Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-53779 |
|
Path Traversal in path-traversal (CVE-2026-53779)
path traversal in path-traversal (CVE-2026-53779). Confidential information can be exposed externally.
|
| CVE-2026-10852 |
|
Vulnerability in dos (CVE-2026-10852)
vulnerability in dos (CVE-2026-10852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11834 |
|
OS Command Injection in CVE-2026-11834 (CVE-2026-11834)
OS command injection in CVE-2026-11834 (CVE-2026-11834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46607 |
|
Unsafe Deserialization in glances (CVE-2026-46607)
vulnerability in glances (CVE-2026-46607). Successful exploitation can lead to full system takeover. Exploitable via ``self.cache_file``. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-55599 |
|
SSRF (Server-Side Request Forgery) in phpseclib/phpseclib (CVE-2026-55599)
SSRF in phpseclib/phpseclib (CVE-2026-55599). Risk of unauthorized operations or information disclosure. Exploitable via `GET /ssrf`. Mitigation: upgrade to `3.0.54` or later.
|
| CVE-2026-54651 |
|
Vulnerability in pypdf (CVE-2026-54651)
vulnerability in pypdf (CVE-2026-54651). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.13.1` or later.
|
| CVE-2026-46606 |
|
OS Command Injection in glances (CVE-2026-46606)
OS command injection in glances (CVE-2026-46606). Successful exploitation can lead to full system takeover. Exploitable via ``domain``. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-44795 |
|
Vulnerability in io.spinnaker.rosco:rosco-core (CVE-2026-44795)
vulnerability in io.spinnaker.rosco:rosco-core (CVE-2026-44795). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2025.3.3` or later.
|
| CVE-2026-44585 |
|
Vulnerability in paymenter/paymenter (CVE-2026-44585)
vulnerability in paymenter/paymenter (CVE-2026-44585). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.0` or later.
|
| CVE-2026-44583 |
|
SSRF (Server-Side Request Forgery) in paymenter/paymenter (CVE-2026-44583)
SSRF in paymenter/paymenter (CVE-2026-44583). Risk of unauthorized operations or information disclosure. Exploitable via ``file_get_contents``. Mitigation: upgrade to `1.5.0` or later.
|
| CVE-2026-44517 |
|
Path Traversal in github.com/containers/buildah (CVE-2026-44517)
path traversal in github.com/containers/buildah (CVE-2026-44517). Confidential information can be exposed externally. Exploitable via ``add``. Mitigation: upgrade to `1.43.2` or later.
|
| CVE-2026-33692 |
|
Vulnerability in wwbn/avideo (CVE-2026-33692)
vulnerability in wwbn/avideo (CVE-2026-33692). Confidential information can be exposed externally. Exploitable via `GET /.env`. Mitigation: upgrade to `29.0` or later.
|
| CVE-2026-55443 |
|
Path Traversal in langchain (CVE-2026-55443)
path traversal in langchain (CVE-2026-55443). Confidential information can be exposed externally. Mitigation: upgrade to `1.3.9` or later.
|
| CVE-2026-56109 |
|
Vulnerability in c (CVE-2026-56109)
vulnerability in c (CVE-2026-56109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42127 |
|
Vulnerability in dos (CVE-2026-42127)
vulnerability in dos (CVE-2026-42127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11994 |
|
Cross-Site Scripting (XSS) in CVE-2026-11994 (CVE-2026-11994)
cross-site scripting in CVE-2026-11994 (CVE-2026-11994). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10789 |
|
Code Injection in autodesk (CVE-2026-10789)
code injection in autodesk (CVE-2026-10789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33684 |
|
Vulnerability in wwbn/avideo (CVE-2026-33684)
vulnerability in wwbn/avideo (CVE-2026-33684). Risk of unauthorized operations or information disclosure. Exploitable via ``set_api_signUp``. Mitigation: upgrade to `29.0` or later.
|
| CVE-2026-33646 |
|
Code Injection in mise (CVE-2026-33646)
code injection in mise (CVE-2026-33646). Successful exploitation can lead to full system takeover. Exploitable via ``tera_exec``. Mitigation: upgrade to `2026.3.10` or later.
|
| CVE-2026-32315 |
|
Information Disclosure in motioneye (CVE-2026-32315)
vulnerability in motioneye (CVE-2026-32315). Confidential information can be exposed externally. Exploitable via ``motion.conf``. Mitigation: upgrade to `0.44.0` or later.
|
| CVE-2026-31978 |
|
Path Traversal in motioneye (CVE-2026-31978)
path traversal in motioneye (CVE-2026-31978). Confidential information can be exposed externally. Exploitable via ``mediafiles.py``. Mitigation: upgrade to `0.44.0` or later.
|
| CVE-2026-25119 |
|
Vulnerability in gogs.io/gogs (CVE-2026-25119)
vulnerability in gogs.io/gogs (CVE-2026-25119). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-64719 |
|
Vulnerability in gogs.io/gogs (CVE-2025-64719)
vulnerability in gogs.io/gogs (CVE-2025-64719). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9610 |
|
Vulnerability in ibm (CVE-2026-9610)
vulnerability in ibm (CVE-2026-9610). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9072 |
|
Code Injection in dos (CVE-2026-9072)
code injection in dos (CVE-2026-9072). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9071 |
|
Vulnerability in dos (CVE-2026-9071)
vulnerability in dos (CVE-2026-9071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9320 |
|
Vulnerability in dos (CVE-2026-9320)
vulnerability in dos (CVE-2026-9320). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8934 |
|
Vulnerability in CVE-2026-8934 (CVE-2026-8934)
vulnerability in CVE-2026-8934 (CVE-2026-8934). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9006 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9006)
SSRF in ssrf (CVE-2026-9006). Confidential information can be exposed externally.
|
| CVE-2026-8823 |
|
Authorization Flaw in mattermost (CVE-2026-8823)
vulnerability in mattermost (CVE-2026-8823). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8646 |
|
Vulnerability in ibm (CVE-2026-8646)
vulnerability in ibm (CVE-2026-8646). Confidential information can be exposed externally.
|
| CVE-2026-8858 |
|
Code Injection in dos (CVE-2026-8858)
code injection in dos (CVE-2026-8858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7664 |
|
Authentication Bypass in langflow (CVE-2026-7664)
authentication bypass in langflow (CVE-2026-7664). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7253 |
|
SQL Injection in ssrf (CVE-2026-7253)
SQL injection in ssrf (CVE-2026-7253). Confidential information can be exposed externally.
|
| CVE-2026-8059 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2026-8059)
cross-site scripting in ibm (CVE-2026-8059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56104 |
|
Vulnerability in CVE-2026-56104 (CVE-2026-56104)
vulnerability in CVE-2026-56104 (CVE-2026-56104). Confidential information can be exposed externally.
|
| CVE-2026-50178 |
|
Cross-Site Scripting (XSS) in angular (CVE-2026-50178)
cross-site scripting in angular (CVE-2026-50178). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `21.2.4` or later.
|
| CVE-2026-49241 |
|
Cross-Site Scripting (XSS) in angular (CVE-2026-49241)
cross-site scripting in angular (CVE-2026-49241). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `21.2.4` or later.
|
| CVE-2026-41046 |
|
Vulnerability in path-traversal (CVE-2026-41046)
vulnerability in path-traversal (CVE-2026-41046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41048 |
|
Authorization Flaw in presire (CVE-2026-41048)
vulnerability in presire (CVE-2026-41048). Data can be tampered with by attackers.
|
| CVE-2026-41049 |
|
Authorization Flaw in presire (CVE-2026-41049)
vulnerability in presire (CVE-2026-41049). Data can be tampered with by attackers.
|
| CVE-2026-41047 |
|
Vulnerability in presire (CVE-2026-41047)
vulnerability in presire (CVE-2026-41047). Confidential information can be exposed externally.
|
| CVE-2026-12725 |
|
Vulnerability in dos (CVE-2026-12725)
vulnerability in dos (CVE-2026-12725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41045 |
|
Vulnerability in presire (CVE-2026-41045)
vulnerability in presire (CVE-2026-41045). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12628 |
|
Vulnerability in ibm (CVE-2026-12628)
vulnerability in ibm (CVE-2026-12628). Confidential information can be exposed externally.
|
| CVE-2026-12479 |
|
Path Traversal in keras (CVE-2026-12479)
path traversal in keras (CVE-2026-12479). Risk of unauthorized operations or information disclosure. Exploitable via ``DiskIOStore.make``. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-11942 |
|
Cross-Site Scripting (XSS) in CVE-2026-11942 (CVE-2026-11942)
cross-site scripting in CVE-2026-11942 (CVE-2026-11942). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11943 |
|
Cross-Site Scripting (XSS) in CVE-2026-11943 (CVE-2026-11943)
cross-site scripting in CVE-2026-11943 (CVE-2026-11943). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11372 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2026-11372)
cross-site scripting in ibm (CVE-2026-11372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10845 |
|
Authentication Bypass in ibm (CVE-2026-10845)
authentication bypass in ibm (CVE-2026-10845). Risk of unauthorized operations or information disclosure.
|