Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48753 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48753). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-48752 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48752)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48752). Successful exploitation can lead to full system takeover. Exploitable via ``templates``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-56876 |
|
Path Traversal in extract-zip (CVE-2026-56876)
path traversal in extract-zip (CVE-2026-56876). Confidential information can be exposed externally.
|
| CVE-2026-11779 |
|
Vulnerability in CVE-2026-11779 (CVE-2026-11779)
vulnerability in CVE-2026-11779 (CVE-2026-11779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57518 |
|
Vulnerability in privilege-escalation (CVE-2026-57518)
vulnerability in privilege-escalation (CVE-2026-57518). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0828 |
|
Vulnerability in CVE-2026-0828 (CVE-2026-0828)
vulnerability in CVE-2026-0828 (CVE-2026-0828). Confidential information can be exposed externally.
|
| CVE-2026-5757 |
|
Out-of-Bounds Read in ollama (CVE-2026-5757)
vulnerability in ollama (CVE-2026-5757). Confidential information can be exposed externally.
|
| CVE-2026-13434 |
|
Vulnerability in kubevirt (CVE-2026-13434)
vulnerability in kubevirt (CVE-2026-13434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45195 |
|
Vulnerability in imaginationtech (CVE-2026-45195)
vulnerability in imaginationtech (CVE-2026-45195). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0685 |
|
Vulnerability in CVE-2026-0685 (CVE-2026-0685)
vulnerability in CVE-2026-0685 (CVE-2026-0685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21734 |
|
Vulnerability in imaginationtech (CVE-2026-21734)
vulnerability in imaginationtech (CVE-2026-21734). Data can be tampered with by attackers.
|
| CVE-2023-20540 |
|
Vulnerability in CVE-2023-20540 (CVE-2023-20540)
vulnerability in CVE-2023-20540 (CVE-2023-20540). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-20572 |
|
Vulnerability in CVE-2023-20572 (CVE-2023-20572)
vulnerability in CVE-2023-20572 (CVE-2023-20572). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-11919 |
|
Vulnerability in CVE-2025-11919 (CVE-2025-11919)
vulnerability in CVE-2025-11919 (CVE-2025-11919). Confidential information can be exposed externally.
|
| CVE-2026-48751 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751). Successful exploitation can lead to full system takeover. Exploitable via ``raw.lxc``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48750 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48750)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48750). Successful exploitation can lead to full system takeover. Exploitable via ``exec_UUID.stdout``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48749 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48749)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48749). Successful exploitation can lead to full system takeover. Exploitable via ``metadata.yaml``. Mitigation: upgrade to `7.2.0` or later.
|
| CGA-fcjh-65j7-5hp6 |
|
CGA-fcjh-65j7-5hp6 |
| CGA-4jc3-m65r-hf69 |
|
CGA-4jc3-m65r-hf69 |
| CGA-436j-9rcw-588x |
|
CGA-436j-9rcw-588x |
| UBUNTU-CVE-2026-56876 |
|
Vulnerability in node-extract-zip (UBUNTU-CVE-2026-56876)
vulnerability in node-extract-zip (UBUNTU-CVE-2026-56876). Confidential information can be exposed externally.
|
| CVE-2026-54341 |
|
Out-of-Bounds Read in dos (CVE-2026-54341)
vulnerability in dos (CVE-2026-54341). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.39.0` or later.
|
| CVE-2026-48743 |
|
Vulnerability in envoyproxy (CVE-2026-48743)
vulnerability in envoyproxy (CVE-2026-48743). Data can be tampered with by attackers. Exploitable via `GET /pwn`. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-48706 |
|
Vulnerability in envoyproxy (CVE-2026-48706)
vulnerability in envoyproxy (CVE-2026-48706). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-48497 |
|
Vulnerability in c (CVE-2026-48497)
vulnerability in c (CVE-2026-48497). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-48044 |
|
Vulnerability in dos (CVE-2026-48044)
vulnerability in dos (CVE-2026-48044). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-48042 |
|
Vulnerability in envoyproxy (CVE-2026-48042)
vulnerability in envoyproxy (CVE-2026-48042). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-47778 |
|
Vulnerability in c (CVE-2026-47778)
vulnerability in c (CVE-2026-47778). Confidential information can be exposed externally. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-47775 |
|
Vulnerability in envoyproxy (CVE-2026-47775)
vulnerability in envoyproxy (CVE-2026-47775). Confidential information can be exposed externally. Mitigation: upgrade to `1.35.11` or later.
|
| CVE-2026-47692 |
|
Vulnerability in envoyproxy (CVE-2026-47692)
vulnerability in envoyproxy (CVE-2026-47692). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-47221 |
|
Vulnerability in dos (CVE-2026-47221)
vulnerability in dos (CVE-2026-47221). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-47207 |
|
Use-After-Free in envoyproxy (CVE-2026-47207)
vulnerability in envoyproxy (CVE-2026-47207). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CVE-2026-47206 |
|
Vulnerability in CVE-2026-47206 (CVE-2026-47206)
vulnerability in CVE-2026-47206 (CVE-2026-47206). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.39.9` or later.
|
| CVE-2026-47204 |
|
Vulnerability in envoyproxy (CVE-2026-47204)
vulnerability in envoyproxy (CVE-2026-47204). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.13` or later.
|
| CGA-q99c-pqq6-c969 |
|
CGA-q99c-pqq6-c969 |
| RLSA-2023:6712 |
|
Vulnerability in python-wheel (RLSA-2023:6712)
vulnerability in python-wheel (RLSA-2023:6712). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.36.2-8.el9` or later.
|
| RLSA-2023:2870 |
|
Vulnerability in freeradius (RLSA-2023:2870)
vulnerability in freeradius (RLSA-2023:2870). Confidential information can be exposed externally. Mitigation: upgrade to `0:3.0.20-14.module+el8.8.0+1130+46a6e0a1` or later.
|
| RLSA-2023:2860 |
|
Vulnerability in babel (RLSA-2023:2860)
vulnerability in babel (RLSA-2023:2860). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0:2.5.1-10.module+el8.9.0+1531+a18208f5` or later.
|
| CGA-97jr-54h6-qwpw |
|
CGA-97jr-54h6-qwpw |
| BELL-CVE-2026-57452 |
|
BELL-CVE-2026-57452 |
| BELL-CVE-2026-57455 |
|
BELL-CVE-2026-57455 |
| BELL-CVE-2026-57454 |
|
BELL-CVE-2026-57454 |
| BELL-CVE-2026-57453 |
|
BELL-CVE-2026-57453 |
| BELL-CVE-2026-57451 |
|
BELL-CVE-2026-57451 |
| BELL-CVE-2026-57456 |
|
BELL-CVE-2026-57456 |
| BELL-CVE-2026-54679 |
|
BELL-CVE-2026-54679 |
| CVE-2026-46623 |
|
Vulnerability in org.openidentityplatform.openam:openam-auth-oauth2 (CVE-2026-46623)
vulnerability in org.openidentityplatform.openam:openam-auth-oauth2 (CVE-2026-46623). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| CVE-2026-46619 |
|
Vulnerability in org.openidentityplatform.openam:openam-auth-msisdn (CVE-2026-46619)
vulnerability in org.openidentityplatform.openam:openam-auth-msisdn (CVE-2026-46619). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.1.1` or later.
|
| BELL-CVE-2026-56123 |
|
BELL-CVE-2026-56123 |
| CVE-2026-44163 |
|
Vulnerability in fluent-plugin-opentelemetry (CVE-2026-44163)
vulnerability in fluent-plugin-opentelemetry (CVE-2026-44163). Risk of unauthorized operations or information disclosure. Exploitable via ``in_opentelemetry``. Mitigation: upgrade to `0.5.3` or later.
|