Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-58384 |
|
Vulnerability in dos (CVE-2026-58384)
vulnerability in dos (CVE-2026-58384). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8377 |
|
Vulnerability in CVE-2026-8377 (CVE-2026-8377)
vulnerability in CVE-2026-8377 (CVE-2026-8377). Confidential information can be exposed externally.
|
| CVE-2026-5799 |
|
Vulnerability in CVE-2026-5799 (CVE-2026-5799)
vulnerability in CVE-2026-5799 (CVE-2026-5799). Confidential information can be exposed externally.
|
| CVE-2026-5730 |
|
Vulnerability in CVE-2026-5730 (CVE-2026-5730)
vulnerability in CVE-2026-5730 (CVE-2026-5730). Confidential information can be exposed externally.
|
| CVE-2026-12277 |
|
Vulnerability in wordpress (CVE-2026-12277)
vulnerability in wordpress (CVE-2026-12277). Data can be tampered with by attackers.
|
| CVE-2026-34158 |
|
OS Command Injection in CVE-2026-34158 (CVE-2026-34158)
OS command injection in CVE-2026-34158 (CVE-2026-34158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42200 |
|
Path Traversal in CVE-2026-42200 (CVE-2026-42200)
path traversal in CVE-2026-42200 (CVE-2026-42200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42143 |
|
OS Command Injection in CVE-2026-42143 (CVE-2026-42143)
OS command injection in CVE-2026-42143 (CVE-2026-42143). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34168 |
|
OS Command Injection in CVE-2026-34168 (CVE-2026-34168)
OS command injection in CVE-2026-34168 (CVE-2026-34168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34171 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-34171 (CVE-2026-34171)
vulnerability in CVE-2026-34171 (CVE-2026-34171). Confidential information can be exposed externally. Exploitable via `GET /invitations/{uuid}`.
|
| CVE-2026-34152 |
|
OS Command Injection in CVE-2026-34152 (CVE-2026-34152)
OS command injection in CVE-2026-34152 (CVE-2026-34152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34058 |
|
OS Command Injection in CVE-2026-34058 (CVE-2026-34058)
OS command injection in CVE-2026-34058 (CVE-2026-34058). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34044 |
|
Vulnerability in CVE-2026-34044 (CVE-2026-34044)
vulnerability in CVE-2026-34044 (CVE-2026-34044). Confidential information can be exposed externally.
|
| CVE-2026-34057 |
|
OS Command Injection in CVE-2026-34057 (CVE-2026-34057)
OS command injection in CVE-2026-34057 (CVE-2026-34057). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34035 |
|
OS Command Injection in CVE-2026-34035 (CVE-2026-34035)
OS command injection in CVE-2026-34035 (CVE-2026-34035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34034 |
|
OS Command Injection in CVE-2026-34034 (CVE-2026-34034)
OS command injection in CVE-2026-34034 (CVE-2026-34034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42204 |
|
OS Command Injection in CVE-2026-42204 (CVE-2026-42204)
OS command injection in CVE-2026-42204 (CVE-2026-42204). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42153 |
|
OS Command Injection in CVE-2026-42153 (CVE-2026-42153)
OS command injection in CVE-2026-42153 (CVE-2026-42153). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34153 |
|
OS Command Injection in CVE-2026-34153 (CVE-2026-34153)
OS command injection in CVE-2026-34153 (CVE-2026-34153). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38976 |
|
Vulnerability in c (CVE-2026-38976)
vulnerability in c (CVE-2026-38976). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34599 |
|
OS Command Injection in CVE-2026-34599 (CVE-2026-34599)
OS command injection in CVE-2026-34599 (CVE-2026-34599). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55501 |
|
Vulnerability in 9router (CVE-2026-55501)
vulnerability in 9router (CVE-2026-55501). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/auth/login`. Mitigation: upgrade to `0.4.77` or later.
|
| CVE-2026-55727 |
|
Authentication Bypass in CVE-2026-55727 (CVE-2026-55727)
authentication bypass in CVE-2026-55727 (CVE-2026-55727). Confidential information can be exposed externally.
|
| CVE-2026-59713 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-59713)
vulnerability in csrf (CVE-2026-59713). Confidential information can be exposed externally.
|
| CVE-2026-59712 |
|
Vulnerability in CVE-2026-59712 (CVE-2026-59712)
vulnerability in CVE-2026-59712 (CVE-2026-59712). Confidential information can be exposed externally.
|
| CVE-2026-14468 |
|
Path Traversal in CVE-2026-14468 (CVE-2026-14468)
path traversal in CVE-2026-14468 (CVE-2026-14468). Confidential information can be exposed externally.
|
| CVE-2026-21379 |
|
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
|
| CVE-2026-25271 |
|
Vulnerability in qualcomm (CVE-2026-25271)
vulnerability in qualcomm (CVE-2026-25271). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25268 |
|
Vulnerability in qualcomm (CVE-2026-25268)
vulnerability in qualcomm (CVE-2026-25268). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21383 |
|
Vulnerability in qualcomm (CVE-2026-21383)
vulnerability in qualcomm (CVE-2026-21383). Confidential information can be exposed externally.
|
| CVE-2026-14471 |
|
SQL Injection in Amazon aws (CVE-2026-14471)
SQL injection in Amazon aws (CVE-2026-14471). Confidential information can be exposed externally.
|
| CVE-2026-57573 |
|
SSRF (Server-Side Request Forgery) in crawl4ai (CVE-2026-57573)
SSRF in crawl4ai (CVE-2026-57573). Confidential information can be exposed externally. Exploitable via `POST /crawl/stream`. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-54765 |
|
Vulnerability in github.com/traefik/traefik/v3 (CVE-2026-54765)
vulnerability in github.com/traefik/traefik/v3 (CVE-2026-54765). Data can be tampered with by attackers. Exploitable via ``backendRef``. Mitigation: upgrade to `3.7.6` or later.
|
| CVE-2026-55574 |
|
Vulnerability in vllm (CVE-2026-55574)
vulnerability in vllm (CVE-2026-55574). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.24.0` or later.
|
| CVE-2026-54234 |
|
Vulnerability in vllm (CVE-2026-54234)
vulnerability in vllm (CVE-2026-54234). Risk of unauthorized operations or information disclosure. Exploitable via ``vocab_size``. Mitigation: upgrade to `0.24.0` or later.
|
| CVE-2026-55426 |
|
OS Command Injection in linuxfabrik-lib (CVE-2026-55426)
OS command injection in linuxfabrik-lib (CVE-2026-55426). Successful exploitation can lead to full system takeover. Exploitable via ``shell_exec``. Mitigation: upgrade to `5.0.0` or later.
|
| CVE-2026-55436 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-55436)
vulnerability in github.com/coder/coder/v2 (CVE-2026-55436). Confidential information can be exposed externally. Exploitable via ``aibridgeproxyd``. Mitigation: upgrade to `2.32.7` or later.
|
| CVE-2026-55431 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-55431)
vulnerability in github.com/coder/coder/v2 (CVE-2026-55431). Confidential information can be exposed externally. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-55428 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-55428)
vulnerability in github.com/coder/coder/v2 (CVE-2026-55428). Confidential information can be exposed externally. Exploitable via ``Addresses``. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-55429 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-55429)
vulnerability in github.com/coder/coder/v2 (CVE-2026-55429). Confidential information can be exposed externally. Exploitable via ``UpsertWorkspaceApp``. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-55427 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-55427)
vulnerability in github.com/coder/coder/v2 (CVE-2026-55427). Successful exploitation can lead to full system takeover. Exploitable via ``HostnameSuffix``. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-55077 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-55077)
vulnerability in github.com/coder/coder/v2 (CVE-2026-55077). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/v2/users/{user}/password`. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-55075 |
|
Authentication Bypass in github.com/coder/coder/v2 (CVE-2026-55075)
authentication bypass in github.com/coder/coder/v2 (CVE-2026-55075). Confidential information can be exposed externally. Exploitable via ``email_verified``. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-55076 |
|
Authentication Bypass in github.com/coder/coder/v2 (CVE-2026-55076)
authentication bypass in github.com/coder/coder/v2 (CVE-2026-55076). Confidential information can be exposed externally. Exploitable via ``email_verified``. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-54771 |
|
Vulnerability in langroid (CVE-2026-54771)
vulnerability in langroid (CVE-2026-54771). Confidential information can be exposed externally. Exploitable via ``Entity.USER``. Mitigation: upgrade to `0.65.3` or later.
|
| CVE-2026-14536 |
|
Authorization Flaw in devolutions (CVE-2026-14536)
vulnerability in devolutions (CVE-2026-14536). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54059 |
|
Vulnerability in pillow (CVE-2026-54059)
vulnerability in pillow (CVE-2026-54059). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-54060 |
|
Vulnerability in pillow (CVE-2026-54060)
vulnerability in pillow (CVE-2026-54060). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-55379 |
|
Vulnerability in pillow (CVE-2026-55379)
vulnerability in pillow (CVE-2026-55379). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-55380 |
|
Vulnerability in pillow (CVE-2026-55380)
vulnerability in pillow (CVE-2026-55380). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.3.0` or later.
|