Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-60765 |
|
Vulnerability in c (CVE-2026-60765)
vulnerability in c (CVE-2026-60765). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18676 |
|
Vulnerability in c (CVE-2026-18676)
vulnerability in c (CVE-2026-18676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19418 |
|
Vulnerability in CVE-2026-19418 (CVE-2026-19418)
vulnerability in CVE-2026-19418 (CVE-2026-19418). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66298 |
|
Vulnerability in livebook (CVE-2026-66298)
vulnerability in livebook (CVE-2026-66298). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70599 |
|
Vulnerability in electron (CVE-2026-70599)
vulnerability in electron (CVE-2026-70599). Confidential information can be exposed externally. Exploitable via ``requestingOrigin``. Mitigation: upgrade to `42.0.0-beta.1` or later.
|
| CVE-2026-69245 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-69245)
vulnerability in guzzlehttp/guzzle (CVE-2026-69245). Risk of unauthorized operations or information disclosure. Exploitable via ``Domain``. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-66420 |
|
Vulnerability in CVE-2026-66420 (CVE-2026-66420)
vulnerability in CVE-2026-66420 (CVE-2026-66420). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63118 |
|
Vulnerability in mcp (CVE-2026-63118)
vulnerability in mcp (CVE-2026-63118). Risk of unauthorized operations or information disclosure. Exploitable via ``mcp``. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-54605 |
|
Information Disclosure in oauth (CVE-2026-54605)
vulnerability in oauth (CVE-2026-54605). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `1.1.6` or later.
|
| CVE-2026-73419 |
|
Vulnerability in @auth/core (CVE-2026-73419)
vulnerability in @auth/core (CVE-2026-73419). Confidential information can be exposed externally. Exploitable via ``state``. Mitigation: upgrade to `0.41.3` or later.
|
| CVE-2026-59950 |
|
Vulnerability in mcp (CVE-2026-59950)
vulnerability in mcp (CVE-2026-59950). Confidential information can be exposed externally. Exploitable via ``mcp.server.websocket.websocket_server``. Mitigation: upgrade to `1.28.1` or later.
|
| CVE-2026-59883 |
|
Information Disclosure in guzzlehttp/guzzle (CVE-2026-59883)
vulnerability in guzzlehttp/guzzle (CVE-2026-59883). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.12.3` or later.
|
| CVE-2026-58266 |
|
Path Traversal in aqt (CVE-2026-58266)
path traversal in aqt (CVE-2026-58266). Confidential information can be exposed externally. Exploitable via ``getImageForOcclusion``. Mitigation: upgrade to `25.9.4` or later.
|
| CVE-2026-42341 |
|
Vulnerability in CVE-2026-42341 (CVE-2026-42341)
vulnerability in CVE-2026-42341 (CVE-2026-42341). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55767 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-55767)
vulnerability in guzzlehttp/guzzle (CVE-2026-55767). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.12.1` or later.
|
| CVE-2026-55669 |
|
Vulnerability in github.com/zitadel/zitadel (CVE-2026-55669)
vulnerability in github.com/zitadel/zitadel (CVE-2026-55669). Risk of unauthorized operations or information disclosure. Exploitable via ``iss``. Mitigation: upgrade to `1.80.0-v2.20.0.20260615132747-d184e976fc79` or later.
|
| CVE-2026-50168 |
|
Vulnerability in @angular/platform-server (CVE-2026-50168)
vulnerability in @angular/platform-server (CVE-2026-50168). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `21.2.15` or later.
|
| CVE-2026-48063 |
|
Vulnerability in baileys (CVE-2026-48063)
vulnerability in baileys (CVE-2026-48063). Risk of unauthorized operations or information disclosure. Exploitable via ``messages.upsert``. Mitigation: upgrade to `7.0.0-rc12` or later.
|
| CVE-2026-11693 |
|
Vulnerability in c (CVE-2026-11693)
vulnerability in c (CVE-2026-11693). Confidential information can be exposed externally.
|
| CVE-2026-47265 |
|
Vulnerability in aiohttp (CVE-2026-47265)
vulnerability in aiohttp (CVE-2026-47265). Confidential information can be exposed externally. Exploitable via ``cookies``. Mitigation: upgrade to `3.14.0` or later.
|
| CVE-2026-44698 |
|
Code Injection in CVE-2026-44698 (CVE-2026-44698)
code injection in CVE-2026-44698 (CVE-2026-44698). Successful exploitation can lead to full system takeover. Exploitable via ``window.externalApp``. Mitigation: upgrade to `2026.4.1` or later.
|
| CVE-2026-46685 |
|
Vulnerability in CVE-2026-46685 (CVE-2026-46685)
vulnerability in CVE-2026-46685 (CVE-2026-46685). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-46701 |
|
Vulnerability in network-ai (CVE-2026-46701)
vulnerability in network-ai (CVE-2026-46701). Data can be tampered with by attackers. Exploitable via `POST /mcp`. Mitigation: upgrade to `5.4.5` or later.
|
| CVE-2026-41886 |
|
Vulnerability in locize (CVE-2026-41886)
vulnerability in locize (CVE-2026-41886). Data can be tampered with by attackers. Exploitable via ``locize``. Mitigation: upgrade to `4.0.21` or later.
|
| CVE-2026-42559 |
|
Vulnerability in rmcp (CVE-2026-42559)
vulnerability in rmcp (CVE-2026-42559). Successful exploitation can lead to full system takeover. Exploitable via ``rmcp``. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-35568 |
|
Vulnerability in lfprojects (CVE-2026-35568)
vulnerability in lfprojects (CVE-2026-35568). Data can be tampered with by attackers. Mitigation: upgrade to `1.0.0` or later.
|
| CVE-2026-34777 |
|
Vulnerability in electronjs (CVE-2026-34777)
vulnerability in electronjs (CVE-2026-34777). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34359 |
|
Vulnerability in hapifhir (CVE-2026-34359)
vulnerability in hapifhir (CVE-2026-34359). Confidential information can be exposed externally.
|
| CVE-2026-34373 |
|
Vulnerability in parseplatform (CVE-2026-34373)
vulnerability in parseplatform (CVE-2026-34373). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8793 |
|
Vulnerability in accellion (CVE-2017-8793)
vulnerability in accellion (CVE-2017-8793). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5858 |
|
Vulnerability in conversejs (CVE-2017-5858)
vulnerability in conversejs (CVE-2017-5858). Data can be tampered with by attackers.
|