Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-10134 Code Injection in langflow (CVE-2026-10134)
code injection in langflow (CVE-2026-10134). Successful exploitation can lead to full system takeover. Exploitable via ``tool_code``.
CVE-2026-58138 Code Injection in CVE-2026-58138 (CVE-2026-58138)
code injection in CVE-2026-58138 (CVE-2026-58138). Successful exploitation can lead to full system takeover.
CVE-2026-48807 Vulnerability in twig/twig (CVE-2026-48807)
vulnerability in twig/twig (CVE-2026-48807). Confidential information can be exposed externally. Exploitable via ``Traversable``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48806 Vulnerability in twig/twig (CVE-2026-48806)
vulnerability in twig/twig (CVE-2026-48806). Confidential information can be exposed externally. Exploitable via ``CheckToStringNode``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48805 Vulnerability in twig/twig (CVE-2026-48805)
vulnerability in twig/twig (CVE-2026-48805). Confidential information can be exposed externally. Exploitable via ``Environment``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-58172 Vulnerability in CVE-2026-58172 (CVE-2026-58172)
vulnerability in CVE-2026-58172 (CVE-2026-58172). Confidential information can be exposed externally.
CVE-2026-58166 Path Traversal in path-traversal (CVE-2026-58166)
path traversal in path-traversal (CVE-2026-58166). Data can be tampered with by attackers.
CVE-2026-48315 Vulnerability in adobe (CVE-2026-48315)
vulnerability in adobe (CVE-2026-48315). Confidential information can be exposed externally.
CVE-2026-48286 Authorization Flaw in adobe (CVE-2026-48286)
vulnerability in adobe (CVE-2026-48286). Successful exploitation can lead to full system takeover.
CVE-2026-48282 KEV [KEV] Path Traversal in Adobe path-traversal (CVE-2026-48282)
path traversal in Adobe path-traversal (CVE-2026-48282). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-48313 Path Traversal in path-traversal (CVE-2026-48313)
path traversal in path-traversal (CVE-2026-48313). Confidential information can be exposed externally.
CVE-2026-48283 Unrestricted File Upload in adobe (CVE-2026-48283)
vulnerability in adobe (CVE-2026-48283). Successful exploitation can lead to full system takeover.
CVE-2026-48277 Vulnerability in adobe (CVE-2026-48277)
vulnerability in adobe (CVE-2026-48277). Successful exploitation can lead to full system takeover.
CVE-2026-48281 Vulnerability in adobe (CVE-2026-48281)
vulnerability in adobe (CVE-2026-48281). Successful exploitation can lead to full system takeover.
CVE-2026-48276 Unrestricted File Upload in adobe (CVE-2026-48276)
vulnerability in adobe (CVE-2026-48276). Successful exploitation can lead to full system takeover.
CVE-2026-8655 Buffer Overflow in dos (CVE-2026-8655)
vulnerability in dos (CVE-2026-8655). Successful exploitation can lead to full system takeover.
CVE-2026-14241 Buffer Overflow in c (CVE-2026-14241)
vulnerability in c (CVE-2026-14241). Successful exploitation can lead to full system takeover.
CVE-2026-8452 KEV [KEV] Buffer Overflow in Citrix dos (CVE-2026-8452)
vulnerability in Citrix dos (CVE-2026-8452). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-58116 Code Injection in hiyouga (CVE-2026-58116)
code injection in hiyouga (CVE-2026-58116). Successful exploitation can lead to full system takeover.
CVE-2026-6556 Vulnerability in express (CVE-2026-6556)
vulnerability in express (CVE-2026-6556). Confidential information can be exposed externally.
CVE-2026-8402 SQL Injection in sqli (CVE-2026-8402)
SQL injection in sqli (CVE-2026-8402). Successful exploitation can lead to full system takeover.
CVE-2026-14162 Vulnerability in CVE-2026-14162 (CVE-2026-14162)
vulnerability in CVE-2026-14162 (CVE-2026-14162). Successful exploitation can lead to full system takeover.
CVE-2026-13766 SQL Injection in sqli (CVE-2026-13766)
SQL injection in sqli (CVE-2026-13766). Successful exploitation can lead to full system takeover.
CVE-2026-9711 SQL Injection in wordpress (CVE-2026-9711)
SQL injection in wordpress (CVE-2026-9711). Successful exploitation can lead to full system takeover.
CVE-2026-12073 Vulnerability in wordpress (CVE-2026-12073)
vulnerability in wordpress (CVE-2026-12073). Successful exploitation can lead to full system takeover. Exploitable via ``user_login``.
CVE-2026-53434 Vulnerability in tomcat (CVE-2026-53434)
vulnerability in tomcat (CVE-2026-53434). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
CVE-2026-55276 Vulnerability in tomcat (CVE-2026-55276)
vulnerability in tomcat (CVE-2026-55276). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
CVE-2026-13762 Vulnerability in Amazon aws (CVE-2026-13762)
vulnerability in Amazon aws (CVE-2026-13762). Successful exploitation can lead to full system takeover.
CVE-2026-57498 Vulnerability in CVE-2026-57498 (CVE-2026-57498)
vulnerability in CVE-2026-57498 (CVE-2026-57498). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.0-beta.474` or later.
CVE-2026-13763 Vulnerability in amazon (CVE-2026-13763)
vulnerability in amazon (CVE-2026-13763). Successful exploitation can lead to full system takeover.
CVE-2026-37637 Code Injection in CVE-2026-37637 (CVE-2026-37637)
code injection in CVE-2026-37637 (CVE-2026-37637). Confidential information can be exposed externally.
CVE-2026-39868 Vulnerability in apple (CVE-2026-39868)
vulnerability in apple (CVE-2026-39868). Data can be tampered with by attackers.
CVE-2026-11720 Path Traversal in path-traversal (CVE-2026-11720)
path traversal in path-traversal (CVE-2026-11720). Confidential information can be exposed externally.
CVE-2026-56782 Vulnerability in CVE-2026-56782 (CVE-2026-56782)
vulnerability in CVE-2026-56782 (CVE-2026-56782). Successful exploitation can lead to full system takeover.
CVE-2026-57331 Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
CVE-2026-56290 KEV [KEV] Unrestricted File Upload in Joomlack page-builder-ck (CVE-2026-56290)
vulnerability in Joomlack page-builder-ck (CVE-2026-56290). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-49048 SQL Injection in joomcoder (CVE-2026-49048)
SQL injection in joomcoder (CVE-2026-49048). Successful exploitation can lead to full system takeover.
CVE-2026-58053 Privilege Escalation in CVE-2026-58053 (CVE-2026-58053)
vulnerability in CVE-2026-58053 (CVE-2026-58053). Successful exploitation can lead to full system takeover.
CVE-2026-12415 Privilege Escalation in wordpress (CVE-2026-12415)
vulnerability in wordpress (CVE-2026-12415). Successful exploitation can lead to full system takeover.
CVE-2026-28701 Path Traversal in daktronics (CVE-2026-28701)
path traversal in daktronics (CVE-2026-28701). Successful exploitation can lead to full system takeover.
CVE-2026-53576 Code Injection in kestra (CVE-2026-53576)
code injection in kestra (CVE-2026-53576). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.45` or later.
CVE-2026-49869 OS Command Injection in kestra (CVE-2026-49869)
OS command injection in kestra (CVE-2026-49869). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.45` or later.
CVE-2026-53309 Vulnerability in linux (CVE-2026-53309)
vulnerability in linux (CVE-2026-53309). Successful exploitation can lead to full system takeover.
CVE-2026-52785 SQL Injection in sqli (CVE-2026-52785)
SQL injection in sqli (CVE-2026-52785). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-52782 Vulnerability in CVE-2026-52782 (CVE-2026-52782)
vulnerability in CVE-2026-52782 (CVE-2026-52782). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-52780 Vulnerability in CVE-2026-52780 (CVE-2026-52780)
vulnerability in CVE-2026-52780 (CVE-2026-52780). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `17.3.3` or later.
CVE-2026-46386 Unsafe Deserialization in rails (CVE-2026-46386)
vulnerability in rails (CVE-2026-46386). Successful exploitation can lead to full system takeover.
CVE-2026-48769 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48769)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48769). Successful exploitation can lead to full system takeover. Exploitable via `POST /1.0/images`. Mitigation: upgrade to `7.2.0` or later.
CVE-2026-48755 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48755)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48755). Successful exploitation can lead to full system takeover. Exploitable via ``compression_algorithm``. Mitigation: upgrade to `7.2.0` or later.
CVE-2026-48753 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →