Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59728 |
|
Vulnerability in @astrojs/rss (CVE-2026-59728)
vulnerability in @astrojs/rss (CVE-2026-59728). Risk of unauthorized operations or information disclosure. Exploitable via ``source.title``. Mitigation: upgrade to `4.0.19` or later.
|
| CVE-2026-59727 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-59727)
cross-site scripting in astro (CVE-2026-59727). Risk of unauthorized operations or information disclosure. Exploitable via ``attrs``. Mitigation: upgrade to `7.0.4` or later.
|
| CVE-2026-15905 |
|
Use-After-Free in google (CVE-2026-15905)
vulnerability in google (CVE-2026-15905). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15904 |
|
Use-After-Free in google (CVE-2026-15904)
vulnerability in google (CVE-2026-15904). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15903 |
|
Out-of-Bounds Read in google (CVE-2026-15903)
vulnerability in google (CVE-2026-15903). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15902 |
|
Use-After-Free in google (CVE-2026-15902)
vulnerability in google (CVE-2026-15902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15901 |
|
Use-After-Free in google (CVE-2026-15901)
vulnerability in google (CVE-2026-15901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15900 |
|
Use-After-Free in google (CVE-2026-15900)
vulnerability in google (CVE-2026-15900). Successful exploitation can lead to full system takeover.
|
| GHSA-gcfj-64vw-6mp9 |
|
Information Disclosure in axios (GHSA-gcfj-64vw-6mp9)
vulnerability in axios (GHSA-gcfj-64vw-6mp9). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-hcpx-6fm6-wx23 |
|
Vulnerability in axios (GHSA-hcpx-6fm6-wx23)
vulnerability in axios (GHSA-hcpx-6fm6-wx23). Risk of unauthorized operations or information disclosure. Exploitable via `POST /forward`. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-7q8q-rj6j-mhjq |
|
Vulnerability in axios (GHSA-7q8q-rj6j-mhjq)
vulnerability in axios (GHSA-7q8q-rj6j-mhjq). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-mwf2-3pr3-8698 |
|
Vulnerability in axios (GHSA-mwf2-3pr3-8698)
vulnerability in axios (GHSA-mwf2-3pr3-8698). Risk of unauthorized operations or information disclosure. Exploitable via ``maxBodyLength``. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-jqh4-m9w3-8hp9 |
|
Vulnerability in axios (GHSA-jqh4-m9w3-8hp9)
vulnerability in axios (GHSA-jqh4-m9w3-8hp9). Risk of unauthorized operations or information disclosure. Exploitable via ``maxBodyLength``. Mitigation: upgrade to `1.18.0` or later.
|
| GHSA-mmx7-hfxf-jppx |
|
Vulnerability in axios (GHSA-mmx7-hfxf-jppx)
vulnerability in axios (GHSA-mmx7-hfxf-jppx). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `0.33.0` or later.
|
| GHSA-f4gw-2p7v-4548 |
|
Vulnerability in axios (GHSA-f4gw-2p7v-4548)
vulnerability in axios (GHSA-f4gw-2p7v-4548). Risk of unauthorized operations or information disclosure. Exploitable via ``NO_PROXY``. Mitigation: upgrade to `0.33.0` or later.
|
| CVE-2026-62684 |
|
Information Disclosure in github.com/filebrowser/filebrowser/v2 (CVE-2026-62684)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-62684). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/shares`. Mitigation: upgrade to `2.63.17` or later.
|
| CVE-2026-64626 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-64626)
SSRF in ssrf (CVE-2026-64626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64625 |
|
OS Command Injection in c (CVE-2026-64625)
OS command injection in c (CVE-2026-64625). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64624 |
|
Vulnerability in freerdp (CVE-2026-64624)
vulnerability in freerdp (CVE-2026-64624). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57852 |
|
Vulnerability in CVE-2026-57852 (CVE-2026-57852)
vulnerability in CVE-2026-57852 (CVE-2026-57852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57495 |
|
Vulnerability in @agenticmail/core (CVE-2026-57495)
vulnerability in @agenticmail/core (CVE-2026-57495). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mail/inbound`. Mitigation: upgrade to `0.9.43` or later.
|
| CVE-2026-55550 |
|
Privilege Escalation in CVE-2026-55550 (CVE-2026-55550)
vulnerability in CVE-2026-55550 (CVE-2026-55550). Data can be tampered with by attackers. Exploitable via ``manager``.
|
| CVE-2026-55544 |
|
Vulnerability in CVE-2026-55544 (CVE-2026-55544)
vulnerability in CVE-2026-55544 (CVE-2026-55544). Data can be tampered with by attackers. Exploitable via ``nxtc__...``.
|
| CVE-2026-52656 |
|
Code Injection in CVE-2026-52656 (CVE-2026-52656)
code injection in CVE-2026-52656 (CVE-2026-52656). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51385 |
|
Code Injection in CVE-2026-51385 (CVE-2026-51385)
code injection in CVE-2026-51385 (CVE-2026-51385). Confidential information can be exposed externally.
|
| CVE-2026-51031 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51031)
SSRF in ssrf (CVE-2026-51031). Confidential information can be exposed externally.
|
| CVE-2026-51025 |
|
Cross-Site Scripting (XSS) in CVE-2026-51025 (CVE-2026-51025)
cross-site scripting in CVE-2026-51025 (CVE-2026-51025). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47134 |
|
Vulnerability in CVE-2026-47134 (CVE-2026-47134)
vulnerability in CVE-2026-47134 (CVE-2026-47134). Risk of unauthorized operations or information disclosure. Exploitable via ``SecKeyCreateRandomKey``.
|
| CVE-2026-47133 |
|
Vulnerability in CVE-2026-47133 (CVE-2026-47133)
vulnerability in CVE-2026-47133 (CVE-2026-47133). Risk of unauthorized operations or information disclosure. Exploitable via ``data_signatures``.
|
| CVE-2026-44510 |
|
Out-of-Bounds Read in CVE-2026-44510 (CVE-2026-44510)
vulnerability in CVE-2026-44510 (CVE-2026-44510). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16324 |
|
Vulnerability in CVE-2026-16324 (CVE-2026-16324)
vulnerability in CVE-2026-16324 (CVE-2026-16324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12900 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12900)
cross-site scripting in wordpress (CVE-2026-12900). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-51316 |
|
Vulnerability in dos (CVE-2024-51316)
vulnerability in dos (CVE-2024-51316). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-51315 |
|
Vulnerability in CVE-2024-51315 (CVE-2024-51315)
vulnerability in CVE-2024-51315 (CVE-2024-51315). Successful exploitation can lead to full system takeover.
|
| CVE-2024-51314 |
|
Vulnerability in CVE-2024-51314 (CVE-2024-51314)
vulnerability in CVE-2024-51314 (CVE-2024-51314). Successful exploitation can lead to full system takeover.
|
| CVE-2024-51312 |
|
Vulnerability in CVE-2024-51312 (CVE-2024-51312)
vulnerability in CVE-2024-51312 (CVE-2024-51312). Successful exploitation can lead to full system takeover.
|
| GHSA-94pj-82f3-465w |
|
Information Disclosure in guzzlehttp/guzzle (GHSA-94pj-82f3-465w)
vulnerability in guzzlehttp/guzzle (GHSA-94pj-82f3-465w). Risk of unauthorized operations or information disclosure. Exploitable via ``CurlHandler``. Mitigation: upgrade to `7.14.2` or later.
|
| CVE-2026-64651 |
|
Authorization Flaw in CVE-2026-64651 (CVE-2026-64651)
vulnerability in CVE-2026-64651 (CVE-2026-64651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64650 |
|
Authorization Flaw in CVE-2026-64650 (CVE-2026-64650)
vulnerability in CVE-2026-64650 (CVE-2026-64650). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58624 |
|
Vulnerability in apache (CVE-2026-58624)
vulnerability in apache (CVE-2026-58624). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56624 |
|
Vulnerability in apache (CVE-2026-56624)
vulnerability in apache (CVE-2026-56624). Confidential information can be exposed externally.
|
| CVE-2026-56623 |
|
Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
|
| CVE-2026-56452 |
|
Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
|
| CVE-2026-53596 |
|
Vulnerability in laravel (CVE-2026-53596)
vulnerability in laravel (CVE-2026-53596). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53595 |
|
Vulnerability in laravel (CVE-2026-53595)
vulnerability in laravel (CVE-2026-53595). Confidential information can be exposed externally. Exploitable via `POST /user-setup/{hash}/{invite_sent_at}`.
|
| CVE-2026-53594 |
|
Path Traversal in laravel (CVE-2026-53594)
path traversal in laravel (CVE-2026-53594). Confidential information can be exposed externally.
|
| CVE-2026-47130 |
|
Vulnerability in CVE-2026-47130 (CVE-2026-47130)
vulnerability in CVE-2026-47130 (CVE-2026-47130). Data can be tampered with by attackers. Exploitable via ``member``.
|
| CVE-2026-47129 |
|
Vulnerability in CVE-2026-47129 (CVE-2026-47129)
vulnerability in CVE-2026-47129 (CVE-2026-47129). Data can be tampered with by attackers. Exploitable via ``activateUser``.
|
| CVE-2026-44509 |
|
Vulnerability in CVE-2026-44509 (CVE-2026-44509)
vulnerability in CVE-2026-44509 (CVE-2026-44509). Confidential information can be exposed externally.
|
| CVE-2026-44508 |
|
Vulnerability in CVE-2026-44508 (CVE-2026-44508)
vulnerability in CVE-2026-44508 (CVE-2026-44508). Confidential information can be exposed externally.
|