Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64655 |
|
Vulnerability in CVE-2026-64655 (CVE-2026-64655)
vulnerability in CVE-2026-64655 (CVE-2026-64655). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64654 |
|
Vulnerability in CVE-2026-64654 (CVE-2026-64654)
vulnerability in CVE-2026-64654 (CVE-2026-64654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64653 |
|
Path Traversal in CVE-2026-64653 (CVE-2026-64653)
path traversal in CVE-2026-64653 (CVE-2026-64653). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64652 |
|
Vulnerability in CVE-2026-64652 (CVE-2026-64652)
vulnerability in CVE-2026-64652 (CVE-2026-64652). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63725 |
|
OS Command Injection in apache (CVE-2026-63725)
OS command injection in apache (CVE-2026-63725). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63637 |
|
Vulnerability in CVE-2026-63637 (CVE-2026-63637)
vulnerability in CVE-2026-63637 (CVE-2026-63637). Confidential information can be exposed externally.
|
| CVE-2026-62857 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-62857 (CVE-2026-62857)
SSRF in CVE-2026-62857 (CVE-2026-62857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5857 |
|
Out-of-Bounds Write in c (CVE-2026-5857)
out-of-bounds write in c (CVE-2026-5857). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5856 |
|
Out-of-Bounds Read in c (CVE-2026-5856)
vulnerability in c (CVE-2026-5856). Confidential information can be exposed externally.
|
| CVE-2026-5855 |
|
Out-of-Bounds Read in c (CVE-2026-5855)
vulnerability in c (CVE-2026-5855). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5336 |
|
Information Disclosure in wordpress (CVE-2026-5336)
vulnerability in wordpress (CVE-2026-5336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53984 |
|
Vulnerability in CVE-2026-53984 (CVE-2026-53984)
vulnerability in CVE-2026-53984 (CVE-2026-53984). Data can be tampered with by attackers.
|
| CVE-2026-53983 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-53983)
SSRF in c (CVE-2026-53983). Confidential information can be exposed externally.
|
| CVE-2026-49391 |
|
Cross-Site Scripting (XSS) in CVE-2026-49391 (CVE-2026-49391)
cross-site scripting in CVE-2026-49391 (CVE-2026-49391). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48088 |
|
Vulnerability in CVE-2026-48088 (CVE-2026-48088)
vulnerability in CVE-2026-48088 (CVE-2026-48088). Confidential information can be exposed externally. Exploitable via `POST /api/tenants/{tenantId}/staff/{staffId}/crypto`.
|
| CVE-2026-48087 |
|
Authentication Bypass in CVE-2026-48087 (CVE-2026-48087)
authentication bypass in CVE-2026-48087 (CVE-2026-48087). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/auth/register/{userId}`.
|
| CVE-2026-48086 |
|
Privilege Escalation in privilege-escalation (CVE-2026-48086)
vulnerability in privilege-escalation (CVE-2026-48086). Successful exploitation can lead to full system takeover. Exploitable via ``GLOBAL_ADMIN``.
|
| CVE-2026-48085 |
|
Vulnerability in csrf (CVE-2026-48085)
vulnerability in csrf (CVE-2026-48085). Successful exploitation can lead to full system takeover. Exploitable via ``default``.
|
| CVE-2026-48084 |
|
Vulnerability in CVE-2026-48084 (CVE-2026-48084)
vulnerability in CVE-2026-48084 (CVE-2026-48084). Confidential information can be exposed externally.
|
| CVE-2026-48083 |
|
Vulnerability in dos (CVE-2026-48083)
vulnerability in dos (CVE-2026-48083). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48082 |
|
Vulnerability in CVE-2026-48082 (CVE-2026-48082)
vulnerability in CVE-2026-48082 (CVE-2026-48082). Risk of unauthorized operations or information disclosure. Exploitable via ``tunnelId``.
|
| CVE-2026-48081 |
|
Cross-Site Scripting (XSS) in CVE-2026-48081 (CVE-2026-48081)
cross-site scripting in CVE-2026-48081 (CVE-2026-48081). Confidential information can be exposed externally. Exploitable via ``links``.
|
| CVE-2026-48080 |
|
Information Disclosure in ssrf (CVE-2026-48080)
vulnerability in ssrf (CVE-2026-48080). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/tenants/{id}`.
|
| CVE-2026-48079 |
|
Vulnerability in CVE-2026-48079 (CVE-2026-48079)
vulnerability in CVE-2026-48079 (CVE-2026-48079). Confidential information can be exposed externally. Exploitable via ``access_token``.
|
| CVE-2026-48078 |
|
Information Disclosure in CVE-2026-48078 (CVE-2026-48078)
vulnerability in CVE-2026-48078 (CVE-2026-48078). Risk of unauthorized operations or information disclosure. Exploitable via ``isPublic``.
|
| CVE-2026-48077 |
|
Vulnerability in CVE-2026-48077 (CVE-2026-48077)
vulnerability in CVE-2026-48077 (CVE-2026-48077). Risk of unauthorized operations or information disclosure. Exploitable via ``encryptedPayload``.
|
| CVE-2026-48076 |
|
Authorization Flaw in CVE-2026-48076 (CVE-2026-48076)
vulnerability in CVE-2026-48076 (CVE-2026-48076). Risk of unauthorized operations or information disclosure. Exploitable via ``tenantId``.
|
| CVE-2026-48075 |
|
Vulnerability in CVE-2026-48075 (CVE-2026-48075)
vulnerability in CVE-2026-48075 (CVE-2026-48075). Data can be tampered with by attackers. Exploitable via `Authorization header`.
|
| CVE-2026-48074 |
|
Authorization Flaw in CVE-2026-48074 (CVE-2026-48074)
vulnerability in CVE-2026-48074 (CVE-2026-48074). Risk of unauthorized operations or information disclosure. Exploitable via ``user_invite``.
|
| CVE-2026-48071 |
|
Vulnerability in dos (CVE-2026-48071)
vulnerability in dos (CVE-2026-48071). Risk of unauthorized operations or information disclosure. Exploitable via ``emailHash``.
|
| CVE-2026-47765 |
|
Vulnerability in CVE-2026-47765 (CVE-2026-47765)
vulnerability in CVE-2026-47765 (CVE-2026-47765). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47194 |
|
Vulnerability in CVE-2026-47194 (CVE-2026-47194)
vulnerability in CVE-2026-47194 (CVE-2026-47194). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-47185 |
|
Cross-Site Scripting (XSS) in CVE-2026-47185 (CVE-2026-47185)
cross-site scripting in CVE-2026-47185 (CVE-2026-47185). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43632 |
|
Vulnerability in cpp (CVE-2026-43632)
vulnerability in cpp (CVE-2026-43632). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43631 |
|
Vulnerability in cpp (CVE-2026-43631)
vulnerability in cpp (CVE-2026-43631). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43630 |
|
Out-of-Bounds Read in cpp (CVE-2026-43630)
vulnerability in cpp (CVE-2026-43630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43629 |
|
Vulnerability in cpp (CVE-2026-43629)
vulnerability in cpp (CVE-2026-43629). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43628 |
|
Out-of-Bounds Read in cpp (CVE-2026-43628)
vulnerability in cpp (CVE-2026-43628). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43627 |
|
Vulnerability in cpp (CVE-2026-43627)
vulnerability in cpp (CVE-2026-43627). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41861 |
|
Path Traversal in path-traversal (CVE-2026-41861)
path traversal in path-traversal (CVE-2026-41861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3418 |
|
Unrestricted File Upload in CVE-2026-3418 (CVE-2026-3418)
vulnerability in CVE-2026-3418 (CVE-2026-3418). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3415 |
|
Vulnerability in CVE-2026-3415 (CVE-2026-3415)
vulnerability in CVE-2026-3415 (CVE-2026-3415). Confidential information can be exposed externally.
|
| CVE-2026-33181 |
|
Vulnerability in CVE-2026-33181 (CVE-2026-33181)
vulnerability in CVE-2026-33181 (CVE-2026-33181). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1289 |
|
Use-After-Free in CVE-2026-1289 (CVE-2026-1289)
vulnerability in CVE-2026-1289 (CVE-2026-1289). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19177 |
|
Vulnerability in google (CVE-2026-19177)
vulnerability in google (CVE-2026-19177). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19176 |
|
Use-After-Free in google (CVE-2026-19176)
vulnerability in google (CVE-2026-19176). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19175 |
|
Use-After-Free in google (CVE-2026-19175)
vulnerability in google (CVE-2026-19175). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19174 |
|
Vulnerability in google (CVE-2026-19174)
vulnerability in google (CVE-2026-19174). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19173 |
|
Out-of-Bounds Write in google (CVE-2026-19173)
out-of-bounds write in google (CVE-2026-19173). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19172 |
|
Use-After-Free in google (CVE-2026-19172)
vulnerability in google (CVE-2026-19172). Successful exploitation can lead to full system takeover.
|