Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16196 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-16196)
SSRF in c (CVE-2026-16196). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16195 |
|
Vulnerability in CVE-2026-16195 (CVE-2026-16195)
vulnerability in CVE-2026-16195 (CVE-2026-16195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10130 |
|
Authorization Flaw in CVE-2026-10130 (CVE-2026-10130)
vulnerability in CVE-2026-10130 (CVE-2026-10130). Confidential information can be exposed externally.
|
| CVE-2026-16194 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16194 (CVE-2026-16194)
SSRF in CVE-2026-16194 (CVE-2026-16194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16156 |
|
Cross-Site Scripting (XSS) in CVE-2026-16156 (CVE-2026-16156)
cross-site scripting in CVE-2026-16156 (CVE-2026-16156). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16154 |
|
Vulnerability in sqli (CVE-2026-16154)
vulnerability in sqli (CVE-2026-16154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57857 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-57857)
cross-site scripting in wordpress (CVE-2026-57857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16155 |
|
Cross-Site Scripting (XSS) in CVE-2026-16155 (CVE-2026-16155)
cross-site scripting in CVE-2026-16155 (CVE-2026-16155). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12228 |
|
Cross-Site Scripting (XSS) in lollms (CVE-2026-12228)
cross-site scripting in lollms (CVE-2026-12228). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/prompts/share`.
|
| CVE-2026-16152 |
|
Vulnerability in sqli (CVE-2026-16152)
vulnerability in sqli (CVE-2026-16152). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57848 |
|
Vulnerability in CVE-2026-57848 (CVE-2026-57848)
vulnerability in CVE-2026-57848 (CVE-2026-57848). Confidential information can be exposed externally.
|
| CVE-2026-53994 |
|
Vulnerability in dos (CVE-2026-53994)
vulnerability in dos (CVE-2026-53994). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16151 |
|
Code Injection in CVE-2026-16151 (CVE-2026-16151)
code injection in CVE-2026-16151 (CVE-2026-16151). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16150 |
|
Code Injection in CVE-2026-16150 (CVE-2026-16150)
code injection in CVE-2026-16150 (CVE-2026-16150). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16133 |
|
Vulnerability in CVE-2026-16133 (CVE-2026-16133)
vulnerability in CVE-2026-16133 (CVE-2026-16133). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16131 |
|
Vulnerability in sqli (CVE-2026-16131)
vulnerability in sqli (CVE-2026-16131). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16130 |
|
Vulnerability in CVE-2026-16130 (CVE-2026-16130)
vulnerability in CVE-2026-16130 (CVE-2026-16130). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16128 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-16128)
SSRF in c (CVE-2026-16128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16129 |
|
Vulnerability in CVE-2026-16129 (CVE-2026-16129)
vulnerability in CVE-2026-16129 (CVE-2026-16129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16127 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-16127)
SSRF in c (CVE-2026-16127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16126 |
|
Vulnerability in c (CVE-2026-16126)
vulnerability in c (CVE-2026-16126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16125 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-16125)
SSRF in c (CVE-2026-16125). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16124 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16124 (CVE-2026-16124)
SSRF in CVE-2026-16124 (CVE-2026-16124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16122 |
|
Vulnerability in CVE-2026-16122 (CVE-2026-16122)
vulnerability in CVE-2026-16122 (CVE-2026-16122). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16123 |
|
Vulnerability in CVE-2026-16123 (CVE-2026-16123)
vulnerability in CVE-2026-16123 (CVE-2026-16123). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16121 |
|
Vulnerability in CVE-2026-16121 (CVE-2026-16121)
vulnerability in CVE-2026-16121 (CVE-2026-16121). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9323 |
|
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
|
| CVE-2026-16120 |
|
Vulnerability in CVE-2026-16120 (CVE-2026-16120)
vulnerability in CVE-2026-16120 (CVE-2026-16120). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16119 |
|
Vulnerability in CVE-2026-16119 (CVE-2026-16119)
vulnerability in CVE-2026-16119 (CVE-2026-16119). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16117 |
|
Vulnerability in fastify (CVE-2026-16117)
vulnerability in fastify (CVE-2026-16117). Confidential information can be exposed externally.
|
| CVE-2026-11826 |
|
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
|
| CVE-2025-71398 |
|
SSRF (Server-Side Request Forgery) in surrealdb (CVE-2025-71398)
SSRF in surrealdb (CVE-2025-71398). Confidential information can be exposed externally.
|
| CVE-2025-71397 |
|
Vulnerability in surrealdb (CVE-2025-71397)
vulnerability in surrealdb (CVE-2025-71397). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71396 |
|
Vulnerability in dos (CVE-2025-71396)
vulnerability in dos (CVE-2025-71396). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71395 |
|
Vulnerability in dos (CVE-2025-71395)
vulnerability in dos (CVE-2025-71395). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71394 |
|
Path Traversal in surrealdb (CVE-2025-71394)
path traversal in surrealdb (CVE-2025-71394). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71393 |
|
Vulnerability in surrealdb (CVE-2025-71393)
vulnerability in surrealdb (CVE-2025-71393). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71392 |
|
Command Injection in privilege-escalation (CVE-2025-71392)
command injection in privilege-escalation (CVE-2025-71392). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71391 |
|
Vulnerability in surrealdb (CVE-2025-71391)
vulnerability in surrealdb (CVE-2025-71391). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71390 |
|
Authorization Flaw in surrealdb (CVE-2025-71390)
vulnerability in surrealdb (CVE-2025-71390). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58370 |
|
Vulnerability in surrealdb (CVE-2024-58370)
vulnerability in surrealdb (CVE-2024-58370). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58369 |
|
Vulnerability in dos (CVE-2024-58369)
vulnerability in dos (CVE-2024-58369). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58368 |
|
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
|
| CVE-2024-58367 |
|
Vulnerability in surrealdb (CVE-2024-58367)
vulnerability in surrealdb (CVE-2024-58367). Confidential information can be exposed externally.
|
| CVE-2024-58366 |
|
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
|
| CVE-2024-58365 |
|
Vulnerability in surrealdb (CVE-2024-58365)
vulnerability in surrealdb (CVE-2024-58365). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58364 |
|
Vulnerability in dos (CVE-2024-58364)
vulnerability in dos (CVE-2024-58364). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58363 |
|
Authentication Bypass in surrealdb (CVE-2024-58363)
authentication bypass in surrealdb (CVE-2024-58363). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58362 |
|
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...
|
| CVE-2024-58361 |
|
Vulnerability in surrealdb (CVE-2024-58361)
vulnerability in surrealdb (CVE-2024-58361). Risk of unauthorized operations or information disclosure.
|