Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-50254 |
|
Vulnerability in CVE-2026-50254 (CVE-2026-50254)
vulnerability in CVE-2026-50254 (CVE-2026-50254). Confidential information can be exposed externally.
|
| CVE-2026-52196 |
|
Vulnerability in dos (CVE-2026-52196)
vulnerability in dos (CVE-2026-52196). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52868 |
|
Path Traversal in CVE-2026-52868 (CVE-2026-52868)
path traversal in CVE-2026-52868 (CVE-2026-52868). Confidential information can be exposed externally.
|
| CVE-2026-35505 |
|
Vulnerability in CVE-2026-35505 (CVE-2026-35505)
vulnerability in CVE-2026-35505 (CVE-2026-35505). Confidential information can be exposed externally.
|
| CVE-2026-11541 |
|
Vulnerability in ibm (CVE-2026-11541)
vulnerability in ibm (CVE-2026-11541). Confidential information can be exposed externally.
|
| CVE-2026-13774 |
|
Use-After-Free in Google chrome (CVE-2026-13774)
vulnerability in Google chrome (CVE-2026-13774). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54672 |
|
Vulnerability in app-builder-lib (CVE-2026-54672)
vulnerability in app-builder-lib (CVE-2026-54672). Successful exploitation can lead to full system takeover. Exploitable via ``AppImage``. Mitigation: upgrade to `26.15.0` or later.
|
| CVE-2026-57585 |
|
Use-After-Free in dos (CVE-2026-57585)
vulnerability in dos (CVE-2026-57585). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11594 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2026-11594)
cross-site scripting in ibm (CVE-2026-11594). Confidential information can be exposed externally.
|
| CVE-2025-36359 |
|
Vulnerability in ibm (CVE-2025-36359)
vulnerability in ibm (CVE-2025-36359). Confidential information can be exposed externally.
|
| CVE-2026-13207 |
|
Vulnerability in CVE-2026-13207 (CVE-2026-13207)
vulnerability in CVE-2026-13207 (CVE-2026-13207). Confidential information can be exposed externally.
|
| CVE-2026-44628 |
|
Vulnerability in CVE-2026-44628 (CVE-2026-44628)
vulnerability in CVE-2026-44628 (CVE-2026-44628). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10560 |
|
Authentication Bypass in dos (CVE-2026-10560)
authentication bypass in dos (CVE-2026-10560). Confidential information can be exposed externally.
|
| CVE-2026-10564 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-10564)
SSRF in c (CVE-2026-10564). Confidential information can be exposed externally.
|
| CVE-2026-13759 |
|
Unsafe Deserialization in ibm (CVE-2026-13759)
vulnerability in ibm (CVE-2026-13759). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11546 |
|
SSRF (Server-Side Request Forgery) in ibm (CVE-2026-11546)
SSRF in ibm (CVE-2026-11546). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11806 |
|
Vulnerability in ibm (CVE-2026-11806)
vulnerability in ibm (CVE-2026-11806). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10546 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-10546)
SSRF in ssrf (CVE-2026-10546). Confidential information can be exposed externally.
|
| CVE-2026-11714 |
|
SSRF (Server-Side Request Forgery) in ibm (CVE-2026-11714)
SSRF in ibm (CVE-2026-11714). Confidential information can be exposed externally.
|
| CVE-2026-13449 |
|
XXE (XML External Entity) in ibm (CVE-2026-13449)
vulnerability in ibm (CVE-2026-13449). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13772 |
|
Vulnerability in ibm (CVE-2026-13772)
vulnerability in ibm (CVE-2026-13772). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10129 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-10129)
SSRF in ssrf (CVE-2026-10129). Confidential information can be exposed externally.
|
| CVE-2026-10513 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10513)
cross-site scripting in wordpress (CVE-2026-10513). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48808 |
|
Vulnerability in twig/twig (CVE-2026-48808)
vulnerability in twig/twig (CVE-2026-48808). Confidential information can be exposed externally. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-49478 |
|
SSRF (Server-Side Request Forgery) in github.com/sigstore/fulcio (CVE-2026-49478)
SSRF in github.com/sigstore/fulcio (CVE-2026-49478). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.6` or later.
|
| CVE-2026-48795 |
|
Vulnerability in @adonisjs/bodyparser (CVE-2026-48795)
vulnerability in @adonisjs/bodyparser (CVE-2026-48795). Risk of unauthorized operations or information disclosure. Exploitable via ``FormFields``. Mitigation: upgrade to `11.0.3` or later.
|
| CVE-2026-58375 |
|
Vulnerability in CVE-2026-58375 (CVE-2026-58375)
vulnerability in CVE-2026-58375 (CVE-2026-58375). Confidential information can be exposed externally. Exploitable via `POST /jmreport/auto/export`.
|
| CVE-2026-58370 |
|
Vulnerability in CVE-2026-58370 (CVE-2026-58370)
vulnerability in CVE-2026-58370 (CVE-2026-58370). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58377 |
|
Vulnerability in CVE-2026-58377 (CVE-2026-58377)
vulnerability in CVE-2026-58377 (CVE-2026-58377). Confidential information can be exposed externally.
|
| CVE-2026-58372 |
|
Path Traversal in path-traversal (CVE-2026-58372)
path traversal in path-traversal (CVE-2026-58372). Data can be tampered with by attackers.
|
| CVE-2026-58376 |
|
SQL Injection in sqli (CVE-2026-58376)
SQL injection in sqli (CVE-2026-58376). Confidential information can be exposed externally.
|
| CVE-2026-58170 |
|
Path Traversal in path-traversal (CVE-2026-58170)
path traversal in path-traversal (CVE-2026-58170). Data can be tampered with by attackers.
|
| CVE-2026-58165 |
|
Vulnerability in privilege-escalation (CVE-2026-58165)
vulnerability in privilege-escalation (CVE-2026-58165). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58168 |
|
Vulnerability in CVE-2026-58168 (CVE-2026-58168)
vulnerability in CVE-2026-58168 (CVE-2026-58168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58169 |
|
Vulnerability in CVE-2026-58169 (CVE-2026-58169)
vulnerability in CVE-2026-58169 (CVE-2026-58169). Successful exploitation can lead to full system takeover. Exploitable via `Host header`.
|
| CVE-2026-48307 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48307)
cross-site scripting in adobe (CVE-2026-48307). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48285 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48285)
SSRF in ssrf (CVE-2026-48285). Confidential information can be exposed externally.
|
| CVE-2026-49473 |
|
Vulnerability in @cedar-policy/authorization-for-expressjs (CVE-2026-49473)
vulnerability in @cedar-policy/authorization-for-expressjs (CVE-2026-49473). Successful exploitation can lead to full system takeover. Exploitable via `GET /users`. Mitigation: upgrade to `0.3.0` or later.
|
| CVE-2026-47198 |
|
Vulnerability in paymenter/paymenter (CVE-2026-47198)
vulnerability in paymenter/paymenter (CVE-2026-47198). Data can be tampered with by attackers. Exploitable via ``Checkout``. Mitigation: upgrade to `1.5.1` or later.
|
| CVE-2026-49451 |
|
Vulnerability in Microsoft.OpenAPI (CVE-2026-49451)
vulnerability in Microsoft.OpenAPI (CVE-2026-49451). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.4` or later.
|
| CVE-2026-8451 |
|
Out-of-Bounds Read in citrix (CVE-2026-8451)
vulnerability in citrix (CVE-2026-8451). Confidential information can be exposed externally.
|
| CVE-2026-58014 |
|
Vulnerability in c (CVE-2026-58014)
vulnerability in c (CVE-2026-58014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58016 |
|
Vulnerability in c (CVE-2026-58016)
vulnerability in c (CVE-2026-58016). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10817 |
|
Out-of-Bounds Read in citrix (CVE-2026-10817)
vulnerability in citrix (CVE-2026-10817). Confidential information can be exposed externally.
|
| CVE-2026-53433 |
|
Vulnerability in dos (CVE-2026-53433)
vulnerability in dos (CVE-2026-53433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13474 |
|
Vulnerability in dos (CVE-2026-13474)
vulnerability in dos (CVE-2026-13474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53432 |
|
Vulnerability in junegunn (CVE-2026-53432)
vulnerability in junegunn (CVE-2026-53432). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10816 |
|
Vulnerability in citrix (CVE-2026-10816)
vulnerability in citrix (CVE-2026-10816). Confidential information can be exposed externally.
|
| CVE-2026-27957 |
|
OS Command Injection in CVE-2026-27957 (CVE-2026-27957)
OS command injection in CVE-2026-27957 (CVE-2026-27957). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.0-beta.464` or later.
|
| CVE-2026-44946 |
|
Vulnerability in suse (CVE-2026-44946)
vulnerability in suse (CVE-2026-44946). Confidential information can be exposed externally.
|