Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-32823 |
|
Cross-Site Request Forgery (CSRF) in rails (CVE-2026-32823)
vulnerability in rails (CVE-2026-32823). Risk of unauthorized operations or information disclosure. Exploitable via ``GET``.
|
| CVE-2026-32821 |
|
Vulnerability in CVE-2026-32821 (CVE-2026-32821)
vulnerability in CVE-2026-32821 (CVE-2026-32821). Confidential information can be exposed externally. Exploitable via ``user_email``.
|
| CVE-2026-32820 |
|
Path Traversal in rails (CVE-2026-32820)
path traversal in rails (CVE-2026-32820). Confidential information can be exposed externally. Exploitable via ``docs``.
|
| CVE-2026-32819 |
|
Vulnerability in CVE-2026-32819 (CVE-2026-32819)
vulnerability in CVE-2026-32819 (CVE-2026-32819). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32806 |
|
Vulnerability in CVE-2026-32806 (CVE-2026-32806)
vulnerability in CVE-2026-32806 (CVE-2026-32806). Confidential information can be exposed externally. Mitigation: upgrade to `26.06.08` or later.
|
| CVE-2026-16312 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-6793 |
|
Cross-Site Scripting (XSS) in CVE-2026-6793 (CVE-2026-6793)
cross-site scripting in CVE-2026-6793 (CVE-2026-6793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63429 |
|
Vulnerability in CVE-2026-63429 (CVE-2026-63429)
vulnerability in CVE-2026-63429 (CVE-2026-63429). Data can be tampered with by attackers. Exploitable via `POST /api/upload`.
|
| CVE-2026-63428 |
|
Vulnerability in CVE-2026-63428 (CVE-2026-63428)
vulnerability in CVE-2026-63428 (CVE-2026-63428). Risk of unauthorized operations or information disclosure. Exploitable via ``completeSubmission``.
|
| CVE-2026-63102 |
|
Vulnerability in privilege-escalation (CVE-2026-63102)
vulnerability in privilege-escalation (CVE-2026-63102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51027 |
|
Information Disclosure in CVE-2026-51027 (CVE-2026-51027)
vulnerability in CVE-2026-51027 (CVE-2026-51027). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51026 |
|
Vulnerability in path-traversal (CVE-2026-51026)
vulnerability in path-traversal (CVE-2026-51026). Confidential information can be exposed externally.
|
| CVE-2026-46428 |
|
Vulnerability in lettre (CVE-2026-46428)
vulnerability in lettre (CVE-2026-46428). Risk of unauthorized operations or information disclosure. Exploitable via ``rustls``. Mitigation: upgrade to `0.11.22` or later.
|
| CVE-2026-45797 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-45797)
cross-site scripting in express (CVE-2026-45797). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35198 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2026-35198)
cross-site scripting in privilege-escalation (CVE-2026-35198). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32822 |
|
Vulnerability in CVE-2026-32822 (CVE-2026-32822)
vulnerability in CVE-2026-32822 (CVE-2026-32822). Risk of unauthorized operations or information disclosure. Exploitable via ``innerHTML``.
|
| CVE-2026-32807 |
|
Vulnerability in CVE-2026-32807 (CVE-2026-32807)
vulnerability in CVE-2026-32807 (CVE-2026-32807). Confidential information can be exposed externally.
|
| CVE-2026-28220 |
|
Unsafe Deserialization in wazuh (CVE-2026-28220)
vulnerability in wazuh (CVE-2026-28220). Successful exploitation can lead to full system takeover. Exploitable via ``ALLOWED_CALLABLES_PACKAGES``.
|
| CVE-2026-26199 |
|
Vulnerability in hdfgroup (CVE-2026-26199)
vulnerability in hdfgroup (CVE-2026-26199). Risk of unauthorized operations or information disclosure. Exploitable via ``H5Iget_name``.
|
| CVE-2026-26197 |
|
Out-of-Bounds Read in hdfgroup (CVE-2026-26197)
vulnerability in hdfgroup (CVE-2026-26197). Confidential information can be exposed externally.
|
| CVE-2026-26081 |
|
Vulnerability in haproxy (CVE-2026-26081)
vulnerability in haproxy (CVE-2026-26081). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26080 |
|
Vulnerability in haproxy (CVE-2026-26080)
vulnerability in haproxy (CVE-2026-26080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25039 |
|
Vulnerability in CVE-2026-25039 (CVE-2026-25039)
vulnerability in CVE-2026-25039 (CVE-2026-25039). Successful exploitation can lead to full system takeover. Exploitable via ``NTLM``.
|
| CVE-2026-21824 |
|
Vulnerability in privilege-escalation (CVE-2026-21824)
vulnerability in privilege-escalation (CVE-2026-21824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13724 |
|
Vulnerability in CVE-2026-13724 (CVE-2026-13724)
vulnerability in CVE-2026-13724 (CVE-2026-13724). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63090 |
|
Vulnerability in c (CVE-2026-63090)
vulnerability in c (CVE-2026-63090). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63091 |
|
Vulnerability in proftpd (CVE-2026-63091)
vulnerability in proftpd (CVE-2026-63091). Confidential information can be exposed externally.
|
| CVE-2026-59238 |
|
Cross-Site Scripting (XSS) in CVE-2026-59238 (CVE-2026-59238)
cross-site scripting in CVE-2026-59238 (CVE-2026-59238). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52349 |
|
Path Traversal in path-traversal (CVE-2026-52349)
path traversal in path-traversal (CVE-2026-52349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53421 |
|
Vulnerability in apache (CVE-2026-53421)
vulnerability in apache (CVE-2026-53421). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62183 |
|
Privilege Escalation in apache (CVE-2026-62183)
vulnerability in apache (CVE-2026-62183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63071 |
|
Vulnerability in apache (CVE-2026-63071)
vulnerability in apache (CVE-2026-63071). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62418 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-62418)
SSRF in apache (CVE-2026-62418). Confidential information can be exposed externally.
|
| CVE-2026-57308 |
|
SQL Injection in apache (CVE-2026-57308)
SQL injection in apache (CVE-2026-57308). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16277 |
|
Vulnerability in dos (CVE-2026-16277)
vulnerability in dos (CVE-2026-16277). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53405 |
|
Vulnerability in apache (CVE-2026-53405)
vulnerability in apache (CVE-2026-53405). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16252 |
|
Vulnerability in sqli (CVE-2026-16252)
vulnerability in sqli (CVE-2026-16252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51386 |
|
Vulnerability in CVE-2026-51386 (CVE-2026-51386)
vulnerability in CVE-2026-51386 (CVE-2026-51386). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12701 |
|
Path Traversal in path-traversal (CVE-2026-12701)
path traversal in path-traversal (CVE-2026-12701). Data can be tampered with by attackers.
|
| CVE-2026-57311 |
|
Unrestricted File Upload in CVE-2026-57311 (CVE-2026-57311)
vulnerability in CVE-2026-57311 (CVE-2026-57311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57310 |
|
Vulnerability in CVE-2026-57310 (CVE-2026-57310)
vulnerability in CVE-2026-57310 (CVE-2026-57310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57309 |
|
SQL Injection in sqli (CVE-2026-57309)
SQL injection in sqli (CVE-2026-57309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16248 |
|
Buffer Overflow in CVE-2026-16248 (CVE-2026-16248)
vulnerability in CVE-2026-16248 (CVE-2026-16248). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16244 |
|
Vulnerability in sqli (CVE-2026-16244)
vulnerability in sqli (CVE-2026-16244). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12080 |
|
Vulnerability in CVE-2026-12080 (CVE-2026-12080)
vulnerability in CVE-2026-12080 (CVE-2026-12080). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54910 |
|
Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
|
| CVE-2026-46516 |
|
Cross-Site Scripting (XSS) in CVE-2026-46516 (CVE-2026-46516)
cross-site scripting in CVE-2026-46516 (CVE-2026-46516). Risk of unauthorized operations or information disclosure. Exploitable via ``formatMarkdown``.
|
| CVE-2026-64623 |
|
Vulnerability in CVE-2026-64623 (CVE-2026-64623)
vulnerability in CVE-2026-64623 (CVE-2026-64623). Data can be tampered with by attackers.
|
| CVE-2026-64621 |
|
Vulnerability in c (CVE-2026-64621)
vulnerability in c (CVE-2026-64621). Data can be tampered with by attackers.
|
| CVE-2026-63762 |
|
Vulnerability in dos (CVE-2026-63762)
vulnerability in dos (CVE-2026-63762). Risk of unauthorized operations or information disclosure.
|