Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-27490 |
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
|
| CVE-2026-27462 |
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lead...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
|
| CVE-2026-54682 |
|
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Format...
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it w...
|
| CVE-2026-63462 |
|
Vulnerability in unleash-server (CVE-2026-63462)
vulnerability in unleash-server (CVE-2026-63462). Risk of unauthorized operations or information disclosure. Exploitable via `POST /edge/validate`. Mitigation: upgrade to `8.0.2` or later.
|
| CVE-2026-77236 |
|
Out-of-Bounds Write in amazon (CVE-2026-77236)
out-of-bounds write in amazon (CVE-2026-77236). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77235 |
|
Use-After-Free in amazon (CVE-2026-77235)
vulnerability in amazon (CVE-2026-77235). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77234 |
|
Authorization Flaw in Amazon aws (CVE-2026-77234)
vulnerability in Amazon aws (CVE-2026-77234). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71862 |
|
Information Disclosure in CVE-2026-71862 (CVE-2026-71862)
vulnerability in CVE-2026-71862 (CVE-2026-71862). Confidential information can be exposed externally. Exploitable via `GET /api/v1/status-page/`.
|
| CVE-2026-62677 |
|
Path Traversal in CVE-2026-62677 (CVE-2026-62677)
path traversal in CVE-2026-62677 (CVE-2026-62677). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62676 |
|
Vulnerability in CVE-2026-62676 (CVE-2026-62676)
vulnerability in CVE-2026-62676 (CVE-2026-62676). Confidential information can be exposed externally.
|
| CVE-2026-62675 |
|
Code Injection in CVE-2026-62675 (CVE-2026-62675)
code injection in CVE-2026-62675 (CVE-2026-62675). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/sessions`.
|
| CVE-2026-55241 |
|
Vulnerability in CVE-2026-55241 (CVE-2026-55241)
vulnerability in CVE-2026-55241 (CVE-2026-55241). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/auth/register`.
|
| CVE-2026-41451 |
|
OS Command Injection in CVE-2026-41451 (CVE-2026-41451)
OS command injection in CVE-2026-41451 (CVE-2026-41451). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41450 |
|
OS Command Injection in CVE-2026-41450 (CVE-2026-41450)
OS command injection in CVE-2026-41450 (CVE-2026-41450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41449 |
|
OS Command Injection in CVE-2026-41449 (CVE-2026-41449)
OS command injection in CVE-2026-41449 (CVE-2026-41449). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74583 |
|
Vulnerability in CVE-2026-74583 (CVE-2026-74583)
vulnerability in CVE-2026-74583 (CVE-2026-74583). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74582 |
|
Vulnerability in CVE-2026-74582 (CVE-2026-74582)
vulnerability in CVE-2026-74582 (CVE-2026-74582). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74580 |
|
Vulnerability in CVE-2026-74580 (CVE-2026-74580)
vulnerability in CVE-2026-74580 (CVE-2026-74580). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39909 |
|
Use-After-Free in cpp (CVE-2026-39909)
vulnerability in cpp (CVE-2026-39909). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75933 |
|
Cross-Site Scripting (XSS) in CVE-2026-75933 (CVE-2026-75933)
cross-site scripting in CVE-2026-75933 (CVE-2026-75933). Confidential information can be exposed externally.
|
| CVE-2026-75932 |
|
Vulnerability in CVE-2026-75932 (CVE-2026-75932)
vulnerability in CVE-2026-75932 (CVE-2026-75932). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54789 |
|
Out-of-Bounds Read in apache (CVE-2026-54789)
vulnerability in apache (CVE-2026-54789). Risk of unauthorized operations or information disclosure. Exploitable via ``mod_auth_openidc``.
|
| CVE-2026-49114 |
|
Path Traversal in CVE-2026-49114 (CVE-2026-49114)
path traversal in CVE-2026-49114 (CVE-2026-49114). Data can be tampered with by attackers. Mitigation: upgrade to `1.21.0` or later.
|
| CVE-2026-22681 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-22681 (CVE-2026-22681)
SSRF in CVE-2026-22681 (CVE-2026-22681). Confidential information can be exposed externally.
|
| CVE-2026-77814 |
|
Path Traversal in CVE-2026-77814 (CVE-2026-77814)
path traversal in CVE-2026-77814 (CVE-2026-77814). Confidential information can be exposed externally.
|
| CVE-2026-75501 |
|
Vulnerability in CVE-2026-75501 (CVE-2026-75501)
vulnerability in CVE-2026-75501 (CVE-2026-75501). Data can be tampered with by attackers.
|
| CVE-2026-77815 |
|
Vulnerability in CVE-2026-77815 (CVE-2026-77815)
vulnerability in CVE-2026-77815 (CVE-2026-77815). Confidential information can be exposed externally.
|
| CVE-2026-55622 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-55622)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-55622). Confidential information can be exposed externally. Exploitable via `POST /1.0/instances`. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-55621 |
|
Vulnerability in github.com/lxc/incus/v7 (CVE-2026-55621)
vulnerability in github.com/lxc/incus/v7 (CVE-2026-55621). Confidential information can be exposed externally. Exploitable via ``req.Source.Project``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-59654 |
|
Vulnerability in apache (CVE-2026-59654)
vulnerability in apache (CVE-2026-59654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77775 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-77775 (CVE-2026-77775)
SSRF in CVE-2026-77775 (CVE-2026-77775). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-59279 |
|
Vulnerability in dos (CVE-2026-59279)
vulnerability in dos (CVE-2026-59279). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77767 |
|
Vulnerability in CVE-2026-77767 (CVE-2026-77767)
vulnerability in CVE-2026-77767 (CVE-2026-77767). Confidential information can be exposed externally.
|
| CVE-2026-47827 |
|
Command Injection in CVE-2026-47827 (CVE-2026-47827)
command injection in CVE-2026-47827 (CVE-2026-47827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66722 |
|
Vulnerability in apache (CVE-2026-66722)
vulnerability in apache (CVE-2026-66722). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68745 |
|
Vulnerability in apache (CVE-2026-68745)
vulnerability in apache (CVE-2026-68745). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59657 |
|
Vulnerability in apache (CVE-2026-59657)
vulnerability in apache (CVE-2026-59657). Confidential information can be exposed externally.
|
| CVE-2026-61400 |
|
Command Injection in apache (CVE-2026-61400)
command injection in apache (CVE-2026-61400). Successful exploitation can lead to full system takeover. Exploitable via ``getDiagnosticsData``.
|
| CVE-2026-59655 |
|
Information Disclosure in apache (CVE-2026-59655)
vulnerability in apache (CVE-2026-59655). Confidential information can be exposed externally.
|
| CVE-2026-59799 |
|
Privilege Escalation in apache (CVE-2026-59799)
vulnerability in apache (CVE-2026-59799). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59780 |
|
Information Disclosure in apache (CVE-2026-59780)
vulnerability in apache (CVE-2026-59780). Confidential information can be exposed externally.
|
| CVE-2026-61397 |
|
Information Disclosure in apache (CVE-2026-61397)
vulnerability in apache (CVE-2026-61397). Confidential information can be exposed externally.
|
| CVE-2026-50222 |
|
Information Disclosure in apache (CVE-2026-50222)
vulnerability in apache (CVE-2026-50222). Confidential information can be exposed externally.
|
| CVE-2026-63046 |
|
Vulnerability in apache (CVE-2026-63046)
vulnerability in apache (CVE-2026-63046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50112 |
|
OS Command Injection in apache (CVE-2026-50112)
OS command injection in apache (CVE-2026-50112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47359 |
|
OS Command Injection in apache (CVE-2026-47359)
OS command injection in apache (CVE-2026-47359). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16323 |
|
Vulnerability in CVE-2026-16323 (CVE-2026-16323)
vulnerability in CVE-2026-16323 (CVE-2026-16323). Confidential information can be exposed externally.
|
| CVE-2026-75796 |
|
Privilege Escalation in wordpress (CVE-2026-75796)
vulnerability in wordpress (CVE-2026-75796). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18781 |
|
Code Injection in wordpress (CVE-2026-18781)
code injection in wordpress (CVE-2026-18781). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16576 |
|
Vulnerability in wordpress (CVE-2026-16576)
vulnerability in wordpress (CVE-2026-16576). Successful exploitation can lead to full system takeover.
|