Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-70482 |
|
Authentication Bypass in open-webui (CVE-2026-70482)
authentication bypass in open-webui (CVE-2026-70482). Confidential information can be exposed externally. Exploitable via `POST /api/v1/auths/oauth/{provider}/token/exchange`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70479 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70479)
SSRF in open-webui (CVE-2026-70479). Confidential information can be exposed externally. Exploitable via ``PLAYWRIGHT_WS_URL``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-47623 |
|
Unsafe Deserialization in dos (CVE-2026-47623)
vulnerability in dos (CVE-2026-47623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24255 |
|
Vulnerability in nvidia (CVE-2026-24255)
vulnerability in nvidia (CVE-2026-24255). Data can be tampered with by attackers.
|
| CVE-2026-47618 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47618)
SSRF in nvidia (CVE-2026-47618). Confidential information can be exposed externally.
|
| CVE-2026-47617 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47617)
SSRF in nvidia (CVE-2026-47617). Confidential information can be exposed externally.
|
| CVE-2026-47613 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47613)
SSRF in nvidia (CVE-2026-47613). Confidential information can be exposed externally.
|
| CVE-2026-18788 |
|
Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24253 |
|
Out-of-Bounds Write in dos (CVE-2026-24253)
out-of-bounds write in dos (CVE-2026-24253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47614 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47614)
SSRF in nvidia (CVE-2026-47614). Confidential information can be exposed externally.
|
| CVE-2026-47616 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47616)
SSRF in nvidia (CVE-2026-47616). Confidential information can be exposed externally.
|
| CVE-2026-47612 |
|
Path Traversal in nvidia (CVE-2026-47612)
path traversal in nvidia (CVE-2026-47612). Confidential information can be exposed externally.
|
| CVE-2026-47615 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47615)
SSRF in nvidia (CVE-2026-47615). Confidential information can be exposed externally.
|
| CVE-2026-15314 |
|
Vulnerability in tp-link (CVE-2026-15314)
vulnerability in tp-link (CVE-2026-15314). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56848 |
|
Use-After-Free in CVE-2026-56848 (CVE-2026-56848)
vulnerability in CVE-2026-56848 (CVE-2026-56848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18787 |
|
Vulnerability in CVE-2026-18787 (CVE-2026-18787)
vulnerability in CVE-2026-18787 (CVE-2026-18787). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15307 |
|
Vulnerability in django (CVE-2026-15307)
vulnerability in django (CVE-2026-15307). Successful exploitation can lead to full system takeover. Exploitable via ``django.contrib.gis.gdal.GDALRaster``.
|
| CVE-2026-18830 |
|
Vulnerability in Amazon aws (CVE-2026-18830)
vulnerability in Amazon aws (CVE-2026-18830). Confidential information can be exposed externally.
|
| CVE-2026-69100 |
|
Code Injection in CVE-2026-69100 (CVE-2026-69100)
code injection in CVE-2026-69100 (CVE-2026-69100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25292 |
|
Vulnerability in qualcomm (CVE-2026-25292)
vulnerability in qualcomm (CVE-2026-25292). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25288 |
|
Vulnerability in dos (CVE-2026-25288)
vulnerability in dos (CVE-2026-25288). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24084 |
|
Vulnerability in qualcomm (CVE-2026-24084)
vulnerability in qualcomm (CVE-2026-24084). Confidential information can be exposed externally.
|
| CVE-2026-24083 |
|
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
|
| CVE-2026-24080 |
|
Memory Corruption when handling malformed request parameters in the fingerprint TA.
Memory Corruption when handling malformed request parameters in the fingerprint TA.
|
| CVE-2026-24079 |
|
Vulnerability in qualcomm (CVE-2026-24079)
vulnerability in qualcomm (CVE-2026-24079). Confidential information can be exposed externally.
|
| CVE-2026-21366 |
|
Memory corruption while processing a packet with a size close to the maximum allowed value.
Memory corruption while processing a packet with a size close to the maximum allowed value.
|
| CVE-2026-67200 |
|
Path Traversal in path-traversal (CVE-2026-67200)
path traversal in path-traversal (CVE-2026-67200). Confidential information can be exposed externally.
|
| CVE-2026-67198 |
|
Vulnerability in CVE-2026-67198 (CVE-2026-67198)
vulnerability in CVE-2026-67198 (CVE-2026-67198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67195 |
|
Vulnerability in CVE-2026-67195 (CVE-2026-67195)
vulnerability in CVE-2026-67195 (CVE-2026-67195). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18650 |
|
Vulnerability in privilege-escalation (CVE-2026-18650)
vulnerability in privilege-escalation (CVE-2026-18650). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18770 |
|
Vulnerability in CVE-2026-18770 (CVE-2026-18770)
vulnerability in CVE-2026-18770 (CVE-2026-18770). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17070 |
|
Vulnerability in CVE-2026-17070 (CVE-2026-17070)
vulnerability in CVE-2026-17070 (CVE-2026-17070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70373 |
|
SQL Injection in CVE-2026-70373 (CVE-2026-70373)
SQL injection in CVE-2026-70373 (CVE-2026-70373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63252 |
|
Vulnerability in eclipse (CVE-2026-63252)
vulnerability in eclipse (CVE-2026-63252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70371 |
|
SQL Injection in CVE-2026-70371 (CVE-2026-70371)
SQL injection in CVE-2026-70371 (CVE-2026-70371). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60007 |
|
Vulnerability in eclipse (CVE-2026-60007)
vulnerability in eclipse (CVE-2026-60007). Confidential information can be exposed externally. Exploitable via ``Basic128Rsa15``.
|
| CVE-2026-61387 |
|
Vulnerability in eclipse (CVE-2026-61387)
vulnerability in eclipse (CVE-2026-61387). Risk of unauthorized operations or information disclosure. Exploitable via ``CreateMonitoredItems``.
|
| CVE-2026-62927 |
|
Authorization Flaw in eclipse (CVE-2026-62927)
vulnerability in eclipse (CVE-2026-62927). Data can be tampered with by attackers.
|
| CVE-2026-70369 |
|
SQL Injection in CVE-2026-70369 (CVE-2026-70369)
SQL injection in CVE-2026-70369 (CVE-2026-70369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70370 |
|
SQL Injection in CVE-2026-70370 (CVE-2026-70370)
SQL injection in CVE-2026-70370 (CVE-2026-70370). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70372 |
|
SQL Injection in CVE-2026-70372 (CVE-2026-70372)
SQL injection in CVE-2026-70372 (CVE-2026-70372). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58080 |
|
Vulnerability in eclipse (CVE-2026-58080)
vulnerability in eclipse (CVE-2026-58080). Data can be tampered with by attackers. Exploitable via ``RoleMapper``.
|
| CVE-2026-10710 |
|
Vulnerability in CVE-2026-10710 (CVE-2026-10710)
vulnerability in CVE-2026-10710 (CVE-2026-10710). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10709 |
|
Vulnerability in CVE-2026-10709 (CVE-2026-10709)
vulnerability in CVE-2026-10709 (CVE-2026-10709). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18806 |
|
Vulnerability in CVE-2026-18806 (CVE-2026-18806)
vulnerability in CVE-2026-18806 (CVE-2026-18806). Data can be tampered with by attackers.
|
| CVE-2026-11368 |
|
Use-After-Free in c (CVE-2026-11368)
vulnerability in c (CVE-2026-11368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14838 |
|
Vulnerability in CVE-2026-14838 (CVE-2026-14838)
vulnerability in CVE-2026-14838 (CVE-2026-14838). Confidential information can be exposed externally.
|
| CVE-2026-67243 |
|
Unrestricted File Upload in jvn (CVE-2026-67243)
vulnerability in jvn (CVE-2026-67243). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18755 |
|
Vulnerability in CVE-2026-18755 (CVE-2026-18755)
vulnerability in CVE-2026-18755 (CVE-2026-18755). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64563 |
|
Vulnerability in c (CVE-2026-64563)
vulnerability in c (CVE-2026-64563). Successful exploitation can lead to full system takeover.
|