Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44422 |
|
Vulnerability in freerdp (CVE-2026-44422)
vulnerability in freerdp (CVE-2026-44422). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-47260 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-47260)
SSRF in phanan/koel (CVE-2026-47260). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.3.5` or later.
|
| CVE-2026-46702 |
|
Vulnerability in russh (CVE-2026-46702)
vulnerability in russh (CVE-2026-46702). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.1` or later.
|
| CVE-2026-47255 |
|
Vulnerability in @agenticmail/api (CVE-2026-47255)
vulnerability in @agenticmail/api (CVE-2026-47255). Data can be tampered with by attackers. Mitigation: upgrade to `0.9.32` or later.
|
| CVE-2026-49372 |
|
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
|
| CVE-2026-49373 |
|
Vulnerability in jetbrains (CVE-2026-49373)
vulnerability in jetbrains (CVE-2026-49373). Confidential information can be exposed externally.
|
| CVE-2026-49374 |
|
Vulnerability in jetbrains (CVE-2026-49374)
vulnerability in jetbrains (CVE-2026-49374). Confidential information can be exposed externally.
|
| CVE-2026-49366 |
|
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
|
| CVE-2026-49367 |
|
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
|
| CVE-2026-49368 |
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
|
| CVE-2026-49371 |
|
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
|
| CVE-2026-47740 |
|
shopper/framework: Authorization bypass in multiple Livewire admin components
shopper/framework: Authorization bypass in multiple Livewire admin components
|
| CVE-2026-42929 |
|
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
|
| CVE-2026-10107 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-10107 (CVE-2026-10107)
SSRF in CVE-2026-10107 (CVE-2026-10107). Confidential information can be exposed externally.
|
| CVE-2026-5768 |
|
Vulnerability in CVE-2026-5768 (CVE-2026-5768)
vulnerability in CVE-2026-5768 (CVE-2026-5768). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10108 |
|
Path Traversal in xiaomusic (CVE-2026-10108)
path traversal in xiaomusic (CVE-2026-10108). Confidential information can be exposed externally. Exploitable via `GET /music/{file_path`. Mitigation: upgrade to `0.5.8` or later.
|
| CVE-2026-10105 |
|
SQL Injection in agno (CVE-2026-10105)
SQL injection in agno (CVE-2026-10105). Confidential information can be exposed externally.
|
| CVE-2026-47139 |
|
Vulnerability in vm2 (CVE-2026-47139)
vulnerability in vm2 (CVE-2026-47139). Confidential information can be exposed externally. Exploitable via ``NodeVM``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47209 |
|
Vulnerability in vm2 (CVE-2026-47209)
vulnerability in vm2 (CVE-2026-47209). Data can be tampered with by attackers. Exploitable via ``BaseHandler.set``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47135 |
|
Vulnerability in vm2 (CVE-2026-47135)
vulnerability in vm2 (CVE-2026-47135). Confidential information can be exposed externally. Exploitable via ``Symbol.for``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-45742 |
|
Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45742)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45742). Risk of unauthorized operations or information disclosure. Exploitable via ``downloadFrom``. Mitigation: upgrade to `8.33.0` or later.
|
| CVE-2026-45741 |
|
Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45741)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-45741). Confidential information can be exposed externally.
|
| CVE-2026-44829 |
|
Path Traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829)
path traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-44829). Data can be tampered with by attackers. Exploitable via ``filepath.Base``. Mitigation: upgrade to `8.33.0` or later.
|
| CVE-2026-45662 |
|
OS Command Injection in CVE-2026-45662 (CVE-2026-45662)
OS command injection in CVE-2026-45662 (CVE-2026-45662). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39276 |
|
Path Traversal in path-traversal (CVE-2026-39276)
path traversal in path-traversal (CVE-2026-39276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35630 |
|
Vulnerability in openclaw (CVE-2026-35630)
vulnerability in openclaw (CVE-2026-35630). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-35674 |
|
Vulnerability in openclaw (CVE-2026-35674)
vulnerability in openclaw (CVE-2026-35674). Successful exploitation can lead to full system takeover. Exploitable via ``operator.approvals``. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-32905 |
|
Authorization Flaw in openclaw (CVE-2026-32905)
vulnerability in openclaw (CVE-2026-32905). Confidential information can be exposed externally. Mitigation: upgrade to `2026.5.4` or later.
|
| CVE-2026-10065 |
|
Buffer Overflow in CVE-2026-10065 (CVE-2026-10065)
vulnerability in CVE-2026-10065 (CVE-2026-10065). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10066 |
|
Buffer Overflow in CVE-2026-10066 (CVE-2026-10066)
vulnerability in CVE-2026-10066 (CVE-2026-10066). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10067 |
|
Buffer Overflow in CVE-2026-10067 (CVE-2026-10067)
vulnerability in CVE-2026-10067 (CVE-2026-10067). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10068 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-10068 (CVE-2026-10068)
SSRF in CVE-2026-10068 (CVE-2026-10068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10069 |
|
Vulnerability in CVE-2026-10069 (CVE-2026-10069)
vulnerability in CVE-2026-10069 (CVE-2026-10069). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25403 |
|
SQL Injection in sqli (CVE-2018-25403)
SQL injection in sqli (CVE-2018-25403). Confidential information can be exposed externally.
|
| CVE-2018-25404 |
|
SQL Injection in sqli (CVE-2018-25404)
SQL injection in sqli (CVE-2018-25404). Confidential information can be exposed externally.
|
| CVE-2018-25396 |
|
Vulnerability in CVE-2018-25396 (CVE-2018-25396)
vulnerability in CVE-2018-25396 (CVE-2018-25396). Confidential information can be exposed externally.
|
| CVE-2018-25398 |
|
SQL Injection in sqli (CVE-2018-25398)
SQL injection in sqli (CVE-2018-25398). Confidential information can be exposed externally.
|
| CVE-2018-25399 |
|
SQL Injection in sqli (CVE-2018-25399)
SQL injection in sqli (CVE-2018-25399). Confidential information can be exposed externally.
|
| CVE-2018-25400 |
|
SQL Injection in sqli (CVE-2018-25400)
SQL injection in sqli (CVE-2018-25400). Confidential information can be exposed externally.
|
| CVE-2018-25401 |
|
SQL Injection in sqli (CVE-2018-25401)
SQL injection in sqli (CVE-2018-25401). Confidential information can be exposed externally.
|
| CVE-2018-25402 |
|
SQL Injection in sqli (CVE-2018-25402)
SQL injection in sqli (CVE-2018-25402). Confidential information can be exposed externally.
|
| CVE-2018-25389 |
|
SQL Injection in sqli (CVE-2018-25389)
SQL injection in sqli (CVE-2018-25389). Confidential information can be exposed externally.
|
| CVE-2018-25390 |
|
SQL Injection in sqli (CVE-2018-25390)
SQL injection in sqli (CVE-2018-25390). Confidential information can be exposed externally.
|
| CVE-2018-25391 |
|
Vulnerability in CVE-2018-25391 (CVE-2018-25391)
vulnerability in CVE-2018-25391 (CVE-2018-25391). Data can be tampered with by attackers.
|
| CVE-2018-25392 |
|
SQL Injection in sqli (CVE-2018-25392)
SQL injection in sqli (CVE-2018-25392). Confidential information can be exposed externally.
|
| CVE-2018-25394 |
|
SQL Injection in sqli (CVE-2018-25394)
SQL injection in sqli (CVE-2018-25394). Confidential information can be exposed externally.
|
| CVE-2018-25395 |
|
SQL Injection in sqli (CVE-2018-25395)
SQL injection in sqli (CVE-2018-25395). Confidential information can be exposed externally.
|
| CVE-2018-25382 |
|
SQL Injection in sqli (CVE-2018-25382)
SQL injection in sqli (CVE-2018-25382). Confidential information can be exposed externally.
|
| CVE-2018-25383 |
|
Vulnerability in CVE-2018-25383 (CVE-2018-25383)
vulnerability in CVE-2018-25383 (CVE-2018-25383). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25385 |
|
SQL Injection in sqli (CVE-2018-25385)
SQL injection in sqli (CVE-2018-25385). Confidential information can be exposed externally.
|