Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15416 |
|
Vulnerability in CVE-2026-15416 (CVE-2026-15416)
vulnerability in CVE-2026-15416 (CVE-2026-15416). Confidential information can be exposed externally.
|
| CVE-2026-44767 |
|
Cross-Site Scripting (XSS) in CVE-2026-44767 (CVE-2026-44767)
cross-site scripting in CVE-2026-44767 (CVE-2026-44767). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62327 |
|
Vulnerability in CVE-2026-62327 (CVE-2026-62327)
vulnerability in CVE-2026-62327 (CVE-2026-62327). Confidential information can be exposed externally.
|
| CVE-2026-59801 |
|
Vulnerability in dos (CVE-2026-59801)
vulnerability in dos (CVE-2026-59801). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6847 |
|
Vulnerability in CVE-2026-6847 (CVE-2026-6847)
vulnerability in CVE-2026-6847 (CVE-2026-6847). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22096 |
|
Vulnerability in CVE-2026-22096 (CVE-2026-22096)
vulnerability in CVE-2026-22096 (CVE-2026-22096). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15491 |
|
Authentication Bypass in CVE-2026-15491 (CVE-2026-15491)
authentication bypass in CVE-2026-15491 (CVE-2026-15491). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57475 |
|
Vulnerability in deloitte (CVE-2026-57475)
vulnerability in deloitte (CVE-2026-57475). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57476 |
|
Vulnerability in deloitte (CVE-2026-57476)
vulnerability in deloitte (CVE-2026-57476). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56675 |
|
Authentication Bypass in CVE-2026-56675 (CVE-2026-56675)
authentication bypass in CVE-2026-56675 (CVE-2026-56675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38059 |
|
Vulnerability in CVE-2026-38059 (CVE-2026-38059)
vulnerability in CVE-2026-38059 (CVE-2026-38059). Confidential information can be exposed externally.
|
| CVE-2026-40006 |
|
Vulnerability in apache (CVE-2026-40006)
vulnerability in apache (CVE-2026-40006). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58123 |
|
Vulnerability in CVE-2026-58123 (CVE-2026-58123)
vulnerability in CVE-2026-58123 (CVE-2026-58123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55605 |
|
Vulnerability in @arikusi/deepseek-mcp-server (CVE-2026-55605)
vulnerability in @arikusi/deepseek-mcp-server (CVE-2026-55605). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mcp`. Mitigation: upgrade to `1.8.0` or later.
|
| CVE-2026-0283 |
|
Vulnerability in paloaltonetworks (CVE-2026-0283)
vulnerability in paloaltonetworks (CVE-2026-0283). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59148 |
|
Vulnerability in express (CVE-2026-59148)
vulnerability in express (CVE-2026-59148). Successful exploitation can lead to full system takeover. Exploitable via `PUT /mockoon-admin/environment`.
|
| CVE-2026-61344 |
|
Vulnerability in CVE-2026-61344 (CVE-2026-61344)
vulnerability in CVE-2026-61344 (CVE-2026-61344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15192 |
|
Authentication Bypass in CVE-2026-15192 (CVE-2026-15192)
authentication bypass in CVE-2026-15192 (CVE-2026-15192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59726 |
|
OS Command Injection in CVE-2026-59726 (CVE-2026-59726)
OS command injection in CVE-2026-59726 (CVE-2026-59726). Successful exploitation can lead to full system takeover. Exploitable via `POST /mcp`.
|
| CVE-2026-59715 |
|
Vulnerability in open-webui (CVE-2026-59715)
vulnerability in open-webui (CVE-2026-59715). Risk of unauthorized operations or information disclosure. Exploitable via ``connect``. Mitigation: upgrade to `0.10.0` or later.
|
| CVE-2026-31983 |
|
Vulnerability in nozominetworks (CVE-2026-31983)
vulnerability in nozominetworks (CVE-2026-31983). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59804 |
|
Vulnerability in CVE-2026-59804 (CVE-2026-59804)
vulnerability in CVE-2026-59804 (CVE-2026-59804). Confidential information can be exposed externally.
|
| CVE-2026-59822 |
|
Authentication Bypass in litellm (CVE-2026-59822)
authentication bypass in litellm (CVE-2026-59822). Confidential information can be exposed externally. Exploitable via ``Authorization``. Mitigation: upgrade to `1.84.0` or later.
|
| CVE-2026-15063 |
|
Vulnerability in CVE-2026-15063 (CVE-2026-15063)
vulnerability in CVE-2026-15063 (CVE-2026-15063). Confidential information can be exposed externally.
|
| CVE-2026-54061 |
|
Vulnerability in github.com/dgraph-io/dgraph/v25 (CVE-2026-54061)
vulnerability in github.com/dgraph-io/dgraph/v25 (CVE-2026-54061). Data can be tampered with by attackers. Exploitable via ``StreamExtSnapshot``. Mitigation: upgrade to `25.3.5` or later.
|
| CVE-2026-51937 |
|
Vulnerability in CVE-2026-51937 (CVE-2026-51937)
vulnerability in CVE-2026-51937 (CVE-2026-51937). Confidential information can be exposed externally.
|
| CVE-2026-59705 |
|
Vulnerability in CVE-2026-59705 (CVE-2026-59705)
vulnerability in CVE-2026-59705 (CVE-2026-59705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59706 |
|
Vulnerability in ssrf (CVE-2026-59706)
vulnerability in ssrf (CVE-2026-59706). Confidential information can be exposed externally. Exploitable via `GET /api/v1/config/`.
|
| CVE-2026-58473 |
|
Vulnerability in CVE-2026-58473 (CVE-2026-58473)
vulnerability in CVE-2026-58473 (CVE-2026-58473). Confidential information can be exposed externally.
|
| CVE-2026-49471 |
|
Vulnerability in serena-agent (CVE-2026-49471)
vulnerability in serena-agent (CVE-2026-49471). Successful exploitation can lead to full system takeover. Exploitable via `Host header`. Mitigation: upgrade to `1.5.2` or later.
|
| CVE-2026-53512 |
|
Authentication Bypass in better-auth (CVE-2026-53512)
authentication bypass in better-auth (CVE-2026-53512). Confidential information can be exposed externally. Exploitable via ``oauthApplication``. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53647 |
|
Information Disclosure in CVE-2026-53647 (CVE-2026-53647)
vulnerability in CVE-2026-53647 (CVE-2026-53647). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41899 |
|
Vulnerability in CVE-2026-41899 (CVE-2026-41899)
vulnerability in CVE-2026-41899 (CVE-2026-41899). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/feedback`.
|
| CVE-2026-42331 |
|
Vulnerability in CVE-2026-42331 (CVE-2026-42331)
vulnerability in CVE-2026-42331 (CVE-2026-42331). Risk of unauthorized operations or information disclosure. Exploitable via ``gateway_id``.
|
| CVE-2026-42341 |
|
Vulnerability in CVE-2026-42341 (CVE-2026-42341)
vulnerability in CVE-2026-42341 (CVE-2026-42341). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53913 |
|
Authentication Bypass in org.apache.camel:camel-keycloak (CVE-2026-53913)
authentication bypass in org.apache.camel:camel-keycloak (CVE-2026-53913). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-14714 |
|
Authentication Bypass in CVE-2026-14714 (CVE-2026-14714)
authentication bypass in CVE-2026-14714 (CVE-2026-14714). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14622 |
|
Authentication Bypass in CVE-2026-14622 (CVE-2026-14622)
authentication bypass in CVE-2026-14622 (CVE-2026-14622). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10054 |
|
Vulnerability in CVE-2026-10054 (CVE-2026-10054)
vulnerability in CVE-2026-10054 (CVE-2026-10054). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4767 |
|
Vulnerability in CVE-2026-4767 (CVE-2026-4767)
vulnerability in CVE-2026-4767 (CVE-2026-4767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50027 |
|
Vulnerability in mcp-memory-service (CVE-2026-50027)
vulnerability in mcp-memory-service (CVE-2026-50027). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload`. Mitigation: upgrade to `10.67.1` or later.
|
| CVE-2026-13125 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-58127 |
|
Vulnerability in csharp (CVE-2026-58127)
vulnerability in csharp (CVE-2026-58127). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58126 |
|
Vulnerability in csharp (CVE-2026-58126)
vulnerability in csharp (CVE-2026-58126). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56286 |
|
Vulnerability in csrf (CVE-2026-56286)
vulnerability in csrf (CVE-2026-56286). Data can be tampered with by attackers.
|
| CVE-2026-58446 |
|
Vulnerability in nginx (CVE-2026-58446)
vulnerability in nginx (CVE-2026-58446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58375 |
|
Vulnerability in CVE-2026-58375 (CVE-2026-58375)
vulnerability in CVE-2026-58375 (CVE-2026-58375). Confidential information can be exposed externally. Exploitable via `POST /jmreport/auto/export`.
|
| CVE-2026-44949 |
|
Vulnerability in CVE-2026-44949 (CVE-2026-44949)
vulnerability in CVE-2026-44949 (CVE-2026-44949). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14162 |
|
Vulnerability in CVE-2026-14162 (CVE-2026-14162)
vulnerability in CVE-2026-14162 (CVE-2026-14162). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12819 |
|
Vulnerability in cisa (CVE-2026-12819)
vulnerability in cisa (CVE-2026-12819). Risk of unauthorized operations or information disclosure.
|