Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-59803 Vulnerability in CVE-2026-59803 (CVE-2026-59803)
vulnerability in CVE-2026-59803 (CVE-2026-59803). Risk of unauthorized operations or information disclosure.
CVE-2026-8649 Vulnerability in progress (CVE-2026-8649)
vulnerability in progress (CVE-2026-8649). Successful exploitation can lead to full system takeover.
CVE-2026-59804 Vulnerability in CVE-2026-59804 (CVE-2026-59804)
vulnerability in CVE-2026-59804 (CVE-2026-59804). Confidential information can be exposed externally.
CVE-2026-59807 Vulnerability in CVE-2026-59807 (CVE-2026-59807)
vulnerability in CVE-2026-59807 (CVE-2026-59807). Confidential information can be exposed externally.
CVE-2026-59805 Vulnerability in CVE-2026-59805 (CVE-2026-59805)
vulnerability in CVE-2026-59805 (CVE-2026-59805). Data can be tampered with by attackers.
CVE-2026-36028 Vulnerability in CVE-2026-36028 (CVE-2026-36028)
vulnerability in CVE-2026-36028 (CVE-2026-36028). Successful exploitation can lead to full system takeover.
CVE-2026-36027 Vulnerability in CVE-2026-36027 (CVE-2026-36027)
vulnerability in CVE-2026-36027 (CVE-2026-36027). Successful exploitation can lead to full system takeover.
CVE-2026-14891 Vulnerability in CVE-2026-14891 (CVE-2026-14891)
vulnerability in CVE-2026-14891 (CVE-2026-14891). Confidential information can be exposed externally.
CVE-2026-14373 Vulnerability in c (CVE-2026-14373)
vulnerability in c (CVE-2026-14373). Confidential information can be exposed externally.
CVE-2026-15154 Vulnerability in dos (CVE-2026-15154)
vulnerability in dos (CVE-2026-15154). Risk of unauthorized operations or information disclosure.
CVE-2026-14361 Vulnerability in CVE-2026-14361 (CVE-2026-14361)
vulnerability in CVE-2026-14361 (CVE-2026-14361). Confidential information can be exposed externally.
MAL-2026-7023 Vulnerability in dbzy-tools (MAL-2026-7023)
vulnerability in dbzy-tools (MAL-2026-7023). Risk of unauthorized operations or information disclosure. Exploitable via ``payload``.
UBUNTU-CVE-2026-10037 Vulnerability in openjdk-9 (UBUNTU-CVE-2026-10037)
vulnerability in openjdk-9 (UBUNTU-CVE-2026-10037). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.70+nmu1ubuntu1.22.04.1` or later.
CVE-2026-59818 Vulnerability in etcd (CVE-2026-59818)
vulnerability in etcd (CVE-2026-59818). Confidential information can be exposed externally.
CVE-2026-58494 Vulnerability in CVE-2026-58494 (CVE-2026-58494)
vulnerability in CVE-2026-58494 (CVE-2026-58494). Data can be tampered with by attackers.
CVE-2026-58211 Authorization Flaw in linuxfoundation (CVE-2026-58211)
vulnerability in linuxfoundation (CVE-2026-58211). Risk of unauthorized operations or information disclosure.
CVE-2026-58208 Vulnerability in linuxfoundation (CVE-2026-58208)
vulnerability in linuxfoundation (CVE-2026-58208). Risk of unauthorized operations or information disclosure.
CVE-2026-58207 Vulnerability in linuxfoundation (CVE-2026-58207)
vulnerability in linuxfoundation (CVE-2026-58207). Risk of unauthorized operations or information disclosure.
CVE-2026-58192 Path Traversal in appium (CVE-2026-58192)
path traversal in appium (CVE-2026-58192). Data can be tampered with by attackers. Exploitable via `POST /storage/delete`.
CVE-2026-58191 Cross-Site Scripting (XSS) in appium (CVE-2026-58191)
cross-site scripting in appium (CVE-2026-58191). Data can be tampered with by attackers.
CVE-2026-57481 Information Disclosure in CVE-2026-57481 (CVE-2026-57481)
vulnerability in CVE-2026-57481 (CVE-2026-57481). Risk of unauthorized operations or information disclosure.
CVE-2026-57480 Vulnerability in CVE-2026-57480 (CVE-2026-57480)
vulnerability in CVE-2026-57480 (CVE-2026-57480). Risk of unauthorized operations or information disclosure.
CVE-2026-56669 Vulnerability in CVE-2026-56669 (CVE-2026-56669)
vulnerability in CVE-2026-56669 (CVE-2026-56669). Risk of unauthorized operations or information disclosure.
CVE-2026-55596 Cross-Site Scripting (XSS) in @platejs/media (CVE-2026-55596)
cross-site scripting in @platejs/media (CVE-2026-55596). Confidential information can be exposed externally. Exploitable via ``provider``. Mitigation: upgrade to `53.1.4` or later.
CVE-2026-54591 Path Traversal in asyncssh (CVE-2026-54591)
path traversal in asyncssh (CVE-2026-54591). Data can be tampered with by attackers. Exploitable via ``_parse_cd_args``. Mitigation: upgrade to `2.23.1` or later.
CVE-2026-54590 Path Traversal in asyncssh (CVE-2026-54590)
path traversal in asyncssh (CVE-2026-54590). Data can be tampered with by attackers. Exploitable via ``AuthorizedKeysFile``. Mitigation: upgrade to `2.23.0` or later.
CVE-2026-49866 Vulnerability in @libp2p/gossipsub (CVE-2026-49866)
vulnerability in @libp2p/gossipsub (CVE-2026-49866). Risk of unauthorized operations or information disclosure. Exploitable via ``opts.decodeRpcLimits``. Mitigation: upgrade to `16.0.0` or later.
CVE-2026-35211 Code Injection in citeum (CVE-2026-35211)
code injection in citeum (CVE-2026-35211). Risk of unauthorized operations or information disclosure.
CVE-2026-35210 Vulnerability in citeum (CVE-2026-35210)
vulnerability in citeum (CVE-2026-35210). Data can be tampered with by attackers.
GHSA-wchw-4whx-qhq5 Vulnerability in tslint-conf (GHSA-wchw-4whx-qhq5)
vulnerability in tslint-conf (GHSA-wchw-4whx-qhq5). Risk of unauthorized operations or information disclosure. Exploitable via ``pino``.
CVE-2026-49464 Vulnerability in nl.nl-portal:taak (CVE-2026-49464)
vulnerability in nl.nl-portal:taak (CVE-2026-49464). Confidential information can be exposed externally. Exploitable via ``burger``. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-49463 Information Disclosure in nl.nl-portal:documenten-api (CVE-2026-49463)
vulnerability in nl.nl-portal:documenten-api (CVE-2026-49463). Confidential information can be exposed externally. Exploitable via ``besluiten``. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-49456 Open Redirect in waku (CVE-2026-49456)
vulnerability in waku (CVE-2026-49456). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `1.0.0-beta.1` or later.
CVE-2026-49455 Cross-Site Request Forgery (CSRF) in waku (CVE-2026-49455)
vulnerability in waku (CVE-2026-49455). Data can be tampered with by attackers. Exploitable via ``Origin``. Mitigation: upgrade to `1.0.0-beta.1` or later.
CVE-2026-53649 Vulnerability in github.com/BishopFox/joro (CVE-2026-53649)
vulnerability in github.com/BishopFox/joro (CVE-2026-53649). Risk of unauthorized operations or information disclosure. Exploitable via ``AuthMiddleware``. Mitigation: upgrade to `0.0.0-20260601151442-5c0ca35db828` or later.
GHSA-q95x-7g78-rccv Use-After-Free in oneringbuf (GHSA-q95x-7g78-rccv)
vulnerability in oneringbuf (GHSA-q95x-7g78-rccv). Risk of unauthorized operations or information disclosure. Exploitable via ``oneringbuf``. Mitigation: upgrade to `0.8.0` or later.
CVE-2026-49833 Path Traversal in org.dspace:dspace-api (CVE-2026-49833)
path traversal in org.dspace:dspace-api (CVE-2026-49833). Confidential information can be exposed externally. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
CVE-2026-49830 Vulnerability in org.dspace:dspace-api (CVE-2026-49830)
vulnerability in org.dspace:dspace-api (CVE-2026-49830). Confidential information can be exposed externally. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
CVE-2026-49831 Path Traversal in org.dspace:dspace-api (CVE-2026-49831)
path traversal in org.dspace:dspace-api (CVE-2026-49831). Risk of unauthorized operations or information disclosure. Exploitable via ``curate``. Mitigation: upgrade to `10.0` or later.
CVE-2026-49832 Code Injection in org.dspace:dspace-api (CVE-2026-49832)
code injection in org.dspace:dspace-api (CVE-2026-49832). Successful exploitation can lead to full system takeover. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
GHSA-mxwc-wh95-pw4g Vulnerability in trapster (GHSA-mxwc-wh95-pw4g)
vulnerability in trapster (GHSA-mxwc-wh95-pw4g). Risk of unauthorized operations or information disclosure. Exploitable via ``RecursionError``.
CVE-2026-52831 OS Command Injection in github.com/nuclio/nuclio (CVE-2026-52831)
OS command injection in github.com/nuclio/nuclio (CVE-2026-52831). Risk of unauthorized operations or information disclosure. Exploitable via ``curl``. Mitigation: upgrade to `0.0.0-20260601075854-3356b86a8bfa` or later.
CVE-2026-53600 Vulnerability in async-tar (CVE-2026-53600)
vulnerability in async-tar (CVE-2026-53600). Risk of unauthorized operations or information disclosure. Exploitable via ``size``. Mitigation: upgrade to `0.6.1` or later.
CVE-2026-50197 Vulnerability in github.com/zalando/skipper (CVE-2026-50197)
vulnerability in github.com/zalando/skipper (CVE-2026-50197). Risk of unauthorized operations or information disclosure. Exploitable via `POST /priv`. Mitigation: upgrade to `0.26.10` or later.
CVE-2026-49825 Vulnerability in lxml_html_clean (CVE-2026-49825)
vulnerability in lxml_html_clean (CVE-2026-49825). Confidential information can be exposed externally. Exploitable via ``lxml_html_clean.Cleaner``. Mitigation: upgrade to `0.4.5` or later.
BELL-CVE-2026-56003 BELL-CVE-2026-56003
BELL-CVE-2026-56001 BELL-CVE-2026-56001
CVE-2026-59948 Path Traversal in composer/composer (CVE-2026-59948)
path traversal in composer/composer (CVE-2026-59948). Successful exploitation can lead to full system takeover. Exploitable via ``install``. Mitigation: upgrade to `2.2.29` or later.
CVE-2026-59947 Vulnerability in composer/composer (CVE-2026-59947)
vulnerability in composer/composer (CVE-2026-59947). Confidential information can be exposed externally. Exploitable via ``repositories``. Mitigation: upgrade to `2.2.29` or later.
CVE-2026-59946 Path Traversal in composer/composer (CVE-2026-59946)
path traversal in composer/composer (CVE-2026-59946). Confidential information can be exposed externally. Exploitable via ``bin``. Mitigation: upgrade to `2.2.29` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →