Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59803 |
|
Vulnerability in CVE-2026-59803 (CVE-2026-59803)
vulnerability in CVE-2026-59803 (CVE-2026-59803). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8649 |
|
Vulnerability in progress (CVE-2026-8649)
vulnerability in progress (CVE-2026-8649). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59804 |
|
Vulnerability in CVE-2026-59804 (CVE-2026-59804)
vulnerability in CVE-2026-59804 (CVE-2026-59804). Confidential information can be exposed externally.
|
| CVE-2026-59807 |
|
Vulnerability in CVE-2026-59807 (CVE-2026-59807)
vulnerability in CVE-2026-59807 (CVE-2026-59807). Confidential information can be exposed externally.
|
| CVE-2026-59805 |
|
Vulnerability in CVE-2026-59805 (CVE-2026-59805)
vulnerability in CVE-2026-59805 (CVE-2026-59805). Data can be tampered with by attackers.
|
| CVE-2026-36028 |
|
Vulnerability in CVE-2026-36028 (CVE-2026-36028)
vulnerability in CVE-2026-36028 (CVE-2026-36028). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36027 |
|
Vulnerability in CVE-2026-36027 (CVE-2026-36027)
vulnerability in CVE-2026-36027 (CVE-2026-36027). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14891 |
|
Vulnerability in CVE-2026-14891 (CVE-2026-14891)
vulnerability in CVE-2026-14891 (CVE-2026-14891). Confidential information can be exposed externally.
|
| CVE-2026-14373 |
|
Vulnerability in c (CVE-2026-14373)
vulnerability in c (CVE-2026-14373). Confidential information can be exposed externally.
|
| CVE-2026-15154 |
|
Vulnerability in dos (CVE-2026-15154)
vulnerability in dos (CVE-2026-15154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14361 |
|
Vulnerability in CVE-2026-14361 (CVE-2026-14361)
vulnerability in CVE-2026-14361 (CVE-2026-14361). Confidential information can be exposed externally.
|
| MAL-2026-7023 |
|
Vulnerability in dbzy-tools (MAL-2026-7023)
vulnerability in dbzy-tools (MAL-2026-7023). Risk of unauthorized operations or information disclosure. Exploitable via ``payload``.
|
| UBUNTU-CVE-2026-10037 |
|
Vulnerability in openjdk-9 (UBUNTU-CVE-2026-10037)
vulnerability in openjdk-9 (UBUNTU-CVE-2026-10037). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.70+nmu1ubuntu1.22.04.1` or later.
|
| CVE-2026-59818 |
|
Vulnerability in etcd (CVE-2026-59818)
vulnerability in etcd (CVE-2026-59818). Confidential information can be exposed externally.
|
| CVE-2026-58494 |
|
Vulnerability in CVE-2026-58494 (CVE-2026-58494)
vulnerability in CVE-2026-58494 (CVE-2026-58494). Data can be tampered with by attackers.
|
| CVE-2026-58211 |
|
Authorization Flaw in linuxfoundation (CVE-2026-58211)
vulnerability in linuxfoundation (CVE-2026-58211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58208 |
|
Vulnerability in linuxfoundation (CVE-2026-58208)
vulnerability in linuxfoundation (CVE-2026-58208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58207 |
|
Vulnerability in linuxfoundation (CVE-2026-58207)
vulnerability in linuxfoundation (CVE-2026-58207). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58192 |
|
Path Traversal in appium (CVE-2026-58192)
path traversal in appium (CVE-2026-58192). Data can be tampered with by attackers. Exploitable via `POST /storage/delete`.
|
| CVE-2026-58191 |
|
Cross-Site Scripting (XSS) in appium (CVE-2026-58191)
cross-site scripting in appium (CVE-2026-58191). Data can be tampered with by attackers.
|
| CVE-2026-57481 |
|
Information Disclosure in CVE-2026-57481 (CVE-2026-57481)
vulnerability in CVE-2026-57481 (CVE-2026-57481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57480 |
|
Vulnerability in CVE-2026-57480 (CVE-2026-57480)
vulnerability in CVE-2026-57480 (CVE-2026-57480). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56669 |
|
Vulnerability in CVE-2026-56669 (CVE-2026-56669)
vulnerability in CVE-2026-56669 (CVE-2026-56669). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55596 |
|
Cross-Site Scripting (XSS) in @platejs/media (CVE-2026-55596)
cross-site scripting in @platejs/media (CVE-2026-55596). Confidential information can be exposed externally. Exploitable via ``provider``. Mitigation: upgrade to `53.1.4` or later.
|
| CVE-2026-54591 |
|
Path Traversal in asyncssh (CVE-2026-54591)
path traversal in asyncssh (CVE-2026-54591). Data can be tampered with by attackers. Exploitable via ``_parse_cd_args``. Mitigation: upgrade to `2.23.1` or later.
|
| CVE-2026-54590 |
|
Path Traversal in asyncssh (CVE-2026-54590)
path traversal in asyncssh (CVE-2026-54590). Data can be tampered with by attackers. Exploitable via ``AuthorizedKeysFile``. Mitigation: upgrade to `2.23.0` or later.
|
| CVE-2026-49866 |
|
Vulnerability in @libp2p/gossipsub (CVE-2026-49866)
vulnerability in @libp2p/gossipsub (CVE-2026-49866). Risk of unauthorized operations or information disclosure. Exploitable via ``opts.decodeRpcLimits``. Mitigation: upgrade to `16.0.0` or later.
|
| CVE-2026-35211 |
|
Code Injection in citeum (CVE-2026-35211)
code injection in citeum (CVE-2026-35211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35210 |
|
Vulnerability in citeum (CVE-2026-35210)
vulnerability in citeum (CVE-2026-35210). Data can be tampered with by attackers.
|
| GHSA-wchw-4whx-qhq5 |
|
Vulnerability in tslint-conf (GHSA-wchw-4whx-qhq5)
vulnerability in tslint-conf (GHSA-wchw-4whx-qhq5). Risk of unauthorized operations or information disclosure. Exploitable via ``pino``.
|
| CVE-2026-49464 |
|
Vulnerability in nl.nl-portal:taak (CVE-2026-49464)
vulnerability in nl.nl-portal:taak (CVE-2026-49464). Confidential information can be exposed externally. Exploitable via ``burger``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-49463 |
|
Information Disclosure in nl.nl-portal:documenten-api (CVE-2026-49463)
vulnerability in nl.nl-portal:documenten-api (CVE-2026-49463). Confidential information can be exposed externally. Exploitable via ``besluiten``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-49456 |
|
Open Redirect in waku (CVE-2026-49456)
vulnerability in waku (CVE-2026-49456). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `1.0.0-beta.1` or later.
|
| CVE-2026-49455 |
|
Cross-Site Request Forgery (CSRF) in waku (CVE-2026-49455)
vulnerability in waku (CVE-2026-49455). Data can be tampered with by attackers. Exploitable via ``Origin``. Mitigation: upgrade to `1.0.0-beta.1` or later.
|
| CVE-2026-53649 |
|
Vulnerability in github.com/BishopFox/joro (CVE-2026-53649)
vulnerability in github.com/BishopFox/joro (CVE-2026-53649). Risk of unauthorized operations or information disclosure. Exploitable via ``AuthMiddleware``. Mitigation: upgrade to `0.0.0-20260601151442-5c0ca35db828` or later.
|
| GHSA-q95x-7g78-rccv |
|
Use-After-Free in oneringbuf (GHSA-q95x-7g78-rccv)
vulnerability in oneringbuf (GHSA-q95x-7g78-rccv). Risk of unauthorized operations or information disclosure. Exploitable via ``oneringbuf``. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2026-49833 |
|
Path Traversal in org.dspace:dspace-api (CVE-2026-49833)
path traversal in org.dspace:dspace-api (CVE-2026-49833). Confidential information can be exposed externally. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
|
| CVE-2026-49830 |
|
Vulnerability in org.dspace:dspace-api (CVE-2026-49830)
vulnerability in org.dspace:dspace-api (CVE-2026-49830). Confidential information can be exposed externally. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
|
| CVE-2026-49831 |
|
Path Traversal in org.dspace:dspace-api (CVE-2026-49831)
path traversal in org.dspace:dspace-api (CVE-2026-49831). Risk of unauthorized operations or information disclosure. Exploitable via ``curate``. Mitigation: upgrade to `10.0` or later.
|
| CVE-2026-49832 |
|
Code Injection in org.dspace:dspace-api (CVE-2026-49832)
code injection in org.dspace:dspace-api (CVE-2026-49832). Successful exploitation can lead to full system takeover. Exploitable via ``dspace.cfg``. Mitigation: upgrade to `10.0` or later.
|
| GHSA-mxwc-wh95-pw4g |
|
Vulnerability in trapster (GHSA-mxwc-wh95-pw4g)
vulnerability in trapster (GHSA-mxwc-wh95-pw4g). Risk of unauthorized operations or information disclosure. Exploitable via ``RecursionError``.
|
| CVE-2026-52831 |
|
OS Command Injection in github.com/nuclio/nuclio (CVE-2026-52831)
OS command injection in github.com/nuclio/nuclio (CVE-2026-52831). Risk of unauthorized operations or information disclosure. Exploitable via ``curl``. Mitigation: upgrade to `0.0.0-20260601075854-3356b86a8bfa` or later.
|
| CVE-2026-53600 |
|
Vulnerability in async-tar (CVE-2026-53600)
vulnerability in async-tar (CVE-2026-53600). Risk of unauthorized operations or information disclosure. Exploitable via ``size``. Mitigation: upgrade to `0.6.1` or later.
|
| CVE-2026-50197 |
|
Vulnerability in github.com/zalando/skipper (CVE-2026-50197)
vulnerability in github.com/zalando/skipper (CVE-2026-50197). Risk of unauthorized operations or information disclosure. Exploitable via `POST /priv`. Mitigation: upgrade to `0.26.10` or later.
|
| CVE-2026-49825 |
|
Vulnerability in lxml_html_clean (CVE-2026-49825)
vulnerability in lxml_html_clean (CVE-2026-49825). Confidential information can be exposed externally. Exploitable via ``lxml_html_clean.Cleaner``. Mitigation: upgrade to `0.4.5` or later.
|
| BELL-CVE-2026-56003 |
|
BELL-CVE-2026-56003 |
| BELL-CVE-2026-56001 |
|
BELL-CVE-2026-56001 |
| CVE-2026-59948 |
|
Path Traversal in composer/composer (CVE-2026-59948)
path traversal in composer/composer (CVE-2026-59948). Successful exploitation can lead to full system takeover. Exploitable via ``install``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59947 |
|
Vulnerability in composer/composer (CVE-2026-59947)
vulnerability in composer/composer (CVE-2026-59947). Confidential information can be exposed externally. Exploitable via ``repositories``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59946 |
|
Path Traversal in composer/composer (CVE-2026-59946)
path traversal in composer/composer (CVE-2026-59946). Confidential information can be exposed externally. Exploitable via ``bin``. Mitigation: upgrade to `2.2.29` or later.
|