Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-47335 |
|
Vulnerability in canonical (CVE-2026-47335)
vulnerability in canonical (CVE-2026-47335). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47337 |
|
Vulnerability in canonical (CVE-2026-47337)
vulnerability in canonical (CVE-2026-47337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47332 |
|
Out-of-Bounds Read in canonical (CVE-2026-47332)
vulnerability in canonical (CVE-2026-47332). Confidential information can be exposed externally.
|
| CVE-2026-47331 |
|
Use-After-Free in canonical (CVE-2026-47331)
vulnerability in canonical (CVE-2026-47331). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47327 |
|
Vulnerability in canonical (CVE-2026-47327)
vulnerability in canonical (CVE-2026-47327). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47326 |
|
Vulnerability in canonical (CVE-2026-47326)
vulnerability in canonical (CVE-2026-47326). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47136 |
|
Information Disclosure in CVE-2026-47136 (CVE-2026-47136)
vulnerability in CVE-2026-47136 (CVE-2026-47136). Risk of unauthorized operations or information disclosure. Exploitable via `GET /rustfs/console/license`. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-46685 |
|
Vulnerability in CVE-2026-46685 (CVE-2026-46685)
vulnerability in CVE-2026-46685 (CVE-2026-46685). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-45044 |
|
Vulnerability in dos (CVE-2026-45044)
vulnerability in dos (CVE-2026-45044). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-45040 |
|
Vulnerability in CVE-2026-45040 (CVE-2026-45040)
vulnerability in CVE-2026-45040 (CVE-2026-45040). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-45039 |
|
Vulnerability in CVE-2026-45039 (CVE-2026-45039)
vulnerability in CVE-2026-45039 (CVE-2026-45039). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-45041 |
|
Vulnerability in CVE-2026-45041 (CVE-2026-45041)
vulnerability in CVE-2026-45041 (CVE-2026-45041). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-44394 |
|
Authorization Flaw in keystone (CVE-2026-44394)
vulnerability in keystone (CVE-2026-44394). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v3/auth/tokens`. Mitigation: upgrade to `29.0.2` or later.
|
| CVE-2026-45042 |
|
Authorization Flaw in CVE-2026-45042 (CVE-2026-45042)
vulnerability in CVE-2026-45042 (CVE-2026-45042). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.0-beta.2` or later.
|
| CVE-2026-42998 |
|
Authorization Flaw in keystone (CVE-2026-42998)
vulnerability in keystone (CVE-2026-42998). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `29.0.2` or later.
|
| CVE-2026-42999 |
|
Vulnerability in keystone (CVE-2026-42999)
vulnerability in keystone (CVE-2026-42999). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `29.0.2` or later.
|
| CVE-2026-43000 |
|
Vulnerability in keystone (CVE-2026-43000)
vulnerability in keystone (CVE-2026-43000). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `29.0.2` or later.
|
| CVE-2026-30760 |
|
Vulnerability in CVE-2026-30760 (CVE-2026-30760)
vulnerability in CVE-2026-30760 (CVE-2026-30760). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30761 |
|
Unrestricted File Upload in CVE-2026-30761 (CVE-2026-30761)
vulnerability in CVE-2026-30761 (CVE-2026-30761). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46439 |
|
Code Injection in compliance-trestle (CVE-2026-46439)
code injection in compliance-trestle (CVE-2026-46439). Successful exploitation can lead to full system takeover. Exploitable via ``render_template``. Mitigation: upgrade to `4.0.3` or later.
|
| CVE-2026-46405 |
|
Vulnerability in github.com/openbao/openbao (CVE-2026-46405)
vulnerability in github.com/openbao/openbao (CVE-2026-46405). Risk of unauthorized operations or information disclosure. Exploitable via ``GET``. Mitigation: upgrade to `2.5.4` or later.
|
| CVE-2026-46380 |
|
SSRF (Server-Side Request Forgery) in compliance-trestle (CVE-2026-46380)
SSRF in compliance-trestle (CVE-2026-46380). Confidential information can be exposed externally. Mitigation: upgrade to `3.12.2` or later.
|
| CVE-2026-45323 |
|
Cross-Site Scripting (XSS) in jpettitt (CVE-2026-45323)
cross-site scripting in jpettitt (CVE-2026-45323). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.3.3` or later.
|
| CVE-2026-45307 |
|
Open Redirect in CVE-2026-45307 (CVE-2026-45307)
vulnerability in CVE-2026-45307 (CVE-2026-45307). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.20-alpha` or later.
|
| CVE-2026-45297 |
|
Vulnerability in CVE-2026-45297 (CVE-2026-45297)
vulnerability in CVE-2026-45297 (CVE-2026-45297). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.26.0` or later.
|
| CVE-2026-45296 |
|
Vulnerability in CVE-2026-45296 (CVE-2026-45296)
vulnerability in CVE-2026-45296 (CVE-2026-45296). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.0` or later.
|
| CVE-2026-46358 |
|
Vulnerability in github.com/openbao/openbao (CVE-2026-46358)
vulnerability in github.com/openbao/openbao (CVE-2026-46358). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.4` or later.
|
| CVE-2026-46345 |
|
Path Traversal in compliance-trestle (CVE-2026-46345)
path traversal in compliance-trestle (CVE-2026-46345). Successful exploitation can lead to full system takeover. Exploitable via ``trestle``. Mitigation: upgrade to `3.12.2` or later.
|
| CVE-2026-45808 |
|
Authorization Flaw in github.com/openbao/openbao (CVE-2026-45808)
vulnerability in github.com/openbao/openbao (CVE-2026-45808). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.4` or later.
|
| CVE-2026-45774 |
|
Path Traversal in compliance-trestle (CVE-2026-45774)
path traversal in compliance-trestle (CVE-2026-45774). Risk of unauthorized operations or information disclosure. Exploitable via ``trestle_root``. Mitigation: upgrade to `3.12.2` or later.
|
| CVE-2026-45756 |
|
Vulnerability in symfony/json-path (CVE-2026-45756)
vulnerability in symfony/json-path (CVE-2026-45756). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonPath``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45755 |
|
Vulnerability in symfony/mailtrap-mailer (CVE-2026-45755)
vulnerability in symfony/mailtrap-mailer (CVE-2026-45755). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45754 |
|
Authentication Bypass in symfony/lox24-notifier (CVE-2026-45754)
authentication bypass in symfony/lox24-notifier (CVE-2026-45754). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45287 |
|
Vulnerability in go.opentelemetry.io/otel/schema/v1.1 (CVE-2026-45287)
vulnerability in go.opentelemetry.io/otel/schema/v1.1 (CVE-2026-45287). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.17` or later.
|
| CVE-2026-9095 |
|
Vulnerability in CVE-2026-9095 (CVE-2026-9095)
vulnerability in CVE-2026-9095 (CVE-2026-9095). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6720 |
|
Vulnerability in github.com/projectcalico/calicoctl/v3 (CVE-2026-6720)
vulnerability in github.com/projectcalico/calicoctl/v3 (CVE-2026-6720). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.31.6` or later.
|
| CVE-2026-8697 |
|
Vulnerability in tp-link (CVE-2026-8697)
vulnerability in tp-link (CVE-2026-8697). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47673 |
|
Vulnerability in hono (CVE-2026-47673)
vulnerability in hono (CVE-2026-47673). Risk of unauthorized operations or information disclosure. Exploitable via ``jwt``. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-47676 |
|
Vulnerability in hono (CVE-2026-47676)
vulnerability in hono (CVE-2026-47676). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-47675 |
|
Vulnerability in hono (CVE-2026-47675)
vulnerability in hono (CVE-2026-47675). Risk of unauthorized operations or information disclosure. Exploitable via ``domain``. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-45261 |
|
Code Injection in CVE-2026-45261 (CVE-2026-45261)
code injection in CVE-2026-45261 (CVE-2026-45261). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.19.7` or later.
|
| CVE-2026-44465 |
|
OS Command Injection in zed (CVE-2026-44465)
OS command injection in zed (CVE-2026-44465). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.227.1` or later.
|
| CVE-2026-44466 |
|
OS Command Injection in zed (CVE-2026-44466)
OS command injection in zed (CVE-2026-44466). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.229.0` or later.
|
| CVE-2026-44463 |
|
OS Command Injection in zed (CVE-2026-44463)
OS command injection in zed (CVE-2026-44463). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.229.0` or later.
|
| CVE-2026-44462 |
|
Vulnerability in zed (CVE-2026-44462)
vulnerability in zed (CVE-2026-44462). Confidential information can be exposed externally. Mitigation: upgrade to `0.229.0` or later.
|
| CVE-2026-44461 |
|
OS Command Injection in zed (CVE-2026-44461)
OS command injection in zed (CVE-2026-44461). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.227.1` or later.
|
| CVE-2026-41184 |
|
Vulnerability in github.com/projectcalico/calico (CVE-2026-41184)
vulnerability in github.com/projectcalico/calico (CVE-2026-41184). Confidential information can be exposed externally. Mitigation: upgrade to `1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f` or later.
|
| CVE-2026-41185 |
|
Vulnerability in github.com/projectcalico/calico (CVE-2026-41185)
vulnerability in github.com/projectcalico/calico (CVE-2026-41185). Confidential information can be exposed externally. Mitigation: upgrade to `1.11.0-cni-plugin.0.20260417001138-cd73bc2cea0f` or later.
|
| CVE-2026-41160 |
|
Vulnerability in CVE-2026-41160 (CVE-2026-41160)
vulnerability in CVE-2026-41160 (CVE-2026-41160). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/Note/{id}/pin`. Mitigation: upgrade to `9.3.5` or later.
|
| CVE-2026-38702 |
|
Command Injection in inhandnetworks (CVE-2026-38702)
command injection in inhandnetworks (CVE-2026-38702). Successful exploitation can lead to full system takeover.
|