Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44374 |
|
Authorization Flaw in @backstage/plugin-catalog-unprocessed-entities-common (CVE-2026-44374)
vulnerability in @backstage/plugin-catalog-unprocessed-entities-common (CVE-2026-44374). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.15` or later.
|
| CVE-2026-45321 KEV |
|
[KEV] Vulnerability in @tanstack/arktype-adapter (CVE-2026-45321)
vulnerability in @tanstack/arktype-adapter (CVE-2026-45321). Successful exploitation can lead to full system takeover. Exploitable via ``pull_request_target``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.166.16` or later.
|
| CVE-2026-44477 |
|
Vulnerability in github.com/cloudnative-pg/cloudnative-pg (CVE-2026-44477)
vulnerability in github.com/cloudnative-pg/cloudnative-pg (CVE-2026-44477). Successful exploitation can lead to full system takeover. Exploitable via ``postgres``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-44247 |
|
Vulnerability in volcano.sh/volcano (CVE-2026-44247)
vulnerability in volcano.sh/volcano (CVE-2026-44247). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.14.2` or later.
|
| CVE-2026-41491 |
|
Path Traversal in github.com/dapr/dapr (CVE-2026-41491)
path traversal in github.com/dapr/dapr (CVE-2026-41491). Confidential information can be exposed externally. Exploitable via ``purell.NormalizeURLString``. Mitigation: upgrade to `1.15.14` or later.
|
| CVE-2026-37525 |
|
Privilege Escalation in c (CVE-2026-37525)
vulnerability in c (CVE-2026-37525). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37530 |
|
Vulnerability in c (CVE-2026-37530)
vulnerability in c (CVE-2026-37530). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37531 |
|
Path Traversal in c (CVE-2026-37531)
path traversal in c (CVE-2026-37531). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37526 |
|
Vulnerability in c (CVE-2026-37526)
vulnerability in c (CVE-2026-37526). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37532 |
|
Vulnerability in c (CVE-2026-37532)
vulnerability in c (CVE-2026-37532). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40938 |
|
Vulnerability in github.com/tektoncd/pipeline (CVE-2026-40938)
vulnerability in github.com/tektoncd/pipeline (CVE-2026-40938). Successful exploitation can lead to full system takeover. Exploitable via ``revision``. Mitigation: upgrade to `1.0.2` or later.
|
| CVE-2026-40924 |
|
Vulnerability in github.com/tektoncd/pipeline (CVE-2026-40924)
vulnerability in github.com/tektoncd/pipeline (CVE-2026-40924). Risk of unauthorized operations or information disclosure. Exploitable via ``FetchHttpResource``. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-40923 |
|
Path Traversal in github.com/tektoncd/pipeline (CVE-2026-40923)
path traversal in github.com/tektoncd/pipeline (CVE-2026-40923). Risk of unauthorized operations or information disclosure. Exploitable via ``strings.HasPrefix``. Mitigation: upgrade to `1.0.2` or later.
|
| CVE-2026-40161 |
|
Vulnerability in github.com/tektoncd/pipeline (CVE-2026-40161)
vulnerability in github.com/tektoncd/pipeline (CVE-2026-40161). Confidential information can be exposed externally. Exploitable via ``serverURL``. Mitigation: upgrade to `1.11.1` or later.
|
| CVE-2026-25542 |
|
Vulnerability in github.com/tektoncd/pipeline (CVE-2026-25542)
vulnerability in github.com/tektoncd/pipeline (CVE-2026-25542). Data can be tampered with by attackers. Exploitable via ``refSource.URI``. Mitigation: upgrade to `1.11.1` or later.
|
| CVE-2026-29773 |
|
Authorization Flaw in privilege-escalation (CVE-2026-29773)
vulnerability in privilege-escalation (CVE-2026-29773). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-48363 |
|
Vulnerability in musicpd (CVE-2022-48363)
vulnerability in musicpd (CVE-2022-48363). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-17697 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2017-17697)
SSRF in ssrf (CVE-2017-17697). Confidential information can be exposed externally.
|