Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59278 |
|
SSRF (Server-Side Request Forgery) in csharp (CVE-2026-59278)
SSRF in csharp (CVE-2026-59278). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47851 |
|
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
|
| CVE-2026-76576 |
|
Path Traversal in vue (CVE-2026-76576)
path traversal in vue (CVE-2026-76576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73635 |
|
Vulnerability in apache (CVE-2026-73635)
vulnerability in apache (CVE-2026-73635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73243 |
|
SSRF (Server-Side Request Forgery) in spring (CVE-2026-73243)
SSRF in spring (CVE-2026-73243). Risk of unauthorized operations or information disclosure. Exploitable via `GET /addTask`.
|
| CVE-2026-73244 |
|
Path Traversal in spring (CVE-2026-73244)
path traversal in spring (CVE-2026-73244). Risk of unauthorized operations or information disclosure. Exploitable via `POST /listFiles`.
|
| CVE-2026-66909 |
|
Unsafe Deserialization in apache (CVE-2026-66909)
vulnerability in apache (CVE-2026-66909). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66713 |
|
Unsafe Deserialization in apache (CVE-2026-66713)
vulnerability in apache (CVE-2026-66713). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48586 |
|
Vulnerability in c (CVE-2026-48586)
vulnerability in c (CVE-2026-48586). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43871 |
|
Vulnerability in apache (CVE-2026-43871)
vulnerability in apache (CVE-2026-43871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45112 |
|
Vulnerability in apache (CVE-2026-45112)
vulnerability in apache (CVE-2026-45112). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64606 |
|
Unsafe Deserialization in apache (CVE-2026-64606)
vulnerability in apache (CVE-2026-64606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58624 |
|
Vulnerability in apache (CVE-2026-58624)
vulnerability in apache (CVE-2026-58624). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56624 |
|
Vulnerability in apache (CVE-2026-56624)
vulnerability in apache (CVE-2026-56624). Confidential information can be exposed externally.
|
| CVE-2026-56452 |
|
Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
|
| CVE-2026-56623 |
|
Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
|
| CVE-2026-62183 |
|
Privilege Escalation in apache (CVE-2026-62183)
vulnerability in apache (CVE-2026-62183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40008 |
|
Vulnerability in c (CVE-2026-40008)
vulnerability in c (CVE-2026-40008). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41042 |
|
Vulnerability in apache (CVE-2026-41042)
vulnerability in apache (CVE-2026-41042). Confidential information can be exposed externally.
|
| CVE-2026-43825 |
|
Unsafe Deserialization in apache (CVE-2026-43825)
vulnerability in apache (CVE-2026-43825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56139 |
|
Vulnerability in org.apache.camel:camel-undertow (CVE-2026-56139)
vulnerability in org.apache.camel:camel-undertow (CVE-2026-56139). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-49365 |
|
Vulnerability in org.apache.camel:camel-netty-http (CVE-2026-49365)
vulnerability in org.apache.camel:camel-netty-http (CVE-2026-49365). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46590 |
|
Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-46590)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-46590). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-42527 |
|
Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-42527)
vulnerability in org.apache.camel:camel-jms (CVE-2026-42527). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-24012 |
|
Vulnerability in apache (CVE-2026-24012)
vulnerability in apache (CVE-2026-24012). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43865 |
|
Unsafe Deserialization in org.apache.camel:camel-hazelcast (CVE-2026-43865)
vulnerability in org.apache.camel:camel-hazelcast (CVE-2026-43865). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-40859 |
|
Unsafe Deserialization in org.apache.camel:camel-vertx-http (CVE-2026-40859)
vulnerability in org.apache.camel:camel-vertx-http (CVE-2026-40859). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-40047 |
|
Vulnerability in org.apache.camel:camel-docling (CVE-2026-40047)
vulnerability in org.apache.camel:camel-docling (CVE-2026-40047). Confidential information can be exposed externally. Exploitable via ``docling``. Mitigation: upgrade to `4.18.3` or later.
|
| CVE-2026-43867 |
|
Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-43867)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-43867). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-43866 |
|
Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-43866)
vulnerability in org.apache.camel:camel-jms (CVE-2026-43866). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46453 |
|
Vulnerability in org.apache.camel:camel-elasticsearch-rest-client (CVE-2026-46453)
vulnerability in org.apache.camel:camel-elasticsearch-rest-client (CVE-2026-46453). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-13528 |
|
Path Traversal in vue (CVE-2026-13528)
path traversal in vue (CVE-2026-13528). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50076 |
|
Unsafe Deserialization in org.apache.fory:fory-core (CVE-2026-50076)
vulnerability in org.apache.fory:fory-core (CVE-2026-50076). Confidential information can be exposed externally. Mitigation: upgrade to `1.1.0` or later.
|
| CVE-2026-47065 |
|
Unsafe Deserialization in org.apache.mina:mina-core (CVE-2026-47065)
vulnerability in org.apache.mina:mina-core (CVE-2026-47065). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.29` or later.
|
| CVE-2026-41258 |
|
Code Injection in org.openmrs.api:openmrs-api (CVE-2026-41258)
code injection in org.openmrs.api:openmrs-api (CVE-2026-41258). Successful exploitation can lead to full system takeover. Exploitable via ``VelocityEngine``. Mitigation: upgrade to `2.8.6` or later.
|
| CVE-2026-35194 |
|
Code Injection in flink (CVE-2026-35194)
code injection in flink (CVE-2026-35194). Confidential information can be exposed externally. Mitigation: upgrade to `1.20.4, 2.0.2, 2.1.1, 2.2.1` or later.
|
| CVE-2026-44501 |
|
Unsafe Deserialization in react (CVE-2026-44501)
vulnerability in react (CVE-2026-44501). Risk of unauthorized operations or information disclosure. Exploitable via `GET /callback/oidc`. Mitigation: upgrade to `1.5.0.3` or later.
|
| CVE-2026-45091 |
|
Information Disclosure in sealed-env (CVE-2026-45091)
vulnerability in sealed-env (CVE-2026-45091). Confidential information can be exposed externally. Mitigation: upgrade to `0.1.0-alpha.4` or later.
|
| CVE-2026-27172 |
|
Unsafe Deserialization in apache (CVE-2026-27172)
vulnerability in apache (CVE-2026-27172). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40858 |
|
Unsafe Deserialization in apache (CVE-2026-40858)
vulnerability in apache (CVE-2026-40858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40048 |
|
Unsafe Deserialization in apache (CVE-2026-40048)
vulnerability in apache (CVE-2026-40048). Successful exploitation can lead to full system takeover. Exploitable via ``java.security.KeyPair``.
|
| CVE-2026-40473 |
|
Unsafe Deserialization in apache (CVE-2026-40473)
vulnerability in apache (CVE-2026-40473). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35554 |
|
Vulnerability in apache (CVE-2026-35554)
vulnerability in apache (CVE-2026-35554). Confidential information can be exposed externally.
|
| CVE-2026-25747 |
|
Unsafe Deserialization in apache (CVE-2026-25747)
vulnerability in apache (CVE-2026-25747). Successful exploitation can lead to full system takeover.
|
| CVE-2025-11226 |
|
Vulnerability in spring (CVE-2025-11226)
vulnerability in spring (CVE-2025-11226). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-48795 |
|
Vulnerability in russh (CVE-2023-48795)
vulnerability in russh (CVE-2023-48795). Data can be tampered with by attackers. Mitigation: upgrade to `0.40.2` or later.
|
| CVE-2022-47966 KEV |
|
[KEV] Vulnerability in Zoho manageengine (CVE-2022-47966)
vulnerability in Zoho manageengine (CVE-2022-47966). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-34169 |
|
Vulnerability in apache (CVE-2022-34169)
vulnerability in apache (CVE-2022-34169). Data can be tampered with by attackers.
|
| CVE-2022-23437 |
|
Vulnerability in apache (CVE-2022-23437)
vulnerability in apache (CVE-2022-23437). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-44832 |
|
Vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832)
vulnerability in org.apache.logging.log4j:log4j-core (CVE-2021-44832). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.17.1` or later.
|