Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75118 |
|
Vulnerability in CVE-2026-75118 (CVE-2026-75118)
vulnerability in CVE-2026-75118 (CVE-2026-75118). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3686 |
|
Vulnerability in dos (CVE-2026-3686)
vulnerability in dos (CVE-2026-3686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19295 |
|
Vulnerability in privilege-escalation (CVE-2026-19295)
vulnerability in privilege-escalation (CVE-2026-19295). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19286 |
|
Code Injection in CVE-2026-19286 (CVE-2026-19286)
code injection in CVE-2026-19286 (CVE-2026-19286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18899 |
|
Path Traversal in path-traversal (CVE-2026-18899)
path traversal in path-traversal (CVE-2026-18899). Confidential information can be exposed externally.
|
| CVE-2026-16821 |
|
Vulnerability in CVE-2026-16821 (CVE-2026-16821)
vulnerability in CVE-2026-16821 (CVE-2026-16821). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18891 |
|
Authentication Bypass in CVE-2026-18891 (CVE-2026-18891)
authentication bypass in CVE-2026-18891 (CVE-2026-18891). Confidential information can be exposed externally.
|
| CVE-2026-18545 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-18545)
SSRF in ssrf (CVE-2026-18545). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13735 |
|
Vulnerability in c (CVE-2026-13735)
vulnerability in c (CVE-2026-13735). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18729 |
|
Code Injection in CVE-2026-18729 (CVE-2026-18729)
code injection in CVE-2026-18729 (CVE-2026-18729). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17203 |
|
Authentication Bypass in CVE-2026-17203 (CVE-2026-17203)
authentication bypass in CVE-2026-17203 (CVE-2026-17203). Confidential information can be exposed externally.
|
| CVE-2026-13734 |
|
Vulnerability in c (CVE-2026-13734)
vulnerability in c (CVE-2026-13734). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-36290 |
|
Vulnerability in CVE-2025-36290 (CVE-2025-36290)
vulnerability in CVE-2025-36290 (CVE-2025-36290). Confidential information can be exposed externally.
|
| CVE-2025-64649 |
|
Vulnerability in CVE-2025-64649 (CVE-2025-64649)
vulnerability in CVE-2025-64649 (CVE-2025-64649). Data can be tampered with by attackers.
|
| CVE-2026-55841 |
|
Vulnerability in org.graylog2:graylog2-server (CVE-2026-55841)
vulnerability in org.graylog2:graylog2-server (CVE-2026-55841). Data can be tampered with by attackers. Mitigation: upgrade to `7.1.2` or later.
|
| CVE-2026-55764 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-55764)
vulnerability in github.com/klever-io/klever-go (CVE-2026-55764). Risk of unauthorized operations or information disclosure. Exploitable via ``SFTAddCirculation``. Mitigation: upgrade to `1.7.19` or later.
|
| CVE-2026-55854 |
|
Vulnerability in mariadb (CVE-2026-55854)
vulnerability in mariadb (CVE-2026-55854). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-55678 |
|
Vulnerability in github.com/basekick-labs/arc (CVE-2026-55678)
vulnerability in github.com/basekick-labs/arc (CVE-2026-55678). Risk of unauthorized operations or information disclosure. Exploitable via ``cluster.shared_secret``. Mitigation: upgrade to `0.0.0-20260615160325-38402ad2ebdd` or later.
|
| CVE-2026-55891 |
|
Vulnerability in privatebin/privatebin (CVE-2026-55891)
vulnerability in privatebin/privatebin (CVE-2026-55891). Risk of unauthorized operations or information disclosure. Exploitable via ``FILTER_SANITIZE_URL``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-55696 |
|
Cross-Site Scripting (XSS) in privatebin/privatebin (CVE-2026-55696)
cross-site scripting in privatebin/privatebin (CVE-2026-55696). Risk of unauthorized operations or information disclosure. Exploitable via ``lang``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-82329 |
|
Authentication Bypass in CVE-2026-82329 (CVE-2026-82329)
authentication bypass in CVE-2026-82329 (CVE-2026-82329). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82343 |
|
Vulnerability in dos (CVE-2026-82343)
vulnerability in dos (CVE-2026-82343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82286 |
|
Path Traversal in CVE-2026-82286 (CVE-2026-82286)
path traversal in CVE-2026-82286 (CVE-2026-82286). Data can be tampered with by attackers. Exploitable via `POST /crawl`.
|
| CVE-2026-82289 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82289 (CVE-2026-82289)
SSRF in CVE-2026-82289 (CVE-2026-82289). Confidential information can be exposed externally.
|
| CVE-2026-82288 |
|
Vulnerability in CVE-2026-82288 (CVE-2026-82288)
vulnerability in CVE-2026-82288 (CVE-2026-82288). Confidential information can be exposed externally.
|
| CVE-2026-82306 |
|
Information Disclosure in CVE-2026-82306 (CVE-2026-82306)
vulnerability in CVE-2026-82306 (CVE-2026-82306). Confidential information can be exposed externally.
|
| CVE-2026-82285 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82285 (CVE-2026-82285)
SSRF in CVE-2026-82285 (CVE-2026-82285). Confidential information can be exposed externally. Exploitable via `POST /api/v1/workflow/report/callback`.
|
| CVE-2026-82279 |
|
Vulnerability in CVE-2026-82279 (CVE-2026-82279)
vulnerability in CVE-2026-82279 (CVE-2026-82279). Data can be tampered with by attackers. Exploitable via `PATCH /team/apiKey`.
|
| CVE-2026-82282 |
|
Vulnerability in CVE-2026-82282 (CVE-2026-82282)
vulnerability in CVE-2026-82282 (CVE-2026-82282). Confidential information can be exposed externally.
|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-82277 |
|
Vulnerability in csrf (CVE-2026-82277)
vulnerability in csrf (CVE-2026-82277). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82273 |
|
Vulnerability in CVE-2026-82273 (CVE-2026-82273)
vulnerability in CVE-2026-82273 (CVE-2026-82273). Confidential information can be exposed externally. Exploitable via `GET /api/memory/threads`.
|
| CVE-2026-82272 |
|
Authorization Flaw in CVE-2026-82272 (CVE-2026-82272)
vulnerability in CVE-2026-82272 (CVE-2026-82272). Confidential information can be exposed externally.
|
| CVE-2026-82275 |
|
Path Traversal in path-traversal (CVE-2026-82275)
path traversal in path-traversal (CVE-2026-82275). Confidential information can be exposed externally.
|
| CVE-2026-82274 |
|
Open Redirect in CVE-2026-82274 (CVE-2026-82274)
vulnerability in CVE-2026-82274 (CVE-2026-82274). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82276 |
|
Vulnerability in CVE-2026-82276 (CVE-2026-82276)
vulnerability in CVE-2026-82276 (CVE-2026-82276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82266 |
|
Vulnerability in CVE-2026-82266 (CVE-2026-82266)
vulnerability in CVE-2026-82266 (CVE-2026-82266). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82269 |
|
Vulnerability in CVE-2026-82269 (CVE-2026-82269)
vulnerability in CVE-2026-82269 (CVE-2026-82269). Confidential information can be exposed externally.
|
| CVE-2026-82270 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82270 (CVE-2026-82270)
SSRF in CVE-2026-82270 (CVE-2026-82270). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-82268 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82268 (CVE-2026-82268)
SSRF in CVE-2026-82268 (CVE-2026-82268). Confidential information can be exposed externally.
|
| CVE-2026-82265 |
|
Vulnerability in spring (CVE-2026-82265)
vulnerability in spring (CVE-2026-82265). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82267 |
|
Vulnerability in CVE-2026-82267 (CVE-2026-82267)
vulnerability in CVE-2026-82267 (CVE-2026-82267). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82264 |
|
Path Traversal in path-traversal (CVE-2026-82264)
path traversal in path-traversal (CVE-2026-82264). Data can be tampered with by attackers.
|
| CVE-2026-82262 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82262 (CVE-2026-82262)
SSRF in CVE-2026-82262 (CVE-2026-82262). Confidential information can be exposed externally. Exploitable via `POST /api/hooks/`.
|
| CVE-2026-82263 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82263 (CVE-2026-82263)
SSRF in CVE-2026-82263 (CVE-2026-82263). Confidential information can be exposed externally.
|
| CVE-2026-82020 |
|
Vulnerability in CVE-2026-82020 (CVE-2026-82020)
vulnerability in CVE-2026-82020 (CVE-2026-82020). Confidential information can be exposed externally.
|
| CVE-2026-82021 |
|
Vulnerability in CVE-2026-82021 (CVE-2026-82021)
vulnerability in CVE-2026-82021 (CVE-2026-82021). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77939 |
|
Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
|
| CVE-2026-77586 |
|
SQL Injection in CVE-2026-77586 (CVE-2026-77586)
SQL injection in CVE-2026-77586 (CVE-2026-77586). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77184 |
|
SQL Injection in CVE-2026-77184 (CVE-2026-77184)
SQL injection in CVE-2026-77184 (CVE-2026-77184). Confidential information can be exposed externally.
|