Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-57896 |
|
Out-of-Bounds Read in CVE-2026-57896 (CVE-2026-57896)
vulnerability in CVE-2026-57896 (CVE-2026-57896). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60073 |
|
Out-of-Bounds Read in CVE-2026-60073 (CVE-2026-60073)
vulnerability in CVE-2026-60073 (CVE-2026-60073). Confidential information can be exposed externally.
|
| CVE-2026-36425 |
|
Privilege Escalation in CVE-2026-36425 (CVE-2026-36425)
vulnerability in CVE-2026-36425 (CVE-2026-36425). Confidential information can be exposed externally.
|
| CVE-2024-32385 |
|
Information Disclosure in CVE-2024-32385 (CVE-2024-32385)
vulnerability in CVE-2024-32385 (CVE-2024-32385). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-32387 |
|
Information Disclosure in CVE-2024-32387 (CVE-2024-32387)
vulnerability in CVE-2024-32387 (CVE-2024-32387). Confidential information can be exposed externally.
|
| CVE-2024-34268 |
|
Vulnerability in CVE-2024-34268 (CVE-2024-34268)
vulnerability in CVE-2024-34268 (CVE-2024-34268). Data can be tampered with by attackers.
|
| CVE-2026-53410 |
|
Vulnerability in zoom (CVE-2026-53410)
vulnerability in zoom (CVE-2026-53410). Successful exploitation can lead to full system takeover.
|
| CVE-2024-32389 |
|
Vulnerability in CVE-2024-32389 (CVE-2024-32389)
vulnerability in CVE-2024-32389 (CVE-2024-32389). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-32386 |
|
Path Traversal in path-traversal (CVE-2024-32386)
path traversal in path-traversal (CVE-2024-32386). Confidential information can be exposed externally.
|
| CVE-2026-38158 |
|
SQL Injection in sqli (CVE-2026-38158)
SQL injection in sqli (CVE-2026-38158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53409 |
|
Vulnerability in zoom (CVE-2026-53409)
vulnerability in zoom (CVE-2026-53409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62309 |
|
Vulnerability in corednsio (CVE-2026-62309)
vulnerability in corednsio (CVE-2026-62309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63397 |
|
Vulnerability in @genql/cli (CVE-2026-63397)
vulnerability in @genql/cli (CVE-2026-63397). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.3.4` or later.
|
| CVE-2026-62994 |
|
Vulnerability in corednsio (CVE-2026-62994)
vulnerability in corednsio (CVE-2026-62994). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60140 |
|
Out-of-Bounds Read in CVE-2026-60140 (CVE-2026-60140)
vulnerability in CVE-2026-60140 (CVE-2026-60140). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62299 |
|
Vulnerability in corednsio (CVE-2026-62299)
vulnerability in corednsio (CVE-2026-62299). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61389 |
|
Out-of-Bounds Write in privilege-escalation (CVE-2026-61389)
out-of-bounds write in privilege-escalation (CVE-2026-61389). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61718 |
|
Vulnerability in CVE-2026-61718 (CVE-2026-61718)
vulnerability in CVE-2026-61718 (CVE-2026-61718). Risk of unauthorized operations or information disclosure. Exploitable via `POST /cache/delete`.
|
| CVE-2026-62290 |
|
Authorization Flaw in linuxfoundation (CVE-2026-62290)
vulnerability in linuxfoundation (CVE-2026-62290). Confidential information can be exposed externally. Exploitable via `X-API-Key header`.
|
| CVE-2026-55629 |
|
Path Traversal in whistle (CVE-2026-55629)
path traversal in whistle (CVE-2026-55629). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.3` or later.
|
| CVE-2026-54728 |
|
Vulnerability in CVE-2026-54728 (CVE-2026-54728)
vulnerability in CVE-2026-54728 (CVE-2026-54728). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-60063 |
|
Out-of-Bounds Write in privilege-escalation (CVE-2026-60063)
out-of-bounds write in privilege-escalation (CVE-2026-60063). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15422 |
|
Vulnerability in CVE-2026-15422 (CVE-2026-15422)
vulnerability in CVE-2026-15422 (CVE-2026-15422). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15449 |
|
Vulnerability in c (CVE-2026-15449)
vulnerability in c (CVE-2026-15449). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55579 |
|
Vulnerability in pheditor/pheditor (CVE-2026-55579)
vulnerability in pheditor/pheditor (CVE-2026-55579). Successful exploitation can lead to full system takeover. Exploitable via ``admin``. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-55578 |
|
OS Command Injection in pheditor/pheditor (CVE-2026-55578)
OS command injection in pheditor/pheditor (CVE-2026-55578). Successful exploitation can lead to full system takeover. Exploitable via ``terminal``. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-54540 |
|
OS Command Injection in pheditor/pheditor (CVE-2026-54540)
OS command injection in pheditor/pheditor (CVE-2026-54540). Successful exploitation can lead to full system takeover. Exploitable via ``TERMINAL_COMMANDS``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-52832 |
|
Path Traversal in github.com/nuclio/nuclio (CVE-2026-52832)
path traversal in github.com/nuclio/nuclio (CVE-2026-52832). Data can be tampered with by attackers. Exploitable via `POST /api/functions`. Mitigation: upgrade to `1.16.5` or later.
|
| CVE-2026-52833 |
|
Code Injection in github.com/nuclio/nuclio (CVE-2026-52833)
code injection in github.com/nuclio/nuclio (CVE-2026-52833). Successful exploitation can lead to full system takeover. Exploitable via ``build.gradle``. Mitigation: upgrade to `1.16.5` or later.
|
| CVE-2026-53535 |
|
Path Traversal in dos (CVE-2026-53535)
path traversal in dos (CVE-2026-53535). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54526 |
|
Vulnerability in github.com/argoproj/argo-workflows/v4 (CVE-2026-54526)
vulnerability in github.com/argoproj/argo-workflows/v4 (CVE-2026-54526). Successful exploitation can lead to full system takeover. Exploitable via ``hostNetwork``. Mitigation: upgrade to `4.0.6` or later.
|
| CVE-2026-47089 |
|
Vulnerability in CVE-2026-47089 (CVE-2026-47089)
vulnerability in CVE-2026-47089 (CVE-2026-47089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47086 |
|
Authorization Flaw in CVE-2026-47086 (CVE-2026-47086)
vulnerability in CVE-2026-47086 (CVE-2026-47086). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47081 |
|
Authorization Flaw in CVE-2026-47081 (CVE-2026-47081)
vulnerability in CVE-2026-47081 (CVE-2026-47081). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47082 |
|
Authorization Flaw in CVE-2026-47082 (CVE-2026-47082)
vulnerability in CVE-2026-47082 (CVE-2026-47082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47084 |
|
Authorization Flaw in CVE-2026-47084 (CVE-2026-47084)
vulnerability in CVE-2026-47084 (CVE-2026-47084). Data can be tampered with by attackers.
|
| CVE-2026-46515 |
|
Vulnerability in CVE-2026-46515 (CVE-2026-46515)
vulnerability in CVE-2026-46515 (CVE-2026-46515). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46404 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-46404 (CVE-2026-46404)
SSRF in CVE-2026-46404 (CVE-2026-46404). Confidential information can be exposed externally.
|
| CVE-2026-46353 |
|
Vulnerability in CVE-2026-46353 (CVE-2026-46353)
vulnerability in CVE-2026-46353 (CVE-2026-46353). Confidential information can be exposed externally.
|
| CVE-2026-46512 |
|
Code Injection in CVE-2026-46512 (CVE-2026-46512)
code injection in CVE-2026-46512 (CVE-2026-46512). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46514 |
|
Vulnerability in CVE-2026-46514 (CVE-2026-46514)
vulnerability in CVE-2026-46514 (CVE-2026-46514). Confidential information can be exposed externally.
|
| CVE-2026-46351 |
|
Vulnerability in CVE-2026-46351 (CVE-2026-46351)
vulnerability in CVE-2026-46351 (CVE-2026-46351). Confidential information can be exposed externally.
|
| CVE-2026-46687 |
|
Vulnerability in CVE-2026-46687 (CVE-2026-46687)
vulnerability in CVE-2026-46687 (CVE-2026-46687). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46686 |
|
Cross-Site Scripting (XSS) in CVE-2026-46686 (CVE-2026-46686)
cross-site scripting in CVE-2026-46686 (CVE-2026-46686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45336 |
|
Vulnerability in flask (CVE-2026-45336)
vulnerability in flask (CVE-2026-45336). Confidential information can be exposed externally.
|
| CVE-2026-46336 |
|
Path Traversal in path-traversal (CVE-2026-46336)
path traversal in path-traversal (CVE-2026-46336). Data can be tampered with by attackers.
|
| CVE-2021-27137 KEV |
|
[KEV] Vulnerability in Dd-wrt c (CVE-2021-27137)
vulnerability in Dd-wrt c (CVE-2021-27137). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-15737 |
|
Vulnerability in Amazon aws (CVE-2026-15737)
vulnerability in Amazon aws (CVE-2026-15737). Confidential information can be exposed externally.
|
| CVE-2026-63085 |
|
Authorization Flaw in CVE-2026-63085 (CVE-2026-63085)
vulnerability in CVE-2026-63085 (CVE-2026-63085). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63086 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63086)
SSRF in ssrf (CVE-2026-63086). Confidential information can be exposed externally.
|