Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-54901 |
|
Use-After-Free in oj (CVE-2026-54901)
vulnerability in oj (CVE-2026-54901). Risk of unauthorized operations or information disclosure. Exploitable via ``array_class``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-54900 |
|
Use-After-Free in oj (CVE-2026-54900)
vulnerability in oj (CVE-2026-54900). Risk of unauthorized operations or information disclosure. Exploitable via ``create_id``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-54784 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54784)
vulnerability in CoreWCF.Primitives (CVE-2026-54784). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54783 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54783)
vulnerability in CoreWCF.Primitives (CVE-2026-54783). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54782 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54782)
vulnerability in CoreWCF.Primitives (CVE-2026-54782). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54781 |
|
Authentication Bypass in CoreWCF.Primitives (CVE-2026-54781)
authentication bypass in CoreWCF.Primitives (CVE-2026-54781). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54780 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54780)
vulnerability in CoreWCF.Primitives (CVE-2026-54780). Risk of unauthorized operations or information disclosure. Exploitable via ``SignatureMethod``. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54779 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54779)
vulnerability in CoreWCF.Primitives (CVE-2026-54779). Data can be tampered with by attackers. Exploitable via ``ITokenReplayCache``. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54778 |
|
Vulnerability in CoreWCF.UnixDomainSocket (CVE-2026-54778)
vulnerability in CoreWCF.UnixDomainSocket (CVE-2026-54778). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54777 |
|
Vulnerability in CoreWCF.NetNamedPipe (CVE-2026-54777)
vulnerability in CoreWCF.NetNamedPipe (CVE-2026-54777). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54776 |
|
Vulnerability in CoreWCF.UnixDomainSocket (CVE-2026-54776)
vulnerability in CoreWCF.UnixDomainSocket (CVE-2026-54776). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54775 |
|
Vulnerability in CoreWCF.Kafka (CVE-2026-54775)
vulnerability in CoreWCF.Kafka (CVE-2026-54775). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54774 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54774)
vulnerability in CoreWCF.Primitives (CVE-2026-54774). Confidential information can be exposed externally. Exploitable via ``BinarySecretSecurityToken``. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54773 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54773)
vulnerability in CoreWCF.Primitives (CVE-2026-54773). Data can be tampered with by attackers. Exploitable via ``KeyInfo``. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-54772 |
|
Vulnerability in CoreWCF.NetFramingBase (CVE-2026-54772)
vulnerability in CoreWCF.NetFramingBase (CVE-2026-54772). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-55865 |
|
Vulnerability in python-liquid (CVE-2026-55865)
vulnerability in python-liquid (CVE-2026-55865). Risk of unauthorized operations or information disclosure. Exploitable via ``liquid.TokenStream.eof``. Mitigation: upgrade to `2.2.1` or later.
|
| CVE-2026-49342 |
|
Path Traversal in yard (CVE-2026-49342)
path traversal in yard (CVE-2026-49342). Risk of unauthorized operations or information disclosure. Exploitable via ``adapter.document_root``. Mitigation: upgrade to `0.9.44` or later.
|
| CVE-2026-54898 |
|
Use-After-Free in oj (CVE-2026-54898)
vulnerability in oj (CVE-2026-54898). Risk of unauthorized operations or information disclosure. Exploitable via ``hash_start``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-54897 |
|
Use-After-Free in oj (CVE-2026-54897)
vulnerability in oj (CVE-2026-54897). Risk of unauthorized operations or information disclosure. Exploitable via ``each_value``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-54896 |
|
Vulnerability in oj (CVE-2026-54896)
vulnerability in oj (CVE-2026-54896). Risk of unauthorized operations or information disclosure. Exploitable via ``Oj.dump``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-55778 |
|
Unrestricted File Upload in parse-server (CVE-2026-55778)
vulnerability in parse-server (CVE-2026-55778). Risk of unauthorized operations or information disclosure. Exploitable via ``fileUpload.fileExtensions``. Mitigation: upgrade to `8.6.81` or later.
|
| CVE-2026-54592 |
|
Out-of-Bounds Read in oj (CVE-2026-54592)
vulnerability in oj (CVE-2026-54592). Risk of unauthorized operations or information disclosure. Exploitable via ``doc_each_child``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-54527 |
|
Cross-Site Scripting (XSS) in jupyterlab-git (CVE-2026-54527)
cross-site scripting in jupyterlab-git (CVE-2026-54527). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/terminals`. Mitigation: upgrade to `0.54.0` or later.
|
| CVE-2026-54500 |
|
Out-of-Bounds Read in oj (CVE-2026-54500)
vulnerability in oj (CVE-2026-54500). Risk of unauthorized operations or information disclosure. Exploitable via ``Oj.load``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-54499 |
|
Unsafe Deserialization in stanza (CVE-2026-54499)
vulnerability in stanza (CVE-2026-54499). Successful exploitation can lead to full system takeover. Exploitable via ``pickle.UnpicklingError``. Mitigation: upgrade to `1.12.2` or later.
|
| CVE-2026-54297 |
|
Vulnerability in faraday (CVE-2026-54297)
vulnerability in faraday (CVE-2026-54297). Risk of unauthorized operations or information disclosure. Exploitable via ``Hash``. Mitigation: upgrade to `1.10.6` or later.
|
| CVE-2026-54502 |
|
Vulnerability in oj (CVE-2026-54502)
vulnerability in oj (CVE-2026-54502). Risk of unauthorized operations or information disclosure. Exploitable via ``Oj.dump``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-49216 |
|
Cross-Site Scripting (XSS) in symfony/ux-autocomplete (CVE-2026-49216)
cross-site scripting in symfony/ux-autocomplete (CVE-2026-49216). Risk of unauthorized operations or information disclosure. Exploitable via ``text``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49215 |
|
Cross-Site Request Forgery (CSRF) in symfony/ux-live-component (CVE-2026-49215)
vulnerability in symfony/ux-live-component (CVE-2026-49215). Risk of unauthorized operations or information disclosure. Exploitable via ``Accept``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49212 |
|
Vulnerability in symfony/ux-live-component (CVE-2026-49212)
vulnerability in symfony/ux-live-component (CVE-2026-49212). Data can be tampered with by attackers. Exploitable via ``propsFromParent``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49211 |
|
Information Disclosure in symfony/ux-autocomplete (CVE-2026-49211)
vulnerability in symfony/ux-autocomplete (CVE-2026-49211). Confidential information can be exposed externally. Exploitable via ``LIKE``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49210 |
|
Cross-Site Scripting (XSS) in symfony/ux-live-component (CVE-2026-49210)
cross-site scripting in symfony/ux-live-component (CVE-2026-49210). Risk of unauthorized operations or information disclosure. Exploitable via ``LiveComponentSubscriber``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49209 |
|
Vulnerability in symfony/ux-live-component (CVE-2026-49209)
vulnerability in symfony/ux-live-component (CVE-2026-49209). Risk of unauthorized operations or information disclosure. Exploitable via ``actions``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-54899 |
|
Use-After-Free in oj (CVE-2026-54899)
vulnerability in oj (CVE-2026-54899). Risk of unauthorized operations or information disclosure. Exploitable via ``symbol_keys``. Mitigation: upgrade to `3.17.3` or later.
|
| CVE-2026-49208 |
|
Vulnerability in symfony/ux-live-component (CVE-2026-49208)
vulnerability in symfony/ux-live-component (CVE-2026-49208). Risk of unauthorized operations or information disclosure. Exploitable via ``DateTimeInterface``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-23879 |
|
Vulnerability in py7zr (CVE-2026-23879)
vulnerability in py7zr (CVE-2026-23879). Successful exploitation can lead to full system takeover. Exploitable via ``py7zr``. Mitigation: upgrade to `1.1.3` or later.
|
| CVE-2026-49293 |
|
Vulnerability in js-toml (CVE-2026-49293)
vulnerability in js-toml (CVE-2026-49293). Risk of unauthorized operations or information disclosure. Exploitable via ``parseBigInt``. Mitigation: upgrade to `1.1.1` or later.
|
| CVE-2019-25762 |
|
Vulnerability in joomboost (CVE-2019-25762)
vulnerability in joomboost (CVE-2019-25762). Confidential information can be exposed externally.
|
| CVE-2019-25760 |
|
Vulnerability in joomtech (CVE-2019-25760)
vulnerability in joomtech (CVE-2019-25760). Confidential information can be exposed externally.
|
| CVE-2019-25761 |
|
SQL Injection in sqli (CVE-2019-25761)
SQL injection in sqli (CVE-2019-25761). Confidential information can be exposed externally.
|
| CVE-2019-25758 |
|
Unrestricted File Upload in wdmtech (CVE-2019-25758)
vulnerability in wdmtech (CVE-2019-25758). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25753 |
|
SQL Injection in sqli (CVE-2019-25753)
SQL injection in sqli (CVE-2019-25753). Confidential information can be exposed externally.
|
| CVE-2019-25752 |
|
SQL Injection in sqli (CVE-2019-25752)
SQL injection in sqli (CVE-2019-25752). Confidential information can be exposed externally.
|
| CVE-2017-20281 |
|
SQL Injection in sqli (CVE-2017-20281)
SQL injection in sqli (CVE-2017-20281). Confidential information can be exposed externally.
|
| CVE-2017-20282 |
|
SQL Injection in sqli (CVE-2017-20282)
SQL injection in sqli (CVE-2017-20282). Confidential information can be exposed externally.
|
| CVE-2017-20270 |
|
SQL Injection in sqli (CVE-2017-20270)
SQL injection in sqli (CVE-2017-20270). Confidential information can be exposed externally.
|
| CVE-2017-20271 |
|
SQL Injection in sqli (CVE-2017-20271)
SQL injection in sqli (CVE-2017-20271). Confidential information can be exposed externally.
|
| CVE-2017-20274 |
|
SQL Injection in sqli (CVE-2017-20274)
SQL injection in sqli (CVE-2017-20274). Confidential information can be exposed externally.
|
| CVE-2017-20275 |
|
SQL Injection in sqli (CVE-2017-20275)
SQL injection in sqli (CVE-2017-20275). Confidential information can be exposed externally.
|
| CVE-2017-20279 |
|
SQL Injection in sqli (CVE-2017-20279)
SQL injection in sqli (CVE-2017-20279). Confidential information can be exposed externally.
|