Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-49255 OS Command Injection in electerm (CVE-2026-49255)
OS command injection in electerm (CVE-2026-49255). Successful exploitation can lead to full system takeover. Exploitable via ``rmrf``. Mitigation: upgrade to `3.11.11` or later.
CVE-2026-49254 Information Disclosure in d7y.io/dragonfly/v2 (CVE-2026-49254)
vulnerability in d7y.io/dragonfly/v2 (CVE-2026-49254). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/oauth`. Mitigation: upgrade to `2.4.4` or later.
CVE-2026-49253 Path Traversal in electerm (CVE-2026-49253)
path traversal in electerm (CVE-2026-49253). Data can be tampered with by attackers. Exploitable via ``savedFilePaths``. Mitigation: upgrade to `3.11.11` or later.
CVE-2026-49250 Vulnerability in @conform-to/dom (CVE-2026-49250)
vulnerability in @conform-to/dom (CVE-2026-49250). Risk of unauthorized operations or information disclosure. Exploitable via ``parseSubmission``. Mitigation: upgrade to `1.19.4` or later.
CVE-2026-7311 Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
CVE-2026-58465 Vulnerability in c (CVE-2026-58465)
vulnerability in c (CVE-2026-58465). Risk of unauthorized operations or information disclosure.
GHSA-vv65-f55v-xm6g OS Command Injection in @grackle-ai/runtime-sdk (GHSA-vv65-f55v-xm6g)
OS command injection in @grackle-ai/runtime-sdk (GHSA-vv65-f55v-xm6g). Risk of unauthorized operations or information disclosure. Exploitable via ``git``.
MINI-4h52-hvvq-f4pq MINI-4h52-hvvq-f4pq
MINI-2hh2-x2gh-f3j2 MINI-2hh2-x2gh-f3j2
MINI-qv6q-fv83-8732 MINI-qv6q-fv83-8732
MINI-hrmp-qfwg-h782 MINI-hrmp-qfwg-h782
MINI-wf56-7pp6-3gfr MINI-wf56-7pp6-3gfr
MINI-rm77-hpxh-jw9f MINI-rm77-hpxh-jw9f
MINI-v6wh-6pjc-26fj MINI-v6wh-6pjc-26fj
MINI-r224-j68w-6m47 MINI-r224-j68w-6m47
MINI-fwrh-qwqp-f6q8 MINI-fwrh-qwqp-f6q8
MINI-cfp5-87q2-f4hp MINI-cfp5-87q2-f4hp
MINI-2vhg-rc47-c7mf MINI-2vhg-rc47-c7mf
CVE-2026-49852 Authentication Bypass in joserfc (CVE-2026-49852)
authentication bypass in joserfc (CVE-2026-49852). Risk of unauthorized operations or information disclosure. Exploitable via ``joserfc.jwt.decode``. Mitigation: upgrade to `1.6.8` or later.
MINI-g7qr-f579-xpgq MINI-g7qr-f579-xpgq
MINI-c8h3-65w4-cvm7 MINI-c8h3-65w4-cvm7
MINI-rcv8-w337-8f7h MINI-rcv8-w337-8f7h
MINI-rjqq-wvvh-wv8q MINI-rjqq-wvvh-wv8q
MINI-2qj9-4j2f-7928 MINI-2qj9-4j2f-7928
MINI-4497-2x62-4fx9 MINI-4497-2x62-4fx9
MINI-m3xq-62w8-8rf4 MINI-m3xq-62w8-8rf4
MINI-cw32-j3fw-5gjr MINI-cw32-j3fw-5gjr
CVE-2026-49245 Cross-Site Scripting (XSS) in github.com/drakkan/sftpgo/v2 (CVE-2026-49245)
cross-site scripting in github.com/drakkan/sftpgo/v2 (CVE-2026-49245). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.3` or later.
CVE-2026-49244 Path Traversal in github.com/drakkan/sftpgo/v2 (CVE-2026-49244)
path traversal in github.com/drakkan/sftpgo/v2 (CVE-2026-49244). Confidential information can be exposed externally. Mitigation: upgrade to `2.7.3` or later.
CVE-2026-50290 Cross-Site Scripting (XSS) in @asymmetric-effort/specifyjs (CVE-2026-50290)
cross-site scripting in @asymmetric-effort/specifyjs (CVE-2026-50290). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.136` or later.
GHSA-j5qp-p44g-2m49 SSRF (Server-Side Request Forgery) in @asymmetric-effort/specifyjs (GHSA-j5qp-p44g-2m49)
SSRF in @asymmetric-effort/specifyjs (GHSA-j5qp-p44g-2m49). Risk of unauthorized operations or information disclosure. Exploitable via ``assertSecureUrl``. Mitigation: upgrade to `0.2.136` or later.
GHSA-2944-57xv-2682 SSRF (Server-Side Request Forgery) in @asymmetric-effort/specifyjs (GHSA-2944-57xv-2682)
SSRF in @asymmetric-effort/specifyjs (GHSA-2944-57xv-2682). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.136` or later.
GHSA-xw57-23p8-9wc5 SSRF (Server-Side Request Forgery) in @asymmetric-effort/specifyjs (GHSA-xw57-23p8-9wc5)
SSRF in @asymmetric-effort/specifyjs (GHSA-xw57-23p8-9wc5). Risk of unauthorized operations or information disclosure. Exploitable via ``localhost``. Mitigation: upgrade to `0.2.136` or later.
GHSA-qcr8-x557-7cp3 Vulnerability in @asymmetric-effort/specifyjs (GHSA-qcr8-x557-7cp3)
vulnerability in @asymmetric-effort/specifyjs (GHSA-qcr8-x557-7cp3). Risk of unauthorized operations or information disclosure. Exploitable via ``console.warn``. Mitigation: upgrade to `0.2.140` or later.
MINI-cgwm-8wg3-6php MINI-cgwm-8wg3-6php
MINI-79j6-7cmx-2m5c MINI-79j6-7cmx-2m5c
MINI-v6jm-jvrh-rqp4 MINI-v6jm-jvrh-rqp4
MINI-cjvh-6gh8-gw7r MINI-cjvh-6gh8-gw7r
MINI-chfc-28gq-m5c4 MINI-chfc-28gq-m5c4
MINI-c8mp-fxq5-j6m2 MINI-c8mp-fxq5-j6m2
MINI-q7cx-7c9m-56pp MINI-q7cx-7c9m-56pp
MINI-mccj-2jhv-rpr2 MINI-mccj-2jhv-rpr2
MINI-r66m-pxwv-x735 MINI-r66m-pxwv-x735
MINI-6wv9-785g-w69p MINI-6wv9-785g-w69p
MINI-qffh-xq78-m6gv MINI-qffh-xq78-m6gv
MINI-8w42-4cgq-q9w7 MINI-8w42-4cgq-q9w7
GHSA-5c7w-4wm3-85vw Vulnerability in @asymmetric-effort/specifyjs (GHSA-5c7w-4wm3-85vw)
vulnerability in @asymmetric-effort/specifyjs (GHSA-5c7w-4wm3-85vw). Risk of unauthorized operations or information disclosure. Exploitable via ``gql``. Mitigation: upgrade to `0.2.136` or later.
MINI-48c8-v3h8-88pj MINI-48c8-v3h8-88pj
MINI-vrv7-r6jm-3p3h MINI-vrv7-r6jm-3p3h
MINI-q27c-83cq-x94p MINI-q27c-83cq-x94p

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →