Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-48753 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.0` or later.
CVE-2026-48752 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48752)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48752). Successful exploitation can lead to full system takeover. Exploitable via ``templates``. Mitigation: upgrade to `7.2.0` or later.
CVE-2026-56876 Path Traversal in extract-zip (CVE-2026-56876)
path traversal in extract-zip (CVE-2026-56876). Confidential information can be exposed externally.
CVE-2026-11779 Vulnerability in CVE-2026-11779 (CVE-2026-11779)
vulnerability in CVE-2026-11779 (CVE-2026-11779). Risk of unauthorized operations or information disclosure.
CVE-2026-57518 Vulnerability in privilege-escalation (CVE-2026-57518)
vulnerability in privilege-escalation (CVE-2026-57518). Successful exploitation can lead to full system takeover.
CVE-2026-0828 Vulnerability in CVE-2026-0828 (CVE-2026-0828)
vulnerability in CVE-2026-0828 (CVE-2026-0828). Confidential information can be exposed externally.
CVE-2026-5757 Out-of-Bounds Read in ollama (CVE-2026-5757)
vulnerability in ollama (CVE-2026-5757). Confidential information can be exposed externally.
CVE-2026-13434 Vulnerability in kubevirt (CVE-2026-13434)
vulnerability in kubevirt (CVE-2026-13434). Risk of unauthorized operations or information disclosure.
CVE-2026-45195 Vulnerability in imaginationtech (CVE-2026-45195)
vulnerability in imaginationtech (CVE-2026-45195). Successful exploitation can lead to full system takeover.
CVE-2026-0685 Vulnerability in CVE-2026-0685 (CVE-2026-0685)
vulnerability in CVE-2026-0685 (CVE-2026-0685). Successful exploitation can lead to full system takeover.
CVE-2026-21734 Vulnerability in imaginationtech (CVE-2026-21734)
vulnerability in imaginationtech (CVE-2026-21734). Data can be tampered with by attackers.
CVE-2023-20540 Vulnerability in CVE-2023-20540 (CVE-2023-20540)
vulnerability in CVE-2023-20540 (CVE-2023-20540). Risk of unauthorized operations or information disclosure.
CVE-2023-20572 Vulnerability in CVE-2023-20572 (CVE-2023-20572)
vulnerability in CVE-2023-20572 (CVE-2023-20572). Risk of unauthorized operations or information disclosure.
CVE-2025-11919 Vulnerability in CVE-2025-11919 (CVE-2025-11919)
vulnerability in CVE-2025-11919 (CVE-2025-11919). Confidential information can be exposed externally.
CVE-2026-48751 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751). Successful exploitation can lead to full system takeover. Exploitable via ``raw.lxc``. Mitigation: upgrade to `7.2.0` or later.
CVE-2026-48750 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48750)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48750). Successful exploitation can lead to full system takeover. Exploitable via ``exec_UUID.stdout``. Mitigation: upgrade to `7.2.0` or later.
CVE-2026-48749 Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48749)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48749). Successful exploitation can lead to full system takeover. Exploitable via ``metadata.yaml``. Mitigation: upgrade to `7.2.0` or later.
CGA-fcjh-65j7-5hp6 CGA-fcjh-65j7-5hp6
CGA-4jc3-m65r-hf69 CGA-4jc3-m65r-hf69
CGA-436j-9rcw-588x CGA-436j-9rcw-588x
UBUNTU-CVE-2026-56876 Vulnerability in node-extract-zip (UBUNTU-CVE-2026-56876)
vulnerability in node-extract-zip (UBUNTU-CVE-2026-56876). Confidential information can be exposed externally.
CVE-2026-54341 Out-of-Bounds Read in dos (CVE-2026-54341)
vulnerability in dos (CVE-2026-54341). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.39.0` or later.
CVE-2026-48743 Vulnerability in envoyproxy (CVE-2026-48743)
vulnerability in envoyproxy (CVE-2026-48743). Data can be tampered with by attackers. Exploitable via `GET /pwn`. Mitigation: upgrade to `1.35.11` or later.
CVE-2026-48706 Vulnerability in envoyproxy (CVE-2026-48706)
vulnerability in envoyproxy (CVE-2026-48706). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
CVE-2026-48497 Vulnerability in c (CVE-2026-48497)
vulnerability in c (CVE-2026-48497). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.11` or later.
CVE-2026-48044 Vulnerability in dos (CVE-2026-48044)
vulnerability in dos (CVE-2026-48044). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.11` or later.
CVE-2026-48042 Vulnerability in envoyproxy (CVE-2026-48042)
vulnerability in envoyproxy (CVE-2026-48042). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.11` or later.
CVE-2026-47778 Vulnerability in c (CVE-2026-47778)
vulnerability in c (CVE-2026-47778). Confidential information can be exposed externally. Mitigation: upgrade to `1.35.11` or later.
CVE-2026-47775 Vulnerability in envoyproxy (CVE-2026-47775)
vulnerability in envoyproxy (CVE-2026-47775). Confidential information can be exposed externally. Mitigation: upgrade to `1.35.11` or later.
CVE-2026-47692 Vulnerability in envoyproxy (CVE-2026-47692)
vulnerability in envoyproxy (CVE-2026-47692). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
CVE-2026-47221 Vulnerability in dos (CVE-2026-47221)
vulnerability in dos (CVE-2026-47221). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
CVE-2026-47207 Use-After-Free in envoyproxy (CVE-2026-47207)
vulnerability in envoyproxy (CVE-2026-47207). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
CVE-2026-47206 Vulnerability in CVE-2026-47206 (CVE-2026-47206)
vulnerability in CVE-2026-47206 (CVE-2026-47206). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.39.9` or later.
CVE-2026-47204 Vulnerability in envoyproxy (CVE-2026-47204)
vulnerability in envoyproxy (CVE-2026-47204). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
CGA-q99c-pqq6-c969 CGA-q99c-pqq6-c969
RLSA-2023:6712 Vulnerability in python-wheel (RLSA-2023:6712)
vulnerability in python-wheel (RLSA-2023:6712). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.36.2-8.el9` or later.
RLSA-2023:2870 Vulnerability in freeradius (RLSA-2023:2870)
vulnerability in freeradius (RLSA-2023:2870). Confidential information can be exposed externally. Mitigation: upgrade to `0:3.0.20-14.module+el8.8.0+1130+46a6e0a1` or later.
RLSA-2023:2860 Vulnerability in babel (RLSA-2023:2860)
vulnerability in babel (RLSA-2023:2860). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.5.1-10.module+el8.9.0+1531+a18208f5` or later.
CGA-97jr-54h6-qwpw CGA-97jr-54h6-qwpw
BELL-CVE-2026-57452 BELL-CVE-2026-57452
BELL-CVE-2026-57455 BELL-CVE-2026-57455
BELL-CVE-2026-57454 BELL-CVE-2026-57454
BELL-CVE-2026-57453 BELL-CVE-2026-57453
BELL-CVE-2026-57451 BELL-CVE-2026-57451
BELL-CVE-2026-57456 BELL-CVE-2026-57456
BELL-CVE-2026-54679 BELL-CVE-2026-54679
CVE-2026-46623 Vulnerability in org.openidentityplatform.openam:openam-auth-oauth2 (CVE-2026-46623)
vulnerability in org.openidentityplatform.openam:openam-auth-oauth2 (CVE-2026-46623). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
CVE-2026-46619 Vulnerability in org.openidentityplatform.openam:openam-auth-msisdn (CVE-2026-46619)
vulnerability in org.openidentityplatform.openam:openam-auth-msisdn (CVE-2026-46619). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
BELL-CVE-2026-56123 BELL-CVE-2026-56123
CVE-2026-44163 Vulnerability in fluent-plugin-opentelemetry (CVE-2026-44163)
vulnerability in fluent-plugin-opentelemetry (CVE-2026-44163). Risk of unauthorized operations or information disclosure. Exploitable via ``in_opentelemetry``. Mitigation: upgrade to `0.5.3` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →