Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-45344 |
|
Vulnerability in CVE-2026-45344 (CVE-2026-45344)
vulnerability in CVE-2026-45344 (CVE-2026-45344). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.5.6` or later.
|
| CVE-2026-10044 |
|
Vulnerability in path-traversal (CVE-2026-10044)
vulnerability in path-traversal (CVE-2026-10044). Confidential information can be exposed externally. Exploitable via `GET /api/prompts/{filename}`.
|
| CVE-2026-39929 |
|
Out-of-Bounds Read in dos (CVE-2026-39929)
vulnerability in dos (CVE-2026-39929). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46827 |
|
Privilege Escalation in c (CVE-2026-46827)
vulnerability in c (CVE-2026-46827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46826 |
|
Vulnerability in c (CVE-2026-46826)
vulnerability in c (CVE-2026-46826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46823 |
|
Authorization Flaw in c (CVE-2026-46823)
vulnerability in c (CVE-2026-46823). Confidential information can be exposed externally.
|
| CVE-2026-46829 |
|
Vulnerability in c (CVE-2026-46829)
vulnerability in c (CVE-2026-46829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46828 |
|
Vulnerability in c (CVE-2026-46828)
vulnerability in c (CVE-2026-46828). Confidential information can be exposed externally.
|
| CVE-2026-46834 |
|
Vulnerability in c (CVE-2026-46834)
vulnerability in c (CVE-2026-46834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46835 |
|
Vulnerability in c (CVE-2026-46835)
vulnerability in c (CVE-2026-46835). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46837 |
|
Privilege Escalation in c (CVE-2026-46837)
vulnerability in c (CVE-2026-46837). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46820 |
|
Vulnerability in c (CVE-2026-46820)
vulnerability in c (CVE-2026-46820). Confidential information can be exposed externally.
|
| CVE-2026-46818 |
|
Vulnerability in c (CVE-2026-46818)
vulnerability in c (CVE-2026-46818). Confidential information can be exposed externally.
|
| CVE-2026-46821 |
|
Vulnerability in c (CVE-2026-46821)
vulnerability in c (CVE-2026-46821). Confidential information can be exposed externally.
|
| CVE-2026-42398 |
|
SSRF (Server-Side Request Forgery) in elk (CVE-2026-42398)
SSRF in elk (CVE-2026-42398). Confidential information can be exposed externally. Mitigation: upgrade to `9.2.8, 9.3.2` or later.
|
| CVE-2026-35277 |
|
Vulnerability in c (CVE-2026-35277)
vulnerability in c (CVE-2026-35277). Confidential information can be exposed externally.
|
| CVE-2026-35266 |
|
Vulnerability in c (CVE-2026-35266)
vulnerability in c (CVE-2026-35266). Confidential information can be exposed externally.
|
| CVE-2026-49127 |
|
Vulnerability in CVE-2026-49127 (CVE-2026-49127)
vulnerability in CVE-2026-49127 (CVE-2026-49127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49128 |
|
Path Traversal in path-traversal (CVE-2026-49128)
path traversal in path-traversal (CVE-2026-49128). Confidential information can be exposed externally.
|
| CVE-2026-32847 |
|
Path Traversal in path-traversal (CVE-2026-32847)
path traversal in path-traversal (CVE-2026-32847). Confidential information can be exposed externally. Exploitable via `GET /{full_path`.
|
| CVE-2026-47333 |
|
Out-of-Bounds Read in canonical (CVE-2026-47333)
vulnerability in canonical (CVE-2026-47333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4944 |
|
Path Traversal in CVE-2026-4944 (CVE-2026-4944)
path traversal in CVE-2026-4944 (CVE-2026-4944). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47331 |
|
Use-After-Free in canonical (CVE-2026-47331)
vulnerability in canonical (CVE-2026-47331). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30760 |
|
Vulnerability in CVE-2026-30760 (CVE-2026-30760)
vulnerability in CVE-2026-30760 (CVE-2026-30760). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30761 |
|
Unrestricted File Upload in CVE-2026-30761 (CVE-2026-30761)
vulnerability in CVE-2026-30761 (CVE-2026-30761). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46439 |
|
Vulnerability in compliance-trestle (CVE-2026-46439)
vulnerability in compliance-trestle (CVE-2026-46439). Successful exploitation can lead to full system takeover. Exploitable via ``render_template``. Mitigation: upgrade to `4.0.3` or later.
|
| CVE-2026-45296 |
|
Vulnerability in CVE-2026-45296 (CVE-2026-45296)
vulnerability in CVE-2026-45296 (CVE-2026-45296). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.0` or later.
|
| CVE-2026-34126 |
|
Vulnerability in tp-link (CVE-2026-34126)
vulnerability in tp-link (CVE-2026-34126). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46345 |
|
Path Traversal in compliance-trestle (CVE-2026-46345)
path traversal in compliance-trestle (CVE-2026-46345). Successful exploitation can lead to full system takeover. Exploitable via ``trestle``. Mitigation: upgrade to `3.12.2` or later.
|
| CVE-2026-45756 |
|
Vulnerability in symfony/json-path (CVE-2026-45756)
vulnerability in symfony/json-path (CVE-2026-45756). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonPath``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-9095 |
|
Vulnerability in CVE-2026-9095 (CVE-2026-9095)
vulnerability in CVE-2026-9095 (CVE-2026-9095). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9096 |
|
Vulnerability in github.com/casdoor/casdoor (CVE-2026-9096)
vulnerability in github.com/casdoor/casdoor (CVE-2026-9096). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8697 |
|
Vulnerability in tp-link (CVE-2026-8697)
vulnerability in tp-link (CVE-2026-8697). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44465 |
|
OS Command Injection in zed (CVE-2026-44465)
OS command injection in zed (CVE-2026-44465). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.227.1` or later.
|
| CVE-2026-44466 |
|
OS Command Injection in zed (CVE-2026-44466)
OS command injection in zed (CVE-2026-44466). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.229.0` or later.
|
| CVE-2026-44463 |
|
OS Command Injection in zed (CVE-2026-44463)
OS command injection in zed (CVE-2026-44463). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.229.0` or later.
|
| CVE-2026-44461 |
|
OS Command Injection in zed (CVE-2026-44461)
OS command injection in zed (CVE-2026-44461). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.227.1` or later.
|
| CVE-2026-6824 |
|
Cross-Site Scripting (XSS) in cisa (CVE-2026-6824)
cross-site scripting in cisa (CVE-2026-6824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42941 |
|
Vulnerability in cisa (CVE-2026-42941)
vulnerability in cisa (CVE-2026-42941). Confidential information can be exposed externally.
|
| CVE-2026-48526 |
|
Authentication Bypass in pyjwt (CVE-2026-48526)
authentication bypass in pyjwt (CVE-2026-48526). Confidential information can be exposed externally. Mitigation: upgrade to `2.13.0` or later.
|
| CVE-2026-47760 |
|
Cross-Site Scripting (XSS) in tinymce (CVE-2026-47760)
cross-site scripting in tinymce (CVE-2026-47760). Confidential information can be exposed externally. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-47759 |
|
Cross-Site Scripting (XSS) in tinymce (CVE-2026-47759)
cross-site scripting in tinymce (CVE-2026-47759). Confidential information can be exposed externally. Mitigation: upgrade to `8.5.1` or later.
|
| CVE-2026-47762 |
|
Cross-Site Scripting (XSS) in tinymce (CVE-2026-47762)
cross-site scripting in tinymce (CVE-2026-47762). Confidential information can be exposed externally. Mitigation: upgrade to `8.5.1` or later.
|
| CVE-2026-47761 |
|
Cross-Site Scripting (XSS) in tinymce (CVE-2026-47761)
cross-site scripting in tinymce (CVE-2026-47761). Confidential information can be exposed externally. Mitigation: upgrade to `8.5.1` or later.
|
| CVE-2026-44358 |
|
Vulnerability in CVE-2026-44358 (CVE-2026-44358)
vulnerability in CVE-2026-44358 (CVE-2026-44358). Data can be tampered with by attackers. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-41565 |
|
Vulnerability in CVE-2026-41565 (CVE-2026-41565)
vulnerability in CVE-2026-41565 (CVE-2026-41565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49237 |
|
Vulnerability in privilege-escalation (CVE-2026-49237)
vulnerability in privilege-escalation (CVE-2026-49237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49238 |
|
Path Traversal in cpp (CVE-2026-49238)
path traversal in cpp (CVE-2026-49238). Confidential information can be exposed externally.
|
| CVE-2026-37266 |
|
Vulnerability in CVE-2026-37266 (CVE-2026-37266)
vulnerability in CVE-2026-37266 (CVE-2026-37266). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37579 |
|
Unsafe Deserialization in CVE-2026-37579 (CVE-2026-37579)
vulnerability in CVE-2026-37579 (CVE-2026-37579). Risk of unauthorized operations or information disclosure.
|