Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82481 |
|
The cohttp package before 6.3.0 for OCaml allows directory traversal.
The cohttp package before 6.3.0 for OCaml allows directory traversal.
|
| CVE-2026-76203 |
|
Vulnerability in CVE-2026-76203 (CVE-2026-76203)
vulnerability in CVE-2026-76203 (CVE-2026-76203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72917 |
|
Vulnerability in CVE-2026-72917 (CVE-2026-72917)
vulnerability in CVE-2026-72917 (CVE-2026-72917). Confidential information can be exposed externally. Exploitable via `POST /api/system/recover-account`.
|
| CVE-2026-69246 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-69246)
vulnerability in guzzlehttp/guzzle (CVE-2026-69246). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-69245 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-69245)
vulnerability in guzzlehttp/guzzle (CVE-2026-69245). Risk of unauthorized operations or information disclosure. Exploitable via ``Domain``. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-62999 |
|
Path Traversal in CVE-2026-62999 (CVE-2026-62999)
path traversal in CVE-2026-62999 (CVE-2026-62999). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15704 |
|
Vulnerability in CVE-2026-15704 (CVE-2026-15704)
vulnerability in CVE-2026-15704 (CVE-2026-15704). Successful exploitation can lead to full system takeover. Exploitable via `GET /shells/`.
|
| CVE-2026-73420 |
|
Vulnerability in @auth/core (CVE-2026-73420)
vulnerability in @auth/core (CVE-2026-73420). Risk of unauthorized operations or information disclosure. Exploitable via ``normalizeIdentifier``. Mitigation: upgrade to `0.41.3` or later.
|
| CVE-2026-7120 |
|
Vulnerability in @fastify/static (CVE-2026-7120)
vulnerability in @fastify/static (CVE-2026-7120). Risk of unauthorized operations or information disclosure. Exploitable via ``allowedPath``. Mitigation: upgrade to `10.1.2` or later.
|
| CVE-2026-73416 |
|
Vulnerability in jupyterlab (CVE-2026-73416)
vulnerability in jupyterlab (CVE-2026-73416). Risk of unauthorized operations or information disclosure. Exploitable via ``blocked_extensions_uris``. Mitigation: upgrade to `4.5.10` or later.
|
| CVE-2026-52747 |
|
Vulnerability in nginx (CVE-2026-52747)
vulnerability in nginx (CVE-2026-52747). Data can be tampered with by attackers.
|
| CVE-2026-49984 |
|
Path Traversal in kestra (CVE-2026-49984)
path traversal in kestra (CVE-2026-49984). Confidential information can be exposed externally. Exploitable via `GET /api/v1/{tenant}/executions/{executionId}/file`. Mitigation: upgrade to `1.0.45` or later.
|
| CVE-2026-48721 |
|
Vulnerability in c (CVE-2026-48721)
vulnerability in c (CVE-2026-48721). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.2026.05.06.15.42.stable` or later.
|
| CVE-2026-42462 |
|
Vulnerability in @fedify/fedify (CVE-2026-42462)
vulnerability in @fedify/fedify (CVE-2026-42462). Data can be tampered with by attackers. Exploitable via ``Activity``. Mitigation: upgrade to `1.9.11` or later.
|
| CVE-2026-45022 |
|
Vulnerability in github.com/go-git/go-git/v6 (CVE-2026-45022)
vulnerability in github.com/go-git/go-git/v6 (CVE-2026-45022). Data can be tampered with by attackers. Exploitable via ``commit``. Mitigation: upgrade to `6.0.0-alpha.3` or later.
|
| CVE-2026-39409 |
|
Vulnerability in hono (CVE-2026-39409)
vulnerability in hono (CVE-2026-39409). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-39364 |
|
Vulnerability in vitejs (CVE-2026-39364)
vulnerability in vitejs (CVE-2026-39364). Confidential information can be exposed externally. Mitigation: upgrade to `7.3.2` or later.
|
| CVE-2026-34786 |
|
Vulnerability in rack (CVE-2026-34786)
vulnerability in rack (CVE-2026-34786). Risk of unauthorized operations or information disclosure. Exploitable via ``header_rules``. Mitigation: upgrade to `3.2.6` or later.
|