Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-58359 |
|
Vulnerability in dos (CVE-2024-58359)
vulnerability in dos (CVE-2024-58359). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58358 |
|
Vulnerability in dos (CVE-2024-58358)
vulnerability in dos (CVE-2024-58358). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58357 |
|
Vulnerability in dos (CVE-2024-58357)
vulnerability in dos (CVE-2024-58357). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58356 |
|
Vulnerability in surrealdb (CVE-2024-58356)
vulnerability in surrealdb (CVE-2024-58356). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-54366 |
|
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
|
| CVE-2026-9147 |
|
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
|
| CVE-2026-59173 |
|
Vulnerability in apache (CVE-2026-59173)
vulnerability in apache (CVE-2026-59173). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16158 |
|
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
|
| CVE-2026-15631 |
|
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
|
| CVE-2026-16097 |
|
Buffer Overflow in CVE-2026-16097 (CVE-2026-16097)
vulnerability in CVE-2026-16097 (CVE-2026-16097). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16095 |
|
Buffer Overflow in CVE-2026-16095 (CVE-2026-16095)
vulnerability in CVE-2026-16095 (CVE-2026-16095). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16096 |
|
Buffer Overflow in CVE-2026-16096 (CVE-2026-16096)
vulnerability in CVE-2026-16096 (CVE-2026-16096). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16088 |
|
Path Traversal in path-traversal (CVE-2026-16088)
path traversal in path-traversal (CVE-2026-16088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16085 |
|
Vulnerability in CVE-2026-16085 (CVE-2026-16085)
vulnerability in CVE-2026-16085 (CVE-2026-16085). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47870 |
|
Privilege Escalation in privilege-escalation (CVE-2026-47870)
vulnerability in privilege-escalation (CVE-2026-47870). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-47871 |
|
Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-47869 |
|
Code Injection in broadcom (CVE-2026-47869)
code injection in broadcom (CVE-2026-47869). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-47868 |
|
Privilege Escalation in privilege-escalation (CVE-2026-47868)
vulnerability in privilege-escalation (CVE-2026-47868). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-16084 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16084 (CVE-2026-16084)
SSRF in CVE-2026-16084 (CVE-2026-16084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47865 |
|
Authentication Bypass in broadcom (CVE-2026-47865)
authentication bypass in broadcom (CVE-2026-47865). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `31.2.2-2p3` or later.
|
| CVE-2026-47866 |
|
Authorization Flaw in broadcom (CVE-2026-47866)
vulnerability in broadcom (CVE-2026-47866). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-16082 |
|
Vulnerability in CVE-2026-16082 (CVE-2026-16082)
vulnerability in CVE-2026-16082 (CVE-2026-16082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47867 |
|
Code Injection in broadcom (CVE-2026-47867)
code injection in broadcom (CVE-2026-47867). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-16083 |
|
Authentication Bypass in CVE-2026-16083 (CVE-2026-16083)
authentication bypass in CVE-2026-16083 (CVE-2026-16083). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16081 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-16081 (CVE-2026-16081)
vulnerability in CVE-2026-16081 (CVE-2026-16081). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16077 |
|
Vulnerability in CVE-2026-16077 (CVE-2026-16077)
vulnerability in CVE-2026-16077 (CVE-2026-16077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16076 |
|
Authentication Bypass in CVE-2026-16076 (CVE-2026-16076)
authentication bypass in CVE-2026-16076 (CVE-2026-16076). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9734 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9734)
vulnerability in wordpress (CVE-2026-9734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16075 |
|
Vulnerability in CVE-2026-16075 (CVE-2026-16075)
vulnerability in CVE-2026-16075 (CVE-2026-16075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57980 |
|
Vulnerability in microsoft (CVE-2026-57980)
vulnerability in microsoft (CVE-2026-57980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56741 |
|
Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741). Risk of unauthorized operations or information disclosure. Exploitable via ``Telnet``. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2026-56740 |
|
Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740). Risk of unauthorized operations or information disclosure. Exploitable via ``HashMap``. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2026-56171 |
|
Vulnerability in microsoft (CVE-2026-56171)
vulnerability in microsoft (CVE-2026-56171). Confidential information can be exposed externally.
|
| GHSA-8qqm-fp2q-v734 |
|
Vulnerability in github.com/zalando/skipper (GHSA-8qqm-fp2q-v734)
vulnerability in github.com/zalando/skipper (GHSA-8qqm-fp2q-v734). Risk of unauthorized operations or information disclosure. Exploitable via ``parsed_body``. Mitigation: upgrade to `0.27.26` or later.
|
| CVE-2026-54246 |
|
Vulnerability in github.com/zalando/skipper (CVE-2026-54246)
vulnerability in github.com/zalando/skipper (CVE-2026-54246). Risk of unauthorized operations or information disclosure. Exploitable via `GET /routes`. Mitigation: upgrade to `0.27.13` or later.
|
| CVE-2026-55177 |
|
SSRF (Server-Side Request Forgery) in @tak-ps/cloudtak (CVE-2026-55177)
SSRF in @tak-ps/cloudtak (CVE-2026-55177). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/esri`. Mitigation: upgrade to `13.10.0` or later.
|
| CVE-2026-52348 |
|
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
|
| CVE-2026-52203 |
|
Information Disclosure in CVE-2026-52203 (CVE-2026-52203)
vulnerability in CVE-2026-52203 (CVE-2026-52203). Confidential information can be exposed externally.
|
| CVE-2026-52584 |
|
Vulnerability in CVE-2026-52584 (CVE-2026-52584)
vulnerability in CVE-2026-52584 (CVE-2026-52584). Confidential information can be exposed externally.
|
| CVE-2026-16074 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16074 (CVE-2026-16074)
SSRF in CVE-2026-16074 (CVE-2026-16074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13446 |
|
Vulnerability in langflow (CVE-2026-13446)
vulnerability in langflow (CVE-2026-13446). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13445 |
|
Vulnerability in langflow (CVE-2026-13445)
vulnerability in langflow (CVE-2026-13445). Confidential information can be exposed externally.
|
| CVE-2026-54559 |
|
Buffer Overflow in pocketsphinx (CVE-2026-54559)
vulnerability in pocketsphinx (CVE-2026-54559). Risk of unauthorized operations or information disclosure. Exploitable via ``sscanf``. Mitigation: upgrade to `5.1.1` or later.
|
| CVE-2026-54570 |
|
Vulnerability in AngleSharp (CVE-2026-54570)
vulnerability in AngleSharp (CVE-2026-54570). Data can be tampered with by attackers. Exploitable via ``MathAnnotationXmlElement``. Mitigation: upgrade to `1.5.0` or later.
|
| GHSA-mfr4-mq8w-vmg6 |
|
Path Traversal in proot-distro (GHSA-mfr4-mq8w-vmg6)
path traversal in proot-distro (GHSA-mfr4-mq8w-vmg6). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.1.0` or later.
|
| CVE-2026-53496 |
|
Vulnerability in exifreader (CVE-2026-53496)
vulnerability in exifreader (CVE-2026-53496). Risk of unauthorized operations or information disclosure. Exploitable via ``ftyp``. Mitigation: upgrade to `4.40.1` or later.
|
| CVE-2026-8861 |
|
Vulnerability in ibm (CVE-2026-8861)
vulnerability in ibm (CVE-2026-8861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8859 |
|
Path Traversal in path-traversal (CVE-2026-8859)
path traversal in path-traversal (CVE-2026-8859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8635 |
|
Code Injection in c (CVE-2026-8635)
code injection in c (CVE-2026-8635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8505 |
|
Vulnerability in langflow (CVE-2026-8505)
vulnerability in langflow (CVE-2026-8505). Successful exploitation can lead to full system takeover.
|