Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-74247 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-74247)
SSRF in ssrf (CVE-2026-74247). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74245 |
|
Vulnerability in redhat (CVE-2026-74245)
vulnerability in redhat (CVE-2026-74245). Confidential information can be exposed externally.
|
| CVE-2026-74244 |
|
Vulnerability in redhat (CVE-2026-74244)
vulnerability in redhat (CVE-2026-74244). Data can be tampered with by attackers.
|
| CVE-2026-74243 |
|
Vulnerability in path-traversal (CVE-2026-74243)
vulnerability in path-traversal (CVE-2026-74243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74242 |
|
Vulnerability in redhat (CVE-2026-74242)
vulnerability in redhat (CVE-2026-74242). Confidential information can be exposed externally.
|
| CVE-2026-74240 |
|
Authentication Bypass in redhat (CVE-2026-74240)
authentication bypass in redhat (CVE-2026-74240). Risk of unauthorized operations or information disclosure. Exploitable via ``azp``.
|
| CVE-2026-74241 |
|
Vulnerability in redhat (CVE-2026-74241)
vulnerability in redhat (CVE-2026-74241). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44495 |
|
Code Injection in axios (CVE-2026-44495)
code injection in axios (CVE-2026-44495). Confidential information can be exposed externally. Exploitable via ``Object.prototype.transformResponse``. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-6848 |
|
Vulnerability in redhat (CVE-2026-6848)
vulnerability in redhat (CVE-2026-6848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32591 |
|
SSRF (Server-Side Request Forgery) in redhat (CVE-2026-32591)
SSRF in redhat (CVE-2026-32591). Confidential information can be exposed externally.
|
| CVE-2026-32589 |
|
Vulnerability in redhat (CVE-2026-32589)
vulnerability in redhat (CVE-2026-32589). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32590 |
|
Unsafe Deserialization in redhat (CVE-2026-32590)
vulnerability in redhat (CVE-2026-32590). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2377 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-2377)
SSRF in ssrf (CVE-2026-2377). Confidential information can be exposed externally.
|
| CVE-2026-2376 |
|
Open Redirect in redhat (CVE-2026-2376)
vulnerability in redhat (CVE-2026-2376). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-4374 |
|
Vulnerability in redhat (CVE-2025-4374)
vulnerability in redhat (CVE-2025-4374). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-44487 KEV |
|
[KEV] Vulnerability in Ietf golang.org/x/net (CVE-2023-44487)
vulnerability in Ietf golang.org/x/net (CVE-2023-44487). Risk of unauthorized operations or information disclosure. Exploitable via ``Channel``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.17.0` or later.
|
| CVE-2023-3384 |
|
Cross-Site Scripting (XSS) in redhat (CVE-2023-3384)
cross-site scripting in redhat (CVE-2023-3384). Risk of unauthorized operations or information disclosure.
|