Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-67440 |
|
Vulnerability in CVE-2026-67440 (CVE-2026-67440)
vulnerability in CVE-2026-67440 (CVE-2026-67440). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67443 |
|
Vulnerability in CVE-2026-67443 (CVE-2026-67443)
vulnerability in CVE-2026-67443 (CVE-2026-67443). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/heartbeat`.
|
| CVE-2026-65985 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65985)
SSRF in ssrf (CVE-2026-65985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57826 |
|
Vulnerability in CVE-2026-57826 (CVE-2026-57826)
vulnerability in CVE-2026-57826 (CVE-2026-57826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52480 |
|
Vulnerability in CVE-2026-52480 (CVE-2026-52480)
vulnerability in CVE-2026-52480 (CVE-2026-52480). Confidential information can be exposed externally.
|
| CVE-2026-52481 |
|
Information Disclosure in CVE-2026-52481 (CVE-2026-52481)
vulnerability in CVE-2026-52481 (CVE-2026-52481). Confidential information can be exposed externally.
|
| CVE-2026-19670 |
|
Authorization Flaw in nginx (CVE-2026-19670)
vulnerability in nginx (CVE-2026-19670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12520 |
|
Out-of-Bounds Write in c (CVE-2026-12520)
out-of-bounds write in c (CVE-2026-12520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70667 |
|
Vulnerability in lemur (CVE-2026-70667)
vulnerability in lemur (CVE-2026-70667). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/1/certificates/upload`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-65959 |
|
Vulnerability in CVE-2026-65959 (CVE-2026-65959)
vulnerability in CVE-2026-65959 (CVE-2026-65959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47629 |
|
Vulnerability in dos (CVE-2026-47629)
vulnerability in dos (CVE-2026-47629). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47630 |
|
Vulnerability in path-traversal (CVE-2026-47630)
vulnerability in path-traversal (CVE-2026-47630). Confidential information can be exposed externally.
|
| CVE-2026-47627 |
|
Path Traversal in path-traversal (CVE-2026-47627)
path traversal in path-traversal (CVE-2026-47627). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47628 |
|
Vulnerability in dos (CVE-2026-47628)
vulnerability in dos (CVE-2026-47628). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47606 |
|
Vulnerability in path-traversal (CVE-2026-47606)
vulnerability in path-traversal (CVE-2026-47606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24185 |
|
Vulnerability in CVE-2026-24185 (CVE-2026-24185)
vulnerability in CVE-2026-24185 (CVE-2026-24185). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24183 |
|
Vulnerability in CVE-2026-24183 (CVE-2026-24183)
vulnerability in CVE-2026-24183 (CVE-2026-24183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17106 |
|
Vulnerability in github.com/moby/go-archive (CVE-2026-17106)
vulnerability in github.com/moby/go-archive (CVE-2026-17106). Risk of unauthorized operations or information disclosure. Exploitable via ``Unpack``. Mitigation: upgrade to `0.3.0` or later.
|
| CVE-2026-24184 |
|
Vulnerability in CVE-2026-24184 (CVE-2026-24184)
vulnerability in CVE-2026-24184 (CVE-2026-24184). Successful exploitation can lead to full system takeover.
|
| CVE-2025-9211 |
|
Cross-Site Scripting (XSS) in CVE-2025-9211 (CVE-2025-9211)
cross-site scripting in CVE-2025-9211 (CVE-2025-9211). Confidential information can be exposed externally.
|
| CVE-2025-9210 |
|
Vulnerability in CVE-2025-9210 (CVE-2025-9210)
vulnerability in CVE-2025-9210 (CVE-2025-9210). Confidential information can be exposed externally.
|
| CVE-2021-43718 |
|
Vulnerability in dos (CVE-2021-43718)
vulnerability in dos (CVE-2021-43718). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71879 |
|
Vulnerability in CVE-2026-71879 (CVE-2026-71879)
vulnerability in CVE-2026-71879 (CVE-2026-71879). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71880 |
|
Vulnerability in CVE-2026-71880 (CVE-2026-71880)
vulnerability in CVE-2026-71880 (CVE-2026-71880). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71878 |
|
Vulnerability in CVE-2026-71878 (CVE-2026-71878)
vulnerability in CVE-2026-71878 (CVE-2026-71878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67920 |
|
Vulnerability in CVE-2026-67920 (CVE-2026-67920)
vulnerability in CVE-2026-67920 (CVE-2026-67920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67921 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-67921)
vulnerability in csrf (CVE-2026-67921). Confidential information can be exposed externally.
|
| CVE-2026-66780 |
|
Vulnerability in CVE-2026-66780 (CVE-2026-66780)
vulnerability in CVE-2026-66780 (CVE-2026-66780). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52608 |
|
Vulnerability in CVE-2026-52608 (CVE-2026-52608)
vulnerability in CVE-2026-52608 (CVE-2026-52608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52607 |
|
Path Traversal in path-traversal (CVE-2026-52607)
path traversal in path-traversal (CVE-2026-52607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52610 |
|
Path Traversal in path-traversal (CVE-2026-52610)
path traversal in path-traversal (CVE-2026-52610). Confidential information can be exposed externally.
|
| CVE-2026-67262 |
|
Vulnerability in CVE-2026-67262 (CVE-2026-67262)
vulnerability in CVE-2026-67262 (CVE-2026-67262). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52609 |
|
Cross-Site Scripting (XSS) in CVE-2026-52609 (CVE-2026-52609)
cross-site scripting in CVE-2026-52609 (CVE-2026-52609). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-43716 |
|
Vulnerability in CVE-2021-43716 (CVE-2021-43716)
vulnerability in CVE-2021-43716 (CVE-2021-43716). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43717 |
|
Vulnerability in CVE-2021-43717 (CVE-2021-43717)
vulnerability in CVE-2021-43717 (CVE-2021-43717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74038 |
|
Path Traversal in path-traversal (CVE-2026-74038)
path traversal in path-traversal (CVE-2026-74038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74044 |
|
Path Traversal in path-traversal (CVE-2026-74044)
path traversal in path-traversal (CVE-2026-74044). Data can be tampered with by attackers.
|
| CVE-2026-74039 |
|
Vulnerability in dos (CVE-2026-74039)
vulnerability in dos (CVE-2026-74039). Risk of unauthorized operations or information disclosure. Exploitable via `POST /security/user/authenticate/run_as`.
|
| CVE-2026-71551 |
|
OS Command Injection in CVE-2026-71551 (CVE-2026-71551)
OS command injection in CVE-2026-71551 (CVE-2026-71551). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61696 |
|
Vulnerability in csrf (CVE-2026-61696)
vulnerability in csrf (CVE-2026-61696). Confidential information can be exposed externally.
|
| CVE-2026-50161 |
|
Vulnerability in c (CVE-2026-50161)
vulnerability in c (CVE-2026-50161). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44472 |
|
Authentication Bypass in CVE-2026-44472 (CVE-2026-44472)
authentication bypass in CVE-2026-44472 (CVE-2026-44472). Confidential information can be exposed externally.
|
| CVE-2026-68922 |
|
Path Traversal in mobsf (CVE-2026-68922)
path traversal in mobsf (CVE-2026-68922). Confidential information can be exposed externally. Exploitable via `GET /download/`. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-68923 |
|
Cross-Site Request Forgery (CSRF) in mobsf (CVE-2026-68923)
vulnerability in mobsf (CVE-2026-68923). Data can be tampered with by attackers. Exploitable via ``CsrfViewMiddleware``. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-68927 |
|
SSRF (Server-Side Request Forgery) in mobsf (CVE-2026-68927)
SSRF in mobsf (CVE-2026-68927). Risk of unauthorized operations or information disclosure. Exploitable via ``rebind.example``. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-68924 |
|
Vulnerability in mobsf (CVE-2026-68924)
vulnerability in mobsf (CVE-2026-68924). Risk of unauthorized operations or information disclosure. Exploitable via ``ZIP_MAX_UNCOMPRESSED_FILE_SIZE``. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-63640 |
|
Information Disclosure in magicmirror (CVE-2026-63640)
vulnerability in magicmirror (CVE-2026-63640). Risk of unauthorized operations or information disclosure. Exploitable via ``magicmirror``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-55182 |
|
Command Injection in librenms/librenms (CVE-2026-55182)
command injection in librenms/librenms (CVE-2026-55182). Risk of unauthorized operations or information disclosure. Exploitable via ``exec``. Mitigation: upgrade to `26.5.0` or later.
|
| CVE-2026-63643 |
|
Vulnerability in magicmirror (CVE-2026-63643)
vulnerability in magicmirror (CVE-2026-63643). Risk of unauthorized operations or information disclosure. Exploitable via ``ADD_CALENDAR``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-63642 |
|
SSRF (Server-Side Request Forgery) in magicmirror (CVE-2026-63642)
SSRF in magicmirror (CVE-2026-63642). Risk of unauthorized operations or information disclosure. Exploitable via ``CHECK_ARTICLE_URL``. Mitigation: upgrade to `2.37.0` or later.
|