Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-41434 |
|
Vulnerability in trustedfirmware (CVE-2026-41434)
vulnerability in trustedfirmware (CVE-2026-41434). Risk of unauthorized operations or information disclosure.
|
| CGA-4r4g-r9vj-3rp9 |
|
CGA-4r4g-r9vj-3rp9 |
| RLSA-2026:35833 |
|
Vulnerability in aardvark-dns (RLSA-2026:35833)
vulnerability in aardvark-dns (RLSA-2026:35833). Confidential information can be exposed externally. Mitigation: upgrade to `2:1.10.1-2.module+el8.10.0+40047+0c0a73f4` or later.
|
| CVE-2026-35338 |
|
Path Traversal in uu_chmod (CVE-2026-35338)
path traversal in uu_chmod (CVE-2026-35338). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-55786 |
|
OS Command Injection in flyto-core (CVE-2026-55786)
OS command injection in flyto-core (CVE-2026-55786). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mcp`. Mitigation: upgrade to `2.26.4` or later.
|
| CVE-2026-55787 |
|
SSRF (Server-Side Request Forgery) in flyto-core (CVE-2026-55787)
SSRF in flyto-core (CVE-2026-55787). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/execute`. Mitigation: upgrade to `2.26.3` or later.
|
| GHSA-7jvp-hj45-2f2m |
|
Vulnerability in Scriban (GHSA-7jvp-hj45-2f2m)
vulnerability in Scriban (GHSA-7jvp-hj45-2f2m). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.2.2` or later.
|
| CVE-2026-49452 |
|
Vulnerability in weasyprint (CVE-2026-49452)
vulnerability in weasyprint (CVE-2026-49452). Risk of unauthorized operations or information disclosure. Exploitable via ``background``.
|
| CVE-2026-40257 |
|
Out-of-Bounds Write in trustedfirmware (CVE-2026-40257)
out-of-bounds write in trustedfirmware (CVE-2026-40257). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-53831 |
|
Cross-Site Scripting (XSS) in CVE-2025-53831 (CVE-2025-53831)
cross-site scripting in CVE-2025-53831 (CVE-2025-53831). Confidential information can be exposed externally.
|
| CVE-2026-49445 |
|
Vulnerability in github.com/cilium/cilium (CVE-2026-49445)
vulnerability in github.com/cilium/cilium (CVE-2026-49445). Confidential information can be exposed externally. Mitigation: upgrade to `1.17.14` or later.
|
| CVE-2026-49439 |
|
Vulnerability in io.openremote:openremote-manager (CVE-2026-49439)
vulnerability in io.openremote:openremote-manager (CVE-2026-49439). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/{realm}/asset/predicted/{assetId}/{attributeName}`. Mitigation: upgrade to `1.24.1` or later.
|
| CVE-2026-52889 |
|
Vulnerability in verbb/formie (CVE-2026-52889)
vulnerability in verbb/formie (CVE-2026-52889). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.27` or later.
|
| CVE-2022-46292 |
|
Buffer Overflow in openbabel (CVE-2022-46292)
vulnerability in openbabel (CVE-2022-46292). Risk of unauthorized operations or information disclosure. Exploitable via ``obabel``. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-5268 |
|
Vulnerability in CVE-2026-5268 (CVE-2026-5268)
vulnerability in CVE-2026-5268 (CVE-2026-5268). Confidential information can be exposed externally.
|
| CVE-2026-59196 |
|
Path Traversal in pnpm (CVE-2026-59196)
path traversal in pnpm (CVE-2026-59196). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-59195 |
|
Path Traversal in pnpm (CVE-2026-59195)
path traversal in pnpm (CVE-2026-59195). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-59194 |
|
Path Traversal in pnpm (CVE-2026-59194)
path traversal in pnpm (CVE-2026-59194). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-59152 |
|
Path Traversal in CVE-2026-59152 (CVE-2026-59152)
path traversal in CVE-2026-59152 (CVE-2026-59152). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.18` or later.
|
| CVE-2026-58203 |
|
Path Traversal in pydantic (CVE-2026-58203)
path traversal in pydantic (CVE-2026-58203). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.14.2` or later.
|
| CVE-2026-13122 |
|
Vulnerability in dos (CVE-2026-13122)
vulnerability in dos (CVE-2026-13122). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-53830 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-53830)
SSRF in ssrf (CVE-2025-53830). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53829 |
|
Vulnerability in path-traversal (CVE-2025-53829)
vulnerability in path-traversal (CVE-2025-53829). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53828 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-53828)
SSRF in ssrf (CVE-2025-53828). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53827 |
|
Vulnerability in CVE-2025-53827 (CVE-2025-53827)
vulnerability in CVE-2025-53827 (CVE-2025-53827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7185 |
|
Path Traversal in CVE-2026-7185 (CVE-2026-7185)
path traversal in CVE-2026-7185 (CVE-2026-7185). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13698 |
|
Vulnerability in dos (CVE-2026-13698)
vulnerability in dos (CVE-2026-13698). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58380 |
|
Vulnerability in dos (CVE-2026-58380)
vulnerability in dos (CVE-2026-58380). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54893 |
|
Vulnerability in CVE-2026-54893 (CVE-2026-54893)
vulnerability in CVE-2026-54893 (CVE-2026-54893). Risk of unauthorized operations or information disclosure.
|
| ECHO-472d-c4a6-c1f9 |
|
ECHO-472d-c4a6-c1f9 |
| ECHO-9424-03b0-16ec |
|
ECHO-9424-03b0-16ec |
| ECHO-e69f-bf97-7e4d |
|
ECHO-e69f-bf97-7e4d |
| ECHO-f3a8-c570-0651 |
|
ECHO-f3a8-c570-0651 |
| ECHO-e539-f67b-c9c9 |
|
ECHO-e539-f67b-c9c9 |
| ECHO-a7a1-bdcd-ae94 |
|
ECHO-a7a1-bdcd-ae94 |
| ECHO-d6cd-cd8e-da88 |
|
ECHO-d6cd-cd8e-da88 |
| ECHO-3143-27bf-6ffe |
|
ECHO-3143-27bf-6ffe |
| ECHO-e2ea-59e2-c0ed |
|
ECHO-e2ea-59e2-c0ed |
| ECHO-0491-17c2-e2eb |
|
ECHO-0491-17c2-e2eb |
| ECHO-bd12-91c3-3a49 |
|
ECHO-bd12-91c3-3a49 |
| ECHO-1c44-ab8a-99dc |
|
ECHO-1c44-ab8a-99dc |
| ECHO-f3e6-91d3-80f4 |
|
ECHO-f3e6-91d3-80f4 |
| ECHO-cc97-1e1d-fa8a |
|
ECHO-cc97-1e1d-fa8a |
| ECHO-c935-1d3a-fa71 |
|
ECHO-c935-1d3a-fa71 |
| ECHO-3d80-2b0d-3cd8 |
|
ECHO-3d80-2b0d-3cd8 |
| ECHO-51d7-a3ba-5dda |
|
ECHO-51d7-a3ba-5dda |
| ECHO-86cc-fab1-4f33 |
|
ECHO-86cc-fab1-4f33 |
| ECHO-d69c-c998-c31f |
|
ECHO-d69c-c998-c31f |
| ECHO-e0cb-315b-49ce |
|
ECHO-e0cb-315b-49ce |
| ECHO-0c8b-fbde-9864 |
|
ECHO-0c8b-fbde-9864 |