Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-79939 |
|
Vulnerability in CVE-2026-79939 (CVE-2026-79939)
vulnerability in CVE-2026-79939 (CVE-2026-79939). Data can be tampered with by attackers.
|
| CVE-2026-75038 |
|
Vulnerability in CVE-2026-75038 (CVE-2026-75038)
vulnerability in CVE-2026-75038 (CVE-2026-75038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55168 |
|
Vulnerability in CVE-2026-55168 (CVE-2026-55168)
vulnerability in CVE-2026-55168 (CVE-2026-55168). Data can be tampered with by attackers. Exploitable via `PUT /api/user-config/demoapp3`.
|
| CVE-2026-63125 |
|
Vulnerability in CVE-2026-63125 (CVE-2026-63125)
vulnerability in CVE-2026-63125 (CVE-2026-63125). Successful exploitation can lead to full system takeover. Exploitable via ``can_create_images``.
|
| CVE-2026-64846 |
|
Vulnerability in CVE-2026-64846 (CVE-2026-64846)
vulnerability in CVE-2026-64846 (CVE-2026-64846). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32657 |
|
Vulnerability in CVE-2026-32657 (CVE-2026-32657)
vulnerability in CVE-2026-32657 (CVE-2026-32657). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47766 |
|
Vulnerability in c (CVE-2026-47766)
vulnerability in c (CVE-2026-47766). Risk of unauthorized operations or information disclosure. Exploitable via ``O_NOFOLLOW``.
|
| CVE-2026-53802 |
|
Vulnerability in CVE-2026-53802 (CVE-2026-53802)
vulnerability in CVE-2026-53802 (CVE-2026-53802). Confidential information can be exposed externally.
|
| CVE-2026-62992 |
|
Path Traversal in smarty/smarty (CVE-2026-62992)
path traversal in smarty/smarty (CVE-2026-62992). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.8.2` or later.
|
| CVE-2026-54574 |
|
Vulnerability in proot-distro (CVE-2026-54574)
vulnerability in proot-distro (CVE-2026-54574). Confidential information can be exposed externally. Exploitable via ``member.linkname``. Mitigation: upgrade to `5.1.5` or later.
|
| CVE-2026-56748 |
|
Vulnerability in cribl (CVE-2026-56748)
vulnerability in cribl (CVE-2026-56748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17459 |
|
Vulnerability in CVE-2026-17459 (CVE-2026-17459)
vulnerability in CVE-2026-17459 (CVE-2026-17459). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65010 |
|
Vulnerability in privilege-escalation (CVE-2026-65010)
vulnerability in privilege-escalation (CVE-2026-65010). Data can be tampered with by attackers.
|
| CVE-2026-12080 |
|
Vulnerability in CVE-2026-12080 (CVE-2026-12080)
vulnerability in CVE-2026-12080 (CVE-2026-12080). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59674 |
|
Vulnerability in CVE-2026-59674 (CVE-2026-59674)
vulnerability in CVE-2026-59674 (CVE-2026-59674). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39822 |
|
Vulnerability in golang (CVE-2026-39822)
vulnerability in golang (CVE-2026-39822). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14699 |
|
Vulnerability in CVE-2026-14699 (CVE-2026-14699)
vulnerability in CVE-2026-14699 (CVE-2026-14699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13748 |
|
Path Traversal in snowflake (CVE-2026-13748)
path traversal in snowflake (CVE-2026-13748). Confidential information can be exposed externally.
|
| CVE-2026-56876 |
|
Path Traversal in extract-zip (CVE-2026-56876)
path traversal in extract-zip (CVE-2026-56876). Confidential information can be exposed externally.
|
| CVE-2026-13218 |
|
Vulnerability in kubevirt (CVE-2026-13218)
vulnerability in kubevirt (CVE-2026-13218). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13201 |
|
Vulnerability in kubevirt (CVE-2026-13201)
vulnerability in kubevirt (CVE-2026-13201). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12958 |
|
Vulnerability in CVE-2026-12958 (CVE-2026-12958)
vulnerability in CVE-2026-12958 (CVE-2026-12958). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52811 |
|
Path Traversal in gogs.io/gogs (CVE-2026-52811)
path traversal in gogs.io/gogs (CVE-2026-52811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56815 |
|
Vulnerability in CVE-2026-56815 (CVE-2026-56815)
vulnerability in CVE-2026-56815 (CVE-2026-56815). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41579 |
|
Vulnerability in github.com/opencontainers/runc (CVE-2026-41579)
vulnerability in github.com/opencontainers/runc (CVE-2026-41579). Risk of unauthorized operations or information disclosure. Exploitable via ``setupPtmx``. Mitigation: upgrade to `1.5.0-rc.3` or later.
|
| CVE-2026-55447 |
|
Information Disclosure in langflow (CVE-2026-55447)
vulnerability in langflow (CVE-2026-55447). Successful exploitation can lead to full system takeover. Exploitable via ``BaseFileComponent``. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2026-53489 |
|
Vulnerability in github.com/containerd/containerd/v2 (CVE-2026-53489)
vulnerability in github.com/containerd/containerd/v2 (CVE-2026-53489). Confidential information can be exposed externally. Mitigation: upgrade to `2.1.9, 2.2.5, 2.3.2` or later.
|
| CVE-2026-49248 |
|
Vulnerability in CVE-2026-49248 (CVE-2026-49248)
vulnerability in CVE-2026-49248 (CVE-2026-49248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55686 |
|
Vulnerability in github.com/containers/podman/v5 (CVE-2026-55686)
vulnerability in github.com/containers/podman/v5 (CVE-2026-55686). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.7.1` or later.
|
| CVE-2026-54420 KEV |
|
[KEV] Vulnerability in litespeed (CVE-2026-54420)
vulnerability in litespeed (CVE-2026-54420). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2025-43278 |
|
Vulnerability in apple (CVE-2025-43278)
vulnerability in apple (CVE-2025-43278). Confidential information can be exposed externally.
|
| CVE-2026-47763 |
|
Vulnerability in pdm (CVE-2026-47763)
vulnerability in pdm (CVE-2026-47763). Risk of unauthorized operations or information disclosure. Exploitable via ``pdm.toml``. Mitigation: upgrade to `2.27.0` or later.
|
| CVE-2026-5223 |
|
Vulnerability in cargo (CVE-2026-5223)
vulnerability in cargo (CVE-2026-5223). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.97.0` or later.
|
| CVE-2026-42306 |
|
Vulnerability in github.com/docker/docker (CVE-2026-42306)
vulnerability in github.com/docker/docker (CVE-2026-42306). Data can be tampered with by attackers. Exploitable via `PUT /containers/{id}/archive`. Mitigation: upgrade to `2.0.0-beta.14` or later.
|
| CVE-2026-8784 |
|
Vulnerability in c (CVE-2026-8784)
vulnerability in c (CVE-2026-8784). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41937 |
|
Vulnerability in CVE-2026-41937 (CVE-2026-41937)
vulnerability in CVE-2026-41937 (CVE-2026-41937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6475 |
|
Vulnerability in postgresql (CVE-2026-6475)
vulnerability in postgresql (CVE-2026-6475). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `14.23.0, 15.18.0, 16.14.0, 17.10.0, 18.4.0` or later.
|
| CVE-2026-7819 |
|
Vulnerability in pgadmin4 (CVE-2026-7819)
vulnerability in pgadmin4 (CVE-2026-7819). Data can be tampered with by attackers. Mitigation: upgrade to `9.15` or later.
|
| CVE-2026-29203 |
|
Vulnerability in privilege-escalation (CVE-2026-29203)
vulnerability in privilege-escalation (CVE-2026-29203). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42275 |
|
Path Traversal in github.com/openziti/zrok (CVE-2026-42275)
path traversal in github.com/openziti/zrok (CVE-2026-42275). Confidential information can be exposed externally. Mitigation: upgrade to `2.0.2` or later.
|
| CVE-2026-31893 |
|
Vulnerability in tunnelblick (CVE-2026-31893)
vulnerability in tunnelblick (CVE-2026-31893). Confidential information can be exposed externally.
|
| CVE-2026-41326 |
|
Vulnerability in github.com/kata-containers/kata-containers (CVE-2026-41326)
vulnerability in github.com/kata-containers/kata-containers (CVE-2026-41326). Confidential information can be exposed externally. Exploitable via ``policy_data.common.cpath``. Mitigation: upgrade to `0.0.0-20260422180503-1b9e49eb2763` or later.
|
| CVE-2026-39860 |
|
Vulnerability in nixos (CVE-2026-39860)
vulnerability in nixos (CVE-2026-39860). Confidential information can be exposed externally. Mitigation: upgrade to `2.34.5` or later.
|
| CVE-2026-35525 |
|
Vulnerability in liquidjs (CVE-2026-35525)
vulnerability in liquidjs (CVE-2026-35525). Confidential information can be exposed externally. Mitigation: upgrade to `10.25.3` or later.
|
| CVE-2026-34078 |
|
Vulnerability in flatpak (CVE-2026-34078)
vulnerability in flatpak (CVE-2026-34078). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.16.4` or later.
|
| CVE-2026-27489 |
|
Vulnerability in path-traversal (CVE-2026-27489)
vulnerability in path-traversal (CVE-2026-27489). Confidential information can be exposed externally.
|