Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-7fjv-hm97-r96c |
|
MINI-7fjv-hm97-r96c |
| MINI-3f6x-35mh-49gw |
|
MINI-3f6x-35mh-49gw |
| MINI-3445-326c-w86h |
|
MINI-3445-326c-w86h |
| MINI-8qfw-984x-pj2r |
|
MINI-8qfw-984x-pj2r |
| MINI-vvcg-m4cg-93f6 |
|
MINI-vvcg-m4cg-93f6 |
| MINI-p636-mwh6-2gmh |
|
MINI-p636-mwh6-2gmh |
| MINI-7j63-8xqm-27xc |
|
MINI-7j63-8xqm-27xc |
| CVE-2026-53483 |
|
Authentication Bypass in dell (CVE-2026-53483)
authentication bypass in dell (CVE-2026-53483). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53481 |
|
Path Traversal in path-traversal (CVE-2026-53481)
path traversal in path-traversal (CVE-2026-53481). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10659 |
|
Vulnerability in c (CVE-2026-10659)
vulnerability in c (CVE-2026-10659). Risk of unauthorized operations or information disclosure.
|
| ROOT-APP-PYPI-CVE-2026-48990 |
|
Vulnerability in rootio-joserfc (ROOT-APP-PYPI-CVE-2026-48990)
vulnerability in rootio-joserfc (ROOT-APP-PYPI-CVE-2026-48990). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.0+root.io.4, 1.6.5+root.io.2, 1.6.3+root.io.2, 1.6.2+root.io.4, 1.4.3+root.io.3, 1.6.0+root.io.4, 1.6.4+root.io.2, 1.6.1+root.io.4` or later.
|
| ROOT-APP-PYPI-CVE-2026-49852 |
|
Vulnerability in rootio-joserfc (ROOT-APP-PYPI-CVE-2026-49852)
vulnerability in rootio-joserfc (ROOT-APP-PYPI-CVE-2026-49852). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.7+root.io.1, 1.6.2+root.io.3, 1.6.0+root.io.3, 1.6.4+root.io.1, 1.5.0+root.io.3, 1.6.3+root.io.1, 1.6.1+root.io.3, 1.6.5+root.io.1, 1.5.0+root.io.4, 1.6.5+root.io.2, 1.6.3+root.io.2, 1.6.2+root.io.4, 1.4.3+root.io.3, 1.6.0+root.io.4, 1.6.4+root.io.2, 1.6.1+root.io.4` or later.
|
| CVE-2026-45016 |
|
Vulnerability in egroupware/egroupware (CVE-2026-45016)
vulnerability in egroupware/egroupware (CVE-2026-45016). Confidential information can be exposed externally. Mitigation: upgrade to `23.1.20260601` or later.
|
| CVE-2026-44512 |
|
Vulnerability in onnx (CVE-2026-44512)
vulnerability in onnx (CVE-2026-44512). Risk of unauthorized operations or information disclosure. Exploitable via ``width_scale``. Mitigation: upgrade to `1.22.0` or later.
|
| CVE-2026-44342 |
|
Cross-Site Request Forgery (CSRF) in github.com/QuantumNous/new-api (CVE-2026-44342)
vulnerability in github.com/QuantumNous/new-api (CVE-2026-44342). Data can be tampered with by attackers. Exploitable via `GET /api/oauth/email/bind`. Mitigation: upgrade to `0.12.0-alpha.1` or later.
|
| CVE-2026-40187 |
|
OS Command Injection in egroupware/egroupware (CVE-2026-40187)
OS command injection in egroupware/egroupware (CVE-2026-40187). Risk of unauthorized operations or information disclosure. Exploitable via ``chgrp``. Mitigation: upgrade to `23.1.20260601` or later.
|
| CVE-2026-34151 |
|
Vulnerability in org.xwiki.platform:xwiki-platform-oldcore (CVE-2026-34151)
vulnerability in org.xwiki.platform:xwiki-platform-oldcore (CVE-2026-34151). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.2.0` or later.
|
| CVE-2026-33655 |
|
SSRF (Server-Side Request Forgery) in github.com/QuantumNous/new-api (CVE-2026-33655)
SSRF in github.com/QuantumNous/new-api (CVE-2026-33655). Confidential information can be exposed externally. Exploitable via ``ApplyIPFilterForDomain``. Mitigation: upgrade to `0.12.0-alpha.1` or later.
|
| CVE-2026-27823 |
|
Path Traversal in egroupware/egroupware (CVE-2026-27823)
path traversal in egroupware/egroupware (CVE-2026-27823). Risk of unauthorized operations or information disclosure. Exploitable via ``participant_role``. Mitigation: upgrade to `23.1.20260224` or later.
|
| CVE-2026-13696 |
|
Vulnerability in CVE-2026-13696 (CVE-2026-13696)
vulnerability in CVE-2026-13696 (CVE-2026-13696). Successful exploitation can lead to full system takeover.
|
| CVE-2011-10043 |
|
Vulnerability in CVE-2011-10043 (CVE-2011-10043)
vulnerability in CVE-2011-10043 (CVE-2011-10043). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11348 |
|
Vulnerability in CVE-2026-11348 (CVE-2026-11348)
vulnerability in CVE-2026-11348 (CVE-2026-11348). Successful exploitation can lead to full system takeover.
|
| RLSA-2026:35826 |
|
Vulnerability in grafana-pcp (RLSA-2026:35826)
vulnerability in grafana-pcp (RLSA-2026:35826). Confidential information can be exposed externally. Mitigation: upgrade to `0:5.3.0-7.el10_2` or later.
|
| RLSA-2026:33731 |
|
Vulnerability in rrdtool (RLSA-2026:33731)
vulnerability in rrdtool (RLSA-2026:33731). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:1.8.0-21.el10_2` or later.
|
| RLSA-2026:35832 |
|
Vulnerability in golang-github-openprinting-ipp-usb (RLSA-2026:35832)
vulnerability in golang-github-openprinting-ipp-usb (RLSA-2026:35832). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:0.9.27-7.el10_2.2` or later.
|
| RLSA-2026:34109 |
|
Vulnerability in httpd (RLSA-2026:34109)
vulnerability in httpd (RLSA-2026:34109). Data can be tampered with by attackers. Mitigation: upgrade to `0:2.4.63-13.el10_2.4` or later.
|
| RLSA-2026:35827 |
|
Vulnerability in grafana (RLSA-2026:35827)
vulnerability in grafana (RLSA-2026:35827). Confidential information can be exposed externally. Mitigation: upgrade to `0:10.2.6-27.el10_2` or later.
|
| RLSA-2026:34355 |
|
Vulnerability in mod_http2 (RLSA-2026:34355)
vulnerability in mod_http2 (RLSA-2026:34355). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.0.29-4.el10_2.2` or later.
|
| RLSA-2026:34357 |
|
Vulnerability in opentelemetry-collector (RLSA-2026:34357)
vulnerability in opentelemetry-collector (RLSA-2026:34357). Confidential information can be exposed externally. Mitigation: upgrade to `0:0.152.1-1.el10_2` or later.
|
| RLSA-2026:35828 |
|
Vulnerability in grafana (RLSA-2026:35828)
vulnerability in grafana (RLSA-2026:35828). Confidential information can be exposed externally. Mitigation: upgrade to `0:10.2.6-23.el9_8` or later.
|
| RLSA-2026:35829 |
|
Vulnerability in grafana-pcp (RLSA-2026:35829)
vulnerability in grafana-pcp (RLSA-2026:35829). Confidential information can be exposed externally. Mitigation: upgrade to `0:5.1.1-17.el9_8` or later.
|
| CVE-2024-37063 |
|
Cross-Site Scripting (XSS) in ydata-profiling (CVE-2024-37063)
cross-site scripting in ydata-profiling (CVE-2024-37063). Successful exploitation can lead to full system takeover.
|
| CVE-2024-37065 |
|
Unsafe Deserialization in skops (CVE-2024-37065)
vulnerability in skops (CVE-2024-37065). Successful exploitation can lead to full system takeover.
|
| CVE-2024-5629 |
|
Out-of-Bounds Read in pymongo (CVE-2024-5629)
vulnerability in pymongo (CVE-2024-5629). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.6.3` or later.
|
| CVE-2024-37064 |
|
Unsafe Deserialization in ydata-profiling (CVE-2024-37064)
vulnerability in ydata-profiling (CVE-2024-37064). Successful exploitation can lead to full system takeover.
|
| CVE-2024-37062 |
|
Unsafe Deserialization in ydata-profiling (CVE-2024-37062)
vulnerability in ydata-profiling (CVE-2024-37062). Successful exploitation can lead to full system takeover.
|
| CVE-2024-4325 |
|
SSRF (Server-Side Request Forgery) in gradio (CVE-2024-4325)
SSRF in gradio (CVE-2024-4325). Confidential information can be exposed externally. Exploitable via ``save_url_to_cache``.
|
| CVE-2024-3095 |
|
SSRF (Server-Side Request Forgery) in langchain-community (CVE-2024-3095)
SSRF in langchain-community (CVE-2024-3095). Confidential information can be exposed externally. Mitigation: upgrade to `0.2.9` or later.
|
| CVE-2024-35196 |
|
Vulnerability in sentry (CVE-2024-35196)
vulnerability in sentry (CVE-2024-35196). Risk of unauthorized operations or information disclosure. Exploitable via ``request_data.token``. Mitigation: upgrade to `24.5.0` or later.
|
| CVE-2024-3924 |
|
Code Injection in text-generation (CVE-2024-3924)
code injection in text-generation (CVE-2024-3924). Risk of unauthorized operations or information disclosure. Exploitable via ``github.head_ref``. Mitigation: upgrade to `2.0.0` or later.
|
| CVE-2024-4330 |
|
Vulnerability in lollms (CVE-2024-4330)
vulnerability in lollms (CVE-2024-4330). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-35228 |
|
Vulnerability in wagtail (CVE-2024-35228)
vulnerability in wagtail (CVE-2024-35228). Data can be tampered with by attackers. Exploitable via ``wagtail.contrib.settings``. Mitigation: upgrade to `6.1.2` or later.
|
| CVE-2024-1727 |
|
Cross-Site Request Forgery (CSRF) in gradio (CVE-2024-1727)
vulnerability in gradio (CVE-2024-1727). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.19.2` or later.
|
| CVE-2024-35180 |
|
Vulnerability in omero-web (CVE-2024-35180)
vulnerability in omero-web (CVE-2024-35180). Risk of unauthorized operations or information disclosure. Exploitable via ``callback``. Mitigation: upgrade to `5.26.0` or later.
|
| CVE-2024-32969 |
|
Vulnerability in vantage6 (CVE-2024-32969)
vulnerability in vantage6 (CVE-2024-32969). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.5.0rc3` or later.
|
| CVE-2024-35189 |
|
Information Disclosure in ethyca-fides (CVE-2024-35189)
vulnerability in ethyca-fides (CVE-2024-35189). Confidential information can be exposed externally. Exploitable via `GET /api/v1/connections`. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2022-4969 |
|
Vulnerability in rockhopper (CVE-2022-4969)
vulnerability in rockhopper (CVE-2022-4969). Risk of unauthorized operations or information disclosure. Exploitable via ``count_rows``. Mitigation: upgrade to `0.2.0` or later.
|
| CVE-2024-34715 |
|
Vulnerability in ethyca-fides (CVE-2024-34715)
vulnerability in ethyca-fides (CVE-2024-34715). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2024-36105 |
|
Vulnerability in dbt-core (CVE-2024-36105)
vulnerability in dbt-core (CVE-2024-36105). Risk of unauthorized operations or information disclosure. Exploitable via ``INADDR_ANY``. Mitigation: upgrade to `1.8.1` or later.
|
| CVE-2024-36110 |
|
Cross-Site Scripting (XSS) in ansibleguy-webui (CVE-2024-36110)
cross-site scripting in ansibleguy-webui (CVE-2024-36110). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.21` or later.
|