Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-67587 |
|
Unsafe Deserialization in apache (CVE-2026-67587)
vulnerability in apache (CVE-2026-67587). Successful exploitation can lead to full system takeover. Exploitable via ``Callback``.
|
| CVE-2026-67260 |
|
Unsafe Deserialization in apache (CVE-2026-67260)
vulnerability in apache (CVE-2026-67260). Risk of unauthorized operations or information disclosure. Exploitable via ``awaiting_input``.
|
| CVE-2026-66384 KEV |
|
[KEV] Path Traversal in Jfrog artifactory (CVE-2026-66384)
path traversal in Jfrog artifactory (CVE-2026-66384). Data can be tampered with by attackers. Listed in CISA KEV — actively exploited.
|
| CVE-2026-66016 |
|
Vulnerability in CVE-2026-66016 (CVE-2026-66016)
vulnerability in CVE-2026-66016 (CVE-2026-66016). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65941 |
|
Vulnerability in CVE-2026-65941 (CVE-2026-65941)
vulnerability in CVE-2026-65941 (CVE-2026-65941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65940 |
|
Vulnerability in CVE-2026-65940 (CVE-2026-65940)
vulnerability in CVE-2026-65940 (CVE-2026-65940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65939 |
|
Path Traversal in CVE-2026-65939 (CVE-2026-65939)
path traversal in CVE-2026-65939 (CVE-2026-65939). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65938 |
|
Vulnerability in CVE-2026-65938 (CVE-2026-65938)
vulnerability in CVE-2026-65938 (CVE-2026-65938). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65937 |
|
Cross-Site Scripting (XSS) in CVE-2026-65937 (CVE-2026-65937)
cross-site scripting in CVE-2026-65937 (CVE-2026-65937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65926 |
|
Vulnerability in CVE-2026-65926 (CVE-2026-65926)
vulnerability in CVE-2026-65926 (CVE-2026-65926). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65017 |
|
Information Disclosure in apache (CVE-2026-65017)
vulnerability in apache (CVE-2026-65017). Confidential information can be exposed externally.
|
| CVE-2026-64639 |
|
Vulnerability in CVE-2026-64639 (CVE-2026-64639)
vulnerability in CVE-2026-64639 (CVE-2026-64639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59244 |
|
Vulnerability in apache (CVE-2026-59244)
vulnerability in apache (CVE-2026-59244). Confidential information can be exposed externally.
|
| CVE-2026-59242 |
|
Unsafe Deserialization in apache (CVE-2026-59242)
vulnerability in apache (CVE-2026-59242). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v2/{...}/xcomEntries/{key}`.
|
| CVE-2026-58076 |
|
Unsafe Deserialization in apache (CVE-2026-58076)
vulnerability in apache (CVE-2026-58076). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v2/dags/{dag_id}/details`.
|
| CVE-2026-54183 |
|
Information Disclosure in apache (CVE-2026-54183)
vulnerability in apache (CVE-2026-54183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19548 |
|
Use-After-Free in c (CVE-2026-19548)
vulnerability in c (CVE-2026-19548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15803 |
|
XXE (XML External Entity) in CVE-2026-15803 (CVE-2026-15803)
vulnerability in CVE-2026-15803 (CVE-2026-15803). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-35988 |
|
Vulnerability in CVE-2025-35988 (CVE-2025-35988)
vulnerability in CVE-2025-35988 (CVE-2025-35988). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-35977 |
|
Vulnerability in CVE-2025-35977 (CVE-2025-35977)
vulnerability in CVE-2025-35977 (CVE-2025-35977). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-32737 |
|
Vulnerability in CVE-2025-32737 (CVE-2025-32737)
vulnerability in CVE-2025-32737 (CVE-2025-32737). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-32087 |
|
Vulnerability in CVE-2025-32087 (CVE-2025-32087)
vulnerability in CVE-2025-32087 (CVE-2025-32087). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-32084 |
|
Vulnerability in CVE-2025-32084 (CVE-2025-32084)
vulnerability in CVE-2025-32084 (CVE-2025-32084). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-31943 |
|
Vulnerability in CVE-2025-31943 (CVE-2025-31943)
vulnerability in CVE-2025-31943 (CVE-2025-31943). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-30178 |
|
Vulnerability in CVE-2025-30178 (CVE-2025-30178)
vulnerability in CVE-2025-30178 (CVE-2025-30178). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-27570 |
|
Vulnerability in CVE-2025-27570 (CVE-2025-27570)
vulnerability in CVE-2025-27570 (CVE-2025-27570). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-27245 |
|
Vulnerability in CVE-2025-27245 (CVE-2025-27245)
vulnerability in CVE-2025-27245 (CVE-2025-27245). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-25275 |
|
Vulnerability in CVE-2025-25275 (CVE-2025-25275)
vulnerability in CVE-2025-25275 (CVE-2025-25275). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-24837 |
|
Vulnerability in CVE-2025-24837 (CVE-2025-24837)
vulnerability in CVE-2025-24837 (CVE-2025-24837). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-24488 |
|
Vulnerability in CVE-2025-24488 (CVE-2025-24488)
vulnerability in CVE-2025-24488 (CVE-2025-24488). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-20020 |
|
Vulnerability in CVE-2025-20020 (CVE-2025-20020)
vulnerability in CVE-2025-20020 (CVE-2025-20020). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73405 |
|
Vulnerability in CVE-2026-73405 (CVE-2026-73405)
vulnerability in CVE-2026-73405 (CVE-2026-73405). Risk of unauthorized operations or information disclosure. Exploitable via `X-API-Key header`.
|
| CVE-2026-73431 |
|
Vulnerability in CVE-2026-73431 (CVE-2026-73431)
vulnerability in CVE-2026-73431 (CVE-2026-73431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73374 |
|
Cross-Site Scripting (XSS) in CVE-2026-73374 (CVE-2026-73374)
cross-site scripting in CVE-2026-73374 (CVE-2026-73374). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73432 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-73432)
SSRF in ssrf (CVE-2026-73432). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68757 |
|
A user with access to a valid SAML response may impersonate another user under specific conditions.
A user with access to a valid SAML response may impersonate another user under specific conditions.
|
| CVE-2026-68755 |
|
A bundle writer may create misleading release promotion information under specific conditions.
A bundle writer may create misleading release promotion information under specific conditions.
|
| CVE-2026-68760 |
|
An unauthenticated user may bypass authentication under specific cache conditions.
An unauthenticated user may bypass authentication under specific cache conditions.
|
| CVE-2026-68756 |
|
Unsafe Deserialization in CVE-2026-68756 (CVE-2026-68756)
vulnerability in CVE-2026-68756 (CVE-2026-68756). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68754 |
|
Vulnerability in CVE-2026-68754 (CVE-2026-68754)
vulnerability in CVE-2026-68754 (CVE-2026-68754). Data can be tampered with by attackers.
|
| CVE-2026-68753 |
|
Vulnerability in CVE-2026-68753 (CVE-2026-68753)
vulnerability in CVE-2026-68753 (CVE-2026-68753). Confidential information can be exposed externally.
|
| CVE-2026-68752 |
|
A Project Resource Manager may gain broader administrative privileges under specific conditions.
A Project Resource Manager may gain broader administrative privileges under specific conditions.
|
| CVE-2026-66382 |
|
Path Traversal in CVE-2026-66382 (CVE-2026-66382)
path traversal in CVE-2026-66382 (CVE-2026-66382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66381 |
|
Path Traversal in CVE-2026-66381 (CVE-2026-66381)
path traversal in CVE-2026-66381 (CVE-2026-66381). Confidential information can be exposed externally.
|
| CVE-2026-66380 |
|
Vulnerability in CVE-2026-66380 (CVE-2026-66380)
vulnerability in CVE-2026-66380 (CVE-2026-66380). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67286 |
|
Path Traversal in CVE-2026-67286 (CVE-2026-67286)
path traversal in CVE-2026-67286 (CVE-2026-67286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66379 |
|
An authenticated user may view private Puppet module metadata without repository read access.
An authenticated user may view private Puppet module metadata without repository read access.
|
| CVE-2026-67287 |
|
Vulnerability in CVE-2026-67287 (CVE-2026-67287)
vulnerability in CVE-2026-67287 (CVE-2026-67287). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66376 |
|
Credentials for a deleted user may remain valid for a short period under specific conditions.
Credentials for a deleted user may remain valid for a short period under specific conditions.
|
| CVE-2026-66377 |
|
An unauthenticated user may access restricted repository information under specific conditions.
An unauthenticated user may access restricted repository information under specific conditions.
|