Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66787 |
|
Vulnerability in CVE-2026-66787 (CVE-2026-66787)
vulnerability in CVE-2026-66787 (CVE-2026-66787). Confidential information can be exposed externally.
|
| CVE-2026-66785 |
|
Vulnerability in CVE-2026-66785 (CVE-2026-66785)
vulnerability in CVE-2026-66785 (CVE-2026-66785). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66002 |
|
Vulnerability in CVE-2026-66002 (CVE-2026-66002)
vulnerability in CVE-2026-66002 (CVE-2026-66002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66001 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-66001 (CVE-2026-66001)
vulnerability in CVE-2026-66001 (CVE-2026-66001). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64777 |
|
Path Traversal in apple (CVE-2026-64777)
path traversal in apple (CVE-2026-64777). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63654 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-63654 (CVE-2026-63654)
vulnerability in CVE-2026-63654 (CVE-2026-63654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62315 |
|
Vulnerability in CVE-2026-62315 (CVE-2026-62315)
vulnerability in CVE-2026-62315 (CVE-2026-62315). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53993 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-53587 |
|
Vulnerability in c (CVE-2026-53587)
vulnerability in c (CVE-2026-53587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53586 |
|
Information Disclosure in c (CVE-2026-53586)
vulnerability in c (CVE-2026-53586). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-53585 |
|
Vulnerability in c (CVE-2026-53585)
vulnerability in c (CVE-2026-53585). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53584 |
|
Path Traversal in c (CVE-2026-53584)
path traversal in c (CVE-2026-53584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53583 |
|
Vulnerability in c (CVE-2026-53583)
vulnerability in c (CVE-2026-53583). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53569 |
|
Vulnerability in CVE-2026-53569 (CVE-2026-53569)
vulnerability in CVE-2026-53569 (CVE-2026-53569). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50190 |
|
Cross-Site Scripting (XSS) in CVE-2026-50190 (CVE-2026-50190)
cross-site scripting in CVE-2026-50190 (CVE-2026-50190). Risk of unauthorized operations or information disclosure. Exploitable via ``permalink``.
|
| CVE-2026-49996 |
|
Open Redirect in CVE-2026-49996 (CVE-2026-49996)
vulnerability in CVE-2026-49996 (CVE-2026-49996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46537 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-46536 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-46535 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-46534 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-46533 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-43678 |
|
Vulnerability in apple (CVE-2026-43678)
vulnerability in apple (CVE-2026-43678). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19683 |
|
Vulnerability in CVE-2026-19683 (CVE-2026-19683)
vulnerability in CVE-2026-19683 (CVE-2026-19683). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19586 |
|
OS Command Injection in CVE-2026-19586 (CVE-2026-19586)
OS command injection in CVE-2026-19586 (CVE-2026-19586). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15743 |
|
Vulnerability in CVE-2026-15743 (CVE-2026-15743)
vulnerability in CVE-2026-15743 (CVE-2026-15743). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| GHSA-jm5p-837g-rv8g |
|
Vulnerability in wagtail (GHSA-jm5p-837g-rv8g)
vulnerability in wagtail (GHSA-jm5p-837g-rv8g). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0rc2` or later.
|
| GHSA-x5cx-w6p2-mxf2 |
|
Vulnerability in wagtail (GHSA-x5cx-w6p2-mxf2)
vulnerability in wagtail (GHSA-x5cx-w6p2-mxf2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0rc2` or later.
|
| GHSA-c2xx-cjmh-9q8f |
|
Vulnerability in wagtail (GHSA-c2xx-cjmh-9q8f)
vulnerability in wagtail (GHSA-c2xx-cjmh-9q8f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0rc2` or later.
|
| GHSA-92hv-j533-69wc |
|
Vulnerability in wagtail (GHSA-92hv-j533-69wc)
vulnerability in wagtail (GHSA-92hv-j533-69wc). Risk of unauthorized operations or information disclosure. Exploitable via ``file_hash``. Mitigation: upgrade to `8.0rc2` or later.
|
| GHSA-hq84-x37p-j6q5 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (GHSA-hq84-x37p-j6q5)
cross-site scripting in winter/wn-backend-module (GHSA-hq84-x37p-j6q5). Risk of unauthorized operations or information disclosure. Exploitable via ``search``. Mitigation: upgrade to `1.2.14` or later.
|
| GHSA-p2ch-c2c3-4xm5 |
|
Cross-Site Request Forgery (CSRF) in winter/wn-backend-module (GHSA-p2ch-c2c3-4xm5)
vulnerability in winter/wn-backend-module (GHSA-p2ch-c2c3-4xm5). Risk of unauthorized operations or information disclosure. Exploitable via ``GET``. Mitigation: upgrade to `1.2.14` or later.
|
| GHSA-5cwr-5jxg-pcf6 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (GHSA-5cwr-5jxg-pcf6)
cross-site scripting in winter/wn-backend-module (GHSA-5cwr-5jxg-pcf6). Risk of unauthorized operations or information disclosure. Exploitable via ``backend.manage_branding``. Mitigation: upgrade to `1.2.14` or later.
|
| GHSA-fm29-4mq3-phg6 |
|
Vulnerability in winter/wn-backend-module (GHSA-fm29-4mq3-phg6)
vulnerability in winter/wn-backend-module (GHSA-fm29-4mq3-phg6). Risk of unauthorized operations or information disclosure. Exploitable via ``ImportExportController``. Mitigation: upgrade to `1.2.14` or later.
|
| GHSA-mpmw-f6h6-3g26 |
|
Vulnerability in winter/wn-backend-module (GHSA-mpmw-f6h6-3g26)
vulnerability in winter/wn-backend-module (GHSA-mpmw-f6h6-3g26). Risk of unauthorized operations or information disclosure. Exploitable via `GET /backend/backend/myaccount/preview/{other_user_id}`. Mitigation: upgrade to `1.2.14` or later.
|
| GHSA-7mpf-4465-7fc2 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (GHSA-7mpf-4465-7fc2)
cross-site scripting in winter/wn-backend-module (GHSA-7mpf-4465-7fc2). Risk of unauthorized operations or information disclosure. Exploitable via ``src``. Mitigation: upgrade to `1.2.14` or later.
|
| GHSA-rxhg-vcww-2mpw |
|
SQL Injection in github.com/fleetdm/fleet/v4 (GHSA-rxhg-vcww-2mpw)
SQL injection in github.com/fleetdm/fleet/v4 (GHSA-rxhg-vcww-2mpw). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/fleet/activities`. Mitigation: upgrade to `4.89.0` or later.
|
| GHSA-q9c5-pp7m-fm2g |
|
Vulnerability in github.com/fleetdm/fleet/v4 (GHSA-q9c5-pp7m-fm2g)
vulnerability in github.com/fleetdm/fleet/v4 (GHSA-q9c5-pp7m-fm2g). Risk of unauthorized operations or information disclosure. Exploitable via ``InstallEnterpriseApplication``. Mitigation: upgrade to `4.87.0` or later.
|
| GHSA-8cfw-pcwh-v63w |
|
Vulnerability in winter/wn-system-module (GHSA-8cfw-pcwh-v63w)
vulnerability in winter/wn-system-module (GHSA-8cfw-pcwh-v63w). Risk of unauthorized operations or information disclosure. Exploitable via ``cms.manage_pages``. Mitigation: upgrade to `1.2.13` or later.
|
| GHSA-2223-f22x-24cq |
|
Path Traversal in winter/wn-system-module (GHSA-2223-f22x-24cq)
path traversal in winter/wn-system-module (GHSA-2223-f22x-24cq). Risk of unauthorized operations or information disclosure. Exploitable via ``cms.manage_assets``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-63202 |
|
Vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-63202)
vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-63202). Risk of unauthorized operations or information disclosure. Exploitable via ``d3f2b49``. Mitigation: upgrade to `0.0.23.Final` or later.
|
| CVE-2026-63179 |
|
Path Traversal in winter/wn-backend-module (CVE-2026-63179)
path traversal in winter/wn-backend-module (CVE-2026-63179). Confidential information can be exposed externally. Exploitable via ``BrandSetting.custom_css``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-61827 |
|
Vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-61827)
vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-61827). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.23.Final` or later.
|
| CVE-2026-63124 |
|
Vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-63124)
vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-63124). Risk of unauthorized operations or information disclosure. Exploitable via ``BinaryHttpParser``. Mitigation: upgrade to `0.0.23.Final` or later.
|
| CVE-2026-61799 |
|
Vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-61799)
vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-61799). Risk of unauthorized operations or information disclosure. Exploitable via ``long``. Mitigation: upgrade to `0.0.23.Final` or later.
|
| CVE-2026-61798 |
|
Information Disclosure in io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (CVE-2026-61798)
vulnerability in io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (CVE-2026-61798). Risk of unauthorized operations or information disclosure. Exploitable via ``IllegalArgumentException``. Mitigation: upgrade to `0.0.23.Final` or later.
|
| CVE-2026-61663 |
|
Vulnerability in django-cms (CVE-2026-61663)
vulnerability in django-cms (CVE-2026-61663). Risk of unauthorized operations or information disclosure. Exploitable via ``PageContent``. Mitigation: upgrade to `5.0.9` or later.
|
| CVE-2026-63003 |
|
Vulnerability in django-cms (CVE-2026-63003)
vulnerability in django-cms (CVE-2026-63003). Confidential information can be exposed externally. Exploitable via `POST /admin/cms/pagecontent/`. Mitigation: upgrade to `5.0.9` or later.
|
| CVE-2026-75526 |
|
Cross-Site Scripting (XSS) in django-cms (CVE-2026-75526)
cross-site scripting in django-cms (CVE-2026-75526). Risk of unauthorized operations or information disclosure. Exploitable via ``message``. Mitigation: upgrade to `5.0.9` or later.
|
| CVE-2026-57570 |
|
Vulnerability in backpack/crud (CVE-2026-57570)
vulnerability in backpack/crud (CVE-2026-57570). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.8.15` or later.
|
| CVE-2026-55468 |
|
Vulnerability in wagtail (CVE-2026-55468)
vulnerability in wagtail (CVE-2026-55468). Risk of unauthorized operations or information disclosure. Exploitable via ``api_fields``. Mitigation: upgrade to `8.0rc2` or later.
|