Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-55576 OS Command Injection in CVE-2026-55576 (CVE-2026-55576)
OS command injection in CVE-2026-55576 (CVE-2026-55576). Risk of unauthorized operations or information disclosure.
CVE-2026-55445 Authentication Bypass in @whyour/qinglong (CVE-2026-55445)
authentication bypass in @whyour/qinglong (CVE-2026-55445). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /open/user/init`. Mitigation: upgrade to `2.20.1` or later.
CVE-2026-55234 Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize ag...
Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update modifier. Any authen...
CVE-2026-53447 Vulnerability in CVE-2026-53447 (CVE-2026-53447)
vulnerability in CVE-2026-53447 (CVE-2026-53447). Confidential information can be exposed externally.
CVE-2026-53446 SSRF (Server-Side Request Forgery) in CVE-2026-53446 (CVE-2026-53446)
SSRF in CVE-2026-53446 (CVE-2026-53446). Risk of unauthorized operations or information disclosure.
CVE-2026-53445 Vulnerability in CVE-2026-53445 (CVE-2026-53445)
vulnerability in CVE-2026-53445 (CVE-2026-53445). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/boards/`.
CVE-2026-53444 Privilege Escalation in CVE-2026-53444 (CVE-2026-53444)
vulnerability in CVE-2026-53444 (CVE-2026-53444). Risk of unauthorized operations or information disclosure.
CVE-2026-52893 Authentication Bypass in CVE-2026-52893 (CVE-2026-52893)
authentication bypass in CVE-2026-52893 (CVE-2026-52893). Risk of unauthorized operations or information disclosure.
CVE-2026-52892 Vulnerability in CVE-2026-52892 (CVE-2026-52892)
vulnerability in CVE-2026-52892 (CVE-2026-52892). Data can be tampered with by attackers.
CVE-2026-52891 OS Command Injection in CVE-2026-52891 (CVE-2026-52891)
OS command injection in CVE-2026-52891 (CVE-2026-52891). Successful exploitation can lead to full system takeover.
CVE-2026-52890 Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled...
Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.path and versions.original.storage fields. The server/permissions/attachments.js...
CVE-2026-45313 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and...
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the thread belongs to the...
CVE-2026-38974 Vulnerability in CVE-2026-38974 (CVE-2026-38974)
vulnerability in CVE-2026-38974 (CVE-2026-38974). Risk of unauthorized operations or information disclosure.
CVE-2026-38755 Vulnerability in c (CVE-2026-38755)
vulnerability in c (CVE-2026-38755). Risk of unauthorized operations or information disclosure.
CVE-2026-38754 Out-of-Bounds Read in c (CVE-2026-38754)
vulnerability in c (CVE-2026-38754). Risk of unauthorized operations or information disclosure.
CVE-2026-38752 Vulnerability in c (CVE-2026-38752)
vulnerability in c (CVE-2026-38752). Risk of unauthorized operations or information disclosure.
CVE-2026-36590 Vulnerability in c (CVE-2026-36590)
vulnerability in c (CVE-2026-36590). Risk of unauthorized operations or information disclosure.
CVE-2026-30623 Command Injection in c (CVE-2026-30623)
command injection in c (CVE-2026-30623). Successful exploitation can lead to full system takeover.
CVE-2026-30618 Code Injection in CVE-2026-30618 (CVE-2026-30618)
code injection in CVE-2026-30618 (CVE-2026-30618). Successful exploitation can lead to full system takeover.
CVE-2026-26719 Cross-Site Scripting (XSS) in CVE-2026-26719 (CVE-2026-26719)
cross-site scripting in CVE-2026-26719 (CVE-2026-26719). Risk of unauthorized operations or information disclosure.
CVE-2026-26718 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-26718)
vulnerability in csrf (CVE-2026-26718). Confidential information can be exposed externally.
CVE-2026-15921 Path Traversal in CVE-2026-15921 (CVE-2026-15921)
path traversal in CVE-2026-15921 (CVE-2026-15921). Risk of unauthorized operations or information disclosure. Exploitable via ``index.tab``.
CVE-2025-65720 Command Injection in CVE-2025-65720 (CVE-2025-65720)
command injection in CVE-2025-65720 (CVE-2025-65720). Successful exploitation can lead to full system takeover.
CVE-2026-54490 Vulnerability in websocket-driver (CVE-2026-54490)
vulnerability in websocket-driver (CVE-2026-54490). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.7.5` or later.
CVE-2026-54466 Vulnerability in websocket-driver (CVE-2026-54466)
vulnerability in websocket-driver (CVE-2026-54466). Data can be tampered with by attackers. Mitigation: upgrade to `0.7.5` or later.
CVE-2026-54465 Vulnerability in websocket-driver (CVE-2026-54465)
vulnerability in websocket-driver (CVE-2026-54465). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.1` or later.
CVE-2026-54464 Vulnerability in websocket-driver (CVE-2026-54464)
vulnerability in websocket-driver (CVE-2026-54464). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.1` or later.
CVE-2026-54463 Vulnerability in websocket-driver (CVE-2026-54463)
vulnerability in websocket-driver (CVE-2026-54463). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.8.1` or later.
CVE-2026-54254 Vulnerability in cyberdrop-dl-patched (CVE-2026-54254)
vulnerability in cyberdrop-dl-patched (CVE-2026-54254). Risk of unauthorized operations or information disclosure. Exploitable via ``Authorization``. Mitigation: upgrade to `9.14.0` or later.
CVE-2026-54457 Vulnerability in tensorzero (CVE-2026-54457)
vulnerability in tensorzero (CVE-2026-54457). Confidential information can be exposed externally. Exploitable via ``storage_path``. Mitigation: upgrade to `2026.6.0` or later.
CVE-2026-54452 SSRF (Server-Side Request Forgery) in github.com/doyensec/safeurl (CVE-2026-54452)
SSRF in github.com/doyensec/safeurl (CVE-2026-54452). Risk of unauthorized operations or information disclosure. Exploitable via ``privateNetworks``. Mitigation: upgrade to `0.2.4` or later.
CVE-2026-53656 Vulnerability in fiftyone (CVE-2026-53656)
vulnerability in fiftyone (CVE-2026-53656). Confidential information can be exposed externally. Exploitable via ``allowed_origins``. Mitigation: upgrade to `1.17.0` or later.
GHSA-62gx-5q78-wrvx Path Traversal in obsidian-local-rest-api (GHSA-62gx-5q78-wrvx)
path traversal in obsidian-local-rest-api (GHSA-62gx-5q78-wrvx). Risk of unauthorized operations or information disclosure. Exploitable via ``decodeURIComponent``.
CVE-2026-54450 SSRF (Server-Side Request Forgery) in github.com/stacklok/toolhive (CVE-2026-54450)
SSRF in github.com/stacklok/toolhive (CVE-2026-54450). Risk of unauthorized operations or information disclosure. Exploitable via ``networking.IsPrivateIP``. Mitigation: upgrade to `0.29.1` or later.
CVE-2026-55399 Vulnerability in dos (CVE-2026-55399)
vulnerability in dos (CVE-2026-55399). Risk of unauthorized operations or information disclosure.
CVE-2026-51380 Vulnerability in dos (CVE-2026-51380)
vulnerability in dos (CVE-2026-51380). Successful exploitation can lead to full system takeover.
CVE-2026-55398 Buffer Overflow in dos (CVE-2026-55398)
vulnerability in dos (CVE-2026-55398). Risk of unauthorized operations or information disclosure.
CVE-2026-38753 Use-After-Free in c (CVE-2026-38753)
vulnerability in c (CVE-2026-38753). Risk of unauthorized operations or information disclosure.
CVE-2026-33445 Vulnerability in dos (CVE-2026-33445)
vulnerability in dos (CVE-2026-33445). Risk of unauthorized operations or information disclosure.
CVE-2026-33444 Buffer Overflow in dos (CVE-2026-33444)
vulnerability in dos (CVE-2026-33444). Risk of unauthorized operations or information disclosure.
CVE-2026-40957 Vulnerability in absolute (CVE-2026-40957)
vulnerability in absolute (CVE-2026-40957). Confidential information can be exposed externally.
CVE-2026-40955 Vulnerability in dos (CVE-2026-40955)
vulnerability in dos (CVE-2026-40955). Risk of unauthorized operations or information disclosure.
CVE-2026-40952 Vulnerability in absolute (CVE-2026-40952)
vulnerability in absolute (CVE-2026-40952). Successful exploitation can lead to full system takeover.
CVE-2026-40956 Information Disclosure in absolute (CVE-2026-40956)
vulnerability in absolute (CVE-2026-40956). Risk of unauthorized operations or information disclosure.
CVE-2026-40958 Vulnerability in dos (CVE-2026-40958)
vulnerability in dos (CVE-2026-40958). Risk of unauthorized operations or information disclosure.
CVE-2026-40953 Out-of-Bounds Write in dos (CVE-2026-40953)
out-of-bounds write in dos (CVE-2026-40953). Risk of unauthorized operations or information disclosure.
CVE-2026-40954 Vulnerability in dos (CVE-2026-40954)
vulnerability in dos (CVE-2026-40954). Risk of unauthorized operations or information disclosure.
CVE-2026-33443 Vulnerability in dos (CVE-2026-33443)
vulnerability in dos (CVE-2026-33443). Risk of unauthorized operations or information disclosure.
CVE-2026-62361 SQL Injection in CVE-2026-62361 (CVE-2026-62361)
SQL injection in CVE-2026-62361 (CVE-2026-62361). Confidential information can be exposed externally. Exploitable via `GET /api/subscribers/export`.
CVE-2026-62312 OS Command Injection in CVE-2026-62312 (CVE-2026-62312)
OS command injection in CVE-2026-62312 (CVE-2026-62312). Successful exploitation can lead to full system takeover. Exploitable via `Host header`.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →