Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-53456 Vulnerability in CVE-2026-53456 (CVE-2026-53456)
vulnerability in CVE-2026-53456 (CVE-2026-53456). Risk of unauthorized operations or information disclosure.
CVE-2026-53455 OS Command Injection in CVE-2026-53455 (CVE-2026-53455)
OS command injection in CVE-2026-53455 (CVE-2026-53455). Risk of unauthorized operations or information disclosure.
CVE-2026-53454 Vulnerability in CVE-2026-53454 (CVE-2026-53454)
vulnerability in CVE-2026-53454 (CVE-2026-53454). Risk of unauthorized operations or information disclosure.
CVE-2026-53453 Vulnerability in CVE-2026-53453 (CVE-2026-53453)
vulnerability in CVE-2026-53453 (CVE-2026-53453). Risk of unauthorized operations or information disclosure.
CVE-2026-41921 Cross-Site Scripting (XSS) in CVE-2026-41921 (CVE-2026-41921)
cross-site scripting in CVE-2026-41921 (CVE-2026-41921). Risk of unauthorized operations or information disclosure.
CVE-2026-18504 Vulnerability in CVE-2026-18504 (CVE-2026-18504)
vulnerability in CVE-2026-18504 (CVE-2026-18504). Risk of unauthorized operations or information disclosure.
CVE-2026-16732 Vulnerability in csrf (CVE-2026-16732)
vulnerability in csrf (CVE-2026-16732). Confidential information can be exposed externally.
CVE-2026-15571 Vulnerability in CVE-2026-15571 (CVE-2026-15571)
vulnerability in CVE-2026-15571 (CVE-2026-15571). Confidential information can be exposed externally.
CVE-2026-12632 Out-of-Bounds Read in c (CVE-2026-12632)
vulnerability in c (CVE-2026-12632). Risk of unauthorized operations or information disclosure.
CVE-2026-12631 Vulnerability in c (CVE-2026-12631)
vulnerability in c (CVE-2026-12631). Risk of unauthorized operations or information disclosure.
CVE-2026-76034 Vulnerability in Google chrome (CVE-2026-76034)
vulnerability in Google chrome (CVE-2026-76034). Successful exploitation can lead to full system takeover.
CVE-2026-71417 Vulnerability in lemur (CVE-2026-71417)
vulnerability in lemur (CVE-2026-71417). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/1/certificates/`. Mitigation: upgrade to `1.9.3` or later.
CVE-2026-71322 Vulnerability in lemur (CVE-2026-71322)
vulnerability in lemur (CVE-2026-71322). Risk of unauthorized operations or information disclosure. Exploitable via ``CertificateExport``. Mitigation: upgrade to `1.9.3` or later.
CVE-2026-71317 Vulnerability in lemur (CVE-2026-71317)
vulnerability in lemur (CVE-2026-71317). Data can be tampered with by attackers. Exploitable via `POST /api/1/authorities`. Mitigation: upgrade to `1.9.3` or later.
CVE-2026-71308 Vulnerability in lemur (CVE-2026-71308)
vulnerability in lemur (CVE-2026-71308). Data can be tampered with by attackers. Exploitable via `POST /api/1/certificates`. Mitigation: upgrade to `1.9.3` or later.
CVE-2026-71307 Vulnerability in lemur (CVE-2026-71307)
vulnerability in lemur (CVE-2026-71307). Confidential information can be exposed externally. Exploitable via `GET /api/1/destinations`. Mitigation: upgrade to `1.9.3` or later.
CVE-2026-71303 SSRF (Server-Side Request Forgery) in lemur (CVE-2026-71303)
SSRF in lemur (CVE-2026-71303). Confidential information can be exposed externally. Exploitable via `PUT /api/1/authorities/`. Mitigation: upgrade to `1.9.3` or later.
CVE-2026-70666 SSRF (Server-Side Request Forgery) in lemur (CVE-2026-70666)
SSRF in lemur (CVE-2026-70666). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /authorities/`. Mitigation: upgrade to `1.9.3` or later.
CVE-2026-62988 Information Disclosure in froxlor/froxlor (CVE-2026-62988)
vulnerability in froxlor/froxlor (CVE-2026-62988). Confidential information can be exposed externally. Exploitable via ``password``. Mitigation: upgrade to `2.3.8` or later.
CVE-2026-55593 Cross-Site Request Forgery (CSRF) in froxlor/froxlor (CVE-2026-55593)
vulnerability in froxlor/froxlor (CVE-2026-55593). Data can be tampered with by attackers. Exploitable via ``allowed_from``. Mitigation: upgrade to `2.3.8` or later.
CVE-2026-54543 Vulnerability in froxlor/froxlor (CVE-2026-54543)
vulnerability in froxlor/froxlor (CVE-2026-54543). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.8` or later.
CVE-2026-54348 SQL Injection in froxlor/froxlor (CVE-2026-54348)
SQL injection in froxlor/froxlor (CVE-2026-54348). Successful exploitation can lead to full system takeover. Exploitable via ``panel_admins.ip``. Mitigation: upgrade to `2.3.8` or later.
CVE-2026-54347 Cross-Site Scripting (XSS) in froxlor/froxlor (CVE-2026-54347)
cross-site scripting in froxlor/froxlor (CVE-2026-54347). Confidential information can be exposed externally. Exploitable via ``content``. Mitigation: upgrade to `2.3.8` or later.
CVE-2026-54723 Vulnerability in devpi-server (CVE-2026-54723)
vulnerability in devpi-server (CVE-2026-54723). Risk of unauthorized operations or information disclosure. Exploitable via ``primary``. Mitigation: upgrade to `6.20.2` or later.
CVE-2026-55224 Path Traversal in mineadmin/mineadmin (CVE-2026-55224)
path traversal in mineadmin/mineadmin (CVE-2026-55224). Risk of unauthorized operations or information disclosure. Exploitable via ``identifier``. Mitigation: upgrade to `3.2.0-alpha.2` or later.
CVE-2026-75935 Vulnerability in Amazon aws (CVE-2026-75935)
vulnerability in Amazon aws (CVE-2026-75935). Risk of unauthorized operations or information disclosure.
GHSA-wg9g-w2j2-8pgr Unsafe Deserialization in monai (GHSA-wg9g-w2j2-8pgr)
vulnerability in monai (GHSA-wg9g-w2j2-8pgr). Risk of unauthorized operations or information disclosure. Exploitable via ``NumpyReader``. Mitigation: upgrade to `1.6.0` or later.
GHSA-rghg-q7wp-9767 OS Command Injection in MONAI (GHSA-rghg-q7wp-9767)
OS command injection in MONAI (GHSA-rghg-q7wp-9767). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.0` or later.
GHSA-qxq5-qhx6-94qw Unsafe Deserialization in monai (GHSA-qxq5-qhx6-94qw)
vulnerability in monai (GHSA-qxq5-qhx6-94qw). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.2` or later.
GHSA-vjf8-9fx6-mv6x Vulnerability in triton-vm (GHSA-vjf8-9fx6-mv6x)
vulnerability in triton-vm (GHSA-vjf8-9fx6-mv6x). Risk of unauthorized operations or information disclosure. Exploitable via ``sponge_absorb_mem``. Mitigation: upgrade to `4.0.0` or later.
CVE-2026-76032 Vulnerability in CVE-2026-76032 (CVE-2026-76032)
vulnerability in CVE-2026-76032 (CVE-2026-76032). Risk of unauthorized operations or information disclosure. Exploitable via `GET /a/share/link/{Uuid}`.
CVE-2026-75936 Vulnerability in dos (CVE-2026-75936)
vulnerability in dos (CVE-2026-75936). Risk of unauthorized operations or information disclosure.
CVE-2026-75877 Buffer Overflow in CVE-2026-75877 (CVE-2026-75877)
vulnerability in CVE-2026-75877 (CVE-2026-75877). Successful exploitation can lead to full system takeover.
CVE-2026-75876 Vulnerability in sqli (CVE-2026-75876)
vulnerability in sqli (CVE-2026-75876). Risk of unauthorized operations or information disclosure.
CVE-2026-73529 Vulnerability in laravel (CVE-2026-73529)
vulnerability in laravel (CVE-2026-73529). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/sessions`.
CVE-2026-73112 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73111 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73106 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73105 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73104 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-73103 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-71676 Vulnerability in dos (CVE-2026-71676)
vulnerability in dos (CVE-2026-71676). Risk of unauthorized operations or information disclosure.
CVE-2026-71675 Vulnerability in c (CVE-2026-71675)
vulnerability in c (CVE-2026-71675). Risk of unauthorized operations or information disclosure.
CVE-2026-67443 Vulnerability in CVE-2026-67443 (CVE-2026-67443)
vulnerability in CVE-2026-67443 (CVE-2026-67443). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/heartbeat`.
CVE-2026-67440 Vulnerability in CVE-2026-67440 (CVE-2026-67440)
vulnerability in CVE-2026-67440 (CVE-2026-67440). Risk of unauthorized operations or information disclosure.
CVE-2026-65985 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65985)
SSRF in ssrf (CVE-2026-65985). Risk of unauthorized operations or information disclosure.
CVE-2026-65984 Vulnerability in CVE-2026-65984 (CVE-2026-65984)
vulnerability in CVE-2026-65984 (CVE-2026-65984). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/refresh`.
CVE-2026-59915 Vulnerability in CVE-2026-59915 (CVE-2026-59915)
vulnerability in CVE-2026-59915 (CVE-2026-59915). Successful exploitation can lead to full system takeover.
CVE-2026-57826 Vulnerability in CVE-2026-57826 (CVE-2026-57826)
vulnerability in CVE-2026-57826 (CVE-2026-57826). Successful exploitation can lead to full system takeover.
CVE-2026-52481 Information Disclosure in CVE-2026-52481 (CVE-2026-52481)
vulnerability in CVE-2026-52481 (CVE-2026-52481). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →