Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15218 |
|
Vulnerability in CVE-2026-15218 (CVE-2026-15218)
vulnerability in CVE-2026-15218 (CVE-2026-15218). Confidential information can be exposed externally.
|
| CVE-2026-75010 |
|
Vulnerability in CVE-2026-75010 (CVE-2026-75010)
vulnerability in CVE-2026-75010 (CVE-2026-75010). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75000 |
|
Vulnerability in privilege-escalation (CVE-2026-75000)
vulnerability in privilege-escalation (CVE-2026-75000). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75002 |
|
Command Injection in privilege-escalation (CVE-2026-75002)
command injection in privilege-escalation (CVE-2026-75002). Confidential information can be exposed externally.
|
| CVE-2026-74999 |
|
Cross-Site Scripting (XSS) in CVE-2026-74999 (CVE-2026-74999)
cross-site scripting in CVE-2026-74999 (CVE-2026-74999). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70412 |
|
Vulnerability in CVE-2026-70412 (CVE-2026-70412)
vulnerability in CVE-2026-70412 (CVE-2026-70412). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18674 |
|
Vulnerability in CVE-2026-18674 (CVE-2026-18674)
vulnerability in CVE-2026-18674 (CVE-2026-18674). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16467 |
|
Vulnerability in CVE-2026-16467 (CVE-2026-16467)
vulnerability in CVE-2026-16467 (CVE-2026-16467). Confidential information can be exposed externally.
|
| CVE-2026-74998 |
|
Cross-Site Scripting (XSS) in CVE-2026-74998 (CVE-2026-74998)
cross-site scripting in CVE-2026-74998 (CVE-2026-74998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74997 |
|
OS Command Injection in CVE-2026-74997 (CVE-2026-74997)
OS command injection in CVE-2026-74997 (CVE-2026-74997). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14564 |
|
Vulnerability in CVE-2026-14564 (CVE-2026-14564)
vulnerability in CVE-2026-14564 (CVE-2026-14564). Confidential information can be exposed externally.
|
| CVE-2026-71567 |
|
OS Command Injection in CVE-2026-71567 (CVE-2026-71567)
OS command injection in CVE-2026-71567 (CVE-2026-71567). Data can be tampered with by attackers.
|
| CVE-2026-71566 |
|
Vulnerability in CVE-2026-71566 (CVE-2026-71566)
vulnerability in CVE-2026-71566 (CVE-2026-71566). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53728 |
|
Vulnerability in @medplum/core (CVE-2026-53728)
vulnerability in @medplum/core (CVE-2026-53728). Risk of unauthorized operations or information disclosure. Exploitable via `GET /auth/external`. Mitigation: upgrade to `5.1.6` or later.
|
| CVE-2026-55158 |
|
OS Command Injection in wktk/conflibot (CVE-2026-55158)
OS command injection in wktk/conflibot (CVE-2026-55158). Risk of unauthorized operations or information disclosure. Exploitable via ``git``. Mitigation: upgrade to `1.2.1` or later.
|
| CVE-2026-40345 |
|
Vulnerability in deepmerge-ts (CVE-2026-40345)
vulnerability in deepmerge-ts (CVE-2026-40345). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.0` or later.
|
| CVE-2026-74899 |
|
Vulnerability in jahlives (CVE-2026-74899)
vulnerability in jahlives (CVE-2026-74899). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74894 |
|
Authentication Bypass in CVE-2026-74894 (CVE-2026-74894)
authentication bypass in CVE-2026-74894 (CVE-2026-74894). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`.
|
| CVE-2026-74895 |
|
Vulnerability in CVE-2026-74895 (CVE-2026-74895)
vulnerability in CVE-2026-74895 (CVE-2026-74895). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74900 |
|
Vulnerability in CVE-2026-74900 (CVE-2026-74900)
vulnerability in CVE-2026-74900 (CVE-2026-74900). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74896 |
|
Vulnerability in CVE-2026-74896 (CVE-2026-74896)
vulnerability in CVE-2026-74896 (CVE-2026-74896). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74843 |
|
Buffer Overflow in CVE-2026-74843 (CVE-2026-74843)
vulnerability in CVE-2026-74843 (CVE-2026-74843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40126 |
|
Cross-Site Scripting (XSS) in CVE-2026-40126 (CVE-2026-40126)
cross-site scripting in CVE-2026-40126 (CVE-2026-40126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74901 |
|
Vulnerability in CVE-2026-74901 (CVE-2026-74901)
vulnerability in CVE-2026-74901 (CVE-2026-74901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74892 |
|
Vulnerability in CVE-2026-74892 (CVE-2026-74892)
vulnerability in CVE-2026-74892 (CVE-2026-74892). Confidential information can be exposed externally.
|
| CVE-2026-74893 |
|
Vulnerability in CVE-2026-74893 (CVE-2026-74893)
vulnerability in CVE-2026-74893 (CVE-2026-74893). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74889 |
|
Vulnerability in CVE-2026-74889 (CVE-2026-74889)
vulnerability in CVE-2026-74889 (CVE-2026-74889). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74887 |
|
Vulnerability in CVE-2026-74887 (CVE-2026-74887)
vulnerability in CVE-2026-74887 (CVE-2026-74887). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74891 |
|
Vulnerability in CVE-2026-74891 (CVE-2026-74891)
vulnerability in CVE-2026-74891 (CVE-2026-74891). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74888 |
|
Vulnerability in CVE-2026-74888 (CVE-2026-74888)
vulnerability in CVE-2026-74888 (CVE-2026-74888). Confidential information can be exposed externally.
|
| CVE-2026-74890 |
|
Vulnerability in CVE-2026-74890 (CVE-2026-74890)
vulnerability in CVE-2026-74890 (CVE-2026-74890). Data can be tampered with by attackers.
|
| CVE-2026-74886 |
|
Vulnerability in CVE-2026-74886 (CVE-2026-74886)
vulnerability in CVE-2026-74886 (CVE-2026-74886). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74885 |
|
Vulnerability in CVE-2026-74885 (CVE-2026-74885)
vulnerability in CVE-2026-74885 (CVE-2026-74885). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74883 |
|
Vulnerability in CVE-2026-74883 (CVE-2026-74883)
vulnerability in CVE-2026-74883 (CVE-2026-74883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74884 |
|
Vulnerability in path-traversal (CVE-2026-74884)
vulnerability in path-traversal (CVE-2026-74884). Confidential information can be exposed externally.
|
| CVE-2026-74879 |
|
Vulnerability in CVE-2026-74879 (CVE-2026-74879)
vulnerability in CVE-2026-74879 (CVE-2026-74879). Confidential information can be exposed externally.
|
| CVE-2026-74881 |
|
Vulnerability in CVE-2026-74881 (CVE-2026-74881)
vulnerability in CVE-2026-74881 (CVE-2026-74881). Confidential information can be exposed externally.
|
| CVE-2026-74882 |
|
Vulnerability in CVE-2026-74882 (CVE-2026-74882)
vulnerability in CVE-2026-74882 (CVE-2026-74882). Confidential information can be exposed externally.
|
| CVE-2026-74880 |
|
Vulnerability in CVE-2026-74880 (CVE-2026-74880)
vulnerability in CVE-2026-74880 (CVE-2026-74880). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-74872 |
|
Vulnerability in CVE-2026-74872 (CVE-2026-74872)
vulnerability in CVE-2026-74872 (CVE-2026-74872). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74876 |
|
Vulnerability in CVE-2026-74876 (CVE-2026-74876)
vulnerability in CVE-2026-74876 (CVE-2026-74876). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74842 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-74842 (CVE-2026-74842)
SSRF in CVE-2026-74842 (CVE-2026-74842). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74875 |
|
Vulnerability in CVE-2026-74875 (CVE-2026-74875)
vulnerability in CVE-2026-74875 (CVE-2026-74875). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74877 |
|
Vulnerability in CVE-2026-74877 (CVE-2026-74877)
vulnerability in CVE-2026-74877 (CVE-2026-74877). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74878 |
|
Vulnerability in CVE-2026-74878 (CVE-2026-74878)
vulnerability in CVE-2026-74878 (CVE-2026-74878). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74874 |
|
Vulnerability in CVE-2026-74874 (CVE-2026-74874)
vulnerability in CVE-2026-74874 (CVE-2026-74874). Confidential information can be exposed externally.
|
| CVE-2026-74867 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-74867 (CVE-2026-74867)
vulnerability in CVE-2026-74867 (CVE-2026-74867). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74802 |
|
Vulnerability in CVE-2026-74802 (CVE-2026-74802)
vulnerability in CVE-2026-74802 (CVE-2026-74802). Confidential information can be exposed externally.
|
| CVE-2026-74871 |
|
Vulnerability in CVE-2026-74871 (CVE-2026-74871)
vulnerability in CVE-2026-74871 (CVE-2026-74871). Confidential information can be exposed externally.
|
| CVE-2026-74800 |
|
Cross-Site Scripting (XSS) in CVE-2026-74800 (CVE-2026-74800)
cross-site scripting in CVE-2026-74800 (CVE-2026-74800). Successful exploitation can lead to full system takeover.
|