Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12631 |
|
Vulnerability in c (CVE-2026-12631)
vulnerability in c (CVE-2026-12631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12632 |
|
Out-of-Bounds Read in c (CVE-2026-12632)
vulnerability in c (CVE-2026-12632). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71417 |
|
Vulnerability in lemur (CVE-2026-71417)
vulnerability in lemur (CVE-2026-71417). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/1/certificates/`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-55593 |
|
Cross-Site Request Forgery (CSRF) in froxlor/froxlor (CVE-2026-55593)
vulnerability in froxlor/froxlor (CVE-2026-55593). Data can be tampered with by attackers. Exploitable via ``allowed_from``. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-54348 |
|
SQL Injection in froxlor/froxlor (CVE-2026-54348)
SQL injection in froxlor/froxlor (CVE-2026-54348). Successful exploitation can lead to full system takeover. Exploitable via ``panel_admins.ip``. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-75935 |
|
Vulnerability in Amazon aws (CVE-2026-75935)
vulnerability in Amazon aws (CVE-2026-75935). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75936 |
|
Vulnerability in dos (CVE-2026-75936)
vulnerability in dos (CVE-2026-75936). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75876 |
|
Vulnerability in sqli (CVE-2026-75876)
vulnerability in sqli (CVE-2026-75876). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71675 |
|
Vulnerability in c (CVE-2026-71675)
vulnerability in c (CVE-2026-71675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71676 |
|
Vulnerability in dos (CVE-2026-71676)
vulnerability in dos (CVE-2026-71676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65985 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65985)
SSRF in ssrf (CVE-2026-65985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49500 |
|
Vulnerability in dos (CVE-2026-49500)
vulnerability in dos (CVE-2026-49500). Data can be tampered with by attackers.
|
| CVE-2026-47629 |
|
Vulnerability in dos (CVE-2026-47629)
vulnerability in dos (CVE-2026-47629). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47630 |
|
Vulnerability in path-traversal (CVE-2026-47630)
vulnerability in path-traversal (CVE-2026-47630). Confidential information can be exposed externally.
|
| CVE-2026-47627 |
|
Path Traversal in path-traversal (CVE-2026-47627)
path traversal in path-traversal (CVE-2026-47627). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47628 |
|
Vulnerability in dos (CVE-2026-47628)
vulnerability in dos (CVE-2026-47628). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47606 |
|
Vulnerability in path-traversal (CVE-2026-47606)
vulnerability in path-traversal (CVE-2026-47606). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-9211 |
|
Cross-Site Scripting (XSS) in CVE-2025-9211 (CVE-2025-9211)
cross-site scripting in CVE-2025-9211 (CVE-2025-9211). Confidential information can be exposed externally.
|
| CVE-2021-43718 |
|
Vulnerability in dos (CVE-2021-43718)
vulnerability in dos (CVE-2021-43718). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71879 |
|
Vulnerability in CVE-2026-71879 (CVE-2026-71879)
vulnerability in CVE-2026-71879 (CVE-2026-71879). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71878 |
|
Vulnerability in CVE-2026-71878 (CVE-2026-71878)
vulnerability in CVE-2026-71878 (CVE-2026-71878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52609 |
|
Cross-Site Scripting (XSS) in CVE-2026-52609 (CVE-2026-52609)
cross-site scripting in CVE-2026-52609 (CVE-2026-52609). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52607 |
|
Path Traversal in path-traversal (CVE-2026-52607)
path traversal in path-traversal (CVE-2026-52607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52610 |
|
Path Traversal in path-traversal (CVE-2026-52610)
path traversal in path-traversal (CVE-2026-52610). Confidential information can be exposed externally.
|
| CVE-2026-67921 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-67921)
vulnerability in csrf (CVE-2026-67921). Confidential information can be exposed externally.
|
| CVE-2026-52608 |
|
Vulnerability in CVE-2026-52608 (CVE-2026-52608)
vulnerability in CVE-2026-52608 (CVE-2026-52608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74046 |
|
Vulnerability in dos (CVE-2026-74046)
vulnerability in dos (CVE-2026-74046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74039 |
|
Vulnerability in dos (CVE-2026-74039)
vulnerability in dos (CVE-2026-74039). Risk of unauthorized operations or information disclosure. Exploitable via `POST /security/user/authenticate/run_as`.
|
| CVE-2026-74038 |
|
Path Traversal in path-traversal (CVE-2026-74038)
path traversal in path-traversal (CVE-2026-74038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74044 |
|
Path Traversal in path-traversal (CVE-2026-74044)
path traversal in path-traversal (CVE-2026-74044). Data can be tampered with by attackers.
|
| CVE-2026-61696 |
|
Vulnerability in csrf (CVE-2026-61696)
vulnerability in csrf (CVE-2026-61696). Confidential information can be exposed externally.
|
| CVE-2026-50161 |
|
Vulnerability in c (CVE-2026-50161)
vulnerability in c (CVE-2026-50161). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68923 |
|
Cross-Site Request Forgery (CSRF) in mobsf (CVE-2026-68923)
vulnerability in mobsf (CVE-2026-68923). Data can be tampered with by attackers. Exploitable via ``CsrfViewMiddleware``. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-63643 |
|
Vulnerability in magicmirror (CVE-2026-63643)
vulnerability in magicmirror (CVE-2026-63643). Risk of unauthorized operations or information disclosure. Exploitable via ``ADD_CALENDAR``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-75897 |
|
Vulnerability in Amazon dos (CVE-2026-75897)
vulnerability in Amazon dos (CVE-2026-75897). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75924 |
|
Privilege Escalation in privilege-escalation (CVE-2026-75924)
vulnerability in privilege-escalation (CVE-2026-75924). Confidential information can be exposed externally.
|
| CVE-2026-73336 |
|
Cross-Site Scripting (XSS) in CVE-2026-73336 (CVE-2026-73336)
cross-site scripting in CVE-2026-73336 (CVE-2026-73336). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70415 |
|
Vulnerability in dos (CVE-2026-70415)
vulnerability in dos (CVE-2026-70415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67271 |
|
Out-of-Bounds Write in dos (CVE-2026-67271)
out-of-bounds write in dos (CVE-2026-67271). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52606 |
|
Cross-Site Scripting (XSS) in CVE-2026-52606 (CVE-2026-52606)
cross-site scripting in CVE-2026-52606 (CVE-2026-52606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30250 |
|
Cross-Site Scripting (XSS) in CVE-2026-30250 (CVE-2026-30250)
cross-site scripting in CVE-2026-30250 (CVE-2026-30250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61634 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-61634)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-61634). Risk of unauthorized operations or information disclosure. Exploitable via ``frame_max``. Mitigation: upgrade to `5.33.0` or later.
|
| CVE-2026-63335 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-63335)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-63335). Risk of unauthorized operations or information disclosure. Exploitable via ``UnsupportedOperationException``. Mitigation: upgrade to `5.31.0` or later.
|
| CVE-2026-69219 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-69219)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-69219). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `5.33.1` or later.
|
| CVE-2026-69220 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-69220)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-69220). Risk of unauthorized operations or information disclosure. Exploitable via ``connection.start``. Mitigation: upgrade to `5.33.1` or later.
|
| CVE-2026-55839 |
|
Cross-Site Scripting (XSS) in io.kestra:kestra (CVE-2026-55839)
cross-site scripting in io.kestra:kestra (CVE-2026-55839). Confidential information can be exposed externally. Exploitable via ``onclick``. Mitigation: upgrade to `1.3.24` or later.
|
| CVE-2026-75914 |
|
Path Traversal in path-traversal (CVE-2026-75914)
path traversal in path-traversal (CVE-2026-75914). Confidential information can be exposed externally.
|
| CVE-2026-75858 |
|
Code Injection in CVE-2026-75858 (CVE-2026-75858)
code injection in CVE-2026-75858 (CVE-2026-75858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.64` or later.
|
| CVE-2026-75856 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75856)
SSRF in ssrf (CVE-2026-75856). Confidential information can be exposed externally.
|
| CVE-2026-71365 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71365)
SSRF in ssrf (CVE-2026-71365). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|