Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55168 |
|
Vulnerability in CVE-2026-55168 (CVE-2026-55168)
vulnerability in CVE-2026-55168 (CVE-2026-55168). Data can be tampered with by attackers. Exploitable via `PUT /api/user-config/demoapp3`.
|
| CVE-2026-63125 |
|
Vulnerability in CVE-2026-63125 (CVE-2026-63125)
vulnerability in CVE-2026-63125 (CVE-2026-63125). Successful exploitation can lead to full system takeover. Exploitable via ``can_create_images``.
|
| CVE-2026-64846 |
|
Vulnerability in CVE-2026-64846 (CVE-2026-64846)
vulnerability in CVE-2026-64846 (CVE-2026-64846). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62992 |
|
Path Traversal in smarty/smarty (CVE-2026-62992)
path traversal in smarty/smarty (CVE-2026-62992). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.8.2` or later.
|
| CVE-2026-17459 |
|
Vulnerability in CVE-2026-17459 (CVE-2026-17459)
vulnerability in CVE-2026-17459 (CVE-2026-17459). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14699 |
|
Vulnerability in CVE-2026-14699 (CVE-2026-14699)
vulnerability in CVE-2026-14699 (CVE-2026-14699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13748 |
|
Path Traversal in snowflake (CVE-2026-13748)
path traversal in snowflake (CVE-2026-13748). Confidential information can be exposed externally.
|
| CVE-2026-56876 |
|
Path Traversal in extract-zip (CVE-2026-56876)
path traversal in extract-zip (CVE-2026-56876). Confidential information can be exposed externally.
|
| CVE-2026-52811 |
|
Path Traversal in gogs.io/gogs (CVE-2026-52811)
path traversal in gogs.io/gogs (CVE-2026-52811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55447 |
|
Information Disclosure in langflow (CVE-2026-55447)
vulnerability in langflow (CVE-2026-55447). Successful exploitation can lead to full system takeover. Exploitable via ``BaseFileComponent``. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2026-42306 |
|
Vulnerability in github.com/docker/docker (CVE-2026-42306)
vulnerability in github.com/docker/docker (CVE-2026-42306). Data can be tampered with by attackers. Exploitable via `PUT /containers/{id}/archive`. Mitigation: upgrade to `2.0.0-beta.14` or later.
|
| CVE-2026-8784 |
|
Vulnerability in c (CVE-2026-8784)
vulnerability in c (CVE-2026-8784). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41937 |
|
Vulnerability in CVE-2026-41937 (CVE-2026-41937)
vulnerability in CVE-2026-41937 (CVE-2026-41937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42275 |
|
Path Traversal in github.com/openziti/zrok (CVE-2026-42275)
path traversal in github.com/openziti/zrok (CVE-2026-42275). Confidential information can be exposed externally. Mitigation: upgrade to `2.0.2` or later.
|
| CVE-2026-41326 |
|
Vulnerability in github.com/kata-containers/kata-containers (CVE-2026-41326)
vulnerability in github.com/kata-containers/kata-containers (CVE-2026-41326). Confidential information can be exposed externally. Exploitable via ``policy_data.common.cpath``. Mitigation: upgrade to `0.0.0-20260422180503-1b9e49eb2763` or later.
|
| CVE-2026-34078 |
|
Vulnerability in flatpak (CVE-2026-34078)
vulnerability in flatpak (CVE-2026-34078). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.16.4` or later.
|
| CVE-2026-27489 |
|
Vulnerability in path-traversal (CVE-2026-27489)
vulnerability in path-traversal (CVE-2026-27489). Confidential information can be exposed externally.
|