Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48112 |
|
Out-of-Bounds Read in 7-zip (CVE-2026-48112)
vulnerability in 7-zip (CVE-2026-48112). Confidential information can be exposed externally.
|
| CVE-2026-48103 |
|
Out-of-Bounds Read in cpp (CVE-2026-48103)
vulnerability in cpp (CVE-2026-48103). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48104 |
|
Out-of-Bounds Read in dos (CVE-2026-48104)
vulnerability in dos (CVE-2026-48104). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48111 |
|
Out-of-Bounds Read in cpp (CVE-2026-48111)
vulnerability in cpp (CVE-2026-48111). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11339 |
|
Vulnerability in c (CVE-2026-11339)
vulnerability in c (CVE-2026-11339). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11338 |
|
Cross-Site Scripting (XSS) in CVE-2026-11338 (CVE-2026-11338)
cross-site scripting in CVE-2026-11338 (CVE-2026-11338). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11337 |
|
Cross-Site Scripting (XSS) in CVE-2026-11337 (CVE-2026-11337)
cross-site scripting in CVE-2026-11337 (CVE-2026-11337). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-5089 |
|
Vulnerability in dos (CVE-2025-5089)
vulnerability in dos (CVE-2025-5089). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-5090 |
|
Vulnerability in dos (CVE-2025-5090)
vulnerability in dos (CVE-2025-5090). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-5088 |
|
Privilege Escalation in CVE-2025-5088 (CVE-2025-5088)
vulnerability in CVE-2025-5088 (CVE-2025-5088). Confidential information can be exposed externally.
|
| CVE-2026-54533 |
|
Vulnerability in vantage6 (CVE-2026-54533)
vulnerability in vantage6 (CVE-2026-54533). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.0` or later.
|
| CVE-2026-54445 |
|
Vulnerability in vantage6 (CVE-2026-54445)
vulnerability in vantage6 (CVE-2026-54445). Risk of unauthorized operations or information disclosure. Exploitable via ``root``. Mitigation: upgrade to `5.0.0` or later.
|
| CVE-2026-52878 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-52878)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52878). Risk of unauthorized operations or information disclosure. Exploitable via `POST /transaction/send`. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2026-52880 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-52880)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52880). Risk of unauthorized operations or information disclosure. Exploitable via ``Engine.Run``. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2026-52879 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-52879)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52879). Risk of unauthorized operations or information disclosure. Exploitable via ``networkMessenger.directMessageHandler``. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2026-49343 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-49343)
vulnerability in github.com/klever-io/klever-go (CVE-2026-49343). Risk of unauthorized operations or information disclosure. Exploitable via ``NumGoRoutinesThrottler``. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2026-48017 |
|
Code Injection in dbgate-api (CVE-2026-48017)
code injection in dbgate-api (CVE-2026-48017). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/load-reader`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47684 |
|
SSRF (Server-Side Request Forgery) in @sync-in/server (CVE-2026-47684)
SSRF in @sync-in/server (CVE-2026-47684). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-47670 |
|
Command Injection in dbgate-api (CVE-2026-47670)
command injection in dbgate-api (CVE-2026-47670). Risk of unauthorized operations or information disclosure. Exploitable via ``functionName``. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47669 |
|
Path Traversal in dbgate (CVE-2026-47669)
path traversal in dbgate (CVE-2026-47669). Risk of unauthorized operations or information disclosure. Exploitable via `POST /auth/login`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47668 |
|
Vulnerability in dbgate-serve (CVE-2026-47668)
vulnerability in dbgate-serve (CVE-2026-47668). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/start`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47387 |
|
Cross-Site Scripting (XSS) in nocodb (CVE-2026-47387)
cross-site scripting in nocodb (CVE-2026-47387). Risk of unauthorized operations or information disclosure. Exploitable via ``redirect_url``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47386 |
|
Vulnerability in nocodb (CVE-2026-47386)
vulnerability in nocodb (CVE-2026-47386). Risk of unauthorized operations or information disclosure. Exploitable via ``is_used``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47385 |
|
Path Traversal in nocodb (CVE-2026-47385)
path traversal in nocodb (CVE-2026-47385). Risk of unauthorized operations or information disclosure. Exploitable via ``fs.exists``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47384 |
|
SQL Injection in nocodb (CVE-2026-47384)
SQL injection in nocodb (CVE-2026-47384). Risk of unauthorized operations or information disclosure. Exploitable via ``column_name``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47383 |
|
Cross-Site Scripting (XSS) in nocodb (CVE-2026-47383)
cross-site scripting in nocodb (CVE-2026-47383). Risk of unauthorized operations or information disclosure. Exploitable via ``localStorage``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47382 |
|
SSRF (Server-Side Request Forgery) in nocodb (CVE-2026-47382)
SSRF in nocodb (CVE-2026-47382). Risk of unauthorized operations or information disclosure. Exploitable via ``localhost``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-11362 |
|
Vulnerability in binary (CVE-2026-11362)
vulnerability in binary (CVE-2026-11362). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9270 |
|
Vulnerability in binary (CVE-2026-9270)
vulnerability in binary (CVE-2026-9270). Confidential information can be exposed externally.
|
| CVE-2026-48102 |
|
Out-of-Bounds Read in cpp (CVE-2026-48102)
vulnerability in cpp (CVE-2026-48102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48101 |
|
Vulnerability in 7-zip (CVE-2026-48101)
vulnerability in 7-zip (CVE-2026-48101). Confidential information can be exposed externally.
|
| CVE-2026-11336 |
|
Vulnerability in CVE-2026-11336 (CVE-2026-11336)
vulnerability in CVE-2026-11336 (CVE-2026-11336). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47381 |
|
Vulnerability in nocodb (CVE-2026-47381)
vulnerability in nocodb (CVE-2026-47381). Risk of unauthorized operations or information disclosure. Exploitable via ``testConnection``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47380 |
|
Vulnerability in nocodb (CVE-2026-47380)
vulnerability in nocodb (CVE-2026-47380). Risk of unauthorized operations or information disclosure. Exploitable via ``auth.service.ts``. Mitigation: upgrade to `2026.04.1` or later.
|
| CVE-2026-47379 |
|
Information Disclosure in nocodb (CVE-2026-47379)
vulnerability in nocodb (CVE-2026-47379). Risk of unauthorized operations or information disclosure. Exploitable via ``View.ts``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47377 |
|
Open Redirect in nocodb (CVE-2026-47377)
vulnerability in nocodb (CVE-2026-47377). Risk of unauthorized operations or information disclosure. Exploitable via ``hashRedirect``. Mitigation: upgrade to `2026.04.1` or later.
|
| CVE-2026-47376 |
|
Cross-Site Scripting (XSS) in nocodb (CVE-2026-47376)
cross-site scripting in nocodb (CVE-2026-47376). Risk of unauthorized operations or information disclosure. Exploitable via ``dataset.token``. Mitigation: upgrade to `2026.04.1` or later.
|
| CVE-2026-47375 |
|
SQL Injection in nocodb (CVE-2026-47375)
SQL injection in nocodb (CVE-2026-47375). Risk of unauthorized operations or information disclosure. Exploitable via ``columnAdd``. Mitigation: upgrade to `2026.04.1` or later.
|
| CVE-2026-47279 |
|
Vulnerability in nocodb (CVE-2026-47279)
vulnerability in nocodb (CVE-2026-47279). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v2/public/shared-view/`. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47250 |
|
Vulnerability in mcp-server-kubernetes (CVE-2026-47250)
vulnerability in mcp-server-kubernetes (CVE-2026-47250). Confidential information can be exposed externally. Exploitable via ``kubectl_generic``. Mitigation: upgrade to `3.7.0` or later.
|
| CVE-2026-6209 |
|
Vulnerability in CVE-2026-6209 (CVE-2026-6209)
vulnerability in CVE-2026-6209 (CVE-2026-6209). Confidential information can be exposed externally.
|
| CVE-2026-11333 |
|
Vulnerability in CVE-2026-11333 (CVE-2026-11333)
vulnerability in CVE-2026-11333 (CVE-2026-11333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10879 |
|
Out-of-Bounds Write in perl (CVE-2026-10879)
out-of-bounds write in perl (CVE-2026-10879). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11334 |
|
Vulnerability in sqli (CVE-2026-11334)
vulnerability in sqli (CVE-2026-11334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38579 |
|
Cross-Site Scripting (XSS) in CVE-2026-38579 (CVE-2026-38579)
cross-site scripting in CVE-2026-38579 (CVE-2026-38579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47249 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-47249)
vulnerability in github.com/klever-io/klever-go (CVE-2026-47249). Risk of unauthorized operations or information disclosure. Exploitable via ``RequestDataType_HashArrayType``. Mitigation: upgrade to `1.7.18` or later.
|
| CVE-2024-24769 |
|
Vulnerability in vantage6 (CVE-2024-24769)
vulnerability in vantage6 (CVE-2024-24769). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.0` or later.
|
| CVE-2026-48092 |
|
Out-of-Bounds Read in 7-zip (CVE-2026-48092)
vulnerability in 7-zip (CVE-2026-48092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48095 |
|
Vulnerability in dos (CVE-2026-48095)
vulnerability in dos (CVE-2026-48095). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50234 |
|
Path Traversal in c (CVE-2026-50234)
path traversal in c (CVE-2026-50234). Confidential information can be exposed externally.
|