Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-1288 |
|
Vulnerability in autodesk (CVE-2026-1288)
vulnerability in autodesk (CVE-2026-1288). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2675 |
|
Vulnerability in rti (CVE-2026-2675)
vulnerability in rti (CVE-2026-2675). Data can be tampered with by attackers.
|
| CVE-2026-30802 |
|
Out-of-Bounds Read in rti (CVE-2026-30802)
vulnerability in rti (CVE-2026-30802). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2467 |
|
Vulnerability in rti (CVE-2026-2467)
vulnerability in rti (CVE-2026-2467). Data can be tampered with by attackers.
|
| CVE-2026-20265 |
|
Vulnerability in splunk (CVE-2026-20265)
vulnerability in splunk (CVE-2026-20265). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20266 |
|
OS Command Injection in splunk (CVE-2026-20266)
OS command injection in splunk (CVE-2026-20266). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35069 |
|
SQL Injection in sqli (CVE-2026-35069)
SQL injection in sqli (CVE-2026-35069). Confidential information can be exposed externally.
|
| CVE-2026-53872 |
|
Path Traversal in picklescan (CVE-2026-53872)
path traversal in picklescan (CVE-2026-53872). Confidential information can be exposed externally. Exploitable via ``picklescan``. Mitigation: upgrade to `0.0.35` or later.
|
| CVE-2026-3490 |
|
Vulnerability in picklescan (CVE-2026-3490)
vulnerability in picklescan (CVE-2026-3490). Successful exploitation can lead to full system takeover. Exploitable via ``pkgutil.resolve_name``. Mitigation: upgrade to `1.0.4` or later.
|
| GHSA-rmpp-8wf5-xx5q |
|
Unsafe Deserialization in picklescan (GHSA-rmpp-8wf5-xx5q)
vulnerability in picklescan (GHSA-rmpp-8wf5-xx5q). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.33` or later.
|
| GHSA-7f79-rvx6-vxc4 |
|
Vulnerability in picklescan (GHSA-7f79-rvx6-vxc4)
vulnerability in picklescan (GHSA-7f79-rvx6-vxc4). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.33` or later.
|
| GHSA-6v84-v468-3c7f |
|
Vulnerability in picklescan (GHSA-6v84-v468-3c7f)
vulnerability in picklescan (GHSA-6v84-v468-3c7f). Successful exploitation can lead to full system takeover.
|
| GHSA-5rph-q42j-36j9 |
|
Vulnerability in picklescan (GHSA-5rph-q42j-36j9)
vulnerability in picklescan (GHSA-5rph-q42j-36j9). Successful exploitation can lead to full system takeover.
|
| GHSA-5gp7-4733-2w2v |
|
Vulnerability in picklescan (GHSA-5gp7-4733-2w2v)
vulnerability in picklescan (GHSA-5gp7-4733-2w2v). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71322 |
|
Vulnerability in picklescan (CVE-2025-71322)
vulnerability in picklescan (CVE-2025-71322). Successful exploitation can lead to full system takeover. Exploitable via ``pty``. Mitigation: upgrade to `0.0.33` or later.
|
| CVE-2025-26240 |
|
Vulnerability in pdfkit (CVE-2025-26240)
vulnerability in pdfkit (CVE-2025-26240). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71325 |
|
Unsafe Deserialization in picklescan (CVE-2025-71325)
vulnerability in picklescan (CVE-2025-71325). Successful exploitation can lead to full system takeover. Exploitable via ``STACK_GLOBAL``. Mitigation: upgrade to `0.0.27` or later.
|
| CVE-2025-71323 |
|
Vulnerability in picklescan (CVE-2025-71323)
vulnerability in picklescan (CVE-2025-71323). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.33` or later.
|
| CVE-2026-49502 |
|
Authentication Bypass in dell (CVE-2026-49502)
authentication bypass in dell (CVE-2026-49502). Confidential information can be exposed externally.
|
| CVE-2026-35066 |
|
Vulnerability in dos (CVE-2026-35066)
vulnerability in dos (CVE-2026-35066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55743 |
|
OS Command Injection in CVE-2026-55743 (CVE-2026-55743)
OS command injection in CVE-2026-55743 (CVE-2026-55743). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42055 |
|
Vulnerability in nginx (CVE-2026-42055)
vulnerability in nginx (CVE-2026-42055). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55748 |
|
OS Command Injection in horizon (CVE-2026-55748)
OS command injection in horizon (CVE-2026-55748). Confidential information can be exposed externally.
|
| CVE-2026-42530 |
|
Use-After-Free in nginx (CVE-2026-42530)
vulnerability in nginx (CVE-2026-42530). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71321 |
|
Unsafe Deserialization in picklescan (CVE-2025-71321)
vulnerability in picklescan (CVE-2025-71321). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.33` or later.
|
| CVE-2026-40641 |
|
Vulnerability in dell (CVE-2026-40641)
vulnerability in dell (CVE-2026-40641). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54415 |
|
Privilege Escalation in CVE-2026-54415 (CVE-2026-54415)
vulnerability in CVE-2026-54415 (CVE-2026-54415). Confidential information can be exposed externally.
|
| CVE-2026-54810 |
|
Vulnerability in CVE-2026-54810 (CVE-2026-54810)
vulnerability in CVE-2026-54810 (CVE-2026-54810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48142 |
|
Out-of-Bounds Read in nginx (CVE-2026-48142)
vulnerability in nginx (CVE-2026-48142). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71320 |
|
Vulnerability in picklescan (CVE-2025-71320)
vulnerability in picklescan (CVE-2025-71320). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.33` or later.
|
| CVE-2025-32748 |
|
Open Redirect in dell (CVE-2025-32748)
vulnerability in dell (CVE-2025-32748). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-54812 |
|
SQL Injection in sqli (CVE-2026-54812)
SQL injection in sqli (CVE-2026-54812). Confidential information can be exposed externally.
|
| CVE-2026-35067 |
|
Vulnerability in dell (CVE-2026-35067)
vulnerability in dell (CVE-2026-35067). Confidential information can be exposed externally.
|
| CVE-2026-35162 |
|
Vulnerability in dos (CVE-2026-35162)
vulnerability in dos (CVE-2026-35162). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35065 |
|
Vulnerability in dos (CVE-2026-35065)
vulnerability in dos (CVE-2026-35065). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54815 |
|
SQL Injection in c (CVE-2026-54815)
SQL injection in c (CVE-2026-54815). Confidential information can be exposed externally.
|
| CVE-2026-22283 |
|
Vulnerability in dell (CVE-2026-22283)
vulnerability in dell (CVE-2026-22283). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11311 |
|
Vulnerability in nginx-gateway-fabric (CVE-2026-11311)
vulnerability in nginx-gateway-fabric (CVE-2026-11311). Confidential information can be exposed externally. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-54813 |
|
SQL Injection in sqli (CVE-2026-54813)
SQL injection in sqli (CVE-2026-54813). Confidential information can be exposed externally.
|
| CVE-2026-54817 |
|
Vulnerability in CVE-2026-54817 (CVE-2026-54817)
vulnerability in CVE-2026-54817 (CVE-2026-54817). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32804 |
|
Authentication Bypass in dell (CVE-2026-32804)
authentication bypass in dell (CVE-2026-32804). Data can be tampered with by attackers.
|
| CVE-2026-54808 |
|
SQL Injection in sqli (CVE-2026-54808)
SQL injection in sqli (CVE-2026-54808). Confidential information can be exposed externally.
|
| CVE-2026-52716 |
|
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions.
|
| CVE-2026-55738 |
|
Vulnerability in c (CVE-2026-55738)
vulnerability in c (CVE-2026-55738). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54193 |
|
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
|
| CVE-2026-54417 |
|
Vulnerability in c (CVE-2026-54417)
vulnerability in c (CVE-2026-54417). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54816 |
|
Code Injection in CVE-2026-54816 (CVE-2026-54816)
code injection in CVE-2026-54816 (CVE-2026-54816). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52707 |
|
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
|
| CVE-2026-49268 |
|
Vulnerability in org.apache.shiro:shiro-core (CVE-2026-49268)
vulnerability in org.apache.shiro:shiro-core (CVE-2026-49268). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-49108 |
|
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
|