Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44680 |
|
SQL Injection in @mikro-orm/sql (CVE-2026-44680)
SQL injection in @mikro-orm/sql (CVE-2026-44680). Confidential information can be exposed externally. Exploitable via ``Platform.quoteIdentifier``. Mitigation: upgrade to `7.0.14` or later.
|
| CVE-2026-8178 |
|
Vulnerability in com.amazon.redshift:redshift-jdbc42 (CVE-2026-8178)
vulnerability in com.amazon.redshift:redshift-jdbc42 (CVE-2026-8178). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.2.2` or later.
|
| CVE-2026-29202 |
|
Code Injection in CVE-2026-29202 (CVE-2026-29202)
code injection in CVE-2026-29202 (CVE-2026-29202). Successful exploitation can lead to full system takeover. Exploitable via ``plugin``.
|
| CVE-2026-29203 |
|
Vulnerability in privilege-escalation (CVE-2026-29203)
vulnerability in privilege-escalation (CVE-2026-29203). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29201 |
|
Vulnerability in CVE-2026-29201 (CVE-2026-29201)
vulnerability in CVE-2026-29201 (CVE-2026-29201). Confidential information can be exposed externally.
|
| CVE-2026-6322 |
|
Vulnerability in fast-uri (CVE-2026-6322)
vulnerability in fast-uri (CVE-2026-6322). Data can be tampered with by attackers. Exploitable via ``evil.com``. Mitigation: upgrade to `2.4.1` or later.
|
| CVE-2026-44721 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-44721)
cross-site scripting in open-webui (CVE-2026-44721). Confidential information can be exposed externally. Exploitable via ``marked``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-6659 |
|
Vulnerability in CVE-2026-6659 (CVE-2026-6659)
vulnerability in CVE-2026-6659 (CVE-2026-6659). Confidential information can be exposed externally.
|
| CVE-2026-44714 |
|
Vulnerability in org.bitcoinj:bitcoinj-core (CVE-2026-44714)
vulnerability in org.bitcoinj:bitcoinj-core (CVE-2026-44714). Data can be tampered with by attackers. Exploitable via ``P2PKH``. Mitigation: upgrade to `0.17.1` or later.
|
| CVE-2026-6321 |
|
Path Traversal in fast-uri (CVE-2026-6321)
path traversal in fast-uri (CVE-2026-6321). Data can be tampered with by attackers. Mitigation: upgrade to `2.4.1` or later.
|
| CVE-2026-7768 |
|
Vulnerability in @fastify/accepts-serializer (CVE-2026-7768)
vulnerability in @fastify/accepts-serializer (CVE-2026-7768). Risk of unauthorized operations or information disclosure. Exploitable via ``Accept``. Mitigation: upgrade to `6.0.4` or later.
|
| CVE-2026-44671 |
|
Vulnerability in github.com/zitadel/zitadel (CVE-2026-44671)
vulnerability in github.com/zitadel/zitadel (CVE-2026-44671). Confidential information can be exposed externally. Mitigation: upgrade to `3.4.10` or later.
|
| CVE-2026-41886 |
|
Vulnerability in locize (CVE-2026-41886)
vulnerability in locize (CVE-2026-41886). Data can be tampered with by attackers. Exploitable via ``locize``. Mitigation: upgrade to `4.0.21` or later.
|
| CVE-2026-42353 |
|
Path Traversal in i18next-http-middleware (CVE-2026-42353)
path traversal in i18next-http-middleware (CVE-2026-42353). Confidential information can be exposed externally. Exploitable via `GET /locales/resources.json`. Mitigation: upgrade to `3.9.3` or later.
|
| CVE-2026-41883 |
|
Vulnerability in org.omnifaces:omnifaces (CVE-2026-41883)
vulnerability in org.omnifaces:omnifaces (CVE-2026-41883). Successful exploitation can lead to full system takeover. Exploitable via ``CDNResourceHandler``. Mitigation: upgrade to `5.2.3` or later.
|
| CVE-2026-41690 |
|
Vulnerability in i18next-http-middleware (CVE-2026-41690)
vulnerability in i18next-http-middleware (CVE-2026-41690). Data can be tampered with by attackers. Exploitable via `GET /locales/resources.json`. Mitigation: upgrade to `3.9.3` or later.
|
| CVE-2026-41693 |
|
Path Traversal in i18next-fs-backend (CVE-2026-41693)
path traversal in i18next-fs-backend (CVE-2026-41693). Confidential information can be exposed externally. Exploitable via ``lng``. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-41683 |
|
Vulnerability in i18next-http-middleware (CVE-2026-41683)
vulnerability in i18next-http-middleware (CVE-2026-41683). Data can be tampered with by attackers. Exploitable via ``i18next``. Mitigation: upgrade to `3.9.3` or later.
|
| CVE-2026-29974 |
|
Vulnerability in CVE-2026-29974 (CVE-2026-29974)
vulnerability in CVE-2026-29974 (CVE-2026-29974). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29975 |
|
Vulnerability in c (CVE-2026-29975)
vulnerability in c (CVE-2026-29975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34354 |
|
Vulnerability in privilege-escalation (CVE-2026-34354)
vulnerability in privilege-escalation (CVE-2026-34354). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29972 |
|
Vulnerability in c (CVE-2026-29972)
vulnerability in c (CVE-2026-29972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44498 |
|
Vulnerability in zebrad (CVE-2026-44498)
vulnerability in zebrad (CVE-2026-44498). Data can be tampered with by attackers. Exploitable via ``MAX_BLOCK_SIGOPS``. Mitigation: upgrade to `4.4.0` or later.
|
| CVE-2026-43462 |
|
Vulnerability in linux (CVE-2026-43462)
vulnerability in linux (CVE-2026-43462). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43464 |
|
Vulnerability in linux (CVE-2026-43464)
vulnerability in linux (CVE-2026-43464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43466 |
|
Vulnerability in c (CVE-2026-43466)
vulnerability in c (CVE-2026-43466). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43469 |
|
Vulnerability in linux (CVE-2026-43469)
vulnerability in linux (CVE-2026-43469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43454 |
|
Vulnerability in linux (CVE-2026-43454)
vulnerability in linux (CVE-2026-43454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43456 |
|
Vulnerability in c (CVE-2026-43456)
vulnerability in c (CVE-2026-43456). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43461 |
|
Vulnerability in linux (CVE-2026-43461)
vulnerability in linux (CVE-2026-43461). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43453 |
|
Out-of-Bounds Read in linux (CVE-2026-43453)
vulnerability in linux (CVE-2026-43453). Confidential information can be exposed externally.
|
| CVE-2026-43458 |
|
Use-After-Free in linux (CVE-2026-43458)
vulnerability in linux (CVE-2026-43458). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43459 |
|
Use-After-Free in linux (CVE-2026-43459)
vulnerability in linux (CVE-2026-43459). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43460 |
|
Vulnerability in linux (CVE-2026-43460)
vulnerability in linux (CVE-2026-43460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43452 |
|
Vulnerability in linux (CVE-2026-43452)
vulnerability in linux (CVE-2026-43452). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43447 |
|
Use-After-Free in linux (CVE-2026-43447)
vulnerability in linux (CVE-2026-43447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43449 |
|
Out-of-Bounds Read in c (CVE-2026-43449)
vulnerability in c (CVE-2026-43449). Confidential information can be exposed externally.
|
| CVE-2026-43450 |
|
Out-of-Bounds Read in linux (CVE-2026-43450)
vulnerability in linux (CVE-2026-43450). Confidential information can be exposed externally.
|
| CVE-2026-43437 |
|
Use-After-Free in linux (CVE-2026-43437)
vulnerability in linux (CVE-2026-43437). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43438 |
|
Use-After-Free in linux (CVE-2026-43438)
vulnerability in linux (CVE-2026-43438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43440 |
|
Use-After-Free in linux (CVE-2026-43440)
vulnerability in linux (CVE-2026-43440). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43441 |
|
Vulnerability in linux (CVE-2026-43441)
vulnerability in linux (CVE-2026-43441). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43442 |
|
Vulnerability in linux (CVE-2026-43442)
vulnerability in linux (CVE-2026-43442). Confidential information can be exposed externally.
|
| CVE-2026-43433 |
|
Vulnerability in CVE-2026-43433 (CVE-2026-43433)
vulnerability in CVE-2026-43433 (CVE-2026-43433). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43434 |
|
Vulnerability in c (CVE-2026-43434)
vulnerability in c (CVE-2026-43434). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43426 |
|
Use-After-Free in linux (CVE-2026-43426)
vulnerability in linux (CVE-2026-43426). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43427 |
|
Out-of-Bounds Read in linux (CVE-2026-43427)
vulnerability in linux (CVE-2026-43427). Confidential information can be exposed externally.
|
| CVE-2026-43405 |
|
Vulnerability in linux (CVE-2026-43405)
vulnerability in linux (CVE-2026-43405). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43408 |
|
Vulnerability in c (CVE-2026-43408)
vulnerability in c (CVE-2026-43408). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43403 |
|
Vulnerability in linux (CVE-2026-43403)
vulnerability in linux (CVE-2026-43403). Successful exploitation can lead to full system takeover.
|