Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-81097 |
|
OS Command Injection in CVE-2026-81097 (CVE-2026-81097)
OS command injection in CVE-2026-81097 (CVE-2026-81097). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80213 |
|
Vulnerability in c (CVE-2026-80213)
vulnerability in c (CVE-2026-80213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80212 |
|
Vulnerability in CVE-2026-80212 (CVE-2026-80212)
vulnerability in CVE-2026-80212 (CVE-2026-80212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70665 |
|
Vulnerability in rails (CVE-2026-70665)
vulnerability in rails (CVE-2026-70665). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79771 |
|
Vulnerability in dos (CVE-2026-79771)
vulnerability in dos (CVE-2026-79771). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62382 |
|
Authorization Flaw in CVE-2026-62382 (CVE-2026-62382)
vulnerability in CVE-2026-62382 (CVE-2026-62382). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.6` or later.
|
| CVE-2026-53970 |
|
Vulnerability in CVE-2026-53970 (CVE-2026-53970)
vulnerability in CVE-2026-53970 (CVE-2026-53970). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67991 |
|
Vulnerability in dos (CVE-2026-67991)
vulnerability in dos (CVE-2026-67991). Confidential information can be exposed externally.
|
| CVE-2026-67990 |
|
Cross-Site Request Forgery (CSRF) in rails (CVE-2026-67990)
vulnerability in rails (CVE-2026-67990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67986 |
|
Code Injection in CVE-2026-67986 (CVE-2026-67986)
code injection in CVE-2026-67986 (CVE-2026-67986). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73330 |
|
Vulnerability in rails (CVE-2026-73330)
vulnerability in rails (CVE-2026-73330). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48122 |
|
OS Command Injection in CVE-2026-48122 (CVE-2026-48122)
OS command injection in CVE-2026-48122 (CVE-2026-48122). Risk of unauthorized operations or information disclosure. Exploitable via ``Gemfile``.
|
| CVE-2026-71847 |
|
Use-After-Free in json (CVE-2026-71847)
vulnerability in json (CVE-2026-71847). Risk of unauthorized operations or information disclosure. Exploitable via ``state.start``. Mitigation: upgrade to `2.21.2` or later.
|
| CVE-2026-53510 |
|
Code Injection in savon (CVE-2026-53510)
code injection in savon (CVE-2026-53510). Successful exploitation can lead to full system takeover. Exploitable via ``module_eval``. Mitigation: upgrade to `2.17.2` or later.
|
| CVE-2026-66066 |
|
Vulnerability in activestorage (CVE-2026-66066)
vulnerability in activestorage (CVE-2026-66066). Risk of unauthorized operations or information disclosure. Exploitable via ``secret_key_base``. Mitigation: upgrade to `8.1.3.1` or later.
|
| CVE-2026-54522 |
|
Use-After-Free in msgpack (CVE-2026-54522)
vulnerability in msgpack (CVE-2026-54522). Risk of unauthorized operations or information disclosure. Exploitable via ``rmem_last``. Mitigation: upgrade to `1.8.2` or later.
|
| CVE-2026-67432 |
|
Vulnerability in mcp (CVE-2026-67432)
vulnerability in mcp (CVE-2026-67432). Risk of unauthorized operations or information disclosure. Exploitable via ``String``. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-67431 |
|
Vulnerability in mcp (CVE-2026-67431)
vulnerability in mcp (CVE-2026-67431). Risk of unauthorized operations or information disclosure. Exploitable via `GET /mcp`. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-67430 |
|
Vulnerability in mcp (CVE-2026-67430)
vulnerability in mcp (CVE-2026-67430). Risk of unauthorized operations or information disclosure. Exploitable via ``initialize``. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-63119 |
|
Vulnerability in mcp (CVE-2026-63119)
vulnerability in mcp (CVE-2026-63119). Risk of unauthorized operations or information disclosure. Exploitable via ``limit``. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-63118 |
|
Vulnerability in mcp (CVE-2026-63118)
vulnerability in mcp (CVE-2026-63118). Risk of unauthorized operations or information disclosure. Exploitable via ``mcp``. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-54659 |
|
Path Traversal in pagy (CVE-2026-54659)
path traversal in pagy (CVE-2026-54659). Risk of unauthorized operations or information disclosure. Exploitable via ``nil``. Mitigation: upgrade to `43.5.6` or later.
|
| CVE-2026-54603 |
|
Information Disclosure in oauth2 (CVE-2026-54603)
vulnerability in oauth2 (CVE-2026-54603). Confidential information can be exposed externally. Exploitable via `GET /leak`. Mitigation: upgrade to `2.0.22` or later.
|
| CVE-2026-54605 |
|
Information Disclosure in oauth (CVE-2026-54605)
vulnerability in oauth (CVE-2026-54605). Risk of unauthorized operations or information disclosure. Exploitable via ``Location``. Mitigation: upgrade to `1.1.6` or later.
|
| CVE-2026-54620 |
|
Use-After-Free in sqlite3-ruby (CVE-2026-54620)
vulnerability in sqlite3-ruby (CVE-2026-54620). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.5` or later.
|
| CVE-2026-54619 |
|
Use-After-Free in sqlite3-ruby (CVE-2026-54619)
vulnerability in sqlite3-ruby (CVE-2026-54619). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.5` or later.
|
| CVE-2026-66748 |
|
Code Injection in CVE-2026-66748 (CVE-2026-66748)
code injection in CVE-2026-66748 (CVE-2026-66748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49158 |
|
Vulnerability in apache (CVE-2026-49158)
vulnerability in apache (CVE-2026-49158). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73648 |
|
Cross-Site Scripting (XSS) in rails-html-sanitizer (CVE-2026-73648)
cross-site scripting in rails-html-sanitizer (CVE-2026-73648). Risk of unauthorized operations or information disclosure. Exploitable via ``SVG_ALLOW_LOCAL_HREF``. Mitigation: upgrade to `1.7.1` or later.
|
| CVE-2026-32825 |
|
Vulnerability in rails (CVE-2026-32825)
vulnerability in rails (CVE-2026-32825). Confidential information can be exposed externally.
|
| CVE-2026-32820 |
|
Path Traversal in rails (CVE-2026-32820)
path traversal in rails (CVE-2026-32820). Confidential information can be exposed externally. Exploitable via ``docs``.
|
| CVE-2026-32823 |
|
Cross-Site Request Forgery (CSRF) in rails (CVE-2026-32823)
vulnerability in rails (CVE-2026-32823). Risk of unauthorized operations or information disclosure. Exploitable via ``GET``.
|
| CVE-2026-59861 |
|
Code Injection in Microsoft.OpenAPI.Kiota (CVE-2026-59861)
code injection in Microsoft.OpenAPI.Kiota (CVE-2026-59861). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-54497 |
|
Vulnerability in view_component (CVE-2026-54497)
vulnerability in view_component (CVE-2026-54497). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `4.12.0` or later.
|
| CVE-2026-54498 |
|
Cross-Site Scripting (XSS) in view_component (CVE-2026-54498)
cross-site scripting in view_component (CVE-2026-54498). Confidential information can be exposed externally. Exploitable via ``around_render``. Mitigation: upgrade to `4.12.0` or later.
|
| CVE-2026-54463 |
|
Vulnerability in websocket-driver (CVE-2026-54463)
vulnerability in websocket-driver (CVE-2026-54463). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.1` or later.
|
| CVE-2026-45378 |
|
Information Disclosure in decidim-verifications (CVE-2026-45378)
vulnerability in decidim-verifications (CVE-2026-45378). Confidential information can be exposed externally. Exploitable via ``verification_attachment``. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-54171 |
|
Vulnerability in excon (CVE-2026-54171)
vulnerability in excon (CVE-2026-54171). Confidential information can be exposed externally. Mitigation: upgrade to `1.5.0` or later.
|
| CVE-2026-53727 |
|
SSRF (Server-Side Request Forgery) in css_parser (CVE-2026-53727)
SSRF in css_parser (CVE-2026-53727). Confidential information can be exposed externally. Exploitable via ``css_parser``. Mitigation: upgrade to `3.0.0` or later.
|
| CVE-2026-38969 |
|
Vulnerability in CVE-2026-38969 (CVE-2026-38969)
vulnerability in CVE-2026-38969 (CVE-2026-38969). Data can be tampered with by attackers.
|
| CVE-2026-54696 |
|
Vulnerability in json (CVE-2026-54696)
vulnerability in json (CVE-2026-54696). Risk of unauthorized operations or information disclosure. Exploitable via ``FBUFFER_IO_BUFFER_SIZE``. Mitigation: upgrade to `2.19.9` or later.
|
| CVE-2026-52783 |
|
Vulnerability in rails (CVE-2026-52783)
vulnerability in rails (CVE-2026-52783). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-46386 |
|
Unsafe Deserialization in rails (CVE-2026-46386)
vulnerability in rails (CVE-2026-46386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57438 |
|
Use-After-Free in nokogiri (CVE-2026-57438)
vulnerability in nokogiri (CVE-2026-57438). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.4` or later.
|
| CVE-2026-57436 |
|
Use-After-Free in nokogiri (CVE-2026-57436)
vulnerability in nokogiri (CVE-2026-57436). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.4` or later.
|
| CVE-2026-57435 |
|
Use-After-Free in nokogiri (CVE-2026-57435)
vulnerability in nokogiri (CVE-2026-57435). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.4` or later.
|
| CVE-2026-57437 |
|
Use-After-Free in nokogiri (CVE-2026-57437)
vulnerability in nokogiri (CVE-2026-57437). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.4` or later.
|
| CVE-2026-57236 |
|
Use-After-Free in nokogiri (CVE-2026-57236)
vulnerability in nokogiri (CVE-2026-57236). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.4` or later.
|
| CVE-2026-57235 |
|
Out-of-Bounds Read in nokogiri (CVE-2026-57235)
vulnerability in nokogiri (CVE-2026-57235). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.4` or later.
|