Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72899 |
|
SQL Injection in CVE-2026-72899 (CVE-2026-72899)
SQL injection in CVE-2026-72899 (CVE-2026-72899). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72736 |
|
Command Injection in CVE-2026-72736 (CVE-2026-72736)
command injection in CVE-2026-72736 (CVE-2026-72736). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-72737 |
|
Vulnerability in CVE-2026-72737 (CVE-2026-72737)
vulnerability in CVE-2026-72737 (CVE-2026-72737). Confidential information can be exposed externally.
|
| CVE-2026-72738 |
|
OS Command Injection in CVE-2026-72738 (CVE-2026-72738)
OS command injection in CVE-2026-72738 (CVE-2026-72738). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72739 |
|
OS Command Injection in CVE-2026-72739 (CVE-2026-72739)
OS command injection in CVE-2026-72739 (CVE-2026-72739). Confidential information can be exposed externally. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-72740 |
|
OS Command Injection in CVE-2026-72740 (CVE-2026-72740)
OS command injection in CVE-2026-72740 (CVE-2026-72740). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72733 |
|
OS Command Injection in CVE-2026-72733 (CVE-2026-72733)
OS command injection in CVE-2026-72733 (CVE-2026-72733). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72735 |
|
Command Injection in CVE-2026-72735 (CVE-2026-72735)
command injection in CVE-2026-72735 (CVE-2026-72735). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72732 |
|
Vulnerability in CVE-2026-72732 (CVE-2026-72732)
vulnerability in CVE-2026-72732 (CVE-2026-72732). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70622 |
|
Vulnerability in CVE-2026-70622 (CVE-2026-70622)
vulnerability in CVE-2026-70622 (CVE-2026-70622). Confidential information can be exposed externally.
|
| CVE-2026-48159 |
|
Vulnerability in react (CVE-2026-48159)
vulnerability in react (CVE-2026-48159). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| CVE-2026-16626 |
|
XXE (XML External Entity) in CVE-2026-16626 (CVE-2026-16626)
vulnerability in CVE-2026-16626 (CVE-2026-16626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10754 |
|
Vulnerability in CVE-2026-10754 (CVE-2026-10754)
vulnerability in CVE-2026-10754 (CVE-2026-10754). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72731 |
|
SQL Injection in CVE-2026-72731 (CVE-2026-72731)
SQL injection in CVE-2026-72731 (CVE-2026-72731). Confidential information can be exposed externally.
|
| CVE-2026-72728 |
|
Vulnerability in CVE-2026-72728 (CVE-2026-72728)
vulnerability in CVE-2026-72728 (CVE-2026-72728). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72729 |
|
Cross-Site Scripting (XSS) in CVE-2026-72729 (CVE-2026-72729)
cross-site scripting in CVE-2026-72729 (CVE-2026-72729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72730 |
|
Cross-Site Scripting (XSS) in CVE-2026-72730 (CVE-2026-72730)
cross-site scripting in CVE-2026-72730 (CVE-2026-72730). Confidential information can be exposed externally.
|
| CVE-2026-72727 |
|
Cross-Site Scripting (XSS) in CVE-2026-72727 (CVE-2026-72727)
cross-site scripting in CVE-2026-72727 (CVE-2026-72727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71577 |
|
Vulnerability in CVE-2026-71577 (CVE-2026-71577)
vulnerability in CVE-2026-71577 (CVE-2026-71577). Confidential information can be exposed externally.
|
| CVE-2026-63623 |
|
Vulnerability in CVE-2026-63623 (CVE-2026-63623)
vulnerability in CVE-2026-63623 (CVE-2026-63623). Confidential information can be exposed externally.
|
| CVE-2026-56619 |
|
Cross-Site Scripting (XSS) in CVE-2026-56619 (CVE-2026-56619)
cross-site scripting in CVE-2026-56619 (CVE-2026-56619). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12624 |
|
Authorization Flaw in CVE-2026-12624 (CVE-2026-12624)
vulnerability in CVE-2026-12624 (CVE-2026-12624). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72726 |
|
Information Disclosure in CVE-2026-72726 (CVE-2026-72726)
vulnerability in CVE-2026-72726 (CVE-2026-72726). Confidential information can be exposed externally. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-72721 |
|
Vulnerability in CVE-2026-72721 (CVE-2026-72721)
vulnerability in CVE-2026-72721 (CVE-2026-72721). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72722 |
|
Vulnerability in CVE-2026-72722 (CVE-2026-72722)
vulnerability in CVE-2026-72722 (CVE-2026-72722). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72723 |
|
Vulnerability in CVE-2026-72723 (CVE-2026-72723)
vulnerability in CVE-2026-72723 (CVE-2026-72723). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72720 |
|
Cross-Site Scripting (XSS) in CVE-2026-72720 (CVE-2026-72720)
cross-site scripting in CVE-2026-72720 (CVE-2026-72720). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72725 |
|
Cross-Site Scripting (XSS) in CVE-2026-72725 (CVE-2026-72725)
cross-site scripting in CVE-2026-72725 (CVE-2026-72725). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-66738 |
|
Code Injection in CVE-2026-66738 (CVE-2026-66738)
code injection in CVE-2026-66738 (CVE-2026-66738). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72718 |
|
Code Injection in CVE-2026-72718 (CVE-2026-72718)
code injection in CVE-2026-72718 (CVE-2026-72718). Risk of unauthorized operations or information disclosure. Exploitable via ``git``.
|
| CVE-2026-48158 |
|
Vulnerability in react (CVE-2026-48158)
vulnerability in react (CVE-2026-48158). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| CVE-2026-56620 |
|
Vulnerability in CVE-2026-56620 (CVE-2026-56620)
vulnerability in CVE-2026-56620 (CVE-2026-56620). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47754 |
|
Path Traversal in tomcat (CVE-2026-47754)
path traversal in tomcat (CVE-2026-47754). Confidential information can be exposed externally. Exploitable via ``archiveEntryName``.
|
| CVE-2026-72760 |
|
Information Disclosure in CVE-2026-72760 (CVE-2026-72760)
vulnerability in CVE-2026-72760 (CVE-2026-72760). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72759 |
|
Vulnerability in CVE-2026-72759 (CVE-2026-72759)
vulnerability in CVE-2026-72759 (CVE-2026-72759). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71959 |
|
Vulnerability in CVE-2026-71959 (CVE-2026-71959)
vulnerability in CVE-2026-71959 (CVE-2026-71959). Risk of unauthorized operations or information disclosure. Exploitable via `POST /collect`.
|
| CVE-2026-72751 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-72751)
cross-site scripting in c (CVE-2026-72751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63106 |
|
SQL Injection in sqli (CVE-2026-63106)
SQL injection in sqli (CVE-2026-63106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63105 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-63105)
cross-site scripting in vue (CVE-2026-63105). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18478 |
|
Cross-Site Scripting (XSS) in CVE-2026-18478 (CVE-2026-18478)
cross-site scripting in CVE-2026-18478 (CVE-2026-18478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72692 |
|
Vulnerability in CVE-2026-72692 (CVE-2026-72692)
vulnerability in CVE-2026-72692 (CVE-2026-72692). Data can be tampered with by attackers.
|
| CVE-2026-72691 |
|
Vulnerability in CVE-2026-72691 (CVE-2026-72691)
vulnerability in CVE-2026-72691 (CVE-2026-72691). Confidential information can be exposed externally.
|
| CVE-2026-59112 |
|
Vulnerability in CVE-2026-59112 (CVE-2026-59112)
vulnerability in CVE-2026-59112 (CVE-2026-59112). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6373 |
|
Vulnerability in CVE-2026-6373 (CVE-2026-6373)
vulnerability in CVE-2026-6373 (CVE-2026-6373). Confidential information can be exposed externally.
|
| CVE-2026-72688 |
|
Vulnerability in CVE-2026-72688 (CVE-2026-72688)
vulnerability in CVE-2026-72688 (CVE-2026-72688). Confidential information can be exposed externally.
|
| CVE-2026-6374 |
|
Vulnerability in CVE-2026-6374 (CVE-2026-6374)
vulnerability in CVE-2026-6374 (CVE-2026-6374). Confidential information can be exposed externally.
|
| CVE-2026-18370 |
|
Vulnerability in dos (CVE-2026-18370)
vulnerability in dos (CVE-2026-18370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12984 |
|
Vulnerability in CVE-2026-12984 (CVE-2026-12984)
vulnerability in CVE-2026-12984 (CVE-2026-12984). Confidential information can be exposed externally.
|
| CVE-2026-19429 |
|
Vulnerability in CVE-2026-19429 (CVE-2026-19429)
vulnerability in CVE-2026-19429 (CVE-2026-19429). Successful exploitation can lead to full system takeover. Exploitable via `POST /job/{name}/build`.
|
| CVE-2026-59090 |
|
Vulnerability in gimp (CVE-2026-59090)
vulnerability in gimp (CVE-2026-59090). Data can be tampered with by attackers. Exploitable via ``block_rem``.
|