Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-13757 Vulnerability in redhat (CVE-2026-13757)
vulnerability in redhat (CVE-2026-13757). Risk of unauthorized operations or information disclosure.
CVE-2026-57958 Cross-Site Scripting (XSS) in laravel (CVE-2026-57958)
cross-site scripting in laravel (CVE-2026-57958). Risk of unauthorized operations or information disclosure.
CVE-2026-57951 Authorization Flaw in its-a-feature (CVE-2026-57951)
vulnerability in its-a-feature (CVE-2026-57951). Confidential information can be exposed externally.
CVE-2026-57950 ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
CVE-2026-57959 Vulnerability in CVE-2026-57959 (CVE-2026-57959)
vulnerability in CVE-2026-57959 (CVE-2026-57959). Data can be tampered with by attackers.
CVE-2026-57949 Vulnerability in vue (CVE-2026-57949)
vulnerability in vue (CVE-2026-57949). Confidential information can be exposed externally. Exploitable via `GET /admin-api/crm/follow-up-record/get`.
CVE-2026-57948 Vulnerability in CVE-2026-57948 (CVE-2026-57948)
vulnerability in CVE-2026-57948 (CVE-2026-57948). Confidential information can be exposed externally.
CVE-2026-57952 Vulnerability in its-a-feature (CVE-2026-57952)
vulnerability in its-a-feature (CVE-2026-57952). Confidential information can be exposed externally.
CVE-2026-57947 Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook...
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook...
CVE-2026-57953 Authorization Flaw in its-a-feature (CVE-2026-57953)
vulnerability in its-a-feature (CVE-2026-57953). Risk of unauthorized operations or information disclosure.
CVE-2026-57954 Vulnerability in CVE-2026-57954 (CVE-2026-57954)
vulnerability in CVE-2026-57954 (CVE-2026-57954). Risk of unauthorized operations or information disclosure.
CVE-2026-57960 Vulnerability in CVE-2026-57960 (CVE-2026-57960)
vulnerability in CVE-2026-57960 (CVE-2026-57960). Confidential information can be exposed externally. Exploitable via `GET /api/public/check-in-lists/{short_id}/attendees`.
CVE-2026-57957 Vulnerability in CVE-2026-57957 (CVE-2026-57957)
vulnerability in CVE-2026-57957 (CVE-2026-57957). Risk of unauthorized operations or information disclosure.
CVE-2026-57955 SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers...
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers...
CVE-2026-57956 Vulnerability in CVE-2026-57956 (CVE-2026-57956)
vulnerability in CVE-2026-57956 (CVE-2026-57956). Data can be tampered with by attackers.
CVE-2026-57946 Vulnerability in CVE-2026-57946 (CVE-2026-57946)
vulnerability in CVE-2026-57946 (CVE-2026-57946). Risk of unauthorized operations or information disclosure.
CVE-2026-56781 Vulnerability in CVE-2026-56781 (CVE-2026-56781)
vulnerability in CVE-2026-56781 (CVE-2026-56781). Risk of unauthorized operations or information disclosure.
CVE-2026-56285 Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
CVE-2026-56783 Vulnerability in CVE-2026-56783 (CVE-2026-56783)
vulnerability in CVE-2026-56783 (CVE-2026-56783). Confidential information can be exposed externally. Exploitable via `GET /api/v1/targets`.
CVE-2026-13591 Vulnerability in CVE-2026-13591 (CVE-2026-13591)
vulnerability in CVE-2026-13591 (CVE-2026-13591). Risk of unauthorized operations or information disclosure.
CVE-2026-56780 Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api...
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api...
CVE-2026-56782 Vulnerability in CVE-2026-56782 (CVE-2026-56782)
vulnerability in CVE-2026-56782 (CVE-2026-56782). Successful exploitation can lead to full system takeover.
CVE-2026-13590 Buffer Overflow in CVE-2026-13590 (CVE-2026-13590)
vulnerability in CVE-2026-13590 (CVE-2026-13590). Risk of unauthorized operations or information disclosure.
CVE-2026-57942 Vulnerability in CVE-2026-57942 (CVE-2026-57942)
vulnerability in CVE-2026-57942 (CVE-2026-57942). Risk of unauthorized operations or information disclosure.
CVE-2026-13592 Buffer Overflow in CVE-2026-13592 (CVE-2026-13592)
vulnerability in CVE-2026-13592 (CVE-2026-13592). Risk of unauthorized operations or information disclosure.
CVE-2026-57945 Vulnerability in CVE-2026-57945 (CVE-2026-57945)
vulnerability in CVE-2026-57945 (CVE-2026-57945). Risk of unauthorized operations or information disclosure.
CVE-2026-11720 Path Traversal in path-traversal (CVE-2026-11720)
path traversal in path-traversal (CVE-2026-11720). Confidential information can be exposed externally.
CVE-2026-57943 Vulnerability in CVE-2026-57943 (CVE-2026-57943)
vulnerability in CVE-2026-57943 (CVE-2026-57943). Confidential information can be exposed externally.
CVE-2026-36848 Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
CVE-2026-13588 Buffer Overflow in cpp (CVE-2026-13588)
vulnerability in cpp (CVE-2026-13588). Risk of unauthorized operations or information disclosure.
CVE-2026-13751 Vulnerability in snowflake (CVE-2026-13751)
vulnerability in snowflake (CVE-2026-13751). Risk of unauthorized operations or information disclosure.
CVE-2026-13589 Buffer Overflow in cpp (CVE-2026-13589)
vulnerability in cpp (CVE-2026-13589). Risk of unauthorized operations or information disclosure.
CVE-2026-13752 SQL Injection in snowflake (CVE-2026-13752)
SQL injection in snowflake (CVE-2026-13752). Confidential information can be exposed externally.
CVE-2026-12912 Vulnerability in dos (CVE-2026-12912)
vulnerability in dos (CVE-2026-12912). Successful exploitation can lead to full system takeover.
USN-8481-1 Vulnerability in nss (USN-8481-1)
vulnerability in nss (USN-8481-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:3.98-0ubuntu0.22.04.4` or later.
CVE-2026-48717 Vulnerability in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-48717)
vulnerability in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-48717). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
CVE-2026-47426 Authentication Bypass in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-47426)
authentication bypass in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-47426). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
CVE-2026-47424 Vulnerability in org.openidentityplatform.openam:openam-scripting (CVE-2026-47424)
vulnerability in org.openidentityplatform.openam:openam-scripting (CVE-2026-47424). Risk of unauthorized operations or information disclosure. Exploitable via ``RealmAdmin``. Mitigation: upgrade to `16.1.1` or later.
USN-8480-1 Vulnerability in sqlite3 (USN-8480-1)
vulnerability in sqlite3 (USN-8480-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.37.2-2ubuntu0.6` or later.
CVE-2026-12672 Vulnerability in CVE-2026-12672 (CVE-2026-12672)
vulnerability in CVE-2026-12672 (CVE-2026-12672). Risk of unauthorized operations or information disclosure.
PYSEC-2026-584 Vulnerability in rlask (PYSEC-2026-584)
vulnerability in rlask (PYSEC-2026-584). Risk of unauthorized operations or information disclosure.
GHSA-8cxm-2pmw-c822 Vulnerability in @sixt-payment/form-react (GHSA-8cxm-2pmw-c822)
vulnerability in @sixt-payment/form-react (GHSA-8cxm-2pmw-c822). Risk of unauthorized operations or information disclosure.
GHSA-5x3r-97g5-r9j5 Vulnerability in @cseo-hr/trpweb-shared (GHSA-5x3r-97g5-r9j5)
vulnerability in @cseo-hr/trpweb-shared (GHSA-5x3r-97g5-r9j5). Risk of unauthorized operations or information disclosure.
GHSA-m7gq-xcwc-78ff Vulnerability in @bodata/angular-client (GHSA-m7gq-xcwc-78ff)
vulnerability in @bodata/angular-client (GHSA-m7gq-xcwc-78ff). Risk of unauthorized operations or information disclosure.
GHSA-3vmg-w948-phr5 Vulnerability in @bc-workspace/utils (GHSA-3vmg-w948-phr5)
vulnerability in @bc-workspace/utils (GHSA-3vmg-w948-phr5). Risk of unauthorized operations or information disclosure.
GHSA-cf57-g4p6-cqjh Vulnerability in @tbe-ui/ides (GHSA-cf57-g4p6-cqjh)
vulnerability in @tbe-ui/ides (GHSA-cf57-g4p6-cqjh). Risk of unauthorized operations or information disclosure.
GHSA-4gpj-m85h-j7rq Vulnerability in @report-portal/service-ui (GHSA-4gpj-m85h-j7rq)
vulnerability in @report-portal/service-ui (GHSA-4gpj-m85h-j7rq). Risk of unauthorized operations or information disclosure.
GHSA-h7fx-c9v6-pg77 Vulnerability in @react-thee/rapier (GHSA-h7fx-c9v6-pg77)
vulnerability in @react-thee/rapier (GHSA-h7fx-c9v6-pg77). Risk of unauthorized operations or information disclosure.
GHSA-jv69-xjcr-5hx9 Vulnerability in @postman-app-monolith/renderer (GHSA-jv69-xjcr-5hx9)
vulnerability in @postman-app-monolith/renderer (GHSA-jv69-xjcr-5hx9). Risk of unauthorized operations or information disclosure.
GHSA-mfvg-7g48-p7c2 Vulnerability in @postidigital-feature/oneaccount-orgadmin-front (GHSA-mfvg-7g48-p7c2)
vulnerability in @postidigital-feature/oneaccount-orgadmin-front (GHSA-mfvg-7g48-p7c2). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →