Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-53486 |
|
Path Traversal in @xhmikosr/decompress (CVE-2026-53486)
path traversal in @xhmikosr/decompress (CVE-2026-53486). Confidential information can be exposed externally. Exploitable via ``path.relative``. Mitigation: upgrade to `11.1.3` or later.
|
| CVE-2026-58404 |
|
SSRF (Server-Side Request Forgery) in gohugo (CVE-2026-58404)
SSRF in gohugo (CVE-2026-58404). Confidential information can be exposed externally. Mitigation: upgrade to `0.163.1` or later.
|
| CVE-2026-59089 |
|
Vulnerability in dos (CVE-2026-59089)
vulnerability in dos (CVE-2026-59089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58403 |
|
Vulnerability in gohugo (CVE-2026-58403)
vulnerability in gohugo (CVE-2026-58403). Confidential information can be exposed externally. Mitigation: upgrade to `0.163.1` or later.
|
| CVE-2026-58402 |
|
Cross-Site Scripting (XSS) in gohugo (CVE-2026-58402)
cross-site scripting in gohugo (CVE-2026-58402). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.163.3` or later.
|
| CVE-2026-53763 |
|
Vulnerability in trustedfirmware (CVE-2026-53763)
vulnerability in trustedfirmware (CVE-2026-53763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55646 |
|
Vulnerability in vllm (CVE-2026-55646)
vulnerability in vllm (CVE-2026-55646). Risk of unauthorized operations or information disclosure. Exploitable via ``VLLM_MAX_AUDIO_CLIP_FILESIZE_MB``. Mitigation: upgrade to `0.24.0` or later.
|
| CVE-2026-42546 |
|
Vulnerability in c (CVE-2026-42546)
vulnerability in c (CVE-2026-42546). Risk of unauthorized operations or information disclosure. Exploitable via ``OPTEE_MSG_ATTR_TYPE_MASK``.
|
| CVE-2026-44362 |
|
Vulnerability in c (CVE-2026-44362)
vulnerability in c (CVE-2026-44362). Data can be tampered with by attackers. Exploitable via ``subkey_version``.
|
| CVE-2026-41515 |
|
Vulnerability in trustedfirmware (CVE-2026-41515)
vulnerability in trustedfirmware (CVE-2026-41515). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41516 |
|
Vulnerability in trustedfirmware (CVE-2026-41516)
vulnerability in trustedfirmware (CVE-2026-41516). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41514 |
|
Vulnerability in trustedfirmware (CVE-2026-41514)
vulnerability in trustedfirmware (CVE-2026-41514). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14898 |
|
Information Disclosure in CVE-2026-14898 (CVE-2026-14898)
vulnerability in CVE-2026-14898 (CVE-2026-14898). Confidential information can be exposed externally.
|
| CVE-2026-14536 |
|
Authorization Flaw in devolutions (CVE-2026-14536)
vulnerability in devolutions (CVE-2026-14536). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9181 |
|
Path Traversal in path-traversal (CVE-2026-9181)
path traversal in path-traversal (CVE-2026-9181). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9182 |
|
Unrestricted File Upload in esri (CVE-2026-9182)
vulnerability in esri (CVE-2026-9182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55798 |
|
OS Command Injection in Pillow (CVE-2026-55798)
OS command injection in Pillow (CVE-2026-55798). Risk of unauthorized operations or information disclosure. Exploitable via ``cmd.exe``. Mitigation: upgrade to `12.3.0` or later.
|
| CVE-2026-13753 |
|
Vulnerability in CVE-2026-13753 (CVE-2026-13753)
vulnerability in CVE-2026-13753 (CVE-2026-13753). Confidential information can be exposed externally.
|
| CVE-2026-48614 |
|
Code Injection in privilege-escalation (CVE-2026-48614)
code injection in privilege-escalation (CVE-2026-48614). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48316 |
|
Vulnerability in adobe (CVE-2026-48316)
vulnerability in adobe (CVE-2026-48316). Confidential information can be exposed externally.
|
| CVE-2026-12154 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12154)
cross-site scripting in wordpress (CVE-2026-12154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43825 |
|
Unsafe Deserialization in apache (CVE-2026-43825)
vulnerability in apache (CVE-2026-43825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40140 |
|
Vulnerability in beyondtrust (CVE-2026-40140)
vulnerability in beyondtrust (CVE-2026-40140). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40139 |
|
Authentication Bypass in beyondtrust (CVE-2026-40139)
authentication bypass in beyondtrust (CVE-2026-40139). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40138 |
|
Authentication Bypass in beyondtrust (CVE-2026-40138)
authentication bypass in beyondtrust (CVE-2026-40138). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41434 |
|
Vulnerability in trustedfirmware (CVE-2026-41434)
vulnerability in trustedfirmware (CVE-2026-41434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49452 |
|
Vulnerability in weasyprint (CVE-2026-49452)
vulnerability in weasyprint (CVE-2026-49452). Risk of unauthorized operations or information disclosure. Exploitable via ``background``.
|
| CVE-2026-40257 |
|
Out-of-Bounds Write in trustedfirmware (CVE-2026-40257)
out-of-bounds write in trustedfirmware (CVE-2026-40257). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-53831 |
|
Cross-Site Scripting (XSS) in CVE-2025-53831 (CVE-2025-53831)
cross-site scripting in CVE-2025-53831 (CVE-2025-53831). Confidential information can be exposed externally.
|
| CVE-2026-49445 |
|
Vulnerability in github.com/cilium/cilium (CVE-2026-49445)
vulnerability in github.com/cilium/cilium (CVE-2026-49445). Confidential information can be exposed externally. Mitigation: upgrade to `1.17.14` or later.
|
| CVE-2026-52889 |
|
Vulnerability in verbb/formie (CVE-2026-52889)
vulnerability in verbb/formie (CVE-2026-52889). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.27` or later.
|
| CVE-2026-5268 |
|
Vulnerability in CVE-2026-5268 (CVE-2026-5268)
vulnerability in CVE-2026-5268 (CVE-2026-5268). Confidential information can be exposed externally.
|
| CVE-2026-59152 |
|
Path Traversal in CVE-2026-59152 (CVE-2026-59152)
path traversal in CVE-2026-59152 (CVE-2026-59152). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.18` or later.
|
| CVE-2026-59194 |
|
Path Traversal in pnpm (CVE-2026-59194)
path traversal in pnpm (CVE-2026-59194). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-59195 |
|
Path Traversal in pnpm (CVE-2026-59195)
path traversal in pnpm (CVE-2026-59195). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-59196 |
|
Path Traversal in pnpm (CVE-2026-59196)
path traversal in pnpm (CVE-2026-59196). Data can be tampered with by attackers. Mitigation: upgrade to `10.34.4` or later.
|
| CVE-2026-58203 |
|
Path Traversal in pydantic (CVE-2026-58203)
path traversal in pydantic (CVE-2026-58203). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.14.2` or later.
|
| CVE-2025-53829 |
|
Vulnerability in path-traversal (CVE-2025-53829)
vulnerability in path-traversal (CVE-2025-53829). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53830 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-53830)
SSRF in ssrf (CVE-2025-53830). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53828 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-53828)
SSRF in ssrf (CVE-2025-53828). Successful exploitation can lead to full system takeover.
|
| CVE-2025-53827 |
|
Vulnerability in CVE-2025-53827 (CVE-2025-53827)
vulnerability in CVE-2025-53827 (CVE-2025-53827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7185 |
|
Path Traversal in CVE-2026-7185 (CVE-2026-7185)
path traversal in CVE-2026-7185 (CVE-2026-7185). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58380 |
|
Vulnerability in dos (CVE-2026-58380)
vulnerability in dos (CVE-2026-58380). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13698 |
|
Vulnerability in dos (CVE-2026-13698)
vulnerability in dos (CVE-2026-13698). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54893 |
|
Vulnerability in CVE-2026-54893 (CVE-2026-54893)
vulnerability in CVE-2026-54893 (CVE-2026-54893). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13705 |
|
Out-of-Bounds Read in CVE-2026-13705 (CVE-2026-13705)
vulnerability in CVE-2026-13705 (CVE-2026-13705). Confidential information can be exposed externally.
|
| CVE-2026-13708 |
|
Vulnerability in dos (CVE-2026-13708)
vulnerability in dos (CVE-2026-13708). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15667 |
|
Buffer Overflow in c (CVE-2025-15667)
vulnerability in c (CVE-2025-15667). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6901 |
|
Vulnerability in CVE-2026-6901 (CVE-2026-6901)
vulnerability in CVE-2026-6901 (CVE-2026-6901). Confidential information can be exposed externally.
|
| CVE-2026-6900 |
|
Vulnerability in CVE-2026-6900 (CVE-2026-6900)
vulnerability in CVE-2026-6900 (CVE-2026-6900). Confidential information can be exposed externally.
|