Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59725 |
|
Vulnerability in engine.io (CVE-2026-59725)
vulnerability in engine.io (CVE-2026-59725). Risk of unauthorized operations or information disclosure. Exploitable via ``POST``. Mitigation: upgrade to `6.6.7` or later.
|
| CVE-2026-59724 |
|
Vulnerability in dos (CVE-2026-59724)
vulnerability in dos (CVE-2026-59724). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59702 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-59702 (CVE-2026-59702)
SSRF in CVE-2026-59702 (CVE-2026-59702). Confidential information can be exposed externally. Exploitable via `POST /api/pack`.
|
| CVE-2026-59262 |
|
Vulnerability in CVE-2026-59262 (CVE-2026-59262)
vulnerability in CVE-2026-59262 (CVE-2026-59262). Confidential information can be exposed externally.
|
| CVE-2026-57439 |
|
Cross-Site Scripting (XSS) in CVE-2026-57439 (CVE-2026-57439)
cross-site scripting in CVE-2026-57439 (CVE-2026-57439). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55761 |
|
Authentication Bypass in github.com/portainer/portainer (CVE-2026-55761)
authentication bypass in github.com/portainer/portainer (CVE-2026-55761). Data can be tampered with by attackers. Exploitable via ``bouncer.PublicAccess``. Mitigation: upgrade to `2.43.0` or later.
|
| CVE-2026-54344 |
|
OS Command Injection in tooljet (CVE-2026-54344)
OS command injection in tooljet (CVE-2026-54344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53951 |
|
Path Traversal in copier (CVE-2026-53951)
path traversal in copier (CVE-2026-53951). Risk of unauthorized operations or information disclosure. Exploitable via ``trust``. Mitigation: upgrade to `9.15.2` or later.
|
| CVE-2026-49946 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-49945 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-49944 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-3144 |
|
Vulnerability in ibm (CVE-2026-3144)
vulnerability in ibm (CVE-2026-3144). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15063 |
|
Vulnerability in CVE-2026-15063 (CVE-2026-15063)
vulnerability in CVE-2026-15063 (CVE-2026-15063). Confidential information can be exposed externally.
|
| CVE-2026-14967 |
|
Path Traversal in blacklanternsecurity (CVE-2026-14967)
path traversal in blacklanternsecurity (CVE-2026-14967). Risk of unauthorized operations or information disclosure. Exploitable via ``github_workflows``.
|
| CVE-2026-14966 |
|
Vulnerability in dos (CVE-2026-14966)
vulnerability in dos (CVE-2026-14966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49145 |
|
Vulnerability in CVE-2026-49145 (CVE-2026-49145)
vulnerability in CVE-2026-49145 (CVE-2026-49145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56374 |
|
Out-of-Bounds Read in dos (CVE-2026-56374)
vulnerability in dos (CVE-2026-56374). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56776 |
|
Authorization Flaw in n8n (CVE-2026-56776)
vulnerability in n8n (CVE-2026-56776). Risk of unauthorized operations or information disclosure. Exploitable via `POST /workflows/{workflowId}/test-runs/new`.
|
| CVE-2026-56360 |
|
Vulnerability in n8n (CVE-2026-56360)
vulnerability in n8n (CVE-2026-56360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56362 |
|
Out-of-Bounds Read in imagemagick (CVE-2026-56362)
vulnerability in imagemagick (CVE-2026-56362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56359 |
|
Cross-Site Scripting (XSS) in n8n (CVE-2026-56359)
cross-site scripting in n8n (CVE-2026-56359). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56297 |
|
Vulnerability in dos (CVE-2026-56297)
vulnerability in dos (CVE-2026-56297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56284 |
|
Information Disclosure in CVE-2026-56284 (CVE-2026-56284)
vulnerability in CVE-2026-56284 (CVE-2026-56284). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56273 |
|
Path Traversal in path-traversal (CVE-2026-56273)
path traversal in path-traversal (CVE-2026-56273). Data can be tampered with by attackers.
|
| CVE-2026-56293 |
|
Vulnerability in CVE-2026-56293 (CVE-2026-56293)
vulnerability in CVE-2026-56293 (CVE-2026-56293). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56283 |
|
Cross-Site Scripting (XSS) in CVE-2026-56283 (CVE-2026-56283)
cross-site scripting in CVE-2026-56283 (CVE-2026-56283). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56250 |
|
Vulnerability in dos (CVE-2026-56250)
vulnerability in dos (CVE-2026-56250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56298 |
|
Information Disclosure in CVE-2026-56298 (CVE-2026-56298)
vulnerability in CVE-2026-56298 (CVE-2026-56298). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56086 |
|
Authorization Flaw in dell (CVE-2026-56086)
vulnerability in dell (CVE-2026-56086). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56220 |
|
Authorization Flaw in CVE-2026-56220 (CVE-2026-56220)
vulnerability in CVE-2026-56220 (CVE-2026-56220). Data can be tampered with by attackers.
|
| CVE-2026-56246 |
|
Vulnerability in CVE-2026-56246 (CVE-2026-56246)
vulnerability in CVE-2026-56246 (CVE-2026-56246). Data can be tampered with by attackers. Exploitable via `DELETE /organization`.
|
| CVE-2026-56226 |
|
Information Disclosure in CVE-2026-56226 (CVE-2026-56226)
vulnerability in CVE-2026-56226 (CVE-2026-56226). Confidential information can be exposed externally. Exploitable via `POST /rest/v1/rpc/get_orgs_v6`.
|
| CVE-2026-15035 |
|
Vulnerability in bentoml (CVE-2026-15035)
vulnerability in bentoml (CVE-2026-15035). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41122 |
|
Cross-Site Scripting (XSS) in dell (CVE-2026-41122)
cross-site scripting in dell (CVE-2026-41122). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56217 |
|
Vulnerability in CVE-2026-56217 (CVE-2026-56217)
vulnerability in CVE-2026-56217 (CVE-2026-56217). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15034 |
|
Cross-Site Request Forgery (CSRF) in flask (CVE-2026-15034)
vulnerability in flask (CVE-2026-15034). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15053 |
|
Tanium addressed a denial of service vulnerability in Tanium Server.
Tanium addressed a denial of service vulnerability in Tanium Server.
|
| CVE-2026-53480 |
|
Path Traversal in path-traversal (CVE-2026-53480)
path traversal in path-traversal (CVE-2026-53480). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15033 |
|
Command Injection in CVE-2026-15033 (CVE-2026-15033)
command injection in CVE-2026-15033 (CVE-2026-15033). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53482 |
|
Vulnerability in dos (CVE-2026-53482)
vulnerability in dos (CVE-2026-53482). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22927 |
|
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
|
| CVE-2026-59703 |
|
Vulnerability in c (CVE-2026-59703)
vulnerability in c (CVE-2026-59703). Confidential information can be exposed externally.
|
| CVE-2026-55874 |
|
Path Traversal in github.com/seaweedfs/seaweedfs (CVE-2026-55874)
path traversal in github.com/seaweedfs/seaweedfs (CVE-2026-55874). Confidential information can be exposed externally. Exploitable via ``CopyObject``. Mitigation: upgrade to `0.0.0-20260612000715-b44cf51fe931` or later.
|
| CVE-2026-55873 |
|
Authorization Flaw in github.com/seaweedfs/seaweedfs (CVE-2026-55873)
vulnerability in github.com/seaweedfs/seaweedfs (CVE-2026-55873). Risk of unauthorized operations or information disclosure. Exploitable via `GET /buckets`. Mitigation: upgrade to `0.0.0-20260614205536-b13463880c1f` or later.
|
| CVE-2026-55668 |
|
Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55668)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-55668). Data can be tampered with by attackers. Exploitable via `POST /api/resources/`. Mitigation: upgrade to `2.63.16` or later.
|
| CVE-2026-54652 |
|
Privilege Escalation in nginx (CVE-2026-54652)
vulnerability in nginx (CVE-2026-54652). Confidential information can be exposed externally. Exploitable via `GET /api/logs/{service}`.
|
| CVE-2026-49147 |
|
Vulnerability in c (CVE-2026-49147)
vulnerability in c (CVE-2026-49147). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49146 |
|
Vulnerability in c (CVE-2026-49146)
vulnerability in c (CVE-2026-49146). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24700 |
|
OS Command Injection in cisco (CVE-2026-24700)
OS command injection in cisco (CVE-2026-24700). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24699 |
|
OS Command Injection in cisco (CVE-2026-24699)
OS command injection in cisco (CVE-2026-24699). Successful exploitation can lead to full system takeover.
|