Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13694 |
|
Vulnerability in c (CVE-2026-13694)
vulnerability in c (CVE-2026-13694). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16266 |
|
Vulnerability in CVE-2026-16266 (CVE-2026-16266)
vulnerability in CVE-2026-16266 (CVE-2026-16266). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16336 |
|
Open Redirect in CVE-2026-16336 (CVE-2026-16336)
vulnerability in CVE-2026-16336 (CVE-2026-16336). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63729 |
|
Use-After-Free in c (CVE-2026-63729)
vulnerability in c (CVE-2026-63729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16334 |
|
Vulnerability in sqli (CVE-2026-16334)
vulnerability in sqli (CVE-2026-16334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16332 |
|
Vulnerability in CVE-2026-16332 (CVE-2026-16332)
vulnerability in CVE-2026-16332 (CVE-2026-16332). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16331 |
|
Vulnerability in CVE-2026-16331 (CVE-2026-16331)
vulnerability in CVE-2026-16331 (CVE-2026-16331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16330 |
|
Vulnerability in CVE-2026-16330 (CVE-2026-16330)
vulnerability in CVE-2026-16330 (CVE-2026-16330). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16329 |
|
Vulnerability in CVE-2026-16329 (CVE-2026-16329)
vulnerability in CVE-2026-16329 (CVE-2026-16329). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16327 |
|
Vulnerability in CVE-2026-16327 (CVE-2026-16327)
vulnerability in CVE-2026-16327 (CVE-2026-16327). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59727 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-59727)
cross-site scripting in astro (CVE-2026-59727). Risk of unauthorized operations or information disclosure. Exploitable via ``attrs``. Mitigation: upgrade to `7.0.4` or later.
|
| CVE-2026-64625 |
|
OS Command Injection in c (CVE-2026-64625)
OS command injection in c (CVE-2026-64625). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51025 |
|
Cross-Site Scripting (XSS) in CVE-2026-51025 (CVE-2026-51025)
cross-site scripting in CVE-2026-51025 (CVE-2026-51025). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58624 |
|
Vulnerability in apache (CVE-2026-58624)
vulnerability in apache (CVE-2026-58624). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56624 |
|
Vulnerability in apache (CVE-2026-56624)
vulnerability in apache (CVE-2026-56624). Confidential information can be exposed externally.
|
| CVE-2026-56623 |
|
Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
|
| CVE-2026-56452 |
|
Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
|
| CVE-2026-53596 |
|
Vulnerability in laravel (CVE-2026-53596)
vulnerability in laravel (CVE-2026-53596). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53595 |
|
Vulnerability in laravel (CVE-2026-53595)
vulnerability in laravel (CVE-2026-53595). Confidential information can be exposed externally. Exploitable via `POST /user-setup/{hash}/{invite_sent_at}`.
|
| CVE-2026-53594 |
|
Path Traversal in laravel (CVE-2026-53594)
path traversal in laravel (CVE-2026-53594). Confidential information can be exposed externally.
|
| CVE-2026-47129 |
|
Vulnerability in CVE-2026-47129 (CVE-2026-47129)
vulnerability in CVE-2026-47129 (CVE-2026-47129). Data can be tampered with by attackers. Exploitable via ``activateUser``.
|
| CVE-2026-73422 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-73422)
cross-site scripting in astro (CVE-2026-73422). Risk of unauthorized operations or information disclosure. Exploitable via ``duration``. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-53593 |
|
Unrestricted File Upload in laravel (CVE-2026-53593)
vulnerability in laravel (CVE-2026-53593). Successful exploitation can lead to full system takeover. Exploitable via `POST /uploads/upload`.
|
| CVE-2026-53592 |
|
Vulnerability in laravel (CVE-2026-53592)
vulnerability in laravel (CVE-2026-53592). Risk of unauthorized operations or information disclosure. Exploitable via ``getQueryParam``.
|
| CVE-2026-53591 |
|
Authentication Bypass in laravel (CVE-2026-53591)
authentication bypass in laravel (CVE-2026-53591). Data can be tampered with by attackers. Exploitable via ``last_reply_from``.
|
| CVE-2026-44230 |
|
Cross-Site Scripting (XSS) in bestpractical (CVE-2026-44230)
cross-site scripting in bestpractical (CVE-2026-44230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44229 |
|
Cross-Site Scripting (XSS) in bestpractical (CVE-2026-44229)
cross-site scripting in bestpractical (CVE-2026-44229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64194 |
|
Vulnerability in c (CVE-2026-64194)
vulnerability in c (CVE-2026-64194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63769 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-63769)
SSRF in c (CVE-2026-63769). Confidential information can be exposed externally.
|
| CVE-2026-60026 |
|
Code Injection in CVE-2026-60026 (CVE-2026-60026)
code injection in CVE-2026-60026 (CVE-2026-60026). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8169 |
|
Vulnerability in CVE-2026-8169 (CVE-2026-8169)
vulnerability in CVE-2026-8169 (CVE-2026-8169). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26483 |
|
Cross-Site Scripting (XSS) in CVE-2026-26483 (CVE-2026-26483)
cross-site scripting in CVE-2026-26483 (CVE-2026-26483). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48812 |
|
Authentication Bypass in laravel (CVE-2026-48812)
authentication bypass in laravel (CVE-2026-48812). Confidential information can be exposed externally. Exploitable via ``token_type``.
|
| CVE-2026-44228 |
|
Cross-Site Scripting (XSS) in bestpractical (CVE-2026-44228)
cross-site scripting in bestpractical (CVE-2026-44228). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44227 |
|
Cross-Site Scripting (XSS) in bestpractical (CVE-2026-44227)
cross-site scripting in bestpractical (CVE-2026-44227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45295 |
|
Vulnerability in laravel (CVE-2026-45295)
vulnerability in laravel (CVE-2026-45295). Risk of unauthorized operations or information disclosure. Exploitable via `GET /thread/read/{conversation_id}/{thread_id}`.
|
| CVE-2026-39878 |
|
Cross-Site Scripting (XSS) in CVE-2026-39878 (CVE-2026-39878)
cross-site scripting in CVE-2026-39878 (CVE-2026-39878). Confidential information can be exposed externally. Mitigation: upgrade to `1.11.40` or later.
|
| CVE-2026-34239 |
|
Vulnerability in CVE-2026-34239 (CVE-2026-34239)
vulnerability in CVE-2026-34239 (CVE-2026-34239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64190 |
|
Vulnerability in c (CVE-2026-64190)
vulnerability in c (CVE-2026-64190). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64191 |
|
Out-of-Bounds Read in c (CVE-2026-64191)
vulnerability in c (CVE-2026-64191). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64187 |
|
Vulnerability in c (CVE-2026-64187)
vulnerability in c (CVE-2026-64187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64188 |
|
Use-After-Free in c (CVE-2026-64188)
vulnerability in c (CVE-2026-64188). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64189 |
|
Vulnerability in c (CVE-2026-64189)
vulnerability in c (CVE-2026-64189). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58484 |
|
Path Traversal in network-ai (CVE-2026-58484)
path traversal in network-ai (CVE-2026-58484). Data can be tampered with by attackers. Exploitable via ``path``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-58482 |
|
Cross-Site Request Forgery (CSRF) in ssrf (CVE-2026-58482)
vulnerability in ssrf (CVE-2026-58482). Data can be tampered with by attackers. Exploitable via `POST /approvals/`. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-58481 |
|
Path Traversal in network-ai (CVE-2026-58481)
path traversal in network-ai (CVE-2026-58481). Confidential information can be exposed externally. Exploitable via ``AgentRuntime``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-58414 |
|
Path Traversal in network-ai (CVE-2026-58414)
path traversal in network-ai (CVE-2026-58414). Confidential information can be exposed externally. Exploitable via ``lstatSync``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-58413 |
|
Path Traversal in network-ai (CVE-2026-58413)
path traversal in network-ai (CVE-2026-58413). Confidential information can be exposed externally. Exploitable via ``backupId``. Mitigation: upgrade to `5.12.2` or later.
|
| CVE-2026-50743 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-50743)
vulnerability in csrf (CVE-2026-50743). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47275 |
|
Vulnerability in c (CVE-2026-47275)
vulnerability in c (CVE-2026-47275). Risk of unauthorized operations or information disclosure. Exploitable via ``prop``.
|