Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14057 |
|
Vulnerability in google (CVE-2026-14057)
vulnerability in google (CVE-2026-14057). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13913 |
|
Vulnerability in google (CVE-2026-13913)
vulnerability in google (CVE-2026-13913). Confidential information can be exposed externally.
|
| CVE-2026-13887 |
|
Vulnerability in google (CVE-2026-13887)
vulnerability in google (CVE-2026-13887). Confidential information can be exposed externally.
|
| CVE-2026-13881 |
|
Vulnerability in google (CVE-2026-13881)
vulnerability in google (CVE-2026-13881). Data can be tampered with by attackers.
|
| CVE-2026-13838 |
|
Vulnerability in google (CVE-2026-13838)
vulnerability in google (CVE-2026-13838). Data can be tampered with by attackers.
|
| CVE-2026-13839 |
|
Vulnerability in google (CVE-2026-13839)
vulnerability in google (CVE-2026-13839). Data can be tampered with by attackers.
|
| CVE-2026-13840 |
|
Vulnerability in google (CVE-2026-13840)
vulnerability in google (CVE-2026-13840). Confidential information can be exposed externally.
|
| CVE-2026-13868 |
|
Vulnerability in google (CVE-2026-13868)
vulnerability in google (CVE-2026-13868). Data can be tampered with by attackers.
|
| CVE-2026-13822 |
|
Vulnerability in google (CVE-2026-13822)
vulnerability in google (CVE-2026-13822). Data can be tampered with by attackers.
|
| CVE-2026-13826 |
|
Vulnerability in google (CVE-2026-13826)
vulnerability in google (CVE-2026-13826). Confidential information can be exposed externally.
|
| CVE-2026-13793 |
|
Vulnerability in google (CVE-2026-13793)
vulnerability in google (CVE-2026-13793). Confidential information can be exposed externally.
|
| CVE-2026-58169 |
|
Vulnerability in CVE-2026-58169 (CVE-2026-58169)
vulnerability in CVE-2026-58169 (CVE-2026-58169). Successful exploitation can lead to full system takeover. Exploitable via `Host header`.
|
| CVE-2026-43700 |
|
Vulnerability in apple (CVE-2026-43700)
vulnerability in apple (CVE-2026-43700). Confidential information can be exposed externally.
|
| CVE-2026-55487 |
|
Vulnerability in pnpm (CVE-2026-55487)
vulnerability in pnpm (CVE-2026-55487). Successful exploitation can lead to full system takeover. Exploitable via ``bf1b731ee6``. Mitigation: upgrade to `10.34.2` or later.
|
| CVE-2026-54030 |
|
Vulnerability in librechat (CVE-2026-54030)
vulnerability in librechat (CVE-2026-54030). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.5` or later.
|
| CVE-2026-54069 |
|
Vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-54069)
vulnerability in github.com/siyuan-note/siyuan/kernel (CVE-2026-54069). Risk of unauthorized operations or information disclosure. Exploitable via ``RoleAdministrator``. Mitigation: upgrade to `0.0.0-20260628153353-2d5d72223df4` or later.
|
| CVE-2026-13034 |
|
Vulnerability in google (CVE-2026-13034)
vulnerability in google (CVE-2026-13034). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13022 |
|
Vulnerability in google (CVE-2026-13022)
vulnerability in google (CVE-2026-13022). Confidential information can be exposed externally.
|
| CVE-2026-13021 |
|
Vulnerability in google (CVE-2026-13021)
vulnerability in google (CVE-2026-13021). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46611 |
|
Vulnerability in glances (CVE-2026-46611)
vulnerability in glances (CVE-2026-46611). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `4.5.2` or later.
|
| CVE-2026-54665 |
|
Vulnerability in nifi (CVE-2026-54665)
vulnerability in nifi (CVE-2026-54665). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `2.10.0` or later.
|
| CVE-2026-55660 |
|
Vulnerability in tinacms (CVE-2026-55660)
vulnerability in tinacms (CVE-2026-55660). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.9.3` or later.
|
| CVE-2026-55767 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-55767)
vulnerability in guzzlehttp/guzzle (CVE-2026-55767). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.12.1` or later.
|
| CVE-2026-55669 |
|
Vulnerability in github.com/zitadel/zitadel (CVE-2026-55669)
vulnerability in github.com/zitadel/zitadel (CVE-2026-55669). Risk of unauthorized operations or information disclosure. Exploitable via ``iss``. Mitigation: upgrade to `1.80.0-v2.20.0.20260615132747-d184e976fc79` or later.
|
| CVE-2026-6734 |
|
Vulnerability in undici (CVE-2026-6734)
vulnerability in undici (CVE-2026-6734). Successful exploitation can lead to full system takeover. Exploitable via ``Socks5ProxyAgent``. Mitigation: upgrade to `8.2.0` or later.
|
| CVE-2026-54007 |
|
Vulnerability in open-webui (CVE-2026-54007)
vulnerability in open-webui (CVE-2026-54007). Data can be tampered with by attackers. Exploitable via `POST /api/v1/chats/new`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-12304 |
|
Vulnerability in mozilla (CVE-2026-12304)
vulnerability in mozilla (CVE-2026-12304). Confidential information can be exposed externally.
|
| CVE-2026-47825 |
|
Vulnerability in CVE-2026-47825 (CVE-2026-47825)
vulnerability in CVE-2026-47825 (CVE-2026-47825). Data can be tampered with by attackers.
|
| CVE-2026-50168 |
|
Vulnerability in @angular/platform-server (CVE-2026-50168)
vulnerability in @angular/platform-server (CVE-2026-50168). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `21.2.15` or later.
|
| CVE-2026-9595 |
|
Vulnerability in webpack-dev-server (CVE-2026-9595)
vulnerability in webpack-dev-server (CVE-2026-9595). Risk of unauthorized operations or information disclosure. Exploitable via ``Origin``. Mitigation: upgrade to `5.2.5` or later.
|
| CVE-2026-11624 |
|
Vulnerability in github.com/googleapis/mcp-toolbox (CVE-2026-11624)
vulnerability in github.com/googleapis/mcp-toolbox (CVE-2026-11624). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.25.0` or later.
|
| CVE-2026-45173 |
|
Vulnerability in paloaltonetworks (CVE-2026-45173)
vulnerability in paloaltonetworks (CVE-2026-45173). Data can be tampered with by attackers.
|
| CVE-2026-12032 |
|
Vulnerability in google (CVE-2026-12032)
vulnerability in google (CVE-2026-12032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12024 |
|
Vulnerability in google (CVE-2026-12024)
vulnerability in google (CVE-2026-12024). Data can be tampered with by attackers.
|
| CVE-2026-48022 |
|
Vulnerability in @hapi/wreck (CVE-2026-48022)
vulnerability in @hapi/wreck (CVE-2026-48022). Confidential information can be exposed externally. Exploitable via ``beforeRedirect``. Mitigation: upgrade to `18.1.2` or later.
|
| CVE-2026-41700 |
|
Vulnerability in org.springframework.graphql:spring-graphql (CVE-2026-41700)
vulnerability in org.springframework.graphql:spring-graphql (CVE-2026-41700). Confidential information can be exposed externally.
|
| CVE-2026-42558 |
|
Cross-Site Scripting (XSS) in CVE-2026-42558 (CVE-2026-42558)
cross-site scripting in CVE-2026-42558 (CVE-2026-42558). Confidential information can be exposed externally.
|
| CVE-2026-48063 |
|
Vulnerability in baileys (CVE-2026-48063)
vulnerability in baileys (CVE-2026-48063). Risk of unauthorized operations or information disclosure. Exploitable via ``messages.upsert``. Mitigation: upgrade to `7.0.0-rc12` or later.
|
| CVE-2026-10846 |
|
Vulnerability in nlnetlabs (CVE-2026-10846)
vulnerability in nlnetlabs (CVE-2026-10846). Data can be tampered with by attackers.
|
| CVE-2026-44755 |
|
Vulnerability in CVE-2026-44755 (CVE-2026-44755)
vulnerability in CVE-2026-44755 (CVE-2026-44755). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11693 |
|
Vulnerability in c (CVE-2026-11693)
vulnerability in c (CVE-2026-11693). Confidential information can be exposed externally.
|
| CVE-2026-47691 |
|
Vulnerability in io.netty:netty-resolver-dns (CVE-2026-47691)
vulnerability in io.netty:netty-resolver-dns (CVE-2026-47691). Confidential information can be exposed externally. Exploitable via ``DnsResolveContext``. Mitigation: upgrade to `4.1.135.Final` or later.
|
| CVE-2026-45674 |
|
Vulnerability in io.netty:netty-resolver-dns (CVE-2026-45674)
vulnerability in io.netty:netty-resolver-dns (CVE-2026-45674). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.135.Final` or later.
|
| CVE-2026-44894 |
|
Vulnerability in io.netty:netty-codec-classes-quic (CVE-2026-44894)
vulnerability in io.netty:netty-codec-classes-quic (CVE-2026-44894). Data can be tampered with by attackers. Mitigation: upgrade to `4.2.15.Final` or later.
|
| CVE-2026-43972 |
|
Vulnerability in gun (CVE-2026-43972)
vulnerability in gun (CVE-2026-43972). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-37737 |
|
Vulnerability in sanic-cors (CVE-2026-37737)
vulnerability in sanic-cors (CVE-2026-37737). Confidential information can be exposed externally.
|
| CVE-2026-11309 |
|
Vulnerability in google (CVE-2026-11309)
vulnerability in google (CVE-2026-11309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11298 |
|
Vulnerability in google (CVE-2026-11298)
vulnerability in google (CVE-2026-11298). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11291 |
|
Vulnerability in google (CVE-2026-11291)
vulnerability in google (CVE-2026-11291). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11278 |
|
Vulnerability in google (CVE-2026-11278)
vulnerability in google (CVE-2026-11278). Confidential information can be exposed externally.
|