Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10134 |
|
Code Injection in langflow (CVE-2026-10134)
code injection in langflow (CVE-2026-10134). Successful exploitation can lead to full system takeover. Exploitable via ``tool_code``.
|
| CVE-2026-58138 |
|
Code Injection in CVE-2026-58138 (CVE-2026-58138)
code injection in CVE-2026-58138 (CVE-2026-58138). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48807 |
|
Vulnerability in twig/twig (CVE-2026-48807)
vulnerability in twig/twig (CVE-2026-48807). Confidential information can be exposed externally. Exploitable via ``Traversable``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48806 |
|
Vulnerability in twig/twig (CVE-2026-48806)
vulnerability in twig/twig (CVE-2026-48806). Confidential information can be exposed externally. Exploitable via ``CheckToStringNode``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48805 |
|
Vulnerability in twig/twig (CVE-2026-48805)
vulnerability in twig/twig (CVE-2026-48805). Confidential information can be exposed externally. Exploitable via ``Environment``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-58172 |
|
Vulnerability in CVE-2026-58172 (CVE-2026-58172)
vulnerability in CVE-2026-58172 (CVE-2026-58172). Confidential information can be exposed externally.
|
| CVE-2026-58166 |
|
Path Traversal in path-traversal (CVE-2026-58166)
path traversal in path-traversal (CVE-2026-58166). Data can be tampered with by attackers.
|
| CVE-2026-48315 |
|
Vulnerability in adobe (CVE-2026-48315)
vulnerability in adobe (CVE-2026-48315). Confidential information can be exposed externally.
|
| CVE-2026-48286 |
|
Authorization Flaw in adobe (CVE-2026-48286)
vulnerability in adobe (CVE-2026-48286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48282 KEV |
|
[KEV] Path Traversal in Adobe path-traversal (CVE-2026-48282)
path traversal in Adobe path-traversal (CVE-2026-48282). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-48313 |
|
Path Traversal in path-traversal (CVE-2026-48313)
path traversal in path-traversal (CVE-2026-48313). Confidential information can be exposed externally.
|
| CVE-2026-48283 |
|
Unrestricted File Upload in adobe (CVE-2026-48283)
vulnerability in adobe (CVE-2026-48283). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48277 |
|
Vulnerability in adobe (CVE-2026-48277)
vulnerability in adobe (CVE-2026-48277). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48281 |
|
Vulnerability in adobe (CVE-2026-48281)
vulnerability in adobe (CVE-2026-48281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48276 |
|
Unrestricted File Upload in adobe (CVE-2026-48276)
vulnerability in adobe (CVE-2026-48276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8655 |
|
Buffer Overflow in dos (CVE-2026-8655)
vulnerability in dos (CVE-2026-8655). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14241 |
|
Buffer Overflow in c (CVE-2026-14241)
vulnerability in c (CVE-2026-14241). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8452 KEV |
|
[KEV] Buffer Overflow in Citrix dos (CVE-2026-8452)
vulnerability in Citrix dos (CVE-2026-8452). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-58116 |
|
Code Injection in hiyouga (CVE-2026-58116)
code injection in hiyouga (CVE-2026-58116). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6556 |
|
Vulnerability in express (CVE-2026-6556)
vulnerability in express (CVE-2026-6556). Confidential information can be exposed externally.
|
| CVE-2026-8402 |
|
SQL Injection in sqli (CVE-2026-8402)
SQL injection in sqli (CVE-2026-8402). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14162 |
|
Vulnerability in CVE-2026-14162 (CVE-2026-14162)
vulnerability in CVE-2026-14162 (CVE-2026-14162). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13766 |
|
SQL Injection in sqli (CVE-2026-13766)
SQL injection in sqli (CVE-2026-13766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9711 |
|
SQL Injection in wordpress (CVE-2026-9711)
SQL injection in wordpress (CVE-2026-9711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12073 |
|
Vulnerability in wordpress (CVE-2026-12073)
vulnerability in wordpress (CVE-2026-12073). Successful exploitation can lead to full system takeover. Exploitable via ``user_login``.
|
| CVE-2026-53434 |
|
Vulnerability in tomcat (CVE-2026-53434)
vulnerability in tomcat (CVE-2026-53434). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-55276 |
|
Vulnerability in tomcat (CVE-2026-55276)
vulnerability in tomcat (CVE-2026-55276). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-13762 |
|
Vulnerability in Amazon aws (CVE-2026-13762)
vulnerability in Amazon aws (CVE-2026-13762). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57498 |
|
Vulnerability in CVE-2026-57498 (CVE-2026-57498)
vulnerability in CVE-2026-57498 (CVE-2026-57498). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.0-beta.474` or later.
|
| CVE-2026-13763 |
|
Vulnerability in amazon (CVE-2026-13763)
vulnerability in amazon (CVE-2026-13763). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37637 |
|
Code Injection in CVE-2026-37637 (CVE-2026-37637)
code injection in CVE-2026-37637 (CVE-2026-37637). Confidential information can be exposed externally.
|
| CVE-2026-39868 |
|
Vulnerability in apple (CVE-2026-39868)
vulnerability in apple (CVE-2026-39868). Data can be tampered with by attackers.
|
| CVE-2026-11720 |
|
Path Traversal in path-traversal (CVE-2026-11720)
path traversal in path-traversal (CVE-2026-11720). Confidential information can be exposed externally.
|
| CVE-2026-56782 |
|
Vulnerability in CVE-2026-56782 (CVE-2026-56782)
vulnerability in CVE-2026-56782 (CVE-2026-56782). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57331 |
|
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
|
| CVE-2026-56290 KEV |
|
[KEV] Unrestricted File Upload in Joomlack page-builder-ck (CVE-2026-56290)
vulnerability in Joomlack page-builder-ck (CVE-2026-56290). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-49048 |
|
SQL Injection in joomcoder (CVE-2026-49048)
SQL injection in joomcoder (CVE-2026-49048). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58053 |
|
Privilege Escalation in CVE-2026-58053 (CVE-2026-58053)
vulnerability in CVE-2026-58053 (CVE-2026-58053). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12415 |
|
Privilege Escalation in wordpress (CVE-2026-12415)
vulnerability in wordpress (CVE-2026-12415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28701 |
|
Path Traversal in daktronics (CVE-2026-28701)
path traversal in daktronics (CVE-2026-28701). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53576 |
|
Code Injection in kestra (CVE-2026-53576)
code injection in kestra (CVE-2026-53576). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.45` or later.
|
| CVE-2026-49869 |
|
OS Command Injection in kestra (CVE-2026-49869)
OS command injection in kestra (CVE-2026-49869). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.45` or later.
|
| CVE-2026-53309 |
|
Vulnerability in linux (CVE-2026-53309)
vulnerability in linux (CVE-2026-53309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52785 |
|
SQL Injection in sqli (CVE-2026-52785)
SQL injection in sqli (CVE-2026-52785). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-52782 |
|
Vulnerability in CVE-2026-52782 (CVE-2026-52782)
vulnerability in CVE-2026-52782 (CVE-2026-52782). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-52780 |
|
Vulnerability in CVE-2026-52780 (CVE-2026-52780)
vulnerability in CVE-2026-52780 (CVE-2026-52780). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-46386 |
|
Unsafe Deserialization in rails (CVE-2026-46386)
vulnerability in rails (CVE-2026-46386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48769 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48769)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48769). Successful exploitation can lead to full system takeover. Exploitable via `POST /1.0/images`. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48755 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48755)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48755). Successful exploitation can lead to full system takeover. Exploitable via ``compression_algorithm``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48753 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.0` or later.
|