Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-20275 |
|
SQL Injection in sqli (CVE-2017-20275)
SQL injection in sqli (CVE-2017-20275). Confidential information can be exposed externally.
|
| CVE-2017-20274 |
|
SQL Injection in sqli (CVE-2017-20274)
SQL injection in sqli (CVE-2017-20274). Confidential information can be exposed externally.
|
| CVE-2017-20268 |
|
SQL Injection in sqli (CVE-2017-20268)
SQL injection in sqli (CVE-2017-20268). Confidential information can be exposed externally.
|
| CVE-2017-20271 |
|
SQL Injection in sqli (CVE-2017-20271)
SQL injection in sqli (CVE-2017-20271). Confidential information can be exposed externally.
|
| CVE-2017-20270 |
|
SQL Injection in sqli (CVE-2017-20270)
SQL injection in sqli (CVE-2017-20270). Confidential information can be exposed externally.
|
| CVE-2017-20282 |
|
SQL Injection in sqli (CVE-2017-20282)
SQL injection in sqli (CVE-2017-20282). Confidential information can be exposed externally.
|
| CVE-2017-20281 |
|
SQL Injection in sqli (CVE-2017-20281)
SQL injection in sqli (CVE-2017-20281). Confidential information can be exposed externally.
|
| CVE-2017-20267 |
|
SQL Injection in sqli (CVE-2017-20267)
SQL injection in sqli (CVE-2017-20267). Confidential information can be exposed externally.
|
| CVE-2017-20261 |
|
SQL Injection in sqli (CVE-2017-20261)
SQL injection in sqli (CVE-2017-20261). Confidential information can be exposed externally.
|
| CVE-2017-20263 |
|
SQL Injection in sqli (CVE-2017-20263)
SQL injection in sqli (CVE-2017-20263). Confidential information can be exposed externally.
|
| CVE-2026-12622 |
|
Open Redirect in microchip (CVE-2026-12622)
vulnerability in microchip (CVE-2026-12622). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-20259 |
|
SQL Injection in sqli (CVE-2017-20259)
SQL injection in sqli (CVE-2017-20259). Confidential information can be exposed externally.
|
| CVE-2017-20262 |
|
SQL Injection in sqli (CVE-2017-20262)
SQL injection in sqli (CVE-2017-20262). Confidential information can be exposed externally.
|
| CVE-2026-12620 |
|
Information Disclosure in microchip (CVE-2026-12620)
vulnerability in microchip (CVE-2026-12620). Confidential information can be exposed externally.
|
| CVE-2017-20257 |
|
SQL Injection in sqli (CVE-2017-20257)
SQL injection in sqli (CVE-2017-20257). Confidential information can be exposed externally.
|
| CVE-2026-12621 |
|
Cross-Site Scripting (XSS) in microchip (CVE-2026-12621)
cross-site scripting in microchip (CVE-2026-12621). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12619 |
|
Cross-Site Scripting (XSS) in microchip (CVE-2026-12619)
cross-site scripting in microchip (CVE-2026-12619). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-20265 |
|
SQL Injection in sqli (CVE-2017-20265)
SQL injection in sqli (CVE-2017-20265). Confidential information can be exposed externally.
|
| CVE-2017-20266 |
|
SQL Injection in sqli (CVE-2017-20266)
SQL injection in sqli (CVE-2017-20266). Confidential information can be exposed externally.
|
| CVE-2017-20264 |
|
SQL Injection in sqli (CVE-2017-20264)
SQL injection in sqli (CVE-2017-20264). Confidential information can be exposed externally.
|
| CVE-2017-20260 |
|
SQL Injection in sqli (CVE-2017-20260)
SQL injection in sqli (CVE-2017-20260). Confidential information can be exposed externally.
|
| CVE-2017-20256 |
|
SQL Injection in sqli (CVE-2017-20256)
SQL injection in sqli (CVE-2017-20256). Confidential information can be exposed externally.
|
| CVE-2017-20253 |
|
SQL Injection in sqli (CVE-2017-20253)
SQL injection in sqli (CVE-2017-20253). Confidential information can be exposed externally.
|
| CVE-2017-20252 |
|
SQL Injection in sqli (CVE-2017-20252)
SQL injection in sqli (CVE-2017-20252). Confidential information can be exposed externally.
|
| CVE-2017-20255 |
|
SQL Injection in sqli (CVE-2017-20255)
SQL injection in sqli (CVE-2017-20255). Confidential information can be exposed externally.
|
| CVE-2017-20254 |
|
SQL Injection in sqli (CVE-2017-20254)
SQL injection in sqli (CVE-2017-20254). Confidential information can be exposed externally.
|
| CVE-2017-20258 |
|
SQL Injection in sqli (CVE-2017-20258)
SQL injection in sqli (CVE-2017-20258). Confidential information can be exposed externally.
|
| CVE-2026-49359 |
|
SSRF (Server-Side Request Forgery) in pontedilana/php-weasyprint (CVE-2026-49359)
SSRF in pontedilana/php-weasyprint (CVE-2026-49359). Confidential information can be exposed externally. Exploitable via ``attachment``. Mitigation: upgrade to `2.6.0` or later.
|
| CVE-2026-49290 |
|
Path Traversal in CVE-2026-49290 (CVE-2026-49290)
path traversal in CVE-2026-49290 (CVE-2026-49290). Risk of unauthorized operations or information disclosure. Exploitable via ``zipfile``.
|
| CVE-2026-49287 |
|
Vulnerability in statamic/cms (CVE-2026-49287)
vulnerability in statamic/cms (CVE-2026-49287). Data can be tampered with by attackers. Mitigation: upgrade to `5.73.23` or later.
|
| CVE-2026-49286 |
|
Unsafe Deserialization in pontedilana/php-weasyprint (CVE-2026-49286)
vulnerability in pontedilana/php-weasyprint (CVE-2026-49286). Successful exploitation can lead to full system takeover. Exploitable via ``eb8accc``. Mitigation: upgrade to `2.6.0` or later.
|
| CVE-2026-49271 |
|
Out-of-Bounds Read in struktur (CVE-2026-49271)
vulnerability in struktur (CVE-2026-49271). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-49271 |
|
Vulnerability in libheif (UBUNTU-CVE-2026-49271)
vulnerability in libheif (UBUNTU-CVE-2026-49271). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.21.2-3ubuntu0.2` or later.
|
| GHSA-mqq5-j7w8-2hgh |
|
Vulnerability in alchemy_cms (GHSA-mqq5-j7w8-2hgh)
vulnerability in alchemy_cms (GHSA-mqq5-j7w8-2hgh). Confidential information can be exposed externally. Exploitable via `GET /api/pages/nested`. Mitigation: upgrade to `7.4.15` or later.
|
| GHSA-c3wq-j5vh-68rc |
|
Vulnerability in github.com/gohugoio/hugo (GHSA-c3wq-j5vh-68rc)
vulnerability in github.com/gohugoio/hugo (GHSA-c3wq-j5vh-68rc). Risk of unauthorized operations or information disclosure. Exploitable via ``resources.Get``. Mitigation: upgrade to `0.163.1` or later.
|
| GHSA-q76j-gcg9-vxc6 |
|
Cross-Site Scripting (XSS) in github.com/gohugoio/hugo (GHSA-q76j-gcg9-vxc6)
cross-site scripting in github.com/gohugoio/hugo (GHSA-q76j-gcg9-vxc6). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.163.3` or later.
|
| GHSA-9wxg-vf3r-56hc |
|
Vulnerability in @openzeppelin/wizard (GHSA-9wxg-vf3r-56hc)
vulnerability in @openzeppelin/wizard (GHSA-9wxg-vf3r-56hc). Risk of unauthorized operations or information disclosure. Exploitable via ``info.securityContact``. Mitigation: upgrade to `0.10.11` or later.
|
| GHSA-7qpf-5pm7-57rh |
|
Vulnerability in free-claude (GHSA-7qpf-5pm7-57rh)
vulnerability in free-claude (GHSA-7qpf-5pm7-57rh). Risk of unauthorized operations or information disclosure. Exploitable via ``npx``.
|
| CVE-2026-49260 |
|
OS Command Injection in pontedilana/php-weasyprint (CVE-2026-49260)
OS command injection in pontedilana/php-weasyprint (CVE-2026-49260). Successful exploitation can lead to full system takeover. Exploitable via ``master``. Mitigation: upgrade to `2.5.1` or later.
|
| UBUNTU-CVE-2026-56208 |
|
Vulnerability in aom (UBUNTU-CVE-2026-56208)
vulnerability in aom (UBUNTU-CVE-2026-56208). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-56210 |
|
Vulnerability in aom (UBUNTU-CVE-2026-56210)
vulnerability in aom (UBUNTU-CVE-2026-56210). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-56211 |
|
Vulnerability in aom (UBUNTU-CVE-2026-56211)
vulnerability in aom (UBUNTU-CVE-2026-56211). Data can be tampered with by attackers.
|
| UBUNTU-CVE-2026-56209 |
|
Vulnerability in aom (UBUNTU-CVE-2026-56209)
vulnerability in aom (UBUNTU-CVE-2026-56209). Risk of unauthorized operations or information disclosure.
|
| openSUSE-SU-2026:21111-1 |
|
Vulnerability in himmelblau (openSUSE-SU-2026:21111-1)
vulnerability in himmelblau (openSUSE-SU-2026:21111-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.11+git1.116c6763-160000.1.1` or later.
|
| openSUSE-SU-2026:21109-1 |
|
Vulnerability in dovecot24 (openSUSE-SU-2026:21109-1)
vulnerability in dovecot24 (openSUSE-SU-2026:21109-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.4-160000.1.1` or later.
|
| SUSE-SU-2026:22185-1 |
|
Vulnerability in dovecot24 (SUSE-SU-2026:22185-1)
vulnerability in dovecot24 (SUSE-SU-2026:22185-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.4-160000.1.1` or later.
|
| openSUSE-SU-2026:21104-1 |
|
Vulnerability in postgresql16 (openSUSE-SU-2026:21104-1)
vulnerability in postgresql16 (openSUSE-SU-2026:21104-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.14-160000.1.1` or later.
|
| SUSE-SU-2026:22186-1 |
|
Vulnerability in himmelblau (SUSE-SU-2026:22186-1)
vulnerability in himmelblau (SUSE-SU-2026:22186-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.11+git1.116c6763-160000.1.1` or later.
|
| openSUSE-SU-2026:21103-1 |
|
Vulnerability in postgresql15 (openSUSE-SU-2026:21103-1)
vulnerability in postgresql15 (openSUSE-SU-2026:21103-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `15.18-160000.1.1` or later.
|
| SUSE-SU-2026:22184-1 |
|
Vulnerability in postgresql16 (SUSE-SU-2026:22184-1)
vulnerability in postgresql16 (SUSE-SU-2026:22184-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.14-160000.1.1` or later.
|