Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-57158 |
|
Out-of-Bounds Read in c (CVE-2026-57158)
vulnerability in c (CVE-2026-57158). Confidential information can be exposed externally.
|
| CVE-2026-57157 |
|
Out-of-Bounds Read in c (CVE-2026-57157)
vulnerability in c (CVE-2026-57157). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57156 |
|
Vulnerability in c (CVE-2026-57156)
vulnerability in c (CVE-2026-57156). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55827 |
|
Vulnerability in freerdp (CVE-2026-55827)
vulnerability in freerdp (CVE-2026-55827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55789 |
|
Vulnerability in privilege-escalation (CVE-2026-55789)
vulnerability in privilege-escalation (CVE-2026-55789). Data can be tampered with by attackers.
|
| CVE-2026-55515 |
|
Vulnerability in snipe/snipe-it (CVE-2026-55515)
vulnerability in snipe/snipe-it (CVE-2026-55515). Risk of unauthorized operations or information disclosure. Exploitable via ``reports.view``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55481 |
|
Cross-Site Scripting (XSS) in snipe/snipe-it (CVE-2026-55481)
cross-site scripting in snipe/snipe-it (CVE-2026-55481). Risk of unauthorized operations or information disclosure. Exploitable via ``default.blade.php``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55479 |
|
Authorization Flaw in snipe/snipe-it (CVE-2026-55479)
vulnerability in snipe/snipe-it (CVE-2026-55479). Risk of unauthorized operations or information disclosure. Exploitable via ``checkout``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55475 |
|
Authorization Flaw in snipe/snipe-it (CVE-2026-55475)
vulnerability in snipe/snipe-it (CVE-2026-55475). Data can be tampered with by attackers. Exploitable via ``created_by``. Mitigation: upgrade to `8.6.1` or later.
|
| CVE-2026-55469 |
|
Path Traversal in snipe/snipe-it (CVE-2026-55469)
path traversal in snipe/snipe-it (CVE-2026-55469). Data can be tampered with by attackers. Exploitable via ``import``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55466 |
|
Cross-Site Scripting (XSS) in snipe/snipe-it (CVE-2026-55466)
cross-site scripting in snipe/snipe-it (CVE-2026-55466). Confidential information can be exposed externally. Exploitable via ``mimes``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55462 |
|
Authorization Flaw in snipe/snipe-it (CVE-2026-55462)
vulnerability in snipe/snipe-it (CVE-2026-55462). Risk of unauthorized operations or information disclosure. Exploitable via `GET /users/{user}`. Mitigation: upgrade to `374f426f0c` or later.
|
| CVE-2026-55461 |
|
Open Redirect in snipe/snipe-it (CVE-2026-55461)
vulnerability in snipe/snipe-it (CVE-2026-55461). Risk of unauthorized operations or information disclosure. Exploitable via ``Referer``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55452 |
|
Vulnerability in snipe/snipe-it (CVE-2026-55452)
vulnerability in snipe/snipe-it (CVE-2026-55452). Confidential information can be exposed externally. Exploitable via `User-Agent header`. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55377 |
|
Authentication Bypass in CVE-2026-55377 (CVE-2026-55377)
authentication bypass in CVE-2026-55377 (CVE-2026-55377). Confidential information can be exposed externally.
|
| CVE-2026-55370 |
|
Vulnerability in CVE-2026-55370 (CVE-2026-55370)
vulnerability in CVE-2026-55370 (CVE-2026-55370). Confidential information can be exposed externally.
|
| CVE-2026-54714 |
|
Cross-Site Scripting (XSS) in CVE-2026-54714 (CVE-2026-54714)
cross-site scripting in CVE-2026-54714 (CVE-2026-54714). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/saml/`.
|
| CVE-2026-15295 |
|
Vulnerability in wordpress (CVE-2026-15295)
vulnerability in wordpress (CVE-2026-15295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11321 |
|
SQL Injection in sqli (CVE-2026-11321)
SQL injection in sqli (CVE-2026-11321). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73498 |
|
Path Traversal in mcp-atlassian (CVE-2026-73498)
path traversal in mcp-atlassian (CVE-2026-73498). Confidential information can be exposed externally. Exploitable via ``confluence_upload_attachment``. Mitigation: upgrade to `0.22.0` or later.
|
| GHSA-wm45-qh3g-v83f |
|
Path Traversal in mcp-atlassian (GHSA-wm45-qh3g-v83f)
path traversal in mcp-atlassian (GHSA-wm45-qh3g-v83f). Risk of unauthorized operations or information disclosure. Exploitable via ``file_path``. Mitigation: upgrade to `0.22.0` or later.
|
| GHSA-xrmc-c5cg-rv7x |
|
Vulnerability in safeinstall-cli (GHSA-xrmc-c5cg-rv7x)
vulnerability in safeinstall-cli (GHSA-xrmc-c5cg-rv7x). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.10.2` or later.
|
| GHSA-qv4m-m73m-8hj7 |
|
Path Traversal in notrinos/notrinos-erp (GHSA-qv4m-m73m-8hj7)
path traversal in notrinos/notrinos-erp (GHSA-qv4m-m73m-8hj7). Successful exploitation can lead to full system takeover. Exploitable via `POST /hrm/manage/employees.php`.
|
| CVE-2026-54071 |
|
Unsafe Deserialization in BabelDOC (CVE-2026-54071)
vulnerability in BabelDOC (CVE-2026-54071). Successful exploitation can lead to full system takeover. Exploitable via ``psparser._parse_literal_hex``. Mitigation: upgrade to `0.6.3` or later.
|
| GHSA-99j7-fhr2-xfj4 |
|
Vulnerability in exploration (GHSA-99j7-fhr2-xfj4)
vulnerability in exploration (GHSA-99j7-fhr2-xfj4). Risk of unauthorized operations or information disclosure. Exploitable via ``exploration``.
|
| MINI-2cjq-hqcm-83pw |
|
MINI-2cjq-hqcm-83pw |
| MINI-cf25-p8fm-975x |
|
MINI-cf25-p8fm-975x |
| MINI-v95h-r8m8-4r94 |
|
MINI-v95h-r8m8-4r94 |
| MINI-v572-9pj3-p5cj |
|
MINI-v572-9pj3-p5cj |
| MINI-j2v7-mjfv-238c |
|
MINI-j2v7-mjfv-238c |
| MINI-wvfg-vpj7-w322 |
|
MINI-wvfg-vpj7-w322 |
| MINI-grqg-j3mc-f455 |
|
MINI-grqg-j3mc-f455 |
| MINI-9558-8wm8-rcxh |
|
MINI-9558-8wm8-rcxh |
| MINI-gwrc-9gfc-h7h2 |
|
MINI-gwrc-9gfc-h7h2 |
| MINI-mmrx-5m9c-xxh3 |
|
MINI-mmrx-5m9c-xxh3 |
| MINI-7545-qvg7-2q3c |
|
MINI-7545-qvg7-2q3c |
| MINI-8rfp-p3c4-f86w |
|
MINI-8rfp-p3c4-f86w |
| MINI-4qwp-756h-4cr9 |
|
MINI-4qwp-756h-4cr9 |
| MINI-6x5v-95mg-rxvw |
|
MINI-6x5v-95mg-rxvw |
| MINI-j729-vgq8-jr9p |
|
MINI-j729-vgq8-jr9p |
| MINI-6jmc-mr4r-4chg |
|
MINI-6jmc-mr4r-4chg |
| MINI-vmq5-5jm5-8xgw |
|
MINI-vmq5-5jm5-8xgw |
| MINI-76gp-x8fm-67qc |
|
MINI-76gp-x8fm-67qc |
| MINI-w96r-8hvv-wxfw |
|
MINI-w96r-8hvv-wxfw |
| MINI-mhfw-878v-w2fm |
|
MINI-mhfw-878v-w2fm |
| MINI-6wcf-cx68-475p |
|
MINI-6wcf-cx68-475p |
| MINI-86p6-7jw6-x2mj |
|
MINI-86p6-7jw6-x2mj |
| MINI-9h9c-6v52-qmqf |
|
MINI-9h9c-6v52-qmqf |
| MINI-4wh7-495c-3947 |
|
MINI-4wh7-495c-3947 |
| MINI-gppg-rmrw-rh76 |
|
MINI-gppg-rmrw-rh76 |