Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16732 |
|
Vulnerability in csrf (CVE-2026-16732)
vulnerability in csrf (CVE-2026-16732). Confidential information can be exposed externally.
|
| CVE-2026-25552 |
|
Vulnerability in nginx (CVE-2026-25552)
vulnerability in nginx (CVE-2026-25552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63220 |
|
Vulnerability in codeigniter4/framework (CVE-2026-63220)
vulnerability in codeigniter4/framework (CVE-2026-63220). Risk of unauthorized operations or information disclosure. Exploitable via ``forceGlobalSecureRequests``. Mitigation: upgrade to `4.7.4` or later.
|
| CVE-2026-50243 |
|
Vulnerability in nlnetlabs (CVE-2026-50243)
vulnerability in nlnetlabs (CVE-2026-50243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64619 |
|
Vulnerability in CVE-2026-64619 (CVE-2026-64619)
vulnerability in CVE-2026-64619 (CVE-2026-64619). Confidential information can be exposed externally.
|
| CVE-2026-63770 |
|
Vulnerability in CVE-2026-63770 (CVE-2026-63770)
vulnerability in CVE-2026-63770 (CVE-2026-63770). Confidential information can be exposed externally.
|
| CVE-2026-9561 |
|
Vulnerability in dos (CVE-2026-9561)
vulnerability in dos (CVE-2026-9561). Data can be tampered with by attackers.
|
| CVE-2026-55641 |
|
Vulnerability in 9router (CVE-2026-55641)
vulnerability in 9router (CVE-2026-55641). Confidential information can be exposed externally. Exploitable via `POST /v1/search`. Mitigation: upgrade to `0.5.2` or later.
|
| CVE-2026-58122 |
|
Vulnerability in CVE-2026-58122 (CVE-2026-58122)
vulnerability in CVE-2026-58122 (CVE-2026-58122). Confidential information can be exposed externally.
|
| CVE-2026-59897 |
|
Vulnerability in hono (CVE-2026-59897)
vulnerability in hono (CVE-2026-59897). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-59999 |
|
Vulnerability in openbsd (CVE-2026-59999)
vulnerability in openbsd (CVE-2026-59999). Data can be tampered with by attackers.
|
| CVE-2026-46466 |
|
Vulnerability in dell (CVE-2026-46466)
vulnerability in dell (CVE-2026-46466). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57942 |
|
Vulnerability in CVE-2026-57942 (CVE-2026-57942)
vulnerability in CVE-2026-57942 (CVE-2026-57942). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12249 |
|
Vulnerability in CVE-2026-12249 (CVE-2026-12249)
vulnerability in CVE-2026-12249 (CVE-2026-12249). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48772 |
|
Vulnerability in proxysql (CVE-2026-48772)
vulnerability in proxysql (CVE-2026-48772). Confidential information can be exposed externally. Exploitable via ``UNKNOWN``.
|
| CVE-2026-44046 |
|
Vulnerability in apisix (CVE-2026-44046)
vulnerability in apisix (CVE-2026-44046). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-54289 |
|
Vulnerability in hono (CVE-2026-54289)
vulnerability in hono (CVE-2026-54289). Risk of unauthorized operations or information disclosure. Exploitable via ``Headers.set``. Mitigation: upgrade to `4.12.25` or later.
|
| CVE-2020-37248 |
|
Vulnerability in CVE-2020-37248 (CVE-2020-37248)
vulnerability in CVE-2020-37248 (CVE-2020-37248). Confidential information can be exposed externally.
|
| CVE-2026-46415 |
|
Vulnerability in pkg.jsn.cam/caddy-defender (CVE-2026-46415)
vulnerability in pkg.jsn.cam/caddy-defender (CVE-2026-46415). Confidential information can be exposed externally. Exploitable via ``r.RemoteAddr``. Mitigation: upgrade to `0.10.1` or later.
|
| CVE-2026-43634 |
|
Vulnerability in CVE-2026-43634 (CVE-2026-43634)
vulnerability in CVE-2026-43634 (CVE-2026-43634). Data can be tampered with by attackers.
|
| CVE-2026-44183 |
|
Vulnerability in CVE-2026-44183 (CVE-2026-44183)
vulnerability in CVE-2026-44183 (CVE-2026-44183). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.9.10` or later.
|
| CVE-2026-35391 |
|
Vulnerability in bulwarkmail (CVE-2026-35391)
vulnerability in bulwarkmail (CVE-2026-35391). Data can be tampered with by attackers. Mitigation: upgrade to `1.4.11` or later.
|
| CVE-2026-35507 |
|
Shynet before 0.14.0 allows Host header injection in the password reset flow.
Shynet before 0.14.0 allows Host header injection in the password reset flow.
|