Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13757 |
|
Vulnerability in redhat (CVE-2026-13757)
vulnerability in redhat (CVE-2026-13757). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57958 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-57958)
cross-site scripting in laravel (CVE-2026-57958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57951 |
|
Authorization Flaw in its-a-feature (CVE-2026-57951)
vulnerability in its-a-feature (CVE-2026-57951). Confidential information can be exposed externally.
|
| CVE-2026-57950 |
|
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
|
| CVE-2026-57959 |
|
Vulnerability in CVE-2026-57959 (CVE-2026-57959)
vulnerability in CVE-2026-57959 (CVE-2026-57959). Data can be tampered with by attackers.
|
| CVE-2026-57949 |
|
Vulnerability in vue (CVE-2026-57949)
vulnerability in vue (CVE-2026-57949). Confidential information can be exposed externally. Exploitable via `GET /admin-api/crm/follow-up-record/get`.
|
| CVE-2026-57948 |
|
Vulnerability in CVE-2026-57948 (CVE-2026-57948)
vulnerability in CVE-2026-57948 (CVE-2026-57948). Confidential information can be exposed externally.
|
| CVE-2026-57952 |
|
Vulnerability in its-a-feature (CVE-2026-57952)
vulnerability in its-a-feature (CVE-2026-57952). Confidential information can be exposed externally.
|
| CVE-2026-57947 |
|
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook...
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook...
|
| CVE-2026-57953 |
|
Authorization Flaw in its-a-feature (CVE-2026-57953)
vulnerability in its-a-feature (CVE-2026-57953). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57954 |
|
Vulnerability in CVE-2026-57954 (CVE-2026-57954)
vulnerability in CVE-2026-57954 (CVE-2026-57954). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57960 |
|
Vulnerability in CVE-2026-57960 (CVE-2026-57960)
vulnerability in CVE-2026-57960 (CVE-2026-57960). Confidential information can be exposed externally. Exploitable via `GET /api/public/check-in-lists/{short_id}/attendees`.
|
| CVE-2026-57957 |
|
Vulnerability in CVE-2026-57957 (CVE-2026-57957)
vulnerability in CVE-2026-57957 (CVE-2026-57957). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57955 |
|
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers...
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers...
|
| CVE-2026-57956 |
|
Vulnerability in CVE-2026-57956 (CVE-2026-57956)
vulnerability in CVE-2026-57956 (CVE-2026-57956). Data can be tampered with by attackers.
|
| CVE-2026-57946 |
|
Vulnerability in CVE-2026-57946 (CVE-2026-57946)
vulnerability in CVE-2026-57946 (CVE-2026-57946). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56781 |
|
Vulnerability in CVE-2026-56781 (CVE-2026-56781)
vulnerability in CVE-2026-56781 (CVE-2026-56781). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56285 |
|
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
|
| CVE-2026-56783 |
|
Vulnerability in CVE-2026-56783 (CVE-2026-56783)
vulnerability in CVE-2026-56783 (CVE-2026-56783). Confidential information can be exposed externally. Exploitable via `GET /api/v1/targets`.
|
| CVE-2026-13591 |
|
Vulnerability in CVE-2026-13591 (CVE-2026-13591)
vulnerability in CVE-2026-13591 (CVE-2026-13591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56780 |
|
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api...
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api...
|
| CVE-2026-56782 |
|
Vulnerability in CVE-2026-56782 (CVE-2026-56782)
vulnerability in CVE-2026-56782 (CVE-2026-56782). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13590 |
|
Buffer Overflow in CVE-2026-13590 (CVE-2026-13590)
vulnerability in CVE-2026-13590 (CVE-2026-13590). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57942 |
|
Vulnerability in CVE-2026-57942 (CVE-2026-57942)
vulnerability in CVE-2026-57942 (CVE-2026-57942). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13592 |
|
Buffer Overflow in CVE-2026-13592 (CVE-2026-13592)
vulnerability in CVE-2026-13592 (CVE-2026-13592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57945 |
|
Vulnerability in CVE-2026-57945 (CVE-2026-57945)
vulnerability in CVE-2026-57945 (CVE-2026-57945). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11720 |
|
Path Traversal in path-traversal (CVE-2026-11720)
path traversal in path-traversal (CVE-2026-11720). Confidential information can be exposed externally.
|
| CVE-2026-57943 |
|
Vulnerability in CVE-2026-57943 (CVE-2026-57943)
vulnerability in CVE-2026-57943 (CVE-2026-57943). Confidential information can be exposed externally.
|
| CVE-2026-36848 |
|
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
|
| CVE-2026-13588 |
|
Buffer Overflow in cpp (CVE-2026-13588)
vulnerability in cpp (CVE-2026-13588). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13751 |
|
Vulnerability in snowflake (CVE-2026-13751)
vulnerability in snowflake (CVE-2026-13751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13589 |
|
Buffer Overflow in cpp (CVE-2026-13589)
vulnerability in cpp (CVE-2026-13589). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13752 |
|
SQL Injection in snowflake (CVE-2026-13752)
SQL injection in snowflake (CVE-2026-13752). Confidential information can be exposed externally.
|
| CVE-2026-12912 |
|
Vulnerability in dos (CVE-2026-12912)
vulnerability in dos (CVE-2026-12912). Successful exploitation can lead to full system takeover.
|
| USN-8481-1 |
|
Vulnerability in nss (USN-8481-1)
vulnerability in nss (USN-8481-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2:3.98-0ubuntu0.22.04.4` or later.
|
| CVE-2026-48717 |
|
Vulnerability in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-48717)
vulnerability in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-48717). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| CVE-2026-47426 |
|
Authentication Bypass in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-47426)
authentication bypass in org.openidentityplatform.openam:openam-oauth2 (CVE-2026-47426). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| CVE-2026-47424 |
|
Vulnerability in org.openidentityplatform.openam:openam-scripting (CVE-2026-47424)
vulnerability in org.openidentityplatform.openam:openam-scripting (CVE-2026-47424). Risk of unauthorized operations or information disclosure. Exploitable via ``RealmAdmin``. Mitigation: upgrade to `16.1.1` or later.
|
| USN-8480-1 |
|
Vulnerability in sqlite3 (USN-8480-1)
vulnerability in sqlite3 (USN-8480-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.37.2-2ubuntu0.6` or later.
|
| CVE-2026-12672 |
|
Vulnerability in CVE-2026-12672 (CVE-2026-12672)
vulnerability in CVE-2026-12672 (CVE-2026-12672). Risk of unauthorized operations or information disclosure.
|
| PYSEC-2026-584 |
|
Vulnerability in rlask (PYSEC-2026-584)
vulnerability in rlask (PYSEC-2026-584). Risk of unauthorized operations or information disclosure.
|
| GHSA-8cxm-2pmw-c822 |
|
Vulnerability in @sixt-payment/form-react (GHSA-8cxm-2pmw-c822)
vulnerability in @sixt-payment/form-react (GHSA-8cxm-2pmw-c822). Risk of unauthorized operations or information disclosure.
|
| GHSA-5x3r-97g5-r9j5 |
|
Vulnerability in @cseo-hr/trpweb-shared (GHSA-5x3r-97g5-r9j5)
vulnerability in @cseo-hr/trpweb-shared (GHSA-5x3r-97g5-r9j5). Risk of unauthorized operations or information disclosure.
|
| GHSA-m7gq-xcwc-78ff |
|
Vulnerability in @bodata/angular-client (GHSA-m7gq-xcwc-78ff)
vulnerability in @bodata/angular-client (GHSA-m7gq-xcwc-78ff). Risk of unauthorized operations or information disclosure.
|
| GHSA-3vmg-w948-phr5 |
|
Vulnerability in @bc-workspace/utils (GHSA-3vmg-w948-phr5)
vulnerability in @bc-workspace/utils (GHSA-3vmg-w948-phr5). Risk of unauthorized operations or information disclosure.
|
| GHSA-cf57-g4p6-cqjh |
|
Vulnerability in @tbe-ui/ides (GHSA-cf57-g4p6-cqjh)
vulnerability in @tbe-ui/ides (GHSA-cf57-g4p6-cqjh). Risk of unauthorized operations or information disclosure.
|
| GHSA-4gpj-m85h-j7rq |
|
Vulnerability in @report-portal/service-ui (GHSA-4gpj-m85h-j7rq)
vulnerability in @report-portal/service-ui (GHSA-4gpj-m85h-j7rq). Risk of unauthorized operations or information disclosure.
|
| GHSA-h7fx-c9v6-pg77 |
|
Vulnerability in @react-thee/rapier (GHSA-h7fx-c9v6-pg77)
vulnerability in @react-thee/rapier (GHSA-h7fx-c9v6-pg77). Risk of unauthorized operations or information disclosure.
|
| GHSA-jv69-xjcr-5hx9 |
|
Vulnerability in @postman-app-monolith/renderer (GHSA-jv69-xjcr-5hx9)
vulnerability in @postman-app-monolith/renderer (GHSA-jv69-xjcr-5hx9). Risk of unauthorized operations or information disclosure.
|
| GHSA-mfvg-7g48-p7c2 |
|
Vulnerability in @postidigital-feature/oneaccount-orgadmin-front (GHSA-mfvg-7g48-p7c2)
vulnerability in @postidigital-feature/oneaccount-orgadmin-front (GHSA-mfvg-7g48-p7c2). Risk of unauthorized operations or information disclosure.
|