Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-81664 |
|
Vulnerability in CVE-2026-81664 (CVE-2026-81664)
vulnerability in CVE-2026-81664 (CVE-2026-81664). Risk of unauthorized operations or information disclosure. Exploitable via `GET /system/telemetry`.
|
| CVE-2026-81335 |
|
Vulnerability in CVE-2026-81335 (CVE-2026-81335)
vulnerability in CVE-2026-81335 (CVE-2026-81335). Confidential information can be exposed externally.
|
| CVE-2026-81334 |
|
Out-of-Bounds Read in cpp (CVE-2026-81334)
vulnerability in cpp (CVE-2026-81334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81097 |
|
OS Command Injection in CVE-2026-81097 (CVE-2026-81097)
OS command injection in CVE-2026-81097 (CVE-2026-81097). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81098 |
|
Vulnerability in CVE-2026-81098 (CVE-2026-81098)
vulnerability in CVE-2026-81098 (CVE-2026-81098). Confidential information can be exposed externally.
|
| CVE-2026-81101 |
|
Information Disclosure in CVE-2026-81101 (CVE-2026-81101)
vulnerability in CVE-2026-81101 (CVE-2026-81101). Confidential information can be exposed externally.
|
| CVE-2026-81094 |
|
Vulnerability in CVE-2026-81094 (CVE-2026-81094)
vulnerability in CVE-2026-81094 (CVE-2026-81094). Confidential information can be exposed externally.
|
| CVE-2026-80213 |
|
Vulnerability in c (CVE-2026-80213)
vulnerability in c (CVE-2026-80213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81096 |
|
Code Injection in CVE-2026-81096 (CVE-2026-81096)
code injection in CVE-2026-81096 (CVE-2026-81096). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81093 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-81093 (CVE-2026-81093)
SSRF in CVE-2026-81093 (CVE-2026-81093). Confidential information can be exposed externally.
|
| CVE-2026-81091 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-81091 (CVE-2026-81091)
SSRF in CVE-2026-81091 (CVE-2026-81091). Confidential information can be exposed externally.
|
| CVE-2026-80212 |
|
Vulnerability in CVE-2026-80212 (CVE-2026-80212)
vulnerability in CVE-2026-80212 (CVE-2026-80212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80209 |
|
Authorization Flaw in CVE-2026-80209 (CVE-2026-80209)
vulnerability in CVE-2026-80209 (CVE-2026-80209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80207 |
|
Vulnerability in nginx (CVE-2026-80207)
vulnerability in nginx (CVE-2026-80207). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/internal/notification/create`.
|
| CVE-2026-80208 |
|
Vulnerability in nginx (CVE-2026-80208)
vulnerability in nginx (CVE-2026-80208). Data can be tampered with by attackers.
|
| CVE-2026-80210 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-80210)
vulnerability in csrf (CVE-2026-80210). Data can be tampered with by attackers.
|
| CVE-2026-79720 |
|
Cross-Site Scripting (XSS) in CVE-2026-79720 (CVE-2026-79720)
cross-site scripting in CVE-2026-79720 (CVE-2026-79720). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79988 |
|
Vulnerability in CVE-2026-79988 (CVE-2026-79988)
vulnerability in CVE-2026-79988 (CVE-2026-79988). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79719 |
|
Cross-Site Scripting (XSS) in CVE-2026-79719 (CVE-2026-79719)
cross-site scripting in CVE-2026-79719 (CVE-2026-79719). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79718 |
|
Cross-Site Scripting (XSS) in CVE-2026-79718 (CVE-2026-79718)
cross-site scripting in CVE-2026-79718 (CVE-2026-79718). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79653 |
|
Path Traversal in path-traversal (CVE-2026-79653)
path traversal in path-traversal (CVE-2026-79653). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54718 |
|
Vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718)
vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-78251 |
|
Vulnerability in CVE-2026-78251 (CVE-2026-78251)
vulnerability in CVE-2026-78251 (CVE-2026-78251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78002 |
|
Vulnerability in dos (CVE-2026-78002)
vulnerability in dos (CVE-2026-78002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75871 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-75871 (CVE-2026-75871)
SSRF in CVE-2026-75871 (CVE-2026-75871). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| CVE-2026-75573 |
|
Vulnerability in CVE-2026-75573 (CVE-2026-75573)
vulnerability in CVE-2026-75573 (CVE-2026-75573). Confidential information can be exposed externally.
|
| CVE-2026-75159 |
|
Vulnerability in CVE-2026-75159 (CVE-2026-75159)
vulnerability in CVE-2026-75159 (CVE-2026-75159). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71402 |
|
Out-of-Bounds Read in c (CVE-2026-71402)
vulnerability in c (CVE-2026-71402). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71401 |
|
Vulnerability in c (CVE-2026-71401)
vulnerability in c (CVE-2026-71401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64896 |
|
Vulnerability in CVE-2026-64896 (CVE-2026-64896)
vulnerability in CVE-2026-64896 (CVE-2026-64896). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5680 |
|
Vulnerability in dos (CVE-2026-5680)
vulnerability in dos (CVE-2026-5680). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5738 |
|
Cross-Site Scripting (XSS) in CVE-2026-5738 (CVE-2026-5738)
cross-site scripting in CVE-2026-5738 (CVE-2026-5738). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59280 |
|
Path Traversal in spring (CVE-2026-59280)
path traversal in spring (CVE-2026-59280). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57499 |
|
Vulnerability in CVE-2026-57499 (CVE-2026-57499)
vulnerability in CVE-2026-57499 (CVE-2026-57499). Successful exploitation can lead to full system takeover. Exploitable via ``ip_address``. Mitigation: upgrade to `2.2.2` or later.
|
| CVE-2026-56651 |
|
Vulnerability in CVE-2026-56651 (CVE-2026-56651)
vulnerability in CVE-2026-56651 (CVE-2026-56651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40526 |
|
Path Traversal in path-traversal (CVE-2026-40526)
path traversal in path-traversal (CVE-2026-40526). Confidential information can be exposed externally. Exploitable via `GET /public/get-file/{path}`.
|
| CVE-2026-34674 |
|
Vulnerability in CVE-2026-34674 (CVE-2026-34674)
vulnerability in CVE-2026-34674 (CVE-2026-34674). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30062 |
|
Vulnerability in dos (CVE-2026-30062)
vulnerability in dos (CVE-2026-30062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30057 |
|
Vulnerability in dos (CVE-2026-30057)
vulnerability in dos (CVE-2026-30057). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30050 |
|
Vulnerability in dos (CVE-2026-30050)
vulnerability in dos (CVE-2026-30050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30056 |
|
Vulnerability in dos (CVE-2026-30056)
vulnerability in dos (CVE-2026-30056). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19889 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19889 (CVE-2026-19889)
SSRF in CVE-2026-19889 (CVE-2026-19889). Confidential information can be exposed externally.
|
| CVE-2026-16279 |
|
Vulnerability in CVE-2026-16279 (CVE-2026-16279)
vulnerability in CVE-2026-16279 (CVE-2026-16279). Confidential information can be exposed externally.
|
| CVE-2026-11747 |
|
Cross-Site Scripting (XSS) in CVE-2026-11747 (CVE-2026-11747)
cross-site scripting in CVE-2026-11747 (CVE-2026-11747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11754 |
|
Vulnerability in CVE-2026-11754 (CVE-2026-11754)
vulnerability in CVE-2026-11754 (CVE-2026-11754). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54687 |
|
Path Traversal in n8n-nodes-sqlite3 (CVE-2026-54687)
path traversal in n8n-nodes-sqlite3 (CVE-2026-54687). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0` or later.
|
| CVE-2026-54721 |
|
Code Injection in silverstripe/userforms (CVE-2026-54721)
code injection in silverstripe/userforms (CVE-2026-54721). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.1` or later.
|
| CVE-2026-81743 |
|
Path Traversal in CVE-2026-81743 (CVE-2026-81743)
path traversal in CVE-2026-81743 (CVE-2026-81743). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81677 |
|
SQL Injection in sqli (CVE-2026-81677)
SQL injection in sqli (CVE-2026-81677). Risk of unauthorized operations or information disclosure. Exploitable via ``id_ambito``.
|
| CVE-2026-81676 |
|
SQL Injection in sqli (CVE-2026-81676)
SQL injection in sqli (CVE-2026-81676). Risk of unauthorized operations or information disclosure. Exploitable via ``limit_videos``.
|