Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    SUSE-SU-2026:3995-1
    Fix available
    Packages

    wireshark, wireshark

    Summary

    Security update for wireshark

    Published
    7 Sept 2026
    SUSE-SU-2026:3994-1
    Fix available
    Packages

    wireshark, wireshark

    Summary

    Security update for wireshark

    Published
    7 Sept 2026
    SUSE-SU-2026:3993-1
    Fix available
    Packages

    emacs, emacs

    Summary

    Security update for emacs

    Published
    7 Sept 2026
    SUSE-SU-2026:3992-1
    Fix available
    Packages

    aws-nitro-enclaves-cli, aws-nitro-enclaves-cli

    Summary

    Security update for aws-nitro-enclaves-cli

    Published
    7 Sept 2026
    SUSE-SU-2026:3991-1
    Fix available
    Packages

    redis7, redis7

    Summary

    Security update for redis7

    Published
    7 Sept 2026
    SUSE-SU-2026:3990-1
    Fix available
    Packages

    redis, redis

    Summary

    Security update for redis

    Published
    7 Sept 2026
    Packages

    go.etcd.io/etcd/server/v3, rootio-go.etcd.io/etcd/server/v3

    Summary

    CVE-2026-73499 in go.etcd.io/etcd/server/v3 - Patched by Root

    Published
    7 Sept 2026
    Packages

    org.apache.httpcomponents.core5:httpcore5, org.apache.httpcomponents.core5:httpcore5-h2, org.apache.httpcomponents.core5:httpcore5-parent, org.apache.httpcomponents.core5:httpcore5-reactive, org.apache.httpcomponents.core5:httpcore5-testing

    Summary

    TuxCare security update for org.apache.httpcomponents.core5 (2 CVEs)

    Published
    7 Sept 2026
    Packages

    org.bouncycastle:bcjmail-jdk15to18, org.bouncycastle:bcjmail-jdk18on, org.bouncycastle:bcmail-jdk15to18, org.bouncycastle:bcmail-jdk18on, org.bouncycastle:bcpg-jdk15to18, org.bouncycastle:bcpg-jdk18on, org.bouncycastle:bcpkix-jdk15to18, org.bouncycastle:bcpkix-jdk18on, org.bouncycastle:bcprov-ext-jdk15to18, org.bouncycastle:bcprov-ext-jdk18on, org.bouncycastle:bcprov-jdk15to18, org.bouncycastle:bcprov-jdk18on, org.bouncycastle:bctls-jdk15to18, org.bouncycastle:bctls-jdk18on, org.bouncycastle:bcutil-jdk15to18, org.bouncycastle:bcutil-jdk18on

    Summary

    TuxCare security update for org.bouncycastle (4 CVEs)

    Published
    7 Sept 2026
    CGA-283c-xmq7-xm8f
    Fix available
    Packages

    openstack-tempest-2025.1

    Summary

    Published
    7 Sept 2026
    CGA-vg38-f894-93wg
    Fix available
    Packages

    openstack-tempest-2025.1

    Summary

    Published
    7 Sept 2026
    Packages

    node-min

    Summary

    Published
    7 Sept 2026
    BIT-node-2026-48932
    Fix available
    Packages

    node

    Summary

    Published
    7 Sept 2026
    Packages

    kibana

    Summary

    Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitoring

    Published
    7 Sept 2026
    BIT-elk-2026-72633
    Fix available
    Packages

    elk

    Summary

    Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitoring

    Published
    7 Sept 2026
    Packages

    elasticsearch

    Summary

    Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service

    Published
    7 Sept 2026
    Packages

    composer

    Summary

    Composer: Perforce source URL permits P4PORT `rsh:` command execution

    Published
    7 Sept 2026
    CGA-fh9w-v38f-c87v
    Fix available
    Packages

    openstack-tempest-2025.1

    Summary

    Published
    7 Sept 2026
    CGA-hxgx-2q7x-mg6m
    Fix available
    Packages

    openstack-tempest-2025.1

    Summary

    Published
    7 Sept 2026
    CVE-2026-86274
    No fix available
    Packages

    Summary

    projeto-siga Authentication Flow ExAutenticacaoController.java ExAutenticacaoController.autenticar authorization

    Published
    7 Sept 2026
    Packages

    org.apache.commons:commons-configuration2

    Summary

    TuxCare security update for org.apache.commons:commons-configuration2 (1 CVE)

    Published
    7 Sept 2026
    Packages

    org.apache.commons:commons-lang3

    Summary

    TuxCare security update for org.apache.commons:commons-lang3 (1 CVE)

    Published
    7 Sept 2026
    Packages

    commons-beanutils:commons-beanutils

    Summary

    TuxCare security update for commons-beanutils:commons-beanutils (1 CVE)

    Published
    7 Sept 2026
    Packages

    io.airlift:aircompressor

    Summary

    TuxCare security update for io.airlift:aircompressor (1 CVE)

    Published
    7 Sept 2026
    Packages

    io.airlift:aircompressor

    Summary

    TuxCare security update for io.airlift:aircompressor (1 CVE)

    Published
    7 Sept 2026
    Packages

    io.airlift:aircompressor

    Summary

    TuxCare security update for io.airlift:aircompressor (1 CVE)

    Published
    7 Sept 2026
    Packages

    commons-beanutils:commons-beanutils

    Summary

    TuxCare security update for commons-beanutils:commons-beanutils (1 CVE)

    Published
    7 Sept 2026
    Packages

    apache-zookeeper

    Summary

    In Eclipse Jetty, the HTTP/1

    Published
    7 Sept 2026
    Packages

    commons-io:commons-io

    Summary

    TuxCare security update for commons-io:commons-io (1 CVE)

    Published
    7 Sept 2026
    CVE-2026-86273
    No fix available
    Packages

    Summary

    projeto-siga HTML-to-PDF Endpoint ExUtilController.java DownloadExterno.getUrl server-side request forgery

    Published
    7 Sept 2026
    CVE-2026-86271
    No fix available
    Packages

    Summary

    FluentCMS PermissionManager.cs GetAccessible authorization

    Published
    7 Sept 2026
    ECHO-0130-fa3a-9541
    No fix available
    Packages

    nodejs

    Summary

    Published
    7 Sept 2026
    CVE-2026-86315
    No fix available
    Packages

    Summary

    Published
    7 Sept 2026
    CVE-2026-86264
    No fix available
    Packages

    Summary

    sfturing ssm_pro Order Endpoint OrderController.java cross site scripting

    Published
    7 Sept 2026
    CVE-2026-86263
    No fix available
    Packages

    Summary

    sfturing hosp_order Order Cancellation OrderController.java orderRecordsService.cancelOrder authorization

    Published
    7 Sept 2026
    CVE-2026-86262
    No fix available
    Packages

    Summary

    sfturing hosp_order Order OrderController.java updateOrderdiseaseInfo authorization

    Published
    7 Sept 2026
    CVE-2026-86314
    No fix available
    Packages

    Summary

    Published
    7 Sept 2026
    CVE-2026-86261
    No fix available
    Packages

    Summary

    sfturing hosp_order Order Controller OrderController.java authorization

    Published
    7 Sept 2026
    CVE-2026-86313
    No fix available
    Packages

    Summary

    Published
    7 Sept 2026
    CVE-2026-86260
    No fix available
    Packages

    Summary

    sfturing hosp_order Password Recovery CommonUserController.java modifyPassWord unverified password change

    Published
    7 Sept 2026
    CVE-2026-86244
    Fix available
    Packages

    Summary

    FastAdmin User Controller User.php login cross site scripting

    Published
    7 Sept 2026
    CVE-2026-86241
    No fix available
    Packages

    Summary

    liufee FeehiCMS Cookie Validation main-local.php hard-coded key

    Published
    7 Sept 2026
    CVE-2026-86240
    No fix available
    Packages

    Summary

    liufee FeehiCMS UEditor Uploader.php catchImage server-side request forgery

    Published
    7 Sept 2026
    CVE-2026-86239
    No fix available
    Packages

    Summary

    liufee FeehiCMS UEditor Widget UeditorAction.php init unrestricted upload

    Published
    7 Sept 2026
    CVE-2026-86237
    No fix available
    Packages

    Summary

    openagents-org openagents http.py test_default_model server-side request forgery

    Published
    7 Sept 2026
    UBUNTU-CVE-2026-85218
    No fix available
    Packages

    bluez, bluez, bluez, bluez, bluez, bluez

    Summary

    Published
    7 Sept 2026
    UBUNTU-CVE-2026-68546
    No fix available
    Packages

    exiv2, exiv2, exiv2, exiv2, exiv2, exiv2

    Summary

    Published
    7 Sept 2026
    UBUNTU-CVE-2026-68547
    No fix available
    Packages

    exiv2, exiv2, exiv2, exiv2, exiv2, exiv2

    Summary

    Published
    7 Sept 2026
    UBUNTU-CVE-2026-71223
    No fix available
    Packages

    gfs2-utils, gfs2-utils, gfs2-utils, gfs2-utils, gfs2-utils, gfs2-utils

    Summary

    Published
    7 Sept 2026
    Packages

    policykit-1, policykit-1, policykit-1, policykit-1, policykit-1, policykit-1, policykit-1

    Summary

    Published
    7 Sept 2026