Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-27490 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
CVE-2026-27462 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lead...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
CVE-2026-54682 DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Format...
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it w...
CVE-2026-63462 Vulnerability in unleash-server (CVE-2026-63462)
vulnerability in unleash-server (CVE-2026-63462). Risk of unauthorized operations or information disclosure. Exploitable via `POST /edge/validate`. Mitigation: upgrade to `8.0.2` or later.
CVE-2026-77236 Out-of-Bounds Write in amazon (CVE-2026-77236)
out-of-bounds write in amazon (CVE-2026-77236). Risk of unauthorized operations or information disclosure.
CVE-2026-77235 Use-After-Free in amazon (CVE-2026-77235)
vulnerability in amazon (CVE-2026-77235). Risk of unauthorized operations or information disclosure.
CVE-2026-77234 Authorization Flaw in Amazon aws (CVE-2026-77234)
vulnerability in Amazon aws (CVE-2026-77234). Successful exploitation can lead to full system takeover.
CVE-2026-71862 Information Disclosure in CVE-2026-71862 (CVE-2026-71862)
vulnerability in CVE-2026-71862 (CVE-2026-71862). Confidential information can be exposed externally. Exploitable via `GET /api/v1/status-page/`.
CVE-2026-62677 Path Traversal in CVE-2026-62677 (CVE-2026-62677)
path traversal in CVE-2026-62677 (CVE-2026-62677). Successful exploitation can lead to full system takeover.
CVE-2026-62676 Vulnerability in CVE-2026-62676 (CVE-2026-62676)
vulnerability in CVE-2026-62676 (CVE-2026-62676). Confidential information can be exposed externally.
CVE-2026-62675 Code Injection in CVE-2026-62675 (CVE-2026-62675)
code injection in CVE-2026-62675 (CVE-2026-62675). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/sessions`.
CVE-2026-55241 Vulnerability in CVE-2026-55241 (CVE-2026-55241)
vulnerability in CVE-2026-55241 (CVE-2026-55241). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/auth/register`.
CVE-2026-41451 OS Command Injection in CVE-2026-41451 (CVE-2026-41451)
OS command injection in CVE-2026-41451 (CVE-2026-41451). Successful exploitation can lead to full system takeover.
CVE-2026-41450 OS Command Injection in CVE-2026-41450 (CVE-2026-41450)
OS command injection in CVE-2026-41450 (CVE-2026-41450). Successful exploitation can lead to full system takeover.
CVE-2026-41449 OS Command Injection in CVE-2026-41449 (CVE-2026-41449)
OS command injection in CVE-2026-41449 (CVE-2026-41449). Successful exploitation can lead to full system takeover.
CVE-2026-74583 Vulnerability in CVE-2026-74583 (CVE-2026-74583)
vulnerability in CVE-2026-74583 (CVE-2026-74583). Successful exploitation can lead to full system takeover.
CVE-2026-74582 Vulnerability in CVE-2026-74582 (CVE-2026-74582)
vulnerability in CVE-2026-74582 (CVE-2026-74582). Successful exploitation can lead to full system takeover.
CVE-2026-74580 Vulnerability in CVE-2026-74580 (CVE-2026-74580)
vulnerability in CVE-2026-74580 (CVE-2026-74580). Successful exploitation can lead to full system takeover.
CVE-2026-39909 Use-After-Free in cpp (CVE-2026-39909)
vulnerability in cpp (CVE-2026-39909). Successful exploitation can lead to full system takeover.
CVE-2026-75933 Cross-Site Scripting (XSS) in CVE-2026-75933 (CVE-2026-75933)
cross-site scripting in CVE-2026-75933 (CVE-2026-75933). Confidential information can be exposed externally.
CVE-2026-75932 Vulnerability in CVE-2026-75932 (CVE-2026-75932)
vulnerability in CVE-2026-75932 (CVE-2026-75932). Risk of unauthorized operations or information disclosure.
CVE-2026-54789 Out-of-Bounds Read in apache (CVE-2026-54789)
vulnerability in apache (CVE-2026-54789). Risk of unauthorized operations or information disclosure. Exploitable via ``mod_auth_openidc``.
CVE-2026-49114 Path Traversal in CVE-2026-49114 (CVE-2026-49114)
path traversal in CVE-2026-49114 (CVE-2026-49114). Data can be tampered with by attackers. Mitigation: upgrade to `1.21.0` or later.
CVE-2026-22681 SSRF (Server-Side Request Forgery) in CVE-2026-22681 (CVE-2026-22681)
SSRF in CVE-2026-22681 (CVE-2026-22681). Confidential information can be exposed externally.
CVE-2026-77814 Path Traversal in CVE-2026-77814 (CVE-2026-77814)
path traversal in CVE-2026-77814 (CVE-2026-77814). Confidential information can be exposed externally.
CVE-2026-75501 Vulnerability in CVE-2026-75501 (CVE-2026-75501)
vulnerability in CVE-2026-75501 (CVE-2026-75501). Data can be tampered with by attackers.
CVE-2026-77815 Vulnerability in CVE-2026-77815 (CVE-2026-77815)
vulnerability in CVE-2026-77815 (CVE-2026-77815). Confidential information can be exposed externally.
CVE-2026-55622 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-55622)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-55622). Confidential information can be exposed externally. Exploitable via `POST /1.0/instances`. Mitigation: upgrade to `7.2.0` or later.
CVE-2026-55621 Vulnerability in github.com/lxc/incus/v7 (CVE-2026-55621)
vulnerability in github.com/lxc/incus/v7 (CVE-2026-55621). Confidential information can be exposed externally. Exploitable via ``req.Source.Project``. Mitigation: upgrade to `7.2.0` or later.
CVE-2026-59654 Vulnerability in apache (CVE-2026-59654)
vulnerability in apache (CVE-2026-59654). Risk of unauthorized operations or information disclosure.
CVE-2026-77775 SSRF (Server-Side Request Forgery) in CVE-2026-77775 (CVE-2026-77775)
SSRF in CVE-2026-77775 (CVE-2026-77775). Confidential information can be exposed externally. Exploitable via `Authorization header`.
CVE-2026-59279 Vulnerability in dos (CVE-2026-59279)
vulnerability in dos (CVE-2026-59279). Risk of unauthorized operations or information disclosure.
CVE-2026-77767 Vulnerability in CVE-2026-77767 (CVE-2026-77767)
vulnerability in CVE-2026-77767 (CVE-2026-77767). Confidential information can be exposed externally.
CVE-2026-47827 Command Injection in CVE-2026-47827 (CVE-2026-47827)
command injection in CVE-2026-47827 (CVE-2026-47827). Successful exploitation can lead to full system takeover.
CVE-2026-66722 Vulnerability in apache (CVE-2026-66722)
vulnerability in apache (CVE-2026-66722). Successful exploitation can lead to full system takeover.
CVE-2026-68745 Vulnerability in apache (CVE-2026-68745)
vulnerability in apache (CVE-2026-68745). Successful exploitation can lead to full system takeover.
CVE-2026-59657 Vulnerability in apache (CVE-2026-59657)
vulnerability in apache (CVE-2026-59657). Confidential information can be exposed externally.
CVE-2026-61400 Command Injection in apache (CVE-2026-61400)
command injection in apache (CVE-2026-61400). Successful exploitation can lead to full system takeover. Exploitable via ``getDiagnosticsData``.
CVE-2026-59655 Information Disclosure in apache (CVE-2026-59655)
vulnerability in apache (CVE-2026-59655). Confidential information can be exposed externally.
CVE-2026-59799 Privilege Escalation in apache (CVE-2026-59799)
vulnerability in apache (CVE-2026-59799). Successful exploitation can lead to full system takeover.
CVE-2026-59780 Information Disclosure in apache (CVE-2026-59780)
vulnerability in apache (CVE-2026-59780). Confidential information can be exposed externally.
CVE-2026-61397 Information Disclosure in apache (CVE-2026-61397)
vulnerability in apache (CVE-2026-61397). Confidential information can be exposed externally.
CVE-2026-50222 Information Disclosure in apache (CVE-2026-50222)
vulnerability in apache (CVE-2026-50222). Confidential information can be exposed externally.
CVE-2026-63046 Vulnerability in apache (CVE-2026-63046)
vulnerability in apache (CVE-2026-63046). Successful exploitation can lead to full system takeover.
CVE-2026-50112 OS Command Injection in apache (CVE-2026-50112)
OS command injection in apache (CVE-2026-50112). Successful exploitation can lead to full system takeover.
CVE-2026-47359 OS Command Injection in apache (CVE-2026-47359)
OS command injection in apache (CVE-2026-47359). Successful exploitation can lead to full system takeover.
CVE-2026-16323 Vulnerability in CVE-2026-16323 (CVE-2026-16323)
vulnerability in CVE-2026-16323 (CVE-2026-16323). Confidential information can be exposed externally.
CVE-2026-75796 Privilege Escalation in wordpress (CVE-2026-75796)
vulnerability in wordpress (CVE-2026-75796). Successful exploitation can lead to full system takeover.
CVE-2026-18781 Code Injection in wordpress (CVE-2026-18781)
code injection in wordpress (CVE-2026-18781). Successful exploitation can lead to full system takeover.
CVE-2026-16576 Vulnerability in wordpress (CVE-2026-16576)
vulnerability in wordpress (CVE-2026-16576). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →