Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-49299 |
|
Authorization Flaw in neutron (CVE-2026-49299)
vulnerability in neutron (CVE-2026-49299). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.0.4` or later.
|
| CVE-2026-46823 |
|
Authorization Flaw in c (CVE-2026-46823)
vulnerability in c (CVE-2026-46823). Confidential information can be exposed externally.
|
| CVE-2026-47128 |
|
Authorization Flaw in nono-cli (CVE-2026-47128)
vulnerability in nono-cli (CVE-2026-47128). Data can be tampered with by attackers. Exploitable via ``make``. Mitigation: upgrade to `0.55.0` or later.
|
| CVE-2026-44394 |
|
Authorization Flaw in keystone (CVE-2026-44394)
vulnerability in keystone (CVE-2026-44394). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v3/auth/tokens`. Mitigation: upgrade to `29.0.2` or later.
|
| CVE-2026-45042 |
|
Authorization Flaw in CVE-2026-45042 (CVE-2026-45042)
vulnerability in CVE-2026-45042 (CVE-2026-45042). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-42998 |
|
Authorization Flaw in keystone (CVE-2026-42998)
vulnerability in keystone (CVE-2026-42998). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `29.0.2` or later.
|
| CVE-2026-42999 |
|
Vulnerability in keystone (CVE-2026-42999)
vulnerability in keystone (CVE-2026-42999). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `29.0.2` or later.
|
| CVE-2026-43000 |
|
Vulnerability in keystone (CVE-2026-43000)
vulnerability in keystone (CVE-2026-43000). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `29.0.2` or later.
|
| CVE-2026-45297 |
|
Vulnerability in CVE-2026-45297 (CVE-2026-45297)
vulnerability in CVE-2026-45297 (CVE-2026-45297). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.26.0` or later.
|
| CVE-2026-45808 |
|
Authorization Flaw in github.com/openbao/openbao (CVE-2026-45808)
vulnerability in github.com/openbao/openbao (CVE-2026-45808). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.4` or later.
|
| CVE-2026-22872 |
|
Vulnerability in github.com/projectcapsule/capsule (CVE-2026-22872)
vulnerability in github.com/projectcapsule/capsule (CVE-2026-22872). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.13.0` or later.
|
| CVE-2026-40914 |
|
Authorization Flaw in org.apache.artemis:artemis-stomp-protocol (CVE-2026-40914)
vulnerability in org.apache.artemis:artemis-stomp-protocol (CVE-2026-40914). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9807 |
|
Authorization Flaw in gitlab (CVE-2026-9807)
vulnerability in gitlab (CVE-2026-9807). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.7, 18.11.4, 19.0.1` or later.
|
| CVE-2026-9791 |
|
Authorization Flaw in org.keycloak:keycloak-server-spi-private (CVE-2026-9791)
vulnerability in org.keycloak:keycloak-server-spi-private (CVE-2026-9791). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45075 |
|
Authorization Flaw in symfony/http-kernel (CVE-2026-45075)
vulnerability in symfony/http-kernel (CVE-2026-45075). Data can be tampered with by attackers. Exploitable via ``HEAD``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-48064 |
|
Authorization Flaw in CVE-2026-48064 (CVE-2026-48064)
vulnerability in CVE-2026-48064 (CVE-2026-48064). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.9.1` or later.
|
| CVE-2026-45108 |
|
Authorization Flaw in CVE-2026-45108 (CVE-2026-45108)
vulnerability in CVE-2026-45108 (CVE-2026-45108). Confidential information can be exposed externally. Mitigation: upgrade to `3.1.5` or later.
|
| CVE-2026-6713 |
|
Authorization Flaw in gitlab (CVE-2026-6713)
vulnerability in gitlab (CVE-2026-6713). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.7, 18.11.4, 19.0.2` or later.
|
| CVE-2026-48152 |
|
Authorization Flaw in @budibase/server (CVE-2026-48152)
vulnerability in @budibase/server (CVE-2026-48152). Confidential information can be exposed externally. Exploitable via `GET /api/datasources/`. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-45081 |
|
Authorization Flaw in CVE-2026-45081 (CVE-2026-45081)
vulnerability in CVE-2026-45081 (CVE-2026-45081). Confidential information can be exposed externally. Mitigation: upgrade to `16.5.0` or later.
|
| CVE-2026-44838 |
|
Authorization Flaw in rabbitmq (CVE-2026-44838)
vulnerability in rabbitmq (CVE-2026-44838). Confidential information can be exposed externally. Mitigation: upgrade to `4.2.4` or later.
|
| CVE-2026-42280 |
|
Authorization Flaw in auth0-js (CVE-2026-42280)
vulnerability in auth0-js (CVE-2026-42280). Confidential information can be exposed externally. Mitigation: upgrade to `10.0.0` or later.
|
| CVE-2024-47272 |
|
Authorization Flaw in synology (CVE-2024-47272)
vulnerability in synology (CVE-2024-47272). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43947 |
|
Authorization Flaw in fuxa-server (CVE-2026-43947)
vulnerability in fuxa-server (CVE-2026-43947). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/runscript`. Mitigation: upgrade to `1.3.1` or later.
|
| CVE-2026-43946 |
|
Authorization Flaw in fuxa-server (CVE-2026-43946)
vulnerability in fuxa-server (CVE-2026-43946). Risk of unauthorized operations or information disclosure. Exploitable via ``req.userId``. Mitigation: upgrade to `1.3.1` or later.
|
| CVE-2026-43945 |
|
Code Injection in @frangoteam/fuxa (CVE-2026-43945)
code injection in @frangoteam/fuxa (CVE-2026-43945). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.3.1` or later.
|
| CVE-2026-9603 |
|
Vulnerability in CVE-2026-9603 (CVE-2026-9603)
vulnerability in CVE-2026-9603 (CVE-2026-9603). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3660 |
|
Authorization Flaw in ibm (CVE-2026-3660)
vulnerability in ibm (CVE-2026-3660). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44314 |
|
Authorization Flaw in traccar (CVE-2026-44314)
vulnerability in traccar (CVE-2026-44314). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.13.0` or later.
|
| CVE-2026-8046 |
|
Authorization Flaw in CVE-2026-8046 (CVE-2026-8046)
vulnerability in CVE-2026-8046 (CVE-2026-8046). Data can be tampered with by attackers.
|
| CVE-2026-9350 |
|
Vulnerability in CVE-2026-9350 (CVE-2026-9350)
vulnerability in CVE-2026-9350 (CVE-2026-9350). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25353 |
|
Authorization Flaw in CVE-2018-25353 (CVE-2018-25353)
vulnerability in CVE-2018-25353 (CVE-2018-25353). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6406 |
|
Authorization Flaw in docker (CVE-2026-6406)
vulnerability in docker (CVE-2026-6406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28735 |
|
Authorization Flaw in github.com/mattermost/mattermost-server (CVE-2026-28735)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-28735). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.11.15` or later.
|
| CVE-2026-47120 |
|
Vulnerability in github.com/nezhahq/nezha (CVE-2026-47120)
vulnerability in github.com/nezhahq/nezha (CVE-2026-47120). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/alert-rule`. Mitigation: upgrade to `1.14.15-0.20260517022419-d7526351cf97` or later.
|
| CVE-2026-46717 |
|
Authorization Flaw in github.com/nezhahq/nezha (CVE-2026-46717)
vulnerability in github.com/nezhahq/nezha (CVE-2026-46717). Confidential information can be exposed externally. Exploitable via `POST /api/v1/notification`. Mitigation: upgrade to `1.14.15-0.20260517022419-d06d539d34c1` or later.
|
| CVE-2026-39966 |
|
Authorization Flaw in CVE-2026-39966 (CVE-2026-39966)
vulnerability in CVE-2026-39966 (CVE-2026-39966). Confidential information can be exposed externally.
|
| CVE-2026-46595 |
|
Authorization Flaw in golang.org/x/crypto (CVE-2026-46595)
vulnerability in golang.org/x/crypto (CVE-2026-46595). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-8350 |
|
Authorization Flaw in concrete5/concrete5 (CVE-2026-8350)
vulnerability in concrete5/concrete5 (CVE-2026-8350). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-47102 |
|
Authorization Flaw in litellm (CVE-2026-47102)
vulnerability in litellm (CVE-2026-47102). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.83.10` or later.
|
| CVE-2026-47101 |
|
Authorization Flaw in litellm (CVE-2026-47101)
vulnerability in litellm (CVE-2026-47101). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.83.14` or later.
|
| CVE-2026-46635 |
|
Authorization Flaw in twig/twig (CVE-2026-46635)
vulnerability in twig/twig (CVE-2026-46635). Risk of unauthorized operations or information disclosure. Exploitable via ``column``. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-46549 |
|
Authorization Flaw in nocodb (CVE-2026-46549)
vulnerability in nocodb (CVE-2026-46549). Risk of unauthorized operations or information disclosure. Exploitable via ``oauth_scope``.
|
| CVE-2026-46519 |
|
Authorization Flaw in mcp-server-kubernetes (CVE-2026-46519)
vulnerability in mcp-server-kubernetes (CVE-2026-46519). Successful exploitation can lead to full system takeover. Exploitable via ``ALLOW_ONLY_READONLY_TOOLS``. Mitigation: upgrade to `3.6.0` or later.
|
| CVE-2026-4055 |
|
Authorization Flaw in github.com/mattermost/mattermost/server/v8 (CVE-2026-4055)
vulnerability in github.com/mattermost/mattermost/server/v8 (CVE-2026-4055). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.0-20260320113102-f2b3d1c6a945` or later.
|
| CVE-2026-20238 |
|
Authorization Flaw in splunk (CVE-2026-20238)
vulnerability in splunk (CVE-2026-20238). Confidential information can be exposed externally. Exploitable via ``srchFilter``.
|
| CVE-2026-56268 |
|
Authorization Flaw in flowise (CVE-2026-56268)
vulnerability in flowise (CVE-2026-56268). Confidential information can be exposed externally. Exploitable via ``keyonly``. Mitigation: upgrade to `3.1.2` or later.
|
| CVE-2026-34600 |
|
Information Disclosure in CVE-2026-34600 (CVE-2026-34600)
vulnerability in CVE-2026-34600 (CVE-2026-34600). Confidential information can be exposed externally.
|
| CVE-2026-42526 |
|
Authorization Flaw in apache-airflow-providers-amazon (CVE-2026-42526)
vulnerability in apache-airflow-providers-amazon (CVE-2026-42526). Confidential information can be exposed externally. Exploitable via ``conn_id``. Mitigation: upgrade to `9.28.0` or later.
|
| CVE-2026-41470 |
|
Authorization Flaw in CVE-2026-41470 (CVE-2026-41470)
vulnerability in CVE-2026-41470 (CVE-2026-41470). Risk of unauthorized operations or information disclosure.
|