Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-63640 |
|
Information Disclosure in magicmirror (CVE-2026-63640)
vulnerability in magicmirror (CVE-2026-63640). Risk of unauthorized operations or information disclosure. Exploitable via ``magicmirror``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-55182 |
|
Command Injection in librenms/librenms (CVE-2026-55182)
command injection in librenms/librenms (CVE-2026-55182). Risk of unauthorized operations or information disclosure. Exploitable via ``exec``. Mitigation: upgrade to `26.5.0` or later.
|
| CVE-2026-63643 |
|
Vulnerability in magicmirror (CVE-2026-63643)
vulnerability in magicmirror (CVE-2026-63643). Risk of unauthorized operations or information disclosure. Exploitable via ``ADD_CALENDAR``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-63642 |
|
SSRF (Server-Side Request Forgery) in magicmirror (CVE-2026-63642)
SSRF in magicmirror (CVE-2026-63642). Risk of unauthorized operations or information disclosure. Exploitable via ``CHECK_ARTICLE_URL``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-63641 |
|
Vulnerability in magicmirror (CVE-2026-63641)
vulnerability in magicmirror (CVE-2026-63641). Risk of unauthorized operations or information disclosure. Exploitable via ``ipWhitelist``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-52606 |
|
Cross-Site Scripting (XSS) in CVE-2026-52606 (CVE-2026-52606)
cross-site scripting in CVE-2026-52606 (CVE-2026-52606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57580 |
|
Vulnerability in c (CVE-2026-57580)
vulnerability in c (CVE-2026-57580). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50126 |
|
Out-of-Bounds Read in cpp (CVE-2026-50126)
vulnerability in cpp (CVE-2026-50126). Risk of unauthorized operations or information disclosure. Exploitable via ``polygon.u.array.length``.
|
| CVE-2026-49228 |
|
Vulnerability in CVE-2026-49228 (CVE-2026-49228)
vulnerability in CVE-2026-49228 (CVE-2026-49228). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49225 |
|
Vulnerability in CVE-2026-49225 (CVE-2026-49225)
vulnerability in CVE-2026-49225 (CVE-2026-49225). Confidential information can be exposed externally.
|
| CVE-2026-49224 |
|
Vulnerability in CVE-2026-49224 (CVE-2026-49224)
vulnerability in CVE-2026-49224 (CVE-2026-49224). Confidential information can be exposed externally.
|
| CVE-2026-61634 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-61634)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-61634). Risk of unauthorized operations or information disclosure. Exploitable via ``frame_max``. Mitigation: upgrade to `5.33.0` or later.
|
| CVE-2026-63336 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-63336)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-63336). Risk of unauthorized operations or information disclosure. Exploitable via ``TrustEverythingTrustManager``. Mitigation: upgrade to `5.33.0` or later.
|
| CVE-2026-63335 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-63335)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-63335). Risk of unauthorized operations or information disclosure. Exploitable via ``UnsupportedOperationException``. Mitigation: upgrade to `5.31.0` or later.
|
| CVE-2026-63337 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-63337)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-63337). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonRpcClient``. Mitigation: upgrade to `5.33.0` or later.
|
| CVE-2026-69219 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-69219)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-69219). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `5.33.1` or later.
|
| CVE-2026-69220 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-69220)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-69220). Risk of unauthorized operations or information disclosure. Exploitable via ``connection.start``. Mitigation: upgrade to `5.33.1` or later.
|
| CVE-2026-55839 |
|
Cross-Site Scripting (XSS) in io.kestra:kestra (CVE-2026-55839)
cross-site scripting in io.kestra:kestra (CVE-2026-55839). Confidential information can be exposed externally. Exploitable via ``onclick``. Mitigation: upgrade to `1.3.24` or later.
|
| CVE-2026-75926 |
|
Vulnerability in CVE-2026-75926 (CVE-2026-75926)
vulnerability in CVE-2026-75926 (CVE-2026-75926). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75915 |
|
Information Disclosure in CVE-2026-75915 (CVE-2026-75915)
vulnerability in CVE-2026-75915 (CVE-2026-75915). Confidential information can be exposed externally.
|
| CVE-2026-75904 |
|
Out-of-Bounds Read in cpp (CVE-2026-75904)
vulnerability in cpp (CVE-2026-75904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75858 |
|
Code Injection in CVE-2026-75858 (CVE-2026-75858)
code injection in CVE-2026-75858 (CVE-2026-75858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.64` or later.
|
| CVE-2026-71477 |
|
Vulnerability in CVE-2026-71477 (CVE-2026-71477)
vulnerability in CVE-2026-71477 (CVE-2026-71477). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73073 |
|
Code Injection in c (CVE-2026-73073)
code injection in c (CVE-2026-73073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49227 |
|
Vulnerability in CVE-2026-49227 (CVE-2026-49227)
vulnerability in CVE-2026-49227 (CVE-2026-49227). Data can be tampered with by attackers.
|
| CVE-2026-49226 |
|
Vulnerability in CVE-2026-49226 (CVE-2026-49226)
vulnerability in CVE-2026-49226 (CVE-2026-49226). Data can be tampered with by attackers.
|
| CVE-2026-49221 |
|
Vulnerability in CVE-2026-49221 (CVE-2026-49221)
vulnerability in CVE-2026-49221 (CVE-2026-49221). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47245 |
|
Vulnerability in CVE-2026-47245 (CVE-2026-47245)
vulnerability in CVE-2026-47245 (CVE-2026-47245). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46482 |
|
Vulnerability in c (CVE-2026-46482)
vulnerability in c (CVE-2026-46482). Risk of unauthorized operations or information disclosure. Exploitable via ``question_id``.
|
| CVE-2026-45734 |
|
Vulnerability in CVE-2026-45734 (CVE-2026-45734)
vulnerability in CVE-2026-45734 (CVE-2026-45734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45129 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-45129 (CVE-2026-45129)
vulnerability in CVE-2026-45129 (CVE-2026-45129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45128 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-45128 (CVE-2026-45128)
vulnerability in CVE-2026-45128 (CVE-2026-45128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45127 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-45127 (CVE-2026-45127)
vulnerability in CVE-2026-45127 (CVE-2026-45127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45126 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-45126)
vulnerability in csrf (CVE-2026-45126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45125 |
|
Vulnerability in CVE-2026-45125 (CVE-2026-45125)
vulnerability in CVE-2026-45125 (CVE-2026-45125). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45124 |
|
Vulnerability in CVE-2026-45124 (CVE-2026-45124)
vulnerability in CVE-2026-45124 (CVE-2026-45124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45123 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-45123 (CVE-2026-45123)
SSRF in CVE-2026-45123 (CVE-2026-45123). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45122 |
|
Authorization Flaw in CVE-2026-45122 (CVE-2026-45122)
vulnerability in CVE-2026-45122 (CVE-2026-45122). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45121 |
|
Authorization Flaw in CVE-2026-45121 (CVE-2026-45121)
vulnerability in CVE-2026-45121 (CVE-2026-45121). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45120 |
|
Vulnerability in CVE-2026-45120 (CVE-2026-45120)
vulnerability in CVE-2026-45120 (CVE-2026-45120). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45119 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-45119 (CVE-2026-45119)
vulnerability in CVE-2026-45119 (CVE-2026-45119). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45118 |
|
Vulnerability in CVE-2026-45118 (CVE-2026-45118)
vulnerability in CVE-2026-45118 (CVE-2026-45118). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-45117 |
|
Code Injection in CVE-2026-45117 (CVE-2026-45117)
code injection in CVE-2026-45117 (CVE-2026-45117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45116 |
|
Cross-Site Scripting (XSS) in CVE-2026-45116 (CVE-2026-45116)
cross-site scripting in CVE-2026-45116 (CVE-2026-45116). Confidential information can be exposed externally.
|
| CVE-2026-45115 |
|
Cross-Site Scripting (XSS) in CVE-2026-45115 (CVE-2026-45115)
cross-site scripting in CVE-2026-45115 (CVE-2026-45115). Confidential information can be exposed externally.
|
| CVE-2026-74012 |
|
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
|
| CVE-2026-75872 |
|
Vulnerability in c (CVE-2026-75872)
vulnerability in c (CVE-2026-75872). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71539 |
|
Vulnerability in CVE-2026-71539 (CVE-2026-71539)
vulnerability in CVE-2026-71539 (CVE-2026-71539). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73376 |
|
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
|
| CVE-2026-73380 |
|
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
|