Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48702 |
|
Vulnerability in github.com/sigstore/rekor (CVE-2026-48702)
vulnerability in github.com/sigstore/rekor (CVE-2026-48702). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/log/entries`. Mitigation: upgrade to `1.5.2` or later.
|
| CVE-2026-48529 |
|
Vulnerability in github.com/github/github-mcp-server (CVE-2026-48529)
vulnerability in github.com/github/github-mcp-server (CVE-2026-48529). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-38637 |
|
Vulnerability in dos (CVE-2026-38637)
vulnerability in dos (CVE-2026-38637). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56445 |
|
Path Traversal in c (CVE-2026-56445)
path traversal in c (CVE-2026-56445). Data can be tampered with by attackers.
|
| CVE-2026-6679 |
|
Vulnerability in wolfssl (CVE-2026-6679)
vulnerability in wolfssl (CVE-2026-6679). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6681 |
|
Vulnerability in wolfssl (CVE-2026-6681)
vulnerability in wolfssl (CVE-2026-6681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6678 |
|
Vulnerability in wolfssl (CVE-2026-6678)
vulnerability in wolfssl (CVE-2026-6678). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6731 |
|
Vulnerability in wolfssl (CVE-2026-6731)
vulnerability in wolfssl (CVE-2026-6731). Data can be tampered with by attackers.
|
| CVE-2026-6450 |
|
Vulnerability in wolfssl (CVE-2026-6450)
vulnerability in wolfssl (CVE-2026-6450). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10592 |
|
Vulnerability in wolfssl (CVE-2026-10592)
vulnerability in wolfssl (CVE-2026-10592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11310 |
|
Vulnerability in wolfssl (CVE-2026-11310)
vulnerability in wolfssl (CVE-2026-11310). Data can be tampered with by attackers.
|
| CVE-2026-55964 |
|
Vulnerability in wolfssl (CVE-2026-55964)
vulnerability in wolfssl (CVE-2026-55964). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55960 |
|
Vulnerability in wolfssl (CVE-2026-55960)
vulnerability in wolfssl (CVE-2026-55960). Data can be tampered with by attackers.
|
| CVE-2026-57522 |
|
Vulnerability in bitwarden (CVE-2026-57522)
vulnerability in bitwarden (CVE-2026-57522). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37453 |
|
Information Disclosure in msi (CVE-2026-37453)
vulnerability in msi (CVE-2026-37453). Confidential information can be exposed externally.
|
| CVE-2026-37454 |
|
Information Disclosure in msi (CVE-2026-37454)
vulnerability in msi (CVE-2026-37454). Confidential information can be exposed externally.
|
| CVE-2026-37452 |
|
Information Disclosure in CVE-2026-37452 (CVE-2026-37452)
vulnerability in CVE-2026-37452 (CVE-2026-37452). Confidential information can be exposed externally.
|
| CVE-2026-12340 |
|
Out-of-Bounds Read in dos (CVE-2026-12340)
vulnerability in dos (CVE-2026-12340). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7531 |
|
Use-After-Free in wolfssl (CVE-2026-7531)
vulnerability in wolfssl (CVE-2026-7531). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55958 |
|
Vulnerability in dos (CVE-2026-55958)
vulnerability in dos (CVE-2026-55958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37149 |
|
SQL Injection in sqli (CVE-2026-37149)
SQL injection in sqli (CVE-2026-37149). Confidential information can be exposed externally.
|
| CVE-2026-38640 |
|
Vulnerability in dos (CVE-2026-38640)
vulnerability in dos (CVE-2026-38640). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57520 |
|
Vulnerability in privilege-escalation (CVE-2026-57520)
vulnerability in privilege-escalation (CVE-2026-57520). Data can be tampered with by attackers.
|
| CVE-2026-2299 |
|
Vulnerability in mattermost (CVE-2026-2299)
vulnerability in mattermost (CVE-2026-2299). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57521 |
|
Vulnerability in bitwarden (CVE-2026-57521)
vulnerability in bitwarden (CVE-2026-57521). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12473 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-12473 (CVE-2026-12473)
SSRF in CVE-2026-12473 (CVE-2026-12473). Confidential information can be exposed externally.
|
| CVE-2026-56769 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-56769 (CVE-2026-56769)
SSRF in CVE-2026-56769 (CVE-2026-56769). Confidential information can be exposed externally.
|
| CVE-2026-56771 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-56771 (CVE-2026-56771)
SSRF in CVE-2026-56771 (CVE-2026-56771). Data can be tampered with by attackers.
|
| CVE-2026-56779 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-56779 (CVE-2026-56779)
SSRF in CVE-2026-56779 (CVE-2026-56779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56789 |
|
Vulnerability in c (CVE-2026-56789)
vulnerability in c (CVE-2026-56789). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57700 |
|
Unrestricted File Upload in CVE-2026-57700 (CVE-2026-57700)
vulnerability in CVE-2026-57700 (CVE-2026-57700). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56788 |
|
Out-of-Bounds Read in dos (CVE-2026-56788)
vulnerability in dos (CVE-2026-56788). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-60465 |
|
Use-After-Free in c (CVE-2025-60465)
vulnerability in c (CVE-2025-60465). Data can be tampered with by attackers.
|
| CVE-2025-60464 |
|
Use-After-Free in c (CVE-2025-60464)
vulnerability in c (CVE-2025-60464). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56786 |
|
Out-of-Bounds Write in dos (CVE-2026-56786)
out-of-bounds write in dos (CVE-2026-56786). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56790 |
|
Vulnerability in c (CVE-2026-56790)
vulnerability in c (CVE-2026-56790). Data can be tampered with by attackers.
|
| CVE-2026-56787 |
|
Vulnerability in c (CVE-2026-56787)
vulnerability in c (CVE-2026-56787). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10097 |
|
Vulnerability in wolfssl (CVE-2026-10097)
vulnerability in wolfssl (CVE-2026-10097). Confidential information can be exposed externally.
|
| CVE-2026-56766 |
|
Vulnerability in CVE-2026-56766 (CVE-2026-56766)
vulnerability in CVE-2026-56766 (CVE-2026-56766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56768 |
|
Vulnerability in CVE-2026-56768 (CVE-2026-56768)
vulnerability in CVE-2026-56768 (CVE-2026-56768). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v2.1/share-link-zip-task/`.
|
| CVE-2026-56767 |
|
Vulnerability in CVE-2026-56767 (CVE-2026-56767)
vulnerability in CVE-2026-56767 (CVE-2026-56767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12897 |
|
Out-of-Bounds Read in CVE-2026-12897 (CVE-2026-12897)
vulnerability in CVE-2026-12897 (CVE-2026-12897). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12921 |
|
Use-After-Free in azeotech (CVE-2026-12921)
vulnerability in azeotech (CVE-2026-12921). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55667 |
|
Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55667)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55667). Data can be tampered with by attackers. Exploitable via `GET /api/raw/link/secret.txt`. Mitigation: upgrade to `2.63.16` or later.
|
| CVE-2026-54917 |
|
Path Traversal in github.com/seaweedfs/seaweedfs (CVE-2026-54917)
path traversal in github.com/seaweedfs/seaweedfs (CVE-2026-54917). Confidential information can be exposed externally. Exploitable via `GET /bucket-A/../evil-bucket/key`. Mitigation: upgrade to `0.0.0-20260526080459-dd1b4287899e` or later.
|
| CVE-2026-54250 |
|
Path Traversal in github.com/k3s-io/k3s (CVE-2026-54250)
path traversal in github.com/k3s-io/k3s (CVE-2026-54250). Data can be tampered with by attackers. Exploitable via ``GODEBUG``. Mitigation: upgrade to `1.33.10` or later.
|
| CVE-2026-54089 |
|
Authentication Bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089)
authentication bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089). Confidential information can be exposed externally. Exploitable via `POST /api/login`.
|
| CVE-2026-54088 |
|
OS Command Injection in github.com/filebrowser/filebrowser/v2 (CVE-2026-54088)
OS command injection in github.com/filebrowser/filebrowser/v2 (CVE-2026-54088). Risk of unauthorized operations or information disclosure. Exploitable via ``os.Expand``. Mitigation: upgrade to `2.63.6` or later.
|
| CVE-2026-50549 |
|
Vulnerability in anysphere (CVE-2026-50549)
vulnerability in anysphere (CVE-2026-50549). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.0` or later.
|
| CVE-2026-50548 |
|
Path Traversal in anysphere (CVE-2026-50548)
path traversal in anysphere (CVE-2026-50548). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.0` or later.
|