Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Clear
ID Title
CVE-2026-15746 SSRF (Server-Side Request Forgery) in Amazon aws (CVE-2026-15746)
SSRF in Amazon aws (CVE-2026-15746). Confidential information can be exposed externally. Exploitable via `Authorization header`.
CVE-2026-56087 Vulnerability in CVE-2026-56087 (CVE-2026-56087)
vulnerability in CVE-2026-56087 (CVE-2026-56087). Confidential information can be exposed externally.
CVE-2026-62389 Vulnerability in dos (CVE-2026-62389)
vulnerability in dos (CVE-2026-62389). Risk of unauthorized operations or information disclosure.
CVE-2026-59255 Vulnerability in CVE-2026-59255 (CVE-2026-59255)
vulnerability in CVE-2026-59255 (CVE-2026-59255). Data can be tampered with by attackers.
CVE-2026-59258 Authorization Flaw in CVE-2026-59258 (CVE-2026-59258)
vulnerability in CVE-2026-59258 (CVE-2026-59258). Data can be tampered with by attackers. Exploitable via `PUT /albums/`.
CVE-2026-20297 Path Traversal in path-traversal (CVE-2026-20297)
path traversal in path-traversal (CVE-2026-20297). Successful exploitation can lead to full system takeover. Exploitable via ``edit_local_apps``.
CVE-2026-14960 Privilege Escalation in CVE-2026-14960 (CVE-2026-14960)
vulnerability in CVE-2026-14960 (CVE-2026-14960). Successful exploitation can lead to full system takeover. Exploitable via ``Tdelo64.sys``.
CVE-2026-12382 Vulnerability in CVE-2026-12382 (CVE-2026-12382)
vulnerability in CVE-2026-12382 (CVE-2026-12382). Data can be tampered with by attackers.
CVE-2026-58659 Vulnerability in lightningai (CVE-2026-58659)
vulnerability in lightningai (CVE-2026-58659). Successful exploitation can lead to full system takeover.
CVE-2026-20296 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-20296)
vulnerability in csrf (CVE-2026-20296). Confidential information can be exposed externally. Exploitable via ``list_deployment_server``.
CVE-2026-20298 Information Disclosure in splunk (CVE-2026-20298)
vulnerability in splunk (CVE-2026-20298). Confidential information can be exposed externally. Exploitable via ``encr_password``.
CVE-2026-58658 Vulnerability in CVE-2026-58658 (CVE-2026-58658)
vulnerability in CVE-2026-58658 (CVE-2026-58658). Confidential information can be exposed externally.
CVE-2026-40501 Vulnerability in CVE-2026-40501 (CVE-2026-40501)
vulnerability in CVE-2026-40501 (CVE-2026-40501). Successful exploitation can lead to full system takeover.
CVE-2026-14961 Vulnerability in privilege-escalation (CVE-2026-14961)
vulnerability in privilege-escalation (CVE-2026-14961). Confidential information can be exposed externally. Exploitable via ``Tdelo64.sys``.
CVE-2026-54494 SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54494)
SSRF in phanan/koel (CVE-2026-54494). Risk of unauthorized operations or information disclosure. Exploitable via `GET /secret`. Mitigation: upgrade to `9.7.1` or later.
CVE-2026-62948 Cross-Site Scripting (XSS) in c (CVE-2026-62948)
cross-site scripting in c (CVE-2026-62948). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `25.12.5` or later.
CVE-2026-61643 Authorization Flaw in CVE-2026-61643 (CVE-2026-61643)
vulnerability in CVE-2026-61643 (CVE-2026-61643). Data can be tampered with by attackers.
CVE-2026-53515 Privilege Escalation in @better-auth/sso (CVE-2026-53515)
vulnerability in @better-auth/sso (CVE-2026-53515). Data can be tampered with by attackers. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-50562 Vulnerability in CVE-2026-50562 (CVE-2026-50562)
vulnerability in CVE-2026-50562 (CVE-2026-50562). Risk of unauthorized operations or information disclosure.
CVE-2026-10673 Out-of-Bounds Read in c (CVE-2026-10673)
vulnerability in c (CVE-2026-10673). Data can be tampered with by attackers.
CVE-2026-54491 SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54491)
SSRF in phanan/koel (CVE-2026-54491). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.7.1` or later.
CVE-2026-54449 Command Injection in langbot (CVE-2026-54449)
command injection in langbot (CVE-2026-54449). Successful exploitation can lead to full system takeover.
CVE-2026-62378 Cross-Site Scripting (XSS) in CVE-2026-62378 (CVE-2026-62378)
cross-site scripting in CVE-2026-62378 (CVE-2026-62378). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.10` or later.
CVE-2026-20153 Vulnerability in cisco (CVE-2026-20153)
vulnerability in cisco (CVE-2026-20153). Risk of unauthorized operations or information disclosure.
CVE-2026-20187 Vulnerability in cisco (CVE-2026-20187)
vulnerability in cisco (CVE-2026-20187). Risk of unauthorized operations or information disclosure.
CVE-2026-20158 Vulnerability in cisco (CVE-2026-20158)
vulnerability in cisco (CVE-2026-20158). Risk of unauthorized operations or information disclosure.
CVE-2026-20156 Buffer Overflow in cisco (CVE-2026-20156)
vulnerability in cisco (CVE-2026-20156). Successful exploitation can lead to full system takeover.
CVE-2026-1562 Cross-Site Scripting (XSS) in pega (CVE-2026-1562)
cross-site scripting in pega (CVE-2026-1562). Risk of unauthorized operations or information disclosure.
CVE-2026-1563 Cross-Site Scripting (XSS) in pega (CVE-2026-1563)
cross-site scripting in pega (CVE-2026-1563). Risk of unauthorized operations or information disclosure.
CVE-2026-54493 SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54493)
SSRF in phanan/koel (CVE-2026-54493). Confidential information can be exposed externally. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
CVE-2026-54492 SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54492)
SSRF in phanan/koel (CVE-2026-54492). Risk of unauthorized operations or information disclosure. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
CVE-2026-20146 Path Traversal in Cisco path-traversal (CVE-2026-20146)
path traversal in Cisco path-traversal (CVE-2026-20146). Confidential information can be exposed externally.
CVE-2026-20150 Vulnerability in Cisco roomos (CVE-2026-20150)
vulnerability in Cisco roomos (CVE-2026-20150). Successful exploitation can lead to full system takeover.
CVE-2026-62843 Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-62843)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-62843). Data can be tampered with by attackers. Exploitable via `POST /api/resources/ziptest/..`. Mitigation: upgrade to `2.63.17` or later.
CVE-2026-9007 Cross-Site Scripting (XSS) in CVE-2026-9007 (CVE-2026-9007)
cross-site scripting in CVE-2026-9007 (CVE-2026-9007). Risk of unauthorized operations or information disclosure.
CVE-2026-62683 Authorization Flaw in CVE-2026-62683 (CVE-2026-62683)
vulnerability in CVE-2026-62683 (CVE-2026-62683). Risk of unauthorized operations or information disclosure.
CVE-2026-62685 Vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-62685)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-62685). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/raw/secretA.txt`. Mitigation: upgrade to `2.63.17` or later.
CVE-2026-61371 Vulnerability in CVE-2026-61371 (CVE-2026-61371)
vulnerability in CVE-2026-61371 (CVE-2026-61371). Confidential information can be exposed externally.
CVE-2026-61828 Vulnerability in CVE-2026-61828 (CVE-2026-61828)
vulnerability in CVE-2026-61828 (CVE-2026-61828). Risk of unauthorized operations or information disclosure.
CVE-2026-60005 Vulnerability in nginx (CVE-2026-60005)
vulnerability in nginx (CVE-2026-60005). Risk of unauthorized operations or information disclosure.
CVE-2026-55242 Authorization Flaw in CVE-2026-55242 (CVE-2026-55242)
vulnerability in CVE-2026-55242 (CVE-2026-55242). Successful exploitation can lead to full system takeover.
CVE-2026-50148 Vulnerability in metabase (CVE-2026-50148)
vulnerability in metabase (CVE-2026-50148). Successful exploitation can lead to full system takeover.
CVE-2026-50147 Vulnerability in metabase (CVE-2026-50147)
vulnerability in metabase (CVE-2026-50147). Confidential information can be exposed externally.
CVE-2026-47160 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-47160)
SSRF in ssrf (CVE-2026-47160). Risk of unauthorized operations or information disclosure.
CVE-2026-47159 Authentication Bypass in CVE-2026-47159 (CVE-2026-47159)
authentication bypass in CVE-2026-47159 (CVE-2026-47159). Risk of unauthorized operations or information disclosure.
CVE-2026-47164 Vulnerability in CVE-2026-47164 (CVE-2026-47164)
vulnerability in CVE-2026-47164 (CVE-2026-47164). Confidential information can be exposed externally.
CVE-2026-46709 Command Injection in tabby (CVE-2026-46709)
command injection in tabby (CVE-2026-46709). Successful exploitation can lead to full system takeover.
CVE-2026-47158 Cross-Site Request Forgery (CSRF) in CVE-2026-47158 (CVE-2026-47158)
vulnerability in CVE-2026-47158 (CVE-2026-47158). Data can be tampered with by attackers.
CVE-2026-45150 Vulnerability in CVE-2026-45150 (CVE-2026-45150)
vulnerability in CVE-2026-45150 (CVE-2026-45150). Risk of unauthorized operations or information disclosure.
CVE-2026-45806 SSRF (Server-Side Request Forgery) in CVE-2026-45806 (CVE-2026-45806)
SSRF in CVE-2026-45806 (CVE-2026-45806). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →