Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: products Clear
ID Title
CVE-2026-15903 Out-of-Bounds Read in google (CVE-2026-15903)
vulnerability in google (CVE-2026-15903). Successful exploitation can lead to full system takeover.
CVE-2026-15904 Use-After-Free in google (CVE-2026-15904)
vulnerability in google (CVE-2026-15904). Successful exploitation can lead to full system takeover.
CVE-2026-15905 Use-After-Free in google (CVE-2026-15905)
vulnerability in google (CVE-2026-15905). Successful exploitation can lead to full system takeover.
CVE-2026-15902 Use-After-Free in google (CVE-2026-15902)
vulnerability in google (CVE-2026-15902). Successful exploitation can lead to full system takeover.
CVE-2026-56624 Vulnerability in apache (CVE-2026-56624)
vulnerability in apache (CVE-2026-56624). Confidential information can be exposed externally.
CVE-2026-56623 Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
CVE-2026-56452 Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
CVE-2026-53593 Unrestricted File Upload in laravel (CVE-2026-53593)
vulnerability in laravel (CVE-2026-53593). Successful exploitation can lead to full system takeover. Exploitable via `POST /uploads/upload`.
CVE-2026-53591 Authentication Bypass in laravel (CVE-2026-53591)
authentication bypass in laravel (CVE-2026-53591). Data can be tampered with by attackers. Exploitable via ``last_reply_from``.
CVE-2026-48812 Authentication Bypass in laravel (CVE-2026-48812)
authentication bypass in laravel (CVE-2026-48812). Confidential information can be exposed externally. Exploitable via ``token_type``.
CVE-2026-62418 SSRF (Server-Side Request Forgery) in apache (CVE-2026-62418)
SSRF in apache (CVE-2026-62418). Confidential information can be exposed externally.
CVE-2026-16228 Vulnerability in sqli (CVE-2026-16228)
vulnerability in sqli (CVE-2026-16228). Risk of unauthorized operations or information disclosure.
CVE-2026-16227 Vulnerability in sqli (CVE-2026-16227)
vulnerability in sqli (CVE-2026-16227). Risk of unauthorized operations or information disclosure.
CVE-2026-16154 Vulnerability in sqli (CVE-2026-16154)
vulnerability in sqli (CVE-2026-16154). Risk of unauthorized operations or information disclosure.
CVE-2026-16152 Vulnerability in sqli (CVE-2026-16152)
vulnerability in sqli (CVE-2026-16152). Risk of unauthorized operations or information disclosure.
CVE-2026-59173 Vulnerability in apache (CVE-2026-59173)
vulnerability in apache (CVE-2026-59173). Risk of unauthorized operations or information disclosure.
CVE-2026-13445 Vulnerability in langflow (CVE-2026-13445)
vulnerability in langflow (CVE-2026-13445). Confidential information can be exposed externally.
CVE-2026-8056 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
CVE-2026-7872 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
CVE-2026-7755 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
CVE-2026-7754 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
CVE-2026-48373 Vulnerability in adobe (CVE-2026-48373)
vulnerability in adobe (CVE-2026-48373). Successful exploitation can lead to full system takeover.
CVE-2026-13448 Vulnerability in langflow (CVE-2026-13448)
vulnerability in langflow (CVE-2026-13448). Successful exploitation can lead to full system takeover.
CVE-2026-13473 Vulnerability in ibm (CVE-2026-13473)
vulnerability in ibm (CVE-2026-13473). Successful exploitation can lead to full system takeover.
CVE-2026-14499 OS Command Injection in langflow (CVE-2026-14499)
OS command injection in langflow (CVE-2026-14499). Successful exploitation can lead to full system takeover.
CVE-2026-63093 Vulnerability in anysphere (CVE-2026-63093)
vulnerability in anysphere (CVE-2026-63093). Successful exploitation can lead to full system takeover.
CVE-2026-62230 Vulnerability in CVE-2026-62230 (CVE-2026-62230)
vulnerability in CVE-2026-62230 (CVE-2026-62230). Confidential information can be exposed externally.
CVE-2026-55578 OS Command Injection in pheditor/pheditor (CVE-2026-55578)
OS command injection in pheditor/pheditor (CVE-2026-55578). Successful exploitation can lead to full system takeover. Exploitable via ``terminal``. Mitigation: upgrade to `2.0.6` or later.
CVE-2026-54540 OS Command Injection in pheditor/pheditor (CVE-2026-54540)
OS command injection in pheditor/pheditor (CVE-2026-54540). Successful exploitation can lead to full system takeover. Exploitable via ``TERMINAL_COMMANDS``. Mitigation: upgrade to `2.0.5` or later.
CVE-2026-46513 Vulnerability in CVE-2026-46513 (CVE-2026-46513)
vulnerability in CVE-2026-46513 (CVE-2026-46513). Confidential information can be exposed externally.
CVE-2026-63304 OS Command Injection in CVE-2026-63304 (CVE-2026-63304)
OS command injection in CVE-2026-63304 (CVE-2026-63304). Successful exploitation can lead to full system takeover.
CVE-2026-63305 OS Command Injection in CVE-2026-63305 (CVE-2026-63305)
OS command injection in CVE-2026-63305 (CVE-2026-63305). Successful exploitation can lead to full system takeover.
CVE-2026-15005 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15005)
vulnerability in wordpress (CVE-2026-15005). Successful exploitation can lead to full system takeover.
CVE-2026-15008 Unsafe Deserialization in wordpress (CVE-2026-15008)
vulnerability in wordpress (CVE-2026-15008). Successful exploitation can lead to full system takeover.
CVE-2026-45313 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and...
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the...
CVE-2026-40952 Vulnerability in absolute (CVE-2026-40952)
vulnerability in absolute (CVE-2026-40952). Successful exploitation can lead to full system takeover.
CVE-2026-54493 SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54493)
SSRF in phanan/koel (CVE-2026-54493). Confidential information can be exposed externally. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
CVE-2026-50147 Vulnerability in metabase (CVE-2026-50147)
vulnerability in metabase (CVE-2026-50147). Confidential information can be exposed externally.
CVE-2026-61873 Vulnerability in path-traversal (CVE-2026-61873)
vulnerability in path-traversal (CVE-2026-61873). Data can be tampered with by attackers.
CVE-2026-61457 Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
vulnerability in CVE-2026-61457 (CVE-2026-61457). Successful exploitation can lead to full system takeover.
CVE-2026-35152 SQL Injection in apache (CVE-2026-35152)
SQL injection in apache (CVE-2026-35152). Successful exploitation can lead to full system takeover.
CVE-2026-56287 SQL Injection in apache (CVE-2026-56287)
SQL injection in apache (CVE-2026-56287). Confidential information can be exposed externally. Exploitable via `GET /api/v1/clients`.
CVE-2026-57821 SQL Injection in apache (CVE-2026-57821)
SQL injection in apache (CVE-2026-57821). Confidential information can be exposed externally. Exploitable via `GET /api/v1/offices`.
CVE-2026-48351 Vulnerability in adobe (CVE-2026-48351)
vulnerability in adobe (CVE-2026-48351). Risk of unauthorized operations or information disclosure.
CVE-2026-48337 Out-of-Bounds Write in adobe (CVE-2026-48337)
out-of-bounds write in adobe (CVE-2026-48337). Successful exploitation can lead to full system takeover.
CVE-2026-48352 Vulnerability in adobe (CVE-2026-48352)
vulnerability in adobe (CVE-2026-48352). Risk of unauthorized operations or information disclosure.
CVE-2026-48335 Out-of-Bounds Write in adobe (CVE-2026-48335)
out-of-bounds write in adobe (CVE-2026-48335). Successful exploitation can lead to full system takeover.
CVE-2026-48336 Out-of-Bounds Write in adobe (CVE-2026-48336)
out-of-bounds write in adobe (CVE-2026-48336). Successful exploitation can lead to full system takeover.
CVE-2026-48275 Vulnerability in adobe (CVE-2026-48275)
vulnerability in adobe (CVE-2026-48275). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →