Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2024-32387 |
|
Information Disclosure in CVE-2024-32387 (CVE-2024-32387)
vulnerability in CVE-2024-32387 (CVE-2024-32387). Confidential information can be exposed externally.
|
| CVE-2026-55579 |
|
Vulnerability in pheditor/pheditor (CVE-2026-55579)
vulnerability in pheditor/pheditor (CVE-2026-55579). Successful exploitation can lead to full system takeover. Exploitable via ``admin``. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-45336 |
|
Vulnerability in flask (CVE-2026-45336)
vulnerability in flask (CVE-2026-45336). Confidential information can be exposed externally.
|
| CVE-2026-61740 |
|
Authentication Bypass in lightrag-hku (CVE-2026-61740)
authentication bypass in lightrag-hku (CVE-2026-61740). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /documents`. Mitigation: upgrade to `1.5.4` or later.
|
| CVE-2026-61684 |
|
Vulnerability in CVE-2026-61684 (CVE-2026-61684)
vulnerability in CVE-2026-61684 (CVE-2026-61684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37270 |
|
Authentication Bypass in CVE-2026-37270 (CVE-2026-37270)
authentication bypass in CVE-2026-37270 (CVE-2026-37270). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57172 |
|
Vulnerability in CVE-2026-57172 (CVE-2026-57172)
vulnerability in CVE-2026-57172 (CVE-2026-57172). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14807 |
|
Vulnerability in CVE-2026-14807 (CVE-2026-14807)
vulnerability in CVE-2026-14807 (CVE-2026-14807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13768 |
|
Vulnerability in CVE-2026-13768 (CVE-2026-13768)
vulnerability in CVE-2026-13768 (CVE-2026-13768). Confidential information can be exposed externally.
|
| CVE-2026-13728 |
|
Vulnerability in watchguard (CVE-2026-13728)
vulnerability in watchguard (CVE-2026-13728). Confidential information can be exposed externally.
|
| CVE-2026-49352 |
|
Vulnerability in 9router (CVE-2026-49352)
vulnerability in 9router (CVE-2026-49352). Successful exploitation can lead to full system takeover. Exploitable via ``JWT_SECRET``. Mitigation: upgrade to `0.4.45` or later.
|
| CVE-2026-7839 |
|
Vulnerability in c (CVE-2026-7839)
vulnerability in c (CVE-2026-7839). Confidential information can be exposed externally.
|
| CVE-2026-56278 |
|
Vulnerability in express (CVE-2026-56278)
vulnerability in express (CVE-2026-56278). Confidential information can be exposed externally.
|
| CVE-2026-50110 |
|
Vulnerability in CVE-2026-50110 (CVE-2026-50110)
vulnerability in CVE-2026-50110 (CVE-2026-50110). Confidential information can be exposed externally.
|
| CVE-2026-31928 |
|
Vulnerability in daktronics (CVE-2026-31928)
vulnerability in daktronics (CVE-2026-31928). Confidential information can be exposed externally.
|
| CVE-2026-46386 |
|
Unsafe Deserialization in rails (CVE-2026-46386)
vulnerability in rails (CVE-2026-46386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12628 |
|
Vulnerability in ibm (CVE-2026-12628)
vulnerability in ibm (CVE-2026-12628). Confidential information can be exposed externally.
|
| CVE-2026-11746 |
|
Vulnerability in CVE-2026-11746 (CVE-2026-11746)
vulnerability in CVE-2026-11746 (CVE-2026-11746). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56265 |
|
Vulnerability in kidocode (CVE-2026-56265)
vulnerability in kidocode (CVE-2026-56265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47847 |
|
Vulnerability in mariadb-galera (CVE-2026-47847)
vulnerability in mariadb-galera (CVE-2026-47847). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.6.27-0, 10.11.17-0, 11.4.12-0, 11.8.7-0, 12.3.2-0` or later.
|
| CVE-2026-47846 |
|
Vulnerability in cassandra (CVE-2026-47846)
vulnerability in cassandra (CVE-2026-47846). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.20-0, 4.1.11-0, 5.0.8-0` or later.
|
| CVE-2025-10560 |
|
Vulnerability in CVE-2025-10560 (CVE-2025-10560)
vulnerability in CVE-2025-10560 (CVE-2025-10560). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22312 |
|
Vulnerability in CVE-2026-22312 (CVE-2026-22312)
vulnerability in CVE-2026-22312 (CVE-2026-22312). Data can be tampered with by attackers.
|
| CVE-2026-5667 |
|
Vulnerability in jvn (CVE-2026-5667)
vulnerability in jvn (CVE-2026-5667). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9260 |
|
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
|
| CVE-2026-50091 |
|
Vulnerability in c (CVE-2026-50091)
vulnerability in c (CVE-2026-50091). Confidential information can be exposed externally.
|
| CVE-2026-50083 |
|
Vulnerability in c (CVE-2026-50083)
vulnerability in c (CVE-2026-50083). Confidential information can be exposed externally.
|
| CVE-2026-11849 |
|
Vulnerability in CVE-2026-11849 (CVE-2026-11849)
vulnerability in CVE-2026-11849 (CVE-2026-11849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10557 |
|
Vulnerability in cisa (CVE-2026-10557)
vulnerability in cisa (CVE-2026-10557). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48031 |
|
Vulnerability in github.com/dhax/go-base (CVE-2026-48031)
vulnerability in github.com/dhax/go-base (CVE-2026-48031). Confidential information can be exposed externally. Exploitable via ``dev.env``. Mitigation: upgrade to `0.0.0-20260517152733-cc82b9740fa6` or later.
|
| CVE-2026-47281 |
|
Vulnerability in microsoft (CVE-2026-47281)
vulnerability in microsoft (CVE-2026-47281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11414 |
|
Path Traversal in path-traversal (CVE-2026-11414)
path traversal in path-traversal (CVE-2026-11414). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71317 |
|
Vulnerability in CVE-2025-71317 (CVE-2025-71317)
vulnerability in CVE-2025-71317 (CVE-2025-71317). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21404 |
|
Vulnerability in cisa (CVE-2026-21404)
vulnerability in cisa (CVE-2026-21404). Data can be tampered with by attackers.
|
| CVE-2026-50213 |
|
Vulnerability in acer (CVE-2026-50213)
vulnerability in acer (CVE-2026-50213). Confidential information can be exposed externally.
|
| CVE-2026-49204 |
|
Vulnerability in acer (CVE-2026-49204)
vulnerability in acer (CVE-2026-49204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8876 |
|
Vulnerability in securly (CVE-2026-8876)
vulnerability in securly (CVE-2026-8876). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36606 |
|
Vulnerability in CVE-2026-36606 (CVE-2026-36606)
vulnerability in CVE-2026-36606 (CVE-2026-36606). Confidential information can be exposed externally.
|
| CVE-2026-36616 |
|
Vulnerability in CVE-2026-36616 (CVE-2026-36616)
vulnerability in CVE-2026-36616 (CVE-2026-36616). Confidential information can be exposed externally.
|
| CVE-2019-25722 |
|
Vulnerability in CVE-2019-25722 (CVE-2019-25722)
vulnerability in CVE-2019-25722 (CVE-2019-25722). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42251 |
|
Vulnerability in CVE-2026-42251 (CVE-2026-42251)
vulnerability in CVE-2026-42251 (CVE-2026-42251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25600 |
|
Vulnerability in CVE-2026-25600 (CVE-2026-25600)
vulnerability in CVE-2026-25600 (CVE-2026-25600). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44825 |
|
Vulnerability in solr (CVE-2026-44825)
vulnerability in solr (CVE-2026-44825). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.0.0` or later.
|
| CVE-2026-47410 |
|
Vulnerability in praisonai-platform (CVE-2026-47410)
vulnerability in praisonai-platform (CVE-2026-47410). Successful exploitation can lead to full system takeover. Exploitable via `POST /auth/register`. Mitigation: upgrade to `0.1.4` or later.
|
| CVE-2026-47255 |
|
Vulnerability in @agenticmail/api (CVE-2026-47255)
vulnerability in @agenticmail/api (CVE-2026-47255). Data can be tampered with by attackers. Mitigation: upgrade to `0.9.32` or later.
|
| CVE-2026-42929 |
|
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
|
| CVE-2026-45631 |
|
Vulnerability in CVE-2026-45631 (CVE-2026-45631)
vulnerability in CVE-2026-45631 (CVE-2026-45631). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.3` or later.
|
| CVE-2026-46376 |
|
Vulnerability in sangoma (CVE-2026-46376)
vulnerability in sangoma (CVE-2026-46376). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `16.0.45` or later.
|
| CVE-2026-49323 |
|
Vulnerability in CVE-2026-49323 (CVE-2026-49323)
vulnerability in CVE-2026-49323 (CVE-2026-49323). Confidential information can be exposed externally.
|
| CVE-2026-49201 |
|
Vulnerability in acer (CVE-2026-49201)
vulnerability in acer (CVE-2026-49201). Successful exploitation can lead to full system takeover.
|