Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
GHSA-vx2m-jpxr-xv7w Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (GHSA-vx2m-jpxr-xv7w)
vulnerability in github.com/cloudreve/Cloudreve/v4 (GHSA-vx2m-jpxr-xv7w). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4/file`.
CVE-2026-7455 Out-of-Bounds Write in autodesk (CVE-2026-7455)
out-of-bounds write in autodesk (CVE-2026-7455). Successful exploitation can lead to full system takeover.
CVE-2026-19568 Vulnerability in autodesk (CVE-2026-19568)
vulnerability in autodesk (CVE-2026-19568). Successful exploitation can lead to full system takeover.
CVE-2026-75464 OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
CVE-2026-5006 Vulnerability in CVE-2026-5006 (CVE-2026-5006)
vulnerability in CVE-2026-5006 (CVE-2026-5006). Confidential information can be exposed externally.
CVE-2026-52492 Vulnerability in CVE-2026-52492 (CVE-2026-52492)
vulnerability in CVE-2026-52492 (CVE-2026-52492). Successful exploitation can lead to full system takeover.
CVE-2026-16783 Out-of-Bounds Write in autodesk (CVE-2026-16783)
out-of-bounds write in autodesk (CVE-2026-16783). Successful exploitation can lead to full system takeover.
CVE-2026-52490 Code Injection in c (CVE-2026-52490)
code injection in c (CVE-2026-52490). Successful exploitation can lead to full system takeover.
CVE-2022-30983 Cross-Site Scripting (XSS) in CVE-2022-30983 (CVE-2022-30983)
cross-site scripting in CVE-2022-30983 (CVE-2022-30983). Risk of unauthorized operations or information disclosure.
CVE-2026-16781 Vulnerability in autodesk (CVE-2026-16781)
vulnerability in autodesk (CVE-2026-16781). Risk of unauthorized operations or information disclosure.
CVE-2026-16782 Out-of-Bounds Read in autodesk (CVE-2026-16782)
vulnerability in autodesk (CVE-2026-16782). Risk of unauthorized operations or information disclosure.
CVE-2026-77635 SQL Injection in sqli (CVE-2026-77635)
SQL injection in sqli (CVE-2026-77635). Risk of unauthorized operations or information disclosure.
CVE-2026-77634 Vulnerability in CVE-2026-77634 (CVE-2026-77634)
vulnerability in CVE-2026-77634 (CVE-2026-77634). Risk of unauthorized operations or information disclosure.
CVE-2026-77567 Authentication Bypass in laravel (CVE-2026-77567)
authentication bypass in laravel (CVE-2026-77567). Confidential information can be exposed externally.
CVE-2026-75554 Vulnerability in CVE-2026-75554 (CVE-2026-75554)
vulnerability in CVE-2026-75554 (CVE-2026-75554). Risk of unauthorized operations or information disclosure.
CVE-2026-75542 Authorization Flaw in CVE-2026-75542 (CVE-2026-75542)
vulnerability in CVE-2026-75542 (CVE-2026-75542). Risk of unauthorized operations or information disclosure.
CVE-2026-56136 Out-of-Bounds Read in c (CVE-2026-56136)
vulnerability in c (CVE-2026-56136). Confidential information can be exposed externally.
CVE-2026-56135 Vulnerability in c (CVE-2026-56135)
vulnerability in c (CVE-2026-56135). Successful exploitation can lead to full system takeover.
GHSA-w67g-5rqw-f597 Vulnerability in github.com/gorilla/websocket (GHSA-w67g-5rqw-f597)
vulnerability in github.com/gorilla/websocket (GHSA-w67g-5rqw-f597). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.3` or later.
GHSA-4ph6-mjv7-3fq6 Vulnerability in github.com/tinfoil-factory/netfoil (GHSA-4ph6-mjv7-3fq6)
vulnerability in github.com/tinfoil-factory/netfoil (GHSA-4ph6-mjv7-3fq6). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.5.0` or later.
CVE-2026-78555 Information Disclosure in CVE-2026-78555 (CVE-2026-78555)
vulnerability in CVE-2026-78555 (CVE-2026-78555). Risk of unauthorized operations or information disclosure.
CVE-2026-78553 Vulnerability in flask (CVE-2026-78553)
vulnerability in flask (CVE-2026-78553). Risk of unauthorized operations or information disclosure.
CVE-2026-78551 Vulnerability in dos (CVE-2026-78551)
vulnerability in dos (CVE-2026-78551). Risk of unauthorized operations or information disclosure.
CVE-2026-78430 Command Injection in CVE-2026-78430 (CVE-2026-78430)
command injection in CVE-2026-78430 (CVE-2026-78430). Risk of unauthorized operations or information disclosure.
CVE-2026-77923 Authorization Flaw in CVE-2026-77923 (CVE-2026-77923)
vulnerability in CVE-2026-77923 (CVE-2026-77923). Risk of unauthorized operations or information disclosure.
CVE-2026-77310 SSRF (Server-Side Request Forgery) in csharp (CVE-2026-77310)
SSRF in csharp (CVE-2026-77310). Risk of unauthorized operations or information disclosure.
CVE-2026-76816 Vulnerability in CVE-2026-76816 (CVE-2026-76816)
vulnerability in CVE-2026-76816 (CVE-2026-76816). Risk of unauthorized operations or information disclosure.
CVE-2026-76098 Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens fr...
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee...
CVE-2026-75509 Vulnerability in CVE-2026-75509 (CVE-2026-75509)
vulnerability in CVE-2026-75509 (CVE-2026-75509). Data can be tampered with by attackers.
CVE-2026-75369 Out-of-Bounds Read in dos (CVE-2026-75369)
vulnerability in dos (CVE-2026-75369). Risk of unauthorized operations or information disclosure.
CVE-2026-75368 Vulnerability in dos (CVE-2026-75368)
vulnerability in dos (CVE-2026-75368). Risk of unauthorized operations or information disclosure.
CVE-2026-72714 Vulnerability in CVE-2026-72714 (CVE-2026-72714)
vulnerability in CVE-2026-72714 (CVE-2026-72714). Data can be tampered with by attackers.
CVE-2026-72711 Vulnerability in CVE-2026-72711 (CVE-2026-72711)
vulnerability in CVE-2026-72711 (CVE-2026-72711). Data can be tampered with by attackers. Mitigation: upgrade to `4.32.2` or later.
CVE-2026-72705 Vulnerability in CVE-2026-72705 (CVE-2026-72705)
vulnerability in CVE-2026-72705 (CVE-2026-72705). Data can be tampered with by attackers.
CVE-2026-72704 Vulnerability in CVE-2026-72704 (CVE-2026-72704)
vulnerability in CVE-2026-72704 (CVE-2026-72704). Data can be tampered with by attackers.
CVE-2026-72703 Vulnerability in CVE-2026-72703 (CVE-2026-72703)
vulnerability in CVE-2026-72703 (CVE-2026-72703). Data can be tampered with by attackers.
CVE-2026-71511 Vulnerability in CVE-2026-71511 (CVE-2026-71511)
vulnerability in CVE-2026-71511 (CVE-2026-71511). Confidential information can be exposed externally.
CVE-2026-71510 Authorization Flaw in sqli (CVE-2026-71510)
vulnerability in sqli (CVE-2026-71510). Confidential information can be exposed externally.
CVE-2026-63693 Vulnerability in CVE-2026-63693 (CVE-2026-63693)
vulnerability in CVE-2026-63693 (CVE-2026-63693). Data can be tampered with by attackers.
CVE-2026-61419 Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
CVE-2020-37268 Vulnerability in CVE-2020-37268 (CVE-2020-37268)
vulnerability in CVE-2020-37268 (CVE-2020-37268). Data can be tampered with by attackers.
GHSA-3gjw-f78c-vvpw Out-of-Bounds Read in tokio-postgres (GHSA-3gjw-f78c-vvpw)
vulnerability in tokio-postgres (GHSA-3gjw-f78c-vvpw). Risk of unauthorized operations or information disclosure. Exploitable via ``try_get``. Mitigation: upgrade to `0.7.18` or later.
GHSA-rgqc-3x5p-6gwg Vulnerability in postgres-protocol (GHSA-rgqc-3x5p-6gwg)
vulnerability in postgres-protocol (GHSA-rgqc-3x5p-6gwg). Risk of unauthorized operations or information disclosure. Exploitable via ``hstore``. Mitigation: upgrade to `0.6.12` or later.
GHSA-5x78-73v4-xg6w Vulnerability in postgres-protocol (GHSA-5x78-73v4-xg6w)
vulnerability in postgres-protocol (GHSA-5x78-73v4-xg6w). Risk of unauthorized operations or information disclosure. Exploitable via ``tokio``. Mitigation: upgrade to `0.6.12` or later.
CVE-2026-54050 Vulnerability in org.sakaiproject.profile2:profile2-api (CVE-2026-54050)
vulnerability in org.sakaiproject.profile2:profile2-api (CVE-2026-54050). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/users/{userId}/profile/image`.
CVE-2026-54049 Cross-Site Scripting (XSS) in org.sakaiproject.conversations:sakai-conversations-impl (CVE-2026-54049)
cross-site scripting in org.sakaiproject.conversations:sakai-conversations-impl (CVE-2026-54049). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/sites/{siteId}/topics`.
CVE-2026-78541 OS Command Injection in CVE-2026-78541 (CVE-2026-78541)
OS command injection in CVE-2026-78541 (CVE-2026-78541). Risk of unauthorized operations or information disclosure.
CVE-2026-78417 Vulnerability in CVE-2026-78417 (CVE-2026-78417)
vulnerability in CVE-2026-78417 (CVE-2026-78417). Risk of unauthorized operations or information disclosure.
CVE-2026-75371 Vulnerability in dos (CVE-2026-75371)
vulnerability in dos (CVE-2026-75371). Risk of unauthorized operations or information disclosure.
CVE-2026-75370 Out-of-Bounds Read in dos (CVE-2026-75370)
vulnerability in dos (CVE-2026-75370). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →