Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-67527 Vulnerability in CVE-2026-67527 (CVE-2026-67527)
vulnerability in CVE-2026-67527 (CVE-2026-67527). Data can be tampered with by attackers. Exploitable via `PATCH /api/v3/work_packages/{id}`. Mitigation: upgrade to `17.6.0` or later.
CVE-2026-61536 Code Injection in CVE-2026-61536 (CVE-2026-61536)
code injection in CVE-2026-61536 (CVE-2026-61536). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.4.2` or later.
CVE-2026-18140 Vulnerability in Amazon dos (CVE-2026-18140)
vulnerability in Amazon dos (CVE-2026-18140). Risk of unauthorized operations or information disclosure.
CVE-2026-9322 Vulnerability in dos (CVE-2026-9322)
vulnerability in dos (CVE-2026-9322). Risk of unauthorized operations or information disclosure.
CVE-2026-12945 Vulnerability in langflow (CVE-2026-12945)
vulnerability in langflow (CVE-2026-12945). Confidential information can be exposed externally.
CVE-2026-12996 Out-of-Bounds Read in dos (CVE-2026-12996)
vulnerability in dos (CVE-2026-12996). Confidential information can be exposed externally.
CVE-2026-12932 Vulnerability in dos (CVE-2026-12932)
vulnerability in dos (CVE-2026-12932). Confidential information can be exposed externally.
CVE-2026-11885 Vulnerability in CVE-2026-11885 (CVE-2026-11885)
vulnerability in CVE-2026-11885 (CVE-2026-11885). Data can be tampered with by attackers.
CVE-2026-13117 Use-After-Free in dos (CVE-2026-13117)
vulnerability in dos (CVE-2026-13117). Confidential information can be exposed externally.
CVE-2026-11771 Vulnerability in openvpn (CVE-2026-11771)
vulnerability in openvpn (CVE-2026-11771). Risk of unauthorized operations or information disclosure.
CVE-2026-58222 Vulnerability in privilege-escalation (CVE-2026-58222)
vulnerability in privilege-escalation (CVE-2026-58222). Successful exploitation can lead to full system takeover.
CVE-2026-57862 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57862)
SSRF in ssrf (CVE-2026-57862). Confidential information can be exposed externally.
CVE-2026-28813 Cross-Site Request Forgery (CSRF) in apache (CVE-2026-28813)
vulnerability in apache (CVE-2026-28813). Successful exploitation can lead to full system takeover.
CVE-2026-28814 Vulnerability in apache (CVE-2026-28814)
vulnerability in apache (CVE-2026-28814). Confidential information can be exposed externally.
CVE-2026-28811 Vulnerability in apache (CVE-2026-28811)
vulnerability in apache (CVE-2026-28811). Confidential information can be exposed externally.
CVE-2026-15658 Vulnerability in CVE-2026-15658 (CVE-2026-15658)
vulnerability in CVE-2026-15658 (CVE-2026-15658). Confidential information can be exposed externally.
CVE-2026-10842 Vulnerability in ibm (CVE-2026-10842)
vulnerability in ibm (CVE-2026-10842). Confidential information can be exposed externally.
CVE-2026-62663 Path Traversal in path-traversal (CVE-2026-62663)
path traversal in path-traversal (CVE-2026-62663). Confidential information can be exposed externally.
CVE-2026-41186 Information Disclosure in tigera (CVE-2026-41186)
vulnerability in tigera (CVE-2026-41186). Confidential information can be exposed externally.
CVE-2026-67348 Vulnerability in CVE-2026-67348 (CVE-2026-67348)
vulnerability in CVE-2026-67348 (CVE-2026-67348). Confidential information can be exposed externally.
CVE-2026-67349 Vulnerability in CVE-2026-67349 (CVE-2026-67349)
vulnerability in CVE-2026-67349 (CVE-2026-67349). Confidential information can be exposed externally. Exploitable via `GET /helmValues`.
CVE-2026-11980 Vulnerability in ibm (CVE-2026-11980)
vulnerability in ibm (CVE-2026-11980). Successful exploitation can lead to full system takeover.
CVE-2026-16308 Vulnerability in dos (CVE-2026-16308)
vulnerability in dos (CVE-2026-16308). Risk of unauthorized operations or information disclosure.
CVE-2026-14980 Privilege Escalation in ssrf (CVE-2026-14980)
vulnerability in ssrf (CVE-2026-14980). Confidential information can be exposed externally.
CVE-2026-67346 SSRF (Server-Side Request Forgery) in CVE-2026-67346 (CVE-2026-67346)
SSRF in CVE-2026-67346 (CVE-2026-67346). Confidential information can be exposed externally.
CVE-2026-12947 Vulnerability in ibm (CVE-2026-12947)
vulnerability in ibm (CVE-2026-12947). Confidential information can be exposed externally.
CVE-2026-6540 Path Traversal in tigera (CVE-2026-6540)
path traversal in tigera (CVE-2026-6540). Confidential information can be exposed externally.
CVE-2026-11897 Vulnerability in dos (CVE-2026-11897)
vulnerability in dos (CVE-2026-11897). Confidential information can be exposed externally.
CVE-2026-67345 Vulnerability in CVE-2026-67345 (CVE-2026-67345)
vulnerability in CVE-2026-67345 (CVE-2026-67345). Confidential information can be exposed externally.
CVE-2026-14522 OS Command Injection in ibm (CVE-2026-14522)
OS command injection in ibm (CVE-2026-14522). Successful exploitation can lead to full system takeover.
CVE-2026-14519 Path Traversal in path-traversal (CVE-2026-14519)
path traversal in path-traversal (CVE-2026-14519). Confidential information can be exposed externally.
CVE-2026-60074 Vulnerability in CVE-2026-60074 (CVE-2026-60074)
vulnerability in CVE-2026-60074 (CVE-2026-60074). Risk of unauthorized operations or information disclosure.
CVE-2026-60075 Vulnerability in dos (CVE-2026-60075)
vulnerability in dos (CVE-2026-60075). Risk of unauthorized operations or information disclosure.
CVE-2026-5219 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-5219)
vulnerability in csrf (CVE-2026-5219). Confidential information can be exposed externally.
CVE-2026-56428 Vulnerability in CVE-2026-56428 (CVE-2026-56428)
vulnerability in CVE-2026-56428 (CVE-2026-56428). Successful exploitation can lead to full system takeover.
CVE-2026-54365 Vulnerability in deserialization (CVE-2026-54365)
vulnerability in deserialization (CVE-2026-54365). Data can be tampered with by attackers.
CVE-2026-54367 Vulnerability in CVE-2026-54367 (CVE-2026-54367)
vulnerability in CVE-2026-54367 (CVE-2026-54367). Data can be tampered with by attackers.
CVE-2026-12722 Vulnerability in CVE-2026-12722 (CVE-2026-12722)
vulnerability in CVE-2026-12722 (CVE-2026-12722). Confidential information can be exposed externally.
CVE-2026-54368 SQL Injection in sqli (CVE-2026-54368)
SQL injection in sqli (CVE-2026-54368). Successful exploitation can lead to full system takeover.
CVE-2026-54366 XXE (XML External Entity) in CVE-2026-54366 (CVE-2026-54366)
vulnerability in CVE-2026-54366 (CVE-2026-54366). Confidential information can be exposed externally.
CVE-2026-41703 Out-of-Bounds Read in dos (CVE-2026-41703)
vulnerability in dos (CVE-2026-41703). Confidential information can be exposed externally.
CVE-2026-67351 Vulnerability in CVE-2026-67351 (CVE-2026-67351)
vulnerability in CVE-2026-67351 (CVE-2026-67351). Successful exploitation can lead to full system takeover.
CVE-2026-57859 Unsafe Deserialization in deserialization (CVE-2026-57859)
vulnerability in deserialization (CVE-2026-57859). Successful exploitation can lead to full system takeover.
CVE-2026-18378 SSRF (Server-Side Request Forgery) in redhat (CVE-2026-18378)
SSRF in redhat (CVE-2026-18378). Confidential information can be exposed externally.
CVE-2026-15397 Vulnerability in wordpress (CVE-2026-15397)
vulnerability in wordpress (CVE-2026-15397). Successful exploitation can lead to full system takeover.
CVE-2026-18381 SSRF (Server-Side Request Forgery) in redhat (CVE-2026-18381)
SSRF in redhat (CVE-2026-18381). Confidential information can be exposed externally.
CVE-2026-22622 OS Command Injection in CVE-2026-22622 (CVE-2026-22622)
OS command injection in CVE-2026-22622 (CVE-2026-22622). Successful exploitation can lead to full system takeover.
CVE-2026-22621 OS Command Injection in CVE-2026-22621 (CVE-2026-22621)
OS command injection in CVE-2026-22621 (CVE-2026-22621). Confidential information can be exposed externally.
CVE-2026-22620 SQL Injection in CVE-2026-22620 (CVE-2026-22620)
SQL injection in CVE-2026-22620 (CVE-2026-22620). Risk of unauthorized operations or information disclosure.
CVE-2026-18361 Cross-Site Scripting (XSS) in CVE-2026-18361 (CVE-2026-18361)
cross-site scripting in CVE-2026-18361 (CVE-2026-18361). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →