Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-40141 |
|
Vulnerability in beyondtrust (CVE-2026-40141)
vulnerability in beyondtrust (CVE-2026-40141). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40139 |
|
Authentication Bypass in beyondtrust (CVE-2026-40139)
authentication bypass in beyondtrust (CVE-2026-40139). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49445 |
|
Vulnerability in github.com/cilium/cilium (CVE-2026-49445)
vulnerability in github.com/cilium/cilium (CVE-2026-49445). Confidential information can be exposed externally. Mitigation: upgrade to `1.17.14` or later.
|
| CVE-2026-52889 |
|
Vulnerability in verbb/formie (CVE-2026-52889)
vulnerability in verbb/formie (CVE-2026-52889). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.27` or later.
|
| CVE-2026-5268 |
|
Vulnerability in CVE-2026-5268 (CVE-2026-5268)
vulnerability in CVE-2026-5268 (CVE-2026-5268). Confidential information can be exposed externally.
|
| CVE-2025-53830 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-53830)
SSRF in ssrf (CVE-2025-53830). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53827 |
|
Vulnerability in CVE-2025-53827 (CVE-2025-53827)
vulnerability in CVE-2025-53827 (CVE-2025-53827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56140 |
|
Vulnerability in org.apache.camel:camel-aws2-sns (CVE-2026-56140)
vulnerability in org.apache.camel:camel-aws2-sns (CVE-2026-56140). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-48205 |
|
Vulnerability in org.apache.camel:camel-dns (CVE-2026-48205)
vulnerability in org.apache.camel:camel-dns (CVE-2026-48205). Confidential information can be exposed externally. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-53913 |
|
Authentication Bypass in org.apache.camel:camel-keycloak (CVE-2026-53913)
authentication bypass in org.apache.camel:camel-keycloak (CVE-2026-53913). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-48203 |
|
Vulnerability in org.apache.camel:camel-solr (CVE-2026-48203)
vulnerability in org.apache.camel:camel-solr (CVE-2026-48203). Confidential information can be exposed externally. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46456 |
|
Vulnerability in org.apache.camel:camel-aws2-sqs (CVE-2026-46456)
vulnerability in org.apache.camel:camel-aws2-sqs (CVE-2026-46456). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-48204 |
|
Vulnerability in org.apache.camel:camel-mongodb-gridfs (CVE-2026-48204)
vulnerability in org.apache.camel:camel-mongodb-gridfs (CVE-2026-48204). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-43867 |
|
Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-43867)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-43867). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-24013 |
|
Vulnerability in apache-iotdb (CVE-2026-24013)
vulnerability in apache-iotdb (CVE-2026-24013). Confidential information can be exposed externally. Mitigation: upgrade to `2.0.8` or later.
|
| CVE-2026-24014 |
|
Vulnerability in apache-iotdb (CVE-2026-24014)
vulnerability in apache-iotdb (CVE-2026-24014). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.8` or later.
|
| CVE-2026-40047 |
|
Vulnerability in org.apache.camel:camel-docling (CVE-2026-40047)
vulnerability in org.apache.camel:camel-docling (CVE-2026-40047). Confidential information can be exposed externally. Exploitable via ``docling``. Mitigation: upgrade to `4.18.3` or later.
|
| CVE-2026-46454 |
|
Vulnerability in org.apache.camel:camel-cometd (CVE-2026-46454)
vulnerability in org.apache.camel:camel-cometd (CVE-2026-46454). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46455 |
|
Vulnerability in org.apache.camel:camel-keycloak (CVE-2026-46455)
vulnerability in org.apache.camel:camel-keycloak (CVE-2026-46455). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-6382 |
|
Vulnerability in wordpress (CVE-2026-6382)
vulnerability in wordpress (CVE-2026-6382). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14808 |
|
Vulnerability in CVE-2026-14808 (CVE-2026-14808)
vulnerability in CVE-2026-14808 (CVE-2026-14808). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14807 |
|
Vulnerability in CVE-2026-14807 (CVE-2026-14807)
vulnerability in CVE-2026-14807 (CVE-2026-14807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58289 |
|
Vulnerability in microsoft (CVE-2026-58289)
vulnerability in microsoft (CVE-2026-58289). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27780 |
|
Authorization Flaw in CVE-2026-27780 (CVE-2026-27780)
vulnerability in CVE-2026-27780 (CVE-2026-27780). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25718 |
|
Vulnerability in CVE-2026-25718 (CVE-2026-25718)
vulnerability in CVE-2026-25718 (CVE-2026-25718). Confidential information can be exposed externally.
|
| CVE-2026-26232 |
|
Vulnerability in CVE-2026-26232 (CVE-2026-26232)
vulnerability in CVE-2026-26232 (CVE-2026-26232). Confidential information can be exposed externally.
|
| CVE-2026-26292 |
|
Vulnerability in CVE-2026-26292 (CVE-2026-26292)
vulnerability in CVE-2026-26292 (CVE-2026-26292). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26247 |
|
Vulnerability in CVE-2026-26247 (CVE-2026-26247)
vulnerability in CVE-2026-26247 (CVE-2026-26247). Confidential information can be exposed externally.
|
| CVE-2026-22547 |
|
Vulnerability in CVE-2026-22547 (CVE-2026-22547)
vulnerability in CVE-2026-22547 (CVE-2026-22547). Confidential information can be exposed externally.
|
| CVE-2026-12481 |
|
Unsafe Deserialization in keras (CVE-2026-12481)
vulnerability in keras (CVE-2026-12481). Successful exploitation can lead to full system takeover. Exploitable via ``Lambda``. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-58426 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58426)
vulnerability in code.gitea.io/gitea (CVE-2026-58426). Confidential information can be exposed externally. Exploitable via ``DownloadArtifact``. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-58422 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58422)
vulnerability in code.gitea.io/gitea (CVE-2026-58422). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/admin/users/alice`. Mitigation: upgrade to `1.26.4` or later.
|
| CVE-2026-22874 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-22874)
SSRF in code.gitea.io/gitea (CVE-2026-22874). Confidential information can be exposed externally. Exploitable via ``MatchBuiltinExternal``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-20896 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-20896)
vulnerability in code.gitea.io/gitea (CVE-2026-20896). Successful exploitation can lead to full system takeover. Exploitable via ``app.ini``. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-56015 |
|
Out-of-Bounds Read in CVE-2026-56015 (CVE-2026-56015)
vulnerability in CVE-2026-56015 (CVE-2026-56015). Confidential information can be exposed externally.
|
| CVE-2026-4321 |
|
SQL Injection in sqli (CVE-2026-4321)
SQL injection in sqli (CVE-2026-4321). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47898 |
|
XXE (XML External Entity) in csharp (CVE-2026-47898)
vulnerability in csharp (CVE-2026-47898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14544 |
|
Vulnerability in CVE-2026-14544 (CVE-2026-14544)
vulnerability in CVE-2026-14544 (CVE-2026-14544). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9079 |
|
Vulnerability in haxx (CVE-2026-9079)
vulnerability in haxx (CVE-2026-9079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8927 |
|
Vulnerability in haxx (CVE-2026-8927)
vulnerability in haxx (CVE-2026-8927). Confidential information can be exposed externally. Exploitable via ``proxyA``.
|
| CVE-2026-8926 |
|
Vulnerability in haxx (CVE-2026-8926)
vulnerability in haxx (CVE-2026-8926). Confidential information can be exposed externally.
|
| CVE-2026-8925 |
|
Vulnerability in haxx (CVE-2026-8925)
vulnerability in haxx (CVE-2026-8925). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8924 |
|
Vulnerability in haxx (CVE-2026-8924)
vulnerability in haxx (CVE-2026-8924). Confidential information can be exposed externally.
|
| CVE-2026-11856 |
|
Vulnerability in haxx (CVE-2026-11856)
vulnerability in haxx (CVE-2026-11856). Successful exploitation can lead to full system takeover. Exploitable via ``hostA``.
|
| CVE-2026-11564 |
|
Vulnerability in haxx (CVE-2026-11564)
vulnerability in haxx (CVE-2026-11564). Confidential information can be exposed externally.
|
| CVE-2026-10536 |
|
Use-After-Free in haxx (CVE-2026-10536)
vulnerability in haxx (CVE-2026-10536). Successful exploitation can lead to full system takeover. Exploitable via ``CURLOPT_STREAM_DEPENDS``.
|
| CVE-2026-9725 |
|
Path Traversal in wordpress (CVE-2026-9725)
path traversal in wordpress (CVE-2026-9725). Data can be tampered with by attackers.
|
| CVE-2026-13768 |
|
Vulnerability in CVE-2026-13768 (CVE-2026-13768)
vulnerability in CVE-2026-13768 (CVE-2026-13768). Confidential information can be exposed externally.
|
| CVE-2026-45499 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45499)
SSRF in ssrf (CVE-2026-45499). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57100 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57100)
SSRF in ssrf (CVE-2026-57100). Successful exploitation can lead to full system takeover.
|