Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-47986 |
|
Vulnerability in parseplatform (CVE-2021-47986)
vulnerability in parseplatform (CVE-2021-47986). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71324 |
|
Vulnerability in path-traversal (CVE-2025-71324)
vulnerability in path-traversal (CVE-2025-71324). Confidential information can be exposed externally.
|
| CVE-2025-71328 |
|
Vulnerability in flowise-ui (CVE-2025-71328)
vulnerability in flowise-ui (CVE-2025-71328). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.10` or later.
|
| CVE-2026-40083 |
|
SQL Injection in sqli (CVE-2026-40083)
SQL injection in sqli (CVE-2026-40083). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48702 |
|
Vulnerability in github.com/sigstore/rekor (CVE-2026-48702)
vulnerability in github.com/sigstore/rekor (CVE-2026-48702). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.2` or later.
|
| CVE-2026-38637 |
|
Vulnerability in dos (CVE-2026-38637)
vulnerability in dos (CVE-2026-38637). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6731 |
|
Vulnerability in wolfssl (CVE-2026-6731)
vulnerability in wolfssl (CVE-2026-6731). Data can be tampered with by attackers.
|
| CVE-2026-6679 |
|
Vulnerability in wolfssl (CVE-2026-6679)
vulnerability in wolfssl (CVE-2026-6679). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46601 |
|
Vulnerability in golang.org/x/image (CVE-2026-46601)
vulnerability in golang.org/x/image (CVE-2026-46601). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.43.0` or later.
|
| CVE-2026-46602 |
|
Vulnerability in golang.org/x/image (CVE-2026-46602)
vulnerability in golang.org/x/image (CVE-2026-46602). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.43.0` or later.
|
| CVE-2026-37452 |
|
Information Disclosure in CVE-2026-37452 (CVE-2026-37452)
vulnerability in CVE-2026-37452 (CVE-2026-37452). Confidential information can be exposed externally.
|
| CVE-2026-37453 |
|
Information Disclosure in msi (CVE-2026-37453)
vulnerability in msi (CVE-2026-37453). Confidential information can be exposed externally.
|
| CVE-2026-37454 |
|
Information Disclosure in msi (CVE-2026-37454)
vulnerability in msi (CVE-2026-37454). Confidential information can be exposed externally.
|
| CVE-2026-37149 |
|
SQL Injection in sqli (CVE-2026-37149)
SQL injection in sqli (CVE-2026-37149). Confidential information can be exposed externally.
|
| CVE-2026-57520 |
|
Vulnerability in privilege-escalation (CVE-2026-57520)
vulnerability in privilege-escalation (CVE-2026-57520). Data can be tampered with by attackers.
|
| CVE-2026-12473 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-12473 (CVE-2026-12473)
SSRF in CVE-2026-12473 (CVE-2026-12473). Confidential information can be exposed externally.
|
| CVE-2026-55960 |
|
Vulnerability in wolfssl (CVE-2026-55960)
vulnerability in wolfssl (CVE-2026-55960). Data can be tampered with by attackers.
|
| CVE-2026-38640 |
|
Vulnerability in dos (CVE-2026-38640)
vulnerability in dos (CVE-2026-38640). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11310 |
|
Vulnerability in wolfssl (CVE-2026-11310)
vulnerability in wolfssl (CVE-2026-11310). Data can be tampered with by attackers.
|
| CVE-2026-12340 |
|
Out-of-Bounds Read in dos (CVE-2026-12340)
vulnerability in dos (CVE-2026-12340). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55958 |
|
Vulnerability in dos (CVE-2026-55958)
vulnerability in dos (CVE-2026-55958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56769 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-56769 (CVE-2026-56769)
SSRF in CVE-2026-56769 (CVE-2026-56769). Confidential information can be exposed externally.
|
| CVE-2026-56790 |
|
Vulnerability in c (CVE-2026-56790)
vulnerability in c (CVE-2026-56790). Data can be tampered with by attackers.
|
| CVE-2025-60464 |
|
Use-After-Free in c (CVE-2025-60464)
vulnerability in c (CVE-2025-60464). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56771 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-56771 (CVE-2026-56771)
SSRF in CVE-2026-56771 (CVE-2026-56771). Data can be tampered with by attackers.
|
| CVE-2026-10512 |
|
Vulnerability in wolfssl (CVE-2026-10512)
vulnerability in wolfssl (CVE-2026-10512). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10097 |
|
Vulnerability in wolfssl (CVE-2026-10097)
vulnerability in wolfssl (CVE-2026-10097). Confidential information can be exposed externally.
|
| CVE-2026-56767 |
|
Vulnerability in CVE-2026-56767 (CVE-2026-56767)
vulnerability in CVE-2026-56767 (CVE-2026-56767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56768 |
|
Vulnerability in CVE-2026-56768 (CVE-2026-56768)
vulnerability in CVE-2026-56768 (CVE-2026-56768). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v2.1/share-link-zip-task/`.
|
| CVE-2026-56766 |
|
Vulnerability in CVE-2026-56766 (CVE-2026-56766)
vulnerability in CVE-2026-56766 (CVE-2026-56766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56770 |
|
Vulnerability in CVE-2026-56770 (CVE-2026-56770)
vulnerability in CVE-2026-56770 (CVE-2026-56770). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12921 |
|
Use-After-Free in azeotech (CVE-2026-12921)
vulnerability in azeotech (CVE-2026-12921). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55667 |
|
Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55667)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55667). Data can be tampered with by attackers. Exploitable via `GET /api/raw/link/secret.txt`. Mitigation: upgrade to `2.63.16` or later.
|
| CVE-2026-48508 |
|
Authorization Flaw in lemur (CVE-2026-48508)
vulnerability in lemur (CVE-2026-48508). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/1/authorities`. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-55967 |
|
Vulnerability in wolfssl (CVE-2026-55967)
vulnerability in wolfssl (CVE-2026-55967). Confidential information can be exposed externally.
|
| CVE-2026-55961 |
|
Vulnerability in wolfssl (CVE-2026-55961)
vulnerability in wolfssl (CVE-2026-55961). Data can be tampered with by attackers.
|
| CVE-2026-9086 |
|
Cross-Site Scripting (XSS) in redhat (CVE-2026-9086)
cross-site scripting in redhat (CVE-2026-9086). Confidential information can be exposed externally.
|
| CVE-2026-56123 |
|
Vulnerability in dest-unreach (CVE-2026-56123)
vulnerability in dest-unreach (CVE-2026-56123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9099 |
|
Vulnerability in redhat (CVE-2026-9099)
vulnerability in redhat (CVE-2026-9099). Confidential information can be exposed externally.
|
| CVE-2026-9800 |
|
Vulnerability in redhat (CVE-2026-9800)
vulnerability in redhat (CVE-2026-9800). Confidential information can be exposed externally.
|
| CVE-2026-11999 |
|
Vulnerability in c (CVE-2026-11999)
vulnerability in c (CVE-2026-11999). Data can be tampered with by attackers.
|
| CVE-2026-9717 |
|
OS Command Injection in schneider-electric (CVE-2026-9717)
OS command injection in schneider-electric (CVE-2026-9717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45233 |
|
Path Traversal in path-traversal (CVE-2026-45233)
path traversal in path-traversal (CVE-2026-45233). Data can be tampered with by attackers.
|
| CVE-2026-9716 |
|
Vulnerability in schneider-electric (CVE-2026-9716)
vulnerability in schneider-electric (CVE-2026-9716). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9650 |
|
Vulnerability in schneider-electric (CVE-2026-9650)
vulnerability in schneider-electric (CVE-2026-9650). Confidential information can be exposed externally.
|
| CVE-2026-12844 |
|
Vulnerability in CVE-2026-12844 (CVE-2026-12844)
vulnerability in CVE-2026-12844 (CVE-2026-12844). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49839 |
|
Out-of-Bounds Write in jqlang (CVE-2026-49839)
out-of-bounds write in jqlang (CVE-2026-49839). Data can be tampered with by attackers. Mitigation: upgrade to `1.8.2` or later.
|
| CVE-2026-55412 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55412)
SSRF in ssrf (CVE-2026-55412). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.20.178-lts` or later.
|
| CVE-2026-55092 |
|
Path Traversal in github.com/aquasecurity/trivy (CVE-2026-55092)
path traversal in github.com/aquasecurity/trivy (CVE-2026-55092). Data can be tampered with by attackers. Exploitable via ``org.opencontainers.image.title``. Mitigation: upgrade to `0.71.1` or later.
|
| CVE-2026-54033 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-54033)
SSRF in ssrf (CVE-2026-54033). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.4-rc1` or later.
|