Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59153 |
|
Path Traversal in aqt (CVE-2026-59153)
path traversal in aqt (CVE-2026-59153). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `25.9.3` or later.
|
| CVE-2026-58266 |
|
Vulnerability in CVE-2026-58266 (CVE-2026-58266)
vulnerability in CVE-2026-58266 (CVE-2026-58266). Confidential information can be exposed externally.
|
| CVE-2026-55490 |
|
Vulnerability in openwrt (CVE-2026-55490)
vulnerability in openwrt (CVE-2026-55490). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55418 |
|
Vulnerability in CVE-2026-55418 (CVE-2026-55418)
vulnerability in CVE-2026-55418 (CVE-2026-55418). Confidential information can be exposed externally.
|
| CVE-2026-55408 |
|
Code Injection in CVE-2026-55408 (CVE-2026-55408)
code injection in CVE-2026-55408 (CVE-2026-55408). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54698 |
|
Authorization Flaw in hasura (CVE-2026-54698)
vulnerability in hasura (CVE-2026-54698). Confidential information can be exposed externally.
|
| CVE-2026-54607 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-54607 (CVE-2026-54607)
SSRF in CVE-2026-54607 (CVE-2026-54607). Confidential information can be exposed externally.
|
| CVE-2026-54602 |
|
Vulnerability in CVE-2026-54602 (CVE-2026-54602)
vulnerability in CVE-2026-54602 (CVE-2026-54602). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/core/ai/record/getRecord`.
|
| CVE-2026-54601 |
|
Vulnerability in CVE-2026-54601 (CVE-2026-54601)
vulnerability in CVE-2026-54601 (CVE-2026-54601). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/core/dataset/collection/create/reTrainingCollection`.
|
| CVE-2026-49033 |
|
Vulnerability in CVE-2026-49033 (CVE-2026-49033)
vulnerability in CVE-2026-49033 (CVE-2026-49033). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42958 |
|
Use-After-Free in CVE-2026-42958 (CVE-2026-42958)
vulnerability in CVE-2026-42958 (CVE-2026-42958). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28378 |
|
Vulnerability in grafana (CVE-2026-28378)
vulnerability in grafana (CVE-2026-28378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59707 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-59707 (CVE-2026-59707)
SSRF in CVE-2026-59707 (CVE-2026-59707). Confidential information can be exposed externally. Exploitable via `POST /models/apply`.
|
| CVE-2026-58583 |
|
Privilege Escalation in privilege-escalation (CVE-2026-58583)
vulnerability in privilege-escalation (CVE-2026-58583). Confidential information can be exposed externally.
|
| CVE-2026-58473 |
|
Vulnerability in CVE-2026-58473 (CVE-2026-58473)
vulnerability in CVE-2026-58473 (CVE-2026-58473). Confidential information can be exposed externally.
|
| CVE-2026-58472 |
|
Vulnerability in c (CVE-2026-58472)
vulnerability in c (CVE-2026-58472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58471 |
|
Vulnerability in c (CVE-2026-58471)
vulnerability in c (CVE-2026-58471). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58470 |
|
Vulnerability in c (CVE-2026-58470)
vulnerability in c (CVE-2026-58470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58469 |
|
Out-of-Bounds Read in c (CVE-2026-58469)
vulnerability in c (CVE-2026-58469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57172 |
|
Vulnerability in CVE-2026-57172 (CVE-2026-57172)
vulnerability in CVE-2026-57172 (CVE-2026-57172). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55647 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-55647)
cross-site scripting in vue (CVE-2026-55647). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55635 |
|
SQL Injection in CVE-2026-55635 (CVE-2026-55635)
SQL injection in CVE-2026-55635 (CVE-2026-55635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55633 |
|
Unrestricted File Upload in CVE-2026-55633 (CVE-2026-55633)
vulnerability in CVE-2026-55633 (CVE-2026-55633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55631 |
|
Path Traversal in path-traversal (CVE-2026-55631)
path traversal in path-traversal (CVE-2026-55631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55592 |
|
Cross-Site Scripting (XSS) in CVE-2026-55592 (CVE-2026-55592)
cross-site scripting in CVE-2026-55592 (CVE-2026-55592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55417 |
|
Vulnerability in CVE-2026-55417 (CVE-2026-55417)
vulnerability in CVE-2026-55417 (CVE-2026-55417). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53751 |
|
Code Injection in CVE-2026-53751 (CVE-2026-53751)
code injection in CVE-2026-53751 (CVE-2026-53751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53730 |
|
Vulnerability in CVE-2026-53730 (CVE-2026-53730)
vulnerability in CVE-2026-53730 (CVE-2026-53730). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53729 |
|
Vulnerability in CVE-2026-53729 (CVE-2026-53729)
vulnerability in CVE-2026-53729 (CVE-2026-53729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53511 |
|
Code Injection in CVE-2026-53511 (CVE-2026-53511)
code injection in CVE-2026-53511 (CVE-2026-53511). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50530 |
|
Vulnerability in CVE-2026-50530 (CVE-2026-50530)
vulnerability in CVE-2026-50530 (CVE-2026-50530). Risk of unauthorized operations or information disclosure. Exploitable via `POST /de2api/chartData/getData.`.
|
| CVE-2026-50529 |
|
Authorization Flaw in CVE-2026-50529 (CVE-2026-50529)
vulnerability in CVE-2026-50529 (CVE-2026-50529). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50007 |
|
Vulnerability in CVE-2026-50007 (CVE-2026-50007)
vulnerability in CVE-2026-50007 (CVE-2026-50007). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49471 |
|
Vulnerability in serena-agent (CVE-2026-49471)
vulnerability in serena-agent (CVE-2026-49471). Successful exploitation can lead to full system takeover. Exploitable via `Host header`. Mitigation: upgrade to `1.5.2` or later.
|
| GHSA-j8v8-g9cx-5qf4 |
|
Vulnerability in @better-auth/scim (GHSA-j8v8-g9cx-5qf4)
vulnerability in @better-auth/scim (GHSA-j8v8-g9cx-5qf4). Risk of unauthorized operations or information disclosure. Exploitable via `POST /scim/generate-token`. Mitigation: upgrade to `1.7.0-beta.4` or later.
|
| GHSA-2vg6-77g8-24mp |
|
Vulnerability in better-auth (GHSA-2vg6-77g8-24mp)
vulnerability in better-auth (GHSA-2vg6-77g8-24mp). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /scim/v2/Users/`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53518 |
|
Vulnerability in @better-auth/oauth-provider (CVE-2026-53518)
vulnerability in @better-auth/oauth-provider (CVE-2026-53518). Confidential information can be exposed externally. Exploitable via `POST /oauth2/token`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53513 |
|
Vulnerability in @better-auth/sso (CVE-2026-53513)
vulnerability in @better-auth/sso (CVE-2026-53513). Confidential information can be exposed externally. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53517 |
|
Vulnerability in @better-auth/oauth-provider (CVE-2026-53517)
vulnerability in @better-auth/oauth-provider (CVE-2026-53517). Confidential information can be exposed externally. Exploitable via `POST /oauth2/token`. Mitigation: upgrade to `1.6.11` or later.
|
| GHSA-9h47-pqcx-hjr4 |
|
Vulnerability in better-auth (GHSA-9h47-pqcx-hjr4)
vulnerability in better-auth (GHSA-9h47-pqcx-hjr4). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `1.6.11` or later.
|
| GHSA-86j7-9j95-vpqj |
|
Cross-Site Scripting (XSS) in better-auth (GHSA-86j7-9j95-vpqj)
cross-site scripting in better-auth (GHSA-86j7-9j95-vpqj). Risk of unauthorized operations or information disclosure. Exploitable via `POST /oauth2/register`. Mitigation: upgrade to `1.7.0-beta.4` or later.
|
| CVE-2026-53516 |
|
Authentication Bypass in better-auth (CVE-2026-53516)
authentication bypass in better-auth (CVE-2026-53516). Confidential information can be exposed externally. Exploitable via ``next``. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53514 |
|
Authentication Bypass in better-auth (CVE-2026-53514)
authentication bypass in better-auth (CVE-2026-53514). Confidential information can be exposed externally. Exploitable via ``organization``. Mitigation: upgrade to `1.6.11` or later.
|
| GHSA-p2fr-6hmx-4528 |
|
Vulnerability in @better-auth/oauth-provider (GHSA-p2fr-6hmx-4528)
vulnerability in @better-auth/oauth-provider (GHSA-p2fr-6hmx-4528). Risk of unauthorized operations or information disclosure. Exploitable via ``aud``. Mitigation: upgrade to `1.7.0-beta.4` or later.
|
| CGA-g448-ff83-rg94 |
|
CGA-g448-ff83-rg94 |
| MAL-2026-6955 |
|
Vulnerability in hello244b (MAL-2026-6955)
vulnerability in hello244b (MAL-2026-6955). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58468 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-58468 (CVE-2026-58468)
SSRF in CVE-2026-58468 (CVE-2026-58468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44877 |
|
Information Disclosure in CVE-2026-44877 (CVE-2026-44877)
vulnerability in CVE-2026-44877 (CVE-2026-44877). Confidential information can be exposed externally.
|
| CVE-2026-53512 |
|
Authentication Bypass in better-auth (CVE-2026-53512)
authentication bypass in better-auth (CVE-2026-53512). Confidential information can be exposed externally. Exploitable via ``oauthApplication``. Mitigation: upgrade to `1.6.11` or later.
|
| GHSA-7856-g3gv-9wq8 |
|
Vulnerability in github.com/tinfoil-factory/netfoil (GHSA-7856-g3gv-9wq8)
vulnerability in github.com/tinfoil-factory/netfoil (GHSA-7856-g3gv-9wq8). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.3.0` or later.
|