Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-53303 |
|
Out-of-Bounds Read in linux (CVE-2026-53303)
vulnerability in linux (CVE-2026-53303). Confidential information can be exposed externally.
|
| CVE-2026-53296 |
|
Use-After-Free in linux (CVE-2026-53296)
vulnerability in linux (CVE-2026-53296). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53294 |
|
Vulnerability in linux (CVE-2026-53294)
vulnerability in linux (CVE-2026-53294). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32833 |
|
OS Command Injection in CVE-2026-32833 (CVE-2026-32833)
OS command injection in CVE-2026-32833 (CVE-2026-32833). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53281 |
|
Vulnerability in linux (CVE-2026-53281)
vulnerability in linux (CVE-2026-53281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53290 |
|
Use-After-Free in linux (CVE-2026-53290)
vulnerability in linux (CVE-2026-53290). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53286 |
|
Vulnerability in linux (CVE-2026-53286)
vulnerability in linux (CVE-2026-53286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53284 |
|
Vulnerability in c (CVE-2026-53284)
vulnerability in c (CVE-2026-53284). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13372 |
|
Vulnerability in devolutions (CVE-2026-13372)
vulnerability in devolutions (CVE-2026-13372). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49258 |
|
Vulnerability in github.com/juev/nebula-mesh (CVE-2026-49258)
vulnerability in github.com/juev/nebula-mesh (CVE-2026-49258). Successful exploitation can lead to full system takeover. Exploitable via `POST /ui/hosts/{id}/block`.
|
| CVE-2026-52884 |
|
Vulnerability in cpp (CVE-2026-52884)
vulnerability in cpp (CVE-2026-52884). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.9.6.2` or later.
|
| CVE-2026-48778 |
|
OS Command Injection in cpp (CVE-2026-48778)
OS command injection in cpp (CVE-2026-48778). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.9.6.1` or later.
|
| CVE-2026-48800 |
|
OS Command Injection in cpp (CVE-2026-48800)
OS command injection in cpp (CVE-2026-48800). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.9.6.1` or later.
|
| CVE-2026-46604 |
|
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image
Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image
|
| CVE-2026-46710 |
|
Vulnerability in privilege-escalation (CVE-2026-46710)
vulnerability in privilege-escalation (CVE-2026-46710). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.9.6` or later.
|
| CVE-2026-48804 |
|
Vulnerability in python-socketio (CVE-2026-48804)
vulnerability in python-socketio (CVE-2026-48804). Risk of unauthorized operations or information disclosure. Exploitable via ``EVENT``. Mitigation: upgrade to `5.16.2` or later.
|
| CVE-2026-48802 |
|
Vulnerability in python-engineio (CVE-2026-48802)
vulnerability in python-engineio (CVE-2026-48802). Risk of unauthorized operations or information disclosure. Exploitable via ``connect``. Mitigation: upgrade to `4.13.2` or later.
|
| CVE-2026-48809 |
|
Vulnerability in python-engineio (CVE-2026-48809)
vulnerability in python-engineio (CVE-2026-48809). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.13.2` or later.
|
| CVE-2026-48801 |
|
Vulnerability in linkify-it (CVE-2026-48801)
vulnerability in linkify-it (CVE-2026-48801). Risk of unauthorized operations or information disclosure. Exploitable via ``LinkifyIt.prototype.match``. Mitigation: upgrade to `5.0.1` or later.
|
| CVE-2026-55189 |
|
Vulnerability in CVE-2026-55189 (CVE-2026-55189)
vulnerability in CVE-2026-55189 (CVE-2026-55189). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.0-beta.9` or later.
|
| CVE-2026-55188 |
|
Information Disclosure in CVE-2026-55188 (CVE-2026-55188)
vulnerability in CVE-2026-55188 (CVE-2026-55188). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.0-beta.9` or later.
|
| CVE-2026-52783 |
|
Vulnerability in rails (CVE-2026-52783)
vulnerability in rails (CVE-2026-52783). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-52784 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-52784)
vulnerability in csrf (CVE-2026-52784). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-49991 |
|
Path Traversal in path-traversal (CVE-2026-49991)
path traversal in path-traversal (CVE-2026-49991). Data can be tampered with by attackers.
|
| CVE-2026-47193 |
|
Information Disclosure in CVE-2026-47193 (CVE-2026-47193)
vulnerability in CVE-2026-47193 (CVE-2026-47193). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-47220 |
|
Vulnerability in envoy (CVE-2026-47220)
vulnerability in envoy (CVE-2026-47220). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `1.37.5` or later.
|
| CVE-2026-56876 |
|
Path Traversal in extract-zip (CVE-2026-56876)
path traversal in extract-zip (CVE-2026-56876). Confidential information can be exposed externally.
|
| CVE-2026-45195 |
|
Vulnerability in imaginationtech (CVE-2026-45195)
vulnerability in imaginationtech (CVE-2026-45195). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0828 |
|
Vulnerability in CVE-2026-0828 (CVE-2026-0828)
vulnerability in CVE-2026-0828 (CVE-2026-0828). Confidential information can be exposed externally.
|
| CVE-2026-21734 |
|
Vulnerability in imaginationtech (CVE-2026-21734)
vulnerability in imaginationtech (CVE-2026-21734). Data can be tampered with by attackers.
|
| CVE-2026-57518 |
|
Vulnerability in privilege-escalation (CVE-2026-57518)
vulnerability in privilege-escalation (CVE-2026-57518). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5757 |
|
Out-of-Bounds Read in ollama (CVE-2026-5757)
vulnerability in ollama (CVE-2026-5757). Confidential information can be exposed externally.
|
| CVE-2026-54341 |
|
Out-of-Bounds Read in dos (CVE-2026-54341)
vulnerability in dos (CVE-2026-54341). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.39.0` or later.
|
| CVE-2026-48743 |
|
Vulnerability in envoy (CVE-2026-48743)
vulnerability in envoy (CVE-2026-48743). Data can be tampered with by attackers. Exploitable via `GET /pwn`. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-48042 |
|
Vulnerability in envoy (CVE-2026-48042)
vulnerability in envoy (CVE-2026-48042). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-48044 |
|
Vulnerability in envoy (CVE-2026-48044)
vulnerability in envoy (CVE-2026-48044). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-55677 |
|
Path Traversal in github.com/labstack/echo/v5 (CVE-2026-55677)
path traversal in github.com/labstack/echo/v5 (CVE-2026-55677). Confidential information can be exposed externally. Exploitable via ``StaticDirectoryHandler``. Mitigation: upgrade to `5.2.0` or later.
|
| CVE-2026-56663 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-56663)
SSRF in ssrf (CVE-2026-56663). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.6.52` or later.
|
| CVE-2026-57231 |
|
Information Disclosure in podman-project (CVE-2026-57231)
vulnerability in podman-project (CVE-2026-57231). Confidential information can be exposed externally. Mitigation: upgrade to `5.8.4` or later.
|
| CVE-2026-44161 |
|
SSRF (Server-Side Request Forgery) in fluentd (CVE-2026-44161)
SSRF in fluentd (CVE-2026-44161). Risk of unauthorized operations or information disclosure. Exploitable via ``out_http``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-44160 |
|
Vulnerability in fluentd (CVE-2026-44160)
vulnerability in fluentd (CVE-2026-44160). Risk of unauthorized operations or information disclosure. Exploitable via ``in_http``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-44025 |
|
Vulnerability in fluentd (CVE-2026-44025)
vulnerability in fluentd (CVE-2026-44025). Confidential information can be exposed externally. Exploitable via ``in_monitor_agent``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-9640 |
|
Authorization Flaw in privilege-escalation (CVE-2026-9640)
vulnerability in privilege-escalation (CVE-2026-9640). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12411 |
|
Vulnerability in canonical (CVE-2026-12411)
vulnerability in canonical (CVE-2026-12411). Confidential information can be exposed externally.
|
| CVE-2026-57645 |
|
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
|
| CVE-2026-57644 |
|
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
|
| CVE-2026-57647 |
|
Vulnerability in CVE-2026-57647 (CVE-2026-57647)
vulnerability in CVE-2026-57647 (CVE-2026-57647). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57653 |
|
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
|
| CVE-2026-57642 |
|
Contributor SQL Injection in Gallery <= 4.7.8 versions.
Contributor SQL Injection in Gallery <= 4.7.8 versions.
|
| CVE-2026-57659 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-57659)
vulnerability in csrf (CVE-2026-57659). Successful exploitation can lead to full system takeover.
|