Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| openSUSE-SU-2026:11114-1 |
|
Vulnerability in vim (openSUSE-SU-2026:11114-1)
vulnerability in vim (openSUSE-SU-2026:11114-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0530-1.1` or later.
|
| openSUSE-SU-2026:11112-1 |
|
Vulnerability in python-py7zr (openSUSE-SU-2026:11112-1)
vulnerability in python-py7zr (openSUSE-SU-2026:11112-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.3-1.1` or later.
|
| openSUSE-SU-2026:11110-1 |
|
Vulnerability in nodejs26 (openSUSE-SU-2026:11110-1)
vulnerability in nodejs26 (openSUSE-SU-2026:11110-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.3.1-1.1` or later.
|
| openSUSE-SU-2026:11106-1 |
|
Vulnerability in asn1c (openSUSE-SU-2026:11106-1)
vulnerability in asn1c (openSUSE-SU-2026:11106-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.29-1.1` or later.
|
| openSUSE-SU-2026:11104-1 |
|
Vulnerability in NetworkManager-openvpn (openSUSE-SU-2026:11104-1)
vulnerability in NetworkManager-openvpn (openSUSE-SU-2026:11104-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.12.5-1.1` or later.
|
| openSUSE-SU-2026:11109-1 |
|
Vulnerability in libssh2_org (openSUSE-SU-2026:11109-1)
vulnerability in libssh2_org (openSUSE-SU-2026:11109-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.11.1-3.1` or later.
|
| openSUSE-SU-2026:11107-1 |
|
Vulnerability in containerd (openSUSE-SU-2026:11107-1)
vulnerability in containerd (openSUSE-SU-2026:11107-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.33-1.1` or later.
|
| openSUSE-SU-2026:11105-1 |
|
Vulnerability in apache-commons-validator (openSUSE-SU-2026:11105-1)
vulnerability in apache-commons-validator (openSUSE-SU-2026:11105-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.10.1-1.1` or later.
|
| openSUSE-SU-2026:11108-1 |
|
Vulnerability in grafana (openSUSE-SU-2026:11108-1)
vulnerability in grafana (openSUSE-SU-2026:11108-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.4.4-1.1` or later.
|
| openSUSE-SU-2026:11113-1 |
|
Vulnerability in python-pypdf (openSUSE-SU-2026:11113-1)
vulnerability in python-pypdf (openSUSE-SU-2026:11113-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.14.0-1.1` or later.
|
| ALSA-2026:28074 |
|
Vulnerability in skopeo (ALSA-2026:28074)
vulnerability in skopeo (ALSA-2026:28074). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:1.22.2-6.el9_8` or later.
|
| CVE-2025-67038 KEV |
|
Lantronix EDS5000 — Lantronix EDS5000 Code Injection Vulnerability
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
|
| CVE-2026-52799 |
|
Vulnerability in gogs.io/gogs (CVE-2026-52799)
vulnerability in gogs.io/gogs (CVE-2026-52799). Confidential information can be exposed externally.
|
| CVE-2026-52798 |
|
Cross-Site Scripting (XSS) in gogs.io/gogs (CVE-2026-52798)
cross-site scripting in gogs.io/gogs (CVE-2026-52798). Confidential information can be exposed externally.
|
| CVE-2026-52796 |
|
Vulnerability in gogs.io/gogs (CVE-2026-52796)
vulnerability in gogs.io/gogs (CVE-2026-52796). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50179 |
|
Vulnerability in @actual-app/web (CVE-2026-50179)
vulnerability in @actual-app/web (CVE-2026-50179). Risk of unauthorized operations or information disclosure. Exploitable via ``exportToCSV``. Mitigation: upgrade to `26.6.0` or later.
|
| CVE-2026-54353 |
|
Vulnerability in @budibase/backend-core (CVE-2026-54353)
vulnerability in @budibase/backend-core (CVE-2026-54353). Confidential information can be exposed externally. Mitigation: upgrade to `3.39.9` or later.
|
| CVE-2026-54352 |
|
Path Traversal in @budibase/server (CVE-2026-54352)
path traversal in @budibase/server (CVE-2026-54352). Confidential information can be exposed externally. Exploitable via `POST /api/pwa/process-zip`. Mitigation: upgrade to `3.39.9` or later.
|
| CVE-2026-54351 |
|
Vulnerability in @budibase/server (CVE-2026-54351)
vulnerability in @budibase/server (CVE-2026-54351). Confidential information can be exposed externally. Exploitable via `POST /api/webhooks/trigger/`. Mitigation: upgrade to `3.39.9` or later.
|
| CVE-2026-49229 |
|
Vulnerability in @actual-app/sync-server (CVE-2026-49229)
vulnerability in @actual-app/sync-server (CVE-2026-49229). Confidential information can be exposed externally. Exploitable via `PATCH /admin/users`. Mitigation: upgrade to `26.6.0` or later.
|
| CVE-2026-50137 |
|
Vulnerability in @budibase/server (CVE-2026-50137)
vulnerability in @budibase/server (CVE-2026-50137). Confidential information can be exposed externally. Exploitable via `POST /api/attachments/`. Mitigation: upgrade to `3.39.0` or later.
|
| USN-8462-1 |
|
Vulnerability in linux-oracle-5.15 (USN-8462-1)
vulnerability in linux-oracle-5.15 (USN-8462-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.15.0-1106.112~20.04.1` or later.
|
| CVE-2026-54232 |
|
Vulnerability in vllm (CVE-2026-54232)
vulnerability in vllm (CVE-2026-54232). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.22.1` or later.
|
| CVE-2026-50136 |
|
Vulnerability in @budibase/server (CVE-2026-50136)
vulnerability in @budibase/server (CVE-2026-50136). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/attachments/`. Mitigation: upgrade to `3.39.2` or later.
|
| CVE-2026-50132 |
|
Vulnerability in @budibase/server (CVE-2026-50132)
vulnerability in @budibase/server (CVE-2026-50132). Confidential information can be exposed externally. Exploitable via `GET /api/chat-links/`. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-48487 |
|
Vulnerability in zeroconf (CVE-2026-48487)
vulnerability in zeroconf (CVE-2026-48487). Risk of unauthorized operations or information disclosure. Exploitable via ``_read_character_string``. Mitigation: upgrade to `0.149.16` or later.
|
| USN-8388-2 |
|
Vulnerability in linux-intel-iotg-5.15 (USN-8388-2)
vulnerability in linux-intel-iotg-5.15 (USN-8388-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.15.0-1104.110~20.04.1` or later.
|
| GHSA-hvqh-jw65-wcpq |
|
Cross-Site Scripting (XSS) in devbridge-autocomplete (GHSA-hvqh-jw65-wcpq)
cross-site scripting in devbridge-autocomplete (GHSA-hvqh-jw65-wcpq). Risk of unauthorized operations or information disclosure. Exploitable via ``formatGroup``. Mitigation: upgrade to `2.0.1` or later.
|
| CVE-2026-48170 |
|
Vulnerability in scim-patch (CVE-2026-48170)
vulnerability in scim-patch (CVE-2026-48170). Data can be tampered with by attackers. Exploitable via `PATCH /Users/`. Mitigation: upgrade to `0.9.1` or later.
|
| GHSA-ghmh-jhmj-wcmf |
|
Vulnerability in github.com/juev/nebula-mesh (GHSA-ghmh-jhmj-wcmf)
vulnerability in github.com/juev/nebula-mesh (GHSA-ghmh-jhmj-wcmf). Risk of unauthorized operations or information disclosure. Exploitable via ``enrollment_tokens.token``. Mitigation: upgrade to `0.3.2` or later.
|
| USN-8461-1 |
|
Vulnerability in linux-azure (USN-8461-1)
vulnerability in linux-azure (USN-8461-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.0-1007.7` or later.
|
| GHSA-74p7-6h78-gw8p |
|
Path Traversal in skillctl (GHSA-74p7-6h78-gw8p)
path traversal in skillctl (GHSA-74p7-6h78-gw8p). Risk of unauthorized operations or information disclosure. Exploitable via ``source_sha``. Mitigation: upgrade to `0.1.3` or later.
|
| CVE-2026-47267 |
|
SSRF (Server-Side Request Forgery) in gogs.io/gogs (CVE-2026-47267)
SSRF in gogs.io/gogs (CVE-2026-47267). Risk of unauthorized operations or information disclosure.
|
| MINI-p8qm-xq4c-3rjm |
|
MINI-p8qm-xq4c-3rjm |
| MINI-mm5q-35p7-2vh7 |
|
MINI-mm5q-35p7-2vh7 |
| MINI-g89x-hxpf-6vph |
|
MINI-g89x-hxpf-6vph |
| MINI-x4wf-p79w-phx9 |
|
MINI-x4wf-p79w-phx9 |
| MINI-mhrh-j5cf-mf86 |
|
MINI-mhrh-j5cf-mf86 |
| MINI-p47w-qr3j-q76f |
|
MINI-p47w-qr3j-q76f |
| MINI-jvrx-fcwp-p2hx |
|
MINI-jvrx-fcwp-p2hx |
| MINI-hjw5-2j77-9grp |
|
MINI-hjw5-2j77-9grp |
| MINI-6cpq-qhq3-cr26 |
|
MINI-6cpq-qhq3-cr26 |
| MINI-2fcw-j62j-3v66 |
|
MINI-2fcw-j62j-3v66 |
| MINI-94jp-86qr-555m |
|
MINI-94jp-86qr-555m |
| MINI-2x22-577h-c7g4 |
|
MINI-2x22-577h-c7g4 |
| MINI-27f6-pp6f-9jwj |
|
MINI-27f6-pp6f-9jwj |
| MINI-v945-2ffp-r95v |
|
MINI-v945-2ffp-r95v |
| MINI-23mc-26m6-qjhx |
|
MINI-23mc-26m6-qjhx |
| MINI-wrmm-84vh-w5rh |
|
MINI-wrmm-84vh-w5rh |
| MINI-vwc5-r4jm-grp9 |
|
MINI-vwc5-r4jm-grp9 |