Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-68433 |
|
Vulnerability in CVE-2026-68433 (CVE-2026-68433)
vulnerability in CVE-2026-68433 (CVE-2026-68433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68429 |
|
Vulnerability in CVE-2026-68429 (CVE-2026-68429)
vulnerability in CVE-2026-68429 (CVE-2026-68429). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68431 |
|
Vulnerability in CVE-2026-68431 (CVE-2026-68431)
vulnerability in CVE-2026-68431 (CVE-2026-68431). Confidential information can be exposed externally.
|
| CVE-2026-68432 |
|
Vulnerability in CVE-2026-68432 (CVE-2026-68432)
vulnerability in CVE-2026-68432 (CVE-2026-68432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73250 |
|
Command Injection in CVE-2026-73250 (CVE-2026-73250)
command injection in CVE-2026-73250 (CVE-2026-73250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73249 |
|
Vulnerability in CVE-2026-73249 (CVE-2026-73249)
vulnerability in CVE-2026-73249 (CVE-2026-73249). Data can be tampered with by attackers. Exploitable via `POST /book-update-annotations/{library_id}/{book_id}/{fmt}`.
|
| CVE-2026-73248 |
|
Code Injection in CVE-2026-73248 (CVE-2026-73248)
code injection in CVE-2026-73248 (CVE-2026-73248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73247 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-73247 (CVE-2026-73247)
SSRF in CVE-2026-73247 (CVE-2026-73247). Confidential information can be exposed externally.
|
| CVE-2026-73246 |
|
Information Disclosure in CVE-2026-73246 (CVE-2026-73246)
vulnerability in CVE-2026-73246 (CVE-2026-73246). Confidential information can be exposed externally. Exploitable via `GET /worker`. Mitigation: upgrade to `2.0.0-rc6` or later.
|
| CVE-2026-73245 |
|
Vulnerability in CVE-2026-73245 (CVE-2026-73245)
vulnerability in CVE-2026-73245 (CVE-2026-73245). Risk of unauthorized operations or information disclosure. Exploitable via `GET /env`. Mitigation: upgrade to `2.0.0-rc6` or later.
|
| CVE-2026-68067 |
|
Vulnerability in CVE-2026-68067 (CVE-2026-68067)
vulnerability in CVE-2026-68067 (CVE-2026-68067). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67568 |
|
Vulnerability in CVE-2026-67568 (CVE-2026-67568)
vulnerability in CVE-2026-67568 (CVE-2026-67568). Confidential information can be exposed externally.
|
| CVE-2026-67558 |
|
Vulnerability in CVE-2026-67558 (CVE-2026-67558)
vulnerability in CVE-2026-67558 (CVE-2026-67558). Confidential information can be exposed externally.
|
| CVE-2026-66875 |
|
Vulnerability in CVE-2026-66875 (CVE-2026-66875)
vulnerability in CVE-2026-66875 (CVE-2026-66875). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66340 |
|
Vulnerability in CVE-2026-66340 (CVE-2026-66340)
vulnerability in CVE-2026-66340 (CVE-2026-66340). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66098 |
|
Vulnerability in CVE-2026-66098 (CVE-2026-66098)
vulnerability in CVE-2026-66098 (CVE-2026-66098). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64934 |
|
Vulnerability in CVE-2026-64934 (CVE-2026-64934)
vulnerability in CVE-2026-64934 (CVE-2026-64934). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5917 |
|
OS Command Injection in c (CVE-2026-5917)
OS command injection in c (CVE-2026-5917). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29036 |
|
Vulnerability in c (CVE-2026-29036)
vulnerability in c (CVE-2026-29036). Data can be tampered with by attackers.
|
| CVE-2026-19560 |
|
Use-After-Free in google (CVE-2026-19560)
vulnerability in google (CVE-2026-19560). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19559 |
|
Use-After-Free in google (CVE-2026-19559)
vulnerability in google (CVE-2026-19559). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19558 |
|
Use-After-Free in google (CVE-2026-19558)
vulnerability in google (CVE-2026-19558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19557 |
|
Use-After-Free in google (CVE-2026-19557)
vulnerability in google (CVE-2026-19557). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18710 |
|
Vulnerability in CVE-2026-18710 (CVE-2026-18710)
vulnerability in CVE-2026-18710 (CVE-2026-18710). Confidential information can be exposed externally.
|
| CVE-2026-19556 |
|
Use-After-Free in Google chrome (CVE-2026-19556)
vulnerability in Google chrome (CVE-2026-19556). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66832 |
|
Vulnerability in CVE-2026-66832 (CVE-2026-66832)
vulnerability in CVE-2026-66832 (CVE-2026-66832). Confidential information can be exposed externally. Exploitable via `User-Agent header`.
|
| CVE-2026-66154 |
|
Vulnerability in CVE-2026-66154 (CVE-2026-66154)
vulnerability in CVE-2026-66154 (CVE-2026-66154). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71290 |
|
Vulnerability in apache (CVE-2026-71290)
vulnerability in apache (CVE-2026-71290). Confidential information can be exposed externally.
|
| CVE-2026-66149 |
|
Code Injection in CVE-2026-66149 (CVE-2026-66149)
code injection in CVE-2026-66149 (CVE-2026-66149). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66147 |
|
Code Injection in CVE-2026-66147 (CVE-2026-66147)
code injection in CVE-2026-66147 (CVE-2026-66147). Data can be tampered with by attackers.
|
| CVE-2026-66148 |
|
Code Injection in CVE-2026-66148 (CVE-2026-66148)
code injection in CVE-2026-66148 (CVE-2026-66148). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66150 |
|
Code Injection in CVE-2026-66150 (CVE-2026-66150)
code injection in CVE-2026-66150 (CVE-2026-66150). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15606 |
|
Vulnerability in wordpress (CVE-2026-15606)
vulnerability in wordpress (CVE-2026-15606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19579 |
|
Vulnerability in snipeitapp (CVE-2026-19579)
vulnerability in snipeitapp (CVE-2026-19579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19550 |
|
Authorization Flaw in redhat (CVE-2026-19550)
vulnerability in redhat (CVE-2026-19550). Confidential information can be exposed externally.
|
| CVE-2026-29035 |
|
Out-of-Bounds Write in dos (CVE-2026-29035)
out-of-bounds write in dos (CVE-2026-29035). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18634 |
|
Unsafe Deserialization in CVE-2026-18634 (CVE-2026-18634)
vulnerability in CVE-2026-18634 (CVE-2026-18634). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14863 |
|
OS Command Injection in CVE-2026-14863 (CVE-2026-14863)
OS command injection in CVE-2026-14863 (CVE-2026-14863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63177 |
|
Authorization Flaw in nginx (CVE-2026-63177)
vulnerability in nginx (CVE-2026-63177). Confidential information can be exposed externally. Exploitable via ``ngx.var.request_uri``.
|
| CVE-2026-63134 |
|
Path Traversal in CVE-2026-63134 (CVE-2026-63134)
path traversal in CVE-2026-63134 (CVE-2026-63134). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63133 |
|
Vulnerability in CVE-2026-63133 (CVE-2026-63133)
vulnerability in CVE-2026-63133 (CVE-2026-63133). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55676 |
|
Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
|
| CVE-2026-48765 |
|
Vulnerability in CVE-2026-48765 (CVE-2026-48765)
vulnerability in CVE-2026-48765 (CVE-2026-48765). Confidential information can be exposed externally. Exploitable via ``credentialsId``.
|
| CVE-2026-48763 |
|
Vulnerability in CVE-2026-48763 (CVE-2026-48763)
vulnerability in CVE-2026-48763 (CVE-2026-48763). Data can be tampered with by attackers. Exploitable via `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url`.
|
| CVE-2026-48762 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48762)
SSRF in ssrf (CVE-2026-48762). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73283 |
|
Vulnerability in CVE-2026-73283 (CVE-2026-73283)
vulnerability in CVE-2026-73283 (CVE-2026-73283). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73282 |
|
Use-After-Free in CVE-2026-73282 (CVE-2026-73282)
vulnerability in CVE-2026-73282 (CVE-2026-73282). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73281 |
|
Vulnerability in CVE-2026-73281 (CVE-2026-73281)
vulnerability in CVE-2026-73281 (CVE-2026-73281). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73244 |
|
Path Traversal in spring (CVE-2026-73244)
path traversal in spring (CVE-2026-73244). Risk of unauthorized operations or information disclosure. Exploitable via `POST /listFiles`.
|
| CVE-2026-73243 |
|
SSRF (Server-Side Request Forgery) in spring (CVE-2026-73243)
SSRF in spring (CVE-2026-73243). Risk of unauthorized operations or information disclosure. Exploitable via `GET /addTask`.
|