Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-80207 |
|
Vulnerability in nginx (CVE-2026-80207)
vulnerability in nginx (CVE-2026-80207). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/internal/notification/create`.
|
| CVE-2026-80208 |
|
Vulnerability in nginx (CVE-2026-80208)
vulnerability in nginx (CVE-2026-80208). Data can be tampered with by attackers.
|
| CVE-2026-66422 |
|
Vulnerability in apache (CVE-2026-66422)
vulnerability in apache (CVE-2026-66422). Data can be tampered with by attackers.
|
| CVE-2026-65637 |
|
Vulnerability in apache (CVE-2026-65637)
vulnerability in apache (CVE-2026-65637). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68763 |
|
Vulnerability in apache (CVE-2026-68763)
vulnerability in apache (CVE-2026-68763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68525 |
|
Authorization Flaw in apache (CVE-2026-68525)
vulnerability in apache (CVE-2026-68525). Confidential information can be exposed externally.
|
| CVE-2026-68569 |
|
Authentication Bypass in apache (CVE-2026-68569)
authentication bypass in apache (CVE-2026-68569). Confidential information can be exposed externally.
|
| CVE-2026-65183 |
|
Vulnerability in apache (CVE-2026-65183)
vulnerability in apache (CVE-2026-65183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65927 |
|
Vulnerability in apache (CVE-2026-65927)
vulnerability in apache (CVE-2026-65927). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65905 |
|
Vulnerability in apache (CVE-2026-65905)
vulnerability in apache (CVE-2026-65905). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65182 |
|
Vulnerability in apache (CVE-2026-65182)
vulnerability in apache (CVE-2026-65182). Confidential information can be exposed externally.
|
| CVE-2026-73180 |
|
Vulnerability in apache (CVE-2026-73180)
vulnerability in apache (CVE-2026-73180). Confidential information can be exposed externally.
|
| CVE-2026-54738 |
|
Vulnerability in nginx (CVE-2026-54738)
vulnerability in nginx (CVE-2026-54738). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v4/account/auth/register`.
|
| CVE-2026-19670 |
|
Authorization Flaw in nginx (CVE-2026-19670)
vulnerability in nginx (CVE-2026-19670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75784 |
|
Buffer Overflow in nginx (CVE-2026-75784)
vulnerability in nginx (CVE-2026-75784). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19728 |
|
Vulnerability in wordpress (CVE-2026-19728)
vulnerability in wordpress (CVE-2026-19728). Confidential information can be exposed externally.
|
| CVE-2026-48528 |
|
SQL Injection in tomcat (CVE-2026-48528)
SQL injection in tomcat (CVE-2026-48528). Successful exploitation can lead to full system takeover. Exploitable via ``nodeId``.
|
| CVE-2026-63177 |
|
Authorization Flaw in nginx (CVE-2026-63177)
vulnerability in nginx (CVE-2026-63177). Confidential information can be exposed externally. Exploitable via ``ngx.var.request_uri``.
|
| CVE-2026-55676 |
|
Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
|
| CVE-2026-47754 |
|
Path Traversal in tomcat (CVE-2026-47754)
path traversal in tomcat (CVE-2026-47754). Confidential information can be exposed externally. Exploitable via ``archiveEntryName``.
|
| CVE-2026-16993 |
|
Information Disclosure in wordpress (CVE-2026-16993)
vulnerability in wordpress (CVE-2026-16993). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67309 |
|
Path Traversal in github.com/traefik/traefik/v3 (CVE-2026-67309)
path traversal in github.com/traefik/traefik/v3 (CVE-2026-67309). Risk of unauthorized operations or information disclosure. Exploitable via ``RewriteTarget``. Mitigation: upgrade to `3.7.8` or later.
|
| CVE-2026-25552 |
|
Vulnerability in nginx (CVE-2026-25552)
vulnerability in nginx (CVE-2026-25552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66713 |
|
Unsafe Deserialization in apache (CVE-2026-66713)
vulnerability in apache (CVE-2026-66713). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66299 |
|
Vulnerability in apache (CVE-2026-66299)
vulnerability in apache (CVE-2026-66299). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18047 |
|
Vulnerability in tomcat (CVE-2026-18047)
vulnerability in tomcat (CVE-2026-18047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65601 |
|
Authorization Flaw in github.com/traefik/traefik (CVE-2026-65601)
vulnerability in github.com/traefik/traefik (CVE-2026-65601). Successful exploitation can lead to full system takeover. Exploitable via ``HTTPRoute``. Mitigation: upgrade to `3.7.7` or later.
|
| CVE-2026-65600 |
|
Path Traversal in github.com/traefik/traefik/v2 (CVE-2026-65600)
path traversal in github.com/traefik/traefik/v2 (CVE-2026-65600). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api../admin`. Mitigation: upgrade to `2.11.52` or later.
|
| CVE-2026-65602 |
|
Authorization Flaw in github.com/traefik/traefik (CVE-2026-65602)
vulnerability in github.com/traefik/traefik (CVE-2026-65602). Successful exploitation can lead to full system takeover. Exploitable via ``crossProviderNamespaces``. Mitigation: upgrade to `3.7.7` or later.
|
| CVE-2026-56584 |
|
Information Disclosure in nginx (CVE-2026-56584)
vulnerability in nginx (CVE-2026-56584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26081 |
|
Vulnerability in haproxy (CVE-2026-26081)
vulnerability in haproxy (CVE-2026-26081). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26080 |
|
Vulnerability in haproxy (CVE-2026-26080)
vulnerability in haproxy (CVE-2026-26080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60005 |
|
Vulnerability in nginx (CVE-2026-60005)
vulnerability in nginx (CVE-2026-60005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56434 |
|
Use-After-Free in nginx (CVE-2026-56434)
vulnerability in nginx (CVE-2026-56434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55723 |
|
Vulnerability in nginx (CVE-2026-55723)
vulnerability in nginx (CVE-2026-55723). Confidential information can be exposed externally.
|
| CVE-2026-42533 |
|
Vulnerability in nginx (CVE-2026-42533)
vulnerability in nginx (CVE-2026-42533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52865 |
|
Vulnerability in nginx (CVE-2026-52865)
vulnerability in nginx (CVE-2026-52865). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60065 |
|
Out-of-Bounds Read in nginx (CVE-2026-60065)
vulnerability in nginx (CVE-2026-60065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60062 |
|
Path Traversal in nginx (CVE-2026-60062)
path traversal in nginx (CVE-2026-60062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59083 |
|
Vulnerability in apache (CVE-2026-59083)
vulnerability in apache (CVE-2026-59083). Confidential information can be exposed externally.
|
| CVE-2026-59084 |
|
Vulnerability in apache (CVE-2026-59084)
vulnerability in apache (CVE-2026-59084). Confidential information can be exposed externally.
|
| CVE-2026-49972 |
|
Unrestricted File Upload in laravel (CVE-2026-49972)
vulnerability in laravel (CVE-2026-49972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52761 |
|
Vulnerability in nginx (CVE-2026-52761)
vulnerability in nginx (CVE-2026-52761). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52747 |
|
Vulnerability in nginx (CVE-2026-52747)
vulnerability in nginx (CVE-2026-52747). Data can be tampered with by attackers.
|
| CVE-2026-54652 |
|
Privilege Escalation in nginx (CVE-2026-54652)
vulnerability in nginx (CVE-2026-54652). Confidential information can be exposed externally. Exploitable via `GET /api/logs/{service}`.
|
| CVE-2026-53646 |
|
Vulnerability in nginx (CVE-2026-53646)
vulnerability in nginx (CVE-2026-53646). Risk of unauthorized operations or information disclosure. Exploitable via ``ClientPasswordReset``.
|
| CVE-2026-54765 |
|
Vulnerability in github.com/traefik/traefik/v3 (CVE-2026-54765)
vulnerability in github.com/traefik/traefik/v3 (CVE-2026-54765). Data can be tampered with by attackers. Exploitable via ``backendRef``. Mitigation: upgrade to `3.7.6` or later.
|
| CVE-2026-54764 |
|
Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54764)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54764). Risk of unauthorized operations or information disclosure. Exploitable via ``req.TLS``. Mitigation: upgrade to `2.11.51` or later.
|
| CVE-2026-54763 |
|
Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763). Confidential information can be exposed externally. Exploitable via ``X_Auth_User``. Mitigation: upgrade to `2.11.42` or later.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|