Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16082 |
|
Vulnerability in CVE-2026-16082 (CVE-2026-16082)
vulnerability in CVE-2026-16082 (CVE-2026-16082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47867 |
|
Code Injection in broadcom (CVE-2026-47867)
code injection in broadcom (CVE-2026-47867). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
|
| CVE-2026-16083 |
|
Authentication Bypass in CVE-2026-16083 (CVE-2026-16083)
authentication bypass in CVE-2026-16083 (CVE-2026-16083). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16081 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-16081 (CVE-2026-16081)
vulnerability in CVE-2026-16081 (CVE-2026-16081). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16077 |
|
Vulnerability in CVE-2026-16077 (CVE-2026-16077)
vulnerability in CVE-2026-16077 (CVE-2026-16077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16076 |
|
Authentication Bypass in CVE-2026-16076 (CVE-2026-16076)
authentication bypass in CVE-2026-16076 (CVE-2026-16076). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9734 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-9734)
vulnerability in wordpress (CVE-2026-9734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16075 |
|
Vulnerability in CVE-2026-16075 (CVE-2026-16075)
vulnerability in CVE-2026-16075 (CVE-2026-16075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57980 |
|
Vulnerability in microsoft (CVE-2026-57980)
vulnerability in microsoft (CVE-2026-57980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56741 |
|
Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741). Risk of unauthorized operations or information disclosure. Exploitable via ``Telnet``. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2026-56740 |
|
Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56740). Risk of unauthorized operations or information disclosure. Exploitable via ``HashMap``. Mitigation: upgrade to `4.2.1` or later.
|
| CVE-2026-56171 |
|
Vulnerability in microsoft (CVE-2026-56171)
vulnerability in microsoft (CVE-2026-56171). Confidential information can be exposed externally.
|
| GHSA-8qqm-fp2q-v734 |
|
Vulnerability in github.com/zalando/skipper (GHSA-8qqm-fp2q-v734)
vulnerability in github.com/zalando/skipper (GHSA-8qqm-fp2q-v734). Risk of unauthorized operations or information disclosure. Exploitable via ``parsed_body``. Mitigation: upgrade to `0.27.26` or later.
|
| CVE-2026-54246 |
|
Vulnerability in github.com/zalando/skipper (CVE-2026-54246)
vulnerability in github.com/zalando/skipper (CVE-2026-54246). Risk of unauthorized operations or information disclosure. Exploitable via `GET /routes`. Mitigation: upgrade to `0.27.13` or later.
|
| CVE-2026-55177 |
|
SSRF (Server-Side Request Forgery) in @tak-ps/cloudtak (CVE-2026-55177)
SSRF in @tak-ps/cloudtak (CVE-2026-55177). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/esri`. Mitigation: upgrade to `13.10.0` or later.
|
| CVE-2026-52348 |
|
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
|
| CVE-2026-52203 |
|
Information Disclosure in CVE-2026-52203 (CVE-2026-52203)
vulnerability in CVE-2026-52203 (CVE-2026-52203). Confidential information can be exposed externally.
|
| CVE-2026-52584 |
|
Vulnerability in CVE-2026-52584 (CVE-2026-52584)
vulnerability in CVE-2026-52584 (CVE-2026-52584). Confidential information can be exposed externally.
|
| CVE-2026-16074 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-16074 (CVE-2026-16074)
SSRF in CVE-2026-16074 (CVE-2026-16074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13446 |
|
Vulnerability in langflow (CVE-2026-13446)
vulnerability in langflow (CVE-2026-13446). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13445 |
|
Vulnerability in langflow (CVE-2026-13445)
vulnerability in langflow (CVE-2026-13445). Confidential information can be exposed externally.
|
| CVE-2026-54559 |
|
Buffer Overflow in pocketsphinx (CVE-2026-54559)
vulnerability in pocketsphinx (CVE-2026-54559). Risk of unauthorized operations or information disclosure. Exploitable via ``sscanf``. Mitigation: upgrade to `5.1.1` or later.
|
| CVE-2026-54570 |
|
Vulnerability in AngleSharp (CVE-2026-54570)
vulnerability in AngleSharp (CVE-2026-54570). Data can be tampered with by attackers. Exploitable via ``MathAnnotationXmlElement``. Mitigation: upgrade to `1.5.0` or later.
|
| GHSA-mfr4-mq8w-vmg6 |
|
Path Traversal in proot-distro (GHSA-mfr4-mq8w-vmg6)
path traversal in proot-distro (GHSA-mfr4-mq8w-vmg6). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.1.0` or later.
|
| CVE-2026-53496 |
|
Vulnerability in exifreader (CVE-2026-53496)
vulnerability in exifreader (CVE-2026-53496). Risk of unauthorized operations or information disclosure. Exploitable via ``ftyp``. Mitigation: upgrade to `4.40.1` or later.
|
| CVE-2026-8861 |
|
Vulnerability in ibm (CVE-2026-8861)
vulnerability in ibm (CVE-2026-8861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8859 |
|
Path Traversal in path-traversal (CVE-2026-8859)
path traversal in path-traversal (CVE-2026-8859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8635 |
|
Code Injection in c (CVE-2026-8635)
code injection in c (CVE-2026-8635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8505 |
|
Vulnerability in langflow (CVE-2026-8505)
vulnerability in langflow (CVE-2026-8505). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8481 |
|
Code Injection in c (CVE-2026-8481)
code injection in c (CVE-2026-8481). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/validate/code`.
|
| CVE-2026-8476 |
|
Unsafe Deserialization in langflow (CVE-2026-8476)
vulnerability in langflow (CVE-2026-8476). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8056 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
|
| CVE-2026-7872 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
|
| CVE-2026-7771 |
|
Vulnerability in dos (CVE-2026-7771)
vulnerability in dos (CVE-2026-7771). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7755 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
|
| CVE-2026-7754 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
|
| CVE-2026-7667 |
|
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
|
| CVE-2026-7364 |
|
Open Redirect in ibm (CVE-2026-7364)
vulnerability in ibm (CVE-2026-7364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63030 KEV |
|
WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
|
| CVE-2026-60137 KEV |
|
[KEV] SQL Injection in Wordpress sqli (CVE-2026-60137)
SQL injection in Wordpress sqli (CVE-2026-60137). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-52199 |
|
Command Injection in CVE-2026-52199 (CVE-2026-52199)
command injection in CVE-2026-52199 (CVE-2026-52199). Confidential information can be exposed externally.
|
| CVE-2026-51833 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51833)
SSRF in ssrf (CVE-2026-51833). Confidential information can be exposed externally.
|
| CVE-2026-4942 |
|
Vulnerability in ibm (CVE-2026-4942)
vulnerability in ibm (CVE-2026-4942). Confidential information can be exposed externally.
|
| CVE-2026-4938 |
|
Authorization Flaw in ibm (CVE-2026-4938)
vulnerability in ibm (CVE-2026-4938). Data can be tampered with by attackers.
|
| CVE-2026-48373 |
|
Vulnerability in adobe (CVE-2026-48373)
vulnerability in adobe (CVE-2026-48373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43636 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-42168 |
|
OS Command Injection in django (CVE-2026-42168)
OS command injection in django (CVE-2026-42168). Confidential information can be exposed externally.
|
| CVE-2026-36669 |
|
Unrestricted File Upload in CVE-2026-36669 (CVE-2026-36669)
vulnerability in CVE-2026-36669 (CVE-2026-36669). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16118 |
|
Vulnerability in c (CVE-2026-16118)
vulnerability in c (CVE-2026-16118). Data can be tampered with by attackers.
|
| CVE-2026-15995 |
|
Vulnerability in ibm (CVE-2026-15995)
vulnerability in ibm (CVE-2026-15995). Risk of unauthorized operations or information disclosure.
|