Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-22621 |
|
OS Command Injection in CVE-2026-22621 (CVE-2026-22621)
OS command injection in CVE-2026-22621 (CVE-2026-22621). Confidential information can be exposed externally.
|
| CVE-2026-22620 |
|
SQL Injection in CVE-2026-22620 (CVE-2026-22620)
SQL injection in CVE-2026-22620 (CVE-2026-22620). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18363 |
|
Vulnerability in CVE-2026-18363 (CVE-2026-18363)
vulnerability in CVE-2026-18363 (CVE-2026-18363). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18369 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-18369)
SSRF in ssrf (CVE-2026-18369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7260 |
|
Vulnerability in c (CVE-2026-7260)
vulnerability in c (CVE-2026-7260). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17544 |
|
Out-of-Bounds Write in CVE-2026-17544 (CVE-2026-17544)
out-of-bounds write in CVE-2026-17544 (CVE-2026-17544). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17543 |
|
SQL Injection in sqli (CVE-2026-17543)
SQL injection in sqli (CVE-2026-17543). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18362 |
|
Vulnerability in CVE-2026-18362 (CVE-2026-18362)
vulnerability in CVE-2026-18362 (CVE-2026-18362). Confidential information can be exposed externally.
|
| CVE-2026-18361 |
|
Cross-Site Scripting (XSS) in CVE-2026-18361 (CVE-2026-18361)
cross-site scripting in CVE-2026-18361 (CVE-2026-18361). Confidential information can be exposed externally.
|
| CVE-2026-18360 |
|
Cross-Site Scripting (XSS) in CVE-2026-18360 (CVE-2026-18360)
cross-site scripting in CVE-2026-18360 (CVE-2026-18360). Confidential information can be exposed externally.
|
| CVE-2026-16971 |
|
Vulnerability in CVE-2026-16971 (CVE-2026-16971)
vulnerability in CVE-2026-16971 (CVE-2026-16971). Confidential information can be exposed externally.
|
| CVE-2026-16970 |
|
Vulnerability in CVE-2026-16970 (CVE-2026-16970)
vulnerability in CVE-2026-16970 (CVE-2026-16970). Confidential information can be exposed externally.
|
| CVE-2026-16969 |
|
Cross-Site Scripting (XSS) in CVE-2026-16969 (CVE-2026-16969)
cross-site scripting in CVE-2026-16969 (CVE-2026-16969). Confidential information can be exposed externally.
|
| CVE-2022-4994 |
|
Vulnerability in CVE-2022-4994 (CVE-2022-4994)
vulnerability in CVE-2022-4994 (CVE-2022-4994). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18353 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18353 (CVE-2026-18353)
SSRF in CVE-2026-18353 (CVE-2026-18353). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/upload/sbom`.
|
| CVE-2026-7849 |
|
Command Injection in CVE-2026-7849 (CVE-2026-7849)
command injection in CVE-2026-7849 (CVE-2026-7849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44108 |
|
Vulnerability in CVE-2026-44108 (CVE-2026-44108)
vulnerability in CVE-2026-44108 (CVE-2026-44108). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44107 |
|
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
|
| CVE-2026-44106 |
|
A privilege escalation vulnerability in the init-script for user-applications allows a low...
A privilege escalation vulnerability in the init-script for user-applications allows a low...
|
| CVE-2026-44105 |
|
Vulnerability in CVE-2026-44105 (CVE-2026-44105)
vulnerability in CVE-2026-44105 (CVE-2026-44105). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44104 |
|
Vulnerability in CVE-2026-44104 (CVE-2026-44104)
vulnerability in CVE-2026-44104 (CVE-2026-44104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44103 |
|
Unrestricted File Upload in CVE-2026-44103 (CVE-2026-44103)
vulnerability in CVE-2026-44103 (CVE-2026-44103). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44102 |
|
Vulnerability in CVE-2026-44102 (CVE-2026-44102)
vulnerability in CVE-2026-44102 (CVE-2026-44102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44101 |
|
Vulnerability in CVE-2026-44101 (CVE-2026-44101)
vulnerability in CVE-2026-44101 (CVE-2026-44101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44100 |
|
Vulnerability in CVE-2026-44100 (CVE-2026-44100)
vulnerability in CVE-2026-44100 (CVE-2026-44100). Data can be tampered with by attackers.
|
| CVE-2026-44099 |
|
A privilege escalation vulnerability in the system configuration allows a low-privileged local...
A privilege escalation vulnerability in the system configuration allows a low-privileged local...
|
| CVE-2026-44098 |
|
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
|
| CVE-2026-44097 |
|
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
|
| CVE-2026-44096 |
|
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute...
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute...
|
| CVE-2026-44095 |
|
A privilege escalation vulnerability in a script used for network configuration allows a low...
A privilege escalation vulnerability in a script used for network configuration allows a low...
|
| CVE-2026-44094 |
|
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
|
| CVE-2026-44093 |
|
A local privilege escalation vulnerability in the init-script for user-applications allows a low...
A local privilege escalation vulnerability in the init-script for user-applications allows a low...
|
| CVE-2026-44092 |
|
Vulnerability in CVE-2026-44092 (CVE-2026-44092)
vulnerability in CVE-2026-44092 (CVE-2026-44092). Data can be tampered with by attackers.
|
| CVE-2026-44091 |
|
Vulnerability in CVE-2026-44091 (CVE-2026-44091)
vulnerability in CVE-2026-44091 (CVE-2026-44091). Data can be tampered with by attackers.
|
| CVE-2026-44090 |
|
Vulnerability in CVE-2026-44090 (CVE-2026-44090)
vulnerability in CVE-2026-44090 (CVE-2026-44090). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13584 |
|
Vulnerability in dos (CVE-2026-13584)
vulnerability in dos (CVE-2026-13584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58046 |
|
SQL Injection in sqli (CVE-2026-58046)
SQL injection in sqli (CVE-2026-58046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58066 |
|
Authentication Bypass in rocketchat (CVE-2026-58066)
authentication bypass in rocketchat (CVE-2026-58066). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59327 |
|
Vulnerability in spring (CVE-2026-59327)
vulnerability in spring (CVE-2026-59327). Confidential information can be exposed externally.
|
| CVE-2026-58040 |
|
Vulnerability in CVE-2026-58040 (CVE-2026-58040)
vulnerability in CVE-2026-58040 (CVE-2026-58040). Confidential information can be exposed externally.
|
| CVE-2026-59326 |
|
Vulnerability in spring (CVE-2026-59326)
vulnerability in spring (CVE-2026-59326). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58043 |
|
Vulnerability in nodejs (CVE-2026-58043)
vulnerability in nodejs (CVE-2026-58043). Confidential information can be exposed externally.
|
| CVE-2026-16531 |
|
Path Traversal in path-traversal (CVE-2026-16531)
path traversal in path-traversal (CVE-2026-16531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16529 |
|
Vulnerability in dos (CVE-2026-16529)
vulnerability in dos (CVE-2026-16529). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47873 |
|
Vulnerability in CVE-2026-47873 (CVE-2026-47873)
vulnerability in CVE-2026-47873 (CVE-2026-47873). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56847 |
|
Vulnerability in nodejs (CVE-2026-56847)
vulnerability in nodejs (CVE-2026-56847). Confidential information can be exposed externally.
|
| CVE-2026-47882 |
|
Vulnerability in spring (CVE-2026-47882)
vulnerability in spring (CVE-2026-47882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16527 |
|
Vulnerability in CVE-2026-16527 (CVE-2026-16527)
vulnerability in CVE-2026-16527 (CVE-2026-16527). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56850 |
|
Authentication Bypass in nodejs (CVE-2026-56850)
authentication bypass in nodejs (CVE-2026-56850). Data can be tampered with by attackers.
|
| CVE-2026-16530 |
|
Out-of-Bounds Read in dos (CVE-2026-16530)
vulnerability in dos (CVE-2026-16530). Risk of unauthorized operations or information disclosure. Exploitable via ``pmproxy``.
|