Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-53456 |
|
Vulnerability in CVE-2026-53456 (CVE-2026-53456)
vulnerability in CVE-2026-53456 (CVE-2026-53456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53455 |
|
OS Command Injection in CVE-2026-53455 (CVE-2026-53455)
OS command injection in CVE-2026-53455 (CVE-2026-53455). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53454 |
|
Vulnerability in CVE-2026-53454 (CVE-2026-53454)
vulnerability in CVE-2026-53454 (CVE-2026-53454). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53453 |
|
Vulnerability in CVE-2026-53453 (CVE-2026-53453)
vulnerability in CVE-2026-53453 (CVE-2026-53453). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41921 |
|
Cross-Site Scripting (XSS) in CVE-2026-41921 (CVE-2026-41921)
cross-site scripting in CVE-2026-41921 (CVE-2026-41921). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18504 |
|
Vulnerability in CVE-2026-18504 (CVE-2026-18504)
vulnerability in CVE-2026-18504 (CVE-2026-18504). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16732 |
|
Vulnerability in csrf (CVE-2026-16732)
vulnerability in csrf (CVE-2026-16732). Confidential information can be exposed externally.
|
| CVE-2026-15571 |
|
Vulnerability in CVE-2026-15571 (CVE-2026-15571)
vulnerability in CVE-2026-15571 (CVE-2026-15571). Confidential information can be exposed externally.
|
| CVE-2026-12632 |
|
Out-of-Bounds Read in c (CVE-2026-12632)
vulnerability in c (CVE-2026-12632). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12631 |
|
Vulnerability in c (CVE-2026-12631)
vulnerability in c (CVE-2026-12631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76034 |
|
Vulnerability in Google chrome (CVE-2026-76034)
vulnerability in Google chrome (CVE-2026-76034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71417 |
|
Vulnerability in lemur (CVE-2026-71417)
vulnerability in lemur (CVE-2026-71417). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/1/certificates/`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-71322 |
|
Vulnerability in lemur (CVE-2026-71322)
vulnerability in lemur (CVE-2026-71322). Risk of unauthorized operations or information disclosure. Exploitable via ``CertificateExport``. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-71317 |
|
Vulnerability in lemur (CVE-2026-71317)
vulnerability in lemur (CVE-2026-71317). Data can be tampered with by attackers. Exploitable via `POST /api/1/authorities`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-71308 |
|
Vulnerability in lemur (CVE-2026-71308)
vulnerability in lemur (CVE-2026-71308). Data can be tampered with by attackers. Exploitable via `POST /api/1/certificates`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-71307 |
|
Vulnerability in lemur (CVE-2026-71307)
vulnerability in lemur (CVE-2026-71307). Confidential information can be exposed externally. Exploitable via `GET /api/1/destinations`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-71303 |
|
SSRF (Server-Side Request Forgery) in lemur (CVE-2026-71303)
SSRF in lemur (CVE-2026-71303). Confidential information can be exposed externally. Exploitable via `PUT /api/1/authorities/`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-70666 |
|
SSRF (Server-Side Request Forgery) in lemur (CVE-2026-70666)
SSRF in lemur (CVE-2026-70666). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /authorities/`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-62988 |
|
Information Disclosure in froxlor/froxlor (CVE-2026-62988)
vulnerability in froxlor/froxlor (CVE-2026-62988). Confidential information can be exposed externally. Exploitable via ``password``. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-55593 |
|
Cross-Site Request Forgery (CSRF) in froxlor/froxlor (CVE-2026-55593)
vulnerability in froxlor/froxlor (CVE-2026-55593). Data can be tampered with by attackers. Exploitable via ``allowed_from``. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-54543 |
|
Vulnerability in froxlor/froxlor (CVE-2026-54543)
vulnerability in froxlor/froxlor (CVE-2026-54543). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-54348 |
|
SQL Injection in froxlor/froxlor (CVE-2026-54348)
SQL injection in froxlor/froxlor (CVE-2026-54348). Successful exploitation can lead to full system takeover. Exploitable via ``panel_admins.ip``. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-54347 |
|
Cross-Site Scripting (XSS) in froxlor/froxlor (CVE-2026-54347)
cross-site scripting in froxlor/froxlor (CVE-2026-54347). Confidential information can be exposed externally. Exploitable via ``content``. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-54723 |
|
Vulnerability in devpi-server (CVE-2026-54723)
vulnerability in devpi-server (CVE-2026-54723). Risk of unauthorized operations or information disclosure. Exploitable via ``primary``. Mitigation: upgrade to `6.20.2` or later.
|
| CVE-2026-55224 |
|
Path Traversal in mineadmin/mineadmin (CVE-2026-55224)
path traversal in mineadmin/mineadmin (CVE-2026-55224). Risk of unauthorized operations or information disclosure. Exploitable via ``identifier``. Mitigation: upgrade to `3.2.0-alpha.2` or later.
|
| CVE-2026-75935 |
|
Vulnerability in Amazon aws (CVE-2026-75935)
vulnerability in Amazon aws (CVE-2026-75935). Risk of unauthorized operations or information disclosure.
|
| GHSA-wg9g-w2j2-8pgr |
|
Unsafe Deserialization in monai (GHSA-wg9g-w2j2-8pgr)
vulnerability in monai (GHSA-wg9g-w2j2-8pgr). Risk of unauthorized operations or information disclosure. Exploitable via ``NumpyReader``. Mitigation: upgrade to `1.6.0` or later.
|
| GHSA-rghg-q7wp-9767 |
|
OS Command Injection in MONAI (GHSA-rghg-q7wp-9767)
OS command injection in MONAI (GHSA-rghg-q7wp-9767). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.0` or later.
|
| GHSA-qxq5-qhx6-94qw |
|
Unsafe Deserialization in monai (GHSA-qxq5-qhx6-94qw)
vulnerability in monai (GHSA-qxq5-qhx6-94qw). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.2` or later.
|
| GHSA-vjf8-9fx6-mv6x |
|
Vulnerability in triton-vm (GHSA-vjf8-9fx6-mv6x)
vulnerability in triton-vm (GHSA-vjf8-9fx6-mv6x). Risk of unauthorized operations or information disclosure. Exploitable via ``sponge_absorb_mem``. Mitigation: upgrade to `4.0.0` or later.
|
| CVE-2026-76032 |
|
Vulnerability in CVE-2026-76032 (CVE-2026-76032)
vulnerability in CVE-2026-76032 (CVE-2026-76032). Risk of unauthorized operations or information disclosure. Exploitable via `GET /a/share/link/{Uuid}`.
|
| CVE-2026-75936 |
|
Vulnerability in dos (CVE-2026-75936)
vulnerability in dos (CVE-2026-75936). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75877 |
|
Buffer Overflow in CVE-2026-75877 (CVE-2026-75877)
vulnerability in CVE-2026-75877 (CVE-2026-75877). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75876 |
|
Vulnerability in sqli (CVE-2026-75876)
vulnerability in sqli (CVE-2026-75876). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73529 |
|
Vulnerability in laravel (CVE-2026-73529)
vulnerability in laravel (CVE-2026-73529). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/sessions`.
|
| CVE-2026-73112 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-73111 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-73106 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-73105 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-73104 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-73103 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-71676 |
|
Vulnerability in dos (CVE-2026-71676)
vulnerability in dos (CVE-2026-71676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71675 |
|
Vulnerability in c (CVE-2026-71675)
vulnerability in c (CVE-2026-71675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67443 |
|
Vulnerability in CVE-2026-67443 (CVE-2026-67443)
vulnerability in CVE-2026-67443 (CVE-2026-67443). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/heartbeat`.
|
| CVE-2026-67440 |
|
Vulnerability in CVE-2026-67440 (CVE-2026-67440)
vulnerability in CVE-2026-67440 (CVE-2026-67440). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65985 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65985)
SSRF in ssrf (CVE-2026-65985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65984 |
|
Vulnerability in CVE-2026-65984 (CVE-2026-65984)
vulnerability in CVE-2026-65984 (CVE-2026-65984). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/refresh`.
|
| CVE-2026-59915 |
|
Vulnerability in CVE-2026-59915 (CVE-2026-59915)
vulnerability in CVE-2026-59915 (CVE-2026-59915). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57826 |
|
Vulnerability in CVE-2026-57826 (CVE-2026-57826)
vulnerability in CVE-2026-57826 (CVE-2026-57826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52481 |
|
Information Disclosure in CVE-2026-52481 (CVE-2026-52481)
vulnerability in CVE-2026-52481 (CVE-2026-52481). Confidential information can be exposed externally.
|