Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72871 |
|
Vulnerability in CVE-2026-72871 (CVE-2026-72871)
vulnerability in CVE-2026-72871 (CVE-2026-72871). Data can be tampered with by attackers.
|
| CVE-2026-72870 |
|
OS Command Injection in CVE-2026-72870 (CVE-2026-72870)
OS command injection in CVE-2026-72870 (CVE-2026-72870). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72869 |
|
Command Injection in CVE-2026-72869 (CVE-2026-72869)
command injection in CVE-2026-72869 (CVE-2026-72869). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72868 |
|
OS Command Injection in CVE-2026-72868 (CVE-2026-72868)
OS command injection in CVE-2026-72868 (CVE-2026-72868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72867 |
|
Vulnerability in CVE-2026-72867 (CVE-2026-72867)
vulnerability in CVE-2026-72867 (CVE-2026-72867). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72866 |
|
Vulnerability in CVE-2026-72866 (CVE-2026-72866)
vulnerability in CVE-2026-72866 (CVE-2026-72866). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72865 |
|
OS Command Injection in c (CVE-2026-72865)
OS command injection in c (CVE-2026-72865). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72864 |
|
Vulnerability in CVE-2026-72864 (CVE-2026-72864)
vulnerability in CVE-2026-72864 (CVE-2026-72864). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72863 |
|
Privilege Escalation in CVE-2026-72863 (CVE-2026-72863)
vulnerability in CVE-2026-72863 (CVE-2026-72863). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-71969 |
|
Vulnerability in CVE-2026-71969 (CVE-2026-71969)
vulnerability in CVE-2026-71969 (CVE-2026-71969). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71968 |
|
Vulnerability in CVE-2026-71968 (CVE-2026-71968)
vulnerability in CVE-2026-71968 (CVE-2026-71968). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71967 |
|
Vulnerability in dos (CVE-2026-71967)
vulnerability in dos (CVE-2026-71967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71964 |
|
Vulnerability in CVE-2026-71964 (CVE-2026-71964)
vulnerability in CVE-2026-71964 (CVE-2026-71964). Confidential information can be exposed externally.
|
| CVE-2026-71962 |
|
Vulnerability in CVE-2026-71962 (CVE-2026-71962)
vulnerability in CVE-2026-71962 (CVE-2026-71962). Confidential information can be exposed externally. Exploitable via `POST /api/v1/openai-assistants-file/download`.
|
| CVE-2026-6791 |
|
Vulnerability in CVE-2026-6791 (CVE-2026-6791)
vulnerability in CVE-2026-6791 (CVE-2026-6791). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6368 |
|
Vulnerability in c (CVE-2026-6368)
vulnerability in c (CVE-2026-6368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68872 |
|
Vulnerability in apache (CVE-2026-68872)
vulnerability in apache (CVE-2026-68872). Confidential information can be exposed externally.
|
| CVE-2026-68871 |
|
Vulnerability in apache (CVE-2026-68871)
vulnerability in apache (CVE-2026-68871). Confidential information can be exposed externally.
|
| CVE-2026-68870 |
|
Vulnerability in apache (CVE-2026-68870)
vulnerability in apache (CVE-2026-68870). Confidential information can be exposed externally.
|
| CVE-2026-59091 |
|
Out-of-Bounds Write in gimp (CVE-2026-59091)
out-of-bounds write in gimp (CVE-2026-59091). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12339 |
|
Path Traversal in path-traversal (CVE-2026-12339)
path traversal in path-traversal (CVE-2026-12339). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72900 |
|
Vulnerability in CVE-2026-72900 (CVE-2026-72900)
vulnerability in CVE-2026-72900 (CVE-2026-72900). Confidential information can be exposed externally.
|
| CVE-2026-72899 |
|
SQL Injection in CVE-2026-72899 (CVE-2026-72899)
SQL injection in CVE-2026-72899 (CVE-2026-72899). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72898 KEV |
|
[KEV] SQL Injection in metabase (CVE-2026-72898)
SQL injection in metabase (CVE-2026-72898). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-72862 |
|
OS Command Injection in CVE-2026-72862 (CVE-2026-72862)
OS command injection in CVE-2026-72862 (CVE-2026-72862). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-72740 |
|
OS Command Injection in CVE-2026-72740 (CVE-2026-72740)
OS command injection in CVE-2026-72740 (CVE-2026-72740). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72739 |
|
OS Command Injection in CVE-2026-72739 (CVE-2026-72739)
OS command injection in CVE-2026-72739 (CVE-2026-72739). Confidential information can be exposed externally. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-72738 |
|
OS Command Injection in CVE-2026-72738 (CVE-2026-72738)
OS command injection in CVE-2026-72738 (CVE-2026-72738). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72737 |
|
Vulnerability in CVE-2026-72737 (CVE-2026-72737)
vulnerability in CVE-2026-72737 (CVE-2026-72737). Confidential information can be exposed externally.
|
| CVE-2026-72736 |
|
Command Injection in CVE-2026-72736 (CVE-2026-72736)
command injection in CVE-2026-72736 (CVE-2026-72736). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.29.13` or later.
|
| CVE-2026-72735 |
|
Command Injection in CVE-2026-72735 (CVE-2026-72735)
command injection in CVE-2026-72735 (CVE-2026-72735). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72734 |
|
Vulnerability in CVE-2026-72734 (CVE-2026-72734)
vulnerability in CVE-2026-72734 (CVE-2026-72734). Confidential information can be exposed externally.
|
| CVE-2026-72733 |
|
OS Command Injection in CVE-2026-72733 (CVE-2026-72733)
OS command injection in CVE-2026-72733 (CVE-2026-72733). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72732 |
|
Vulnerability in CVE-2026-72732 (CVE-2026-72732)
vulnerability in CVE-2026-72732 (CVE-2026-72732). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70622 |
|
Vulnerability in CVE-2026-70622 (CVE-2026-70622)
vulnerability in CVE-2026-70622 (CVE-2026-70622). Confidential information can be exposed externally.
|
| CVE-2026-48159 |
|
Vulnerability in react (CVE-2026-48159)
vulnerability in react (CVE-2026-48159). Risk of unauthorized operations or information disclosure. Exploitable via ``postinstall``.
|
| CVE-2026-16626 |
|
XXE (XML External Entity) in CVE-2026-16626 (CVE-2026-16626)
vulnerability in CVE-2026-16626 (CVE-2026-16626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10754 |
|
Vulnerability in CVE-2026-10754 (CVE-2026-10754)
vulnerability in CVE-2026-10754 (CVE-2026-10754). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72731 |
|
SQL Injection in CVE-2026-72731 (CVE-2026-72731)
SQL injection in CVE-2026-72731 (CVE-2026-72731). Confidential information can be exposed externally.
|
| CVE-2026-72730 |
|
Cross-Site Scripting (XSS) in CVE-2026-72730 (CVE-2026-72730)
cross-site scripting in CVE-2026-72730 (CVE-2026-72730). Confidential information can be exposed externally.
|
| CVE-2026-72729 |
|
Cross-Site Scripting (XSS) in CVE-2026-72729 (CVE-2026-72729)
cross-site scripting in CVE-2026-72729 (CVE-2026-72729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72728 |
|
Vulnerability in CVE-2026-72728 (CVE-2026-72728)
vulnerability in CVE-2026-72728 (CVE-2026-72728). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72727 |
|
Cross-Site Scripting (XSS) in CVE-2026-72727 (CVE-2026-72727)
cross-site scripting in CVE-2026-72727 (CVE-2026-72727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71577 |
|
Vulnerability in CVE-2026-71577 (CVE-2026-71577)
vulnerability in CVE-2026-71577 (CVE-2026-71577). Confidential information can be exposed externally.
|
| CVE-2026-71576 |
|
Vulnerability in CVE-2026-71576 (CVE-2026-71576)
vulnerability in CVE-2026-71576 (CVE-2026-71576). Data can be tampered with by attackers.
|
| CVE-2026-63623 |
|
Vulnerability in CVE-2026-63623 (CVE-2026-63623)
vulnerability in CVE-2026-63623 (CVE-2026-63623). Confidential information can be exposed externally.
|
| CVE-2026-56619 |
|
Cross-Site Scripting (XSS) in CVE-2026-56619 (CVE-2026-56619)
cross-site scripting in CVE-2026-56619 (CVE-2026-56619). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40512 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-35028 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-35027 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|