Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44507 |
|
Authorization Flaw in CVE-2026-44507 (CVE-2026-44507)
vulnerability in CVE-2026-44507 (CVE-2026-44507). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13381 |
|
Vulnerability in vsee (CVE-2026-13381)
vulnerability in vsee (CVE-2026-13381). Confidential information can be exposed externally.
|
| CVE-2026-13380 |
|
Vulnerability in vsee (CVE-2026-13380)
vulnerability in vsee (CVE-2026-13380). Confidential information can be exposed externally.
|
| CVE-2024-51313 |
|
Vulnerability in CVE-2024-51313 (CVE-2024-51313)
vulnerability in CVE-2024-51313 (CVE-2024-51313). Successful exploitation can lead to full system takeover.
|
| CVE-2024-51311 |
|
Vulnerability in CVE-2024-51311 (CVE-2024-51311)
vulnerability in CVE-2024-51311 (CVE-2024-51311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73422 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-73422)
cross-site scripting in astro (CVE-2026-73422). Risk of unauthorized operations or information disclosure. Exploitable via ``duration``. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-63767 |
|
Unsafe Deserialization in deserialization (CVE-2026-63767)
vulnerability in deserialization (CVE-2026-63767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63766 |
|
OS Command Injection in CVE-2026-63766 (CVE-2026-63766)
OS command injection in CVE-2026-63766 (CVE-2026-63766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53593 |
|
Unrestricted File Upload in laravel (CVE-2026-53593)
vulnerability in laravel (CVE-2026-53593). Successful exploitation can lead to full system takeover. Exploitable via `POST /uploads/upload`.
|
| CVE-2026-53592 |
|
Vulnerability in laravel (CVE-2026-53592)
vulnerability in laravel (CVE-2026-53592). Risk of unauthorized operations or information disclosure. Exploitable via ``getQueryParam``.
|
| CVE-2026-53591 |
|
Authentication Bypass in laravel (CVE-2026-53591)
authentication bypass in laravel (CVE-2026-53591). Data can be tampered with by attackers. Exploitable via ``last_reply_from``.
|
| CVE-2026-44231 |
|
Information Disclosure in privilege-escalation (CVE-2026-44231)
vulnerability in privilege-escalation (CVE-2026-44231). Confidential information can be exposed externally.
|
| CVE-2026-44230 |
|
Cross-Site Scripting (XSS) in bestpractical (CVE-2026-44230)
cross-site scripting in bestpractical (CVE-2026-44230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44229 |
|
Cross-Site Scripting (XSS) in bestpractical (CVE-2026-44229)
cross-site scripting in bestpractical (CVE-2026-44229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16337 |
|
Privilege Escalation in CVE-2026-16337 (CVE-2026-16337)
vulnerability in CVE-2026-16337 (CVE-2026-16337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15788 |
|
Vulnerability in mobyproject (CVE-2026-15788)
vulnerability in mobyproject (CVE-2026-15788). Confidential information can be exposed externally.
|
| CVE-2026-64619 |
|
Vulnerability in CVE-2026-64619 (CVE-2026-64619)
vulnerability in CVE-2026-64619 (CVE-2026-64619). Confidential information can be exposed externally.
|
| CVE-2026-64194 |
|
Vulnerability in c (CVE-2026-64194)
vulnerability in c (CVE-2026-64194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64193 |
|
Vulnerability in CVE-2026-64193 (CVE-2026-64193)
vulnerability in CVE-2026-64193 (CVE-2026-64193). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63771 |
|
Vulnerability in CVE-2026-63771 (CVE-2026-63771)
vulnerability in CVE-2026-63771 (CVE-2026-63771). Confidential information can be exposed externally.
|
| CVE-2026-63770 |
|
Vulnerability in CVE-2026-63770 (CVE-2026-63770)
vulnerability in CVE-2026-63770 (CVE-2026-63770). Confidential information can be exposed externally.
|
| CVE-2026-63769 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-63769)
SSRF in c (CVE-2026-63769). Confidential information can be exposed externally.
|
| CVE-2026-63768 |
|
Open Redirect in CVE-2026-63768 (CVE-2026-63768)
vulnerability in CVE-2026-63768 (CVE-2026-63768). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63731 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63731 (CVE-2026-63731)
SSRF in CVE-2026-63731 (CVE-2026-63731). Confidential information can be exposed externally.
|
| CVE-2026-63730 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63730 (CVE-2026-63730)
SSRF in CVE-2026-63730 (CVE-2026-63730). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63108 |
|
Vulnerability in CVE-2026-63108 (CVE-2026-63108)
vulnerability in CVE-2026-63108 (CVE-2026-63108). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63107 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63107 (CVE-2026-63107)
SSRF in CVE-2026-63107 (CVE-2026-63107). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| CVE-2026-62414 |
|
Vulnerability in CVE-2026-62414 (CVE-2026-62414)
vulnerability in CVE-2026-62414 (CVE-2026-62414). Confidential information can be exposed externally.
|
| CVE-2026-61901 |
|
The Joomla extension Hikashop is vulnerable to an open redirect.
The Joomla extension Hikashop is vulnerable to an open redirect.
|
| CVE-2026-61900 |
|
Unrestricted File Upload in CVE-2026-61900 (CVE-2026-61900)
vulnerability in CVE-2026-61900 (CVE-2026-61900). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61425 |
|
Vulnerability in CVE-2026-61425 (CVE-2026-61425)
vulnerability in CVE-2026-61425 (CVE-2026-61425). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61424 |
|
Unrestricted File Upload in CVE-2026-61424 (CVE-2026-61424)
vulnerability in CVE-2026-61424 (CVE-2026-61424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60034 |
|
Cross-Site Scripting (XSS) in CVE-2026-60034 (CVE-2026-60034)
cross-site scripting in CVE-2026-60034 (CVE-2026-60034). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60033 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-60033)
SSRF in ssrf (CVE-2026-60033). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60032 |
|
Unrestricted File Upload in CVE-2026-60032 (CVE-2026-60032)
vulnerability in CVE-2026-60032 (CVE-2026-60032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60031 |
|
Information Disclosure in CVE-2026-60031 (CVE-2026-60031)
vulnerability in CVE-2026-60031 (CVE-2026-60031). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60030 |
|
Vulnerability in CVE-2026-60030 (CVE-2026-60030)
vulnerability in CVE-2026-60030 (CVE-2026-60030). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60029 |
|
Cross-Site Scripting (XSS) in CVE-2026-60029 (CVE-2026-60029)
cross-site scripting in CVE-2026-60029 (CVE-2026-60029). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60028 |
|
Cross-Site Scripting (XSS) in CVE-2026-60028 (CVE-2026-60028)
cross-site scripting in CVE-2026-60028 (CVE-2026-60028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60027 |
|
Path Traversal in path-traversal (CVE-2026-60027)
path traversal in path-traversal (CVE-2026-60027). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60026 |
|
Code Injection in CVE-2026-60026 (CVE-2026-60026)
code injection in CVE-2026-60026 (CVE-2026-60026). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48389 |
|
Vulnerability in adobe (CVE-2026-48389)
vulnerability in adobe (CVE-2026-48389). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12341 |
|
Authentication Bypass in sailpoint (CVE-2026-12341)
authentication bypass in sailpoint (CVE-2026-12341). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28231 |
|
Out-of-Bounds Read in pi-heif (CVE-2026-28231)
vulnerability in pi-heif (CVE-2026-28231). Risk of unauthorized operations or information disclosure. Exploitable via ``_pillow_heif.c``. Mitigation: upgrade to `1.3.0` or later.
|
| CVE-2026-25527 |
|
Path Traversal in changedetection.io (CVE-2026-25527)
path traversal in changedetection.io (CVE-2026-25527). Risk of unauthorized operations or information disclosure. Exploitable via ``flask_app.py``. Mitigation: upgrade to `0.53.2` or later.
|
| CVE-2025-67726 |
|
Vulnerability in tornado (CVE-2025-67726)
vulnerability in tornado (CVE-2025-67726). Risk of unauthorized operations or information disclosure. Exploitable via ``_parseparam``. Mitigation: upgrade to `6.5.3` or later.
|
| CVE-2025-67725 |
|
Vulnerability in tornado (CVE-2025-67725)
vulnerability in tornado (CVE-2025-67725). Risk of unauthorized operations or information disclosure. Exploitable via ``HTTPHeaders.add``. Mitigation: upgrade to `6.5.3` or later.
|
| CVE-2025-67724 |
|
Cross-Site Scripting (XSS) in tornado (CVE-2025-67724)
cross-site scripting in tornado (CVE-2025-67724). Risk of unauthorized operations or information disclosure. Exploitable via ``reason``. Mitigation: upgrade to `6.5.3` or later.
|
| CVE-2026-8170 |
|
Vulnerability in CVE-2026-8170 (CVE-2026-8170)
vulnerability in CVE-2026-8170 (CVE-2026-8170). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64612 |
|
Vulnerability in dos (CVE-2026-64612)
vulnerability in dos (CVE-2026-64612). Risk of unauthorized operations or information disclosure.
|