Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-57265 Vulnerability in CVE-2026-57265 (CVE-2026-57265)
vulnerability in CVE-2026-57265 (CVE-2026-57265). Successful exploitation can lead to full system takeover. Exploitable via ``index``.
CVE-2026-13125 GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
CVE-2026-14415 Vulnerability in google (CVE-2026-14415)
vulnerability in google (CVE-2026-14415). Successful exploitation can lead to full system takeover.
CVE-2026-14422 Out-of-Bounds Read in google (CVE-2026-14422)
vulnerability in google (CVE-2026-14422). Successful exploitation can lead to full system takeover.
CVE-2026-14430 Vulnerability in google (CVE-2026-14430)
vulnerability in google (CVE-2026-14430). Successful exploitation can lead to full system takeover.
CVE-2026-14426 Use-After-Free in google (CVE-2026-14426)
vulnerability in google (CVE-2026-14426). Successful exploitation can lead to full system takeover.
CVE-2026-14431 Vulnerability in google (CVE-2026-14431)
vulnerability in google (CVE-2026-14431). Successful exploitation can lead to full system takeover.
CVE-2026-14428 Vulnerability in google (CVE-2026-14428)
vulnerability in google (CVE-2026-14428). Successful exploitation can lead to full system takeover.
CVE-2026-14427 Vulnerability in google (CVE-2026-14427)
vulnerability in google (CVE-2026-14427). Successful exploitation can lead to full system takeover.
CVE-2026-14432 Use-After-Free in google (CVE-2026-14432)
vulnerability in google (CVE-2026-14432). Successful exploitation can lead to full system takeover.
CVE-2026-14429 Vulnerability in google (CVE-2026-14429)
vulnerability in google (CVE-2026-14429). Successful exploitation can lead to full system takeover.
CVE-2026-14409 Vulnerability in google (CVE-2026-14409)
vulnerability in google (CVE-2026-14409). Successful exploitation can lead to full system takeover.
CVE-2026-14407 Code Injection in google (CVE-2026-14407)
code injection in google (CVE-2026-14407). Successful exploitation can lead to full system takeover.
CVE-2026-14413 Vulnerability in google (CVE-2026-14413)
vulnerability in google (CVE-2026-14413). Successful exploitation can lead to full system takeover.
CVE-2026-14412 Vulnerability in google (CVE-2026-14412)
vulnerability in google (CVE-2026-14412). Successful exploitation can lead to full system takeover.
CVE-2026-14394 Use-After-Free in google (CVE-2026-14394)
vulnerability in google (CVE-2026-14394). Successful exploitation can lead to full system takeover.
CVE-2026-14400 Out-of-Bounds Write in google (CVE-2026-14400)
out-of-bounds write in google (CVE-2026-14400). Successful exploitation can lead to full system takeover.
CVE-2026-14401 Vulnerability in google (CVE-2026-14401)
vulnerability in google (CVE-2026-14401). Successful exploitation can lead to full system takeover.
CVE-2026-14403 Use-After-Free in google (CVE-2026-14403)
vulnerability in google (CVE-2026-14403). Successful exploitation can lead to full system takeover.
CVE-2026-14393 Use-After-Free in google (CVE-2026-14393)
vulnerability in google (CVE-2026-14393). Successful exploitation can lead to full system takeover.
CVE-2026-14389 Vulnerability in google (CVE-2026-14389)
vulnerability in google (CVE-2026-14389). Successful exploitation can lead to full system takeover.
CVE-2026-14395 Out-of-Bounds Write in google (CVE-2026-14395)
out-of-bounds write in google (CVE-2026-14395). Successful exploitation can lead to full system takeover.
CVE-2026-38891 Vulnerability in cpp (CVE-2026-38891)
vulnerability in cpp (CVE-2026-38891). Risk of unauthorized operations or information disclosure.
CVE-2026-52190 Vulnerability in dos (CVE-2026-52190)
vulnerability in dos (CVE-2026-52190). Risk of unauthorized operations or information disclosure.
CVE-2026-14383 Code Injection in google (CVE-2026-14383)
code injection in google (CVE-2026-14383). Successful exploitation can lead to full system takeover.
CVE-2026-14385 Vulnerability in google (CVE-2026-14385)
vulnerability in google (CVE-2026-14385). Successful exploitation can lead to full system takeover.
CVE-2026-36912 Vulnerability in dos (CVE-2026-36912)
vulnerability in dos (CVE-2026-36912). Risk of unauthorized operations or information disclosure.
CVE-2026-54263 Cross-Site Scripting (XSS) in wagtail (CVE-2026-54263)
cross-site scripting in wagtail (CVE-2026-54263). Confidential information can be exposed externally. Mitigation: upgrade to `7.4.2` or later.
CVE-2026-50143 SSRF (Server-Side Request Forgery) in @apify/actors-mcp-server (CVE-2026-50143)
SSRF in @apify/actors-mcp-server (CVE-2026-50143). Confidential information can be exposed externally. Exploitable via ``webServerMcpPath``. Mitigation: upgrade to `0.10.11` or later.
CVE-2026-50138 Vulnerability in goshs.de/goshs/v2 (CVE-2026-50138)
vulnerability in goshs.de/goshs/v2 (CVE-2026-50138). Confidential information can be exposed externally. Exploitable via ``goshs``. Mitigation: upgrade to `2.1.0` or later.
CVE-2026-50163 Path Traversal in oras.land/oras-go/v2 (CVE-2026-50163)
path traversal in oras.land/oras-go/v2 (CVE-2026-50163). Confidential information can be exposed externally. Exploitable via ``ensureLinkPath``. Mitigation: upgrade to `2.6.2` or later.
CVE-2026-58592 Out-of-Bounds Write in cpp (CVE-2026-58592)
out-of-bounds write in cpp (CVE-2026-58592). Successful exploitation can lead to full system takeover.
CVE-2026-58593 Vulnerability in nodebb (CVE-2026-58593)
vulnerability in nodebb (CVE-2026-58593). Data can be tampered with by attackers.
CVE-2026-50521 Use-After-Free in microsoft (CVE-2026-50521)
vulnerability in microsoft (CVE-2026-50521). Confidential information can be exposed externally.
CVE-2026-41121 Vulnerability in dell (CVE-2026-41121)
vulnerability in dell (CVE-2026-41121). Successful exploitation can lead to full system takeover.
CVE-2026-49119 Path Traversal in gradio (CVE-2026-49119)
path traversal in gradio (CVE-2026-49119). Confidential information can be exposed externally. Mitigation: upgrade to `6.16.0` or later.
CVE-2026-50151 SSRF (Server-Side Request Forgery) in oras.land/oras-go/v2 (CVE-2026-50151)
SSRF in oras.land/oras-go/v2 (CVE-2026-50151). Confidential information can be exposed externally. Exploitable via ``Location``. Mitigation: upgrade to `2.6.1` or later.
CVE-2026-58263 Cross-Site Scripting (XSS) in jodit (CVE-2026-58263)
cross-site scripting in jodit (CVE-2026-58263). Risk of unauthorized operations or information disclosure. Exploitable via ``onerror``. Mitigation: upgrade to `4.12.28` or later.
CVE-2026-55153 Vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153)
vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153). Successful exploitation can lead to full system takeover. Exploitable via ``ObjectFactory``. Mitigation: upgrade to `0.6.0` or later.
CVE-2026-41053 Vulnerability in github.com/rancher/rancher (CVE-2026-41053)
vulnerability in github.com/rancher/rancher (CVE-2026-41053). Successful exploitation can lead to full system takeover. Exploitable via ``allowedPrincipalIds``. Mitigation: upgrade to `0.0.0-20260519172014-d0c047bbc6d2` or later.
CVE-2026-44937 Vulnerability in github.com/rancher/fleet (CVE-2026-44937)
vulnerability in github.com/rancher/fleet (CVE-2026-44937). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.12.15` or later.
CVE-2026-44938 Vulnerability in github.com/rancher/fleet (CVE-2026-44938)
vulnerability in github.com/rancher/fleet (CVE-2026-44938). Successful exploitation can lead to full system takeover. Exploitable via ``namespaceLabels``. Mitigation: upgrade to `0.12.15` or later.
CVE-2026-14265 Unsafe Deserialization in Amazon aws (CVE-2026-14265)
vulnerability in Amazon aws (CVE-2026-14265). Successful exploitation can lead to full system takeover.
CVE-2026-49998 Vulnerability in github.com/centrifugal/centrifugo/v6 (CVE-2026-49998)
vulnerability in github.com/centrifugal/centrifugo/v6 (CVE-2026-49998). Confidential information can be exposed externally. Exploitable via ``singleflight``. Mitigation: upgrade to `6.8.1` or later.
CVE-2026-48815 Vulnerability in sigstore (CVE-2026-48815)
vulnerability in sigstore (CVE-2026-48815). Data can be tampered with by attackers. Exploitable via ``certificateOIDs``. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-13760 OS Command Injection in Amazon aws-cdk-lib (CVE-2026-13760)
OS command injection in Amazon aws-cdk-lib (CVE-2026-13760). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.260.0` or later.
CVE-2026-49987 Vulnerability in repomix (CVE-2026-49987)
vulnerability in repomix (CVE-2026-49987). Successful exploitation can lead to full system takeover. Exploitable via ``execGitShallowClone``. Mitigation: upgrade to `1.14.1` or later.
CVE-2026-49981 Vulnerability in twig/twig (CVE-2026-49981)
vulnerability in twig/twig (CVE-2026-49981). Confidential information can be exposed externally. Exploitable via ``Template``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-58454 Code Injection in CVE-2026-58454 (CVE-2026-58454)
code injection in CVE-2026-58454 (CVE-2026-58454). Successful exploitation can lead to full system takeover.
CVE-2026-58452 OS Command Injection in CVE-2026-58452 (CVE-2026-58452)
OS command injection in CVE-2026-58452 (CVE-2026-58452). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →