Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-67440 |
|
Vulnerability in CVE-2026-67440 (CVE-2026-67440)
vulnerability in CVE-2026-67440 (CVE-2026-67440). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65985 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65985)
SSRF in ssrf (CVE-2026-65985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65984 |
|
Vulnerability in CVE-2026-65984 (CVE-2026-65984)
vulnerability in CVE-2026-65984 (CVE-2026-65984). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/refresh`.
|
| CVE-2026-59915 |
|
Vulnerability in CVE-2026-59915 (CVE-2026-59915)
vulnerability in CVE-2026-59915 (CVE-2026-59915). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57826 |
|
Vulnerability in CVE-2026-57826 (CVE-2026-57826)
vulnerability in CVE-2026-57826 (CVE-2026-57826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52481 |
|
Information Disclosure in CVE-2026-52481 (CVE-2026-52481)
vulnerability in CVE-2026-52481 (CVE-2026-52481). Confidential information can be exposed externally.
|
| CVE-2026-52480 |
|
Vulnerability in CVE-2026-52480 (CVE-2026-52480)
vulnerability in CVE-2026-52480 (CVE-2026-52480). Confidential information can be exposed externally.
|
| CVE-2026-49500 |
|
Vulnerability in dos (CVE-2026-49500)
vulnerability in dos (CVE-2026-49500). Data can be tampered with by attackers.
|
| CVE-2026-19671 |
|
Vulnerability in CVE-2026-19671 (CVE-2026-19671)
vulnerability in CVE-2026-19671 (CVE-2026-19671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19670 |
|
Authorization Flaw in nginx (CVE-2026-19670)
vulnerability in nginx (CVE-2026-19670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12520 |
|
Out-of-Bounds Write in c (CVE-2026-12520)
out-of-bounds write in c (CVE-2026-12520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55211 |
|
Out-of-Bounds Read in surfio (CVE-2026-55211)
vulnerability in surfio (CVE-2026-55211). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.0.19` or later.
|
| CVE-2026-55209 |
|
Vulnerability in resdata (CVE-2026-55209)
vulnerability in resdata (CVE-2026-55209). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.9` or later.
|
| CVE-2026-55107 |
|
Code Injection in kobako (CVE-2026-55107)
code injection in kobako (CVE-2026-55107). Risk of unauthorized operations or information disclosure. Exploitable via ``public_send``. Mitigation: upgrade to `0.9.1` or later.
|
| GHSA-c7hr-448w-65px |
|
Vulnerability in meshcentral (GHSA-c7hr-448w-65px)
vulnerability in meshcentral (GHSA-c7hr-448w-65px). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.60` or later.
|
| CVE-2026-70667 |
|
Vulnerability in lemur (CVE-2026-70667)
vulnerability in lemur (CVE-2026-70667). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/1/certificates/upload`. Mitigation: upgrade to `1.9.3` or later.
|
| CVE-2026-65959 |
|
Vulnerability in CVE-2026-65959 (CVE-2026-65959)
vulnerability in CVE-2026-65959 (CVE-2026-65959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47630 |
|
Vulnerability in path-traversal (CVE-2026-47630)
vulnerability in path-traversal (CVE-2026-47630). Confidential information can be exposed externally.
|
| CVE-2026-47629 |
|
Vulnerability in dos (CVE-2026-47629)
vulnerability in dos (CVE-2026-47629). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47628 |
|
Vulnerability in dos (CVE-2026-47628)
vulnerability in dos (CVE-2026-47628). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47627 |
|
Path Traversal in path-traversal (CVE-2026-47627)
path traversal in path-traversal (CVE-2026-47627). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47606 |
|
Vulnerability in path-traversal (CVE-2026-47606)
vulnerability in path-traversal (CVE-2026-47606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24185 |
|
Vulnerability in CVE-2026-24185 (CVE-2026-24185)
vulnerability in CVE-2026-24185 (CVE-2026-24185). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24184 |
|
Vulnerability in CVE-2026-24184 (CVE-2026-24184)
vulnerability in CVE-2026-24184 (CVE-2026-24184). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24183 |
|
Vulnerability in CVE-2026-24183 (CVE-2026-24183)
vulnerability in CVE-2026-24183 (CVE-2026-24183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17106 |
|
Vulnerability in github.com/moby/go-archive (CVE-2026-17106)
vulnerability in github.com/moby/go-archive (CVE-2026-17106). Risk of unauthorized operations or information disclosure. Exploitable via ``Unpack``. Mitigation: upgrade to `0.3.0` or later.
|
| CVE-2025-9211 |
|
Cross-Site Scripting (XSS) in CVE-2025-9211 (CVE-2025-9211)
cross-site scripting in CVE-2025-9211 (CVE-2025-9211). Confidential information can be exposed externally.
|
| CVE-2025-9210 |
|
Vulnerability in CVE-2025-9210 (CVE-2025-9210)
vulnerability in CVE-2025-9210 (CVE-2025-9210). Confidential information can be exposed externally.
|
| CVE-2021-43718 |
|
Vulnerability in dos (CVE-2021-43718)
vulnerability in dos (CVE-2021-43718). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75625 |
|
Vulnerability in CVE-2026-75625 (CVE-2026-75625)
vulnerability in CVE-2026-75625 (CVE-2026-75625). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75130 |
|
Vulnerability in CVE-2026-75130 (CVE-2026-75130)
vulnerability in CVE-2026-75130 (CVE-2026-75130). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71878 |
|
Vulnerability in CVE-2026-71878 (CVE-2026-71878)
vulnerability in CVE-2026-71878 (CVE-2026-71878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71880 |
|
Vulnerability in CVE-2026-71880 (CVE-2026-71880)
vulnerability in CVE-2026-71880 (CVE-2026-71880). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71879 |
|
Vulnerability in CVE-2026-71879 (CVE-2026-71879)
vulnerability in CVE-2026-71879 (CVE-2026-71879). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67920 |
|
Vulnerability in CVE-2026-67920 (CVE-2026-67920)
vulnerability in CVE-2026-67920 (CVE-2026-67920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67262 |
|
Vulnerability in CVE-2026-67262 (CVE-2026-67262)
vulnerability in CVE-2026-67262 (CVE-2026-67262). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67921 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-67921)
vulnerability in csrf (CVE-2026-67921). Confidential information can be exposed externally.
|
| CVE-2026-52609 |
|
Cross-Site Scripting (XSS) in CVE-2026-52609 (CVE-2026-52609)
cross-site scripting in CVE-2026-52609 (CVE-2026-52609). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52610 |
|
Path Traversal in path-traversal (CVE-2026-52610)
path traversal in path-traversal (CVE-2026-52610). Confidential information can be exposed externally.
|
| CVE-2026-52607 |
|
Path Traversal in path-traversal (CVE-2026-52607)
path traversal in path-traversal (CVE-2026-52607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66780 |
|
Vulnerability in CVE-2026-66780 (CVE-2026-66780)
vulnerability in CVE-2026-66780 (CVE-2026-66780). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67846 |
|
Vulnerability in CVE-2026-67846 (CVE-2026-67846)
vulnerability in CVE-2026-67846 (CVE-2026-67846). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52608 |
|
Vulnerability in CVE-2026-52608 (CVE-2026-52608)
vulnerability in CVE-2026-52608 (CVE-2026-52608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32657 |
|
Vulnerability in CVE-2026-32657 (CVE-2026-32657)
vulnerability in CVE-2026-32657 (CVE-2026-32657). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43716 |
|
Vulnerability in CVE-2021-43716 (CVE-2021-43716)
vulnerability in CVE-2021-43716 (CVE-2021-43716). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43717 |
|
Vulnerability in CVE-2021-43717 (CVE-2021-43717)
vulnerability in CVE-2021-43717 (CVE-2021-43717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74046 |
|
Vulnerability in dos (CVE-2026-74046)
vulnerability in dos (CVE-2026-74046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74044 |
|
Path Traversal in path-traversal (CVE-2026-74044)
path traversal in path-traversal (CVE-2026-74044). Data can be tampered with by attackers.
|
| CVE-2026-74039 |
|
Vulnerability in dos (CVE-2026-74039)
vulnerability in dos (CVE-2026-74039). Risk of unauthorized operations or information disclosure. Exploitable via `POST /security/user/authenticate/run_as`.
|
| CVE-2026-74038 |
|
Path Traversal in path-traversal (CVE-2026-74038)
path traversal in path-traversal (CVE-2026-74038). Risk of unauthorized operations or information disclosure.
|