Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48758 |
|
Vulnerability in @sigstore/core (CVE-2026-48758)
vulnerability in @sigstore/core (CVE-2026-48758). Risk of unauthorized operations or information disclosure. Exploitable via ``preAuthEncoding``. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-48756 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48756)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48756). Risk of unauthorized operations or information disclosure. Exploitable via `POST /1.0/storage-pools/`. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-48755 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48755)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48755). Successful exploitation can lead to full system takeover. Exploitable via ``compression_algorithm``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48754 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48754)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48754). Risk of unauthorized operations or information disclosure. Exploitable via `POST /1.0/instances`. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-48753 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-48752 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48752)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48752). Successful exploitation can lead to full system takeover. Exploitable via ``templates``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-56876 |
|
Path Traversal in extract-zip (CVE-2026-56876)
path traversal in extract-zip (CVE-2026-56876). Confidential information can be exposed externally.
|
| CVE-2026-57518 |
|
Vulnerability in privilege-escalation (CVE-2026-57518)
vulnerability in privilege-escalation (CVE-2026-57518). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5757 |
|
Out-of-Bounds Read in ollama (CVE-2026-5757)
vulnerability in ollama (CVE-2026-5757). Confidential information can be exposed externally.
|
| CVE-2026-13434 |
|
Vulnerability in kubevirt (CVE-2026-13434)
vulnerability in kubevirt (CVE-2026-13434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45195 |
|
Vulnerability in imaginationtech (CVE-2026-45195)
vulnerability in imaginationtech (CVE-2026-45195). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21734 |
|
Vulnerability in imaginationtech (CVE-2026-21734)
vulnerability in imaginationtech (CVE-2026-21734). Data can be tampered with by attackers.
|
| CVE-2023-20572 |
|
Vulnerability in CVE-2023-20572 (CVE-2023-20572)
vulnerability in CVE-2023-20572 (CVE-2023-20572). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-20540 |
|
Vulnerability in CVE-2023-20540 (CVE-2023-20540)
vulnerability in CVE-2023-20540 (CVE-2023-20540). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48751 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751). Successful exploitation can lead to full system takeover. Exploitable via ``raw.lxc``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48750 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48750)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48750). Successful exploitation can lead to full system takeover. Exploitable via ``exec_UUID.stdout``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48749 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48749)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48749). Successful exploitation can lead to full system takeover. Exploitable via ``metadata.yaml``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48743 |
|
Vulnerability in envoyproxy (CVE-2026-48743)
vulnerability in envoyproxy (CVE-2026-48743). Data can be tampered with by attackers. Exploitable via `GET /pwn`. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-48706 |
|
Vulnerability in envoyproxy (CVE-2026-48706)
vulnerability in envoyproxy (CVE-2026-48706). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-54341 |
|
Out-of-Bounds Read in dos (CVE-2026-54341)
vulnerability in dos (CVE-2026-54341). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.39.0` or later.
|
| CVE-2026-47221 |
|
Vulnerability in dos (CVE-2026-47221)
vulnerability in dos (CVE-2026-47221). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-47775 |
|
Vulnerability in envoyproxy (CVE-2026-47775)
vulnerability in envoyproxy (CVE-2026-47775). Confidential information can be exposed externally. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-47692 |
|
Vulnerability in envoyproxy (CVE-2026-47692)
vulnerability in envoyproxy (CVE-2026-47692). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-47778 |
|
Vulnerability in c (CVE-2026-47778)
vulnerability in c (CVE-2026-47778). Confidential information can be exposed externally. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-47206 |
|
Vulnerability in CVE-2026-47206 (CVE-2026-47206)
vulnerability in CVE-2026-47206 (CVE-2026-47206). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.39.9` or later.
|
| CVE-2026-47207 |
|
Use-After-Free in envoyproxy (CVE-2026-47207)
vulnerability in envoyproxy (CVE-2026-47207). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-47204 |
|
Vulnerability in envoyproxy (CVE-2026-47204)
vulnerability in envoyproxy (CVE-2026-47204). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-54636 |
|
OS Command Injection in dokku (CVE-2026-54636)
OS command injection in dokku (CVE-2026-54636). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.7` or later.
|
| CVE-2026-56663 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-56663)
SSRF in ssrf (CVE-2026-56663). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.6.52` or later.
|
| CVE-2026-55677 |
|
Path Traversal in github.com/labstack/echo/v5 (CVE-2026-55677)
path traversal in github.com/labstack/echo/v5 (CVE-2026-55677). Confidential information can be exposed externally. Exploitable via ``StaticDirectoryHandler``. Mitigation: upgrade to `5.2.0` or later.
|
| CVE-2026-56823 |
|
Vulnerability in CVE-2026-56823 (CVE-2026-56823)
vulnerability in CVE-2026-56823 (CVE-2026-56823). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/integrations/webhooks/{webhook_id}/ping`.
|
| CVE-2026-57231 |
|
Information Disclosure in podman-project (CVE-2026-57231)
vulnerability in podman-project (CVE-2026-57231). Confidential information can be exposed externally. Mitigation: upgrade to `5.8.4` or later.
|
| CVE-2026-45407 |
|
Vulnerability in dokku (CVE-2026-45407)
vulnerability in dokku (CVE-2026-45407). Confidential information can be exposed externally. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-45406 |
|
Vulnerability in dokku (CVE-2026-45406)
vulnerability in dokku (CVE-2026-45406). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-45405 |
|
Vulnerability in dokku (CVE-2026-45405)
vulnerability in dokku (CVE-2026-45405). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-45408 |
|
OS Command Injection in dokku (CVE-2026-45408)
OS command injection in dokku (CVE-2026-45408). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-28385 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-28385)
SSRF in ssrf (CVE-2026-28385). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-32394 |
|
Vulnerability in dos (CVE-2025-32394)
vulnerability in dos (CVE-2025-32394). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.32` or later.
|
| CVE-2025-32423 |
|
Vulnerability in dos (CVE-2025-32423)
vulnerability in dos (CVE-2025-32423). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6.32` or later.
|
| CVE-2026-44161 |
|
SSRF (Server-Side Request Forgery) in fluentd (CVE-2026-44161)
SSRF in fluentd (CVE-2026-44161). Risk of unauthorized operations or information disclosure. Exploitable via ``out_http``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-44025 |
|
Vulnerability in fluentd (CVE-2026-44025)
vulnerability in fluentd (CVE-2026-44025). Confidential information can be exposed externally. Exploitable via ``in_monitor_agent``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-44024 |
|
Path Traversal in fluentd (CVE-2026-44024)
path traversal in fluentd (CVE-2026-44024). Successful exploitation can lead to full system takeover. Exploitable via ``path``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-9640 |
|
Authorization Flaw in privilege-escalation (CVE-2026-9640)
vulnerability in privilege-escalation (CVE-2026-9640). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9639 |
|
Vulnerability in dos (CVE-2026-9639)
vulnerability in dos (CVE-2026-9639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12411 |
|
Vulnerability in canonical (CVE-2026-12411)
vulnerability in canonical (CVE-2026-12411). Confidential information can be exposed externally.
|
| CVE-2026-57640 |
|
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
|
| CVE-2026-57645 |
|
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
|
| CVE-2026-57654 |
|
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
|
| CVE-2026-57648 |
|
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
|
| CVE-2026-57649 |
|
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
|