Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73259 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-73259)
cross-site scripting in c (CVE-2026-73259). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73258 |
|
Vulnerability in c (CVE-2026-73258)
vulnerability in c (CVE-2026-73258). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73257 |
|
Vulnerability in c (CVE-2026-73257)
vulnerability in c (CVE-2026-73257). Confidential information can be exposed externally.
|
| CVE-2026-73256 |
|
Vulnerability in c (CVE-2026-73256)
vulnerability in c (CVE-2026-73256). Confidential information can be exposed externally.
|
| CVE-2026-73255 |
|
Path Traversal in c (CVE-2026-73255)
path traversal in c (CVE-2026-73255). Confidential information can be exposed externally.
|
| CVE-2026-73254 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-73254)
cross-site scripting in c (CVE-2026-73254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73253 |
|
Vulnerability in c (CVE-2026-73253)
vulnerability in c (CVE-2026-73253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73251 |
|
Vulnerability in c (CVE-2026-73251)
vulnerability in c (CVE-2026-73251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63495 |
|
Vulnerability in c (CVE-2026-63495)
vulnerability in c (CVE-2026-63495). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63388 |
|
Vulnerability in c (CVE-2026-63388)
vulnerability in c (CVE-2026-63388). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63387 |
|
Vulnerability in c (CVE-2026-63387)
vulnerability in c (CVE-2026-63387). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63385 |
|
Vulnerability in c (CVE-2026-63385)
vulnerability in c (CVE-2026-63385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63384 |
|
Vulnerability in c (CVE-2026-63384)
vulnerability in c (CVE-2026-63384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63383 |
|
Out-of-Bounds Read in c (CVE-2026-63383)
vulnerability in c (CVE-2026-63383). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63382 |
|
Vulnerability in c (CVE-2026-63382)
vulnerability in c (CVE-2026-63382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63381 |
|
Vulnerability in c (CVE-2026-63381)
vulnerability in c (CVE-2026-63381). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63380 |
|
Use-After-Free in c (CVE-2026-63380)
vulnerability in c (CVE-2026-63380). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63379 |
|
Vulnerability in c (CVE-2026-63379)
vulnerability in c (CVE-2026-63379). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54625 |
|
Vulnerability in django-cms (CVE-2026-54625)
vulnerability in django-cms (CVE-2026-54625). Risk of unauthorized operations or information disclosure. Exploitable via ``Vary``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-54623 |
|
Vulnerability in django-cms (CVE-2026-54623)
vulnerability in django-cms (CVE-2026-54623). Risk of unauthorized operations or information disclosure. Exploitable via ``move_plugin``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-55253 |
|
Vulnerability in langgraph-checkpoint-mongodb (CVE-2026-55253)
vulnerability in langgraph-checkpoint-mongodb (CVE-2026-55253). Risk of unauthorized operations or information disclosure. Exploitable via ``filter``. Mitigation: upgrade to `0.3.0` or later.
|
| CVE-2026-55244 |
|
Vulnerability in asteval (CVE-2026-55244)
vulnerability in asteval (CVE-2026-55244). Risk of unauthorized operations or information disclosure. Exploitable via ``SystemExit``. Mitigation: upgrade to `1.0.6` or later.
|
| GHSA-9w56-46f6-3qhx |
|
Vulnerability in asteval (GHSA-9w56-46f6-3qhx)
vulnerability in asteval (GHSA-9w56-46f6-3qhx). Risk of unauthorized operations or information disclosure. Exploitable via ``import``. Mitigation: upgrade to `1.0.9` or later.
|
| CVE-2026-55149 |
|
Vulnerability in github.com/vouch/vouch-proxy (CVE-2026-55149)
vulnerability in github.com/vouch/vouch-proxy (CVE-2026-55149). Risk of unauthorized operations or information disclosure. Exploitable via `GET /validate`. Mitigation: upgrade to `0.48.0` or later.
|
| CVE-2026-45404 |
|
Vulnerability in go.opentelemetry.io/otel/bridge/opentracing (CVE-2026-45404)
vulnerability in go.opentelemetry.io/otel/bridge/opentracing (CVE-2026-45404). Risk of unauthorized operations or information disclosure. Exploitable via ``extraBaggageItems``. Mitigation: upgrade to `1.45.0` or later.
|
| CVE-2026-32637 |
|
Path Traversal in github.com/vmware-tanzu/velero (CVE-2026-32637)
path traversal in github.com/vmware-tanzu/velero (CVE-2026-32637). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.18.1` or later.
|
| CVE-2026-77176 |
|
Vulnerability in CVE-2026-77176 (CVE-2026-77176)
vulnerability in CVE-2026-77176 (CVE-2026-77176). Confidential information can be exposed externally.
|
| CVE-2026-77025 |
|
Vulnerability in sqli (CVE-2026-77025)
vulnerability in sqli (CVE-2026-77025). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77022 |
|
Buffer Overflow in c (CVE-2026-77022)
vulnerability in c (CVE-2026-77022). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77020 |
|
Vulnerability in sqli (CVE-2026-77020)
vulnerability in sqli (CVE-2026-77020). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77019 |
|
Vulnerability in sqli (CVE-2026-77019)
vulnerability in sqli (CVE-2026-77019). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72845 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-71492 |
|
Path Traversal in CVE-2026-71492 (CVE-2026-71492)
path traversal in CVE-2026-71492 (CVE-2026-71492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71428 |
|
Open Redirect in CVE-2026-71428 (CVE-2026-71428)
vulnerability in CVE-2026-71428 (CVE-2026-71428). Confidential information can be exposed externally.
|
| CVE-2026-69183 |
|
Vulnerability in CVE-2026-69183 (CVE-2026-69183)
vulnerability in CVE-2026-69183 (CVE-2026-69183). Risk of unauthorized operations or information disclosure. Exploitable via `POST /users/forgotPasswordEmail`.
|
| CVE-2026-65842 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-65842 (CVE-2026-65842)
SSRF in CVE-2026-65842 (CVE-2026-65842). Confidential information can be exposed externally.
|
| CVE-2026-64846 |
|
Vulnerability in CVE-2026-64846 (CVE-2026-64846)
vulnerability in CVE-2026-64846 (CVE-2026-64846). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63481 |
|
Vulnerability in CVE-2026-63481 (CVE-2026-63481)
vulnerability in CVE-2026-63481 (CVE-2026-63481). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`.
|
| CVE-2026-61704 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61704)
SSRF in ssrf (CVE-2026-61704). Confidential information can be exposed externally.
|
| CVE-2026-61625 |
|
Path Traversal in CVE-2026-61625 (CVE-2026-61625)
path traversal in CVE-2026-61625 (CVE-2026-61625). Data can be tampered with by attackers.
|
| CVE-2026-55642 |
|
Vulnerability in CVE-2026-55642 (CVE-2026-55642)
vulnerability in CVE-2026-55642 (CVE-2026-55642). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55586 |
|
Buffer Overflow in c (CVE-2026-55586)
vulnerability in c (CVE-2026-55586). Data can be tampered with by attackers.
|
| CVE-2026-55095 |
|
Vulnerability in CVE-2026-55095 (CVE-2026-55095)
vulnerability in CVE-2026-55095 (CVE-2026-55095). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54770 |
|
Open Redirect in webob (CVE-2026-54770)
vulnerability in webob (CVE-2026-54770). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `1.8.11` or later.
|
| CVE-2026-54616 |
|
Out-of-Bounds Read in cpp (CVE-2026-54616)
vulnerability in cpp (CVE-2026-54616). Confidential information can be exposed externally.
|
| CVE-2026-18309 |
|
Vulnerability in CVE-2026-18309 (CVE-2026-18309)
vulnerability in CVE-2026-18309 (CVE-2026-18309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18308 |
|
Vulnerability in CVE-2026-18308 (CVE-2026-18308)
vulnerability in CVE-2026-18308 (CVE-2026-18308). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18307 |
|
Vulnerability in CVE-2026-18307 (CVE-2026-18307)
vulnerability in CVE-2026-18307 (CVE-2026-18307). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18306 |
|
Vulnerability in CVE-2026-18306 (CVE-2026-18306)
vulnerability in CVE-2026-18306 (CVE-2026-18306). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18305 |
|
Vulnerability in CVE-2026-18305 (CVE-2026-18305)
vulnerability in CVE-2026-18305 (CVE-2026-18305). Successful exploitation can lead to full system takeover.
|