Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66053 |
|
Vulnerability in apache (CVE-2026-66053)
vulnerability in apache (CVE-2026-66053). Confidential information can be exposed externally.
|
| CVE-2026-48586 |
|
Vulnerability in c (CVE-2026-48586)
vulnerability in c (CVE-2026-48586). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41608 |
|
Vulnerability in apache (CVE-2026-41608)
vulnerability in apache (CVE-2026-41608). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43871 |
|
Vulnerability in apache (CVE-2026-43871)
vulnerability in apache (CVE-2026-43871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13014 |
|
Path Traversal in django (CVE-2026-13014)
path traversal in django (CVE-2026-13014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49257 |
|
Vulnerability in mcp-pinot-server (CVE-2026-49257)
vulnerability in mcp-pinot-server (CVE-2026-49257). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-44181 |
|
Vulnerability in jupyter_enterprise_gateway (CVE-2026-44181)
vulnerability in jupyter_enterprise_gateway (CVE-2026-44181). Successful exploitation can lead to full system takeover. Exploitable via ``KERNEL_XXX``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-45426 |
|
Authorization Flaw in apache-airflow (CVE-2026-45426)
vulnerability in apache-airflow (CVE-2026-45426). Risk of unauthorized operations or information disclosure. Exploitable via ``sub``. Mitigation: upgrade to `3.2.2` or later.
|
| CVE-2026-42197 |
|
Cross-Site Scripting (XSS) in django (CVE-2026-42197)
cross-site scripting in django (CVE-2026-42197). Confidential information can be exposed externally. Exploitable via ``ParticipationAdmin``.
|
| CVE-2026-46556 |
|
SSRF (Server-Side Request Forgery) in flaskbb (CVE-2026-46556)
SSRF in flaskbb (CVE-2026-46556). Confidential information can be exposed externally. Exploitable via `POST /user/settings/user-details`.
|
| CVE-2026-48207 |
|
Unsafe Deserialization in pyfory (CVE-2026-48207)
vulnerability in pyfory (CVE-2026-48207). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.0` or later.
|
| CVE-2026-45568 |
|
Path Traversal in zrok (CVE-2026-45568)
path traversal in zrok (CVE-2026-45568). Confidential information can be exposed externally. Exploitable via ``ProxyShare``.
|
| CVE-2026-45306 |
|
Vulnerability in pyload-ng (CVE-2026-45306)
vulnerability in pyload-ng (CVE-2026-45306). Confidential information can be exposed externally. Exploitable via `GET /files/get/`.
|
| SUSE-SU-2026:1740-1 |
|
Vulnerability in django (SUSE-SU-2026:1740-1)
vulnerability in django (SUSE-SU-2026:1740-1). Risk of unauthorized operations or information disclosure. Exploitable via ``ASGIRequest``.
|
| CVE-2026-44015 |
|
SSRF (Server-Side Request Forgery) in github.com/0xJacky/Nginx-UI (CVE-2026-44015)
SSRF in github.com/0xJacky/Nginx-UI (CVE-2026-44015). Confidential information can be exposed externally. Exploitable via `GET /api/settings`.
|
| CVE-2026-40316 |
|
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflo...
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Versions prior to 2.1.1 contain an RCE vulnerability in the .github/workflows/regenerate-migrations.yml workflow. The workflow uses the pull_request_target trigger to run with...
|
| CVE-2026-34406 |
|
Vulnerability in django (CVE-2026-34406)
vulnerability in django (CVE-2026-34406). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/auth/edituser/`.
|
| CVE-2009-3720 |
|
Vulnerability in c (CVE-2009-3720)
vulnerability in c (CVE-2009-3720). Risk of unauthorized operations or information disclosure.
|