Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-41862 |
|
Unsafe Deserialization in CVE-2026-41862 (CVE-2026-41862)
vulnerability in CVE-2026-41862 (CVE-2026-41862). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12112 |
|
Authentication Bypass in privilege-escalation (CVE-2026-12112)
authentication bypass in privilege-escalation (CVE-2026-12112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54555 |
|
Authorization Flaw in CVE-2026-54555 (CVE-2026-54555)
vulnerability in CVE-2026-54555 (CVE-2026-54555). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.42.2` or later.
|
| CVE-2026-39253 |
|
Unsafe Deserialization in CVE-2026-39253 (CVE-2026-39253)
vulnerability in CVE-2026-39253 (CVE-2026-39253). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54320 |
|
Authentication Bypass in CVE-2026-54320 (CVE-2026-54320)
authentication bypass in CVE-2026-54320 (CVE-2026-54320). Confidential information can be exposed externally. Mitigation: upgrade to `0.184.0` or later.
|
| CVE-2025-61024 |
|
SQL Injection in dos (CVE-2025-61024)
SQL injection in dos (CVE-2025-61024). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-9695 |
|
Out-of-Bounds Write in adobe (CVE-2020-9695)
out-of-bounds write in adobe (CVE-2020-9695). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61029 |
|
SQL Injection in dos (CVE-2025-61029)
SQL injection in dos (CVE-2025-61029). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55441 |
|
Vulnerability in mise (CVE-2026-55441)
vulnerability in mise (CVE-2026-55441). Successful exploitation can lead to full system takeover. Exploitable via ``mise.toml``. Mitigation: upgrade to `2026.6.4` or later.
|
| CVE-2026-54318 |
|
Vulnerability in home-assistant (CVE-2026-54318)
vulnerability in home-assistant (CVE-2026-54318). Data can be tampered with by attackers. Mitigation: upgrade to `2026.5.3` or later.
|
| CVE-2026-53925 |
|
Path Traversal in glances (CVE-2026-53925)
path traversal in glances (CVE-2026-53925). Successful exploitation can lead to full system takeover. Exploitable via ``command``. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-55173 |
|
OS Command Injection in wwbn/avideo (CVE-2026-55173)
OS command injection in wwbn/avideo (CVE-2026-55173). Successful exploitation can lead to full system takeover. Exploitable via ``sanitizeFFmpegCommand``.
|
| CVE-2026-56115 |
|
Vulnerability in c (CVE-2026-56115)
vulnerability in c (CVE-2026-56115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44959 |
|
Code Injection in CVE-2026-44959 (CVE-2026-44959)
code injection in CVE-2026-44959 (CVE-2026-44959). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34916 |
|
Code Injection in CVE-2026-34916 (CVE-2026-34916)
code injection in CVE-2026-34916 (CVE-2026-34916). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34914 |
|
SQL Injection in sqli (CVE-2026-34914)
SQL injection in sqli (CVE-2026-34914). Data can be tampered with by attackers.
|
| CVE-2026-13007 |
|
Vulnerability in tenable (CVE-2026-13007)
vulnerability in tenable (CVE-2026-13007). Confidential information can be exposed externally.
|
| CVE-2026-12958 |
|
Vulnerability in CVE-2026-12958 (CVE-2026-12958)
vulnerability in CVE-2026-12958 (CVE-2026-12958). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61021 |
|
SQL Injection in dos (CVE-2025-61021)
SQL injection in dos (CVE-2025-61021). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61020 |
|
SQL Injection in dos (CVE-2025-61020)
SQL injection in dos (CVE-2025-61020). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61022 |
|
SQL Injection in dos (CVE-2025-61022)
SQL injection in dos (CVE-2025-61022). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61028 |
|
SQL Injection in dos (CVE-2025-61028)
SQL injection in dos (CVE-2025-61028). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61027 |
|
SQL Injection in dos (CVE-2025-61027)
SQL injection in dos (CVE-2025-61027). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61025 |
|
SQL Injection in dos (CVE-2025-61025)
SQL injection in dos (CVE-2025-61025). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61023 |
|
SQL Injection in dos (CVE-2025-61023)
SQL injection in dos (CVE-2025-61023). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61019 |
|
SQL Injection in dos (CVE-2025-61019)
SQL injection in dos (CVE-2025-61019). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61018 |
|
SQL Injection in dos (CVE-2025-61018)
SQL injection in dos (CVE-2025-61018). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12957 |
|
Vulnerability in Amazon aws (CVE-2026-12957)
vulnerability in Amazon aws (CVE-2026-12957). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52808 |
|
Privilege Escalation in gogs.io/gogs (CVE-2026-52808)
vulnerability in gogs.io/gogs (CVE-2026-52808). Data can be tampered with by attackers.
|
| CVE-2026-52805 |
|
SSRF (Server-Side Request Forgery) in gogs.io/gogs (CVE-2026-52805)
SSRF in gogs.io/gogs (CVE-2026-52805). Confidential information can be exposed externally.
|
| CVE-2026-1840 |
|
Vulnerability in cisa (CVE-2026-1840)
vulnerability in cisa (CVE-2026-1840). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56815 |
|
Vulnerability in CVE-2026-56815 (CVE-2026-56815)
vulnerability in CVE-2026-56815 (CVE-2026-56815). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35019 |
|
Vulnerability in CVE-2026-35019 (CVE-2026-35019)
vulnerability in CVE-2026-35019 (CVE-2026-35019). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35018 |
|
OS Command Injection in CVE-2026-35018 (CVE-2026-35018)
OS command injection in CVE-2026-35018 (CVE-2026-35018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56784 |
|
Vulnerability in CVE-2026-56784 (CVE-2026-56784)
vulnerability in CVE-2026-56784 (CVE-2026-56784). Confidential information can be exposed externally.
|
| CVE-2026-56379 |
|
Vulnerability in imagemagick (CVE-2026-56379)
vulnerability in imagemagick (CVE-2026-56379). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56275 |
|
SSRF (Server-Side Request Forgery) in flowiseai (CVE-2026-56275)
SSRF in flowiseai (CVE-2026-56275). Confidential information can be exposed externally.
|
| CVE-2026-56322 |
|
Information Disclosure in CVE-2026-56322 (CVE-2026-56322)
vulnerability in CVE-2026-56322 (CVE-2026-56322). Confidential information can be exposed externally.
|
| CVE-2026-56243 |
|
Vulnerability in CVE-2026-56243 (CVE-2026-56243)
vulnerability in CVE-2026-56243 (CVE-2026-56243). Confidential information can be exposed externally.
|
| CVE-2026-56225 |
|
Privilege Escalation in CVE-2026-56225 (CVE-2026-56225)
vulnerability in CVE-2026-56225 (CVE-2026-56225). Confidential information can be exposed externally.
|
| CVE-2026-56222 |
|
Vulnerability in CVE-2026-56222 (CVE-2026-56222)
vulnerability in CVE-2026-56222 (CVE-2026-56222). Successful exploitation can lead to full system takeover. Exploitable via `POST /private/role_bindings`.
|
| CVE-2026-56248 |
|
Vulnerability in dos (CVE-2026-56248)
vulnerability in dos (CVE-2026-56248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56258 |
|
Path Traversal in crawl4ai (CVE-2026-56258)
path traversal in crawl4ai (CVE-2026-56258). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.8` or later.
|
| CVE-2026-10711 |
|
Vulnerability in CVE-2026-10711 (CVE-2026-10711)
vulnerability in CVE-2026-10711 (CVE-2026-10711). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71376 |
|
Unsafe Deserialization in CVE-2025-71376 (CVE-2025-71376)
vulnerability in CVE-2025-71376 (CVE-2025-71376). Confidential information can be exposed externally.
|
| CVE-2025-71370 |
|
Unsafe Deserialization in CVE-2025-71370 (CVE-2025-71370)
vulnerability in CVE-2025-71370 (CVE-2025-71370). Confidential information can be exposed externally.
|
| CVE-2025-71365 |
|
Unsafe Deserialization in CVE-2025-71365 (CVE-2025-71365)
vulnerability in CVE-2025-71365 (CVE-2025-71365). Confidential information can be exposed externally.
|
| CVE-2025-71341 |
|
Unsafe Deserialization in CVE-2025-71341 (CVE-2025-71341)
vulnerability in CVE-2025-71341 (CVE-2025-71341). Confidential information can be exposed externally.
|
| CVE-2025-71337 |
|
Vulnerability in flowiseai (CVE-2025-71337)
vulnerability in flowiseai (CVE-2025-71337). Confidential information can be exposed externally.
|
| CVE-2023-54365 |
|
Vulnerability in traefik (CVE-2023-54365)
vulnerability in traefik (CVE-2023-54365). Risk of unauthorized operations or information disclosure.
|