Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-3g4q-2f67-2gvh |
|
Vulnerability in github.com/tinfoil-factory/netfoil (GHSA-3g4q-2f67-2gvh)
vulnerability in github.com/tinfoil-factory/netfoil (GHSA-3g4q-2f67-2gvh). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.3.0` or later.
|
| GHSA-59qp-cfj3-rp64 |
|
Vulnerability in github.com/tinfoil-factory/netfoil (GHSA-59qp-cfj3-rp64)
vulnerability in github.com/tinfoil-factory/netfoil (GHSA-59qp-cfj3-rp64). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.3.0` or later.
|
| MINI-x8p7-ff83-q5rc |
|
MINI-x8p7-ff83-q5rc |
| MINI-9w2c-fmjm-x4pc |
|
MINI-9w2c-fmjm-x4pc |
| MINI-rgf3-qm9h-x3m8 |
|
MINI-rgf3-qm9h-x3m8 |
| MINI-pj5f-chpx-6xx2 |
|
MINI-pj5f-chpx-6xx2 |
| MINI-r63m-pm7p-645g |
|
MINI-r63m-pm7p-645g |
| MINI-jrgv-4853-gm7f |
|
MINI-jrgv-4853-gm7f |
| MINI-h854-wwjw-5282 |
|
MINI-h854-wwjw-5282 |
| MINI-973r-cf8f-6fvw |
|
MINI-973r-cf8f-6fvw |
| MINI-79jp-x795-3jp6 |
|
MINI-79jp-x795-3jp6 |
| MINI-9p6c-2w3c-2f4c |
|
MINI-9p6c-2w3c-2f4c |
| MINI-9gpq-3mpq-p77x |
|
MINI-9gpq-3mpq-p77x |
| GHSA-fqf6-gxhh-2xhw |
|
Vulnerability in uucore (GHSA-fqf6-gxhh-2xhw)
vulnerability in uucore (GHSA-fqf6-gxhh-2xhw). Risk of unauthorized operations or information disclosure. Exploitable via ``determine_backup_mode``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-53509 |
|
SSRF (Server-Side Request Forgery) in @aborruso/ckan-mcp-server (CVE-2026-53509)
SSRF in @aborruso/ckan-mcp-server (CVE-2026-53509). Confidential information can be exposed externally. Exploitable via ``localhost``. Mitigation: upgrade to `0.4.106` or later.
|
| CVE-2026-7017 |
|
Vulnerability in CVE-2026-7017 (CVE-2026-7017)
vulnerability in CVE-2026-7017 (CVE-2026-7017). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-59708 |
|
Vulnerability in CVE-2026-59708 (CVE-2026-59708)
vulnerability in CVE-2026-59708 (CVE-2026-59708). Confidential information can be exposed externally. Exploitable via `GET /api/v1/public/`.
|
| CVE-2026-48958 |
|
Vulnerability in joomla (CVE-2026-48958)
vulnerability in joomla (CVE-2026-48958). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48957 |
|
An improper access check allows unauthorized users to access com_privacy datasets.
An improper access check allows unauthorized users to access com_privacy datasets.
|
| CVE-2026-48956 |
|
An improper access check allows users to display a list of modules in the frontend.
An improper access check allows users to display a list of modules in the frontend.
|
| CVE-2026-48955 |
|
Vulnerability in joomla (CVE-2026-48955)
vulnerability in joomla (CVE-2026-48955). Confidential information can be exposed externally.
|
| CVE-2026-48954 |
|
Improper validation leads to a generic XSS vector in the language override feature.
Improper validation leads to a generic XSS vector in the language override feature.
|
| CVE-2026-48953 |
|
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
|
| CVE-2026-48952 |
|
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
|
| CVE-2026-48951 |
|
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
|
| CVE-2026-48950 |
|
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
|
| CVE-2026-48949 |
|
Lack of validation leads to an XSS vulnerability in the MFA management views.
Lack of validation leads to an XSS vulnerability in the MFA management views.
|
| CVE-2026-48948 |
|
Vulnerability in joomla (CVE-2026-48948)
vulnerability in joomla (CVE-2026-48948). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48947 |
|
Vulnerability in joomla (CVE-2026-48947)
vulnerability in joomla (CVE-2026-48947). Data can be tampered with by attackers.
|
| CVE-2026-57851 |
|
Vulnerability in privilege-escalation (CVE-2026-57851)
vulnerability in privilege-escalation (CVE-2026-57851). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23698 |
|
Unrestricted File Upload in apache (CVE-2026-23698)
vulnerability in apache (CVE-2026-23698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23697 |
|
Unrestricted File Upload in apache (CVE-2026-23697)
vulnerability in apache (CVE-2026-23697). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14904 |
|
Vulnerability in Amazon aws (CVE-2026-14904)
vulnerability in Amazon aws (CVE-2026-14904). Confidential information can be exposed externally.
|
| CVE-2026-13020 |
|
Vulnerability in esri (CVE-2026-13020)
vulnerability in esri (CVE-2026-13020). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13019 |
|
Vulnerability in esri (CVE-2026-13019)
vulnerability in esri (CVE-2026-13019). Successful exploitation can lead to full system takeover.
|
| CVE-2025-12799 |
|
Cross-Site Scripting (XSS) in CVE-2025-12799 (CVE-2025-12799)
cross-site scripting in CVE-2025-12799 (CVE-2025-12799). Data can be tampered with by attackers.
|
| CVE-2026-20744 |
|
Vulnerability in cisa (CVE-2026-20744)
vulnerability in cisa (CVE-2026-20744). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42953 |
|
Out-of-Bounds Write in cisa (CVE-2026-42953)
out-of-bounds write in cisa (CVE-2026-42953). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35166 |
|
Cross-Site Scripting (XSS) in github.com/gohugoio/hugo (CVE-2026-35166)
cross-site scripting in github.com/gohugoio/hugo (CVE-2026-35166). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.159.2` or later.
|
| CVE-2026-35480 |
|
Vulnerability in github.com/ipld/go-ipld-prime (CVE-2026-35480)
vulnerability in github.com/ipld/go-ipld-prime (CVE-2026-35480). Risk of unauthorized operations or information disclosure. Exploitable via ``basicnode.Prototype.Any``. Mitigation: upgrade to `0.22.0` or later.
|
| CVE-2026-34225 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-34225)
SSRF in open-webui (CVE-2026-34225). Risk of unauthorized operations or information disclosure. Exploitable via ``load_url_image``.
|
| CVE-2026-26193 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-26193)
cross-site scripting in open-webui (CVE-2026-26193). Risk of unauthorized operations or information disclosure. Exploitable via ``embeds``. Mitigation: upgrade to `0.6.44` or later.
|
| CVE-2026-26192 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-26192)
cross-site scripting in open-webui (CVE-2026-26192). Risk of unauthorized operations or information disclosure. Exploitable via ``html``. Mitigation: upgrade to `0.7.0` or later.
|
| CVE-2025-46719 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2025-46719)
cross-site scripting in open-webui (CVE-2025-46719). Risk of unauthorized operations or information disclosure. Exploitable via ``onload``. Mitigation: upgrade to `0.6.6` or later.
|
| CVE-2025-46571 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2025-46571)
cross-site scripting in open-webui (CVE-2025-46571). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/files/`. Mitigation: upgrade to `0.6.6` or later.
|
| CVE-2025-70560 |
|
Unsafe Deserialization in boltz (CVE-2025-70560)
vulnerability in boltz (CVE-2025-70560). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25517 |
|
Vulnerability in wagtail (CVE-2026-25517)
vulnerability in wagtail (CVE-2026-25517). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.3` or later.
|
| CVE-2026-1778 |
|
Vulnerability in sagemaker (CVE-2026-1778)
vulnerability in sagemaker (CVE-2026-1778). Data can be tampered with by attackers. Mitigation: upgrade to `2.256.0` or later.
|
| CVE-2025-69207 |
|
Vulnerability in khoj (CVE-2025-69207)
vulnerability in khoj (CVE-2025-69207). Risk of unauthorized operations or information disclosure. Exploitable via ``state``.
|
| PYSEC-2026-1075 |
|
Vulnerability in tiktoken-mcp (PYSEC-2026-1075)
vulnerability in tiktoken-mcp (PYSEC-2026-1075). Risk of unauthorized operations or information disclosure.
|