Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82291 |
|
Vulnerability in CVE-2026-82291 (CVE-2026-82291)
vulnerability in CVE-2026-82291 (CVE-2026-82291). Confidential information can be exposed externally.
|
| CVE-2026-82287 |
|
Vulnerability in c (CVE-2026-82287)
vulnerability in c (CVE-2026-82287). Confidential information can be exposed externally.
|
| CVE-2025-61163 |
|
Vulnerability in CVE-2025-61163 (CVE-2025-61163)
vulnerability in CVE-2025-61163 (CVE-2025-61163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63407 |
|
Vulnerability in CVE-2026-63407 (CVE-2026-63407)
vulnerability in CVE-2026-63407 (CVE-2026-63407). Confidential information can be exposed externally.
|
| CVE-2026-68517 |
|
Vulnerability in glances (CVE-2026-68517)
vulnerability in glances (CVE-2026-68517). Confidential information can be exposed externally. Exploitable via ``CORSMiddleware``. Mitigation: upgrade to `4.5.6` or later.
|
| CVE-2026-74881 |
|
Vulnerability in CVE-2026-74881 (CVE-2026-74881)
vulnerability in CVE-2026-74881 (CVE-2026-74881). Confidential information can be exposed externally.
|
| CVE-2026-18676 |
|
Vulnerability in c (CVE-2026-18676)
vulnerability in c (CVE-2026-18676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46409 |
|
Code Injection in CVE-2026-46409 (CVE-2026-46409)
code injection in CVE-2026-46409 (CVE-2026-46409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70604 |
|
Vulnerability in electron (CVE-2026-70604)
vulnerability in electron (CVE-2026-70604). Confidential information can be exposed externally. Exploitable via ``XMLHttpRequest``. Mitigation: upgrade to `39.8.10` or later.
|
| CVE-2026-65310 |
|
Vulnerability in CVE-2026-65310 (CVE-2026-65310)
vulnerability in CVE-2026-65310 (CVE-2026-65310). Confidential information can be exposed externally.
|
| CVE-2026-66005 |
|
Vulnerability in CVE-2026-66005 (CVE-2026-66005)
vulnerability in CVE-2026-66005 (CVE-2026-66005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15966 |
|
Vulnerability in progress (CVE-2026-15966)
vulnerability in progress (CVE-2026-15966). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21761 |
|
Vulnerability in hcltech (CVE-2026-21761)
vulnerability in hcltech (CVE-2026-21761). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-23578 |
|
Vulnerability in CVE-2024-23578 (CVE-2024-23578)
vulnerability in CVE-2024-23578 (CVE-2024-23578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62387 |
|
Vulnerability in CVE-2026-62387 (CVE-2026-62387)
vulnerability in CVE-2026-62387 (CVE-2026-62387). Confidential information can be exposed externally. Exploitable via `Referer header`. Mitigation: upgrade to `1.0.0-rc.16` or later.
|
| CVE-2026-53656 |
|
Vulnerability in fiftyone (CVE-2026-53656)
vulnerability in fiftyone (CVE-2026-53656). Confidential information can be exposed externally. Exploitable via ``allowed_origins``. Mitigation: upgrade to `1.17.0` or later.
|
| CVE-2026-61736 |
|
Vulnerability in lightrag-hku (CVE-2026-61736)
vulnerability in lightrag-hku (CVE-2026-61736). Confidential information can be exposed externally. Mitigation: upgrade to `1.5.4` or later.
|
| CVE-2026-8919 |
|
Vulnerability in CVE-2026-8919 (CVE-2026-8919)
vulnerability in CVE-2026-8919 (CVE-2026-8919). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59148 |
|
Vulnerability in express (CVE-2026-59148)
vulnerability in express (CVE-2026-59148). Successful exploitation can lead to full system takeover. Exploitable via `PUT /mockoon-admin/environment`.
|
| CVE-2026-59726 |
|
OS Command Injection in CVE-2026-59726 (CVE-2026-59726)
OS command injection in CVE-2026-59726 (CVE-2026-59726). Successful exploitation can lead to full system takeover. Exploitable via `POST /mcp`.
|
| CVE-2026-56458 |
|
Vulnerability in hcltechsw (CVE-2026-56458)
vulnerability in hcltechsw (CVE-2026-56458). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55110 |
|
Vulnerability in ui (CVE-2026-55110)
vulnerability in ui (CVE-2026-55110). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12084 |
|
Vulnerability in ibm (CVE-2026-12084)
vulnerability in ibm (CVE-2026-12084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57957 |
|
Vulnerability in CVE-2026-57957 (CVE-2026-57957)
vulnerability in CVE-2026-57957 (CVE-2026-57957). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54753 |
|
Vulnerability in nx (CVE-2026-54753)
vulnerability in nx (CVE-2026-54753). Confidential information can be exposed externally. Exploitable via `GET /help`. Mitigation: upgrade to `23.0.0-beta.2` or later.
|
| CVE-2026-46608 |
|
Vulnerability in glances (CVE-2026-46608)
vulnerability in glances (CVE-2026-46608). Confidential information can be exposed externally. Exploitable via ``cors_origins``. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-56076 |
|
Vulnerability in CVE-2026-56076 (CVE-2026-56076)
vulnerability in CVE-2026-56076 (CVE-2026-56076). Confidential information can be exposed externally. Exploitable via `POST /agui`.
|
| CVE-2026-54290 |
|
Vulnerability in hono (CVE-2026-54290)
vulnerability in hono (CVE-2026-54290). Confidential information can be exposed externally. Exploitable via ``origin``. Mitigation: upgrade to `4.12.25` or later.
|
| CVE-2026-50088 |
|
Vulnerability in c (CVE-2026-50088)
vulnerability in c (CVE-2026-50088). Confidential information can be exposed externally.
|
| CVE-2026-50087 |
|
Vulnerability in c (CVE-2026-50087)
vulnerability in c (CVE-2026-50087). Confidential information can be exposed externally.
|
| CVE-2026-10056 |
|
Vulnerability in CVE-2026-10056 (CVE-2026-10056)
vulnerability in CVE-2026-10056 (CVE-2026-10056). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /rest/v2/system/settings`.
|
| CVE-2026-46685 |
|
Vulnerability in CVE-2026-46685 (CVE-2026-46685)
vulnerability in CVE-2026-46685 (CVE-2026-46685). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-9739 |
|
Vulnerability in github.com/googleapis/mcp-toolbox (CVE-2026-9739)
vulnerability in github.com/googleapis/mcp-toolbox (CVE-2026-9739). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-46431 |
|
Vulnerability in github.com/xyproto/algernon (CVE-2026-46431)
vulnerability in github.com/xyproto/algernon (CVE-2026-46431). Risk of unauthorized operations or information disclosure. Exploitable via ``Origin``. Mitigation: upgrade to `1.17.7` or later.
|
| CVE-2026-8948 |
|
Vulnerability in mozilla (CVE-2026-8948)
vulnerability in mozilla (CVE-2026-8948). Confidential information can be exposed externally.
|
| CVE-2026-8576 |
|
Vulnerability in google (CVE-2026-8576)
vulnerability in google (CVE-2026-8576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8537 |
|
Vulnerability in google (CVE-2026-8537)
vulnerability in google (CVE-2026-8537). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45021 |
|
Vulnerability in github.com/kumahq/kuma (CVE-2026-45021)
vulnerability in github.com/kumahq/kuma (CVE-2026-45021). Risk of unauthorized operations or information disclosure. Exploitable via ``Origin``. Mitigation: upgrade to `2.13.5` or later.
|
| CVE-2026-44184 |
|
Vulnerability in CVE-2026-44184 (CVE-2026-44184)
vulnerability in CVE-2026-44184 (CVE-2026-44184). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.9.10` or later.
|
| CVE-2026-44895 |
|
Vulnerability in @yoda.digital/gitlab-mcp-server (CVE-2026-44895)
vulnerability in @yoda.digital/gitlab-mcp-server (CVE-2026-44895). Risk of unauthorized operations or information disclosure. Exploitable via `GET /sse`. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-5302 |
|
Vulnerability in coolercontrol (CVE-2026-5302)
vulnerability in coolercontrol (CVE-2026-5302). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34449 |
|
Vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-34449). Successful exploitation can lead to full system takeover. Exploitable via ``Origin``. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-34227 |
|
Vulnerability in github.com/bishopfox/sliver (CVE-2026-34227)
vulnerability in github.com/bishopfox/sliver (CVE-2026-34227). Successful exploitation can lead to full system takeover. Exploitable via ``ntds.dit``. Mitigation: upgrade to `1.7.4` or later.
|
| CVE-2026-34200 |
|
Vulnerability in nhost (CVE-2026-34200)
vulnerability in nhost (CVE-2026-34200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0397 |
|
Vulnerability in powerdns (CVE-2026-0397)
vulnerability in powerdns (CVE-2026-0397). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34237 |
|
Vulnerability in io.modelcontextprotocol.sdk:mcp-core (CVE-2026-34237)
vulnerability in io.modelcontextprotocol.sdk:mcp-core (CVE-2026-34237). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.18.3` or later.
|
| CVE-2025-55462 |
|
Vulnerability in eramba (CVE-2025-55462)
vulnerability in eramba (CVE-2025-55462). Confidential information can be exposed externally.
|
| CVE-2020-36851 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2020-36851)
SSRF in ssrf (CVE-2020-36851). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-22348 |
|
Vulnerability in hcltech (CVE-2024-22348)
vulnerability in hcltech (CVE-2024-22348). Risk of unauthorized operations or information disclosure.
|