Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-8589 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2026-8589)
cross-site scripting in gitlab (CVE-2026-8589). Confidential information can be exposed externally. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-7250 |
|
Vulnerability in gitlab (CVE-2026-7250)
vulnerability in gitlab (CVE-2026-7250). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-6269 |
|
Authorization Flaw in gitlab (CVE-2026-6269)
vulnerability in gitlab (CVE-2026-6269). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-6277 |
|
Authorization Flaw in gitlab (CVE-2026-6277)
vulnerability in gitlab (CVE-2026-6277). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-9204 |
|
SSRF (Server-Side Request Forgery) in gitlab (CVE-2026-9204)
SSRF in gitlab (CVE-2026-9204). Confidential information can be exposed externally. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-8464 |
|
Path Traversal in path-traversal (CVE-2026-8464)
path traversal in path-traversal (CVE-2026-8464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1500 |
|
Vulnerability in gitlab (CVE-2026-1500)
vulnerability in gitlab (CVE-2026-1500). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2022-45813 |
|
Vulnerability in CVE-2022-45813 (CVE-2022-45813)
vulnerability in CVE-2022-45813 (CVE-2022-45813). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-25969 |
|
Vulnerability in CVE-2023-25969 (CVE-2023-25969)
vulnerability in CVE-2023-25969 (CVE-2023-25969). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-32959 |
|
Vulnerability in CVE-2023-32959 (CVE-2023-32959)
vulnerability in CVE-2023-32959 (CVE-2023-32959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4764 |
|
Vulnerability in CVE-2026-4764 (CVE-2026-4764)
vulnerability in CVE-2026-4764 (CVE-2026-4764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3553 |
|
Authorization Flaw in gitlab (CVE-2026-3553)
vulnerability in gitlab (CVE-2026-3553). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-10087 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2026-10087)
cross-site scripting in gitlab (CVE-2026-10087). Confidential information can be exposed externally. Mitigation: upgrade to `18.10.8, 18.11.5, 19.0.2` or later.
|
| CVE-2026-53912 |
|
Information Disclosure in CVE-2026-53912 (CVE-2026-53912)
vulnerability in CVE-2026-53912 (CVE-2026-53912). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-47150 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2022-47150)
vulnerability in csrf (CVE-2022-47150). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53423 |
|
Vulnerability in membrane_mp4_plugin (CVE-2026-53423)
vulnerability in membrane_mp4_plugin (CVE-2026-53423). Risk of unauthorized operations or information disclosure. Exploitable via ``membrane_mp4_plugin``. Mitigation: upgrade to `0.36.7` or later.
|
| CVE-2026-5497 |
|
vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
|
| CVE-2025-7064 |
|
Vulnerability in CVE-2025-7064 (CVE-2025-7064)
vulnerability in CVE-2025-7064 (CVE-2025-7064). Data can be tampered with by attackers.
|
| CVE-2026-11850 |
|
Vulnerability in c (CVE-2026-11850)
vulnerability in c (CVE-2026-11850). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-44630 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2022-44630)
vulnerability in csrf (CVE-2022-44630). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-42479 |
|
Vulnerability in CVE-2022-42479 (CVE-2022-42479)
vulnerability in CVE-2022-42479 (CVE-2022-42479). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-32110 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2024-32110)
vulnerability in csrf (CVE-2024-32110). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53901 |
|
Vulnerability in CVE-2026-53901 (CVE-2026-53901)
vulnerability in CVE-2026-53901 (CVE-2026-53901). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.37` or later.
|
| CVE-2023-33999 |
|
Cross-Site Scripting (XSS) in CVE-2023-33999 (CVE-2023-33999)
cross-site scripting in CVE-2023-33999 (CVE-2023-33999). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41000 |
|
Vulnerability in org.springframework.ws:spring-ws-security (CVE-2026-41000)
vulnerability in org.springframework.ws:spring-ws-security (CVE-2026-41000). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41699 |
|
Unsafe Deserialization in org.springframework.graphql:spring-graphql (CVE-2026-41699)
vulnerability in org.springframework.graphql:spring-graphql (CVE-2026-41699). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41856 |
|
Vulnerability in org.springframework.graphql:spring-graphql (CVE-2026-41856)
vulnerability in org.springframework.graphql:spring-graphql (CVE-2026-41856). Confidential information can be exposed externally.
|
| CVE-2026-40999 |
|
SSRF (Server-Side Request Forgery) in org.springframework.ws:spring-ws-core (CVE-2026-40999)
SSRF in org.springframework.ws:spring-ws-core (CVE-2026-40999). Confidential information can be exposed externally.
|
| CVE-2026-40987 |
|
Path Traversal in org.springframework.integration:spring-integration-file (CVE-2026-40987)
path traversal in org.springframework.integration:spring-integration-file (CVE-2026-40987). Data can be tampered with by attackers. Mitigation: upgrade to `6.5.9` or later.
|
| CVE-2026-40995 |
|
Authentication Bypass in org.springframework.ws:spring-ws-security (CVE-2026-40995)
authentication bypass in org.springframework.ws:spring-ws-security (CVE-2026-40995). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40994 |
|
Vulnerability in org.springframework.ws:spring-ws-security (CVE-2026-40994)
vulnerability in org.springframework.ws:spring-ws-security (CVE-2026-40994). Data can be tampered with by attackers.
|
| CVE-2026-40997 |
|
Vulnerability in org.springframework.ws:spring-ws-security (CVE-2026-40997)
vulnerability in org.springframework.ws:spring-ws-security (CVE-2026-40997). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40992 |
|
Vulnerability in org.springframework.boot:spring-boot-starter-mail (CVE-2026-40992)
vulnerability in org.springframework.boot:spring-boot-starter-mail (CVE-2026-40992). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40998 |
|
XXE (XML External Entity) in org.springframework.ws:spring-xml (CVE-2026-40998)
vulnerability in org.springframework.ws:spring-xml (CVE-2026-40998). Confidential information can be exposed externally.
|
| CVE-2026-40986 |
|
Cross-Site Scripting (XSS) in org.springframework.webflow:spring-webflow (CVE-2026-40986)
cross-site scripting in org.springframework.webflow:spring-webflow (CVE-2026-40986). Data can be tampered with by attackers.
|
| CVE-2026-10795 |
|
Vulnerability in wordpress (CVE-2026-10795)
vulnerability in wordpress (CVE-2026-10795). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40985 |
|
Vulnerability in org.springframework.webflow:spring-webflow (CVE-2026-40985)
vulnerability in org.springframework.webflow:spring-webflow (CVE-2026-40985). Confidential information can be exposed externally.
|
| CVE-2026-35273 KEV |
|
[KEV] Vulnerability in Oracle c (CVE-2026-35273)
vulnerability in Oracle c (CVE-2026-35273). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-2827 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2827)
cross-site scripting in wordpress (CVE-2026-2827). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53460 |
|
Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-53460)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-53460). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.14.0` or later.
|
| CVE-2026-52726 |
|
Path Traversal in dulwich (CVE-2026-52726)
path traversal in dulwich (CVE-2026-52726). Risk of unauthorized operations or information disclosure. Exploitable via ``dulwich.porcelain.submodule_update``. Mitigation: upgrade to `1.2.5` or later.
|
| CVE-2026-53462 |
|
Use-After-Free in Magick.NET-Q16-AnyCPU (CVE-2026-53462)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-53462). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.14.0` or later.
|
| CVE-2026-53463 |
|
Vulnerability in imagemagick (CVE-2026-53463)
vulnerability in imagemagick (CVE-2026-53463). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53464 |
|
Vulnerability in imagemagick (CVE-2026-53464)
vulnerability in imagemagick (CVE-2026-53464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53461 |
|
Out-of-Bounds Write in Magick.NET-Q16-AnyCPU (CVE-2026-53461)
out-of-bounds write in Magick.NET-Q16-AnyCPU (CVE-2026-53461). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.14.0` or later.
|
| CVE-2026-53465 |
|
Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-53465)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-53465). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.14.0` or later.
|
| CVE-2026-49219 |
|
Information Disclosure in Magick.NET-Q16-AnyCPU (CVE-2026-49219)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-49219). Confidential information can be exposed externally. Mitigation: upgrade to `14.14.0` or later.
|
| CVE-2026-50223 |
|
Code Injection in apache (CVE-2026-50223)
code injection in apache (CVE-2026-50223). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49218 |
|
Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-49218)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-49218). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.14.0` or later.
|
| CVE-2026-48994 |
|
Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-48994)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-48994). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.14.0` or later.
|