Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-53561 |
|
Authentication Bypass in apache (CVE-2026-53561)
authentication bypass in apache (CVE-2026-53561). Confidential information can be exposed externally.
|
| CVE-2026-75509 |
|
Vulnerability in CVE-2026-75509 (CVE-2026-75509)
vulnerability in CVE-2026-75509 (CVE-2026-75509). Data can be tampered with by attackers.
|
| CVE-2026-48106 |
|
Vulnerability in CVE-2026-48106 (CVE-2026-48106)
vulnerability in CVE-2026-48106 (CVE-2026-48106). Risk of unauthorized operations or information disclosure. Exploitable via ``MsgReplicateSync``. Mitigation: upgrade to `2026.06.1` or later.
|
| CVE-2026-48105 |
|
Path Traversal in CVE-2026-48105 (CVE-2026-48105)
path traversal in CVE-2026-48105 (CVE-2026-48105). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.06.1` or later.
|
| CVE-2026-50575 |
|
Vulnerability in CVE-2026-50575 (CVE-2026-50575)
vulnerability in CVE-2026-50575 (CVE-2026-50575). Confidential information can be exposed externally.
|
| CVE-2026-71858 |
|
OS Command Injection in CVE-2026-71858 (CVE-2026-71858)
OS command injection in CVE-2026-71858 (CVE-2026-71858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18674 |
|
Vulnerability in CVE-2026-18674 (CVE-2026-18674)
vulnerability in CVE-2026-18674 (CVE-2026-18674). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73846 |
|
Vulnerability in CVE-2026-73846 (CVE-2026-73846)
vulnerability in CVE-2026-73846 (CVE-2026-73846). Data can be tampered with by attackers.
|
| CVE-2026-73840 |
|
Authentication Bypass in CVE-2026-73840 (CVE-2026-73840)
authentication bypass in CVE-2026-73840 (CVE-2026-73840). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1alpha1/autobuild`.
|
| CVE-2026-73657 |
|
Path Traversal in CVE-2026-73657 (CVE-2026-73657)
path traversal in CVE-2026-73657 (CVE-2026-73657). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/runs/`.
|
| CVE-2026-58262 |
|
Vulnerability in CVE-2026-58262 (CVE-2026-58262)
vulnerability in CVE-2026-58262 (CVE-2026-58262). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47664 |
|
Vulnerability in CVE-2026-47664 (CVE-2026-47664)
vulnerability in CVE-2026-47664 (CVE-2026-47664). Risk of unauthorized operations or information disclosure. Exploitable via ``exportUrl``.
|
| CVE-2026-15246 |
|
Vulnerability in wordpress (CVE-2026-15246)
vulnerability in wordpress (CVE-2026-15246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73419 |
|
Vulnerability in @auth/core (CVE-2026-73419)
vulnerability in @auth/core (CVE-2026-73419). Confidential information can be exposed externally. Exploitable via ``state``. Mitigation: upgrade to `0.41.3` or later.
|
| CVE-2026-52688 |
|
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
|
| CVE-2026-62517 |
|
Vulnerability in c (CVE-2026-62517)
vulnerability in c (CVE-2026-62517). Confidential information can be exposed externally.
|
| CVE-2026-63094 |
|
Vulnerability in CVE-2026-63094 (CVE-2026-63094)
vulnerability in CVE-2026-63094 (CVE-2026-63094). Confidential information can be exposed externally.
|
| CVE-2026-44434 |
|
Vulnerability in h2o (CVE-2026-44434)
vulnerability in h2o (CVE-2026-44434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50526 |
|
Vulnerability in Microsoft.NET.Build.Containers (CVE-2026-50526)
vulnerability in Microsoft.NET.Build.Containers (CVE-2026-50526). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-47304 |
|
Vulnerability in System.Security.Cryptography.Xml (CVE-2026-47304)
vulnerability in System.Security.Cryptography.Xml (CVE-2026-47304). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.4` or later.
|
| CVE-2026-9561 |
|
Vulnerability in dos (CVE-2026-9561)
vulnerability in dos (CVE-2026-9561). Data can be tampered with by attackers.
|
| CVE-2026-53513 |
|
Vulnerability in @better-auth/sso (CVE-2026-53513)
vulnerability in @better-auth/sso (CVE-2026-53513). Confidential information can be exposed externally. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53516 |
|
Authentication Bypass in better-auth (CVE-2026-53516)
authentication bypass in better-auth (CVE-2026-53516). Confidential information can be exposed externally. Exploitable via ``next``. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53514 |
|
Authentication Bypass in better-auth (CVE-2026-53514)
authentication bypass in better-auth (CVE-2026-53514). Confidential information can be exposed externally. Exploitable via ``organization``. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53512 |
|
Authentication Bypass in better-auth (CVE-2026-53512)
authentication bypass in better-auth (CVE-2026-53512). Confidential information can be exposed externally. Exploitable via ``oauthApplication``. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-54763 |
|
Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763). Confidential information can be exposed externally. Exploitable via ``X_Auth_User``. Mitigation: upgrade to `2.11.42` or later.
|
| CVE-2026-55430 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-55430)
vulnerability in github.com/coder/coder/v2 (CVE-2026-55430). Confidential information can be exposed externally. Exploitable via ``Host``. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-58593 |
|
Vulnerability in nodebb (CVE-2026-58593)
vulnerability in nodebb (CVE-2026-58593). Data can be tampered with by attackers.
|
| CVE-2026-55698 |
|
Vulnerability in pnpm (CVE-2026-55698)
vulnerability in pnpm (CVE-2026-55698). Successful exploitation can lead to full system takeover. Exploitable via ``a93449314f398cf4bdf2e28d033c02d37395ad22``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-52812 |
|
Vulnerability in gogs.io/gogs (CVE-2026-52812)
vulnerability in gogs.io/gogs (CVE-2026-52812). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54783 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54783)
vulnerability in CoreWCF.Primitives (CVE-2026-54783). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54781 |
|
Authentication Bypass in CoreWCF.Primitives (CVE-2026-54781)
authentication bypass in CoreWCF.Primitives (CVE-2026-54781). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54774 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54774)
vulnerability in CoreWCF.Primitives (CVE-2026-54774). Confidential information can be exposed externally. Exploitable via ``BinarySecretSecurityToken``. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-50195 |
|
Vulnerability in Amazon github.com/containerd/containerd/v2 (CVE-2026-50195)
vulnerability in Amazon github.com/containerd/containerd/v2 (CVE-2026-50195). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.9, 2.2.5, 2.3.2` or later.
|
| CVE-2026-48781 |
|
Vulnerability in CVE-2026-48781 (CVE-2026-48781)
vulnerability in CVE-2026-48781 (CVE-2026-48781). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48783 |
|
Vulnerability in CVE-2026-48783 (CVE-2026-48783)
vulnerability in CVE-2026-48783 (CVE-2026-48783). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47777 |
|
Vulnerability in CVE-2026-47777 (CVE-2026-47777)
vulnerability in CVE-2026-47777 (CVE-2026-47777). Data can be tampered with by attackers.
|
| CVE-2026-48063 |
|
Vulnerability in baileys (CVE-2026-48063)
vulnerability in baileys (CVE-2026-48063). Risk of unauthorized operations or information disclosure. Exploitable via ``messages.upsert``. Mitigation: upgrade to `7.0.0-rc12` or later.
|
| CVE-2026-48096 |
|
Vulnerability in github.com/openfga/openfga (CVE-2026-48096)
vulnerability in github.com/openfga/openfga (CVE-2026-48096). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-47737 |
|
Vulnerability in puma (CVE-2026-47737)
vulnerability in puma (CVE-2026-47737). Data can be tampered with by attackers. Exploitable via ``REMOTE_ADDR``. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-45337 |
|
Vulnerability in better-auth (CVE-2026-45337)
vulnerability in better-auth (CVE-2026-45337). Confidential information can be exposed externally. Exploitable via `POST /device/approve`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-47123 |
|
Vulnerability in laravel (CVE-2026-47123)
vulnerability in laravel (CVE-2026-47123). Data can be tampered with by attackers. Mitigation: upgrade to `1.8.220` or later.
|
| CVE-2026-46538 |
|
Vulnerability in CVE-2026-46538 (CVE-2026-46538)
vulnerability in CVE-2026-46538 (CVE-2026-46538). Data can be tampered with by attackers.
|
| CVE-2026-45069 |
|
Vulnerability in symfony/security-http (CVE-2026-45069)
vulnerability in symfony/security-http (CVE-2026-45069). Confidential information can be exposed externally. Exploitable via ``OidcTokenHandler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-3012 |
|
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate...
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate...
|
| CVE-2026-47202 |
|
Authentication Bypass in CVE-2026-47202 (CVE-2026-47202)
authentication bypass in CVE-2026-47202 (CVE-2026-47202). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0.2` or later.
|
| CVE-2026-39969 |
|
Authentication Bypass in CVE-2026-39969 (CVE-2026-39969)
authentication bypass in CVE-2026-39969 (CVE-2026-39969). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook`.
|
| CVE-2026-45792 |
|
Vulnerability in rtk (CVE-2026-45792)
vulnerability in rtk (CVE-2026-45792). Data can be tampered with by attackers. Exploitable via ``strip_lines_matching``. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-33233 |
|
Code Injection in deserialization (CVE-2026-33233)
code injection in deserialization (CVE-2026-33233). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32323 |
|
Privilege Escalation in privilege-escalation (CVE-2026-32323)
vulnerability in privilege-escalation (CVE-2026-32323). Successful exploitation can lead to full system takeover.
|