Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-60002 |
|
Use-After-Free in openbsd (CVE-2026-60002)
vulnerability in openbsd (CVE-2026-60002). Confidential information can be exposed externally.
|
| CVE-2026-60001 |
|
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
|
| CVE-2026-60000 |
|
Vulnerability in dos (CVE-2026-60000)
vulnerability in dos (CVE-2026-60000). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59999 |
|
Vulnerability in openbsd (CVE-2026-59999)
vulnerability in openbsd (CVE-2026-59999). Data can be tampered with by attackers.
|
| CVE-2026-59998 |
|
Vulnerability in openbsd (CVE-2026-59998)
vulnerability in openbsd (CVE-2026-59998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59997 |
|
Vulnerability in openbsd (CVE-2026-59997)
vulnerability in openbsd (CVE-2026-59997). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59996 |
|
Vulnerability in openbsd (CVE-2026-59996)
vulnerability in openbsd (CVE-2026-59996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59995 |
|
Vulnerability in openbsd (CVE-2026-59995)
vulnerability in openbsd (CVE-2026-59995). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56843 |
|
Vulnerability in c (CVE-2026-56843)
vulnerability in c (CVE-2026-56843). Successful exploitation can lead to full system takeover.
|
| GHSA-58j3-rgh4-9rjc |
|
Vulnerability in nodemon-node (GHSA-58j3-rgh4-9rjc)
vulnerability in nodemon-node (GHSA-58j3-rgh4-9rjc). Risk of unauthorized operations or information disclosure.
|
| GHSA-xpmf-x27p-9vcc |
|
Vulnerability in ts-await (GHSA-xpmf-x27p-9vcc)
vulnerability in ts-await (GHSA-xpmf-x27p-9vcc). Risk of unauthorized operations or information disclosure.
|
| ECHO-3bbc-736a-5aa2 |
|
ECHO-3bbc-736a-5aa2 |
| ECHO-38d5-c884-2737 |
|
ECHO-38d5-c884-2737 |
| ECHO-7fb5-d5d0-f779 |
|
ECHO-7fb5-d5d0-f779 |
| ECHO-35cc-781b-4acf |
|
ECHO-35cc-781b-4acf |
| ECHO-400a-1b13-ae60 |
|
ECHO-400a-1b13-ae60 |
| ECHO-f85d-c4a6-6f1f |
|
ECHO-f85d-c4a6-6f1f |
| ECHO-7b00-51a9-54be |
|
ECHO-7b00-51a9-54be |
| ECHO-3bfd-1865-8be2 |
|
ECHO-3bfd-1865-8be2 |
| ECHO-da14-670e-14a1 |
|
ECHO-da14-670e-14a1 |
| ECHO-73f1-09ff-6652 |
|
ECHO-73f1-09ff-6652 |
| ECHO-e001-dbbd-1ca3 |
|
ECHO-e001-dbbd-1ca3 |
| ECHO-f509-4388-9b59 |
|
ECHO-f509-4388-9b59 |
| ECHO-5865-ae76-0fca |
|
ECHO-5865-ae76-0fca |
| CVE-2026-53508 |
|
Vulnerability in github.com/oasdiff/oasdiff (CVE-2026-53508)
vulnerability in github.com/oasdiff/oasdiff (CVE-2026-53508). Risk of unauthorized operations or information disclosure. Exploitable via ``breaking``. Mitigation: upgrade to `1.18.1` or later.
|
| CVE-2026-53572 |
|
Vulnerability in github.com/kedacore/keda/v2 (CVE-2026-53572)
vulnerability in github.com/kedacore/keda/v2 (CVE-2026-53572). Confidential information can be exposed externally. Exploitable via ``host``. Mitigation: upgrade to `2.20.0` or later.
|
| GHSA-f66q-9rf6-8795 |
|
Authentication Bypass in Flask-Security-Too (GHSA-f66q-9rf6-8795)
authentication bypass in Flask-Security-Too (GHSA-f66q-9rf6-8795). Risk of unauthorized operations or information disclosure. Exploitable via `POST /wan-verify`. Mitigation: upgrade to `5.8.1` or later.
|
| CVE-2026-53553 |
|
Path Traversal in github.com/zhenorzz/goploy (CVE-2026-53553)
path traversal in github.com/zhenorzz/goploy (CVE-2026-53553). Confidential information can be exposed externally. Exploitable via ``filePath``.
|
| CVE-2026-53552 |
|
Vulnerability in github.com/zhenorzz/goploy (CVE-2026-53552)
vulnerability in github.com/zhenorzz/goploy (CVE-2026-53552). Confidential information can be exposed externally. Exploitable via ``Project.AddFile``.
|
| GHSA-q855-8rh5-jfgq |
|
Vulnerability in ha-mcp (GHSA-q855-8rh5-jfgq)
vulnerability in ha-mcp (GHSA-q855-8rh5-jfgq). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/settings/tools`. Mitigation: upgrade to `7.10.0` or later.
|
| GHSA-cwv4-h3j5-w3cf |
|
Vulnerability in rama (GHSA-cwv4-h3j5-w3cf)
vulnerability in rama (GHSA-cwv4-h3j5-w3cf). Risk of unauthorized operations or information disclosure. Exploitable via ``ServeDir``. Mitigation: upgrade to `0.3.0-rc.1` or later.
|
| CVE-2026-53533 |
|
Command Injection in aiosmtplib (CVE-2026-53533)
command injection in aiosmtplib (CVE-2026-53533). Risk of unauthorized operations or information disclosure. Exploitable via ``aiosmtplib``. Mitigation: upgrade to `5.1.1` or later.
|
| CVE-2026-53487 |
|
Vulnerability in github.com/zxh326/kite (CVE-2026-53487)
vulnerability in github.com/zxh326/kite (CVE-2026-53487). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/overview`. Mitigation: upgrade to `0.12.3` or later.
|
| GHSA-gq4g-fpc9-vjfq |
|
Vulnerability in web-auth/webauthn-lib (GHSA-gq4g-fpc9-vjfq)
vulnerability in web-auth/webauthn-lib (GHSA-gq4g-fpc9-vjfq). Risk of unauthorized operations or information disclosure. Exploitable via ``FakeCredentialGenerator``. Mitigation: upgrade to `5.3.5` or later.
|
| CVE-2026-53531 |
|
Vulnerability in ratex-parser (CVE-2026-53531)
vulnerability in ratex-parser (CVE-2026-53531). Risk of unauthorized operations or information disclosure. Exploitable via ``SIGABRT``. Mitigation: upgrade to `0.1.11` or later.
|
| CVE-2026-53530 |
|
Vulnerability in ratex-parser (CVE-2026-53530)
vulnerability in ratex-parser (CVE-2026-53530). Risk of unauthorized operations or information disclosure. Exploitable via ``parse_symbol_inner``. Mitigation: upgrade to `0.1.11` or later.
|
| CVE-2026-59705 |
|
Vulnerability in CVE-2026-59705 (CVE-2026-59705)
vulnerability in CVE-2026-59705 (CVE-2026-59705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59704 |
|
Vulnerability in CVE-2026-59704 (CVE-2026-59704)
vulnerability in CVE-2026-59704 (CVE-2026-59704). Confidential information can be exposed externally. Exploitable via `GET /api/video/ai`.
|
| CVE-2026-51937 |
|
Vulnerability in CVE-2026-51937 (CVE-2026-51937)
vulnerability in CVE-2026-51937 (CVE-2026-51937). Confidential information can be exposed externally.
|
| CVE-2026-50811 |
|
Out-of-Bounds Read in c (CVE-2026-50811)
vulnerability in c (CVE-2026-50811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50810 |
|
Vulnerability in c (CVE-2026-50810)
vulnerability in c (CVE-2026-50810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37271 |
|
Authentication Bypass in CVE-2026-37271 (CVE-2026-37271)
authentication bypass in CVE-2026-37271 (CVE-2026-37271). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37270 |
|
Authentication Bypass in CVE-2026-37270 (CVE-2026-37270)
authentication bypass in CVE-2026-37270 (CVE-2026-37270). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36163 |
|
Cross-Site Scripting (XSS) in CVE-2026-36163 (CVE-2026-36163)
cross-site scripting in CVE-2026-36163 (CVE-2026-36163). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36162 |
|
Cross-Site Scripting (XSS) in CVE-2026-36162 (CVE-2026-36162)
cross-site scripting in CVE-2026-36162 (CVE-2026-36162). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14895 |
|
Vulnerability in dos (CVE-2026-14895)
vulnerability in dos (CVE-2026-14895). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14740 |
|
Out-of-Bounds Read in perl (CVE-2026-14740)
vulnerability in perl (CVE-2026-14740). Confidential information can be exposed externally.
|
| CVE-2026-14739 |
|
Out-of-Bounds Write in perl (CVE-2026-14739)
out-of-bounds write in perl (CVE-2026-14739). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14380 |
|
Vulnerability in perl (CVE-2026-14380)
vulnerability in perl (CVE-2026-14380). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59706 |
|
Vulnerability in ssrf (CVE-2026-59706)
vulnerability in ssrf (CVE-2026-59706). Confidential information can be exposed externally. Exploitable via `GET /api/v1/config/`.
|