Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-45077 |
|
Unsafe Deserialization in symfony/monolog-bridge (CVE-2026-45077)
vulnerability in symfony/monolog-bridge (CVE-2026-45077). Risk of unauthorized operations or information disclosure. Exploitable via ``allowed_classes``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45075 |
|
Authorization Flaw in symfony/http-kernel (CVE-2026-45075)
vulnerability in symfony/http-kernel (CVE-2026-45075). Data can be tampered with by attackers. Exploitable via ``HEAD``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45074 |
|
Vulnerability in symfony/security-http (CVE-2026-45074)
vulnerability in symfony/security-http (CVE-2026-45074). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45073 |
|
SQL Injection in symfony/cache (CVE-2026-45073)
SQL injection in symfony/cache (CVE-2026-45073). Risk of unauthorized operations or information disclosure. Exploitable via ``AbstractAdapterTrait``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45072 |
|
Cross-Site Scripting (XSS) in symfony/symfony (CVE-2026-45072)
cross-site scripting in symfony/symfony (CVE-2026-45072). Risk of unauthorized operations or information disclosure. Exploitable via ``file_excerpt``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45071 |
|
XXE (XML External Entity) in symfony/dom-crawler (CVE-2026-45071)
vulnerability in symfony/dom-crawler (CVE-2026-45071). Confidential information can be exposed externally. Exploitable via ``Crawler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45070 |
|
Vulnerability in symfony/mime (CVE-2026-45070)
vulnerability in symfony/mime (CVE-2026-45070). Risk of unauthorized operations or information disclosure. Exploitable via ``tokens``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45069 |
|
Vulnerability in symfony/security-http (CVE-2026-45069)
vulnerability in symfony/security-http (CVE-2026-45069). Confidential information can be exposed externally. Exploitable via ``OidcTokenHandler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45068 |
|
Vulnerability in symfony/mailer (CVE-2026-45068)
vulnerability in symfony/mailer (CVE-2026-45068). Data can be tampered with by attackers. Exploitable via ``MAILER_DSN``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45067 |
|
Vulnerability in symfony/mime (CVE-2026-45067)
vulnerability in symfony/mime (CVE-2026-45067). Risk of unauthorized operations or information disclosure. Exploitable via ``SmtpTransport``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-48792 |
|
Vulnerability in c (CVE-2026-48792)
vulnerability in c (CVE-2026-48792). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.1` or later.
|
| CVE-2026-48064 |
|
Authorization Flaw in CVE-2026-48064 (CVE-2026-48064)
vulnerability in CVE-2026-48064 (CVE-2026-48064). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.9.1` or later.
|
| CVE-2026-47274 |
|
Vulnerability in c (CVE-2026-47274)
vulnerability in c (CVE-2026-47274). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-48065 |
|
Vulnerability in c (CVE-2026-48065)
vulnerability in c (CVE-2026-48065). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.9.1` or later.
|
| CVE-2026-48066 |
|
Vulnerability in c (CVE-2026-48066)
vulnerability in c (CVE-2026-48066). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.1` or later.
|
| CVE-2026-47271 |
|
Vulnerability in c (CVE-2026-47271)
vulnerability in c (CVE-2026-47271). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-47272 |
|
Authentication Bypass in c (CVE-2026-47272)
authentication bypass in c (CVE-2026-47272). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-47273 |
|
Vulnerability in CVE-2026-47273 (CVE-2026-47273)
vulnerability in CVE-2026-47273 (CVE-2026-47273). Data can be tampered with by attackers. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-47161 |
|
Unsafe Deserialization in CVE-2026-47161 (CVE-2026-47161)
vulnerability in CVE-2026-47161 (CVE-2026-47161). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45102 |
|
Vulnerability in CVE-2026-45102 (CVE-2026-45102)
vulnerability in CVE-2026-45102 (CVE-2026-45102). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.0.98` or later.
|
| CVE-2026-45108 |
|
Authorization Flaw in CVE-2026-45108 (CVE-2026-45108)
vulnerability in CVE-2026-45108 (CVE-2026-45108). Confidential information can be exposed externally. Mitigation: upgrade to `3.1.5` or later.
|
| CVE-2026-45104 |
|
Vulnerability in osgeo (CVE-2026-45104)
vulnerability in osgeo (CVE-2026-45104). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.6.3` or later.
|
| CVE-2026-44888 |
|
Code Injection in CVE-2026-44888 (CVE-2026-44888)
code injection in CVE-2026-44888 (CVE-2026-44888). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026-05-07` or later.
|
| CVE-2026-44590 |
|
OS Command Injection in CVE-2026-44590 (CVE-2026-44590)
OS command injection in CVE-2026-44590 (CVE-2026-44590). Data can be tampered with by attackers. Mitigation: upgrade to `0.16.1` or later.
|
| CVE-2026-44887 |
|
Code Injection in CVE-2026-44887 (CVE-2026-44887)
code injection in CVE-2026-44887 (CVE-2026-44887). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026-05-07` or later.
|
| CVE-2026-44886 |
|
SQL Injection in sqli (CVE-2026-44886)
SQL injection in sqli (CVE-2026-44886). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026-05-07` or later.
|
| CVE-2026-42197 |
|
Cross-Site Scripting (XSS) in django (CVE-2026-42197)
cross-site scripting in django (CVE-2026-42197). Confidential information can be exposed externally. Exploitable via ``ParticipationAdmin``.
|
| CVE-2026-42877 |
|
Cross-Site Scripting (XSS) in facturascripts/facturascripts (CVE-2026-42877)
cross-site scripting in facturascripts/facturascripts (CVE-2026-42877). Risk of unauthorized operations or information disclosure. Exploitable via ``referencia``.
|
| CVE-2026-45066 |
|
Vulnerability in symfony/html-sanitizer (CVE-2026-45066)
vulnerability in symfony/html-sanitizer (CVE-2026-45066). Risk of unauthorized operations or information disclosure. Exploitable via ``trusted.com``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45064 |
|
Vulnerability in symfony/html-sanitizer (CVE-2026-45064)
vulnerability in symfony/html-sanitizer (CVE-2026-45064). Risk of unauthorized operations or information disclosure. Exploitable via ``HtmlSanitizer``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-44982 |
|
Vulnerability in github.com/crowdsecurity/crowdsec (CVE-2026-44982)
vulnerability in github.com/crowdsecurity/crowdsec (CVE-2026-44982). Risk of unauthorized operations or information disclosure. Exploitable via ``REQUEST_BODY``. Mitigation: upgrade to `1.7.8` or later.
|
| CVE-2026-25879 |
|
SQL Injection in langroid (CVE-2026-25879)
SQL injection in langroid (CVE-2026-25879). Successful exploitation can lead to full system takeover. Exploitable via ``query``. Mitigation: upgrade to `0.63.0` or later.
|
| CVE-2026-8716 |
|
Vulnerability in gitlab (CVE-2026-8716)
vulnerability in gitlab (CVE-2026-8716). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.7, 18.11.4, 19.0.2` or later.
|
| CVE-2026-5296 |
|
Vulnerability in gitlab (CVE-2026-5296)
vulnerability in gitlab (CVE-2026-5296). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.7, 18.11.4, 19.0.2` or later.
|
| CVE-2026-6713 |
|
Authorization Flaw in gitlab (CVE-2026-6713)
vulnerability in gitlab (CVE-2026-6713). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.7, 18.11.4, 19.0.2` or later.
|
| CVE-2026-42878 |
|
Information Disclosure in facturascripts/facturascripts (CVE-2026-42878)
vulnerability in facturascripts/facturascripts (CVE-2026-42878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2601 |
|
Vulnerability in gitlab (CVE-2026-2601)
vulnerability in gitlab (CVE-2026-2601). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.7, 18.11.4, 19.0.2` or later.
|
| CVE-2026-1402 |
|
Vulnerability in gitlab (CVE-2026-1402)
vulnerability in gitlab (CVE-2026-1402). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.10.7, 18.11.4, 19.0.2` or later.
|
| CVE-2026-4391 |
|
Buffer Overflow in CVE-2026-4391 (CVE-2026-4391)
vulnerability in CVE-2026-4391 (CVE-2026-4391). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4390 |
|
Buffer Overflow in CVE-2026-4390 (CVE-2026-4390)
vulnerability in CVE-2026-4390 (CVE-2026-4390). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5509 |
|
Vulnerability in tp-link (CVE-2026-5509)
vulnerability in tp-link (CVE-2026-5509). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38808 |
|
SQL Injection in sqli (CVE-2026-38808)
SQL injection in sqli (CVE-2026-38808). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69600 |
|
Command Injection in CVE-2025-69600 (CVE-2025-69600)
command injection in CVE-2025-69600 (CVE-2025-69600). Successful exploitation can lead to full system takeover.
|
| CVE-2025-67903 |
|
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
|
| CVE-2026-45618 |
|
Code Injection in liquidjs (CVE-2026-45618)
code injection in liquidjs (CVE-2026-45618). Successful exploitation can lead to full system takeover. Exploitable via ``this``. Mitigation: upgrade to `10.26.0` or later.
|
| CVE-2026-48151 |
|
Vulnerability in @budibase/server (CVE-2026-48151)
vulnerability in @budibase/server (CVE-2026-48151). Data can be tampered with by attackers. Exploitable via `POST /api/webhooks/schema/`. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-48152 |
|
Authorization Flaw in @budibase/server (CVE-2026-48152)
vulnerability in @budibase/server (CVE-2026-48152). Confidential information can be exposed externally. Exploitable via `GET /api/datasources/`. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-48148 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-48148)
SSRF in @budibase/server (CVE-2026-48148). Risk of unauthorized operations or information disclosure. Exploitable via ``metadata.google.internal``. Mitigation: upgrade to `3.35.3` or later.
|
| CVE-2026-48153 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-48153)
SSRF in @budibase/server (CVE-2026-48153). Confidential information can be exposed externally. Exploitable via ``fetchToken``. Mitigation: upgrade to `3.39.0` or later.
|
| CVE-2026-48149 |
|
Cross-Site Scripting (XSS) in CVE-2026-48149 (CVE-2026-48149)
cross-site scripting in CVE-2026-48149 (CVE-2026-48149). Confidential information can be exposed externally. Mitigation: upgrade to `3.39.0` or later.
|