Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64760 |
|
Information Disclosure in apple (CVE-2026-64760)
vulnerability in apple (CVE-2026-64760). Confidential information can be exposed externally.
|
| CVE-2026-64715 |
|
Use-After-Free in apple (CVE-2026-64715)
vulnerability in apple (CVE-2026-64715). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63178 |
|
Vulnerability in CVE-2026-63178 (CVE-2026-63178)
vulnerability in CVE-2026-63178 (CVE-2026-63178). Confidential information can be exposed externally. Exploitable via `PATCH /manage/admin/user-group/{user_group_id}`.
|
| CVE-2026-54385 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-51977 |
|
Vulnerability in CVE-2026-51977 (CVE-2026-51977)
vulnerability in CVE-2026-51977 (CVE-2026-51977). Confidential information can be exposed externally.
|
| CVE-2026-45791 |
|
Vulnerability in CVE-2026-45791 (CVE-2026-45791)
vulnerability in CVE-2026-45791 (CVE-2026-45791). Confidential information can be exposed externally.
|
| CVE-2026-45790 |
|
Privilege Escalation in CVE-2026-45790 (CVE-2026-45790)
vulnerability in CVE-2026-45790 (CVE-2026-45790). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43795 |
|
Buffer Overflow in apple (CVE-2026-43795)
vulnerability in apple (CVE-2026-43795). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43794 |
|
Buffer Overflow in c (CVE-2026-43794)
vulnerability in c (CVE-2026-43794). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43667 |
|
Vulnerability in apple (CVE-2026-43667)
vulnerability in apple (CVE-2026-43667). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42163 |
|
Vulnerability in CVE-2026-42163 (CVE-2026-42163)
vulnerability in CVE-2026-42163 (CVE-2026-42163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28984 |
|
Buffer Overflow in apple (CVE-2026-28984)
vulnerability in apple (CVE-2026-28984). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11817 |
|
Authorization Flaw in CVE-2026-11817 (CVE-2026-11817)
vulnerability in CVE-2026-11817 (CVE-2026-11817). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/access-control/users/permissions/search`.
|
| CVE-2026-10080 |
|
Vulnerability in mattermost (CVE-2026-10080)
vulnerability in mattermost (CVE-2026-10080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69148 |
|
Vulnerability in mlflow (CVE-2026-69148)
vulnerability in mlflow (CVE-2026-69148). Confidential information can be exposed externally. Exploitable via `GET /model-versions/get-artifact`. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-69146 |
|
Vulnerability in mlflow (CVE-2026-69146)
vulnerability in mlflow (CVE-2026-69146). Data can be tampered with by attackers. Exploitable via `POST /api/2.0/mlflow/runs/log-inputs`. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-64849 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-64849)
SSRF in mlflow (CVE-2026-64849). Confidential information can be exposed externally. Exploitable via `POST /api/2.0/mlflow/webhooks/{id}/test`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-56677 |
|
Vulnerability in 9router (CVE-2026-56677)
vulnerability in 9router (CVE-2026-56677). Data can be tampered with by attackers. Exploitable via `POST /api/auth/oidc/test`.
|
| CVE-2026-54148 |
|
Vulnerability in org.http4k:http4k-security-digest (CVE-2026-54148)
vulnerability in org.http4k:http4k-security-digest (CVE-2026-54148). Risk of unauthorized operations or information disclosure. Exploitable via ``DigestAuthProvider.verify``.
|
| CVE-2026-54147 |
|
Vulnerability in org.http4k:http4k-security-digest (CVE-2026-54147)
vulnerability in org.http4k:http4k-security-digest (CVE-2026-54147). Risk of unauthorized operations or information disclosure. Exploitable via ``DigestAuthProvider.verify``. Mitigation: upgrade to `6.50.0.0` or later.
|
| GHSA-mpwr-8vm7-h73f |
|
Vulnerability in software.sslmate.com/src/go-pkcs12 (GHSA-mpwr-8vm7-h73f)
vulnerability in software.sslmate.com/src/go-pkcs12 (GHSA-mpwr-8vm7-h73f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.7.2` or later.
|
| CVE-2026-53752 |
|
Vulnerability in org.docx4j:docx4j-core (CVE-2026-53752)
vulnerability in org.docx4j:docx4j-core (CVE-2026-53752). Risk of unauthorized operations or information disclosure. Exploitable via ``PropertyResolver``. Mitigation: upgrade to `11.5.14` or later.
|
| CVE-2026-53659 |
|
Vulnerability in org.http4k:http4k-core (CVE-2026-53659)
vulnerability in org.http4k:http4k-core (CVE-2026-53659). Risk of unauthorized operations or information disclosure. Exploitable via ``ServerFilters.GZip``. Mitigation: upgrade to `6.49.0.0` or later.
|
| GHSA-j659-8xh6-5pq5 |
|
Vulnerability in atomic-agents-stack (GHSA-j659-8xh6-5pq5)
vulnerability in atomic-agents-stack (GHSA-j659-8xh6-5pq5). Risk of unauthorized operations or information disclosure. Exploitable via ``_estimate_batch_cost``. Mitigation: upgrade to `1.1.0` or later.
|
| GHSA-xhcr-cqfr-m3hv |
|
Vulnerability in atomic-agents-stack (GHSA-xhcr-cqfr-m3hv)
vulnerability in atomic-agents-stack (GHSA-xhcr-cqfr-m3hv). Risk of unauthorized operations or information disclosure. Exploitable via ``http``. Mitigation: upgrade to `1.1.0` or later.
|
| CVE-2026-75531 |
|
Cross-Site Scripting (XSS) in CVE-2026-75531 (CVE-2026-75531)
cross-site scripting in CVE-2026-75531 (CVE-2026-75531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75529 |
|
Cross-Site Scripting (XSS) in flask (CVE-2026-75529)
cross-site scripting in flask (CVE-2026-75529). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75483 |
|
Vulnerability in CVE-2026-75483 (CVE-2026-75483)
vulnerability in CVE-2026-75483 (CVE-2026-75483). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75482 |
|
Path Traversal in path-traversal (CVE-2026-75482)
path traversal in path-traversal (CVE-2026-75482). Confidential information can be exposed externally.
|
| CVE-2026-75481 |
|
Privilege Escalation in CVE-2026-75481 (CVE-2026-75481)
vulnerability in CVE-2026-75481 (CVE-2026-75481). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75480 |
|
Authorization Flaw in CVE-2026-75480 (CVE-2026-75480)
vulnerability in CVE-2026-75480 (CVE-2026-75480). Confidential information can be exposed externally.
|
| CVE-2026-75479 |
|
Vulnerability in CVE-2026-75479 (CVE-2026-75479)
vulnerability in CVE-2026-75479 (CVE-2026-75479). Confidential information can be exposed externally.
|
| CVE-2026-75111 |
|
Path Traversal in CVE-2026-75111 (CVE-2026-75111)
path traversal in CVE-2026-75111 (CVE-2026-75111). Confidential information can be exposed externally.
|
| CVE-2026-75110 |
|
Vulnerability in CVE-2026-75110 (CVE-2026-75110)
vulnerability in CVE-2026-75110 (CVE-2026-75110). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75109 |
|
Vulnerability in CVE-2026-75109 (CVE-2026-75109)
vulnerability in CVE-2026-75109 (CVE-2026-75109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75108 |
|
Vulnerability in CVE-2026-75108 (CVE-2026-75108)
vulnerability in CVE-2026-75108 (CVE-2026-75108). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75106 |
|
Vulnerability in CVE-2026-75106 (CVE-2026-75106)
vulnerability in CVE-2026-75106 (CVE-2026-75106). Confidential information can be exposed externally.
|
| CVE-2026-75105 |
|
Vulnerability in CVE-2026-75105 (CVE-2026-75105)
vulnerability in CVE-2026-75105 (CVE-2026-75105). Confidential information can be exposed externally.
|
| CVE-2026-75104 |
|
Path Traversal in CVE-2026-75104 (CVE-2026-75104)
path traversal in CVE-2026-75104 (CVE-2026-75104). Confidential information can be exposed externally.
|
| CVE-2026-75103 |
|
Vulnerability in CVE-2026-75103 (CVE-2026-75103)
vulnerability in CVE-2026-75103 (CVE-2026-75103). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73560 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-73560 (CVE-2026-73560)
SSRF in CVE-2026-73560 (CVE-2026-73560). Confidential information can be exposed externally.
|
| CVE-2026-71518 |
|
Authorization Flaw in CVE-2026-71518 (CVE-2026-71518)
vulnerability in CVE-2026-71518 (CVE-2026-71518). Confidential information can be exposed externally.
|
| CVE-2026-68765 |
|
Vulnerability in CVE-2026-68765 (CVE-2026-68765)
vulnerability in CVE-2026-68765 (CVE-2026-68765). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67967 |
|
Vulnerability in CVE-2026-67967 (CVE-2026-67967)
vulnerability in CVE-2026-67967 (CVE-2026-67967). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67966 |
|
Vulnerability in CVE-2026-67966 (CVE-2026-67966)
vulnerability in CVE-2026-67966 (CVE-2026-67966). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67965 |
|
OS Command Injection in CVE-2026-67965 (CVE-2026-67965)
OS command injection in CVE-2026-67965 (CVE-2026-67965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67926 |
|
Code Injection in CVE-2026-67926 (CVE-2026-67926)
code injection in CVE-2026-67926 (CVE-2026-67926). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67925 |
|
Cross-Site Scripting (XSS) in CVE-2026-67925 (CVE-2026-67925)
cross-site scripting in CVE-2026-67925 (CVE-2026-67925). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67917 |
|
SQL Injection in sqli (CVE-2026-67917)
SQL injection in sqli (CVE-2026-67917). Successful exploitation can lead to full system takeover. Exploitable via ``db.sql``.
|
| CVE-2026-66795 |
|
Vulnerability in privilege-escalation (CVE-2026-66795)
vulnerability in privilege-escalation (CVE-2026-66795). Successful exploitation can lead to full system takeover.
|