Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-34070 |
|
Path Traversal in langchain-core (CVE-2026-34070)
path traversal in langchain-core (CVE-2026-34070). Confidential information can be exposed externally. Exploitable via ``langchain_core.prompts.loading``. Mitigation: upgrade to `1.2.22` or later.
|
| CVE-2026-33984 |
|
Vulnerability in c (CVE-2026-33984)
vulnerability in c (CVE-2026-33984). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33986 |
|
Vulnerability in c (CVE-2026-33986)
vulnerability in c (CVE-2026-33986). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21710 |
|
Vulnerability in node (CVE-2026-21710)
vulnerability in node (CVE-2026-21710). Risk of unauthorized operations or information disclosure. Exploitable via ``TypeError``. Mitigation: upgrade to `20.20.2, 22.22.2, 24.14.1, 25.8.2` or later.
|
| CVE-2026-4046 |
|
Vulnerability in c (CVE-2026-4046)
vulnerability in c (CVE-2026-4046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5121 |
|
Vulnerability in libarchive (CVE-2026-5121)
vulnerability in libarchive (CVE-2026-5121). Confidential information can be exposed externally.
|
| CVE-2026-3945 |
|
Vulnerability in dos (CVE-2026-3945)
vulnerability in dos (CVE-2026-3945). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2370 |
|
Vulnerability in gitlab (CVE-2026-2370)
vulnerability in gitlab (CVE-2026-2370). Confidential information can be exposed externally. Mitigation: upgrade to `18.8.7, 18.9.3, 18.10.1` or later.
|
| CVE-2026-3055 KEV |
|
[KEV] Out-of-Bounds Read in Citrix netscaler (CVE-2026-3055)
vulnerability in Citrix netscaler (CVE-2026-3055). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-4946 |
|
OS Command Injection in nsa (CVE-2026-4946)
OS command injection in nsa (CVE-2026-4946). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34226 |
|
Vulnerability in capricorn86 (CVE-2026-34226)
vulnerability in capricorn86 (CVE-2026-34226). Confidential information can be exposed externally. Exploitable via ``window.location``.
|
| CVE-2026-33940 |
|
Code Injection in handlebarsjs (CVE-2026-33940)
code injection in handlebarsjs (CVE-2026-33940). Successful exploitation can lead to full system takeover. Exploitable via ``undefined``.
|
| CVE-2026-33941 |
|
Cross-Site Scripting (XSS) in handlebarsjs (CVE-2026-33941)
cross-site scripting in handlebarsjs (CVE-2026-33941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33943 |
|
Code Injection in capricorn86 (CVE-2026-33943)
code injection in capricorn86 (CVE-2026-33943). Successful exploitation can lead to full system takeover. Exploitable via ``ECMAScriptModuleCompiler``.
|
| CVE-2026-33939 |
|
Vulnerability in dos (CVE-2026-33939)
vulnerability in dos (CVE-2026-33939). Risk of unauthorized operations or information disclosure. Exploitable via ``undefined``.
|
| CVE-2026-27309 |
|
Use-After-Free in adobe (CVE-2026-27309)
vulnerability in adobe (CVE-2026-27309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33938 |
|
Code Injection in handlebarsjs (CVE-2026-33938)
code injection in handlebarsjs (CVE-2026-33938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34046 |
|
Vulnerability in langflow (CVE-2026-34046)
vulnerability in langflow (CVE-2026-34046). Successful exploitation can lead to full system takeover. Exploitable via ``_read_flow``.
|
| CVE-2026-33895 |
|
Vulnerability in digitalbazaar (CVE-2026-33895)
vulnerability in digitalbazaar (CVE-2026-33895). Data can be tampered with by attackers. Exploitable via ``crypto.verify``.
|
| CVE-2026-33896 |
|
Vulnerability in digitalbazaar (CVE-2026-33896)
vulnerability in digitalbazaar (CVE-2026-33896). Confidential information can be exposed externally. Exploitable via ``basicConstraints``.
|
| CVE-2026-33891 |
|
Vulnerability in dos (CVE-2026-33891)
vulnerability in dos (CVE-2026-33891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33894 |
|
Vulnerability in digitalbazaar (CVE-2026-33894)
vulnerability in digitalbazaar (CVE-2026-33894). Data can be tampered with by attackers.
|
| CVE-2026-33870 |
|
Vulnerability in netty (CVE-2026-33870)
vulnerability in netty (CVE-2026-33870). Data can be tampered with by attackers.
|
| CVE-2026-33871 |
|
Vulnerability in dos (CVE-2026-33871)
vulnerability in dos (CVE-2026-33871). Risk of unauthorized operations or information disclosure. Exploitable via ``CONTINUATION``.
|
| CVE-2026-34040 |
|
Vulnerability in github.com/moby/moby (CVE-2026-34040)
vulnerability in github.com/moby/moby (CVE-2026-34040). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `29.3.1` or later.
|
| CVE-2026-28369 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28369)
vulnerability in io.undertow:undertow-parent (CVE-2026-28369). Confidential information can be exposed externally.
|
| CVE-2026-28367 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28367)
vulnerability in io.undertow:undertow-parent (CVE-2026-28367). Confidential information can be exposed externally.
|
| CVE-2026-28368 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28368)
vulnerability in io.undertow:undertow-parent (CVE-2026-28368). Confidential information can be exposed externally.
|
| CVE-2025-15381 |
|
Information Disclosure in mlflow (CVE-2025-15381)
vulnerability in mlflow (CVE-2025-15381). Confidential information can be exposed externally. Exploitable via ``NO_PERMISSIONS``.
|
| CVE-2026-5027 |
|
Path Traversal in path-traversal (CVE-2026-5027)
path traversal in path-traversal (CVE-2026-5027). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v2/files`.
|
| CVE-2026-4984 |
|
Vulnerability in botpress (CVE-2026-4984)
vulnerability in botpress (CVE-2026-4984). Confidential information can be exposed externally.
|
| CVE-2026-33433 |
|
Vulnerability in traefik (CVE-2026-33433)
vulnerability in traefik (CVE-2026-33433). Successful exploitation can lead to full system takeover. Exploitable via ``headerField``.
|
| CVE-2026-27880 |
|
Out-of-Bounds Write in grafana (CVE-2026-27880)
out-of-bounds write in grafana (CVE-2026-27880). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
|
| CVE-2026-32695 |
|
Vulnerability in traefik (CVE-2026-32695)
vulnerability in traefik (CVE-2026-32695). Confidential information can be exposed externally. Exploitable via ``tenant.example.com``.
|
| CVE-2025-59032 |
|
Vulnerability in dovecot (CVE-2025-59032)
vulnerability in dovecot (CVE-2025-59032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24031 |
|
SQL Injection in dovecot (CVE-2026-24031)
SQL injection in dovecot (CVE-2026-24031). Confidential information can be exposed externally.
|
| CVE-2026-27856 |
|
Authentication Bypass in dovecot (CVE-2026-27856)
authentication bypass in dovecot (CVE-2026-27856). Confidential information can be exposed externally.
|
| CVE-2026-27858 |
|
Vulnerability in dovecot (CVE-2026-27858)
vulnerability in dovecot (CVE-2026-27858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22744 |
|
Vulnerability in vmware (CVE-2026-22744)
vulnerability in vmware (CVE-2026-22744). Confidential information can be exposed externally.
|
| CVE-2026-22742 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-22742)
SSRF in ssrf (CVE-2026-22742). Confidential information can be exposed externally.
|
| CVE-2026-27893 |
|
Vulnerability in vllm (CVE-2026-27893)
vulnerability in vllm (CVE-2026-27893). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.18.0` or later.
|
| CVE-2025-53521 KEV |
|
[KEV] Vulnerability in F5 big-ip (CVE-2025-53521)
vulnerability in F5 big-ip (CVE-2025-53521). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34352 |
|
Vulnerability in tigervnc (CVE-2026-34352)
vulnerability in tigervnc (CVE-2026-34352). Confidential information can be exposed externally.
|
| CVE-2026-0966 |
|
Vulnerability in dos (CVE-2026-0966)
vulnerability in dos (CVE-2026-0966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32285 |
|
Vulnerability in github.com/buger/jsonparser (CVE-2026-32285)
vulnerability in github.com/buger/jsonparser (CVE-2026-32285). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-32286 |
|
Vulnerability in github.com/jackc/pgproto3/v2 (CVE-2026-32286)
vulnerability in github.com/jackc/pgproto3/v2 (CVE-2026-32286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4926 |
|
Vulnerability in c (CVE-2026-4926)
vulnerability in c (CVE-2026-4926). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30463 |
|
SQL Injection in sqli (CVE-2026-30463)
SQL injection in sqli (CVE-2026-30463). Confidential information can be exposed externally.
|
| CVE-2026-33487 |
|
Vulnerability in goxmldsig-project (CVE-2026-33487)
vulnerability in goxmldsig-project (CVE-2026-33487). Data can be tampered with by attackers. Exploitable via ``validateSignature``.
|
| CVE-2026-32857 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32857)
SSRF in ssrf (CVE-2026-32857). Confidential information can be exposed externally.
|