Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9816 |
|
Authorization Flaw in mattermost (CVE-2026-9816)
vulnerability in mattermost (CVE-2026-9816). Data can be tampered with by attackers. Exploitable via `POST /api/v2/boards/{boardID}/members`.
|
| CVE-2026-67918 |
|
Path Traversal in path-traversal (CVE-2026-67918)
path traversal in path-traversal (CVE-2026-67918). Confidential information can be exposed externally.
|
| CVE-2026-65346 |
|
Vulnerability in apple (CVE-2026-65346)
vulnerability in apple (CVE-2026-65346). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65343 |
|
Use-After-Free in apple (CVE-2026-65343)
vulnerability in apple (CVE-2026-65343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45790 |
|
Privilege Escalation in CVE-2026-45790 (CVE-2026-45790)
vulnerability in CVE-2026-45790 (CVE-2026-45790). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43794 |
|
Buffer Overflow in c (CVE-2026-43794)
vulnerability in c (CVE-2026-43794). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69148 |
|
Vulnerability in mlflow (CVE-2026-69148)
vulnerability in mlflow (CVE-2026-69148). Confidential information can be exposed externally. Exploitable via `GET /model-versions/get-artifact`. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-56677 |
|
Vulnerability in 9router (CVE-2026-56677)
vulnerability in 9router (CVE-2026-56677). Data can be tampered with by attackers. Exploitable via `POST /api/auth/oidc/test`.
|
| CVE-2026-75482 |
|
Path Traversal in path-traversal (CVE-2026-75482)
path traversal in path-traversal (CVE-2026-75482). Confidential information can be exposed externally.
|
| CVE-2026-75481 |
|
Privilege Escalation in CVE-2026-75481 (CVE-2026-75481)
vulnerability in CVE-2026-75481 (CVE-2026-75481). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75479 |
|
Vulnerability in CVE-2026-75479 (CVE-2026-75479)
vulnerability in CVE-2026-75479 (CVE-2026-75479). Confidential information can be exposed externally.
|
| CVE-2026-75111 |
|
Path Traversal in CVE-2026-75111 (CVE-2026-75111)
path traversal in CVE-2026-75111 (CVE-2026-75111). Confidential information can be exposed externally.
|
| CVE-2026-75109 |
|
Vulnerability in CVE-2026-75109 (CVE-2026-75109)
vulnerability in CVE-2026-75109 (CVE-2026-75109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75105 |
|
Vulnerability in CVE-2026-75105 (CVE-2026-75105)
vulnerability in CVE-2026-75105 (CVE-2026-75105). Confidential information can be exposed externally.
|
| CVE-2026-75103 |
|
Vulnerability in CVE-2026-75103 (CVE-2026-75103)
vulnerability in CVE-2026-75103 (CVE-2026-75103). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71518 |
|
Authorization Flaw in CVE-2026-71518 (CVE-2026-71518)
vulnerability in CVE-2026-71518 (CVE-2026-71518). Confidential information can be exposed externally.
|
| CVE-2026-65832 |
|
Out-of-Bounds Read in cpp (CVE-2026-65832)
vulnerability in cpp (CVE-2026-65832). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65822 |
|
SQL Injection in CVE-2026-65822 (CVE-2026-65822)
SQL injection in CVE-2026-65822 (CVE-2026-65822). Confidential information can be exposed externally.
|
| CVE-2026-65640 |
|
Unrestricted File Upload in wordpress (CVE-2026-65640)
vulnerability in wordpress (CVE-2026-65640). Successful exploitation can lead to full system takeover. Exploitable via ``upload_files``.
|
| CVE-2026-64657 |
|
SQL Injection in CVE-2026-64657 (CVE-2026-64657)
SQL injection in CVE-2026-64657 (CVE-2026-64657). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63409 |
|
Out-of-Bounds Read in cpp (CVE-2026-63409)
vulnerability in cpp (CVE-2026-63409). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54356 |
|
Vulnerability in @budibase/server (CVE-2026-54356)
vulnerability in @budibase/server (CVE-2026-54356). Data can be tampered with by attackers. Exploitable via `POST /api/attachments/`.
|
| CVE-2026-34789 |
|
Code Injection in cpp (CVE-2026-34789)
code injection in cpp (CVE-2026-34789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34399 |
|
Vulnerability in CVE-2026-34399 (CVE-2026-34399)
vulnerability in CVE-2026-34399 (CVE-2026-34399). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34398 |
|
Vulnerability in CVE-2026-34398 (CVE-2026-34398)
vulnerability in CVE-2026-34398 (CVE-2026-34398). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19589 |
|
Path Traversal in CVE-2026-19589 (CVE-2026-19589)
path traversal in CVE-2026-19589 (CVE-2026-19589). Data can be tampered with by attackers.
|
| CVE-2026-75014 |
|
Vulnerability in sqli (CVE-2026-75014)
vulnerability in sqli (CVE-2026-75014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74234 |
|
Vulnerability in CVE-2026-74234 (CVE-2026-74234)
vulnerability in CVE-2026-74234 (CVE-2026-74234). Confidential information can be exposed externally.
|
| CVE-2026-70495 |
|
Privilege Escalation in CVE-2026-70495 (CVE-2026-70495)
vulnerability in CVE-2026-70495 (CVE-2026-70495). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68005 |
|
Vulnerability in dos (CVE-2026-68005)
vulnerability in dos (CVE-2026-68005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57485 |
|
Information Disclosure in CVE-2026-57485 (CVE-2026-57485)
vulnerability in CVE-2026-57485 (CVE-2026-57485). Confidential information can be exposed externally.
|
| CVE-2026-57233 |
|
Path Traversal in CVE-2026-57233 (CVE-2026-57233)
path traversal in CVE-2026-57233 (CVE-2026-57233). Data can be tampered with by attackers.
|
| CVE-2026-54758 |
|
Vulnerability in cpp (CVE-2026-54758)
vulnerability in cpp (CVE-2026-54758). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19650 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-19650 (CVE-2026-19650)
vulnerability in CVE-2026-19650 (CVE-2026-19650). Data can be tampered with by attackers.
|
| CVE-2026-74238 |
|
Out-of-Bounds Read in CVE-2026-74238 (CVE-2026-74238)
vulnerability in CVE-2026-74238 (CVE-2026-74238). Data can be tampered with by attackers.
|
| CVE-2026-50776 |
|
Path Traversal in path-traversal (CVE-2026-50776)
path traversal in path-traversal (CVE-2026-50776). Confidential information can be exposed externally.
|
| CVE-2026-50773 |
|
Vulnerability in CVE-2026-50773 (CVE-2026-50773)
vulnerability in CVE-2026-50773 (CVE-2026-50773). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45698 |
|
Vulnerability in CVE-2026-45698 (CVE-2026-45698)
vulnerability in CVE-2026-45698 (CVE-2026-45698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73522 |
|
Vulnerability in dos (CVE-2026-73522)
vulnerability in dos (CVE-2026-73522). Data can be tampered with by attackers.
|
| CVE-2026-71979 |
|
Vulnerability in cpp (CVE-2026-71979)
vulnerability in cpp (CVE-2026-71979). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71980 |
|
Out-of-Bounds Read in c (CVE-2026-71980)
vulnerability in c (CVE-2026-71980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73523 |
|
Vulnerability in c (CVE-2026-73523)
vulnerability in c (CVE-2026-73523). Confidential information can be exposed externally.
|
| CVE-2026-75056 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
|
| CVE-2026-50768 |
|
Unrestricted File Upload in CVE-2026-50768 (CVE-2026-50768)
vulnerability in CVE-2026-50768 (CVE-2026-50768). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75060 |
|
Vulnerability in CVE-2026-75060 (CVE-2026-75060)
vulnerability in CVE-2026-75060 (CVE-2026-75060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75050 |
|
Vulnerability in dos (CVE-2026-75050)
vulnerability in dos (CVE-2026-75050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75051 |
|
Vulnerability in CVE-2026-75051 (CVE-2026-75051)
vulnerability in CVE-2026-75051 (CVE-2026-75051). Confidential information can be exposed externally.
|
| CVE-2026-75048 |
|
Cross-Site Scripting (XSS) in CVE-2026-75048 (CVE-2026-75048)
cross-site scripting in CVE-2026-75048 (CVE-2026-75048). Confidential information can be exposed externally.
|
| CVE-2026-75044 |
|
Vulnerability in CVE-2026-75044 (CVE-2026-75044)
vulnerability in CVE-2026-75044 (CVE-2026-75044). Data can be tampered with by attackers.
|
| CVE-2026-33437 |
|
Cross-Site Scripting (XSS) in CVE-2026-33437 (CVE-2026-33437)
cross-site scripting in CVE-2026-33437 (CVE-2026-33437). Confidential information can be exposed externally.
|