.2` or later.
|
| CVE-2026-56263 |
|
Cross-Site Scripting (XSS) in kidocode (CVE-2026-56263)
cross-site scripting in kidocode (CVE-2026-56263). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56258 |
|
Path Traversal in crawl4ai (CVE-2026-56258)
path traversal in crawl4ai (CVE-2026-56258). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.8` or later.
|
| CVE-2026-56248 |
|
Vulnerability in dos (CVE-2026-56248)
vulnerability in dos (CVE-2026-56248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56243 |
|
Vulnerability in CVE-2026-56243 (CVE-2026-56243)
vulnerability in CVE-2026-56243 (CVE-2026-56243). Confidential information can be exposed externally.
|
| CVE-2026-56234 |
|
Vulnerability in CVE-2026-56234 (CVE-2026-56234)
vulnerability in CVE-2026-56234 (CVE-2026-56234). Risk of unauthorized operations or information disclosure. Exploitable via `POST /functions/v1/private/validate_password_compliance`.
|
| CVE-2026-56225 |
|
Privilege Escalation in CVE-2026-56225 (CVE-2026-56225)
vulnerability in CVE-2026-56225 (CVE-2026-56225). Confidential information can be exposed externally.
|
| CVE-2026-56222 |
|
Vulnerability in CVE-2026-56222 (CVE-2026-56222)
vulnerability in CVE-2026-56222 (CVE-2026-56222). Successful exploitation can lead to full system takeover. Exploitable via `POST /private/role_bindings`.
|
| CVE-2026-54892 |
|
Vulnerability in dos (CVE-2026-54892)
vulnerability in dos (CVE-2026-54892). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4610 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4610)
cross-site scripting in wordpress (CVE-2026-4610). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44089 |
|
Vulnerability in CVE-2026-44089 (CVE-2026-44089)
vulnerability in CVE-2026-44089 (CVE-2026-44089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10857 |
|
Cross-Site Scripting (XSS) in CVE-2026-10857 (CVE-2026-10857)
cross-site scripting in CVE-2026-10857 (CVE-2026-10857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10711 |
|
Vulnerability in CVE-2026-10711 (CVE-2026-10711)
vulnerability in CVE-2026-10711 (CVE-2026-10711). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71376 |
|
Unsafe Deserialization in picklescan (CVE-2025-71376)
vulnerability in picklescan (CVE-2025-71376). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.29` or later.
|
| CVE-2025-71370 |
|
Vulnerability in picklescan (CVE-2025-71370)
vulnerability in picklescan (CVE-2025-71370). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.28` or later.
|
| CVE-2025-71365 |
|
Code Injection in picklescan (CVE-2025-71365)
code injection in picklescan (CVE-2025-71365). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.33` or later.
|
| CVE-2025-71341 |
|
Unsafe Deserialization in picklescan (CVE-2025-71341)
vulnerability in picklescan (CVE-2025-71341). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.29` or later.
|
| CVE-2025-71337 |
|
Vulnerability in flowise-ui (CVE-2025-71337)
vulnerability in flowise-ui (CVE-2025-71337). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.10` or later.
|
| CVE-2023-54365 |
|
Vulnerability in golang (CVE-2023-54365)
vulnerability in golang (CVE-2023-54365). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.20.10, 1.21.3` or later.
|
| MINI-hq35-4mfv-p62v |
|
MINI-hq35-4mfv-p62v |
| MINI-c36v-xq37-rm9q |
|
MINI-c36v-xq37-rm9q |
| MINI-6v78-v24m-87wh |
|
MINI-6v78-v24m-87wh |
| MINI-p57j-p76r-gmmr |
|
MINI-p57j-p76r-gmmr |
| SUSE-SU-2026:2579-1 |
|
Vulnerability in docker-stable (SUSE-SU-2026:2579-1)
vulnerability in docker-stable (SUSE-SU-2026:2579-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `24.0.9_ce-150000.1.45.1` or later.
|
| MINI-32g2-cqqw-wf7r |
|
MINI-32g2-cqqw-wf7r |
| MINI-3pvr-ww86-8gpr |
|
MINI-3pvr-ww86-8gpr |
| MINI-rv7m-7hp8-839q |
|
MINI-rv7m-7hp8-839q |
| MINI-xh28-g2mv-7q7v |
|
MINI-xh28-g2mv-7q7v |
| MINI-hx3w-qxj7-g4vp |
|
MINI-hx3w-qxj7-g4vp |
| MINI-mx4m-f6rx-j8qq |
|
MINI-mx4m-f6rx-j8qq |
| MINI-j965-96fw-6fcg |
|
MINI-j965-96fw-6fcg |
| MINI-mc49-4m86-mmpp |
|
MINI-mc49-4m86-mmpp |
| ROOT-APP-MAVEN-CVE-2022-36944 |
|
Vulnerability in io.root.org.scala-lang:scala-library (ROOT-APP-MAVEN-CVE-2022-36944)
vulnerability in io.root.org.scala-lang:scala-library (ROOT-APP-MAVEN-CVE-2022-36944). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.13.8-root.io.1, 2.13.6-root.io.1, 2.13.8-root.io.2, 2.13.6-root.io.2, 2.13.8-root.io.3, 2.13.5-root.io.1` or later.
|
| MINI-cc3r-3j22-qqfr |
|
MINI-cc3r-3j22-qqfr |
| SUSE-SU-2026:2578-1 |
|
Vulnerability in docker-stable (SUSE-SU-2026:2578-1)
vulnerability in docker-stable (SUSE-SU-2026:2578-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `24.0.9_ce-1.37.1` or later.
|
| MINI-5v2m-cx2c-5xr5 |
|
MINI-5v2m-cx2c-5xr5 |
| MINI-c27q-f958-v72p |
|
MINI-c27q-f958-v72p |
| MINI-qv9h-2gx5-9xqh |
|
MINI-qv9h-2gx5-9xqh |
| MINI-8hmv-2v5c-v2h6 |
|
MINI-8hmv-2v5c-v2h6 |
| MINI-h4f7-ch6p-c5pj |
|
MINI-h4f7-ch6p-c5pj |
| openSUSE-SU-2026:21154-1 |
|
Vulnerability in ofono (openSUSE-SU-2026:21154-1)
vulnerability in ofono (openSUSE-SU-2026:21154-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.19-bp160.1.1` or later.
|
| openSUSE-SU-2026:21153-1 |
|
Vulnerability in xar (openSUSE-SU-2026:21153-1)
vulnerability in xar (openSUSE-SU-2026:21153-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.0.0.503-bp160.1.1` or later.
|
| MINI-5h2g-ccqm-x39v |
|
MINI-5h2g-ccqm-x39v |
| MINI-h7cc-xhr9-3wxf |
|
MINI-h7cc-xhr9-3wxf |
| MINI-93f4-cgfc-7q9v |
|
MINI-93f4-cgfc-7q9v |