Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44736 |
|
Information Disclosure in CVE-2026-44736 (CVE-2026-44736)
vulnerability in CVE-2026-44736 (CVE-2026-44736). Confidential information can be exposed externally. Exploitable via `GET /api/v3/relations`. Mitigation: upgrade to `17.4.0` or later.
|
| CVE-2026-44735 |
|
Authorization Flaw in CVE-2026-44735 (CVE-2026-44735)
vulnerability in CVE-2026-44735 (CVE-2026-44735). Confidential information can be exposed externally. Exploitable via `GET /api/v3/shares`. Mitigation: upgrade to `17.3.2` or later.
|
| CVE-2026-44734 |
|
Vulnerability in CVE-2026-44734 (CVE-2026-44734)
vulnerability in CVE-2026-44734 (CVE-2026-44734). Data can be tampered with by attackers. Mitigation: upgrade to `17.3.2` or later.
|
| CVE-2026-44733 |
|
Vulnerability in CVE-2026-44733 (CVE-2026-44733)
vulnerability in CVE-2026-44733 (CVE-2026-44733). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.2` or later.
|
| CVE-2026-44732 |
|
Vulnerability in CVE-2026-44732 (CVE-2026-44732)
vulnerability in CVE-2026-44732 (CVE-2026-44732). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `17.3.2` or later.
|
| CVE-2026-44731 |
|
Vulnerability in CVE-2026-44731 (CVE-2026-44731)
vulnerability in CVE-2026-44731 (CVE-2026-44731). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `17.3.2` or later.
|
| CVE-2026-44696 |
|
Cross-Site Scripting (XSS) in CVE-2026-44696 (CVE-2026-44696)
cross-site scripting in CVE-2026-44696 (CVE-2026-44696). Data can be tampered with by attackers. Mitigation: upgrade to `17.4.0` or later.
|
| UBUNTU-CVE-2026-29509 |
|
Vulnerability in patool (UBUNTU-CVE-2026-29509)
vulnerability in patool (UBUNTU-CVE-2026-29509). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6537 |
|
Vulnerability in gptmini (MAL-2026-6537)
vulnerability in gptmini (MAL-2026-6537). Risk of unauthorized operations or information disclosure. Exploitable via ``gptmini``.
|
| GHSA-qh5x-rfwf-rvfv |
|
Vulnerability in github.com/apernet/hysteria (GHSA-qh5x-rfwf-rvfv)
vulnerability in github.com/apernet/hysteria (GHSA-qh5x-rfwf-rvfv). Risk of unauthorized operations or information disclosure. Exploitable via ``max_datagram_frame_size``. Mitigation: upgrade to `2.9.2` or later.
|
| GHSA-vgrc-hq28-p3xp |
|
Vulnerability in github.com/apernet/hysteria/core/v2 (GHSA-vgrc-hq28-p3xp)
vulnerability in github.com/apernet/hysteria/core/v2 (GHSA-vgrc-hq28-p3xp). Risk of unauthorized operations or information disclosure. Exploitable via ``UDPMessage``. Mitigation: upgrade to `2.9.2` or later.
|
| GHSA-5vwr-qchf-q4pf |
|
OS Command Injection in @cyclonedx/cdxgen (GHSA-5vwr-qchf-q4pf)
OS command injection in @cyclonedx/cdxgen (GHSA-5vwr-qchf-q4pf). Risk of unauthorized operations or information disclosure. Exploitable via `POST /sbom`. Mitigation: upgrade to `12.4.3` or later.
|
| MINI-gxj8-qv8r-h4xv |
|
MINI-gxj8-qv8r-h4xv |
| MINI-67h6-gpvm-pq64 |
|
MINI-67h6-gpvm-pq64 |
| MINI-xqq5-v2v4-9jf6 |
|
MINI-xqq5-v2v4-9jf6 |
| MINI-vw44-gv9g-26gr |
|
MINI-vw44-gv9g-26gr |
| MINI-q6v8-8p88-92vv |
|
MINI-q6v8-8p88-92vv |
| MINI-p53p-wjwc-xpr3 |
|
MINI-p53p-wjwc-xpr3 |
| MINI-g267-3v3j-qpmr |
|
MINI-g267-3v3j-qpmr |
| MINI-555h-cxrg-4cxr |
|
MINI-555h-cxrg-4cxr |
| MINI-3rhr-43m2-qqg3 |
|
MINI-3rhr-43m2-qqg3 |
| MINI-vx24-9595-qwjm |
|
MINI-vx24-9595-qwjm |
| MINI-w9c8-ww72-hfmw |
|
MINI-w9c8-ww72-hfmw |
| MINI-rqph-6rfq-rjgw |
|
MINI-rqph-6rfq-rjgw |
| MINI-cmcf-hjv7-q5xg |
|
MINI-cmcf-hjv7-q5xg |
| MINI-72xq-5jc4-xgg7 |
|
MINI-72xq-5jc4-xgg7 |
| MINI-69wr-3rvq-xqm6 |
|
MINI-69wr-3rvq-xqm6 |
| MINI-2vjj-rrmx-4v4x |
|
MINI-2vjj-rrmx-4v4x |
| MINI-q3vx-9p54-mvh5 |
|
MINI-q3vx-9p54-mvh5 |
| MINI-275j-p7hj-632x |
|
MINI-275j-p7hj-632x |
| MINI-3mhh-h84c-ghpx |
|
MINI-3mhh-h84c-ghpx |
| MINI-h2f8-jmhh-q69q |
|
MINI-h2f8-jmhh-q69q |
| MINI-5fx3-55wr-fff8 |
|
MINI-5fx3-55wr-fff8 |
| MINI-vwvf-8jrj-c529 |
|
MINI-vwvf-8jrj-c529 |
| MINI-jxf9-683h-vvg5 |
|
MINI-jxf9-683h-vvg5 |
| CGA-q9xw-7g2w-p466 |
|
CGA-q9xw-7g2w-p466 |
| CGA-7m3j-g4c5-pwfw |
|
CGA-7m3j-g4c5-pwfw |
| CGA-chrf-95pv-24f7 |
|
CGA-chrf-95pv-24f7 |
| CGA-vr3r-727c-cxpc |
|
CGA-vr3r-727c-cxpc |
| CVE-2026-48785 |
|
Path Traversal in github.com/apptainer/apptainer (CVE-2026-48785)
path traversal in github.com/apptainer/apptainer (CVE-2026-48785). Risk of unauthorized operations or information disclosure. Exploitable via ``apptainer.conf``. Mitigation: upgrade to `1.5.1` or later.
|
| CVE-2026-54753 |
|
Vulnerability in nx (CVE-2026-54753)
vulnerability in nx (CVE-2026-54753). Confidential information can be exposed externally. Exploitable via `GET /help`. Mitigation: upgrade to `23.0.0-beta.2` or later.
|
| CVE-2026-48090 |
|
Use-After-Free in dos (CVE-2026-48090)
vulnerability in dos (CVE-2026-48090). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.37.5` or later.
|
| CVE-2026-47220 |
|
Vulnerability in envoyproxy (CVE-2026-47220)
vulnerability in envoyproxy (CVE-2026-47220). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `1.37.5` or later.
|
| CVE-2026-47205 |
|
Use-After-Free in envoyproxy (CVE-2026-47205)
vulnerability in envoyproxy (CVE-2026-47205). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.36.9` or later.
|
| CVE-2026-48769 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48769)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48769). Successful exploitation can lead to full system takeover. Exploitable via `POST /1.0/images`. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48758 |
|
Vulnerability in @sigstore/core (CVE-2026-48758)
vulnerability in @sigstore/core (CVE-2026-48758). Risk of unauthorized operations or information disclosure. Exploitable via ``preAuthEncoding``. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-48756 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48756)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48756). Risk of unauthorized operations or information disclosure. Exploitable via `POST /1.0/storage-pools/`. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-48755 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48755)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48755). Successful exploitation can lead to full system takeover. Exploitable via ``compression_algorithm``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48754 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48754)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48754). Risk of unauthorized operations or information disclosure. Exploitable via `POST /1.0/instances`. Mitigation: upgrade to `7.1.0` or later.
|
| CGA-mm7w-cgmv-857p |
|
CGA-mm7w-cgmv-857p |