Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64615 |
|
Vulnerability in CVE-2026-64615 (CVE-2026-64615)
vulnerability in CVE-2026-64615 (CVE-2026-64615). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64879 |
|
OS Command Injection in tenable (CVE-2026-64879)
OS command injection in tenable (CVE-2026-64879). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64617 |
|
Vulnerability in CVE-2026-64617 (CVE-2026-64617)
vulnerability in CVE-2026-64617 (CVE-2026-64617). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64878 |
|
OS Command Injection in tenable (CVE-2026-64878)
OS command injection in tenable (CVE-2026-64878). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64613 |
|
Vulnerability in CVE-2026-64613 (CVE-2026-64613)
vulnerability in CVE-2026-64613 (CVE-2026-64613). Confidential information can be exposed externally.
|
| CVE-2026-59147 |
|
Out-of-Bounds Read in CVE-2026-59147 (CVE-2026-59147)
vulnerability in CVE-2026-59147 (CVE-2026-59147). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59146 |
|
Out-of-Bounds Read in CVE-2026-59146 (CVE-2026-59146)
vulnerability in CVE-2026-59146 (CVE-2026-59146). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59145 |
|
Out-of-Bounds Read in CVE-2026-59145 (CVE-2026-59145)
vulnerability in CVE-2026-59145 (CVE-2026-59145). Confidential information can be exposed externally.
|
| CVE-2026-59144 |
|
Vulnerability in CVE-2026-59144 (CVE-2026-59144)
vulnerability in CVE-2026-59144 (CVE-2026-59144). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56146 |
|
Authorization Flaw in elastic (CVE-2026-56146)
vulnerability in elastic (CVE-2026-56146). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56852 |
|
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
|
| CVE-2026-59143 |
|
Out-of-Bounds Read in CVE-2026-59143 (CVE-2026-59143)
vulnerability in CVE-2026-59143 (CVE-2026-59143). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50758 |
|
Cross-Site Scripting (XSS) in CVE-2026-50758 (CVE-2026-50758)
cross-site scripting in CVE-2026-50758 (CVE-2026-50758). Confidential information can be exposed externally.
|
| CVE-2026-56145 |
|
Vulnerability in dos (CVE-2026-56145)
vulnerability in dos (CVE-2026-56145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56144 |
|
Authorization Flaw in elastic (CVE-2026-56144)
vulnerability in elastic (CVE-2026-56144). Confidential information can be exposed externally.
|
| CVE-2026-50757 |
|
Path Traversal in path-traversal (CVE-2026-50757)
path traversal in path-traversal (CVE-2026-50757). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50756 |
|
Vulnerability in CVE-2026-50756 (CVE-2026-50756)
vulnerability in CVE-2026-50756 (CVE-2026-50756). Confidential information can be exposed externally.
|
| CVE-2026-50759 |
|
Vulnerability in CVE-2026-50759 (CVE-2026-50759)
vulnerability in CVE-2026-50759 (CVE-2026-50759). Risk of unauthorized operations or information disclosure. Exploitable via `GET /state`.
|
| CVE-2026-49092 |
|
Authorization Flaw in elastic (CVE-2026-49092)
vulnerability in elastic (CVE-2026-49092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50755 |
|
Vulnerability in CVE-2026-50755 (CVE-2026-50755)
vulnerability in CVE-2026-50755 (CVE-2026-50755). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59139 |
|
Out-of-Bounds Read in CVE-2026-59139 (CVE-2026-59139)
vulnerability in CVE-2026-59139 (CVE-2026-59139). Confidential information can be exposed externally.
|
| CVE-2026-42397 |
|
Vulnerability in dos (CVE-2026-42397)
vulnerability in dos (CVE-2026-42397). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46600 |
|
Out-of-Bounds Read in CVE-2026-46600 (CVE-2026-46600)
vulnerability in CVE-2026-46600 (CVE-2026-46600). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59142 |
|
Out-of-Bounds Read in CVE-2026-59142 (CVE-2026-59142)
vulnerability in CVE-2026-59142 (CVE-2026-59142). Confidential information can be exposed externally.
|
| CVE-2026-59141 |
|
Out-of-Bounds Read in CVE-2026-59141 (CVE-2026-59141)
vulnerability in CVE-2026-59141 (CVE-2026-59141). Confidential information can be exposed externally.
|
| CVE-2026-30632 |
|
Path Traversal in path-traversal (CVE-2026-30632)
path traversal in path-traversal (CVE-2026-30632). Confidential information can be exposed externally.
|
| CVE-2026-63453 |
|
Vulnerability in hpe (CVE-2026-63453)
vulnerability in hpe (CVE-2026-63453). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63454 |
|
Path Traversal in path-traversal (CVE-2026-63454)
path traversal in path-traversal (CVE-2026-63454). Successful exploitation can lead to full system takeover.
|
| CVE-2016-20096 |
|
SQL Injection in sqli (CVE-2016-20096)
SQL injection in sqli (CVE-2016-20096). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59140 |
|
Out-of-Bounds Read in CVE-2026-59140 (CVE-2026-59140)
vulnerability in CVE-2026-59140 (CVE-2026-59140). Confidential information can be exposed externally.
|
| CVE-2026-64877 |
|
Vulnerability in sqli (CVE-2026-64877)
vulnerability in sqli (CVE-2026-64877). Confidential information can be exposed externally.
|
| CVE-2026-12548 |
|
Out-of-Bounds Read in gnome (CVE-2026-12548)
vulnerability in gnome (CVE-2026-12548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16441 |
|
Vulnerability in eclipse (CVE-2026-16441)
vulnerability in eclipse (CVE-2026-16441). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12547 |
|
Vulnerability in CVE-2026-12547 (CVE-2026-12547)
vulnerability in CVE-2026-12547 (CVE-2026-12547). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
|
| CVE-2026-47714 |
|
Vulnerability in struktur (CVE-2026-47714)
vulnerability in struktur (CVE-2026-47714). Risk of unauthorized operations or information disclosure. Exploitable via ``width``.
|
| CVE-2026-47697 |
|
Authorization Flaw in CVE-2026-47697 (CVE-2026-47697)
vulnerability in CVE-2026-47697 (CVE-2026-47697). Confidential information can be exposed externally. Exploitable via ``connect``.
|
| CVE-2026-47690 |
|
Command Injection in CVE-2026-47690 (CVE-2026-47690)
command injection in CVE-2026-47690 (CVE-2026-47690). Data can be tampered with by attackers. Exploitable via ``GITHUB_TOKEN``.
|
| CVE-2026-47689 |
|
Cross-Site Scripting (XSS) in fogproject (CVE-2026-47689)
cross-site scripting in fogproject (CVE-2026-47689). Risk of unauthorized operations or information disclosure. Exploitable via ``fogpage.class.php``.
|
| CVE-2026-47688 |
|
Vulnerability in csrf (CVE-2026-47688)
vulnerability in csrf (CVE-2026-47688). Data can be tampered with by attackers. Exploitable via ``clearAES``.
|
| CVE-2026-47687 |
|
Cross-Site Scripting (XSS) in fogproject (CVE-2026-47687)
cross-site scripting in fogproject (CVE-2026-47687). Confidential information can be exposed externally. Exploitable via ``fogpage.class.php``.
|
| CVE-2026-47685 |
|
Cross-Site Scripting (XSS) in fogproject (CVE-2026-47685)
cross-site scripting in fogproject (CVE-2026-47685). Confidential information can be exposed externally.
|
| CVE-2026-47237 |
|
Vulnerability in CVE-2026-47237 (CVE-2026-47237)
vulnerability in CVE-2026-47237 (CVE-2026-47237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47143 |
|
Vulnerability in capstone-engine (CVE-2026-47143)
vulnerability in capstone-engine (CVE-2026-47143). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45383 |
|
Out-of-Bounds Read in CVE-2026-45383 (CVE-2026-45383)
vulnerability in CVE-2026-45383 (CVE-2026-45383). Risk of unauthorized operations or information disclosure. Exploitable via ``ctbAddrRS``.
|
| CVE-2026-45382 |
|
Out-of-Bounds Read in CVE-2026-45382 (CVE-2026-45382)
vulnerability in CVE-2026-45382 (CVE-2026-45382). Risk of unauthorized operations or information disclosure. Exploitable via ``set_derived_values``.
|
| CVE-2026-16318 |
|
Vulnerability in CVE-2026-16318 (CVE-2026-16318)
vulnerability in CVE-2026-16318 (CVE-2026-16318). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58314 |
|
SSRF (Server-Side Request Forgery) in code.gitea.io/gitea (CVE-2026-58314)
SSRF in code.gitea.io/gitea (CVE-2026-58314). Confidential information can be exposed externally. Exploitable via `POST /api/v1/user/hooks`. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-58436 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-58436)
vulnerability in code.gitea.io/gitea (CVE-2026-58436). Risk of unauthorized operations or information disclosure. Exploitable via ``main``. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-16317 |
|
Vulnerability in Amazon aws (CVE-2026-16317)
vulnerability in Amazon aws (CVE-2026-16317). Data can be tampered with by attackers.
|
| CVE-2026-56657 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-56657)
vulnerability in code.gitea.io/gitea (CVE-2026-56657). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/user/keys`. Mitigation: upgrade to `1.27.0` or later.
|