Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-18941 |
|
Vulnerability in dos (CVE-2026-18941)
vulnerability in dos (CVE-2026-18941). Confidential information can be exposed externally.
|
| CVE-2026-18618 |
|
Vulnerability in dos (CVE-2026-18618)
vulnerability in dos (CVE-2026-18618). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18617 |
|
Vulnerability in privilege-escalation (CVE-2026-18617)
vulnerability in privilege-escalation (CVE-2026-18617). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72912 |
|
Vulnerability in privilege-escalation (CVE-2026-72912)
vulnerability in privilege-escalation (CVE-2026-72912). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72904 |
|
Command Injection in ssrf (CVE-2026-72904)
command injection in ssrf (CVE-2026-72904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11810 |
|
Vulnerability in c (CVE-2026-11810)
vulnerability in c (CVE-2026-11810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11809 |
|
Out-of-Bounds Read in c (CVE-2026-11809)
vulnerability in c (CVE-2026-11809). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72882 |
|
OS Command Injection in CVE-2026-72882 (CVE-2026-72882)
OS command injection in CVE-2026-72882 (CVE-2026-72882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71965 |
|
Vulnerability in CVE-2026-71965 (CVE-2026-71965)
vulnerability in CVE-2026-71965 (CVE-2026-71965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69118 |
|
Authorization Flaw in CVE-2026-69118 (CVE-2026-69118)
vulnerability in CVE-2026-69118 (CVE-2026-69118). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69112 |
|
Path Traversal in path-traversal (CVE-2026-69112)
path traversal in path-traversal (CVE-2026-69112). Confidential information can be exposed externally.
|
| CVE-2026-44401 |
|
Cross-Site Scripting (XSS) in CVE-2026-44401 (CVE-2026-44401)
cross-site scripting in CVE-2026-44401 (CVE-2026-44401). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15681 |
|
Vulnerability in CVE-2025-15681 (CVE-2025-15681)
vulnerability in CVE-2025-15681 (CVE-2025-15681). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13294 |
|
SQL Injection in sqli (CVE-2025-13294)
SQL injection in sqli (CVE-2025-13294). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71967 |
|
Vulnerability in dos (CVE-2026-71967)
vulnerability in dos (CVE-2026-71967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12339 |
|
Path Traversal in path-traversal (CVE-2026-12339)
path traversal in path-traversal (CVE-2026-12339). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72730 |
|
Cross-Site Scripting (XSS) in CVE-2026-72730 (CVE-2026-72730)
cross-site scripting in CVE-2026-72730 (CVE-2026-72730). Confidential information can be exposed externally.
|
| CVE-2026-72727 |
|
Cross-Site Scripting (XSS) in CVE-2026-72727 (CVE-2026-72727)
cross-site scripting in CVE-2026-72727 (CVE-2026-72727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56619 |
|
Cross-Site Scripting (XSS) in CVE-2026-56619 (CVE-2026-56619)
cross-site scripting in CVE-2026-56619 (CVE-2026-56619). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72725 |
|
Cross-Site Scripting (XSS) in CVE-2026-72725 (CVE-2026-72725)
cross-site scripting in CVE-2026-72725 (CVE-2026-72725). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-47754 |
|
Path Traversal in tomcat (CVE-2026-47754)
path traversal in tomcat (CVE-2026-47754). Confidential information can be exposed externally. Exploitable via ``archiveEntryName``.
|
| CVE-2026-72751 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-72751)
cross-site scripting in c (CVE-2026-72751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18412 |
|
Vulnerability in path-traversal (CVE-2026-18412)
vulnerability in path-traversal (CVE-2026-18412). Confidential information can be exposed externally.
|
| CVE-2026-63105 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-63105)
cross-site scripting in vue (CVE-2026-63105). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18478 |
|
Cross-Site Scripting (XSS) in CVE-2026-18478 (CVE-2026-18478)
cross-site scripting in CVE-2026-18478 (CVE-2026-18478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63106 |
|
SQL Injection in sqli (CVE-2026-63106)
SQL injection in sqli (CVE-2026-63106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72691 |
|
Vulnerability in CVE-2026-72691 (CVE-2026-72691)
vulnerability in CVE-2026-72691 (CVE-2026-72691). Confidential information can be exposed externally.
|
| CVE-2026-68411 |
|
Vulnerability in dos (CVE-2026-68411)
vulnerability in dos (CVE-2026-68411). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18370 |
|
Vulnerability in dos (CVE-2026-18370)
vulnerability in dos (CVE-2026-18370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19278 |
|
Vulnerability in privilege-escalation (CVE-2026-19278)
vulnerability in privilege-escalation (CVE-2026-19278). Confidential information can be exposed externally.
|
| CVE-2026-19429 |
|
Vulnerability in CVE-2026-19429 (CVE-2026-19429)
vulnerability in CVE-2026-19429 (CVE-2026-19429). Successful exploitation can lead to full system takeover. Exploitable via `POST /job/{name}/build`.
|
| CVE-2026-72761 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72761)
SSRF in ssrf (CVE-2026-72761). Risk of unauthorized operations or information disclosure. Exploitable via ``ip.is_global``.
|
| CVE-2026-16742 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16742)
vulnerability in privilege-escalation (CVE-2026-16742). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15059 |
|
Path Traversal in path-traversal (CVE-2026-15059)
path traversal in path-traversal (CVE-2026-15059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59088 |
|
Vulnerability in dos (CVE-2026-59088)
vulnerability in dos (CVE-2026-59088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72594 |
|
Cross-Site Scripting (XSS) in CVE-2026-72594 (CVE-2026-72594)
cross-site scripting in CVE-2026-72594 (CVE-2026-72594). Confidential information can be exposed externally.
|
| CVE-2026-72591 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72591)
SSRF in ssrf (CVE-2026-72591). Confidential information can be exposed externally. Exploitable via `PATCH /apis/web/v1/album/{id}/image`.
|
| CVE-2026-72583 |
|
Cross-Site Scripting (XSS) in CVE-2026-72583 (CVE-2026-72583)
cross-site scripting in CVE-2026-72583 (CVE-2026-72583). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72581 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72581)
SSRF in ssrf (CVE-2026-72581). Confidential information can be exposed externally.
|
| CVE-2026-72576 |
|
Cross-Site Scripting (XSS) in CVE-2026-72576 (CVE-2026-72576)
cross-site scripting in CVE-2026-72576 (CVE-2026-72576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72578 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-72578)
vulnerability in csrf (CVE-2026-72578). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72570 |
|
Cross-Site Scripting (XSS) in CVE-2026-72570 (CVE-2026-72570)
cross-site scripting in CVE-2026-72570 (CVE-2026-72570). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72566 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72566)
SSRF in ssrf (CVE-2026-72566). Confidential information can be exposed externally.
|
| CVE-2026-72572 |
|
Path Traversal in path-traversal (CVE-2026-72572)
path traversal in path-traversal (CVE-2026-72572). Confidential information can be exposed externally.
|
| CVE-2026-72571 |
|
Path Traversal in path-traversal (CVE-2026-72571)
path traversal in path-traversal (CVE-2026-72571). Confidential information can be exposed externally.
|
| CVE-2026-72569 |
|
Path Traversal in path-traversal (CVE-2026-72569)
path traversal in path-traversal (CVE-2026-72569). Data can be tampered with by attackers.
|
| CVE-2026-72567 |
|
Path Traversal in path-traversal (CVE-2026-72567)
path traversal in path-traversal (CVE-2026-72567). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72568 |
|
Out-of-Bounds Read in dos (CVE-2026-72568)
vulnerability in dos (CVE-2026-72568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72565 |
|
SQL Injection in sqli (CVE-2026-72565)
SQL injection in sqli (CVE-2026-72565). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66642 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66642)
vulnerability in csrf (CVE-2026-66642). Risk of unauthorized operations or information disclosure.
|