Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15909 |
|
Vulnerability in CVE-2026-15909 (CVE-2026-15909)
vulnerability in CVE-2026-15909 (CVE-2026-15909). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45313 |
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and...
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the...
|
| CVE-2026-40952 |
|
Vulnerability in absolute (CVE-2026-40952)
vulnerability in absolute (CVE-2026-40952). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26032 |
|
Path Traversal in apache (CVE-2026-26032)
path traversal in apache (CVE-2026-26032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54494 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54494)
SSRF in phanan/koel (CVE-2026-54494). Risk of unauthorized operations or information disclosure. Exploitable via `GET /secret`. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-54493 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54493)
SSRF in phanan/koel (CVE-2026-54493). Confidential information can be exposed externally. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-54492 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54492)
SSRF in phanan/koel (CVE-2026-54492). Risk of unauthorized operations or information disclosure. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-20146 |
|
Path Traversal in Cisco path-traversal (CVE-2026-20146)
path traversal in Cisco path-traversal (CVE-2026-20146). Confidential information can be exposed externally.
|
| CVE-2026-50147 |
|
Vulnerability in metabase (CVE-2026-50147)
vulnerability in metabase (CVE-2026-50147). Confidential information can be exposed externally.
|
| CVE-2026-50148 |
|
Vulnerability in metabase (CVE-2026-50148)
vulnerability in metabase (CVE-2026-50148). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61873 |
|
Vulnerability in path-traversal (CVE-2026-61873)
vulnerability in path-traversal (CVE-2026-61873). Data can be tampered with by attackers.
|
| CVE-2026-61866 |
|
Vulnerability in imagemagick (CVE-2026-61866)
vulnerability in imagemagick (CVE-2026-61866). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61863 |
|
Vulnerability in imagemagick (CVE-2026-61863)
vulnerability in imagemagick (CVE-2026-61863). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61859 |
|
Vulnerability in imagemagick (CVE-2026-61859)
vulnerability in imagemagick (CVE-2026-61859). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61457 |
|
Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
vulnerability in CVE-2026-61457 (CVE-2026-61457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59259 |
|
Vulnerability in n8n (CVE-2026-59259)
vulnerability in n8n (CVE-2026-59259). Confidential information can be exposed externally. Mitigation: upgrade to `2.27.4` or later.
|
| CVE-2026-56353 |
|
Authentication Bypass in n8n (CVE-2026-56353)
authentication bypass in n8n (CVE-2026-56353). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.123.22` or later.
|
| CVE-2026-59235 |
|
Vulnerability in CVE-2026-59235 (CVE-2026-59235)
vulnerability in CVE-2026-59235 (CVE-2026-59235). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/bank-account`.
|
| CVE-2026-35152 |
|
SQL Injection in apache (CVE-2026-35152)
SQL injection in apache (CVE-2026-35152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56287 |
|
SQL Injection in apache (CVE-2026-56287)
SQL injection in apache (CVE-2026-56287). Confidential information can be exposed externally. Exploitable via `GET /api/v1/clients`.
|
| CVE-2026-57821 |
|
SQL Injection in apache (CVE-2026-57821)
SQL injection in apache (CVE-2026-57821). Confidential information can be exposed externally. Exploitable via `GET /api/v1/offices`.
|
| CVE-2026-48337 |
|
Out-of-Bounds Write in adobe (CVE-2026-48337)
out-of-bounds write in adobe (CVE-2026-48337). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48351 |
|
Vulnerability in adobe (CVE-2026-48351)
vulnerability in adobe (CVE-2026-48351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48352 |
|
Vulnerability in adobe (CVE-2026-48352)
vulnerability in adobe (CVE-2026-48352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48353 |
|
Vulnerability in adobe (CVE-2026-48353)
vulnerability in adobe (CVE-2026-48353). Confidential information can be exposed externally.
|
| CVE-2026-48354 |
|
Vulnerability in adobe (CVE-2026-48354)
vulnerability in adobe (CVE-2026-48354). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48357 |
|
Vulnerability in adobe (CVE-2026-48357)
vulnerability in adobe (CVE-2026-48357). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48296 |
|
Vulnerability in adobe (CVE-2026-48296)
vulnerability in adobe (CVE-2026-48296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48336 |
|
Out-of-Bounds Write in adobe (CVE-2026-48336)
out-of-bounds write in adobe (CVE-2026-48336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48335 |
|
Out-of-Bounds Write in adobe (CVE-2026-48335)
out-of-bounds write in adobe (CVE-2026-48335). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48334 |
|
Vulnerability in adobe (CVE-2026-48334)
vulnerability in adobe (CVE-2026-48334). Confidential information can be exposed externally.
|
| CVE-2026-48312 |
|
Vulnerability in adobe (CVE-2026-48312)
vulnerability in adobe (CVE-2026-48312). Data can be tampered with by attackers.
|
| CVE-2026-48302 |
|
Vulnerability in adobe (CVE-2026-48302)
vulnerability in adobe (CVE-2026-48302). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48298 |
|
Vulnerability in adobe (CVE-2026-48298)
vulnerability in adobe (CVE-2026-48298). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48295 |
|
Vulnerability in adobe (CVE-2026-48295)
vulnerability in adobe (CVE-2026-48295). Confidential information can be exposed externally.
|
| CVE-2026-48290 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48290)
SSRF in ssrf (CVE-2026-48290). Confidential information can be exposed externally.
|
| CVE-2026-48287 |
|
Vulnerability in adobe (CVE-2026-48287)
vulnerability in adobe (CVE-2026-48287). Confidential information can be exposed externally.
|
| CVE-2026-48275 |
|
Vulnerability in adobe (CVE-2026-48275)
vulnerability in adobe (CVE-2026-48275). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46627 |
|
Vulnerability in symfony (CVE-2026-46627)
vulnerability in symfony (CVE-2026-46627). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48338 |
|
Path Traversal in path-traversal (CVE-2026-48338)
path traversal in path-traversal (CVE-2026-48338). Confidential information can be exposed externally.
|
| CVE-2026-48329 |
|
Vulnerability in adobe (CVE-2026-48329)
vulnerability in adobe (CVE-2026-48329). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15768 |
|
Vulnerability in google (CVE-2026-15768)
vulnerability in google (CVE-2026-15768). Data can be tampered with by attackers.
|
| CVE-2026-15769 |
|
Vulnerability in google (CVE-2026-15769)
vulnerability in google (CVE-2026-15769). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15778 |
|
Vulnerability in google (CVE-2026-15778)
vulnerability in google (CVE-2026-15778). Data can be tampered with by attackers.
|
| CVE-2026-15776 |
|
Vulnerability in google (CVE-2026-15776)
vulnerability in google (CVE-2026-15776). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15772 |
|
Use-After-Free in google (CVE-2026-15772)
vulnerability in google (CVE-2026-15772). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15775 |
|
Vulnerability in google (CVE-2026-15775)
vulnerability in google (CVE-2026-15775). Data can be tampered with by attackers.
|
| CVE-2026-15770 |
|
Vulnerability in google (CVE-2026-15770)
vulnerability in google (CVE-2026-15770). Confidential information can be exposed externally.
|
| CVE-2026-15767 |
|
Vulnerability in google (CVE-2026-15767)
vulnerability in google (CVE-2026-15767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15766 |
|
Vulnerability in google (CVE-2026-15766)
vulnerability in google (CVE-2026-15766). Confidential information can be exposed externally.
|