Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| SUSE-SU-2026:22166-1 |
|
Vulnerability in sqlite3 (SUSE-SU-2026:22166-1)
vulnerability in sqlite3 (SUSE-SU-2026:22166-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.53.2-160000.1.1` or later.
|
| SUSE-SU-2026:22165-1 |
|
Vulnerability in libinput (SUSE-SU-2026:22165-1)
vulnerability in libinput (SUSE-SU-2026:22165-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.1-160000.3.1` or later.
|
| openSUSE-SU-2026:21091-1 |
|
Vulnerability in libinput (openSUSE-SU-2026:21091-1)
vulnerability in libinput (openSUSE-SU-2026:21091-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.1-160000.3.1` or later.
|
| GHSA-g7m4-839x-ch6v |
|
Vulnerability in spomky-labs/otphp (GHSA-g7m4-839x-ch6v)
vulnerability in spomky-labs/otphp (GHSA-g7m4-839x-ch6v). Risk of unauthorized operations or information disclosure. Exploitable via ``digits``. Mitigation: upgrade to `11.4.3` or later.
|
| CVE-2026-0755 |
|
OS Command Injection in gemini-mcp-tool (CVE-2026-0755)
OS command injection in gemini-mcp-tool (CVE-2026-0755). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.1.6` or later.
|
| CGA-259c-cxf7-78x7 |
|
CGA-259c-cxf7-78x7 |
| ECHO-d378-1b5a-f13e |
|
ECHO-d378-1b5a-f13e |
| CVE-2026-48983 |
|
Vulnerability in CVE-2026-48983 (CVE-2026-48983)
vulnerability in CVE-2026-48983 (CVE-2026-48983). Confidential information can be exposed externally.
|
| CVE-2026-48982 |
|
Vulnerability in CVE-2026-48982 (CVE-2026-48982)
vulnerability in CVE-2026-48982 (CVE-2026-48982). Data can be tampered with by attackers.
|
| CVE-2026-48981 |
|
XXE (XML External Entity) in CVE-2026-48981 (CVE-2026-48981)
vulnerability in CVE-2026-48981 (CVE-2026-48981). Confidential information can be exposed externally.
|
| CVE-2026-48980 |
|
Vulnerability in CVE-2026-48980 (CVE-2026-48980)
vulnerability in CVE-2026-48980 (CVE-2026-48980). Confidential information can be exposed externally.
|
| CVE-2026-48716 |
|
Path Traversal in CVE-2026-48716 (CVE-2026-48716)
path traversal in CVE-2026-48716 (CVE-2026-48716). Data can be tampered with by attackers.
|
| CVE-2026-47847 |
|
Vulnerability in mariadb-galera (CVE-2026-47847)
vulnerability in mariadb-galera (CVE-2026-47847). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.6.27-0, 10.11.17-0, 11.4.12-0, 11.8.7-0, 12.3.2-0` or later.
|
| CVE-2026-47846 |
|
Vulnerability in cassandra (CVE-2026-47846)
vulnerability in cassandra (CVE-2026-47846). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.20-0, 4.1.11-0, 5.0.8-0` or later.
|
| CVE-2026-43915 |
|
Cross-Site Scripting (XSS) in coturn-project (CVE-2026-43915)
cross-site scripting in coturn-project (CVE-2026-43915). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2842 |
|
Vulnerability in CVE-2026-2842 (CVE-2026-2842)
vulnerability in CVE-2026-2842 (CVE-2026-2842). Risk of unauthorized operations or information disclosure.
|
| UBUNTU-CVE-2026-43915 |
|
Vulnerability in coturn (UBUNTU-CVE-2026-43915)
vulnerability in coturn (UBUNTU-CVE-2026-43915). Risk of unauthorized operations or information disclosure.
|
| USN-8447-2 |
|
Vulnerability in lxd (USN-8447-2)
vulnerability in lxd (USN-8447-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.11-0ubuntu1~16.04.4+esm3` or later.
|
| CGA-p7mq-ppw3-r7pc |
|
CGA-p7mq-ppw3-r7pc |
| CGA-j7f4-54g6-8864 |
|
CGA-j7f4-54g6-8864 |
| CGA-gg5c-q35p-45j3 |
|
CGA-gg5c-q35p-45j3 |
| CGA-w8r8-7w2x-94pq |
|
CGA-w8r8-7w2x-94pq |
| CGA-6rwr-g7gw-76w8 |
|
CGA-6rwr-g7gw-76w8 |
| UBUNTU-CVE-2026-55392 |
|
Vulnerability in nilfs-tools (UBUNTU-CVE-2026-55392)
vulnerability in nilfs-tools (UBUNTU-CVE-2026-55392). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6140 |
|
Vulnerability in @httpactions/strict-uri-encode (MAL-2026-6140)
vulnerability in @httpactions/strict-uri-encode (MAL-2026-6140). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6139 |
|
Vulnerability in @httpactions/encode-url (MAL-2026-6139)
vulnerability in @httpactions/encode-url (MAL-2026-6139). Risk of unauthorized operations or information disclosure.
|
| SUSE-SU-2026:22163-1 |
|
Vulnerability in freeipmi (SUSE-SU-2026:22163-1)
vulnerability in freeipmi (SUSE-SU-2026:22163-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.15-160000.4.1` or later.
|
| openSUSE-SU-2026:21088-1 |
|
Vulnerability in freeipmi (openSUSE-SU-2026:21088-1)
vulnerability in freeipmi (openSUSE-SU-2026:21088-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.15-160000.4.1` or later.
|
| SUSE-SU-2026:22216-1 |
|
Vulnerability in freeipmi (SUSE-SU-2026:22216-1)
vulnerability in freeipmi (SUSE-SU-2026:22216-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.15-160000.4.1` or later.
|
| CVE-2026-54390 |
|
Vulnerability in CVE-2026-54390 (CVE-2026-54390)
vulnerability in CVE-2026-54390 (CVE-2026-54390). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56021 |
|
Vulnerability in webmin (CVE-2026-56021)
vulnerability in webmin (CVE-2026-56021). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56022 |
|
Vulnerability in webmin (CVE-2026-56022)
vulnerability in webmin (CVE-2026-56022). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.641` or later.
|
| CVE-2026-55205 |
|
Vulnerability in CVE-2026-55205 (CVE-2026-55205)
vulnerability in CVE-2026-55205 (CVE-2026-55205). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/onboarding/oauth/start`.
|
| CVE-2026-38718 |
|
Vulnerability in dos (CVE-2026-38718)
vulnerability in dos (CVE-2026-38718). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56024 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-56024)
vulnerability in csrf (CVE-2026-56024). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55203 |
|
Vulnerability in haproxy (CVE-2026-55203)
vulnerability in haproxy (CVE-2026-55203). Data can be tampered with by attackers. Mitigation: upgrade to `3.4.1` or later.
|
| CVE-2026-54106 |
|
Vulnerability in CVE-2026-54106 (CVE-2026-54106)
vulnerability in CVE-2026-54106 (CVE-2026-54106). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54104 |
|
Vulnerability in CVE-2026-54104 (CVE-2026-54104)
vulnerability in CVE-2026-54104 (CVE-2026-54104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55204 |
|
Vulnerability in haproxy (CVE-2026-55204)
vulnerability in haproxy (CVE-2026-55204). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.4.1` or later.
|
| CVE-2026-56020 |
|
Vulnerability in CVE-2026-56020 (CVE-2026-56020)
vulnerability in CVE-2026-56020 (CVE-2026-56020). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.641` or later.
|
| CVE-2026-54105 |
|
Vulnerability in CVE-2026-54105 (CVE-2026-54105)
vulnerability in CVE-2026-54105 (CVE-2026-54105). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48617 |
|
Vulnerability in nodejs (CVE-2026-48617)
vulnerability in nodejs (CVE-2026-48617). Confidential information can be exposed externally.
|
| CVE-2026-54103 |
|
Vulnerability in CVE-2026-54103 (CVE-2026-54103)
vulnerability in CVE-2026-54103 (CVE-2026-54103). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38717 |
|
Command Injection in inhandnetworks (CVE-2026-38717)
command injection in inhandnetworks (CVE-2026-38717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38715 |
|
Command Injection in inhandnetworks (CVE-2026-38715)
command injection in inhandnetworks (CVE-2026-38715). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10687 |
|
Vulnerability in CVE-2026-10687 (CVE-2026-10687)
vulnerability in CVE-2026-10687 (CVE-2026-10687). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11982 |
|
Cross-Site Scripting (XSS) in CVE-2026-11982 (CVE-2026-11982)
cross-site scripting in CVE-2026-11982 (CVE-2026-11982). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38716 |
|
Command Injection in inhandnetworks (CVE-2026-38716)
command injection in inhandnetworks (CVE-2026-38716). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38714 |
|
Command Injection in inhandnetworks (CVE-2026-38714)
command injection in inhandnetworks (CVE-2026-38714). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48986 |
|
Vulnerability in dos (CVE-2026-48986)
vulnerability in dos (CVE-2026-48986). Risk of unauthorized operations or information disclosure.
|