Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-62312 |
|
OS Command Injection in CVE-2026-62312 (CVE-2026-62312)
OS command injection in CVE-2026-62312 (CVE-2026-62312). Successful exploitation can lead to full system takeover. Exploitable via `Host header`.
|
| CVE-2026-52869 |
|
Vulnerability in mcp (CVE-2026-52869)
vulnerability in mcp (CVE-2026-52869). Confidential information can be exposed externally. Exploitable via ``session_id``. Mitigation: upgrade to `1.27.2` or later.
|
| CVE-2026-52870 |
|
Vulnerability in mcp (CVE-2026-52870)
vulnerability in mcp (CVE-2026-52870). Confidential information can be exposed externally. Exploitable via ``TaskStore``. Mitigation: upgrade to `1.27.2` or later.
|
| CVE-2026-50144 |
|
Vulnerability in CVE-2026-50144 (CVE-2026-50144)
vulnerability in CVE-2026-50144 (CVE-2026-50144). Data can be tampered with by attackers.
|
| CVE-2026-62350 |
|
Code Injection in c (CVE-2026-62350)
code injection in c (CVE-2026-62350). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62349 |
|
Vulnerability in c (CVE-2026-62349)
vulnerability in c (CVE-2026-62349). Confidential information can be exposed externally.
|
| CVE-2026-62351 |
|
Out-of-Bounds Read in c (CVE-2026-62351)
vulnerability in c (CVE-2026-62351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46485 |
|
Vulnerability in CVE-2026-46485 (CVE-2026-46485)
vulnerability in CVE-2026-46485 (CVE-2026-46485). Data can be tampered with by attackers.
|
| CVE-2026-15895 |
|
OS Command Injection in Amazon jsii-diff (CVE-2026-15895)
OS command injection in Amazon jsii-diff (CVE-2026-15895). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.131.0` or later.
|
| CVE-2026-12997 |
|
Path Traversal in wordpress (CVE-2026-12997)
path traversal in wordpress (CVE-2026-12997). Confidential information can be exposed externally.
|
| CVE-2026-12382 |
|
Vulnerability in CVE-2026-12382 (CVE-2026-12382)
vulnerability in CVE-2026-12382 (CVE-2026-12382). Data can be tampered with by attackers.
|
| CVE-2026-20297 |
|
Path Traversal in path-traversal (CVE-2026-20297)
path traversal in path-traversal (CVE-2026-20297). Successful exploitation can lead to full system takeover. Exploitable via ``edit_local_apps``.
|
| CVE-2026-56687 |
|
Vulnerability in CVE-2026-56687 (CVE-2026-56687)
vulnerability in CVE-2026-56687 (CVE-2026-56687). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40501 |
|
Vulnerability in CVE-2026-40501 (CVE-2026-40501)
vulnerability in CVE-2026-40501 (CVE-2026-40501). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20296 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-20296)
vulnerability in csrf (CVE-2026-20296). Confidential information can be exposed externally. Exploitable via ``list_deployment_server``.
|
| CVE-2026-58658 |
|
Vulnerability in CVE-2026-58658 (CVE-2026-58658)
vulnerability in CVE-2026-58658 (CVE-2026-58658). Confidential information can be exposed externally.
|
| CVE-2026-58659 |
|
Vulnerability in lightningai (CVE-2026-58659)
vulnerability in lightningai (CVE-2026-58659). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62389 |
|
Vulnerability in dos (CVE-2026-62389)
vulnerability in dos (CVE-2026-62389). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58660 |
|
Vulnerability in CVE-2026-58660 (CVE-2026-58660)
vulnerability in CVE-2026-58660 (CVE-2026-58660). Data can be tampered with by attackers.
|
| CVE-2026-59258 |
|
Authorization Flaw in CVE-2026-59258 (CVE-2026-59258)
vulnerability in CVE-2026-59258 (CVE-2026-59258). Data can be tampered with by attackers. Exploitable via `PUT /albums/`.
|
| CVE-2026-59255 |
|
Vulnerability in CVE-2026-59255 (CVE-2026-59255)
vulnerability in CVE-2026-59255 (CVE-2026-59255). Data can be tampered with by attackers.
|
| CVE-2026-53515 |
|
Privilege Escalation in @better-auth/sso (CVE-2026-53515)
vulnerability in @better-auth/sso (CVE-2026-53515). Data can be tampered with by attackers. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-10673 |
|
Out-of-Bounds Read in c (CVE-2026-10673)
vulnerability in c (CVE-2026-10673). Data can be tampered with by attackers.
|
| CVE-2026-54491 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54491)
SSRF in phanan/koel (CVE-2026-54491). Confidential information can be exposed externally. Exploitable via `POST /api/podcasts`. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-54449 |
|
Command Injection in langbot (CVE-2026-54449)
command injection in langbot (CVE-2026-54449). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48799 |
|
Vulnerability in CVE-2026-48799 (CVE-2026-48799)
vulnerability in CVE-2026-48799 (CVE-2026-48799). Data can be tampered with by attackers.
|
| CVE-2026-20153 |
|
Vulnerability in cisco (CVE-2026-20153)
vulnerability in cisco (CVE-2026-20153). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20156 |
|
Buffer Overflow in cisco (CVE-2026-20156)
vulnerability in cisco (CVE-2026-20156). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20157 |
|
Vulnerability in cisco (CVE-2026-20157)
vulnerability in cisco (CVE-2026-20157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20158 |
|
Vulnerability in cisco (CVE-2026-20158)
vulnerability in cisco (CVE-2026-20158). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20187 |
|
Vulnerability in cisco (CVE-2026-20187)
vulnerability in cisco (CVE-2026-20187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54493 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54493)
SSRF in phanan/koel (CVE-2026-54493). Confidential information can be exposed externally. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-20150 |
|
Vulnerability in Cisco roomos (CVE-2026-20150)
vulnerability in Cisco roomos (CVE-2026-20150). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62685 |
|
Vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-62685)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-62685). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/raw/secretA.txt`. Mitigation: upgrade to `2.63.17` or later.
|
| CVE-2026-61371 |
|
Vulnerability in CVE-2026-61371 (CVE-2026-61371)
vulnerability in CVE-2026-61371 (CVE-2026-61371). Confidential information can be exposed externally.
|
| CVE-2026-60005 |
|
Vulnerability in nginx (CVE-2026-60005)
vulnerability in nginx (CVE-2026-60005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55242 |
|
Authorization Flaw in CVE-2026-55242 (CVE-2026-55242)
vulnerability in CVE-2026-55242 (CVE-2026-55242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50147 |
|
Vulnerability in metabase (CVE-2026-50147)
vulnerability in metabase (CVE-2026-50147). Confidential information can be exposed externally.
|
| CVE-2026-46709 |
|
Command Injection in tabby (CVE-2026-46709)
command injection in tabby (CVE-2026-46709). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47158 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-47158 (CVE-2026-47158)
vulnerability in CVE-2026-47158 (CVE-2026-47158). Data can be tampered with by attackers.
|
| CVE-2026-47164 |
|
Vulnerability in CVE-2026-47164 (CVE-2026-47164)
vulnerability in CVE-2026-47164 (CVE-2026-47164). Confidential information can be exposed externally.
|
| CVE-2026-45806 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-45806 (CVE-2026-45806)
SSRF in CVE-2026-45806 (CVE-2026-45806). Confidential information can be exposed externally.
|
| CVE-2026-55723 |
|
Vulnerability in nginx (CVE-2026-55723)
vulnerability in nginx (CVE-2026-55723). Confidential information can be exposed externally.
|
| CVE-2026-58558 |
|
Vulnerability in CVE-2026-58558 (CVE-2026-58558)
vulnerability in CVE-2026-58558 (CVE-2026-58558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42533 |
|
Vulnerability in nginx (CVE-2026-42533)
vulnerability in nginx (CVE-2026-42533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59762 |
|
Vulnerability in dos (CVE-2026-59762)
vulnerability in dos (CVE-2026-59762). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15809 |
|
Vulnerability in CVE-2026-15809 (CVE-2026-15809)
vulnerability in CVE-2026-15809 (CVE-2026-15809). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61836 |
|
Vulnerability in directus (CVE-2026-61836)
vulnerability in directus (CVE-2026-61836). Confidential information can be exposed externally. Exploitable via ``version``. Mitigation: upgrade to `12.0.0` or later.
|
| CVE-2026-61835 |
|
SSRF (Server-Side Request Forgery) in directus (CVE-2026-61835)
SSRF in directus (CVE-2026-61835). Confidential information can be exposed externally. Exploitable via ``IMPORT_IP_DENY_LIST``. Mitigation: upgrade to `12.0.0` or later.
|
| CVE-2026-61644 |
|
Authorization Flaw in CVE-2026-61644 (CVE-2026-61644)
vulnerability in CVE-2026-61644 (CVE-2026-61644). Confidential information can be exposed externally. Exploitable via `POST /api/core/chat/record/getCollectionQuote`.
|