Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42055 |
|
Vulnerability in nginx (CVE-2026-42055)
vulnerability in nginx (CVE-2026-42055). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44495 |
|
Code Injection in axios (CVE-2026-44495)
code injection in axios (CVE-2026-44495). Confidential information can be exposed externally. Exploitable via ``Object.prototype.transformResponse``. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-9256 |
|
Vulnerability in nginx (CVE-2026-9256)
vulnerability in nginx (CVE-2026-9256). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.24.0, 1.30.2, 1.31.1` or later.
|
| CVE-2025-13601 |
|
Vulnerability in redhat (CVE-2025-13601)
vulnerability in redhat (CVE-2025-13601). Data can be tampered with by attackers.
|
| CVE-2025-71319 |
|
Vulnerability in image-size (CVE-2025-71319)
vulnerability in image-size (CVE-2025-71319). Risk of unauthorized operations or information disclosure. Exploitable via ``findBox``. Mitigation: upgrade to `2.0.2` or later.
|
| CVE-2024-12088 |
|
Path Traversal in path-traversal (CVE-2024-12088)
path traversal in path-traversal (CVE-2024-12088). Data can be tampered with by attackers.
|
| CVE-2024-23688 |
|
Vulnerability in consensys (CVE-2024-23688)
vulnerability in consensys (CVE-2024-23688). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-48795 |
|
Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
|