Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-61841 |
|
Vulnerability in CVE-2026-61841 (CVE-2026-61841)
vulnerability in CVE-2026-61841 (CVE-2026-61841). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61839 |
|
Vulnerability in CVE-2026-61839 (CVE-2026-61839)
vulnerability in CVE-2026-61839 (CVE-2026-61839). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61829 |
|
Vulnerability in CVE-2026-61829 (CVE-2026-61829)
vulnerability in CVE-2026-61829 (CVE-2026-61829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61710 |
|
Vulnerability in CVE-2026-61710 (CVE-2026-61710)
vulnerability in CVE-2026-61710 (CVE-2026-61710). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61606 |
|
Vulnerability in CVE-2026-61606 (CVE-2026-61606)
vulnerability in CVE-2026-61606 (CVE-2026-61606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52843 |
|
Vulnerability in CVE-2026-52843 (CVE-2026-52843)
vulnerability in CVE-2026-52843 (CVE-2026-52843). Confidential information can be exposed externally.
|
| CVE-2026-52842 |
|
Vulnerability in CVE-2026-52842 (CVE-2026-52842)
vulnerability in CVE-2026-52842 (CVE-2026-52842). Confidential information can be exposed externally.
|
| CVE-2026-48799 |
|
Vulnerability in CVE-2026-48799 (CVE-2026-48799)
vulnerability in CVE-2026-48799 (CVE-2026-48799). Data can be tampered with by attackers.
|
| CVE-2026-20187 |
|
Vulnerability in cisco (CVE-2026-20187)
vulnerability in cisco (CVE-2026-20187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20158 |
|
Vulnerability in cisco (CVE-2026-20158)
vulnerability in cisco (CVE-2026-20158). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20157 |
|
Vulnerability in cisco (CVE-2026-20157)
vulnerability in cisco (CVE-2026-20157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20156 |
|
Buffer Overflow in cisco (CVE-2026-20156)
vulnerability in cisco (CVE-2026-20156). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20153 |
|
Vulnerability in cisco (CVE-2026-20153)
vulnerability in cisco (CVE-2026-20153). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1563 |
|
Cross-Site Scripting (XSS) in pega (CVE-2026-1563)
cross-site scripting in pega (CVE-2026-1563). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1562 |
|
Cross-Site Scripting (XSS) in pega (CVE-2026-1562)
cross-site scripting in pega (CVE-2026-1562). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54493 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54493)
SSRF in phanan/koel (CVE-2026-54493). Confidential information can be exposed externally. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-54492 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54492)
SSRF in phanan/koel (CVE-2026-54492). Risk of unauthorized operations or information disclosure. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-49280 |
|
Vulnerability in mantisbt/mantisbt (CVE-2026-49280)
vulnerability in mantisbt/mantisbt (CVE-2026-49280). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-49273 |
|
Vulnerability in mantisbt/mantisbt (CVE-2026-49273)
vulnerability in mantisbt/mantisbt (CVE-2026-49273). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-47156 |
|
Authentication Bypass in mantisbt/mantisbt (CVE-2026-47156)
authentication bypass in mantisbt/mantisbt (CVE-2026-47156). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-20146 |
|
Path Traversal in Cisco path-traversal (CVE-2026-20146)
path traversal in Cisco path-traversal (CVE-2026-20146). Confidential information can be exposed externally.
|
| CVE-2026-20150 |
|
Vulnerability in Cisco roomos (CVE-2026-20150)
vulnerability in Cisco roomos (CVE-2026-20150). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47142 |
|
SQL Injection in mantisbt/mantisbt (CVE-2026-47142)
SQL injection in mantisbt/mantisbt (CVE-2026-47142). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/rest/config`. Mitigation: upgrade to `2.28.4` or later.
|
| CVE-2026-9007 |
|
Cross-Site Scripting (XSS) in CVE-2026-9007 (CVE-2026-9007)
cross-site scripting in CVE-2026-9007 (CVE-2026-9007). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62843 |
|
Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-62843)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-62843). Data can be tampered with by attackers. Exploitable via `POST /api/resources/ziptest/..`. Mitigation: upgrade to `2.63.17` or later.
|
| CVE-2026-62685 |
|
Vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-62685)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-62685). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/raw/secretA.txt`. Mitigation: upgrade to `2.63.17` or later.
|
| CVE-2026-62683 |
|
Authorization Flaw in CVE-2026-62683 (CVE-2026-62683)
vulnerability in CVE-2026-62683 (CVE-2026-62683). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61828 |
|
Vulnerability in CVE-2026-61828 (CVE-2026-61828)
vulnerability in CVE-2026-61828 (CVE-2026-61828). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61605 |
|
Vulnerability in CVE-2026-61605 (CVE-2026-61605)
vulnerability in CVE-2026-61605 (CVE-2026-61605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61371 |
|
Vulnerability in CVE-2026-61371 (CVE-2026-61371)
vulnerability in CVE-2026-61371 (CVE-2026-61371). Confidential information can be exposed externally.
|
| CVE-2026-60005 |
|
Vulnerability in nginx (CVE-2026-60005)
vulnerability in nginx (CVE-2026-60005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55242 |
|
Authorization Flaw in CVE-2026-55242 (CVE-2026-55242)
vulnerability in CVE-2026-55242 (CVE-2026-55242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50148 |
|
Vulnerability in metabase (CVE-2026-50148)
vulnerability in metabase (CVE-2026-50148). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50147 |
|
Vulnerability in metabase (CVE-2026-50147)
vulnerability in metabase (CVE-2026-50147). Confidential information can be exposed externally.
|
| CVE-2026-47164 |
|
Vulnerability in CVE-2026-47164 (CVE-2026-47164)
vulnerability in CVE-2026-47164 (CVE-2026-47164). Confidential information can be exposed externally.
|
| CVE-2026-47160 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-47160)
SSRF in ssrf (CVE-2026-47160). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47159 |
|
Authentication Bypass in CVE-2026-47159 (CVE-2026-47159)
authentication bypass in CVE-2026-47159 (CVE-2026-47159). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47158 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-47158 (CVE-2026-47158)
vulnerability in CVE-2026-47158 (CVE-2026-47158). Data can be tampered with by attackers.
|
| CVE-2026-46709 |
|
Command Injection in tabby (CVE-2026-46709)
command injection in tabby (CVE-2026-46709). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45806 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-45806 (CVE-2026-45806)
SSRF in CVE-2026-45806 (CVE-2026-45806). Confidential information can be exposed externally.
|
| CVE-2026-45150 |
|
Vulnerability in CVE-2026-45150 (CVE-2026-45150)
vulnerability in CVE-2026-45150 (CVE-2026-45150). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44986 |
|
Authentication Bypass in CVE-2026-44986 (CVE-2026-44986)
authentication bypass in CVE-2026-44986 (CVE-2026-44986). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41580 |
|
Cross-Site Scripting (XSS) in stirling (CVE-2026-41580)
cross-site scripting in stirling (CVE-2026-41580). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56434 |
|
Use-After-Free in nginx (CVE-2026-56434)
vulnerability in nginx (CVE-2026-56434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55723 |
|
Vulnerability in nginx (CVE-2026-55723)
vulnerability in nginx (CVE-2026-55723). Confidential information can be exposed externally.
|
| CVE-2026-42533 |
|
Vulnerability in nginx (CVE-2026-42533)
vulnerability in nginx (CVE-2026-42533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59762 |
|
Vulnerability in dos (CVE-2026-59762)
vulnerability in dos (CVE-2026-59762). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52865 |
|
Vulnerability in nginx (CVE-2026-52865)
vulnerability in nginx (CVE-2026-52865). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58553 |
|
Vulnerability in CVE-2026-58553 (CVE-2026-58553)
vulnerability in CVE-2026-58553 (CVE-2026-58553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58558 |
|
Vulnerability in CVE-2026-58558 (CVE-2026-58558)
vulnerability in CVE-2026-58558 (CVE-2026-58558). Successful exploitation can lead to full system takeover.
|