Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-53369 |
|
Vulnerability in linux (CVE-2026-53369)
vulnerability in linux (CVE-2026-53369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53368 |
|
Vulnerability in linux (CVE-2026-53368)
vulnerability in linux (CVE-2026-53368). Data can be tampered with by attackers.
|
| CVE-2026-16210 |
|
Authentication Bypass in CVE-2026-16210 (CVE-2026-16210)
authentication bypass in CVE-2026-16210 (CVE-2026-16210). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16209 |
|
Authentication Bypass in CVE-2026-16209 (CVE-2026-16209)
authentication bypass in CVE-2026-16209 (CVE-2026-16209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16200 |
|
Vulnerability in c (CVE-2026-16200)
vulnerability in c (CVE-2026-16200). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10130 |
|
Authorization Flaw in CVE-2026-10130 (CVE-2026-10130)
vulnerability in CVE-2026-10130 (CVE-2026-10130). Confidential information can be exposed externally.
|
| CVE-2026-16154 |
|
Vulnerability in sqli (CVE-2026-16154)
vulnerability in sqli (CVE-2026-16154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16152 |
|
Vulnerability in sqli (CVE-2026-16152)
vulnerability in sqli (CVE-2026-16152). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53994 |
|
Vulnerability in dos (CVE-2026-53994)
vulnerability in dos (CVE-2026-53994). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16128 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-16128)
SSRF in c (CVE-2026-16128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16126 |
|
Vulnerability in c (CVE-2026-16126)
vulnerability in c (CVE-2026-16126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16127 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-16127)
SSRF in c (CVE-2026-16127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16125 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-16125)
SSRF in c (CVE-2026-16125). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9323 |
|
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
|
| CVE-2026-11826 |
|
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
|
| CVE-2025-71398 |
|
SSRF (Server-Side Request Forgery) in surrealdb (CVE-2025-71398)
SSRF in surrealdb (CVE-2025-71398). Confidential information can be exposed externally.
|
| CVE-2025-71390 |
|
Authorization Flaw in surrealdb (CVE-2025-71390)
vulnerability in surrealdb (CVE-2025-71390). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71392 |
|
Command Injection in privilege-escalation (CVE-2025-71392)
command injection in privilege-escalation (CVE-2025-71392). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58368 |
|
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
|
| CVE-2024-58362 |
|
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...
|
| CVE-2024-58366 |
|
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
|
| CVE-2023-54366 |
|
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
|
| CVE-2026-16158 |
|
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
|
| CVE-2026-9147 |
|
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
|
| CVE-2026-59173 |
|
Vulnerability in apache (CVE-2026-59173)
vulnerability in apache (CVE-2026-59173). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15631 |
|
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
|
| CVE-2026-16097 |
|
Buffer Overflow in CVE-2026-16097 (CVE-2026-16097)
vulnerability in CVE-2026-16097 (CVE-2026-16097). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16096 |
|
Buffer Overflow in CVE-2026-16096 (CVE-2026-16096)
vulnerability in CVE-2026-16096 (CVE-2026-16096). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16095 |
|
Buffer Overflow in CVE-2026-16095 (CVE-2026-16095)
vulnerability in CVE-2026-16095 (CVE-2026-16095). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47871 |
|
Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-47868 |
|
Privilege Escalation in privilege-escalation (CVE-2026-47868)
vulnerability in privilege-escalation (CVE-2026-47868). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-47869 |
|
Code Injection in broadcom (CVE-2026-47869)
code injection in broadcom (CVE-2026-47869). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-47870 |
|
Privilege Escalation in privilege-escalation (CVE-2026-47870)
vulnerability in privilege-escalation (CVE-2026-47870). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-47866 |
|
Authorization Flaw in broadcom (CVE-2026-47866)
vulnerability in broadcom (CVE-2026-47866). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-16084 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16084 (CVE-2026-16084)
SSRF in CVE-2026-16084 (CVE-2026-16084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47867 |
|
Code Injection in broadcom (CVE-2026-47867)
code injection in broadcom (CVE-2026-47867). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-56740 |
|
Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740). Risk of unauthorized operations or information disclosure. Exploitable via ``HashMap``. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2026-56741 |
|
Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741). Risk of unauthorized operations or information disclosure. Exploitable via ``Telnet``. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2026-56171 |
|
Vulnerability in microsoft (CVE-2026-56171)
vulnerability in microsoft (CVE-2026-56171). Confidential information can be exposed externally.
|
| CVE-2026-52584 |
|
Vulnerability in CVE-2026-52584 (CVE-2026-52584)
vulnerability in CVE-2026-52584 (CVE-2026-52584). Confidential information can be exposed externally.
|
| CVE-2026-52203 |
|
Information Disclosure in CVE-2026-52203 (CVE-2026-52203)
vulnerability in CVE-2026-52203 (CVE-2026-52203). Confidential information can be exposed externally.
|
| CVE-2026-13445 |
|
Vulnerability in langflow (CVE-2026-13445)
vulnerability in langflow (CVE-2026-13445). Confidential information can be exposed externally.
|
| CVE-2026-8056 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
|
| CVE-2026-7755 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
|
| CVE-2026-7872 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
|
| CVE-2026-7754 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
|
| CVE-2026-7667 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
|
| CVE-2026-51833 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51833)
SSRF in ssrf (CVE-2026-51833). Confidential information can be exposed externally.
|
| CVE-2026-48373 |
|
Vulnerability in adobe (CVE-2026-48373)
vulnerability in adobe (CVE-2026-48373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16118 |
|
Vulnerability in c (CVE-2026-16118)
vulnerability in c (CVE-2026-16118). Data can be tampered with by attackers.
|