Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-56854 |
|
Authorization Flaw in CVE-2026-56854 (CVE-2026-56854)
vulnerability in CVE-2026-56854 (CVE-2026-56854). Confidential information can be exposed externally.
|
| CVE-2026-50979 |
|
Command Injection in CVE-2026-50979 (CVE-2026-50979)
command injection in CVE-2026-50979 (CVE-2026-50979). Confidential information can be exposed externally.
|
| CVE-2026-4378 |
|
Cross-Site Scripting (XSS) in CVE-2026-4378 (CVE-2026-4378)
cross-site scripting in CVE-2026-4378 (CVE-2026-4378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3423 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3423)
cross-site scripting in wordpress (CVE-2026-3423). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38725 |
|
Cross-Site Scripting (XSS) in CVE-2026-38725 (CVE-2026-38725)
cross-site scripting in CVE-2026-38725 (CVE-2026-38725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38638 |
|
Vulnerability in dos (CVE-2026-38638)
vulnerability in dos (CVE-2026-38638). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38636 |
|
Vulnerability in dos (CVE-2026-38636)
vulnerability in dos (CVE-2026-38636). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38093 |
|
Path Traversal in path-traversal (CVE-2026-38093)
path traversal in path-traversal (CVE-2026-38093). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37751 |
|
OS Command Injection in CVE-2026-37751 (CVE-2026-37751)
OS command injection in CVE-2026-37751 (CVE-2026-37751). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37736 |
|
Vulnerability in dos (CVE-2026-37736)
vulnerability in dos (CVE-2026-37736). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37710 |
|
Cross-Site Scripting (XSS) in CVE-2026-37710 (CVE-2026-37710)
cross-site scripting in CVE-2026-37710 (CVE-2026-37710). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37237 |
|
Vulnerability in dos (CVE-2026-37237)
vulnerability in dos (CVE-2026-37237). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37236 |
|
Vulnerability in CVE-2026-37236 (CVE-2026-37236)
vulnerability in CVE-2026-37236 (CVE-2026-37236). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19412 |
|
Vulnerability in CVE-2026-19412 (CVE-2026-19412)
vulnerability in CVE-2026-19412 (CVE-2026-19412). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15603 |
|
Vulnerability in CVE-2026-15603 (CVE-2026-15603)
vulnerability in CVE-2026-15603 (CVE-2026-15603). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14942 |
|
Vulnerability in wordpress (CVE-2026-14942)
vulnerability in wordpress (CVE-2026-14942). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13761 |
|
Vulnerability in dos (CVE-2026-13761)
vulnerability in dos (CVE-2026-13761). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55108 |
|
Vulnerability in github.com/oam-dev/kubevela (CVE-2026-55108)
vulnerability in github.com/oam-dev/kubevela (CVE-2026-55108). Risk of unauthorized operations or information disclosure. Exploitable via ``ComponentDefinition``. Mitigation: upgrade to `1.11.0-alpha.4` or later.
|
| GHSA-2vh6-hw4j-32ww |
|
Vulnerability in gix-packetline (GHSA-2vh6-hw4j-32ww)
vulnerability in gix-packetline (GHSA-2vh6-hw4j-32ww). Risk of unauthorized operations or information disclosure. Exploitable via ``gix``. Mitigation: upgrade to `0.21.5` or later.
|
| CVE-2026-54746 |
|
Vulnerability in github.com/hatchet-dev/hatchet (CVE-2026-54746)
vulnerability in github.com/hatchet-dev/hatchet (CVE-2026-54746). Risk of unauthorized operations or information disclosure. Exploitable via ``Dispatcher``. Mitigation: upgrade to `0.91.2` or later.
|
| CVE-2026-82256 |
|
Vulnerability in dos (CVE-2026-82256)
vulnerability in dos (CVE-2026-82256). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82261 |
|
Vulnerability in dos (CVE-2026-82261)
vulnerability in dos (CVE-2026-82261). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.52.2` or later.
|
| CVE-2026-82260 |
|
Vulnerability in dos (CVE-2026-82260)
vulnerability in dos (CVE-2026-82260). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.52.2` or later.
|
| CVE-2026-82259 |
|
Unsafe Deserialization in dos (CVE-2026-82259)
vulnerability in dos (CVE-2026-82259). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.53.3` or later.
|
| CVE-2026-82258 |
|
Vulnerability in CVE-2026-82258 (CVE-2026-82258)
vulnerability in CVE-2026-82258 (CVE-2026-82258). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82257 |
|
Vulnerability in CVE-2026-82257 (CVE-2026-82257)
vulnerability in CVE-2026-82257 (CVE-2026-82257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82254 |
|
Vulnerability in CVE-2026-82254 (CVE-2026-82254)
vulnerability in CVE-2026-82254 (CVE-2026-82254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82255 |
|
Vulnerability in CVE-2026-82255 (CVE-2026-82255)
vulnerability in CVE-2026-82255 (CVE-2026-82255). Confidential information can be exposed externally.
|
| CVE-2026-82251 |
|
Path Traversal in path-traversal (CVE-2026-82251)
path traversal in path-traversal (CVE-2026-82251). Confidential information can be exposed externally.
|
| CVE-2026-82252 |
|
Vulnerability in CVE-2026-82252 (CVE-2026-82252)
vulnerability in CVE-2026-82252 (CVE-2026-82252). Confidential information can be exposed externally.
|
| CVE-2026-82253 |
|
Path Traversal in path-traversal (CVE-2026-82253)
path traversal in path-traversal (CVE-2026-82253). Confidential information can be exposed externally.
|
| CVE-2026-82246 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82246 (CVE-2026-82246)
SSRF in CVE-2026-82246 (CVE-2026-82246). Confidential information can be exposed externally.
|
| CVE-2026-82243 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82243)
SSRF in ssrf (CVE-2026-82243). Confidential information can be exposed externally.
|
| CVE-2026-82242 |
|
Vulnerability in CVE-2026-82242 (CVE-2026-82242)
vulnerability in CVE-2026-82242 (CVE-2026-82242). Data can be tampered with by attackers. Exploitable via `POST /api/resources/duplicate`.
|
| CVE-2026-82250 |
|
Vulnerability in CVE-2026-82250 (CVE-2026-82250)
vulnerability in CVE-2026-82250 (CVE-2026-82250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82245 |
|
Vulnerability in CVE-2026-82245 (CVE-2026-82245)
vulnerability in CVE-2026-82245 (CVE-2026-82245). Data can be tampered with by attackers.
|
| CVE-2026-82248 |
|
Vulnerability in CVE-2026-82248 (CVE-2026-82248)
vulnerability in CVE-2026-82248 (CVE-2026-82248). Data can be tampered with by attackers.
|
| CVE-2026-82247 |
|
Vulnerability in CVE-2026-82247 (CVE-2026-82247)
vulnerability in CVE-2026-82247 (CVE-2026-82247). Confidential information can be exposed externally. Mitigation: upgrade to `0.37.1` or later.
|
| CVE-2026-82249 |
|
Vulnerability in CVE-2026-82249 (CVE-2026-82249)
vulnerability in CVE-2026-82249 (CVE-2026-82249). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82244 |
|
Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82241 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82241)
SSRF in ssrf (CVE-2026-82241). Confidential information can be exposed externally. Exploitable via `POST /api/queries/preview`.
|
| CVE-2026-82238 |
|
Vulnerability in CVE-2026-82238 (CVE-2026-82238)
vulnerability in CVE-2026-82238 (CVE-2026-82238). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82240 |
|
Vulnerability in CVE-2026-82240 (CVE-2026-82240)
vulnerability in CVE-2026-82240 (CVE-2026-82240). Confidential information can be exposed externally.
|
| CVE-2026-82234 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82234)
SSRF in ssrf (CVE-2026-82234). Confidential information can be exposed externally.
|
| CVE-2026-82239 |
|
Vulnerability in CVE-2026-82239 (CVE-2026-82239)
vulnerability in CVE-2026-82239 (CVE-2026-82239). Confidential information can be exposed externally. Exploitable via `POST /api/datasources/query`.
|
| CVE-2026-81733 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-81733)
vulnerability in csrf (CVE-2026-81733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82237 |
|
Vulnerability in CVE-2026-82237 (CVE-2026-82237)
vulnerability in CVE-2026-82237 (CVE-2026-82237). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82233 |
|
Path Traversal in path-traversal (CVE-2026-82233)
path traversal in path-traversal (CVE-2026-82233). Confidential information can be exposed externally.
|
| CVE-2026-82236 |
|
Vulnerability in CVE-2026-82236 (CVE-2026-82236)
vulnerability in CVE-2026-82236 (CVE-2026-82236). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81777 |
|
Vulnerability in CVE-2026-81777 (CVE-2026-81777)
vulnerability in CVE-2026-81777 (CVE-2026-81777). Risk of unauthorized operations or information disclosure.
|