Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-73567 Vulnerability in sm-crypto (CVE-2026-73567)
vulnerability in sm-crypto (CVE-2026-73567). Confidential information can be exposed externally. Exploitable via ``SecureRandom``. Mitigation: upgrade to `0.5.0` or later.
GHSA-v6w6-358x-2433 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (GHSA-v6w6-358x-2433)
vulnerability in github.com/cloudreve/Cloudreve/v4 (GHSA-v6w6-358x-2433). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v4/admin/node`. Mitigation: upgrade to `4.0.0-20260626022735-332a9d800205` or later.
CVE-2026-73652 Authorization Flaw in vantage6 (CVE-2026-73652)
vulnerability in vantage6 (CVE-2026-73652). Risk of unauthorized operations or information disclosure.
GHSA-2625-rw7m-5q5x Vulnerability in hubuum_client (GHSA-2625-rw7m-5q5x)
vulnerability in hubuum_client (GHSA-2625-rw7m-5q5x). Risk of unauthorized operations or information disclosure. Exploitable via ``hubuum_client``. Mitigation: upgrade to `0.6.1` or later.
GHSA-qqc3-94qv-7fw3 Vulnerability in hubuum_client (GHSA-qqc3-94qv-7fw3)
vulnerability in hubuum_client (GHSA-qqc3-94qv-7fw3). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.1` or later.
GHSA-f45q-w629-wr25 Information Disclosure in hubuum_client (GHSA-f45q-w629-wr25)
vulnerability in hubuum_client (GHSA-f45q-w629-wr25). Risk of unauthorized operations or information disclosure. Exploitable via ``BaseUrl``. Mitigation: upgrade to `0.6.1` or later.
CVE-2026-73564 Vulnerability in github.com/fatedier/frp (CVE-2026-73564)
vulnerability in github.com/fatedier/frp (CVE-2026-73564). Risk of unauthorized operations or information disclosure. Exploitable via ``frps``. Mitigation: upgrade to `0.70.1` or later.
CVE-2026-73561 Vulnerability in @anephenix/hub (CVE-2026-73561)
vulnerability in @anephenix/hub (CVE-2026-73561). Risk of unauthorized operations or information disclosure. Exploitable via ``setInterval``. Mitigation: upgrade to `0.2.16` or later.
GHSA-c534-2w9c-x7fm Vulnerability in github.com/zxh326/kite (GHSA-c534-2w9c-x7fm)
vulnerability in github.com/zxh326/kite (GHSA-c534-2w9c-x7fm). Risk of unauthorized operations or information disclosure. Exploitable via ``get``. Mitigation: upgrade to `0.14.1` or later.
CVE-2026-73644 Vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644)
vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644). Confidential information can be exposed externally. Mitigation: upgrade to `5.1.2` or later.
GHSA-68r5-9hpg-7qw9 Vulnerability in org.openidentityplatform.opendj:opendj-dsml-servlet (GHSA-68r5-9hpg-7qw9)
vulnerability in org.openidentityplatform.opendj:opendj-dsml-servlet (GHSA-68r5-9hpg-7qw9). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.1.2` or later.
GHSA-g3hq-hphg-8fhh OS Command Injection in pheditor/pheditor (GHSA-g3hq-hphg-8fhh)
OS command injection in pheditor/pheditor (GHSA-g3hq-hphg-8fhh). Risk of unauthorized operations or information disclosure. Exploitable via ``TERMINAL_COMMANDS``. Mitigation: upgrade to `2.0.7` or later.
GHSA-94p4-4cq8-9g67 Information Disclosure in GitPython (GHSA-94p4-4cq8-9g67)
vulnerability in GitPython (GHSA-94p4-4cq8-9g67). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `3.1.55` or later.
CVE-2026-73307 SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-73307)
SSRF in @budibase/server (CVE-2026-73307). Risk of unauthorized operations or information disclosure.
CVE-2026-73410 Vulnerability in @budibase/server (CVE-2026-73410)
vulnerability in @budibase/server (CVE-2026-73410). Successful exploitation can lead to full system takeover. Exploitable via ``fetchWithBlacklist``.
GHSA-pmpg-2mxq-6xwr SQL Injection in @budibase/server (GHSA-pmpg-2mxq-6xwr)
SQL injection in @budibase/server (GHSA-pmpg-2mxq-6xwr). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/queries/`.
CVE-2026-73306 Vulnerability in @budibase/server (CVE-2026-73306)
vulnerability in @budibase/server (CVE-2026-73306). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/global/auth/`.
GHSA-pvcr-8mvp-w8qr Vulnerability in @budibase/server (GHSA-pvcr-8mvp-w8qr)
vulnerability in @budibase/server (GHSA-pvcr-8mvp-w8qr). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/chat-links/`.
GHSA-2xgg-r2wc-c5r2 SQL Injection in @budibase/server (GHSA-2xgg-r2wc-c5r2)
SQL injection in @budibase/server (GHSA-2xgg-r2wc-c5r2). Risk of unauthorized operations or information disclosure. Exploitable via ``INFORMATION_SCHEMA.TABLES``.
GHSA-qw6m-8fw2-2v64 Vulnerability in @budibase/server (GHSA-qw6m-8fw2-2v64)
vulnerability in @budibase/server (GHSA-qw6m-8fw2-2v64). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v2/queries/`.
CVE-2026-73308 Information Disclosure in @budibase/server (CVE-2026-73308)
vulnerability in @budibase/server (CVE-2026-73308). Confidential information can be exposed externally. Exploitable via `GET /api/automations/`.
CVE-2026-73406 Information Disclosure in @budibase/server (CVE-2026-73406)
vulnerability in @budibase/server (CVE-2026-73406). Confidential information can be exposed externally. Exploitable via `GET /api/global/users/tenant/`.
GHSA-mqhr-6j6h-74p5 Information Disclosure in @budibase/server (GHSA-mqhr-6j6h-74p5)
vulnerability in @budibase/server (GHSA-mqhr-6j6h-74p5). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v2/queries/`.
CVE-2026-62323 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-62323)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-62323). Data can be tampered with by attackers. Exploitable via `PUT /api/v4/file/viewerSession`. Mitigation: upgrade to `4.0.0-20260626022433-f3347130ac48` or later.
CVE-2026-73302 Authentication Bypass in @budibase/server (CVE-2026-73302)
authentication bypass in @budibase/server (CVE-2026-73302). Risk of unauthorized operations or information disclosure. Exploitable via `POST /realms/budi/protocol/openid-connect/token`.
GHSA-xg5g-26x8-cvf4 SSRF (Server-Side Request Forgery) in @budibase/server (GHSA-xg5g-26x8-cvf4)
SSRF in @budibase/server (GHSA-xg5g-26x8-cvf4). Risk of unauthorized operations or information disclosure. Exploitable via ``fetchFn``.
GHSA-xcx6-4f2g-hhgx Authorization Flaw in @budibase/server (GHSA-xcx6-4f2g-hhgx)
vulnerability in @budibase/server (GHSA-xcx6-4f2g-hhgx). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/attachments/`.
CVE-2026-73409 Vulnerability in @budibase/server (CVE-2026-73409)
vulnerability in @budibase/server (CVE-2026-73409). Risk of unauthorized operations or information disclosure. Exploitable via ``tlsCertificateKeyFile``.
GHSA-q6x4-v3qx-85qw SQL Injection in @budibase/server (GHSA-q6x4-v3qx-85qw)
SQL injection in @budibase/server (GHSA-q6x4-v3qx-85qw). Risk of unauthorized operations or information disclosure.
CVE-2026-73303 Vulnerability in @budibase/server (CVE-2026-73303)
vulnerability in @budibase/server (CVE-2026-73303). Confidential information can be exposed externally. Exploitable via `POST /api/v2/email`.
CVE-2026-73304 Information Disclosure in @budibase/server (CVE-2026-73304)
vulnerability in @budibase/server (CVE-2026-73304). Confidential information can be exposed externally. Exploitable via `GET /api/users/metadata`. Mitigation: upgrade to `3.39.25` or later.
CVE-2026-73301 Vulnerability in @budibase/server (CVE-2026-73301)
vulnerability in @budibase/server (CVE-2026-73301). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/global/groups`.
CVE-2026-73305 Privilege Escalation in @budibase/server (CVE-2026-73305)
vulnerability in @budibase/server (CVE-2026-73305). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/public/v1/roles/assign`.
CVE-2026-62379 Code Injection in org.openidentityplatform.openam:openam-core (CVE-2026-62379)
code injection in org.openidentityplatform.openam:openam-core (CVE-2026-62379). Risk of unauthorized operations or information disclosure. Exploitable via ``DSAMECallbackInterface``. Mitigation: upgrade to `16.1.2` or later.
CVE-2026-62280 Cross-Site Scripting (XSS) in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-62280)
cross-site scripting in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-62280). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.2` or later.
CVE-2026-62263 Unsafe Deserialization in org.openidentityplatform.openam:openam-auth-webauthn (CVE-2026-62263)
vulnerability in org.openidentityplatform.openam:openam-auth-webauthn (CVE-2026-62263). Risk of unauthorized operations or information disclosure. Exploitable via ``ObjectInputFilter``. Mitigation: upgrade to `16.1.2` or later.
CVE-2026-57497 Vulnerability in github.com/quic-go/webtransport-go (CVE-2026-57497)
vulnerability in github.com/quic-go/webtransport-go (CVE-2026-57497). Risk of unauthorized operations or information disclosure. Exploitable via ``io.ReadAll``. Mitigation: upgrade to `0.11.1` or later.
CVE-2026-55502 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55502)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55502). Data can be tampered with by attackers. Exploitable via `POST /api/v4/admin/policy/oauth/signin`. Mitigation: upgrade to `4.17.0` or later.
CVE-2026-55499 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55499)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55499). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4/file/events`. Mitigation: upgrade to `4.0.0-20260613030215-0b00dd308f13` or later.
CVE-2026-55497 Vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55497)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55497). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v4/user/setting/avatar`. Mitigation: upgrade to `4.0.0-20260613024411-3607f79bb44c` or later.
CVE-2026-55496 Information Disclosure in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55496)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55496). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4/user/search`. Mitigation: upgrade to `4.0.0-20260613023921-7e1289d55279` or later.
CVE-2026-55495 Path Traversal in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55495)
path traversal in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55495). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v4/file/wopi/`. Mitigation: upgrade to `4.0.0-20260613023150-7968e50429ef` or later.
CVE-2026-66041 FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
CVE-2026-66040 FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
CVE-2026-66039 FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability...
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability...
CVE-2026-66038 Vulnerability in c (CVE-2026-66038)
vulnerability in c (CVE-2026-66038). Confidential information can be exposed externally.
CVE-2026-66037 Vulnerability in c (CVE-2026-66037)
vulnerability in c (CVE-2026-66037). Risk of unauthorized operations or information disclosure.
CVE-2026-66036 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
CVE-2026-62835 Vulnerability in microsoft (CVE-2026-62835)
vulnerability in microsoft (CVE-2026-62835). Confidential information can be exposed externally.
CVE-2026-57531 Cross-Site Scripting (XSS) in CVE-2026-57531 (CVE-2026-57531)
cross-site scripting in CVE-2026-57531 (CVE-2026-57531). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →