Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-47221 |
|
Vulnerability in envoy (CVE-2026-47221)
vulnerability in envoy (CVE-2026-47221). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-47207 |
|
Use-After-Free in envoy (CVE-2026-47207)
vulnerability in envoy (CVE-2026-47207). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-47206 |
|
Vulnerability in CVE-2026-47206 (CVE-2026-47206)
vulnerability in CVE-2026-47206 (CVE-2026-47206). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.39.9` or later.
|
| CVE-2026-47204 |
|
Vulnerability in envoy (CVE-2026-47204)
vulnerability in envoy (CVE-2026-47204). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CGA-33hm-g9cg-gpc8 |
|
CGA-33hm-g9cg-gpc8 |
| CGA-q99c-pqq6-c969 |
|
CGA-q99c-pqq6-c969 |
| RLSA-2023:6712 |
|
Vulnerability in python-wheel (RLSA-2023:6712)
vulnerability in python-wheel (RLSA-2023:6712). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.36.2-8.el9` or later.
|
| RLSA-2023:2870 |
|
Vulnerability in freeradius (RLSA-2023:2870)
vulnerability in freeradius (RLSA-2023:2870). Confidential information can be exposed externally. Mitigation: upgrade to `0:3.0.20-14.module+el8.8.0+1130+46a6e0a1` or later.
|
| RLSA-2023:2860 |
|
Vulnerability in babel (RLSA-2023:2860)
vulnerability in babel (RLSA-2023:2860). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.5.1-10.module+el8.9.0+1531+a18208f5` or later.
|
| CGA-97jr-54h6-qwpw |
|
CGA-97jr-54h6-qwpw |
| GHSA-m282-3m8c-qjwj |
|
Vulnerability in chai-as-assured (GHSA-m282-3m8c-qjwj)
vulnerability in chai-as-assured (GHSA-m282-3m8c-qjwj). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
|
| BELL-CVE-2026-57452 |
|
BELL-CVE-2026-57452 |
| BELL-CVE-2026-57455 |
|
BELL-CVE-2026-57455 |
| BELL-CVE-2026-57454 |
|
BELL-CVE-2026-57454 |
| BELL-CVE-2026-57453 |
|
BELL-CVE-2026-57453 |
| BELL-CVE-2026-57451 |
|
BELL-CVE-2026-57451 |
| BELL-CVE-2026-57456 |
|
BELL-CVE-2026-57456 |
| BELL-CVE-2026-54679 |
|
BELL-CVE-2026-54679 |
| CVE-2026-46623 |
|
Vulnerability in org.openidentityplatform.openam:openam-auth-oauth2 (CVE-2026-46623)
vulnerability in org.openidentityplatform.openam:openam-auth-oauth2 (CVE-2026-46623). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| CVE-2026-46619 |
|
Vulnerability in org.openidentityplatform.openam:openam-auth-msisdn (CVE-2026-46619)
vulnerability in org.openidentityplatform.openam:openam-auth-msisdn (CVE-2026-46619). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| BELL-CVE-2026-56123 |
|
BELL-CVE-2026-56123 |
| CVE-2026-44163 |
|
Vulnerability in fluent-plugin-opentelemetry (CVE-2026-44163)
vulnerability in fluent-plugin-opentelemetry (CVE-2026-44163). Risk of unauthorized operations or information disclosure. Exploitable via ``in_opentelemetry``. Mitigation: upgrade to `0.5.3` or later.
|
| CVE-2026-57231 |
|
Information Disclosure in podman-project (CVE-2026-57231)
vulnerability in podman-project (CVE-2026-57231). Confidential information can be exposed externally. Mitigation: upgrade to `5.8.4` or later.
|
| CVE-2026-56823 |
|
Vulnerability in CVE-2026-56823 (CVE-2026-56823)
vulnerability in CVE-2026-56823 (CVE-2026-56823). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/integrations/webhooks/{webhook_id}/ping`.
|
| CVE-2026-56663 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-56663)
SSRF in ssrf (CVE-2026-56663). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.6.52` or later.
|
| CVE-2026-55677 |
|
Path Traversal in github.com/labstack/echo/v5 (CVE-2026-55677)
path traversal in github.com/labstack/echo/v5 (CVE-2026-55677). Confidential information can be exposed externally. Exploitable via ``StaticDirectoryHandler``. Mitigation: upgrade to `5.2.0` or later.
|
| CVE-2026-54636 |
|
OS Command Injection in dokku (CVE-2026-54636)
OS command injection in dokku (CVE-2026-54636). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.7` or later.
|
| CVE-2026-45408 |
|
OS Command Injection in dokku (CVE-2026-45408)
OS command injection in dokku (CVE-2026-45408). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-45407 |
|
Vulnerability in dokku (CVE-2026-45407)
vulnerability in dokku (CVE-2026-45407). Confidential information can be exposed externally. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-45406 |
|
Vulnerability in dokku (CVE-2026-45406)
vulnerability in dokku (CVE-2026-45406). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-45405 |
|
Vulnerability in dokku (CVE-2026-45405)
vulnerability in dokku (CVE-2026-45405). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-28385 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-28385)
SSRF in ssrf (CVE-2026-28385). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-32423 |
|
Vulnerability in dos (CVE-2025-32423)
vulnerability in dos (CVE-2025-32423). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.32` or later.
|
| CVE-2025-32394 |
|
Vulnerability in dos (CVE-2025-32394)
vulnerability in dos (CVE-2025-32394). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.32` or later.
|
| UBUNTU-CVE-2026-57231 |
|
Vulnerability in podman (UBUNTU-CVE-2026-57231)
vulnerability in podman (UBUNTU-CVE-2026-57231). Confidential information can be exposed externally. Mitigation: upgrade to `5.8.4` or later.
|
| UBUNTU-CVE-2026-55677 |
|
Vulnerability in golang-github-labstack-echo.v2 (UBUNTU-CVE-2026-55677)
vulnerability in golang-github-labstack-echo.v2 (UBUNTU-CVE-2026-55677). Confidential information can be exposed externally. Mitigation: upgrade to `4.15.3` or later.
|
| UBUNTU-CVE-2026-55686 |
|
Vulnerability in podman (UBUNTU-CVE-2026-55686)
vulnerability in podman (UBUNTU-CVE-2026-55686). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.7.1` or later.
|
| CVE-2026-44162 |
|
Vulnerability in fluent-plugin-s3 (CVE-2026-44162)
vulnerability in fluent-plugin-s3 (CVE-2026-44162). Risk of unauthorized operations or information disclosure. Exploitable via ``in_s3``. Mitigation: upgrade to `1.8.5` or later.
|
| PYSEC-2026-236 |
|
Vulnerability in pyphetools (PYSEC-2026-236)
vulnerability in pyphetools (PYSEC-2026-236). Risk of unauthorized operations or information disclosure.
|
| CGA-rp78-v53p-m83p |
|
CGA-rp78-v53p-m83p |
| CGA-43f5-wr5m-xcpp |
|
CGA-43f5-wr5m-xcpp |
| CVE-2026-44161 |
|
SSRF (Server-Side Request Forgery) in fluentd (CVE-2026-44161)
SSRF in fluentd (CVE-2026-44161). Risk of unauthorized operations or information disclosure. Exploitable via ``out_http``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-44160 |
|
Vulnerability in fluentd (CVE-2026-44160)
vulnerability in fluentd (CVE-2026-44160). Risk of unauthorized operations or information disclosure. Exploitable via ``in_http``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-44025 |
|
Vulnerability in fluentd (CVE-2026-44025)
vulnerability in fluentd (CVE-2026-44025). Confidential information can be exposed externally. Exploitable via ``in_monitor_agent``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-44024 |
|
Path Traversal in fluentd (CVE-2026-44024)
path traversal in fluentd (CVE-2026-44024). Successful exploitation can lead to full system takeover. Exploitable via ``path``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-9640 |
|
Authorization Flaw in privilege-escalation (CVE-2026-9640)
vulnerability in privilege-escalation (CVE-2026-9640). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9639 |
|
Vulnerability in dos (CVE-2026-9639)
vulnerability in dos (CVE-2026-9639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12411 |
|
Vulnerability in canonical (CVE-2026-12411)
vulnerability in canonical (CVE-2026-12411). Confidential information can be exposed externally.
|
| UBUNTU-CVE-2026-0685 |
|
Vulnerability in genshi (UBUNTU-CVE-2026-0685)
vulnerability in genshi (UBUNTU-CVE-2026-0685). Successful exploitation can lead to full system takeover.
|
| MAL-2026-6527 |
|
Vulnerability in @immobiliarelabs/backstage-plugin-gitlab-backend (MAL-2026-6527)
vulnerability in @immobiliarelabs/backstage-plugin-gitlab-backend (MAL-2026-6527). Risk of unauthorized operations or information disclosure.
|