Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-46485 |
|
Vulnerability in CVE-2026-46485 (CVE-2026-46485)
vulnerability in CVE-2026-46485 (CVE-2026-46485). Data can be tampered with by attackers.
|
| CVE-2026-26032 |
|
Path Traversal in apache (CVE-2026-26032)
path traversal in apache (CVE-2026-26032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15895 |
|
OS Command Injection in Amazon jsii-diff (CVE-2026-15895)
OS command injection in Amazon jsii-diff (CVE-2026-15895). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.131.0` or later.
|
| CVE-2026-12997 |
|
Path Traversal in wordpress (CVE-2026-12997)
path traversal in wordpress (CVE-2026-12997). Confidential information can be exposed externally.
|
| CVE-2026-15746 |
|
SSRF (Server-Side Request Forgery) in Amazon aws (CVE-2026-15746)
SSRF in Amazon aws (CVE-2026-15746). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-62944 |
|
Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-62944)
cross-site scripting in mantisbt/mantisbt (CVE-2026-62944). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-52883 |
|
Vulnerability in mantisbt/mantisbt (CVE-2026-52883)
vulnerability in mantisbt/mantisbt (CVE-2026-52883). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-52882 |
|
Vulnerability in mantisbt/mantisbt (CVE-2026-52882)
vulnerability in mantisbt/mantisbt (CVE-2026-52882). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-52881 |
|
Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-52881)
cross-site scripting in mantisbt/mantisbt (CVE-2026-52881). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-59255 |
|
Vulnerability in CVE-2026-59255 (CVE-2026-59255)
vulnerability in CVE-2026-59255 (CVE-2026-59255). Data can be tampered with by attackers.
|
| CVE-2026-14961 |
|
Vulnerability in privilege-escalation (CVE-2026-14961)
vulnerability in privilege-escalation (CVE-2026-14961). Confidential information can be exposed externally. Exploitable via ``Tdelo64.sys``.
|
| CVE-2026-62389 |
|
Vulnerability in dos (CVE-2026-62389)
vulnerability in dos (CVE-2026-62389). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58660 |
|
Vulnerability in CVE-2026-58660 (CVE-2026-58660)
vulnerability in CVE-2026-58660 (CVE-2026-58660). Data can be tampered with by attackers.
|
| CVE-2026-59258 |
|
Authorization Flaw in CVE-2026-59258 (CVE-2026-59258)
vulnerability in CVE-2026-59258 (CVE-2026-59258). Data can be tampered with by attackers. Exploitable via `PUT /albums/`.
|
| CVE-2026-58659 |
|
Vulnerability in lightningai (CVE-2026-58659)
vulnerability in lightningai (CVE-2026-58659). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14960 |
|
Privilege Escalation in CVE-2026-14960 (CVE-2026-14960)
vulnerability in CVE-2026-14960 (CVE-2026-14960). Successful exploitation can lead to full system takeover. Exploitable via ``Tdelo64.sys``.
|
| CVE-2026-56087 |
|
Vulnerability in CVE-2026-56087 (CVE-2026-56087)
vulnerability in CVE-2026-56087 (CVE-2026-56087). Confidential information can be exposed externally.
|
| CVE-2026-20297 |
|
Path Traversal in path-traversal (CVE-2026-20297)
path traversal in path-traversal (CVE-2026-20297). Successful exploitation can lead to full system takeover. Exploitable via ``edit_local_apps``.
|
| CVE-2026-56687 |
|
Vulnerability in CVE-2026-56687 (CVE-2026-56687)
vulnerability in CVE-2026-56687 (CVE-2026-56687). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40501 |
|
Vulnerability in CVE-2026-40501 (CVE-2026-40501)
vulnerability in CVE-2026-40501 (CVE-2026-40501). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20296 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-20296)
vulnerability in csrf (CVE-2026-20296). Confidential information can be exposed externally. Exploitable via ``list_deployment_server``.
|
| CVE-2026-58658 |
|
Vulnerability in CVE-2026-58658 (CVE-2026-58658)
vulnerability in CVE-2026-58658 (CVE-2026-58658). Confidential information can be exposed externally.
|
| CVE-2026-12382 |
|
Vulnerability in CVE-2026-12382 (CVE-2026-12382)
vulnerability in CVE-2026-12382 (CVE-2026-12382). Data can be tampered with by attackers.
|
| CVE-2026-20298 |
|
Information Disclosure in splunk (CVE-2026-20298)
vulnerability in splunk (CVE-2026-20298). Confidential information can be exposed externally. Exploitable via ``encr_password``.
|
| CVE-2026-52847 |
|
Cross-Site Scripting (XSS) in mantisbt/mantisbt (CVE-2026-52847)
cross-site scripting in mantisbt/mantisbt (CVE-2026-52847). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-54494 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54494)
SSRF in phanan/koel (CVE-2026-54494). Risk of unauthorized operations or information disclosure. Exploitable via `GET /secret`. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-8055 |
|
Vulnerability in c (CVE-2026-8055)
vulnerability in c (CVE-2026-8055). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62948 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-62948)
cross-site scripting in c (CVE-2026-62948). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `25.12.5` or later.
|
| CVE-2026-61643 |
|
Authorization Flaw in CVE-2026-61643 (CVE-2026-61643)
vulnerability in CVE-2026-61643 (CVE-2026-61643). Data can be tampered with by attackers.
|
| CVE-2026-53515 |
|
Privilege Escalation in @better-auth/sso (CVE-2026-53515)
vulnerability in @better-auth/sso (CVE-2026-53515). Data can be tampered with by attackers. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-50562 |
|
Vulnerability in CVE-2026-50562 (CVE-2026-50562)
vulnerability in CVE-2026-50562 (CVE-2026-50562). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10673 |
|
Out-of-Bounds Read in c (CVE-2026-10673)
vulnerability in c (CVE-2026-10673). Data can be tampered with by attackers.
|
| CVE-2026-54491 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54491)
SSRF in phanan/koel (CVE-2026-54491). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-54451 |
|
Vulnerability in protobuf (CVE-2026-54451)
vulnerability in protobuf (CVE-2026-54451). Risk of unauthorized operations or information disclosure. Exploitable via ``Protobuf.Decoder``. Mitigation: upgrade to `0.16.1` or later.
|
| CVE-2026-54449 |
|
Command Injection in langbot (CVE-2026-54449)
command injection in langbot (CVE-2026-54449). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54447 |
|
Vulnerability in garminconnect (CVE-2026-54447)
vulnerability in garminconnect (CVE-2026-54447). Risk of unauthorized operations or information disclosure. Exploitable via ``garminconnect``. Mitigation: upgrade to `0.3.5` or later.
|
| GHSA-8q6q-m837-fv64 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (GHSA-8q6q-m837-fv64)
SSRF in phanan/koel (GHSA-8q6q-m837-fv64). Risk of unauthorized operations or information disclosure. Exploitable via `GET /rest/createPodcastChannel.view`. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-62378 |
|
Cross-Site Scripting (XSS) in CVE-2026-62378 (CVE-2026-62378)
cross-site scripting in CVE-2026-62378 (CVE-2026-62378). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.10` or later.
|
| CVE-2026-62287 |
|
Vulnerability in CVE-2026-62287 (CVE-2026-62287)
vulnerability in CVE-2026-62287 (CVE-2026-62287). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62248 |
|
Vulnerability in CVE-2026-62248 (CVE-2026-62248)
vulnerability in CVE-2026-62248 (CVE-2026-62248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62180 |
|
Vulnerability in CVE-2026-62180 (CVE-2026-62180)
vulnerability in CVE-2026-62180 (CVE-2026-62180). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62178 |
|
Vulnerability in CVE-2026-62178 (CVE-2026-62178)
vulnerability in CVE-2026-62178 (CVE-2026-62178). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62177 |
|
Vulnerability in CVE-2026-62177 (CVE-2026-62177)
vulnerability in CVE-2026-62177 (CVE-2026-62177). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62174 |
|
Vulnerability in CVE-2026-62174 (CVE-2026-62174)
vulnerability in CVE-2026-62174 (CVE-2026-62174). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62173 |
|
Vulnerability in CVE-2026-62173 (CVE-2026-62173)
vulnerability in CVE-2026-62173 (CVE-2026-62173). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62172 |
|
Vulnerability in CVE-2026-62172 (CVE-2026-62172)
vulnerability in CVE-2026-62172 (CVE-2026-62172). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62169 |
|
Vulnerability in CVE-2026-62169 (CVE-2026-62169)
vulnerability in CVE-2026-62169 (CVE-2026-62169). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62168 |
|
Vulnerability in CVE-2026-62168 (CVE-2026-62168)
vulnerability in CVE-2026-62168 (CVE-2026-62168). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62165 |
|
Vulnerability in CVE-2026-62165 (CVE-2026-62165)
vulnerability in CVE-2026-62165 (CVE-2026-62165). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62164 |
|
Vulnerability in CVE-2026-62164 (CVE-2026-62164)
vulnerability in CVE-2026-62164 (CVE-2026-62164). Risk of unauthorized operations or information disclosure.
|