Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19730 |
|
Vulnerability in CVE-2026-19730 (CVE-2026-19730)
vulnerability in CVE-2026-19730 (CVE-2026-19730). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12908 |
|
Vulnerability in CVE-2026-12908 (CVE-2026-12908)
vulnerability in CVE-2026-12908 (CVE-2026-12908). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12236 |
|
Vulnerability in c (CVE-2026-12236)
vulnerability in c (CVE-2026-12236). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18428 |
|
Vulnerability in Amazon aws (CVE-2026-18428)
vulnerability in Amazon aws (CVE-2026-18428). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58508 |
|
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
|
| CVE-2026-58433 |
|
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
|
| CVE-2026-55986 |
|
Email Management API Bypasses ManageCredentials Feature Restrictions
Email Management API Bypasses ManageCredentials Feature Restrictions
|
| CVE-2025-7639 |
|
Unsafe Deserialization in cisa (CVE-2025-7639)
vulnerability in cisa (CVE-2025-7639). Data can be tampered with by attackers.
|
| CVE-2026-34491 |
|
Cross-Site Scripting (XSS) in cisa (CVE-2026-34491)
cross-site scripting in cisa (CVE-2026-34491). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19188 |
|
OS Command Injection in cisa (CVE-2026-19188)
OS command injection in cisa (CVE-2026-19188). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73671 |
|
Open Redirect in CVE-2026-73671 (CVE-2026-73671)
vulnerability in CVE-2026-73671 (CVE-2026-73671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73670 |
|
SQL Injection in sqli (CVE-2026-73670)
SQL injection in sqli (CVE-2026-73670). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73576 |
|
Vulnerability in synacor (CVE-2026-73576)
vulnerability in synacor (CVE-2026-73576). Data can be tampered with by attackers.
|
| CVE-2026-73575 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73575)
vulnerability in csrf (CVE-2026-73575). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73574 |
|
Vulnerability in synacor (CVE-2026-73574)
vulnerability in synacor (CVE-2026-73574). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73573 |
|
Vulnerability in path-traversal (CVE-2026-73573)
vulnerability in path-traversal (CVE-2026-73573). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73572 |
|
Cross-Site Scripting (XSS) in synacor (CVE-2026-73572)
cross-site scripting in synacor (CVE-2026-73572). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73571 |
|
Authorization Flaw in c (CVE-2026-73571)
vulnerability in c (CVE-2026-73571). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73570 KEV |
|
[KEV] OS Command Injection in Synacor zimbra-collaboration-suite (CVE-2026-73570)
OS command injection in Synacor zimbra-collaboration-suite (CVE-2026-73570). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-73559 |
|
Vulnerability in vllm (CVE-2026-73559)
vulnerability in vllm (CVE-2026-73559). Risk of unauthorized operations or information disclosure. Exploitable via ``prompt``. Mitigation: upgrade to `0.19.0` or later.
|
| CVE-2026-73533 |
|
Vulnerability in CVE-2026-73533 (CVE-2026-73533)
vulnerability in CVE-2026-73533 (CVE-2026-73533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73532 |
|
Vulnerability in CVE-2026-73532 (CVE-2026-73532)
vulnerability in CVE-2026-73532 (CVE-2026-73532). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73515 |
|
Out-of-Bounds Read in dos (CVE-2026-73515)
vulnerability in dos (CVE-2026-73515). Confidential information can be exposed externally.
|
| CVE-2026-73514 |
|
Out-of-Bounds Write in CVE-2026-73514 (CVE-2026-73514)
out-of-bounds write in CVE-2026-73514 (CVE-2026-73514). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55401 |
|
Vulnerability in CVE-2026-55401 (CVE-2026-55401)
vulnerability in CVE-2026-55401 (CVE-2026-55401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55400 |
|
Vulnerability in dos (CVE-2026-55400)
vulnerability in dos (CVE-2026-55400). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19744 |
|
Cross-Site Scripting (XSS) in CVE-2026-19744 (CVE-2026-19744)
cross-site scripting in CVE-2026-19744 (CVE-2026-19744). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19710 |
|
Vulnerability in sqli (CVE-2026-19710)
vulnerability in sqli (CVE-2026-19710). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19487 |
|
Vulnerability in c (CVE-2026-19487)
vulnerability in c (CVE-2026-19487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65936 |
|
Vulnerability in CVE-2026-65936 (CVE-2026-65936)
vulnerability in CVE-2026-65936 (CVE-2026-65936). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68454 |
|
Vulnerability in CVE-2026-68454 (CVE-2026-68454)
vulnerability in CVE-2026-68454 (CVE-2026-68454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68452 |
|
Vulnerability in CVE-2026-68452 (CVE-2026-68452)
vulnerability in CVE-2026-68452 (CVE-2026-68452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68453 |
|
Vulnerability in CVE-2026-68453 (CVE-2026-68453)
vulnerability in CVE-2026-68453 (CVE-2026-68453). Confidential information can be exposed externally.
|
| CVE-2026-65935 |
|
Vulnerability in CVE-2026-65935 (CVE-2026-65935)
vulnerability in CVE-2026-65935 (CVE-2026-65935). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63424 |
|
Vulnerability in CVE-2026-63424 (CVE-2026-63424)
vulnerability in CVE-2026-63424 (CVE-2026-63424). Data can be tampered with by attackers.
|
| CVE-2026-65933 |
|
Vulnerability in CVE-2026-65933 (CVE-2026-65933)
vulnerability in CVE-2026-65933 (CVE-2026-65933). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66256 |
|
Unsafe Deserialization in apache (CVE-2026-66256)
vulnerability in apache (CVE-2026-66256). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65934 |
|
Vulnerability in dos (CVE-2026-65934)
vulnerability in dos (CVE-2026-65934). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63425 |
|
Vulnerability in CVE-2026-63425 (CVE-2026-63425)
vulnerability in CVE-2026-63425 (CVE-2026-63425). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63426 |
|
Vulnerability in CVE-2026-63426 (CVE-2026-63426)
vulnerability in CVE-2026-63426 (CVE-2026-63426). Data can be tampered with by attackers.
|
| CVE-2026-65932 |
|
Vulnerability in dos (CVE-2026-65932)
vulnerability in dos (CVE-2026-65932). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68451 |
|
Vulnerability in CVE-2026-68451 (CVE-2026-68451)
vulnerability in CVE-2026-68451 (CVE-2026-68451). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6387 |
|
Vulnerability in CVE-2026-6387 (CVE-2026-6387)
vulnerability in CVE-2026-6387 (CVE-2026-6387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63423 |
|
Vulnerability in CVE-2026-63423 (CVE-2026-63423)
vulnerability in CVE-2026-63423 (CVE-2026-63423). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28154 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-28154)
cross-site scripting in wordpress (CVE-2026-28154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14256 |
|
Out-of-Bounds Read in CVE-2026-14256 (CVE-2026-14256)
vulnerability in CVE-2026-14256 (CVE-2026-14256). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19734 |
|
Vulnerability in CVE-2026-19734 (CVE-2026-19734)
vulnerability in CVE-2026-19734 (CVE-2026-19734). Risk of unauthorized operations or information disclosure. Exploitable via ``ProductUpdateController``.
|
| CVE-2026-19291 |
|
Vulnerability in CVE-2026-19291 (CVE-2026-19291)
vulnerability in CVE-2026-19291 (CVE-2026-19291). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15994 |
|
Vulnerability in c (CVE-2026-15994)
vulnerability in c (CVE-2026-15994). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14456 |
|
Vulnerability in dos (CVE-2026-14456)
vulnerability in dos (CVE-2026-14456). Risk of unauthorized operations or information disclosure.
|