Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14622 |
|
Authentication Bypass in CVE-2026-14622 (CVE-2026-14622)
authentication bypass in CVE-2026-14622 (CVE-2026-14622). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58423 |
|
Authentication Bypass in code.gitea.io/gitea (CVE-2026-58423)
authentication bypass in code.gitea.io/gitea (CVE-2026-58423). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.26.3` or later.
|
| CVE-2026-52830 |
|
Path Traversal in fast-mcp-telegram (CVE-2026-52830)
path traversal in fast-mcp-telegram (CVE-2026-52830). Confidential information can be exposed externally. Exploitable via ``telegram``. Mitigation: upgrade to `0.19.1` or later.
|
| CVE-2026-49852 |
|
Authentication Bypass in joserfc (CVE-2026-49852)
authentication bypass in joserfc (CVE-2026-49852). Risk of unauthorized operations or information disclosure. Exploitable via ``joserfc.jwt.decode``. Mitigation: upgrade to `1.6.8` or later.
|
| CVE-2026-58029 |
|
Authentication Bypass in mediawiki (CVE-2026-58029)
authentication bypass in mediawiki (CVE-2026-58029). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11387 |
|
Authentication Bypass in wordpress (CVE-2026-11387)
authentication bypass in wordpress (CVE-2026-11387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56219 |
|
Authentication Bypass in CVE-2026-56219 (CVE-2026-56219)
authentication bypass in CVE-2026-56219 (CVE-2026-56219). Confidential information can be exposed externally.
|
| CVE-2026-10560 |
|
Authentication Bypass in dos (CVE-2026-10560)
authentication bypass in dos (CVE-2026-10560). Confidential information can be exposed externally.
|
| CVE-2026-55955 |
|
Authentication Bypass in tomcat (CVE-2026-55955)
authentication bypass in tomcat (CVE-2026-55955). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-41896 |
|
Authentication Bypass in CVE-2026-41896 (CVE-2026-41896)
authentication bypass in CVE-2026-41896 (CVE-2026-41896). Data can be tampered with by attackers. Mitigation: upgrade to `4.0.0-beta.474` or later.
|
| CVE-2026-13546 |
|
Authentication Bypass in CVE-2026-13546 (CVE-2026-13546)
authentication bypass in CVE-2026-13546 (CVE-2026-13546). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13543 |
|
Authentication Bypass in CVE-2026-13543 (CVE-2026-13543)
authentication bypass in CVE-2026-13543 (CVE-2026-13543). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49869 |
|
OS Command Injection in kestra (CVE-2026-49869)
OS command injection in kestra (CVE-2026-49869). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.45` or later.
|
| CVE-2026-55962 |
|
Authentication Bypass in wolfssl (CVE-2026-55962)
authentication bypass in wolfssl (CVE-2026-55962). Data can be tampered with by attackers.
|
| CVE-2026-11703 |
|
Authentication Bypass in wolfssl (CVE-2026-11703)
authentication bypass in wolfssl (CVE-2026-11703). Data can be tampered with by attackers.
|
| CVE-2026-54089 |
|
Authentication Bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089)
authentication bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089). Confidential information can be exposed externally. Exploitable via `POST /api/login`.
|
| CVE-2026-55759 |
|
Authentication Bypass in CVE-2026-55759 (CVE-2026-55759)
authentication bypass in CVE-2026-55759 (CVE-2026-55759). Confidential information can be exposed externally. Mitigation: upgrade to `8.5.1` or later.
|
| CVE-2026-55666 |
|
Authentication Bypass in CVE-2026-55666 (CVE-2026-55666)
authentication bypass in CVE-2026-55666 (CVE-2026-55666). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.5.1` or later.
|
| CVE-2026-13208 |
|
Authentication Bypass in kubevirt (CVE-2026-13208)
authentication bypass in kubevirt (CVE-2026-13208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56237 |
|
Authentication Bypass in CVE-2026-56237 (CVE-2026-56237)
authentication bypass in CVE-2026-56237 (CVE-2026-56237). Confidential information can be exposed externally.
|
| CVE-2026-56223 |
|
Authentication Bypass in CVE-2026-56223 (CVE-2026-56223)
authentication bypass in CVE-2026-56223 (CVE-2026-56223). Confidential information can be exposed externally.
|
| CVE-2026-12112 |
|
Authentication Bypass in privilege-escalation (CVE-2026-12112)
authentication bypass in privilege-escalation (CVE-2026-12112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54320 |
|
Authentication Bypass in CVE-2026-54320 (CVE-2026-54320)
authentication bypass in CVE-2026-54320 (CVE-2026-54320). Confidential information can be exposed externally. Mitigation: upgrade to `0.184.0` or later.
|
| CVE-2026-44961 |
|
Authentication Bypass in CVE-2026-44961 (CVE-2026-44961)
authentication bypass in CVE-2026-44961 (CVE-2026-44961). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34917 |
|
Authentication Bypass in CVE-2026-34917 (CVE-2026-34917)
authentication bypass in CVE-2026-34917 (CVE-2026-34917). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11374 |
|
Authentication Bypass in CVE-2026-11374 (CVE-2026-11374)
authentication bypass in CVE-2026-11374 (CVE-2026-11374). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7664 |
|
Authentication Bypass in langflow (CVE-2026-7664)
authentication bypass in langflow (CVE-2026-7664). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10845 |
|
Authentication Bypass in ibm (CVE-2026-10845)
authentication bypass in ibm (CVE-2026-10845). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12795 |
|
Authentication Bypass in litellm (CVE-2026-12795)
authentication bypass in litellm (CVE-2026-12795). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12773 |
|
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function...
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function...
|
| CVE-2026-56345 |
|
Authentication Bypass in CVE-2026-56345 (CVE-2026-56345)
authentication bypass in CVE-2026-56345 (CVE-2026-56345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56294 |
|
Authentication Bypass in CVE-2026-56294 (CVE-2026-56294)
authentication bypass in CVE-2026-56294 (CVE-2026-56294). Confidential information can be exposed externally.
|
| CVE-2026-56080 |
|
Authentication Bypass in dos (CVE-2026-56080)
authentication bypass in dos (CVE-2026-56080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45480 |
|
Authentication Bypass in microsoft (CVE-2026-45480)
authentication bypass in microsoft (CVE-2026-45480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50559 |
|
Authentication Bypass in io.quarkus:quarkus-vertx-http (CVE-2026-50559)
authentication bypass in io.quarkus:quarkus-vertx-http (CVE-2026-50559). Confidential information can be exposed externally. Exploitable via ``quarkus.http.auth.permission``. Mitigation: upgrade to `3.37.0` or later.
|
| CVE-2026-54781 |
|
Authentication Bypass in CoreWCF.Primitives (CVE-2026-54781)
authentication bypass in CoreWCF.Primitives (CVE-2026-54781). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-49872 |
|
Authentication Bypass in apisix (CVE-2026-49872)
authentication bypass in apisix (CVE-2026-49872). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-55689 |
|
Authentication Bypass in github.com/openfga/openfga (CVE-2026-55689)
authentication bypass in github.com/openfga/openfga (CVE-2026-55689). Confidential information can be exposed externally. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-32174 |
|
Authentication Bypass in microsoft (CVE-2026-32174)
authentication bypass in microsoft (CVE-2026-32174). Data can be tampered with by attackers.
|
| CVE-2026-49454 |
|
Authentication Bypass in relyra (CVE-2026-49454)
authentication bypass in relyra (CVE-2026-49454). Confidential information can be exposed externally. Exploitable via ``SignatureValue``. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-58399 |
|
Vulnerability in @acastellon/auth (CVE-2026-58399)
vulnerability in @acastellon/auth (CVE-2026-58399). Risk of unauthorized operations or information disclosure. Exploitable via `GET /protected`. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-11717 |
|
Authentication Bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11717)
authentication bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11717). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-11718 |
|
Authentication Bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11718)
authentication bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11718). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-55672 |
|
Authentication Bypass in github.com/zitadel/zitadel (CVE-2026-55672)
authentication bypass in github.com/zitadel/zitadel (CVE-2026-55672). Confidential information can be exposed externally. Mitigation: upgrade to `1.80.0-v2.20.0.20260616131956-0973b074b488` or later.
|
| CVE-2026-48991 |
|
Authentication Bypass in CVE-2026-48991 (CVE-2026-48991)
authentication bypass in CVE-2026-48991 (CVE-2026-48991). Confidential information can be exposed externally.
|
| CVE-2026-49502 |
|
Authentication Bypass in dell (CVE-2026-49502)
authentication bypass in dell (CVE-2026-49502). Confidential information can be exposed externally.
|
| CVE-2026-32804 |
|
Authentication Bypass in dell (CVE-2026-32804)
authentication bypass in dell (CVE-2026-32804). Data can be tampered with by attackers.
|
| CVE-2026-48929 |
|
Authentication Bypass in rocketchat (CVE-2026-48929)
authentication bypass in rocketchat (CVE-2026-48929). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46973 |
|
Privilege Escalation in c (CVE-2026-46973)
vulnerability in c (CVE-2026-46973). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46972 |
|
Privilege Escalation in c (CVE-2026-46972)
vulnerability in c (CVE-2026-46972). Successful exploitation can lead to full system takeover.
|