Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2024-58359 Vulnerability in dos (CVE-2024-58359)
vulnerability in dos (CVE-2024-58359). Risk of unauthorized operations or information disclosure.
CVE-2024-58358 Vulnerability in dos (CVE-2024-58358)
vulnerability in dos (CVE-2024-58358). Risk of unauthorized operations or information disclosure.
CVE-2024-58357 Vulnerability in dos (CVE-2024-58357)
vulnerability in dos (CVE-2024-58357). Risk of unauthorized operations or information disclosure.
CVE-2024-58356 Vulnerability in surrealdb (CVE-2024-58356)
vulnerability in surrealdb (CVE-2024-58356). Risk of unauthorized operations or information disclosure.
CVE-2023-54366 SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
CVE-2026-9147 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
CVE-2026-59173 Vulnerability in apache (CVE-2026-59173)
vulnerability in apache (CVE-2026-59173). Risk of unauthorized operations or information disclosure.
CVE-2026-16158 Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
CVE-2026-15631 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
CVE-2026-16097 Buffer Overflow in CVE-2026-16097 (CVE-2026-16097)
vulnerability in CVE-2026-16097 (CVE-2026-16097). Successful exploitation can lead to full system takeover.
CVE-2026-16095 Buffer Overflow in CVE-2026-16095 (CVE-2026-16095)
vulnerability in CVE-2026-16095 (CVE-2026-16095). Successful exploitation can lead to full system takeover.
CVE-2026-16096 Buffer Overflow in CVE-2026-16096 (CVE-2026-16096)
vulnerability in CVE-2026-16096 (CVE-2026-16096). Successful exploitation can lead to full system takeover.
CVE-2026-16088 Path Traversal in path-traversal (CVE-2026-16088)
path traversal in path-traversal (CVE-2026-16088). Risk of unauthorized operations or information disclosure.
CVE-2026-16085 Vulnerability in CVE-2026-16085 (CVE-2026-16085)
vulnerability in CVE-2026-16085 (CVE-2026-16085). Risk of unauthorized operations or information disclosure.
CVE-2026-47870 Privilege Escalation in privilege-escalation (CVE-2026-47870)
vulnerability in privilege-escalation (CVE-2026-47870). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47871 Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47869 Code Injection in broadcom (CVE-2026-47869)
code injection in broadcom (CVE-2026-47869). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47868 Privilege Escalation in privilege-escalation (CVE-2026-47868)
vulnerability in privilege-escalation (CVE-2026-47868). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-16084 SSRF (Server-Side Request Forgery) in CVE-2026-16084 (CVE-2026-16084)
SSRF in CVE-2026-16084 (CVE-2026-16084). Risk of unauthorized operations or information disclosure.
CVE-2026-47865 Authentication Bypass in broadcom (CVE-2026-47865)
authentication bypass in broadcom (CVE-2026-47865). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `31.2.2-2p3` or later.
CVE-2026-47866 Authorization Flaw in broadcom (CVE-2026-47866)
vulnerability in broadcom (CVE-2026-47866). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-16082 Vulnerability in CVE-2026-16082 (CVE-2026-16082)
vulnerability in CVE-2026-16082 (CVE-2026-16082). Risk of unauthorized operations or information disclosure.
CVE-2026-47867 Code Injection in broadcom (CVE-2026-47867)
code injection in broadcom (CVE-2026-47867). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-16083 Authentication Bypass in CVE-2026-16083 (CVE-2026-16083)
authentication bypass in CVE-2026-16083 (CVE-2026-16083). Risk of unauthorized operations or information disclosure.
CVE-2026-16081 Cross-Site Request Forgery (CSRF) in CVE-2026-16081 (CVE-2026-16081)
vulnerability in CVE-2026-16081 (CVE-2026-16081). Risk of unauthorized operations or information disclosure.
CVE-2026-16077 Vulnerability in CVE-2026-16077 (CVE-2026-16077)
vulnerability in CVE-2026-16077 (CVE-2026-16077). Risk of unauthorized operations or information disclosure.
CVE-2026-16076 Authentication Bypass in CVE-2026-16076 (CVE-2026-16076)
authentication bypass in CVE-2026-16076 (CVE-2026-16076). Risk of unauthorized operations or information disclosure.
CVE-2026-9734 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9734)
vulnerability in wordpress (CVE-2026-9734). Risk of unauthorized operations or information disclosure.
CVE-2026-16075 Vulnerability in CVE-2026-16075 (CVE-2026-16075)
vulnerability in CVE-2026-16075 (CVE-2026-16075). Risk of unauthorized operations or information disclosure.
CVE-2026-57980 Vulnerability in microsoft (CVE-2026-57980)
vulnerability in microsoft (CVE-2026-57980). Risk of unauthorized operations or information disclosure.
CVE-2026-56741 Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741). Risk of unauthorized operations or information disclosure. Exploitable via ``Telnet``. Mitigation: upgrade to `4.2.1` or later.
CVE-2026-56740 Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740). Risk of unauthorized operations or information disclosure. Exploitable via ``HashMap``. Mitigation: upgrade to `4.2.1` or later.
CVE-2026-56171 Vulnerability in microsoft (CVE-2026-56171)
vulnerability in microsoft (CVE-2026-56171). Confidential information can be exposed externally.
GHSA-8qqm-fp2q-v734 Vulnerability in github.com/zalando/skipper (GHSA-8qqm-fp2q-v734)
vulnerability in github.com/zalando/skipper (GHSA-8qqm-fp2q-v734). Risk of unauthorized operations or information disclosure. Exploitable via ``parsed_body``. Mitigation: upgrade to `0.27.26` or later.
CVE-2026-54246 Vulnerability in github.com/zalando/skipper (CVE-2026-54246)
vulnerability in github.com/zalando/skipper (CVE-2026-54246). Risk of unauthorized operations or information disclosure. Exploitable via `GET /routes`. Mitigation: upgrade to `0.27.13` or later.
CVE-2026-55177 SSRF (Server-Side Request Forgery) in @tak-ps/cloudtak (CVE-2026-55177)
SSRF in @tak-ps/cloudtak (CVE-2026-55177). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/esri`. Mitigation: upgrade to `13.10.0` or later.
CVE-2026-52348 cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
CVE-2026-52203 Information Disclosure in CVE-2026-52203 (CVE-2026-52203)
vulnerability in CVE-2026-52203 (CVE-2026-52203). Confidential information can be exposed externally.
CVE-2026-52584 Vulnerability in CVE-2026-52584 (CVE-2026-52584)
vulnerability in CVE-2026-52584 (CVE-2026-52584). Confidential information can be exposed externally.
CVE-2026-16074 SSRF (Server-Side Request Forgery) in CVE-2026-16074 (CVE-2026-16074)
SSRF in CVE-2026-16074 (CVE-2026-16074). Risk of unauthorized operations or information disclosure.
CVE-2026-13446 Vulnerability in langflow (CVE-2026-13446)
vulnerability in langflow (CVE-2026-13446). Successful exploitation can lead to full system takeover.
CVE-2026-13445 Vulnerability in langflow (CVE-2026-13445)
vulnerability in langflow (CVE-2026-13445). Confidential information can be exposed externally.
CVE-2026-54559 Buffer Overflow in pocketsphinx (CVE-2026-54559)
vulnerability in pocketsphinx (CVE-2026-54559). Risk of unauthorized operations or information disclosure. Exploitable via ``sscanf``. Mitigation: upgrade to `5.1.1` or later.
CVE-2026-54570 Vulnerability in AngleSharp (CVE-2026-54570)
vulnerability in AngleSharp (CVE-2026-54570). Data can be tampered with by attackers. Exploitable via ``MathAnnotationXmlElement``. Mitigation: upgrade to `1.5.0` or later.
GHSA-mfr4-mq8w-vmg6 Path Traversal in proot-distro (GHSA-mfr4-mq8w-vmg6)
path traversal in proot-distro (GHSA-mfr4-mq8w-vmg6). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.1.0` or later.
CVE-2026-53496 Vulnerability in exifreader (CVE-2026-53496)
vulnerability in exifreader (CVE-2026-53496). Risk of unauthorized operations or information disclosure. Exploitable via ``ftyp``. Mitigation: upgrade to `4.40.1` or later.
CVE-2026-8861 Vulnerability in ibm (CVE-2026-8861)
vulnerability in ibm (CVE-2026-8861). Risk of unauthorized operations or information disclosure.
CVE-2026-8859 Path Traversal in path-traversal (CVE-2026-8859)
path traversal in path-traversal (CVE-2026-8859). Successful exploitation can lead to full system takeover.
CVE-2026-8635 Code Injection in c (CVE-2026-8635)
code injection in c (CVE-2026-8635). Successful exploitation can lead to full system takeover.
CVE-2026-8505 Vulnerability in langflow (CVE-2026-8505)
vulnerability in langflow (CVE-2026-8505). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →