Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-63087 |
|
Vulnerability in CVE-2026-63087 (CVE-2026-63087)
vulnerability in CVE-2026-63087 (CVE-2026-63087). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63086 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63086)
SSRF in ssrf (CVE-2026-63086). Confidential information can be exposed externally.
|
| CVE-2026-63085 |
|
Authorization Flaw in CVE-2026-63085 (CVE-2026-63085)
vulnerability in CVE-2026-63085 (CVE-2026-63085). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57074 |
|
Out-of-Bounds Read in CVE-2026-57074 (CVE-2026-57074)
vulnerability in CVE-2026-57074 (CVE-2026-57074). Confidential information can be exposed externally.
|
| CVE-2026-57073 |
|
Out-of-Bounds Read in CVE-2026-57073 (CVE-2026-57073)
vulnerability in CVE-2026-57073 (CVE-2026-57073). Confidential information can be exposed externally.
|
| CVE-2026-55548 |
|
Vulnerability in org.yamcs:yamcs-core (CVE-2026-55548)
vulnerability in org.yamcs:yamcs-core (CVE-2026-55548). Risk of unauthorized operations or information disclosure. Exploitable via ``PacketsApi.exportPackets``. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55407 |
|
Vulnerability in buffa (CVE-2026-55407)
vulnerability in buffa (CVE-2026-55407). Risk of unauthorized operations or information disclosure. Exploitable via ``decode_unknown_field``. Mitigation: upgrade to `0.8.0` or later.
|
| CVE-2026-55406 |
|
Information Disclosure in buffa (CVE-2026-55406)
vulnerability in buffa (CVE-2026-55406). Risk of unauthorized operations or information disclosure. Exploitable via ``buffa``. Mitigation: upgrade to `0.7.0` or later.
|
| CVE-2026-50012 |
|
Vulnerability in squid-cache (CVE-2026-50012)
vulnerability in squid-cache (CVE-2026-50012). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47729 |
|
Out-of-Bounds Read in squid-cache (CVE-2026-47729)
vulnerability in squid-cache (CVE-2026-47729). Confidential information can be exposed externally.
|
| CVE-2026-45795 |
|
Vulnerability in CVE-2026-45795 (CVE-2026-45795)
vulnerability in CVE-2026-45795 (CVE-2026-45795). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45612 |
|
Out-of-Bounds Read in c (CVE-2026-45612)
vulnerability in c (CVE-2026-45612). Confidential information can be exposed externally.
|
| CVE-2026-3031 |
|
Vulnerability in CVE-2026-3031 (CVE-2026-3031)
vulnerability in CVE-2026-3031 (CVE-2026-3031). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14371 |
|
OS Command Injection in CVE-2026-14371 (CVE-2026-14371)
OS command injection in CVE-2026-14371 (CVE-2026-14371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13401 |
|
Vulnerability in c (CVE-2026-13401)
vulnerability in c (CVE-2026-13401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13397 |
|
Vulnerability in c (CVE-2026-13397)
vulnerability in c (CVE-2026-13397). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13104 |
|
Vulnerability in CVE-2026-13104 (CVE-2026-13104)
vulnerability in CVE-2026-13104 (CVE-2026-13104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13103 |
|
Path Traversal in path-traversal (CVE-2026-13103)
path traversal in path-traversal (CVE-2026-13103). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10590 |
|
Vulnerability in CVE-2026-10590 (CVE-2026-10590)
vulnerability in CVE-2026-10590 (CVE-2026-10590). Data can be tampered with by attackers.
|
| CVE-2026-10589 |
|
Out-of-Bounds Write in CVE-2026-10589 (CVE-2026-10589)
out-of-bounds write in CVE-2026-10589 (CVE-2026-10589). Data can be tampered with by attackers.
|
| CVE-2026-10588 |
|
Vulnerability in CVE-2026-10588 (CVE-2026-10588)
vulnerability in CVE-2026-10588 (CVE-2026-10588). Confidential information can be exposed externally.
|
| CVE-2026-10587 |
|
Out-of-Bounds Write in CVE-2026-10587 (CVE-2026-10587)
out-of-bounds write in CVE-2026-10587 (CVE-2026-10587). Data can be tampered with by attackers.
|
| CVE-2025-45870 |
|
Path Traversal in path-traversal (CVE-2025-45870)
path traversal in path-traversal (CVE-2025-45870). Confidential information can be exposed externally.
|
| CVE-2026-63082 |
|
Vulnerability in CVE-2026-63082 (CVE-2026-63082)
vulnerability in CVE-2026-63082 (CVE-2026-63082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63081 |
|
Cross-Site Scripting (XSS) in CVE-2026-63081 (CVE-2026-63081)
cross-site scripting in CVE-2026-63081 (CVE-2026-63081). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59867 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867). Confidential information can be exposed externally. Exploitable via ``REMOTE_KIOTA_PROP``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-59866 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59866)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59866). Risk of unauthorized operations or information disclosure. Exploitable via ``clientClassName``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-59865 |
|
Code Injection in Microsoft.OpenApi.Kiota (CVE-2026-59865)
code injection in Microsoft.OpenApi.Kiota (CVE-2026-59865). Risk of unauthorized operations or information disclosure. Exploitable via ``dependencyInstallCommand``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-59864 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59864). Risk of unauthorized operations or information disclosure. Exploitable via ``static_template.file``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-57206 |
|
Vulnerability in CVE-2026-57206 (CVE-2026-57206)
vulnerability in CVE-2026-57206 (CVE-2026-57206). Data can be tampered with by attackers. Exploitable via `POST /api/admin/plugins/test-instantiation`.
|
| CVE-2026-57205 |
|
Information Disclosure in CVE-2026-57205 (CVE-2026-57205)
vulnerability in CVE-2026-57205 (CVE-2026-57205). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/user/info/`.
|
| CVE-2026-55440 |
|
Vulnerability in CVE-2026-55440 (CVE-2026-55440)
vulnerability in CVE-2026-55440 (CVE-2026-55440). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54733 |
|
Vulnerability in CVE-2026-54733 (CVE-2026-54733)
vulnerability in CVE-2026-54733 (CVE-2026-54733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54568 |
|
Vulnerability in CVE-2026-54568 (CVE-2026-54568)
vulnerability in CVE-2026-54568 (CVE-2026-54568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53598 |
|
Path Traversal in prompty (CVE-2026-53598)
path traversal in prompty (CVE-2026-53598). Confidential information can be exposed externally. Exploitable via ``prompty``. Mitigation: upgrade to `2.0.0b2` or later.
|
| CVE-2026-53597 |
|
Code Injection in @prompty/core (CVE-2026-53597)
code injection in @prompty/core (CVE-2026-53597). Risk of unauthorized operations or information disclosure. Exploitable via ``javascript``. Mitigation: upgrade to `2.0.0-beta.3` or later.
|
| CVE-2026-14890 |
|
Unsafe Deserialization in deserialization (CVE-2026-14890)
vulnerability in deserialization (CVE-2026-14890). Confidential information can be exposed externally.
|
| CVE-2026-12379 |
|
Open Redirect in CVE-2026-12379 (CVE-2026-12379)
vulnerability in CVE-2026-12379 (CVE-2026-12379). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-45868 |
|
SQL Injection in sqli (CVE-2025-45868)
SQL injection in sqli (CVE-2025-45868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15352 |
|
Vulnerability in cisa (CVE-2026-15352)
vulnerability in cisa (CVE-2026-15352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56456 |
|
Information Disclosure in hcltech (CVE-2026-56456)
vulnerability in hcltech (CVE-2026-56456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59237 |
|
Vulnerability in CVE-2026-59237 (CVE-2026-59237)
vulnerability in CVE-2026-59237 (CVE-2026-59237). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/order/{id}`.
|
| CVE-2026-35145 |
|
Information Disclosure in hcltech (CVE-2026-35145)
vulnerability in hcltech (CVE-2026-35145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56454 |
|
Vulnerability in hcltech (CVE-2026-56454)
vulnerability in hcltech (CVE-2026-56454). Confidential information can be exposed externally.
|
| CVE-2026-56453 |
|
Vulnerability in hcltech (CVE-2026-56453)
vulnerability in hcltech (CVE-2026-56453). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56455 |
|
Vulnerability in dos (CVE-2026-56455)
vulnerability in dos (CVE-2026-56455). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5674 |
|
Vulnerability in CVE-2026-5674 (CVE-2026-5674)
vulnerability in CVE-2026-5674 (CVE-2026-5674). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14254 |
|
Vulnerability in CVE-2026-14254 (CVE-2026-14254)
vulnerability in CVE-2026-14254 (CVE-2026-14254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35142 |
|
Information Disclosure in hcltech (CVE-2026-35142)
vulnerability in hcltech (CVE-2026-35142). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63306 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63306 (CVE-2026-63306)
SSRF in CVE-2026-63306 (CVE-2026-63306). Confidential information can be exposed externally.
|