Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Clear
ID Title
CVE-2026-10109 Code Injection in ibm (CVE-2026-10109)
code injection in ibm (CVE-2026-10109). Successful exploitation can lead to full system takeover.
CVE-2026-10134 Code Injection in langflow (CVE-2026-10134)
code injection in langflow (CVE-2026-10134). Successful exploitation can lead to full system takeover. Exploitable via ``tool_code``.
CVE-2026-58138 Code Injection in CVE-2026-58138 (CVE-2026-58138)
code injection in CVE-2026-58138 (CVE-2026-58138). Successful exploitation can lead to full system takeover.
CVE-2026-10129 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-10129)
SSRF in ssrf (CVE-2026-10129). Confidential information can be exposed externally.
CVE-2026-10513 Cross-Site Scripting (XSS) in wordpress (CVE-2026-10513)
cross-site scripting in wordpress (CVE-2026-10513). Risk of unauthorized operations or information disclosure.
CVE-2026-55219 Vulnerability in paymenter/paymenter (CVE-2026-55219)
vulnerability in paymenter/paymenter (CVE-2026-55219). Data can be tampered with by attackers. Mitigation: upgrade to `1.5.5` or later.
CVE-2026-48808 Vulnerability in twig/twig (CVE-2026-48808)
vulnerability in twig/twig (CVE-2026-48808). Confidential information can be exposed externally. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48807 Vulnerability in twig/twig (CVE-2026-48807)
vulnerability in twig/twig (CVE-2026-48807). Confidential information can be exposed externally. Exploitable via ``Traversable``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48806 Vulnerability in twig/twig (CVE-2026-48806)
vulnerability in twig/twig (CVE-2026-48806). Confidential information can be exposed externally. Exploitable via ``CheckToStringNode``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-48805 Vulnerability in twig/twig (CVE-2026-48805)
vulnerability in twig/twig (CVE-2026-48805). Confidential information can be exposed externally. Exploitable via ``Environment``. Mitigation: upgrade to `3.27.0` or later.
CVE-2026-49835 Vulnerability in github.com/sigstore/timestamp-authority/v2 (CVE-2026-49835)
vulnerability in github.com/sigstore/timestamp-authority/v2 (CVE-2026-49835). Risk of unauthorized operations or information disclosure. Exploitable via ``wrapMetrics``. Mitigation: upgrade to `2.1.0` or later.
CVE-2026-49478 SSRF (Server-Side Request Forgery) in github.com/sigstore/fulcio (CVE-2026-49478)
SSRF in github.com/sigstore/fulcio (CVE-2026-49478). Confidential information can be exposed externally. Exploitable via ``jwks_uri``. Mitigation: upgrade to `1.8.6` or later.
CVE-2026-48796 Path Traversal in CefSharp.Common (CVE-2026-48796)
path traversal in CefSharp.Common (CVE-2026-48796). Confidential information can be exposed externally. Exploitable via ``FolderSchemeHandlerFactory``. Mitigation: upgrade to `148.0.90` or later.
CVE-2026-48795 Vulnerability in @adonisjs/bodyparser (CVE-2026-48795)
vulnerability in @adonisjs/bodyparser (CVE-2026-48795). Risk of unauthorized operations or information disclosure. Exploitable via ``FormFields``. Mitigation: upgrade to `11.0.3` or later.
CVE-2026-49820 Open Redirect in go.probo.inc/probo (CVE-2026-49820)
vulnerability in go.probo.inc/probo (CVE-2026-49820). Risk of unauthorized operations or information disclosure. Exploitable via ``saferedirect``. Mitigation: upgrade to `0.204.0` or later.
CVE-2026-58375 Vulnerability in CVE-2026-58375 (CVE-2026-58375)
vulnerability in CVE-2026-58375 (CVE-2026-58375). Confidential information can be exposed externally. Exploitable via `POST /jmreport/auto/export`.
CVE-2026-58176 Vulnerability in vue (CVE-2026-58176)
vulnerability in vue (CVE-2026-58176). Data can be tampered with by attackers.
CVE-2026-58373 Vulnerability in cvat (CVE-2026-58373)
vulnerability in cvat (CVE-2026-58373). Risk of unauthorized operations or information disclosure.
CVE-2026-58377 Vulnerability in CVE-2026-58377 (CVE-2026-58377)
vulnerability in CVE-2026-58377 (CVE-2026-58377). Confidential information can be exposed externally.
CVE-2026-58173 Path Traversal in path-traversal (CVE-2026-58173)
path traversal in path-traversal (CVE-2026-58173). Data can be tampered with by attackers.
CVE-2026-58372 Path Traversal in path-traversal (CVE-2026-58372)
path traversal in path-traversal (CVE-2026-58372). Data can be tampered with by attackers.
CVE-2026-58174 Vulnerability in CVE-2026-58174 (CVE-2026-58174)
vulnerability in CVE-2026-58174 (CVE-2026-58174). Confidential information can be exposed externally.
CVE-2026-58370 Vulnerability in CVE-2026-58370 (CVE-2026-58370)
vulnerability in CVE-2026-58370 (CVE-2026-58370). Successful exploitation can lead to full system takeover.
CVE-2026-58369 Vulnerability in CVE-2026-58369 (CVE-2026-58369)
vulnerability in CVE-2026-58369 (CVE-2026-58369). Risk of unauthorized operations or information disclosure.
CVE-2026-58376 SQL Injection in sqli (CVE-2026-58376)
SQL injection in sqli (CVE-2026-58376). Confidential information can be exposed externally.
CVE-2026-58371 Cross-Site Scripting (XSS) in CVE-2026-58371 (CVE-2026-58371)
cross-site scripting in CVE-2026-58371 (CVE-2026-58371). Risk of unauthorized operations or information disclosure.
CVE-2026-58172 Vulnerability in CVE-2026-58172 (CVE-2026-58172)
vulnerability in CVE-2026-58172 (CVE-2026-58172). Confidential information can be exposed externally.
CVE-2026-48315 Vulnerability in adobe (CVE-2026-48315)
vulnerability in adobe (CVE-2026-48315). Confidential information can be exposed externally.
CVE-2026-58167 Vulnerability in CVE-2026-58167 (CVE-2026-58167)
vulnerability in CVE-2026-58167 (CVE-2026-58167). Confidential information can be exposed externally. Exploitable via `POST /api/n9e/datasource/list.`.
CVE-2026-58165 Vulnerability in privilege-escalation (CVE-2026-58165)
vulnerability in privilege-escalation (CVE-2026-58165). Successful exploitation can lead to full system takeover.
CVE-2026-58168 Vulnerability in CVE-2026-58168 (CVE-2026-58168)
vulnerability in CVE-2026-58168 (CVE-2026-58168). Successful exploitation can lead to full system takeover.
CVE-2026-48314 Path Traversal in path-traversal (CVE-2026-48314)
path traversal in path-traversal (CVE-2026-48314). Risk of unauthorized operations or information disclosure.
CVE-2026-58170 Path Traversal in path-traversal (CVE-2026-58170)
path traversal in path-traversal (CVE-2026-58170). Data can be tampered with by attackers.
CVE-2026-58171 Path Traversal in CVE-2026-58171 (CVE-2026-58171)
path traversal in CVE-2026-58171 (CVE-2026-58171). Risk of unauthorized operations or information disclosure.
CVE-2026-58166 Path Traversal in path-traversal (CVE-2026-58166)
path traversal in path-traversal (CVE-2026-58166). Data can be tampered with by attackers.
CVE-2026-48286 Authorization Flaw in adobe (CVE-2026-48286)
vulnerability in adobe (CVE-2026-48286). Successful exploitation can lead to full system takeover.
CVE-2026-48285 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48285)
SSRF in ssrf (CVE-2026-48285). Confidential information can be exposed externally.
CVE-2026-48282 KEV [KEV] Path Traversal in Adobe path-traversal (CVE-2026-48282)
path traversal in Adobe path-traversal (CVE-2026-48282). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-48313 Path Traversal in path-traversal (CVE-2026-48313)
path traversal in path-traversal (CVE-2026-48313). Confidential information can be exposed externally.
CVE-2026-48307 Cross-Site Scripting (XSS) in adobe (CVE-2026-48307)
cross-site scripting in adobe (CVE-2026-48307). Successful exploitation can lead to full system takeover.
CVE-2026-48283 Unrestricted File Upload in adobe (CVE-2026-48283)
vulnerability in adobe (CVE-2026-48283). Successful exploitation can lead to full system takeover.
CVE-2026-48276 Unrestricted File Upload in adobe (CVE-2026-48276)
vulnerability in adobe (CVE-2026-48276). Successful exploitation can lead to full system takeover.
CVE-2026-48277 Vulnerability in adobe (CVE-2026-48277)
vulnerability in adobe (CVE-2026-48277). Successful exploitation can lead to full system takeover.
CVE-2026-48281 Vulnerability in adobe (CVE-2026-48281)
vulnerability in adobe (CVE-2026-48281). Successful exploitation can lead to full system takeover.
CVE-2026-48791 Vulnerability in dev.sigstore:sigstore-java (CVE-2026-48791)
vulnerability in dev.sigstore:sigstore-java (CVE-2026-48791). Risk of unauthorized operations or information disclosure. Exploitable via ``integratedTime``. Mitigation: upgrade to `2.1.0` or later.
CVE-2026-49473 Vulnerability in @cedar-policy/authorization-for-expressjs (CVE-2026-49473)
vulnerability in @cedar-policy/authorization-for-expressjs (CVE-2026-49473). Successful exploitation can lead to full system takeover. Exploitable via `GET /users`. Mitigation: upgrade to `0.3.0` or later.
CVE-2026-9263 Out-of-Bounds Read in c (CVE-2026-9263)
vulnerability in c (CVE-2026-9263). Confidential information can be exposed externally.
CVE-2026-10652 Out-of-Bounds Read in c (CVE-2026-10652)
vulnerability in c (CVE-2026-10652). Risk of unauthorized operations or information disclosure.
CVE-2026-10653 Vulnerability in c (CVE-2026-10653)
vulnerability in c (CVE-2026-10653). Risk of unauthorized operations or information disclosure.
CVE-2026-10655 Use-After-Free in c (CVE-2026-10655)
vulnerability in c (CVE-2026-10655). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →