Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-66787 Vulnerability in CVE-2026-66787 (CVE-2026-66787)
vulnerability in CVE-2026-66787 (CVE-2026-66787). Confidential information can be exposed externally.
CVE-2026-66785 Vulnerability in CVE-2026-66785 (CVE-2026-66785)
vulnerability in CVE-2026-66785 (CVE-2026-66785). Successful exploitation can lead to full system takeover.
CVE-2026-66002 Vulnerability in CVE-2026-66002 (CVE-2026-66002)
vulnerability in CVE-2026-66002 (CVE-2026-66002). Risk of unauthorized operations or information disclosure.
CVE-2026-66001 Cross-Site Request Forgery (CSRF) in CVE-2026-66001 (CVE-2026-66001)
vulnerability in CVE-2026-66001 (CVE-2026-66001). Risk of unauthorized operations or information disclosure.
CVE-2026-64777 Path Traversal in apple (CVE-2026-64777)
path traversal in apple (CVE-2026-64777). Risk of unauthorized operations or information disclosure.
CVE-2026-63654 Cross-Site Request Forgery (CSRF) in CVE-2026-63654 (CVE-2026-63654)
vulnerability in CVE-2026-63654 (CVE-2026-63654). Risk of unauthorized operations or information disclosure.
CVE-2026-62315 Vulnerability in CVE-2026-62315 (CVE-2026-62315)
vulnerability in CVE-2026-62315 (CVE-2026-62315). Risk of unauthorized operations or information disclosure.
CVE-2026-53993 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53587 Vulnerability in c (CVE-2026-53587)
vulnerability in c (CVE-2026-53587). Risk of unauthorized operations or information disclosure.
CVE-2026-53586 Information Disclosure in c (CVE-2026-53586)
vulnerability in c (CVE-2026-53586). Confidential information can be exposed externally. Exploitable via `Authorization header`.
CVE-2026-53585 Vulnerability in c (CVE-2026-53585)
vulnerability in c (CVE-2026-53585). Risk of unauthorized operations or information disclosure.
CVE-2026-53584 Path Traversal in c (CVE-2026-53584)
path traversal in c (CVE-2026-53584). Risk of unauthorized operations or information disclosure.
CVE-2026-53583 Vulnerability in c (CVE-2026-53583)
vulnerability in c (CVE-2026-53583). Risk of unauthorized operations or information disclosure.
CVE-2026-53569 Vulnerability in CVE-2026-53569 (CVE-2026-53569)
vulnerability in CVE-2026-53569 (CVE-2026-53569). Risk of unauthorized operations or information disclosure.
CVE-2026-50190 Cross-Site Scripting (XSS) in CVE-2026-50190 (CVE-2026-50190)
cross-site scripting in CVE-2026-50190 (CVE-2026-50190). Risk of unauthorized operations or information disclosure. Exploitable via ``permalink``.
CVE-2026-49996 Open Redirect in CVE-2026-49996 (CVE-2026-49996)
vulnerability in CVE-2026-49996 (CVE-2026-49996). Risk of unauthorized operations or information disclosure.
CVE-2026-46537 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46536 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46535 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46534 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46533 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-43678 Vulnerability in apple (CVE-2026-43678)
vulnerability in apple (CVE-2026-43678). Risk of unauthorized operations or information disclosure.
CVE-2026-19683 Vulnerability in CVE-2026-19683 (CVE-2026-19683)
vulnerability in CVE-2026-19683 (CVE-2026-19683). Risk of unauthorized operations or information disclosure.
CVE-2026-19586 OS Command Injection in CVE-2026-19586 (CVE-2026-19586)
OS command injection in CVE-2026-19586 (CVE-2026-19586). Risk of unauthorized operations or information disclosure.
CVE-2026-15743 Vulnerability in CVE-2026-15743 (CVE-2026-15743)
vulnerability in CVE-2026-15743 (CVE-2026-15743). Confidential information can be exposed externally. Exploitable via `Authorization header`.
GHSA-jm5p-837g-rv8g Vulnerability in wagtail (GHSA-jm5p-837g-rv8g)
vulnerability in wagtail (GHSA-jm5p-837g-rv8g). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0rc2` or later.
GHSA-x5cx-w6p2-mxf2 Vulnerability in wagtail (GHSA-x5cx-w6p2-mxf2)
vulnerability in wagtail (GHSA-x5cx-w6p2-mxf2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0rc2` or later.
GHSA-c2xx-cjmh-9q8f Vulnerability in wagtail (GHSA-c2xx-cjmh-9q8f)
vulnerability in wagtail (GHSA-c2xx-cjmh-9q8f). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0rc2` or later.
GHSA-92hv-j533-69wc Vulnerability in wagtail (GHSA-92hv-j533-69wc)
vulnerability in wagtail (GHSA-92hv-j533-69wc). Risk of unauthorized operations or information disclosure. Exploitable via ``file_hash``. Mitigation: upgrade to `8.0rc2` or later.
GHSA-hq84-x37p-j6q5 Cross-Site Scripting (XSS) in winter/wn-backend-module (GHSA-hq84-x37p-j6q5)
cross-site scripting in winter/wn-backend-module (GHSA-hq84-x37p-j6q5). Risk of unauthorized operations or information disclosure. Exploitable via ``search``. Mitigation: upgrade to `1.2.14` or later.
GHSA-p2ch-c2c3-4xm5 Cross-Site Request Forgery (CSRF) in winter/wn-backend-module (GHSA-p2ch-c2c3-4xm5)
vulnerability in winter/wn-backend-module (GHSA-p2ch-c2c3-4xm5). Risk of unauthorized operations or information disclosure. Exploitable via ``GET``. Mitigation: upgrade to `1.2.14` or later.
GHSA-5cwr-5jxg-pcf6 Cross-Site Scripting (XSS) in winter/wn-backend-module (GHSA-5cwr-5jxg-pcf6)
cross-site scripting in winter/wn-backend-module (GHSA-5cwr-5jxg-pcf6). Risk of unauthorized operations or information disclosure. Exploitable via ``backend.manage_branding``. Mitigation: upgrade to `1.2.14` or later.
GHSA-fm29-4mq3-phg6 Vulnerability in winter/wn-backend-module (GHSA-fm29-4mq3-phg6)
vulnerability in winter/wn-backend-module (GHSA-fm29-4mq3-phg6). Risk of unauthorized operations or information disclosure. Exploitable via ``ImportExportController``. Mitigation: upgrade to `1.2.14` or later.
GHSA-mpmw-f6h6-3g26 Vulnerability in winter/wn-backend-module (GHSA-mpmw-f6h6-3g26)
vulnerability in winter/wn-backend-module (GHSA-mpmw-f6h6-3g26). Risk of unauthorized operations or information disclosure. Exploitable via `GET /backend/backend/myaccount/preview/{other_user_id}`. Mitigation: upgrade to `1.2.14` or later.
GHSA-7mpf-4465-7fc2 Cross-Site Scripting (XSS) in winter/wn-backend-module (GHSA-7mpf-4465-7fc2)
cross-site scripting in winter/wn-backend-module (GHSA-7mpf-4465-7fc2). Risk of unauthorized operations or information disclosure. Exploitable via ``src``. Mitigation: upgrade to `1.2.14` or later.
GHSA-rxhg-vcww-2mpw SQL Injection in github.com/fleetdm/fleet/v4 (GHSA-rxhg-vcww-2mpw)
SQL injection in github.com/fleetdm/fleet/v4 (GHSA-rxhg-vcww-2mpw). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/fleet/activities`. Mitigation: upgrade to `4.89.0` or later.
GHSA-q9c5-pp7m-fm2g Vulnerability in github.com/fleetdm/fleet/v4 (GHSA-q9c5-pp7m-fm2g)
vulnerability in github.com/fleetdm/fleet/v4 (GHSA-q9c5-pp7m-fm2g). Risk of unauthorized operations or information disclosure. Exploitable via ``InstallEnterpriseApplication``. Mitigation: upgrade to `4.87.0` or later.
GHSA-8cfw-pcwh-v63w Vulnerability in winter/wn-system-module (GHSA-8cfw-pcwh-v63w)
vulnerability in winter/wn-system-module (GHSA-8cfw-pcwh-v63w). Risk of unauthorized operations or information disclosure. Exploitable via ``cms.manage_pages``. Mitigation: upgrade to `1.2.13` or later.
GHSA-2223-f22x-24cq Path Traversal in winter/wn-system-module (GHSA-2223-f22x-24cq)
path traversal in winter/wn-system-module (GHSA-2223-f22x-24cq). Risk of unauthorized operations or information disclosure. Exploitable via ``cms.manage_assets``. Mitigation: upgrade to `1.2.13` or later.
CVE-2026-63202 Vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-63202)
vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-63202). Risk of unauthorized operations or information disclosure. Exploitable via ``d3f2b49``. Mitigation: upgrade to `0.0.23.Final` or later.
CVE-2026-63179 Path Traversal in winter/wn-backend-module (CVE-2026-63179)
path traversal in winter/wn-backend-module (CVE-2026-63179). Confidential information can be exposed externally. Exploitable via ``BrandSetting.custom_css``. Mitigation: upgrade to `1.2.13` or later.
CVE-2026-61827 Vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-61827)
vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-61827). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.23.Final` or later.
CVE-2026-63124 Vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-63124)
vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-63124). Risk of unauthorized operations or information disclosure. Exploitable via ``BinaryHttpParser``. Mitigation: upgrade to `0.0.23.Final` or later.
CVE-2026-61799 Vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-61799)
vulnerability in io.netty.incubator:netty-incubator-codec-bhttp (CVE-2026-61799). Risk of unauthorized operations or information disclosure. Exploitable via ``long``. Mitigation: upgrade to `0.0.23.Final` or later.
CVE-2026-61798 Information Disclosure in io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (CVE-2026-61798)
vulnerability in io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (CVE-2026-61798). Risk of unauthorized operations or information disclosure. Exploitable via ``IllegalArgumentException``. Mitigation: upgrade to `0.0.23.Final` or later.
CVE-2026-61663 Vulnerability in django-cms (CVE-2026-61663)
vulnerability in django-cms (CVE-2026-61663). Risk of unauthorized operations or information disclosure. Exploitable via ``PageContent``. Mitigation: upgrade to `5.0.9` or later.
CVE-2026-63003 Vulnerability in django-cms (CVE-2026-63003)
vulnerability in django-cms (CVE-2026-63003). Confidential information can be exposed externally. Exploitable via `POST /admin/cms/pagecontent/`. Mitigation: upgrade to `5.0.9` or later.
CVE-2026-75526 Cross-Site Scripting (XSS) in django-cms (CVE-2026-75526)
cross-site scripting in django-cms (CVE-2026-75526). Risk of unauthorized operations or information disclosure. Exploitable via ``message``. Mitigation: upgrade to `5.0.9` or later.
CVE-2026-57570 Vulnerability in backpack/crud (CVE-2026-57570)
vulnerability in backpack/crud (CVE-2026-57570). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.8.15` or later.
CVE-2026-55468 Vulnerability in wagtail (CVE-2026-55468)
vulnerability in wagtail (CVE-2026-55468). Risk of unauthorized operations or information disclosure. Exploitable via ``api_fields``. Mitigation: upgrade to `8.0rc2` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →