Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55213 |
|
Vulnerability in c (CVE-2026-55213)
vulnerability in c (CVE-2026-55213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55233 |
|
Out-of-Bounds Write in dos (CVE-2026-55233)
out-of-bounds write in dos (CVE-2026-55233). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55827 |
|
Vulnerability in freerdp (CVE-2026-55827)
vulnerability in freerdp (CVE-2026-55827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57850 |
|
Vulnerability in CVE-2026-57850 (CVE-2026-57850)
vulnerability in CVE-2026-57850 (CVE-2026-57850). Confidential information can be exposed externally.
|
| CVE-2026-55789 |
|
Vulnerability in privilege-escalation (CVE-2026-55789)
vulnerability in privilege-escalation (CVE-2026-55789). Data can be tampered with by attackers.
|
| CVE-2026-55452 |
|
Vulnerability in snipe/snipe-it (CVE-2026-55452)
vulnerability in snipe/snipe-it (CVE-2026-55452). Confidential information can be exposed externally. Exploitable via `User-Agent header`. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55466 |
|
Cross-Site Scripting (XSS) in snipe/snipe-it (CVE-2026-55466)
cross-site scripting in snipe/snipe-it (CVE-2026-55466). Confidential information can be exposed externally. Exploitable via ``mimes``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55377 |
|
Authentication Bypass in CVE-2026-55377 (CVE-2026-55377)
authentication bypass in CVE-2026-55377 (CVE-2026-55377). Confidential information can be exposed externally.
|
| CVE-2026-73498 |
|
Path Traversal in mcp-atlassian (CVE-2026-73498)
path traversal in mcp-atlassian (CVE-2026-73498). Confidential information can be exposed externally. Exploitable via ``confluence_upload_attachment``. Mitigation: upgrade to `0.22.0` or later.
|
| CVE-2026-54071 |
|
Unsafe Deserialization in BabelDOC (CVE-2026-54071)
vulnerability in BabelDOC (CVE-2026-54071). Successful exploitation can lead to full system takeover. Exploitable via ``psparser._parse_literal_hex``. Mitigation: upgrade to `0.6.3` or later.
|
| CVE-2026-6212 |
|
Vulnerability in CVE-2026-6212 (CVE-2026-6212)
vulnerability in CVE-2026-6212 (CVE-2026-6212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61460 |
|
Vulnerability in CVE-2026-61460 (CVE-2026-61460)
vulnerability in CVE-2026-61460 (CVE-2026-61460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61461 |
|
SQL Injection in sqli (CVE-2026-61461)
SQL injection in sqli (CVE-2026-61461). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55516 |
|
Vulnerability in snipe/snipe-it (CVE-2026-55516)
vulnerability in snipe/snipe-it (CVE-2026-55516). Data can be tampered with by attackers. Exploitable via `PATCH /api/v1/maintenances/{maintenance_id}`. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55460 |
|
Authorization Flaw in snipe/snipe-it (CVE-2026-55460)
vulnerability in snipe/snipe-it (CVE-2026-55460). Data can be tampered with by attackers. Exploitable via `POST /users/bulksave`. Mitigation: upgrade to `374f426f0c` or later.
|
| CVE-2026-53450 |
|
SSRF (Server-Side Request Forgery) in coturn-project (CVE-2026-53450)
SSRF in coturn-project (CVE-2026-53450). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53448 |
|
SQL Injection in coturn-project (CVE-2026-53448)
SQL injection in coturn-project (CVE-2026-53448). Successful exploitation can lead to full system takeover.
|
| CVE-2025-30007 |
|
OS Command Injection in hestiacp (CVE-2025-30007)
OS command injection in hestiacp (CVE-2025-30007). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39244 |
|
Vulnerability in adm-zip (CVE-2026-39244)
vulnerability in adm-zip (CVE-2026-39244). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-2398 |
|
Vulnerability in privilege-escalation (CVE-2026-2398)
vulnerability in privilege-escalation (CVE-2026-2398). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1667 |
|
Vulnerability in wordpress (CVE-2026-1667)
vulnerability in wordpress (CVE-2026-1667). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-70796 |
|
Path Traversal in path-traversal (CVE-2025-70796)
path traversal in path-traversal (CVE-2025-70796). Confidential information can be exposed externally.
|
| CVE-2026-39903 |
|
Authorization Flaw in CVE-2026-39903 (CVE-2026-39903)
vulnerability in CVE-2026-39903 (CVE-2026-39903). Data can be tampered with by attackers.
|
| CVE-2026-56668 |
|
Vulnerability in CVE-2026-56668 (CVE-2026-56668)
vulnerability in CVE-2026-56668 (CVE-2026-56668). Confidential information can be exposed externally.
|
| CVE-2026-56667 |
|
Cross-Site Scripting (XSS) in CVE-2026-56667 (CVE-2026-56667)
cross-site scripting in CVE-2026-56667 (CVE-2026-56667). Confidential information can be exposed externally.
|
| CVE-2026-59161 |
|
Vulnerability in excelize (CVE-2026-59161)
vulnerability in excelize (CVE-2026-59161). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59162 |
|
Vulnerability in excelize (CVE-2026-59162)
vulnerability in excelize (CVE-2026-59162). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56675 |
|
Authentication Bypass in CVE-2026-56675 (CVE-2026-56675)
authentication bypass in CVE-2026-56675 (CVE-2026-56675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55641 |
|
Vulnerability in 9router (CVE-2026-55641)
vulnerability in 9router (CVE-2026-55641). Confidential information can be exposed externally. Exploitable via `POST /v1/search`. Mitigation: upgrade to `0.5.2` or later.
|
| CVE-2026-55638 |
|
Vulnerability in 9router (CVE-2026-55638)
vulnerability in 9router (CVE-2026-55638). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/responses`. Mitigation: upgrade to `0.5.2` or later.
|
| CVE-2026-55687 |
|
Vulnerability in c (CVE-2026-55687)
vulnerability in c (CVE-2026-55687). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54919 |
|
Vulnerability in c (CVE-2026-54919)
vulnerability in c (CVE-2026-54919). Confidential information can be exposed externally.
|
| CVE-2026-54063 |
|
Vulnerability in github.com/xuri/excelize/v2 (CVE-2026-54063)
vulnerability in github.com/xuri/excelize/v2 (CVE-2026-54063). Risk of unauthorized operations or information disclosure. Exploitable via ``GetCellValue``. Mitigation: upgrade to `2.11.0` or later.
|
| CVE-2026-53657 |
|
Vulnerability in github.com/lima-vm/lima/v2 (CVE-2026-53657)
vulnerability in github.com/lima-vm/lima/v2 (CVE-2026-53657). Successful exploitation can lead to full system takeover. Exploitable via ``qemu``. Mitigation: upgrade to `2.1.3` or later.
|
| CVE-2026-56676 |
|
Vulnerability in CVE-2026-56676 (CVE-2026-56676)
vulnerability in CVE-2026-56676 (CVE-2026-56676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54149 |
|
OS Command Injection in CVE-2026-54149 (CVE-2026-54149)
OS command injection in CVE-2026-54149 (CVE-2026-54149). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33382 |
|
Vulnerability in dos (CVE-2026-33382)
vulnerability in dos (CVE-2026-33382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61437 |
|
Vulnerability in CVE-2026-61437 (CVE-2026-61437)
vulnerability in CVE-2026-61437 (CVE-2026-61437). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61434 |
|
OS Command Injection in CVE-2026-61434 (CVE-2026-61434)
OS command injection in CVE-2026-61434 (CVE-2026-61434). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59795 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-59795)
cross-site scripting in jetbrains (CVE-2026-59795). Confidential information can be exposed externally.
|
| CVE-2026-59796 |
|
Vulnerability in jetbrains (CVE-2026-59796)
vulnerability in jetbrains (CVE-2026-59796). Confidential information can be exposed externally.
|
| CVE-2026-59793 |
|
Vulnerability in jetbrains (CVE-2026-59793)
vulnerability in jetbrains (CVE-2026-59793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59794 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-59794)
cross-site scripting in jetbrains (CVE-2026-59794). Confidential information can be exposed externally.
|
| CVE-2026-60091 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-60091)
SSRF in ssrf (CVE-2026-60091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38057 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-38057)
vulnerability in csrf (CVE-2026-38057). Data can be tampered with by attackers.
|
| CVE-2026-29519 |
|
Cross-Site Scripting (XSS) in CVE-2026-29519 (CVE-2026-29519)
cross-site scripting in CVE-2026-29519 (CVE-2026-29519). Confidential information can be exposed externally.
|
| CVE-2026-56305 |
|
Vulnerability in CVE-2026-56305 (CVE-2026-56305)
vulnerability in CVE-2026-56305 (CVE-2026-56305). Confidential information can be exposed externally.
|
| CVE-2026-56261 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-56261)
SSRF in ssrf (CVE-2026-56261). Confidential information can be exposed externally.
|
| CVE-2026-56254 |
|
Vulnerability in CVE-2026-56254 (CVE-2026-56254)
vulnerability in CVE-2026-56254 (CVE-2026-56254). Data can be tampered with by attackers.
|
| CVE-2026-38059 |
|
Vulnerability in CVE-2026-38059 (CVE-2026-38059)
vulnerability in CVE-2026-38059 (CVE-2026-38059). Confidential information can be exposed externally.
|