Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48371 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48371)
cross-site scripting in adobe (CVE-2026-48371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48355 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48355)
cross-site scripting in adobe (CVE-2026-48355). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48263 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48263)
cross-site scripting in adobe (CVE-2026-48263). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48347 |
|
OS Command Injection in c (CVE-2026-48347)
OS command injection in c (CVE-2026-48347). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48345 |
|
OS Command Injection in c (CVE-2026-48345)
OS command injection in c (CVE-2026-48345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48259 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-48259)
SSRF in c (CVE-2026-48259). Confidential information can be exposed externally.
|
| CVE-2026-48261 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48261)
cross-site scripting in adobe (CVE-2026-48261). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48254 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48254)
cross-site scripting in adobe (CVE-2026-48254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48255 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48255)
cross-site scripting in adobe (CVE-2026-48255). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48260 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48260)
cross-site scripting in adobe (CVE-2026-48260). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48262 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48262)
cross-site scripting in adobe (CVE-2026-48262). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48257 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48257)
cross-site scripting in adobe (CVE-2026-48257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48253 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48253)
cross-site scripting in adobe (CVE-2026-48253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47999 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-47999)
cross-site scripting in adobe (CVE-2026-47999). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47995 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-47995)
cross-site scripting in adobe (CVE-2026-47995). Confidential information can be exposed externally.
|
| CVE-2026-47994 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-47994)
cross-site scripting in adobe (CVE-2026-47994). Confidential information can be exposed externally.
|
| CVE-2026-15714 |
|
Out-of-Bounds Read in c (CVE-2026-15714)
vulnerability in c (CVE-2026-15714). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50649 |
|
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
|
| CVE-2026-50650 |
|
Code Injection in Microsoft.WindowsDesktop.App.Runtime.win-x64 (CVE-2026-50650)
code injection in Microsoft.WindowsDesktop.App.Runtime.win-x64 (CVE-2026-50650). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-50651 |
|
Vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-50651)
vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-50651). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-50659 |
|
Vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-50659)
vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-50659). Data can be tampered with by attackers. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-50524 |
|
Vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-50524)
vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-50524). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-50525 |
|
Vulnerability in System.Security.Cryptography.Xml (CVE-2026-50525)
vulnerability in System.Security.Cryptography.Xml (CVE-2026-50525). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.4` or later.
|
| CVE-2026-50526 |
|
Vulnerability in Microsoft.NET.Build.Containers (CVE-2026-50526)
vulnerability in Microsoft.NET.Build.Containers (CVE-2026-50526). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-50527 |
|
Vulnerability in System.Security.Cryptography.Xml (CVE-2026-50527)
vulnerability in System.Security.Cryptography.Xml (CVE-2026-50527). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.4` or later.
|
| CVE-2026-50528 |
|
Vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-50528)
vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-50528). Data can be tampered with by attackers. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-50646 |
|
Unsafe Deserialization in csharp (CVE-2026-50646)
vulnerability in csharp (CVE-2026-50646). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50648 |
|
Vulnerability in System.Security.Cryptography.Xml (CVE-2026-50648)
vulnerability in System.Security.Cryptography.Xml (CVE-2026-50648). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.4` or later.
|
| CVE-2026-54335 |
|
Vulnerability in @feathersjs/commons (CVE-2026-54335)
vulnerability in @feathersjs/commons (CVE-2026-54335). Risk of unauthorized operations or information disclosure. Exploitable via ``source``. Mitigation: upgrade to `5.0.45` or later.
|
| CVE-2026-47300 |
|
Vulnerability in Microsoft.AspNetCore.Authentication.Negotiate (CVE-2026-47300)
vulnerability in Microsoft.AspNetCore.Authentication.Negotiate (CVE-2026-47300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-47302 |
|
Vulnerability in System.Security.Cryptography.Xml (CVE-2026-47302)
vulnerability in System.Security.Cryptography.Xml (CVE-2026-47302). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.4` or later.
|
| CVE-2026-47303 |
|
Vulnerability in Microsoft.AspNetCore.Authentication.Negotiate (CVE-2026-47303)
vulnerability in Microsoft.AspNetCore.Authentication.Negotiate (CVE-2026-47303). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-47304 |
|
Vulnerability in System.Security.Cryptography.Xml (CVE-2026-47304)
vulnerability in System.Security.Cryptography.Xml (CVE-2026-47304). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.4` or later.
|
| CVE-2026-15712 |
|
Out-of-Bounds Read in c (CVE-2026-15712)
vulnerability in c (CVE-2026-15712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15715 |
|
Cross-Site Scripting (XSS) in CVE-2026-15715 (CVE-2026-15715)
cross-site scripting in CVE-2026-15715 (CVE-2026-15715). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57108 |
|
Vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-57108)
vulnerability in Microsoft.NetCore.App.Runtime.linux-arm (CVE-2026-57108). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.29` or later.
|
| CVE-2026-59888 |
|
Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-59888)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-59888). Risk of unauthorized operations or information disclosure. Exploitable via ``PropertyNamingStrategy``. Mitigation: upgrade to `2.21.4` or later.
|
| CVE-2026-59886 |
|
Vulnerability in pyasn1 (CVE-2026-59886)
vulnerability in pyasn1 (CVE-2026-59886). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.4` or later.
|
| CVE-2026-59891 |
|
Vulnerability in @sigstore/oci (CVE-2026-59891)
vulnerability in @sigstore/oci (CVE-2026-59891). Successful exploitation can lead to full system takeover. Exploitable via ``cr.io``. Mitigation: upgrade to `0.7.1` or later.
|
| CVE-2026-59885 |
|
Vulnerability in pyasn1 (CVE-2026-59885)
vulnerability in pyasn1 (CVE-2026-59885). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.4` or later.
|
| CVE-2026-59884 |
|
Vulnerability in pyssn1 (CVE-2026-59884)
vulnerability in pyssn1 (CVE-2026-59884). Risk of unauthorized operations or information disclosure. Exploitable via ``ValueError``. Mitigation: upgrade to `0.6.4` or later.
|
| CVE-2026-59200 |
|
Vulnerability in Pillow (CVE-2026-59200)
vulnerability in Pillow (CVE-2026-59200). Risk of unauthorized operations or information disclosure. Exploitable via ``PdfParser.py``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-59197 |
|
Vulnerability in Pillow (CVE-2026-59197)
vulnerability in Pillow (CVE-2026-59197). Risk of unauthorized operations or information disclosure. Exploitable via ``INT_MAX``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-56170 |
|
Vulnerability in Microsoft.AspNetCore.App.Runtime.linux-arm (CVE-2026-56170)
vulnerability in Microsoft.AspNetCore.App.Runtime.linux-arm (CVE-2026-56170). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.26` or later.
|
| CVE-2026-54433 |
|
Cross-Site Scripting (XSS) in roundcube (CVE-2026-54433)
cross-site scripting in roundcube (CVE-2026-54433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54058 |
|
Out-of-Bounds Read in pillow (CVE-2026-54058)
vulnerability in pillow (CVE-2026-54058). Confidential information can be exposed externally. Exploitable via ``raw``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-50506 |
|
Vulnerability in csharp (CVE-2026-50506)
vulnerability in csharp (CVE-2026-50506). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45646 |
|
Vulnerability in csharp (CVE-2026-45646)
vulnerability in csharp (CVE-2026-45646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36214 |
|
Cross-Site Scripting (XSS) in CVE-2026-36214 (CVE-2026-36214)
cross-site scripting in CVE-2026-36214 (CVE-2026-36214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15703 |
|
Vulnerability in sqli (CVE-2026-15703)
vulnerability in sqli (CVE-2026-15703). Risk of unauthorized operations or information disclosure.
|