Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-54096 |
|
Vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-54096)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-54096). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.63.7` or later.
|
| CVE-2026-42850 |
|
Command Injection in kovidgoyal (CVE-2026-42850)
command injection in kovidgoyal (CVE-2026-42850). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42851 |
|
Code Injection in kovidgoyal (CVE-2026-42851)
code injection in kovidgoyal (CVE-2026-42851). Successful exploitation can lead to full system takeover. Exploitable via ``cat``.
|
| CVE-2026-53408 |
|
Vulnerability in zoom (CVE-2026-53408)
vulnerability in zoom (CVE-2026-53408). Confidential information can be exposed externally.
|
| CVE-2026-50101 |
|
Vulnerability in CVE-2026-50101 (CVE-2026-50101)
vulnerability in CVE-2026-50101 (CVE-2026-50101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53407 |
|
Vulnerability in zoom (CVE-2026-53407)
vulnerability in zoom (CVE-2026-53407). Confidential information can be exposed externally.
|
| CVE-2026-50108 |
|
Vulnerability in CVE-2026-50108 (CVE-2026-50108)
vulnerability in CVE-2026-50108 (CVE-2026-50108). Confidential information can be exposed externally.
|
| CVE-2026-12143 |
|
Vulnerability in form-data (CVE-2026-12143)
vulnerability in form-data (CVE-2026-12143). Data can be tampered with by attackers. Exploitable via ``field``. Mitigation: upgrade to `4.0.6` or later.
|
| CVE-2026-12043 |
|
Vulnerability in Amazon aws (CVE-2026-12043)
vulnerability in Amazon aws (CVE-2026-12043). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47965 |
|
Out-of-Bounds Write in adobe (CVE-2026-47965)
out-of-bounds write in adobe (CVE-2026-47965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53406 |
|
Vulnerability in zoom (CVE-2026-53406)
vulnerability in zoom (CVE-2026-53406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3840 |
|
Path Traversal in path-traversal (CVE-2026-3840)
path traversal in path-traversal (CVE-2026-3840). Confidential information can be exposed externally.
|
| CVE-2026-6961 |
|
Path Traversal in github.com/mattermost/mattermost-server (CVE-2026-6961)
path traversal in github.com/mattermost/mattermost-server (CVE-2026-6961). Data can be tampered with by attackers. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2026-7387 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-7387)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-7387). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.11.17` or later.
|
| CVE-2025-52465 |
|
Vulnerability in org.geoserver.web:gs-web-app (CVE-2025-52465)
vulnerability in org.geoserver.web:gs-web-app (CVE-2025-52465). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.26.4` or later.
|
| CVE-2026-48165 |
|
OS Command Injection in mariadb (CVE-2026-48165)
OS command injection in mariadb (CVE-2026-48165). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48163 |
|
OS Command Injection in mariadb (CVE-2026-48163)
OS command injection in mariadb (CVE-2026-48163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44168 |
|
OS Command Injection in mariadb (CVE-2026-44168)
OS command injection in mariadb (CVE-2026-44168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53981 |
|
Vulnerability in CVE-2026-53981 (CVE-2026-53981)
vulnerability in CVE-2026-53981 (CVE-2026-53981). Confidential information can be exposed externally.
|
| CVE-2026-9638 |
|
Vulnerability in CVE-2026-9638 (CVE-2026-9638)
vulnerability in CVE-2026-9638 (CVE-2026-9638). Confidential information can be exposed externally.
|
| CVE-2026-50087 |
|
Vulnerability in c (CVE-2026-50087)
vulnerability in c (CVE-2026-50087). Confidential information can be exposed externally.
|
| CVE-2026-50085 |
|
Vulnerability in c (CVE-2026-50085)
vulnerability in c (CVE-2026-50085). Data can be tampered with by attackers.
|
| CVE-2026-50088 |
|
Vulnerability in c (CVE-2026-50088)
vulnerability in c (CVE-2026-50088). Confidential information can be exposed externally.
|
| CVE-2026-50010 |
|
Vulnerability in io.netty:netty-handler (CVE-2026-50010)
vulnerability in io.netty:netty-handler (CVE-2026-50010). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.135.Final` or later.
|
| CVE-2026-50011 |
|
Vulnerability in io.netty:netty-codec-redis (CVE-2026-50011)
vulnerability in io.netty:netty-codec-redis (CVE-2026-50011). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.135.Final` or later.
|
| CVE-2026-48748 |
|
Vulnerability in io.netty:netty-codec-http3 (CVE-2026-48748)
vulnerability in io.netty:netty-codec-http3 (CVE-2026-48748). Risk of unauthorized operations or information disclosure. Exploitable via ``HTTP3_SETTINGS_QPACK_MAX_TABLE_CAPACITY``. Mitigation: upgrade to `4.2.15.Final` or later.
|
| CVE-2026-45833 |
|
Code Injection in chromadb (CVE-2026-45833)
code injection in chromadb (CVE-2026-45833). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45832 |
|
Vulnerability in trychroma (CVE-2026-45832)
vulnerability in trychroma (CVE-2026-45832). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45830 |
|
Vulnerability in chromadb (CVE-2026-45830)
vulnerability in chromadb (CVE-2026-45830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45831 |
|
Authorization Flaw in chromadb (CVE-2026-45831)
vulnerability in chromadb (CVE-2026-45831). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7368 |
|
Vulnerability in CVE-2026-7368 (CVE-2026-7368)
vulnerability in CVE-2026-7368 (CVE-2026-7368). Confidential information can be exposed externally.
|
| CVE-2026-6211 |
|
Unrestricted File Upload in CVE-2026-6211 (CVE-2026-6211)
vulnerability in CVE-2026-6211 (CVE-2026-6211). Confidential information can be exposed externally.
|
| CVE-2026-53721 |
|
Vulnerability in nuxt (CVE-2026-53721)
vulnerability in nuxt (CVE-2026-53721). Confidential information can be exposed externally. Exploitable via ``routeRules``. Mitigation: upgrade to `3.21.7` or later.
|
| CVE-2026-12066 |
|
Vulnerability in CVE-2026-12066 (CVE-2026-12066)
vulnerability in CVE-2026-12066 (CVE-2026-12066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50645 |
|
Vulnerability in org.apache.cxf:cxf-core (CVE-2026-50645)
vulnerability in org.apache.cxf:cxf-core (CVE-2026-50645). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.12` or later.
|
| CVE-2026-50633 |
|
Vulnerability in org.apache.cxf:cxf-integration-jca (CVE-2026-50633)
vulnerability in org.apache.cxf:cxf-integration-jca (CVE-2026-50633). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.7` or later.
|
| CVE-2026-50632 |
|
Vulnerability in org.apache.cxf:cxf-rt-transports-jms (CVE-2026-50632)
vulnerability in org.apache.cxf:cxf-rt-transports-jms (CVE-2026-50632). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.7` or later.
|
| CVE-2026-50631 |
|
Vulnerability in org.apache.cxf:cxf-rt-rs-security-oauth2 (CVE-2026-50631)
vulnerability in org.apache.cxf:cxf-rt-rs-security-oauth2 (CVE-2026-50631). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.7` or later.
|
| CVE-2026-11846 |
|
Path Traversal in CVE-2026-11846 (CVE-2026-11846)
path traversal in CVE-2026-11846 (CVE-2026-11846). Data can be tampered with by attackers.
|
| CVE-2026-11845 |
|
OS Command Injection in CVE-2026-11845 (CVE-2026-11845)
OS command injection in CVE-2026-11845 (CVE-2026-11845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12059 |
|
Vulnerability in CVE-2026-12059 (CVE-2026-12059)
vulnerability in CVE-2026-12059 (CVE-2026-12059). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45169 |
|
Vulnerability in dos (CVE-2026-45169)
vulnerability in dos (CVE-2026-45169). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48612 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-48612 (CVE-2026-48612)
vulnerability in CVE-2026-48612 (CVE-2026-48612). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48610 |
|
Vulnerability in CVE-2026-48610 (CVE-2026-48610)
vulnerability in CVE-2026-48610 (CVE-2026-48610). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47368 |
|
Path Traversal in path-traversal (CVE-2026-47368)
path traversal in path-traversal (CVE-2026-47368). Confidential information can be exposed externally.
|
| CVE-2026-47366 |
|
Vulnerability in privilege-escalation (CVE-2026-47366)
vulnerability in privilege-escalation (CVE-2026-47366). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7737 |
|
Vulnerability in jvn (CVE-2025-7737)
vulnerability in jvn (CVE-2025-7737). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45170 |
|
Vulnerability in paloaltonetworks (CVE-2026-45170)
vulnerability in paloaltonetworks (CVE-2026-45170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11933 |
|
Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
|
| CVE-2026-45418 |
|
SQL Injection in sqli (CVE-2026-45418)
SQL injection in sqli (CVE-2026-45418). Successful exploitation can lead to full system takeover. Exploitable via `POST /actions/subtitle_edit.php`.
|