Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16336 |
|
Open Redirect in CVE-2026-16336 (CVE-2026-16336)
vulnerability in CVE-2026-16336 (CVE-2026-16336). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6952 |
|
OS Command Injection in CVE-2026-6952 (CVE-2026-6952)
OS command injection in CVE-2026-6952 (CVE-2026-6952). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63729 |
|
Use-After-Free in c (CVE-2026-63729)
vulnerability in c (CVE-2026-63729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16334 |
|
Vulnerability in sqli (CVE-2026-16334)
vulnerability in sqli (CVE-2026-16334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16332 |
|
Vulnerability in CVE-2026-16332 (CVE-2026-16332)
vulnerability in CVE-2026-16332 (CVE-2026-16332). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16331 |
|
Vulnerability in CVE-2026-16331 (CVE-2026-16331)
vulnerability in CVE-2026-16331 (CVE-2026-16331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16330 |
|
Vulnerability in CVE-2026-16330 (CVE-2026-16330)
vulnerability in CVE-2026-16330 (CVE-2026-16330). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16329 |
|
Vulnerability in CVE-2026-16329 (CVE-2026-16329)
vulnerability in CVE-2026-16329 (CVE-2026-16329). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16327 |
|
Vulnerability in CVE-2026-16327 (CVE-2026-16327)
vulnerability in CVE-2026-16327 (CVE-2026-16327). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63728 |
|
Vulnerability in CVE-2026-63728 (CVE-2026-63728)
vulnerability in CVE-2026-63728 (CVE-2026-63728). Confidential information can be exposed externally.
|
| CVE-2026-55833 |
|
Vulnerability in io.netty:netty-codec-http (CVE-2026-55833)
vulnerability in io.netty:netty-codec-http (CVE-2026-55833). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.136.Final` or later.
|
| CVE-2026-55831 |
|
Vulnerability in io.netty:netty-codec-http (CVE-2026-55831)
vulnerability in io.netty:netty-codec-http (CVE-2026-55831). Risk of unauthorized operations or information disclosure. Exploitable via ``DefaultSpdySettingsFrame``. Mitigation: upgrade to `4.1.136.Final` or later.
|
| CVE-2026-0770 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-0770)
vulnerability in langflow (CVE-2026-0770). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| GHSA-h95v-h523-3mw8 |
|
Vulnerability in guzzlehttp/guzzle (GHSA-h95v-h523-3mw8)
vulnerability in guzzlehttp/guzzle (GHSA-h95v-h523-3mw8). Risk of unauthorized operations or information disclosure. Exploitable via ``referer``. Mitigation: upgrade to `7.15.1` or later.
|
| GHSA-wm3w-8rrp-j577 |
|
Vulnerability in guzzlehttp/guzzle (GHSA-wm3w-8rrp-j577)
vulnerability in guzzlehttp/guzzle (GHSA-wm3w-8rrp-j577). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.15.1` or later.
|
| GHSA-f283-ghqc-fg79 |
|
Vulnerability in guzzlehttp/guzzle (GHSA-f283-ghqc-fg79)
vulnerability in guzzlehttp/guzzle (GHSA-f283-ghqc-fg79). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.15.1` or later.
|
| CVE-2026-73423 |
|
Cross-Site Request Forgery (CSRF) in astro (CVE-2026-73423)
vulnerability in astro (CVE-2026-73423). Risk of unauthorized operations or information disclosure. Exploitable via ``security.checkOrigin``. Mitigation: upgrade to `7.0.6` or later.
|
| CVE-2026-73424 |
|
Vulnerability in @astrojs/vercel (CVE-2026-73424)
vulnerability in @astrojs/vercel (CVE-2026-73424). Risk of unauthorized operations or information disclosure. Exploitable via `GET /_isr`. Mitigation: upgrade to `10.0.2` or later.
|
| CVE-2026-73425 |
|
Vulnerability in @astrojs/netlify (CVE-2026-73425)
vulnerability in @astrojs/netlify (CVE-2026-73425). Risk of unauthorized operations or information disclosure. Exploitable via ``image.remotePatterns``. Mitigation: upgrade to `8.1.2` or later.
|
| CVE-2026-59730 |
|
Open Redirect in @astrojs/node (CVE-2026-59730)
vulnerability in @astrojs/node (CVE-2026-59730). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `11.0.2` or later.
|
| CVE-2026-59729 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-59729)
cross-site scripting in astro (CVE-2026-59729). Risk of unauthorized operations or information disclosure. Exploitable via ``INVALID_ATTR_NAME_CHAR``. Mitigation: upgrade to `7.0.6` or later.
|
| CVE-2026-59728 |
|
Vulnerability in @astrojs/rss (CVE-2026-59728)
vulnerability in @astrojs/rss (CVE-2026-59728). Risk of unauthorized operations or information disclosure. Exploitable via ``source.title``. Mitigation: upgrade to `4.0.19` or later.
|
| CVE-2026-59727 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-59727)
cross-site scripting in astro (CVE-2026-59727). Risk of unauthorized operations or information disclosure. Exploitable via ``attrs``. Mitigation: upgrade to `7.0.4` or later.
|
| CVE-2026-15905 |
|
Use-After-Free in google (CVE-2026-15905)
vulnerability in google (CVE-2026-15905). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15904 |
|
Use-After-Free in google (CVE-2026-15904)
vulnerability in google (CVE-2026-15904). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15903 |
|
Out-of-Bounds Read in google (CVE-2026-15903)
vulnerability in google (CVE-2026-15903). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15902 |
|
Use-After-Free in google (CVE-2026-15902)
vulnerability in google (CVE-2026-15902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15901 |
|
Use-After-Free in google (CVE-2026-15901)
vulnerability in google (CVE-2026-15901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15900 |
|
Use-After-Free in google (CVE-2026-15900)
vulnerability in google (CVE-2026-15900). Successful exploitation can lead to full system takeover.
|
| GHSA-gcfj-64vw-6mp9 |
|
Information Disclosure in axios (GHSA-gcfj-64vw-6mp9)
vulnerability in axios (GHSA-gcfj-64vw-6mp9). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-hcpx-6fm6-wx23 |
|
Vulnerability in axios (GHSA-hcpx-6fm6-wx23)
vulnerability in axios (GHSA-hcpx-6fm6-wx23). Risk of unauthorized operations or information disclosure. Exploitable via `POST /forward`. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-7q8q-rj6j-mhjq |
|
Vulnerability in axios (GHSA-7q8q-rj6j-mhjq)
vulnerability in axios (GHSA-7q8q-rj6j-mhjq). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-mwf2-3pr3-8698 |
|
Vulnerability in axios (GHSA-mwf2-3pr3-8698)
vulnerability in axios (GHSA-mwf2-3pr3-8698). Risk of unauthorized operations or information disclosure. Exploitable via ``maxBodyLength``. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-jqh4-m9w3-8hp9 |
|
Vulnerability in axios (GHSA-jqh4-m9w3-8hp9)
vulnerability in axios (GHSA-jqh4-m9w3-8hp9). Risk of unauthorized operations or information disclosure. Exploitable via ``maxBodyLength``. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-mmx7-hfxf-jppx |
|
Vulnerability in axios (GHSA-mmx7-hfxf-jppx)
vulnerability in axios (GHSA-mmx7-hfxf-jppx). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `0.33.0` or later.
|
| GHSA-f4gw-2p7v-4548 |
|
Vulnerability in axios (GHSA-f4gw-2p7v-4548)
vulnerability in axios (GHSA-f4gw-2p7v-4548). Risk of unauthorized operations or information disclosure. Exploitable via ``NO_PROXY``. Mitigation: upgrade to `0.33.0` or later.
|
| CVE-2026-62684 |
|
Information Disclosure in github.com/filebrowser/filebrowser/v2 (CVE-2026-62684)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-62684). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/shares`. Mitigation: upgrade to `2.63.17` or later.
|
| CVE-2026-64626 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-64626)
SSRF in ssrf (CVE-2026-64626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64625 |
|
OS Command Injection in c (CVE-2026-64625)
OS command injection in c (CVE-2026-64625). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64624 |
|
Vulnerability in freerdp (CVE-2026-64624)
vulnerability in freerdp (CVE-2026-64624). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57852 |
|
Vulnerability in CVE-2026-57852 (CVE-2026-57852)
vulnerability in CVE-2026-57852 (CVE-2026-57852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57495 |
|
Vulnerability in @agenticmail/core (CVE-2026-57495)
vulnerability in @agenticmail/core (CVE-2026-57495). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mail/inbound`. Mitigation: upgrade to `0.9.43` or later.
|
| CVE-2026-55550 |
|
Privilege Escalation in CVE-2026-55550 (CVE-2026-55550)
vulnerability in CVE-2026-55550 (CVE-2026-55550). Data can be tampered with by attackers. Exploitable via ``manager``.
|
| CVE-2026-55544 |
|
Vulnerability in CVE-2026-55544 (CVE-2026-55544)
vulnerability in CVE-2026-55544 (CVE-2026-55544). Data can be tampered with by attackers. Exploitable via ``nxtc__...``.
|
| CVE-2026-52656 |
|
Code Injection in CVE-2026-52656 (CVE-2026-52656)
code injection in CVE-2026-52656 (CVE-2026-52656). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51385 |
|
Code Injection in CVE-2026-51385 (CVE-2026-51385)
code injection in CVE-2026-51385 (CVE-2026-51385). Confidential information can be exposed externally.
|
| CVE-2026-51031 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51031)
SSRF in ssrf (CVE-2026-51031). Confidential information can be exposed externally.
|
| CVE-2026-51025 |
|
Cross-Site Scripting (XSS) in CVE-2026-51025 (CVE-2026-51025)
cross-site scripting in CVE-2026-51025 (CVE-2026-51025). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47134 |
|
Vulnerability in CVE-2026-47134 (CVE-2026-47134)
vulnerability in CVE-2026-47134 (CVE-2026-47134). Risk of unauthorized operations or information disclosure. Exploitable via ``SecKeyCreateRandomKey``.
|
| CVE-2026-47133 |
|
Vulnerability in CVE-2026-47133 (CVE-2026-47133)
vulnerability in CVE-2026-47133 (CVE-2026-47133). Risk of unauthorized operations or information disclosure. Exploitable via ``data_signatures``.
|