Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-8196 |
|
Vulnerability in CVE-2026-8196 (CVE-2026-8196)
vulnerability in CVE-2026-8196 (CVE-2026-8196). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8195 |
|
Cross-Site Scripting (XSS) in CVE-2026-8195 (CVE-2026-8195)
cross-site scripting in CVE-2026-8195 (CVE-2026-8195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8194 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-8194 (CVE-2026-8194)
vulnerability in CVE-2026-8194 (CVE-2026-8194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42605 |
|
Path Traversal in path-traversal (CVE-2026-42605)
path traversal in path-traversal (CVE-2026-42605). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/station/{station_id}/files/upload`.
|
| CVE-2026-42569 |
|
Vulnerability in CVE-2026-42569 (CVE-2026-42569)
vulnerability in CVE-2026-42569 (CVE-2026-42569). Data can be tampered with by attackers.
|
| CVE-2026-42562 |
|
Privilege Escalation in CVE-2026-42562 (CVE-2026-42562)
vulnerability in CVE-2026-42562 (CVE-2026-42562). Confidential information can be exposed externally. Exploitable via `PUT /api.php/v1/users/{id}.`.
|
| CVE-2026-42245 |
|
Vulnerability in dos (CVE-2026-42245)
vulnerability in dos (CVE-2026-42245). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42246 |
|
Vulnerability in CVE-2026-42246 (CVE-2026-42246)
vulnerability in CVE-2026-42246 (CVE-2026-42246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42256 |
|
Vulnerability in CVE-2026-42256 (CVE-2026-42256)
vulnerability in CVE-2026-42256 (CVE-2026-42256). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42257 |
|
Command Injection in CVE-2026-42257 (CVE-2026-42257)
command injection in CVE-2026-42257 (CVE-2026-42257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42258 |
|
Command Injection in CVE-2026-42258 (CVE-2026-42258)
command injection in CVE-2026-42258 (CVE-2026-42258). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8193 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-8193 (CVE-2026-8193)
SSRF in CVE-2026-8193 (CVE-2026-8193). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8191 |
|
Command Injection in c (CVE-2026-8191)
command injection in c (CVE-2026-8191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8186 |
|
Buffer Overflow in c (CVE-2026-8186)
vulnerability in c (CVE-2026-8186). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8187 |
|
Vulnerability in c (CVE-2026-8187)
vulnerability in c (CVE-2026-8187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42309 |
|
Vulnerability in CVE-2026-42309 (CVE-2026-42309)
vulnerability in CVE-2026-42309 (CVE-2026-42309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42310 |
|
Vulnerability in CVE-2026-42310 (CVE-2026-42310)
vulnerability in CVE-2026-42310 (CVE-2026-42310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42311 |
|
Vulnerability in CVE-2026-42311 (CVE-2026-42311)
vulnerability in CVE-2026-42311 (CVE-2026-42311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42308 |
|
Vulnerability in CVE-2026-42308 (CVE-2026-42308)
vulnerability in CVE-2026-42308 (CVE-2026-42308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8209 |
|
Vulnerability in path-traversal (CVE-2026-8209)
vulnerability in path-traversal (CVE-2026-8209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8208 |
|
Vulnerability in CVE-2026-8208 (CVE-2026-8208)
vulnerability in CVE-2026-8208 (CVE-2026-8208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42301 |
|
Vulnerability in CVE-2026-42301 (CVE-2026-42301)
vulnerability in CVE-2026-42301 (CVE-2026-42301). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41311 |
|
Vulnerability in dos (CVE-2026-41311)
vulnerability in dos (CVE-2026-41311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8207 |
|
SQL Injection in sqli (CVE-2026-8207)
SQL injection in sqli (CVE-2026-8207). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42455 |
|
Cross-Site Scripting (XSS) in CVE-2026-42455 (CVE-2026-42455)
cross-site scripting in CVE-2026-42455 (CVE-2026-42455). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/archives/`.
|
| CVE-2026-44313 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44313)
SSRF in ssrf (CVE-2026-44313). Confidential information can be exposed externally. Exploitable via `GET /api/v1/archives/{linkId}`.
|
| CVE-2026-45130 |
|
Vulnerability in c (CVE-2026-45130)
vulnerability in c (CVE-2026-45130). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42451 |
|
Cross-Site Scripting (XSS) in CVE-2026-42451 (CVE-2026-42451)
cross-site scripting in CVE-2026-42451 (CVE-2026-42451). Confidential information can be exposed externally.
|
| CVE-2026-42351 |
|
Path Traversal in CVE-2026-42351 (CVE-2026-42351)
path traversal in CVE-2026-42351 (CVE-2026-42351). Confidential information can be exposed externally.
|
| CVE-2026-42352 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-42352 (CVE-2026-42352)
SSRF in CVE-2026-42352 (CVE-2026-42352). Confidential information can be exposed externally.
|
| CVE-2026-42343 |
|
Vulnerability in dos (CVE-2026-42343)
vulnerability in dos (CVE-2026-42343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42224 |
|
Cross-Site Scripting (XSS) in CVE-2026-42224 (CVE-2026-42224)
cross-site scripting in CVE-2026-42224 (CVE-2026-42224). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42212 |
|
Vulnerability in csharp (CVE-2026-42212)
vulnerability in csharp (CVE-2026-42212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42199 |
|
Vulnerability in CVE-2026-42199 (CVE-2026-42199)
vulnerability in CVE-2026-42199 (CVE-2026-42199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42205 |
|
Vulnerability in rails (CVE-2026-42205)
vulnerability in rails (CVE-2026-42205). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42193 |
|
Vulnerability in aws (CVE-2026-42193)
vulnerability in aws (CVE-2026-42193). Data can be tampered with by attackers.
|
| CVE-2026-41517 |
|
Unrestricted File Upload in CVE-2026-41517 (CVE-2026-41517)
vulnerability in CVE-2026-41517 (CVE-2026-41517). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42189 |
|
Vulnerability in CVE-2026-42189 (CVE-2026-42189)
vulnerability in CVE-2026-42189 (CVE-2026-42189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41511 |
|
Vulnerability in c (CVE-2026-41511)
vulnerability in c (CVE-2026-41511). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42028 |
|
Path Traversal in path-traversal (CVE-2026-42028)
path traversal in path-traversal (CVE-2026-42028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42072 |
|
Vulnerability in graph (CVE-2026-42072)
vulnerability in graph (CVE-2026-42072). Successful exploitation can lead to full system takeover. Exploitable via ``NORNICDB_ADDRESS``.
|
| CVE-2026-42030 |
|
Vulnerability in CVE-2026-42030 (CVE-2026-42030)
vulnerability in CVE-2026-42030 (CVE-2026-42030). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41887 |
|
Path Traversal in CVE-2026-41887 (CVE-2026-41887)
path traversal in CVE-2026-41887 (CVE-2026-41887). Confidential information can be exposed externally.
|
| CVE-2026-38360 |
|
Path Traversal in path-traversal (CVE-2026-38360)
path traversal in path-traversal (CVE-2026-38360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44499 |
|
Vulnerability in zebrad (CVE-2026-44499)
vulnerability in zebrad (CVE-2026-44499). Risk of unauthorized operations or information disclosure. Exploitable via ``inv``. Mitigation: upgrade to `4.4.0` or later.
|
| CVE-2026-41886 |
|
Cross-Site Scripting (XSS) in CVE-2026-41886 (CVE-2026-41886)
cross-site scripting in CVE-2026-41886 (CVE-2026-41886). Data can be tampered with by attackers.
|
| CVE-2026-42794 |
|
Cross-Site Scripting (XSS) in CVE-2026-42794 (CVE-2026-42794)
cross-site scripting in CVE-2026-42794 (CVE-2026-42794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42353 |
|
Path Traversal in express (CVE-2026-42353)
path traversal in express (CVE-2026-42353). Confidential information can be exposed externally.
|
| CVE-2026-41591 |
|
Cross-Site Scripting (XSS) in CVE-2026-41591 (CVE-2026-41591)
cross-site scripting in CVE-2026-41591 (CVE-2026-41591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41885 |
|
Path Traversal in CVE-2026-41885 (CVE-2026-41885)
path traversal in CVE-2026-41885 (CVE-2026-41885). Risk of unauthorized operations or information disclosure.
|