Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-46775 |
|
Vulnerability in c (CVE-2026-46775)
vulnerability in c (CVE-2026-46775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46822 |
|
Vulnerability in c (CVE-2026-46822)
vulnerability in c (CVE-2026-46822). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46824 |
|
Privilege Escalation in c (CVE-2026-46824)
vulnerability in c (CVE-2026-46824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46819 |
|
Vulnerability in c (CVE-2026-46819)
vulnerability in c (CVE-2026-46819). Confidential information can be exposed externally.
|
| CVE-2026-45039 |
|
Vulnerability in CVE-2026-45039 (CVE-2026-45039)
vulnerability in CVE-2026-45039 (CVE-2026-45039). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-45323 |
|
Cross-Site Scripting (XSS) in jpettitt (CVE-2026-45323)
cross-site scripting in jpettitt (CVE-2026-45323). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.3.3` or later.
|
| CVE-2026-38707 |
|
Command Injection in inhandnetworks (CVE-2026-38707)
command injection in inhandnetworks (CVE-2026-38707). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38704 |
|
Command Injection in inhandnetworks (CVE-2026-38704)
command injection in inhandnetworks (CVE-2026-38704). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38703 |
|
Command Injection in inhandnetworks (CVE-2026-38703)
command injection in inhandnetworks (CVE-2026-38703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38702 |
|
Command Injection in inhandnetworks (CVE-2026-38702)
command injection in inhandnetworks (CVE-2026-38702). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24444 |
|
Vulnerability in CVE-2026-24444 (CVE-2026-24444)
vulnerability in CVE-2026-24444 (CVE-2026-24444). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22872 |
|
Vulnerability in github.com/projectcapsule/capsule (CVE-2026-22872)
vulnerability in github.com/projectcapsule/capsule (CVE-2026-22872). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.13.0` or later.
|
| CVE-2026-7786 |
|
Vulnerability in cisa (CVE-2026-7786)
vulnerability in cisa (CVE-2026-7786). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9813 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9813)
SSRF in ssrf (CVE-2026-9813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46195 |
|
Vulnerability in linux (CVE-2026-46195)
vulnerability in linux (CVE-2026-46195). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46185 |
|
Out-of-Bounds Read in linux (CVE-2026-46185)
vulnerability in linux (CVE-2026-46185). Confidential information can be exposed externally.
|
| CVE-2026-46155 |
|
Out-of-Bounds Read in linux (CVE-2026-46155)
vulnerability in linux (CVE-2026-46155). Confidential information can be exposed externally.
|
| CVE-2026-46135 |
|
Vulnerability in linux (CVE-2026-46135)
vulnerability in linux (CVE-2026-46135). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46137 |
|
Vulnerability in linux (CVE-2026-46137)
vulnerability in linux (CVE-2026-46137). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46119 |
|
Out-of-Bounds Read in linux (CVE-2026-46119)
vulnerability in linux (CVE-2026-46119). Confidential information can be exposed externally.
|
| CVE-2026-4408 |
|
OS Command Injection in redhat (CVE-2026-4408)
OS command injection in redhat (CVE-2026-4408). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32999 |
|
Code Injection in CVE-2026-32999 (CVE-2026-32999)
code injection in CVE-2026-32999 (CVE-2026-32999). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46621 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-46621)
code injection in org.yamcs:yamcs-core (CVE-2026-46621). Successful exploitation can lead to full system takeover. Exploitable via ``ChangeMissionDatabase``. Mitigation: upgrade to `5.12.7` or later.
|
| CVE-2026-46562 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-46562)
code injection in org.yamcs:yamcs-core (CVE-2026-46562). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/mdb/{instance}/{processor}/algorithms/{name`. Mitigation: upgrade to `5.12.7` or later.
|
| CVE-2026-8363 |
|
Vulnerability in CVE-2026-8363 (CVE-2026-8363)
vulnerability in CVE-2026-8363 (CVE-2026-8363). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8362 |
|
Vulnerability in CVE-2026-8362 (CVE-2026-8362)
vulnerability in CVE-2026-8362 (CVE-2026-8362). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8364 |
|
Vulnerability in CVE-2026-8364 (CVE-2026-8364)
vulnerability in CVE-2026-8364 (CVE-2026-8364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45069 |
|
Vulnerability in symfony/security-http (CVE-2026-45069)
vulnerability in symfony/security-http (CVE-2026-45069). Confidential information can be exposed externally. Exploitable via ``OidcTokenHandler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-44888 |
|
Code Injection in CVE-2026-44888 (CVE-2026-44888)
code injection in CVE-2026-44888 (CVE-2026-44888). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026-05-07` or later.
|
| CVE-2026-45102 |
|
Vulnerability in CVE-2026-45102 (CVE-2026-45102)
vulnerability in CVE-2026-45102 (CVE-2026-45102). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.0.98` or later.
|
| CVE-2026-44590 |
|
OS Command Injection in CVE-2026-44590 (CVE-2026-44590)
OS command injection in CVE-2026-44590 (CVE-2026-44590). Data can be tampered with by attackers. Mitigation: upgrade to `0.16.1` or later.
|
| CVE-2026-44887 |
|
Code Injection in CVE-2026-44887 (CVE-2026-44887)
code injection in CVE-2026-44887 (CVE-2026-44887). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026-05-07` or later.
|
| CVE-2026-25879 |
|
SQL Injection in langroid (CVE-2026-25879)
SQL injection in langroid (CVE-2026-25879). Successful exploitation can lead to full system takeover. Exploitable via ``query``. Mitigation: upgrade to `0.63.0` or later.
|
| CVE-2026-45618 |
|
Code Injection in liquidjs (CVE-2026-45618)
code injection in liquidjs (CVE-2026-45618). Successful exploitation can lead to full system takeover. Exploitable via ``this``. Mitigation: upgrade to `10.26.0` or later.
|
| CVE-2026-46425 |
|
Vulnerability in CVE-2026-46425 (CVE-2026-46425)
vulnerability in CVE-2026-46425 (CVE-2026-46425). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.38.2` or later.
|
| CVE-2026-45063 |
|
Vulnerability in symfony/security-http (CVE-2026-45063)
vulnerability in symfony/security-http (CVE-2026-45063). Confidential information can be exposed externally. Exploitable via ``X509Authenticator``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45972 |
|
Use-After-Free in linux (CVE-2026-45972)
vulnerability in linux (CVE-2026-45972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8175 |
|
Vulnerability in dos (CVE-2026-8175)
vulnerability in dos (CVE-2026-8175). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7524 |
|
Path Traversal in langflow (CVE-2026-7524)
path traversal in langflow (CVE-2026-7524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7876 |
|
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
|
| CVE-2026-46039 |
|
Vulnerability in linux (CVE-2026-46039)
vulnerability in linux (CVE-2026-46039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42756 |
|
Path Traversal in path-traversal (CVE-2026-42756)
path traversal in path-traversal (CVE-2026-42756). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42761 |
|
SQL Injection in sqli (CVE-2026-42761)
SQL injection in sqli (CVE-2026-42761). Confidential information can be exposed externally.
|
| CVE-2026-42757 |
|
Path Traversal in path-traversal (CVE-2026-42757)
path traversal in path-traversal (CVE-2026-42757). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42748 |
|
Unrestricted File Upload in CVE-2026-42748 (CVE-2026-42748)
vulnerability in CVE-2026-42748 (CVE-2026-42748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42747 |
|
SQL Injection in sqli (CVE-2026-42747)
SQL injection in sqli (CVE-2026-42747). Confidential information can be exposed externally.
|
| CVE-2026-42755 |
|
SQL Injection in sqli (CVE-2026-42755)
SQL injection in sqli (CVE-2026-42755). Confidential information can be exposed externally.
|
| CVE-2026-42740 |
|
SQL Injection in sqli (CVE-2026-42740)
SQL injection in sqli (CVE-2026-42740). Confidential information can be exposed externally.
|
| CVE-2026-42727 |
|
SQL Injection in sqli (CVE-2026-42727)
SQL injection in sqli (CVE-2026-42727). Confidential information can be exposed externally.
|
| CVE-2026-49002 |
|
Vulnerability in CVE-2026-49002 (CVE-2026-49002)
vulnerability in CVE-2026-49002 (CVE-2026-49002). Confidential information can be exposed externally.
|