Known Vulnerabilities for Xdg-utils by Freedesktop
Listed below are 5 of the newest known vulnerabilities associated with "Xdg-utils" by "Freedesktop".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-35667 json | OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command uses an unpatched killPr... | Not Provided | 2026-04-10 | 2026-04-10 |
| CVE-2026-34840 json | OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementat... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-34826 json | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges parses ... | Not Provided | 2026-04-02 | 2026-04-03 |
| CVE-2026-34743 json | XZ Utils provide a general-purpose data-compression library plus command-line tools. Prior to version 5.8.3, if lzma_index_de... | Not Provided | 2026-04-02 | 2026-04-03 |
| CVE-2026-34230 json | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding pr... | Not Provided | 2026-04-02 | 2026-04-03 |
| CVE-2026-34221 json | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-33718 json | OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in the `... | Not Provided | 2026-03-27 | 2026-03-27 |
| CVE-2026-33693 json | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `act... | Not Provided | 2026-03-27 | 2026-03-30 |
| CVE-2026-33686 json | Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulner... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-33679 json | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in `pkg/... | Not Provided | 2026-03-24 | 2026-03-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Freedesktop | Xdg-utils | 1.1.3 | |||
| Application | Freedesktop | Xdg-utils | 1.1.2 | |||
| Application | Freedesktop | Xdg-utils | 1.1.1 | |||
| Application | Freedesktop | Xdg-utils | 1.1.0 | |||
| Application | Freedesktop | Xdg-utils | 1.0.2 | |||
| Application | Freedesktop | Xdg-utils | 1.0.1 | |||
| Application | Freedesktop | Xdg-utils | 1.0 |