Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-62959 |
|
Out-of-Bounds Read in CVE-2026-62959 (CVE-2026-62959)
vulnerability in CVE-2026-62959 (CVE-2026-62959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55825 |
|
Path Traversal in contao/contao (CVE-2026-55825)
path traversal in contao/contao (CVE-2026-55825). Risk of unauthorized operations or information disclosure. Exploitable via ``jobUuid``. Mitigation: upgrade to `5.7.7` or later.
|
| CVE-2026-38711 |
|
Command Injection in CVE-2026-38711 (CVE-2026-38711)
command injection in CVE-2026-38711 (CVE-2026-38711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53551 |
|
Vulnerability in github.com/free5gc/free5gc (CVE-2026-53551)
vulnerability in github.com/free5gc/free5gc (CVE-2026-53551). Risk of unauthorized operations or information disclosure. Exploitable via `POST /nausf-auth/v1/ue-authentications`. Mitigation: upgrade to `4.2.2` or later.
|
| GHSA-3whf-vgf2-9w6g |
|
Vulnerability in zaino-state (GHSA-3whf-vgf2-9w6g)
vulnerability in zaino-state (GHSA-3whf-vgf2-9w6g). Risk of unauthorized operations or information disclosure. Exploitable via ``previous_block_hash``. Mitigation: upgrade to `0.4.1` or later.
|
| CVE-2026-53599 |
|
Unrestricted File Upload in redaxo/source (CVE-2026-53599)
vulnerability in redaxo/source (CVE-2026-53599). Successful exploitation can lead to full system takeover. Exploitable via ``shell.php.any.jpg``. Mitigation: upgrade to `5.21.1` or later.
|
| CVE-2026-53510 |
|
Code Injection in savon (CVE-2026-53510)
code injection in savon (CVE-2026-53510). Successful exploitation can lead to full system takeover. Exploitable via ``module_eval``. Mitigation: upgrade to `2.17.2` or later.
|
| CVE-2026-18420 |
|
Vulnerability in Amazon aws (CVE-2026-18420)
vulnerability in Amazon aws (CVE-2026-18420). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57232 |
|
SSRF (Server-Side Request Forgery) in symfony (CVE-2026-57232)
SSRF in symfony (CVE-2026-57232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55824 |
|
Information Disclosure in contao/contao (CVE-2026-55824)
vulnerability in contao/contao (CVE-2026-55824). Risk of unauthorized operations or information disclosure. Exploitable via ``Cookie``. Mitigation: upgrade to `5.7.7` or later.
|
| CVE-2026-25552 |
|
Vulnerability in nginx (CVE-2026-25552)
vulnerability in nginx (CVE-2026-25552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18481 |
|
Cross-Site Scripting (XSS) in Amazon aws (CVE-2026-18481)
cross-site scripting in Amazon aws (CVE-2026-18481). Confidential information can be exposed externally.
|
| CVE-2026-18321 |
|
Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
|
| CVE-2026-65841 |
|
Vulnerability in jodit (CVE-2026-65841)
vulnerability in jodit (CVE-2026-65841). Risk of unauthorized operations or information disclosure. Exploitable via ``node.nodeName``. Mitigation: upgrade to `4.13.6` or later.
|
| CVE-2026-62324 |
|
Cross-Site Scripting (XSS) in jodit (CVE-2026-62324)
cross-site scripting in jodit (CVE-2026-62324). Risk of unauthorized operations or information disclosure. Exploitable via ``sanitizeHTMLElement``. Mitigation: upgrade to `4.12.31` or later.
|
| CVE-2026-53502 |
|
Path Traversal in thumbor (CVE-2026-53502)
path traversal in thumbor (CVE-2026-53502). Risk of unauthorized operations or information disclosure. Exploitable via ``imaging.py``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53505 |
|
Vulnerability in thumbor (CVE-2026-53505)
vulnerability in thumbor (CVE-2026-53505). Risk of unauthorized operations or information disclosure. Exploitable via ``value``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53504 |
|
Vulnerability in thumbor (CVE-2026-53504)
vulnerability in thumbor (CVE-2026-53504). Risk of unauthorized operations or information disclosure. Exploitable via ``convolution``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53503 |
|
Vulnerability in thumbor (CVE-2026-53503)
vulnerability in thumbor (CVE-2026-53503). Risk of unauthorized operations or information disclosure. Exploitable via ``columns_count``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53501 |
|
Vulnerability in thumbor (CVE-2026-53501)
vulnerability in thumbor (CVE-2026-53501). Data can be tampered with by attackers. Exploitable via ``url_to_validate``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53500 |
|
SSRF (Server-Side Request Forgery) in thumbor (CVE-2026-53500)
SSRF in thumbor (CVE-2026-53500). Confidential information can be exposed externally. Exploitable via ``ALLOWED_SOURCES``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-34490 |
|
Vulnerability in johnsoncontrols (CVE-2026-34490)
vulnerability in johnsoncontrols (CVE-2026-34490). Confidential information can be exposed externally.
|
| CVE-2026-21662 |
|
Unrestricted File Upload in johnsoncontrols (CVE-2026-21662)
vulnerability in johnsoncontrols (CVE-2026-21662). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34497 |
|
Vulnerability in johnsoncontrols (CVE-2026-34497)
vulnerability in johnsoncontrols (CVE-2026-34497). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34495 |
|
Cross-Site Scripting (XSS) in johnsoncontrols (CVE-2026-34495)
cross-site scripting in johnsoncontrols (CVE-2026-34495). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54737 |
|
Vulnerability in @phun-ky/defaults-deep (CVE-2026-54737)
vulnerability in @phun-ky/defaults-deep (CVE-2026-54737). Risk of unauthorized operations or information disclosure. Exploitable via ``__proto__``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-54725 |
|
SSRF (Server-Side Request Forgery) in github.com/bank-vaults/vault-secrets-webhook (CVE-2026-54725)
SSRF in github.com/bank-vaults/vault-secrets-webhook (CVE-2026-54725). Confidential information can be exposed externally. Exploitable via ``VaultAddrAnnotation``. Mitigation: upgrade to `1.23.1` or later.
|
| CVE-2026-67822 |
|
Vulnerability in CVE-2026-67822 (CVE-2026-67822)
vulnerability in CVE-2026-67822 (CVE-2026-67822). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58048 |
|
SQL Injection in CVE-2026-58048 (CVE-2026-58048)
SQL injection in CVE-2026-58048 (CVE-2026-58048). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58047 |
|
HTTP Smuggling in cPanel allows potential leak of credentials.
HTTP Smuggling in cPanel allows potential leak of credentials.
|
| CVE-2026-55100 |
|
Vulnerability in hashi-vault-js (CVE-2026-55100)
vulnerability in hashi-vault-js (CVE-2026-55100). Risk of unauthorized operations or information disclosure. Exploitable via ``encodeURIComponent``. Mitigation: upgrade to `0.5.2` or later.
|
| CVE-2026-54729 |
|
SSRF (Server-Side Request Forgery) in dssrf (CVE-2026-54729)
SSRF in dssrf (CVE-2026-54729). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.5` or later.
|
| CVE-2026-12075 |
|
SSRF (Server-Side Request Forgery) in nltk (CVE-2026-12075)
SSRF in nltk (CVE-2026-12075). Risk of unauthorized operations or information disclosure. Exploitable via ``nltk.pathsec``. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-12061 |
|
Vulnerability in nltk (CVE-2026-12061)
vulnerability in nltk (CVE-2026-12061). Risk of unauthorized operations or information disclosure. Exploitable via ``ReviewsCorpusReader``. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-12072 |
|
Path Traversal in nltk (CVE-2026-12072)
path traversal in nltk (CVE-2026-12072). Risk of unauthorized operations or information disclosure. Exploitable via ``NKJPCorpusReader``. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-12074 |
|
Path Traversal in nltk (CVE-2026-12074)
path traversal in nltk (CVE-2026-12074). Risk of unauthorized operations or information disclosure. Exploitable via ``nltk.pathsec``. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-54706 |
|
Vulnerability in onionshare-cli (CVE-2026-54706)
vulnerability in onionshare-cli (CVE-2026-54706). Confidential information can be exposed externally. Exploitable via ``onionshare_cli.web``. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-54707 |
|
Authorization Flaw in onionshare-cli (CVE-2026-54707)
vulnerability in onionshare-cli (CVE-2026-54707). Risk of unauthorized operations or information disclosure. Exploitable via `POST /upload`. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-52856 |
|
Vulnerability in github.com/pterodactyl/wings (CVE-2026-52856)
vulnerability in github.com/pterodactyl/wings (CVE-2026-52856). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.13.0` or later.
|
| CVE-2026-67607 |
|
Vulnerability in c (CVE-2026-67607)
vulnerability in c (CVE-2026-67607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59232 |
|
Cross-Site Scripting (XSS) in CVE-2026-59232 (CVE-2026-59232)
cross-site scripting in CVE-2026-59232 (CVE-2026-59232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59231 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-59231 (CVE-2026-59231)
SSRF in CVE-2026-59231 (CVE-2026-59231). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56571 |
|
Vulnerability in hcltech (CVE-2026-56571)
vulnerability in hcltech (CVE-2026-56571). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56570 |
|
Vulnerability in hcltech (CVE-2026-56570)
vulnerability in hcltech (CVE-2026-56570). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56569 |
|
Vulnerability in hcltech (CVE-2026-56569)
vulnerability in hcltech (CVE-2026-56569). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56568 |
|
Vulnerability in hcltech (CVE-2026-56568)
vulnerability in hcltech (CVE-2026-56568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56567 |
|
Vulnerability in hcltech (CVE-2026-56567)
vulnerability in hcltech (CVE-2026-56567). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18141 |
|
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
|
| CVE-2026-17566 |
|
OS Command Injection in pgadmin (CVE-2026-17566)
OS command injection in pgadmin (CVE-2026-17566). Successful exploitation can lead to full system takeover. Exploitable via `POST /import_export/job/`.
|
| CVE-2026-17351 |
|
SQL Injection in pgadmin (CVE-2026-17351)
SQL injection in pgadmin (CVE-2026-17351). Successful exploitation can lead to full system takeover.
|