Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-49298 |
|
Vulnerability in airflow (CVE-2026-49298)
vulnerability in airflow (CVE-2026-49298). Successful exploitation can lead to full system takeover. Exploitable via ``KubernetesExecutor``. Mitigation: upgrade to `3.2.2` or later.
|
| CVE-2026-42359 |
|
Unsafe Deserialization in apache-airflow (CVE-2026-42359)
vulnerability in apache-airflow (CVE-2026-42359). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/v2/xcomEntries/{key}`. Mitigation: upgrade to `3.2.2` or later.
|
| CVE-2026-41084 |
|
Vulnerability in apache-airflow (CVE-2026-41084)
vulnerability in apache-airflow (CVE-2026-41084). Data can be tampered with by attackers. Exploitable via `DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`. Mitigation: upgrade to `3.2.2` or later.
|
| CVE-2026-45360 |
|
Unsafe Deserialization in apache-airflow (CVE-2026-45360)
vulnerability in apache-airflow (CVE-2026-45360). Risk of unauthorized operations or information disclosure. Exploitable via ``DeadlineReference``. Mitigation: upgrade to `3.2.2` or later.
|
| CVE-2026-44825 |
|
Vulnerability in solr (CVE-2026-44825)
vulnerability in solr (CVE-2026-44825). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.0.0` or later.
|
| CVE-2026-42588 |
|
Vulnerability in activemq (CVE-2026-42588)
vulnerability in activemq (CVE-2026-42588). Confidential information can be exposed externally. Mitigation: upgrade to `5.19.7, 6.2.6` or later.
|
| CVE-2026-45505 |
|
Vulnerability in activemq (CVE-2026-45505)
vulnerability in activemq (CVE-2026-45505). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.19.7, 6.2.6` or later.
|
| CVE-2026-32325 |
|
Vulnerability in CVE-2026-32325 (CVE-2026-32325)
vulnerability in CVE-2026-32325 (CVE-2026-32325). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40961 |
|
Open Redirect in airflow (CVE-2026-40961)
vulnerability in airflow (CVE-2026-40961). Risk of unauthorized operations or information disclosure. Exploitable via ``is_safe_url``. Mitigation: upgrade to `3.2.2` or later.
|
| CVE-2026-10236 |
|
Vulnerability in CVE-2026-10236 (CVE-2026-10236)
vulnerability in CVE-2026-10236 (CVE-2026-10236). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10243 |
|
Authentication Bypass in CVE-2026-10243 (CVE-2026-10243)
authentication bypass in CVE-2026-10243 (CVE-2026-10243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27788 |
|
Vulnerability in jvn (CVE-2026-27788)
vulnerability in jvn (CVE-2026-27788). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35563 |
|
Vulnerability in org.apache.directory.api:api-ldap-client-api (CVE-2026-35563)
vulnerability in org.apache.directory.api:api-ldap-client-api (CVE-2026-35563). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.8` or later.
|
| CVE-2026-10227 |
|
Vulnerability in sqli (CVE-2026-10227)
vulnerability in sqli (CVE-2026-10227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10225 |
|
Vulnerability in sqli (CVE-2026-10225)
vulnerability in sqli (CVE-2026-10225). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10226 |
|
Vulnerability in sqli (CVE-2026-10226)
vulnerability in sqli (CVE-2026-10226). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48209 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-48209)
cross-site scripting in c (CVE-2026-48209). Data can be tampered with by attackers.
|
| CVE-2026-20455 |
|
Out-of-Bounds Write in mediatek (CVE-2026-20455)
out-of-bounds write in mediatek (CVE-2026-20455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10219 |
|
Command Injection in github.com/nextlevelbuilder/goclaw (CVE-2026-10219)
command injection in github.com/nextlevelbuilder/goclaw (CVE-2026-10219). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10220 |
|
Vulnerability in CVE-2026-10220 (CVE-2026-10220)
vulnerability in CVE-2026-10220 (CVE-2026-10220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20452 |
|
Vulnerability in mediatek (CVE-2026-20452)
vulnerability in mediatek (CVE-2026-20452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10221 |
|
Vulnerability in hermes-agent (CVE-2026-10221)
vulnerability in hermes-agent (CVE-2026-10221). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10214 |
|
Command Injection in CVE-2026-10214 (CVE-2026-10214)
command injection in CVE-2026-10214 (CVE-2026-10214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10208 |
|
Vulnerability in sqli (CVE-2026-10208)
vulnerability in sqli (CVE-2026-10208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10206 |
|
Buffer Overflow in CVE-2026-10206 (CVE-2026-10206)
vulnerability in CVE-2026-10206 (CVE-2026-10206). Successful exploitation can lead to full system takeover.
|
| CVE-2024-21182 KEV |
|
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core)...
|
| CVE-2026-8796 |
|
Out-of-Bounds Read in c (CVE-2026-8796)
vulnerability in c (CVE-2026-8796). Confidential information can be exposed externally.
|
| CVE-2026-10192 |
|
A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function...
A vulnerability was identified in Tenda W12 3.0.0.7(4763). The affected element is the function...
|
| CVE-2026-10189 |
|
A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the...
A vulnerability has been found in Tenda W12 3.0.0.7(4763). This vulnerability affects the...
|
| CVE-2026-10191 |
|
A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function...
A vulnerability was determined in Tenda W12 3.0.0.7(4763). Impacted is the function...
|
| CVE-2026-10183 |
|
Buffer Overflow in CVE-2026-10183 (CVE-2026-10183)
vulnerability in CVE-2026-10183 (CVE-2026-10183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10184 |
|
Vulnerability in sqli (CVE-2026-10184)
vulnerability in sqli (CVE-2026-10184). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10185 |
|
Vulnerability in sqli (CVE-2026-10185)
vulnerability in sqli (CVE-2026-10185). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10186 |
|
Vulnerability in sqli (CVE-2026-10186)
vulnerability in sqli (CVE-2026-10186). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10188 |
|
Buffer Overflow in CVE-2026-10188 (CVE-2026-10188)
vulnerability in CVE-2026-10188 (CVE-2026-10188). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49489 |
|
SQL Injection in sqli (CVE-2026-49489)
SQL injection in sqli (CVE-2026-49489). Confidential information can be exposed externally.
|
| CVE-2026-49490 |
|
SQL Injection in sqli (CVE-2026-49490)
SQL injection in sqli (CVE-2026-49490). Confidential information can be exposed externally.
|
| CVE-2026-10181 |
|
Buffer Overflow in CVE-2026-10181 (CVE-2026-10181)
vulnerability in CVE-2026-10181 (CVE-2026-10181). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10178 |
|
Vulnerability in sqli (CVE-2026-10178)
vulnerability in sqli (CVE-2026-10178). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10179 |
|
Buffer Overflow in CVE-2026-10179 (CVE-2026-10179)
vulnerability in CVE-2026-10179 (CVE-2026-10179). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10167 |
|
Authentication Bypass in CVE-2026-10167 (CVE-2026-10167)
authentication bypass in CVE-2026-10167 (CVE-2026-10167). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10164 |
|
Buffer Overflow in CVE-2026-10164 (CVE-2026-10164)
vulnerability in CVE-2026-10164 (CVE-2026-10164). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10165 |
|
Buffer Overflow in CVE-2026-10165 (CVE-2026-10165)
vulnerability in CVE-2026-10165 (CVE-2026-10165). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10163 |
|
Buffer Overflow in CVE-2026-10163 (CVE-2026-10163)
vulnerability in CVE-2026-10163 (CVE-2026-10163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10161 |
|
Buffer Overflow in CVE-2026-10161 (CVE-2026-10161)
vulnerability in CVE-2026-10161 (CVE-2026-10161). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10162 |
|
Buffer Overflow in CVE-2026-10162 (CVE-2026-10162)
vulnerability in CVE-2026-10162 (CVE-2026-10162). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10157 |
|
Authentication Bypass in c (CVE-2026-10157)
authentication bypass in c (CVE-2026-10157). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10159 |
|
Buffer Overflow in CVE-2026-10159 (CVE-2026-10159)
vulnerability in CVE-2026-10159 (CVE-2026-10159). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10158 |
|
Buffer Overflow in CVE-2026-10158 (CVE-2026-10158)
vulnerability in CVE-2026-10158 (CVE-2026-10158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10160 |
|
Buffer Overflow in CVE-2026-10160 (CVE-2026-10160)
vulnerability in CVE-2026-10160 (CVE-2026-10160). Successful exploitation can lead to full system takeover.
|