Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-77218 |
|
Vulnerability in dos (CVE-2026-77218)
vulnerability in dos (CVE-2026-77218). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76798 |
|
Cross-Site Scripting (XSS) in CVE-2026-76798 (CVE-2026-76798)
cross-site scripting in CVE-2026-76798 (CVE-2026-76798). Confidential information can be exposed externally.
|
| CVE-2026-77217 |
|
Vulnerability in dos (CVE-2026-77217)
vulnerability in dos (CVE-2026-77217). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75486 |
|
OS Command Injection in CVE-2026-75486 (CVE-2026-75486)
OS command injection in CVE-2026-75486 (CVE-2026-75486). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76794 |
|
Cross-Site Scripting (XSS) in CVE-2026-76794 (CVE-2026-76794)
cross-site scripting in CVE-2026-76794 (CVE-2026-76794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75126 |
|
Vulnerability in dos (CVE-2026-75126)
vulnerability in dos (CVE-2026-75126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75125 |
|
Vulnerability in dos (CVE-2026-75125)
vulnerability in dos (CVE-2026-75125). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75124 |
|
Vulnerability in dos (CVE-2026-75124)
vulnerability in dos (CVE-2026-75124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75121 |
|
OS Command Injection in CVE-2026-75121 (CVE-2026-75121)
OS command injection in CVE-2026-75121 (CVE-2026-75121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75123 |
|
OS Command Injection in CVE-2026-75123 (CVE-2026-75123)
OS command injection in CVE-2026-75123 (CVE-2026-75123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75122 |
|
OS Command Injection in CVE-2026-75122 (CVE-2026-75122)
OS command injection in CVE-2026-75122 (CVE-2026-75122). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72984 |
|
Vulnerability in CVE-2026-72984 (CVE-2026-72984)
vulnerability in CVE-2026-72984 (CVE-2026-72984). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66324 |
|
Vulnerability in CVE-2026-66324 (CVE-2026-66324)
vulnerability in CVE-2026-66324 (CVE-2026-66324). Confidential information can be exposed externally.
|
| CVE-2026-66798 |
|
Use-After-Free in CVE-2026-66798 (CVE-2026-66798)
vulnerability in CVE-2026-66798 (CVE-2026-66798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62904 |
|
Authorization Flaw in CVE-2026-62904 (CVE-2026-62904)
vulnerability in CVE-2026-62904 (CVE-2026-62904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58616 |
|
Vulnerability in CVE-2026-58616 (CVE-2026-58616)
vulnerability in CVE-2026-58616 (CVE-2026-58616). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56100 |
|
Vulnerability in privilege-escalation (CVE-2026-56100)
vulnerability in privilege-escalation (CVE-2026-56100). Confidential information can be exposed externally.
|
| CVE-2026-55378 |
|
OS Command Injection in CVE-2026-55378 (CVE-2026-55378)
OS command injection in CVE-2026-55378 (CVE-2026-55378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54745 |
|
Vulnerability in CVE-2026-54745 (CVE-2026-54745)
vulnerability in CVE-2026-54745 (CVE-2026-54745). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-55484 |
|
Vulnerability in github.com/guno1928/alos-http (CVE-2026-55484)
vulnerability in github.com/guno1928/alos-http (CVE-2026-55484). Risk of unauthorized operations or information disclosure. Exploitable via ``sanitizeRequestPath``. Mitigation: upgrade to `0.0.0-20260617230736-314b6783e196` or later.
|
| CVE-2026-55634 |
|
SQL Injection in pimcore/pimcore (CVE-2026-55634)
SQL injection in pimcore/pimcore (CVE-2026-55634). Successful exploitation can lead to full system takeover. Exploitable via ``objects``. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-55220 |
|
Unsafe Deserialization in pimcore/pimcore (CVE-2026-55220)
vulnerability in pimcore/pimcore (CVE-2026-55220). Risk of unauthorized operations or information disclosure. Exploitable via ``true``. Mitigation: upgrade to `12.3.10` or later.
|
| CVE-2026-55215 |
|
Vulnerability in mariadb (CVE-2026-55215)
vulnerability in mariadb (CVE-2026-55215). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-55247 |
|
Vulnerability in plone.app.event (CVE-2026-55247)
vulnerability in plone.app.event (CVE-2026-55247). Risk of unauthorized operations or information disclosure. Exploitable via ``plone.app.event``. Mitigation: upgrade to `6.0.1` or later.
|
| CVE-2026-55520 |
|
Vulnerability in Protego (CVE-2026-55520)
vulnerability in Protego (CVE-2026-55520). Risk of unauthorized operations or information disclosure. Exploitable via ``robots.txt``. Mitigation: upgrade to `0.6.2` or later.
|
| CVE-2026-55248 |
|
Vulnerability in plone.app.portlets (CVE-2026-55248)
vulnerability in plone.app.portlets (CVE-2026-55248). Risk of unauthorized operations or information disclosure. Exploitable via ``plone.app.portlets``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-55673 |
|
OS Command Injection in com.powsybl:powsybl-computation-local (CVE-2026-55673)
OS command injection in com.powsybl:powsybl-computation-local (CVE-2026-55673). Risk of unauthorized operations or information disclosure. Exploitable via ``AbstractLocalCommandExecutor``. Mitigation: upgrade to `7.2.2` or later.
|
| CVE-2026-55584 |
|
Vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584)
vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584). Confidential information can be exposed externally. Exploitable via ``PSI_ALLOWED``. Mitigation: upgrade to `3.4.6` or later.
|
| CVE-2026-55245 |
|
SSRF (Server-Side Request Forgery) in github.com/maximhq/bifrost/core (CVE-2026-55245)
SSRF in github.com/maximhq/bifrost/core (CVE-2026-55245). Risk of unauthorized operations or information disclosure. Exploitable via ``isPublicIP``. Mitigation: upgrade to `1.5.17` or later.
|
| CVE-2026-81849 |
|
Vulnerability in Amazon aws (CVE-2026-81849)
vulnerability in Amazon aws (CVE-2026-81849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55485 |
|
Information Disclosure in piccolo-admin (CVE-2026-55485)
vulnerability in piccolo-admin (CVE-2026-55485). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/tables/piccolo_user/2/`. Mitigation: upgrade to `1.14.0` or later.
|
| CVE-2026-55509 |
|
SQL Injection in WsgiDAV (CVE-2026-55509)
SQL injection in WsgiDAV (CVE-2026-55509). Risk of unauthorized operations or information disclosure. Exploitable via ``MySQLBrowserProvider``. Mitigation: upgrade to `4.3.5` or later.
|
| CVE-2026-55566 |
|
Cross-Site Scripting (XSS) in org.yamcs:yamcs-core (CVE-2026-55566)
cross-site scripting in org.yamcs:yamcs-core (CVE-2026-55566). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55565 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55565)
code injection in org.yamcs:yamcs-core (CVE-2026-55565). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55559 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55559)
code injection in org.yamcs:yamcs-core (CVE-2026-55559). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/instances`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55552 |
|
Path Traversal in org.yamcs:yamcs-core (CVE-2026-55552)
path traversal in org.yamcs:yamcs-core (CVE-2026-55552). Confidential information can be exposed externally. Mitigation: upgrade to `5.12.0` or later.
|
| CVE-2026-55549 |
|
Cross-Site Scripting (XSS) in org.yamcs:yamcs-core (CVE-2026-55549)
cross-site scripting in org.yamcs:yamcs-core (CVE-2026-55549). Confidential information can be exposed externally. Exploitable via ``fetch``. Mitigation: upgrade to `5.9.4` or later.
|
| CVE-2026-55547 |
|
Vulnerability in org.yamcs:yamcs-core (CVE-2026-55547)
vulnerability in org.yamcs:yamcs-core (CVE-2026-55547). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/roles`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55545 |
|
Vulnerability in org.yamcs:yamcs-core (CVE-2026-55545)
vulnerability in org.yamcs:yamcs-core (CVE-2026-55545). Confidential information can be exposed externally. Exploitable via ``packets``. Mitigation: upgrade to `5.13.2` or later.
|
| CVE-2026-55521 |
|
Vulnerability in org.yamcs:yamcs-core (CVE-2026-55521)
vulnerability in org.yamcs:yamcs-core (CVE-2026-55521). Successful exploitation can lead to full system takeover. Exploitable via ``SystemPrivilege``. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55511 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55511)
code injection in org.yamcs:yamcs-core (CVE-2026-55511). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55068 |
|
Vulnerability in github.com/free5gc/free5gc (CVE-2026-55068)
vulnerability in github.com/free5gc/free5gc (CVE-2026-55068). Risk of unauthorized operations or information disclosure. Exploitable via ``RegisterNFInstance``. Mitigation: upgrade to `4.2.2` or later.
|
| CVE-2026-55065 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-55065)
vulnerability in code.vikunja.io/api (CVE-2026-55065). Data can be tampered with by attackers. Exploitable via `GET /api/v1/projects/`. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-55064 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-55064)
vulnerability in code.vikunja.io/api (CVE-2026-55064). Risk of unauthorized operations or information disclosure. Exploitable via ``ParentProjectID``. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-54766 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-54766)
vulnerability in code.vikunja.io/api (CVE-2026-54766). Risk of unauthorized operations or information disclosure. Exploitable via `POST /projects`. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-54788 |
|
Vulnerability in datadog-opentelemetry (CVE-2026-54788)
vulnerability in datadog-opentelemetry (CVE-2026-54788). Risk of unauthorized operations or information disclosure. Exploitable via ``tracecontext``. Mitigation: upgrade to `0.3.3` or later.
|
| CVE-2026-55834 |
|
Open Redirect in github.com/pocket-id/pocket-id/backend (CVE-2026-55834)
vulnerability in github.com/pocket-id/pocket-id/backend (CVE-2026-55834). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.0` or later.
|
| CVE-2026-55569 |
|
Path Traversal in github.com/aquaproj/aqua/v2 (CVE-2026-55569)
path traversal in github.com/aquaproj/aqua/v2 (CVE-2026-55569). Data can be tampered with by attackers. Exploitable via ``tar.gz``. Mitigation: upgrade to `2.60.1` or later.
|
| CVE-2026-54755 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-54755)
vulnerability in github.com/klever-io/klever-go (CVE-2026-54755). Data can be tampered with by attackers. Exploitable via ``uint32``. Mitigation: upgrade to `1.7.19` or later.
|
| CVE-2026-54754 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-54754)
vulnerability in github.com/klever-io/klever-go (CVE-2026-54754). Data can be tampered with by attackers. Exploitable via ``MarketBuy``. Mitigation: upgrade to `1.7.19` or later.
|