Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-57265 |
|
Vulnerability in CVE-2026-57265 (CVE-2026-57265)
vulnerability in CVE-2026-57265 (CVE-2026-57265). Successful exploitation can lead to full system takeover. Exploitable via ``index``.
|
| CVE-2026-13125 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-14415 |
|
Vulnerability in google (CVE-2026-14415)
vulnerability in google (CVE-2026-14415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14422 |
|
Out-of-Bounds Read in google (CVE-2026-14422)
vulnerability in google (CVE-2026-14422). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14430 |
|
Vulnerability in google (CVE-2026-14430)
vulnerability in google (CVE-2026-14430). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14426 |
|
Use-After-Free in google (CVE-2026-14426)
vulnerability in google (CVE-2026-14426). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14431 |
|
Vulnerability in google (CVE-2026-14431)
vulnerability in google (CVE-2026-14431). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14428 |
|
Vulnerability in google (CVE-2026-14428)
vulnerability in google (CVE-2026-14428). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14427 |
|
Vulnerability in google (CVE-2026-14427)
vulnerability in google (CVE-2026-14427). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14432 |
|
Use-After-Free in google (CVE-2026-14432)
vulnerability in google (CVE-2026-14432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14429 |
|
Vulnerability in google (CVE-2026-14429)
vulnerability in google (CVE-2026-14429). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14409 |
|
Vulnerability in google (CVE-2026-14409)
vulnerability in google (CVE-2026-14409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14407 |
|
Code Injection in google (CVE-2026-14407)
code injection in google (CVE-2026-14407). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14413 |
|
Vulnerability in google (CVE-2026-14413)
vulnerability in google (CVE-2026-14413). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14412 |
|
Vulnerability in google (CVE-2026-14412)
vulnerability in google (CVE-2026-14412). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14394 |
|
Use-After-Free in google (CVE-2026-14394)
vulnerability in google (CVE-2026-14394). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14400 |
|
Out-of-Bounds Write in google (CVE-2026-14400)
out-of-bounds write in google (CVE-2026-14400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14401 |
|
Vulnerability in google (CVE-2026-14401)
vulnerability in google (CVE-2026-14401). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14403 |
|
Use-After-Free in google (CVE-2026-14403)
vulnerability in google (CVE-2026-14403). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14393 |
|
Use-After-Free in google (CVE-2026-14393)
vulnerability in google (CVE-2026-14393). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14389 |
|
Vulnerability in google (CVE-2026-14389)
vulnerability in google (CVE-2026-14389). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14395 |
|
Out-of-Bounds Write in google (CVE-2026-14395)
out-of-bounds write in google (CVE-2026-14395). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38891 |
|
Vulnerability in cpp (CVE-2026-38891)
vulnerability in cpp (CVE-2026-38891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52190 |
|
Vulnerability in dos (CVE-2026-52190)
vulnerability in dos (CVE-2026-52190). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14383 |
|
Code Injection in google (CVE-2026-14383)
code injection in google (CVE-2026-14383). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14385 |
|
Vulnerability in google (CVE-2026-14385)
vulnerability in google (CVE-2026-14385). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36912 |
|
Vulnerability in dos (CVE-2026-36912)
vulnerability in dos (CVE-2026-36912). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54263 |
|
Cross-Site Scripting (XSS) in wagtail (CVE-2026-54263)
cross-site scripting in wagtail (CVE-2026-54263). Confidential information can be exposed externally. Mitigation: upgrade to `7.4.2` or later.
|
| CVE-2026-50143 |
|
SSRF (Server-Side Request Forgery) in @apify/actors-mcp-server (CVE-2026-50143)
SSRF in @apify/actors-mcp-server (CVE-2026-50143). Confidential information can be exposed externally. Exploitable via ``webServerMcpPath``. Mitigation: upgrade to `0.10.11` or later.
|
| CVE-2026-50138 |
|
Vulnerability in goshs.de/goshs/v2 (CVE-2026-50138)
vulnerability in goshs.de/goshs/v2 (CVE-2026-50138). Confidential information can be exposed externally. Exploitable via ``goshs``. Mitigation: upgrade to `2.1.0` or later.
|
| CVE-2026-50163 |
|
Path Traversal in oras.land/oras-go/v2 (CVE-2026-50163)
path traversal in oras.land/oras-go/v2 (CVE-2026-50163). Confidential information can be exposed externally. Exploitable via ``ensureLinkPath``. Mitigation: upgrade to `2.6.2` or later.
|
| CVE-2026-58592 |
|
Out-of-Bounds Write in cpp (CVE-2026-58592)
out-of-bounds write in cpp (CVE-2026-58592). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58593 |
|
Vulnerability in nodebb (CVE-2026-58593)
vulnerability in nodebb (CVE-2026-58593). Data can be tampered with by attackers.
|
| CVE-2026-50521 |
|
Use-After-Free in microsoft (CVE-2026-50521)
vulnerability in microsoft (CVE-2026-50521). Confidential information can be exposed externally.
|
| CVE-2026-41121 |
|
Vulnerability in dell (CVE-2026-41121)
vulnerability in dell (CVE-2026-41121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49119 |
|
Path Traversal in gradio (CVE-2026-49119)
path traversal in gradio (CVE-2026-49119). Confidential information can be exposed externally. Mitigation: upgrade to `6.16.0` or later.
|
| CVE-2026-50151 |
|
SSRF (Server-Side Request Forgery) in oras.land/oras-go/v2 (CVE-2026-50151)
SSRF in oras.land/oras-go/v2 (CVE-2026-50151). Confidential information can be exposed externally. Exploitable via ``Location``. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2026-58263 |
|
Cross-Site Scripting (XSS) in jodit (CVE-2026-58263)
cross-site scripting in jodit (CVE-2026-58263). Risk of unauthorized operations or information disclosure. Exploitable via ``onerror``. Mitigation: upgrade to `4.12.28` or later.
|
| CVE-2026-55153 |
|
Vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153)
vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153). Successful exploitation can lead to full system takeover. Exploitable via ``ObjectFactory``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-41053 |
|
Vulnerability in github.com/rancher/rancher (CVE-2026-41053)
vulnerability in github.com/rancher/rancher (CVE-2026-41053). Successful exploitation can lead to full system takeover. Exploitable via ``allowedPrincipalIds``. Mitigation: upgrade to `0.0.0-20260519172014-d0c047bbc6d2` or later.
|
| CVE-2026-44937 |
|
Vulnerability in github.com/rancher/fleet (CVE-2026-44937)
vulnerability in github.com/rancher/fleet (CVE-2026-44937). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.12.15` or later.
|
| CVE-2026-44938 |
|
Vulnerability in github.com/rancher/fleet (CVE-2026-44938)
vulnerability in github.com/rancher/fleet (CVE-2026-44938). Successful exploitation can lead to full system takeover. Exploitable via ``namespaceLabels``. Mitigation: upgrade to `0.12.15` or later.
|
| CVE-2026-14265 |
|
Unsafe Deserialization in Amazon aws (CVE-2026-14265)
vulnerability in Amazon aws (CVE-2026-14265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49998 |
|
Vulnerability in github.com/centrifugal/centrifugo/v6 (CVE-2026-49998)
vulnerability in github.com/centrifugal/centrifugo/v6 (CVE-2026-49998). Confidential information can be exposed externally. Exploitable via ``singleflight``. Mitigation: upgrade to `6.8.1` or later.
|
| CVE-2026-48815 |
|
Vulnerability in sigstore (CVE-2026-48815)
vulnerability in sigstore (CVE-2026-48815). Data can be tampered with by attackers. Exploitable via ``certificateOIDs``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-13760 |
|
OS Command Injection in Amazon aws-cdk-lib (CVE-2026-13760)
OS command injection in Amazon aws-cdk-lib (CVE-2026-13760). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.260.0` or later.
|
| CVE-2026-49987 |
|
Vulnerability in repomix (CVE-2026-49987)
vulnerability in repomix (CVE-2026-49987). Successful exploitation can lead to full system takeover. Exploitable via ``execGitShallowClone``. Mitigation: upgrade to `1.14.1` or later.
|
| CVE-2026-49981 |
|
Vulnerability in twig/twig (CVE-2026-49981)
vulnerability in twig/twig (CVE-2026-49981). Confidential information can be exposed externally. Exploitable via ``Template``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-58454 |
|
Code Injection in CVE-2026-58454 (CVE-2026-58454)
code injection in CVE-2026-58454 (CVE-2026-58454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58452 |
|
OS Command Injection in CVE-2026-58452 (CVE-2026-58452)
OS command injection in CVE-2026-58452 (CVE-2026-58452). Successful exploitation can lead to full system takeover.
|