Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75476 |
|
Tanium addressed a compression bomb vulnerability in Threat Response.
Tanium addressed a compression bomb vulnerability in Threat Response.
|
| CVE-2026-69222 |
|
Vulnerability in CVE-2026-69222 (CVE-2026-69222)
vulnerability in CVE-2026-69222 (CVE-2026-69222). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68555 |
|
Vulnerability in c (CVE-2026-68555)
vulnerability in c (CVE-2026-68555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68554 |
|
Vulnerability in c (CVE-2026-68554)
vulnerability in c (CVE-2026-68554). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68553 |
|
Vulnerability in c (CVE-2026-68553)
vulnerability in c (CVE-2026-68553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68552 |
|
Vulnerability in c (CVE-2026-68552)
vulnerability in c (CVE-2026-68552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62727 |
|
Vulnerability in CVE-2026-62727 (CVE-2026-62727)
vulnerability in CVE-2026-62727 (CVE-2026-62727). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61556 |
|
Vulnerability in dos (CVE-2026-61556)
vulnerability in dos (CVE-2026-61556). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54743 |
|
Cross-Site Scripting (XSS) in CVE-2026-54743 (CVE-2026-54743)
cross-site scripting in CVE-2026-54743 (CVE-2026-54743). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54741 |
|
Vulnerability in CVE-2026-54741 (CVE-2026-54741)
vulnerability in CVE-2026-54741 (CVE-2026-54741). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54740 |
|
Vulnerability in CVE-2026-54740 (CVE-2026-54740)
vulnerability in CVE-2026-54740 (CVE-2026-54740). Data can be tampered with by attackers.
|
| CVE-2026-54739 |
|
Vulnerability in CVE-2026-54739 (CVE-2026-54739)
vulnerability in CVE-2026-54739 (CVE-2026-54739). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54738 |
|
Vulnerability in nginx (CVE-2026-54738)
vulnerability in nginx (CVE-2026-54738). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v4/account/auth/register`.
|
| CVE-2026-53549 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-53549 (CVE-2026-53549)
SSRF in CVE-2026-53549 (CVE-2026-53549). Confidential information can be exposed externally. Exploitable via `POST /host/db/proxy/test`.
|
| CVE-2026-53548 |
|
Vulnerability in CVE-2026-53548 (CVE-2026-53548)
vulnerability in CVE-2026-53548 (CVE-2026-53548). Confidential information can be exposed externally. Exploitable via `GET /host/db/host/`.
|
| CVE-2026-53547 |
|
Vulnerability in CVE-2026-53547 (CVE-2026-53547)
vulnerability in CVE-2026-53547 (CVE-2026-53547). Successful exploitation can lead to full system takeover. Exploitable via `POST /database/export`.
|
| CVE-2026-53546 |
|
Vulnerability in CVE-2026-53546 (CVE-2026-53546)
vulnerability in CVE-2026-53546 (CVE-2026-53546). Confidential information can be exposed externally.
|
| CVE-2026-53545 |
|
OS Command Injection in CVE-2026-53545 (CVE-2026-53545)
OS command injection in CVE-2026-53545 (CVE-2026-53545). Successful exploitation can lead to full system takeover. Exploitable via `DELETE /ssh/tunnel/disconnect/`.
|
| CVE-2026-53542 |
|
OS Command Injection in CVE-2026-53542 (CVE-2026-53542)
OS command injection in CVE-2026-53542 (CVE-2026-53542). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4937 |
|
Vulnerability in ibm (CVE-2026-4937)
vulnerability in ibm (CVE-2026-4937). Confidential information can be exposed externally.
|
| CVE-2026-4936 |
|
Vulnerability in ibm (CVE-2026-4936)
vulnerability in ibm (CVE-2026-4936). Confidential information can be exposed externally.
|
| CVE-2026-18849 |
|
Path Traversal in CVE-2026-18849 (CVE-2026-18849)
path traversal in CVE-2026-18849 (CVE-2026-18849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18544 |
|
Vulnerability in CVE-2026-18544 (CVE-2026-18544)
vulnerability in CVE-2026-18544 (CVE-2026-18544). Confidential information can be exposed externally.
|
| CVE-2026-18102 |
|
Vulnerability in ibm (CVE-2026-18102)
vulnerability in ibm (CVE-2026-18102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17015 |
|
Out-of-Bounds Read in dos (CVE-2026-17015)
vulnerability in dos (CVE-2026-17015). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14978 |
|
Vulnerability in CVE-2026-14978 (CVE-2026-14978)
vulnerability in CVE-2026-14978 (CVE-2026-14978). Confidential information can be exposed externally.
|
| CVE-2026-14514 |
|
Vulnerability in dos (CVE-2026-14514)
vulnerability in dos (CVE-2026-14514). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12634 |
|
Out-of-Bounds Write in c (CVE-2026-12634)
out-of-bounds write in c (CVE-2026-12634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12633 |
|
Out-of-Bounds Write in c (CVE-2026-12633)
out-of-bounds write in c (CVE-2026-12633). Data can be tampered with by attackers.
|
| CVE-2026-12522 |
|
Out-of-Bounds Write in c (CVE-2026-12522)
out-of-bounds write in c (CVE-2026-12522). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11617 |
|
Tanium addressed a compression bomb vulnerability in Findings.
Tanium addressed a compression bomb vulnerability in Findings.
|
| CVE-2026-63188 |
|
Path Traversal in @logto/tunnel (CVE-2026-63188)
path traversal in @logto/tunnel (CVE-2026-63188). Risk of unauthorized operations or information disclosure. Exploitable via ``request.url``. Mitigation: upgrade to `0.3.9` or later.
|
| CVE-2026-61712 |
|
Vulnerability in github.com/moby/buildkit (CVE-2026-61712)
vulnerability in github.com/moby/buildkit (CVE-2026-61712). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.31.1` or later.
|
| CVE-2026-61711 |
|
Vulnerability in github.com/moby/buildkit (CVE-2026-61711)
vulnerability in github.com/moby/buildkit (CVE-2026-61711). Risk of unauthorized operations or information disclosure. Exploitable via ``security.insecure``. Mitigation: upgrade to `0.31.1` or later.
|
| CVE-2026-76647 |
|
Information Disclosure in CVE-2026-76647 (CVE-2026-76647)
vulnerability in CVE-2026-76647 (CVE-2026-76647). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76574 |
|
Vulnerability in sqli (CVE-2026-76574)
vulnerability in sqli (CVE-2026-76574). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76572 |
|
Vulnerability in CVE-2026-76572 (CVE-2026-76572)
vulnerability in CVE-2026-76572 (CVE-2026-76572). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75593 |
|
Path Traversal in CVE-2026-75593 (CVE-2026-75593)
path traversal in CVE-2026-75593 (CVE-2026-75593). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75112 |
|
Vulnerability in CVE-2026-75112 (CVE-2026-75112)
vulnerability in CVE-2026-75112 (CVE-2026-75112). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74228 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-74227 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-74226 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-68901 |
|
Vulnerability in CVE-2026-68901 (CVE-2026-68901)
vulnerability in CVE-2026-68901 (CVE-2026-68901). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68900 |
|
Cross-Site Scripting (XSS) in CVE-2026-68900 (CVE-2026-68900)
cross-site scripting in CVE-2026-68900 (CVE-2026-68900). Confidential information can be exposed externally.
|
| CVE-2026-68899 |
|
Unrestricted File Upload in CVE-2026-68899 (CVE-2026-68899)
vulnerability in CVE-2026-68899 (CVE-2026-68899). Confidential information can be exposed externally.
|
| CVE-2026-68561 |
|
Privilege Escalation in CVE-2026-68561 (CVE-2026-68561)
vulnerability in CVE-2026-68561 (CVE-2026-68561). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68560 |
|
OS Command Injection in c (CVE-2026-68560)
OS command injection in c (CVE-2026-68560). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68559 |
|
Vulnerability in CVE-2026-68559 (CVE-2026-68559)
vulnerability in CVE-2026-68559 (CVE-2026-68559). Confidential information can be exposed externally.
|
| CVE-2026-68558 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-68558 (CVE-2026-68558)
SSRF in CVE-2026-68558 (CVE-2026-68558). Confidential information can be exposed externally.
|
| CVE-2026-67189 |
|
Cross-Site Scripting (XSS) in CVE-2026-67189 (CVE-2026-67189)
cross-site scripting in CVE-2026-67189 (CVE-2026-67189). Risk of unauthorized operations or information disclosure.
|