Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73406 |
|
Information Disclosure in @budibase/server (CVE-2026-73406)
vulnerability in @budibase/server (CVE-2026-73406). Confidential information can be exposed externally. Exploitable via `GET /api/global/users/tenant/`.
|
| CVE-2026-73303 |
|
Vulnerability in @budibase/server (CVE-2026-73303)
vulnerability in @budibase/server (CVE-2026-73303). Confidential information can be exposed externally. Exploitable via `POST /api/v2/email`.
|
| CVE-2026-73305 |
|
Privilege Escalation in @budibase/server (CVE-2026-73305)
vulnerability in @budibase/server (CVE-2026-73305). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/public/v1/roles/assign`.
|
| CVE-2026-55502 |
|
Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55502)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55502). Data can be tampered with by attackers. Exploitable via `POST /api/v4/admin/policy/oauth/signin`. Mitigation: upgrade to `4.17.0` or later.
|
| CVE-2026-66040 |
|
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
|
| CVE-2026-66041 |
|
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
|
| CVE-2026-66036 |
|
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
|
| CVE-2026-66039 |
|
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability...
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability...
|
| CVE-2026-54342 |
|
Vulnerability in CVE-2026-54342 (CVE-2026-54342)
vulnerability in CVE-2026-54342 (CVE-2026-54342). Confidential information can be exposed externally.
|
| CVE-2026-17107 |
|
Vulnerability in CVE-2026-17107 (CVE-2026-17107)
vulnerability in CVE-2026-17107 (CVE-2026-17107). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66035 |
|
Vulnerability in c (CVE-2026-66035)
vulnerability in c (CVE-2026-66035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66032 |
|
Vulnerability in c (CVE-2026-66032)
vulnerability in c (CVE-2026-66032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66033 |
|
Out-of-Bounds Read in c (CVE-2026-66033)
vulnerability in c (CVE-2026-66033). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66034 |
|
Out-of-Bounds Read in libssh2 (CVE-2026-66034)
vulnerability in libssh2 (CVE-2026-66034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65709 |
|
Vulnerability in CVE-2026-65709 (CVE-2026-65709)
vulnerability in CVE-2026-65709 (CVE-2026-65709). Confidential information can be exposed externally.
|
| CVE-2026-65710 |
|
Vulnerability in CVE-2026-65710 (CVE-2026-65710)
vulnerability in CVE-2026-65710 (CVE-2026-65710). Confidential information can be exposed externally.
|
| CVE-2026-65711 |
|
OS Command Injection in CVE-2026-65711 (CVE-2026-65711)
OS command injection in CVE-2026-65711 (CVE-2026-65711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65708 |
|
Vulnerability in CVE-2026-65708 (CVE-2026-65708)
vulnerability in CVE-2026-65708 (CVE-2026-65708). Confidential information can be exposed externally.
|
| CVE-2026-59714 |
|
Vulnerability in open-webui (CVE-2026-59714)
vulnerability in open-webui (CVE-2026-59714). Data can be tampered with by attackers. Exploitable via `POST /api/chat/completions`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-73507 |
|
Vulnerability in io.netty:netty-codec-xml (CVE-2026-73507)
vulnerability in io.netty:netty-codec-xml (CVE-2026-73507). Risk of unauthorized operations or information disclosure. Exploitable via ``maxFrameLength``. Mitigation: upgrade to `4.1.136.Final` or later.
|
| CVE-2026-73643 |
|
Vulnerability in js-yaml (CVE-2026-73643)
vulnerability in js-yaml (CVE-2026-73643). Risk of unauthorized operations or information disclosure. Exploitable via ``maxDepth``. Mitigation: upgrade to `5.2.2` or later.
|
| CVE-2026-73646 |
|
Path Traversal in postcss (CVE-2026-73646)
path traversal in postcss (CVE-2026-73646). Confidential information can be exposed externally. Exploitable via ``loadFile``. Mitigation: upgrade to `8.5.18` or later.
|
| CVE-2026-64255 |
|
Out-of-Bounds Read in linux (CVE-2026-64255)
vulnerability in linux (CVE-2026-64255). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65693 |
|
Code Injection in CVE-2026-65693 (CVE-2026-65693)
code injection in CVE-2026-65693 (CVE-2026-65693). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66027 |
|
Vulnerability in CVE-2026-66027 (CVE-2026-66027)
vulnerability in CVE-2026-66027 (CVE-2026-66027). Confidential information can be exposed externally.
|
| CVE-2026-64246 |
|
Use-After-Free in linux (CVE-2026-64246)
vulnerability in linux (CVE-2026-64246). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64247 |
|
Out-of-Bounds Read in linux (CVE-2026-64247)
vulnerability in linux (CVE-2026-64247). Confidential information can be exposed externally.
|
| CVE-2026-64249 |
|
Use-After-Free in linux (CVE-2026-64249)
vulnerability in linux (CVE-2026-64249). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64251 |
|
Use-After-Free in linux (CVE-2026-64251)
vulnerability in linux (CVE-2026-64251). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64245 |
|
Use-After-Free in linux (CVE-2026-64245)
vulnerability in linux (CVE-2026-64245). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64239 |
|
Use-After-Free in linux (CVE-2026-64239)
vulnerability in linux (CVE-2026-64239). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64242 |
|
Vulnerability in linux (CVE-2026-64242)
vulnerability in linux (CVE-2026-64242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64243 |
|
Vulnerability in linux (CVE-2026-64243)
vulnerability in linux (CVE-2026-64243). Confidential information can be exposed externally.
|
| CVE-2026-64237 |
|
Out-of-Bounds Read in linux (CVE-2026-64237)
vulnerability in linux (CVE-2026-64237). Confidential information can be exposed externally.
|
| CVE-2026-64235 |
|
Vulnerability in linux (CVE-2026-64235)
vulnerability in linux (CVE-2026-64235). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64226 |
|
Use-After-Free in linux (CVE-2026-64226)
vulnerability in linux (CVE-2026-64226). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64224 |
|
Vulnerability in linux (CVE-2026-64224)
vulnerability in linux (CVE-2026-64224). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64225 |
|
Vulnerability in linux (CVE-2026-64225)
vulnerability in linux (CVE-2026-64225). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64223 |
|
Out-of-Bounds Read in linux (CVE-2026-64223)
vulnerability in linux (CVE-2026-64223). Confidential information can be exposed externally.
|
| CVE-2026-64222 |
|
Vulnerability in linux (CVE-2026-64222)
vulnerability in linux (CVE-2026-64222). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64221 |
|
Use-After-Free in linux (CVE-2026-64221)
vulnerability in linux (CVE-2026-64221). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64217 |
|
Out-of-Bounds Write in linux (CVE-2026-64217)
out-of-bounds write in linux (CVE-2026-64217). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64219 |
|
Vulnerability in linux (CVE-2026-64219)
vulnerability in linux (CVE-2026-64219). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64218 |
|
Vulnerability in linux (CVE-2026-64218)
vulnerability in linux (CVE-2026-64218). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64209 |
|
Out-of-Bounds Read in linux (CVE-2026-64209)
vulnerability in linux (CVE-2026-64209). Confidential information can be exposed externally.
|
| CVE-2026-64210 |
|
Vulnerability in c (CVE-2026-64210)
vulnerability in c (CVE-2026-64210). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64208 |
|
Vulnerability in linux (CVE-2026-64208)
vulnerability in linux (CVE-2026-64208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8789 |
|
Authorization Flaw in wordpress (CVE-2026-8789)
vulnerability in wordpress (CVE-2026-8789). Data can be tampered with by attackers. Exploitable via ``ea_delete_multiple_connections``.
|
| CVE-2026-16801 |
|
Code Injection in devolutions (CVE-2026-16801)
code injection in devolutions (CVE-2026-16801). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16800 |
|
Code Injection in devolutions (CVE-2026-16800)
code injection in devolutions (CVE-2026-16800). Successful exploitation can lead to full system takeover.
|