Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Clear
ID Title
CVE-2026-16209 Authentication Bypass in CVE-2026-16209 (CVE-2026-16209)
authentication bypass in CVE-2026-16209 (CVE-2026-16209). Risk of unauthorized operations or information disclosure.
CVE-2026-16200 Vulnerability in c (CVE-2026-16200)
vulnerability in c (CVE-2026-16200). Risk of unauthorized operations or information disclosure.
CVE-2026-10130 Authorization Flaw in CVE-2026-10130 (CVE-2026-10130)
vulnerability in CVE-2026-10130 (CVE-2026-10130). Confidential information can be exposed externally.
CVE-2026-16154 Vulnerability in sqli (CVE-2026-16154)
vulnerability in sqli (CVE-2026-16154). Risk of unauthorized operations or information disclosure.
CVE-2026-16152 Vulnerability in sqli (CVE-2026-16152)
vulnerability in sqli (CVE-2026-16152). Risk of unauthorized operations or information disclosure.
CVE-2026-53994 Vulnerability in dos (CVE-2026-53994)
vulnerability in dos (CVE-2026-53994). Successful exploitation can lead to full system takeover.
CVE-2026-16128 SSRF (Server-Side Request Forgery) in c (CVE-2026-16128)
SSRF in c (CVE-2026-16128). Risk of unauthorized operations or information disclosure.
CVE-2026-16126 Vulnerability in c (CVE-2026-16126)
vulnerability in c (CVE-2026-16126). Risk of unauthorized operations or information disclosure.
CVE-2026-16127 SSRF (Server-Side Request Forgery) in c (CVE-2026-16127)
SSRF in c (CVE-2026-16127). Risk of unauthorized operations or information disclosure.
CVE-2026-16125 SSRF (Server-Side Request Forgery) in c (CVE-2026-16125)
SSRF in c (CVE-2026-16125). Risk of unauthorized operations or information disclosure.
CVE-2026-11826 OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
CVE-2025-71398 SSRF (Server-Side Request Forgery) in surrealdb (CVE-2025-71398)
SSRF in surrealdb (CVE-2025-71398). Confidential information can be exposed externally.
CVE-2025-71390 Authorization Flaw in surrealdb (CVE-2025-71390)
vulnerability in surrealdb (CVE-2025-71390). Successful exploitation can lead to full system takeover.
CVE-2025-71392 Command Injection in privilege-escalation (CVE-2025-71392)
command injection in privilege-escalation (CVE-2025-71392). Successful exploitation can lead to full system takeover.
CVE-2024-58366 SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
CVE-2023-54366 SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
CVE-2026-59173 Vulnerability in apache (CVE-2026-59173)
vulnerability in apache (CVE-2026-59173). Risk of unauthorized operations or information disclosure.
CVE-2026-9147 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
CVE-2026-16158 Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
CVE-2026-15631 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
CVE-2026-16097 Buffer Overflow in CVE-2026-16097 (CVE-2026-16097)
vulnerability in CVE-2026-16097 (CVE-2026-16097). Successful exploitation can lead to full system takeover.
CVE-2026-16096 Buffer Overflow in CVE-2026-16096 (CVE-2026-16096)
vulnerability in CVE-2026-16096 (CVE-2026-16096). Successful exploitation can lead to full system takeover.
CVE-2026-16095 Buffer Overflow in CVE-2026-16095 (CVE-2026-16095)
vulnerability in CVE-2026-16095 (CVE-2026-16095). Successful exploitation can lead to full system takeover.
CVE-2026-47869 Code Injection in broadcom (CVE-2026-47869)
code injection in broadcom (CVE-2026-47869). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47868 Privilege Escalation in privilege-escalation (CVE-2026-47868)
vulnerability in privilege-escalation (CVE-2026-47868). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47870 Privilege Escalation in privilege-escalation (CVE-2026-47870)
vulnerability in privilege-escalation (CVE-2026-47870). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47871 Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47866 Authorization Flaw in broadcom (CVE-2026-47866)
vulnerability in broadcom (CVE-2026-47866). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-16084 SSRF (Server-Side Request Forgery) in CVE-2026-16084 (CVE-2026-16084)
SSRF in CVE-2026-16084 (CVE-2026-16084). Risk of unauthorized operations or information disclosure.
CVE-2026-47867 Code Injection in broadcom (CVE-2026-47867)
code injection in broadcom (CVE-2026-47867). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-56741 Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741). Risk of unauthorized operations or information disclosure. Exploitable via ``Telnet``. Mitigation: upgrade to `4.2.1` or later.
CVE-2026-56740 Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740). Risk of unauthorized operations or information disclosure. Exploitable via ``HashMap``. Mitigation: upgrade to `4.2.1` or later.
CVE-2026-52584 Vulnerability in CVE-2026-52584 (CVE-2026-52584)
vulnerability in CVE-2026-52584 (CVE-2026-52584). Confidential information can be exposed externally.
CVE-2026-52203 Information Disclosure in CVE-2026-52203 (CVE-2026-52203)
vulnerability in CVE-2026-52203 (CVE-2026-52203). Confidential information can be exposed externally.
CVE-2026-7872 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
CVE-2026-8056 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
CVE-2026-7755 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
CVE-2026-7754 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
CVE-2026-51833 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51833)
SSRF in ssrf (CVE-2026-51833). Confidential information can be exposed externally.
CVE-2026-48373 Vulnerability in adobe (CVE-2026-48373)
vulnerability in adobe (CVE-2026-48373). Successful exploitation can lead to full system takeover.
CVE-2026-16118 Vulnerability in c (CVE-2026-16118)
vulnerability in c (CVE-2026-16118). Data can be tampered with by attackers.
CVE-2026-13473 Vulnerability in ibm (CVE-2026-13473)
vulnerability in ibm (CVE-2026-13473). Successful exploitation can lead to full system takeover.
CVE-2026-13448 Vulnerability in langflow (CVE-2026-13448)
vulnerability in langflow (CVE-2026-13448). Successful exploitation can lead to full system takeover.
CVE-2026-14499 OS Command Injection in langflow (CVE-2026-14499)
OS command injection in langflow (CVE-2026-14499). Successful exploitation can lead to full system takeover.
CVE-2025-51678 Buffer Overflow in CVE-2025-51678 (CVE-2025-51678)
vulnerability in CVE-2025-51678 (CVE-2025-51678). Risk of unauthorized operations or information disclosure.
CVE-2026-9171 Vulnerability in dos (CVE-2026-9171)
vulnerability in dos (CVE-2026-9171). Risk of unauthorized operations or information disclosure.
CVE-2026-58195 OS Command Injection in CVE-2026-58195 (CVE-2026-58195)
OS command injection in CVE-2026-58195 (CVE-2026-58195). Successful exploitation can lead to full system takeover.
CVE-2026-54552 Vulnerability in sh (CVE-2026-54552)
vulnerability in sh (CVE-2026-54552). Confidential information can be exposed externally. Exploitable via ``_uid``. Mitigation: upgrade to `2.2.4` or later.
CVE-2026-9762 Code Injection in ibm (CVE-2026-9762)
code injection in ibm (CVE-2026-9762). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →