Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19426 |
|
Vulnerability in CVE-2026-19426 (CVE-2026-19426)
vulnerability in CVE-2026-19426 (CVE-2026-19426). Data can be tampered with by attackers.
|
| CVE-2026-73246 |
|
Information Disclosure in CVE-2026-73246 (CVE-2026-73246)
vulnerability in CVE-2026-73246 (CVE-2026-73246). Confidential information can be exposed externally. Exploitable via `GET /worker`. Mitigation: upgrade to `2.0.0-rc6` or later.
|
| CVE-2026-73245 |
|
Vulnerability in CVE-2026-73245 (CVE-2026-73245)
vulnerability in CVE-2026-73245 (CVE-2026-73245). Risk of unauthorized operations or information disclosure. Exploitable via `GET /env`. Mitigation: upgrade to `2.0.0-rc6` or later.
|
| CVE-2026-66875 |
|
Vulnerability in CVE-2026-66875 (CVE-2026-66875)
vulnerability in CVE-2026-66875 (CVE-2026-66875). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66098 |
|
Vulnerability in CVE-2026-66098 (CVE-2026-66098)
vulnerability in CVE-2026-66098 (CVE-2026-66098). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73222 |
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
| CVE-2026-61367 |
|
Vulnerability in microsoft (CVE-2026-61367)
vulnerability in microsoft (CVE-2026-61367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50516 |
|
Vulnerability in microsoft (CVE-2026-50516)
vulnerability in microsoft (CVE-2026-50516). Confidential information can be exposed externally.
|
| CVE-2026-42976 |
|
Vulnerability in microsoft (CVE-2026-42976)
vulnerability in microsoft (CVE-2026-42976). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64921 |
|
Vulnerability in microsoft (CVE-2026-64921)
vulnerability in microsoft (CVE-2026-64921). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62777 |
|
Vulnerability in microsoft (CVE-2026-62777)
vulnerability in microsoft (CVE-2026-62777). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61365 |
|
Vulnerability in microsoft (CVE-2026-61365)
vulnerability in microsoft (CVE-2026-61365). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61364 |
|
Vulnerability in microsoft (CVE-2026-61364)
vulnerability in microsoft (CVE-2026-61364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61356 |
|
Vulnerability in microsoft (CVE-2026-61356)
vulnerability in microsoft (CVE-2026-61356). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72920 |
|
Vulnerability in CVE-2026-72920 (CVE-2026-72920)
vulnerability in CVE-2026-72920 (CVE-2026-72920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72748 |
|
Vulnerability in dos (CVE-2026-72748)
vulnerability in dos (CVE-2026-72748). Data can be tampered with by attackers.
|
| CVE-2026-58115 |
|
Vulnerability in CVE-2026-58115 (CVE-2026-58115)
vulnerability in CVE-2026-58115 (CVE-2026-58115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72605 |
|
Vulnerability in CVE-2026-72605 (CVE-2026-72605)
vulnerability in CVE-2026-72605 (CVE-2026-72605). Data can be tampered with by attackers. Exploitable via `POST /auth/profile/create`.
|
| CVE-2026-72542 |
|
Vulnerability in CVE-2026-72542 (CVE-2026-72542)
vulnerability in CVE-2026-72542 (CVE-2026-72542). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72541 |
|
Vulnerability in CVE-2026-72541 (CVE-2026-72541)
vulnerability in CVE-2026-72541 (CVE-2026-72541). Data can be tampered with by attackers.
|
| CVE-2026-72535 |
|
Vulnerability in CVE-2026-72535 (CVE-2026-72535)
vulnerability in CVE-2026-72535 (CVE-2026-72535). Data can be tampered with by attackers.
|
| CVE-2026-72536 |
|
Vulnerability in CVE-2026-72536 (CVE-2026-72536)
vulnerability in CVE-2026-72536 (CVE-2026-72536). Data can be tampered with by attackers.
|
| CVE-2026-15563 |
|
Vulnerability in dos (CVE-2026-15563)
vulnerability in dos (CVE-2026-15563). Confidential information can be exposed externally.
|
| CVE-2026-18941 |
|
Vulnerability in dos (CVE-2026-18941)
vulnerability in dos (CVE-2026-18941). Confidential information can be exposed externally.
|
| CVE-2026-15581 |
|
Vulnerability in CVE-2026-15581 (CVE-2026-15581)
vulnerability in CVE-2026-15581 (CVE-2026-15581). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15683 |
|
Vulnerability in CVE-2025-15683 (CVE-2025-15683)
vulnerability in CVE-2025-15683 (CVE-2025-15683). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15681 |
|
Vulnerability in CVE-2025-15681 (CVE-2025-15681)
vulnerability in CVE-2025-15681 (CVE-2025-15681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72871 |
|
Vulnerability in CVE-2026-72871 (CVE-2026-72871)
vulnerability in CVE-2026-72871 (CVE-2026-72871). Data can be tampered with by attackers.
|
| CVE-2026-72688 |
|
Vulnerability in CVE-2026-72688 (CVE-2026-72688)
vulnerability in CVE-2026-72688 (CVE-2026-72688). Confidential information can be exposed externally.
|
| CVE-2026-72593 |
|
Vulnerability in CVE-2026-72593 (CVE-2026-72593)
vulnerability in CVE-2026-72593 (CVE-2026-72593). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72586 |
|
Vulnerability in CVE-2026-72586 (CVE-2026-72586)
vulnerability in CVE-2026-72586 (CVE-2026-72586). Confidential information can be exposed externally.
|
| CVE-2026-72577 |
|
Vulnerability in flask (CVE-2026-72577)
vulnerability in flask (CVE-2026-72577). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55814 |
|
Vulnerability in apache (CVE-2026-55814)
vulnerability in apache (CVE-2026-55814). Confidential information can be exposed externally.
|
| CVE-2026-46409 |
|
Code Injection in CVE-2026-46409 (CVE-2026-46409)
code injection in CVE-2026-46409 (CVE-2026-46409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61808 |
|
Vulnerability in CVE-2026-61808 (CVE-2026-61808)
vulnerability in CVE-2026-61808 (CVE-2026-61808). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71409 |
|
Vulnerability in cisa (CVE-2025-71409)
vulnerability in cisa (CVE-2025-71409). Data can be tampered with by attackers.
|
| CVE-2026-63508 |
|
Vulnerability in microsoft (CVE-2026-63508)
vulnerability in microsoft (CVE-2026-63508). Confidential information can be exposed externally.
|
| CVE-2026-70559 |
|
Vulnerability in CVE-2026-70559 (CVE-2026-70559)
vulnerability in CVE-2026-70559 (CVE-2026-70559). Confidential information can be exposed externally. Exploitable via `GET /api/sysConfig/getAll`.
|
| CVE-2026-53984 |
|
Vulnerability in CVE-2026-53984 (CVE-2026-53984)
vulnerability in CVE-2026-53984 (CVE-2026-53984). Data can be tampered with by attackers.
|
| CVE-2026-53985 |
|
Vulnerability in CVE-2026-53985 (CVE-2026-53985)
vulnerability in CVE-2026-53985 (CVE-2026-53985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53977 |
|
Vulnerability in express (CVE-2026-53977)
vulnerability in express (CVE-2026-53977). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18990 |
|
Authentication Bypass in CVE-2026-18990 (CVE-2026-18990)
authentication bypass in CVE-2026-18990 (CVE-2026-18990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71319 |
|
Code Injection in @nuxt/devtools (CVE-2026-71319)
code injection in @nuxt/devtools (CVE-2026-71319). Successful exploitation can lead to full system takeover. Exploitable via ``ensureDevAuthToken``. Mitigation: upgrade to `3.3.1` or later.
|
| CVE-2026-69111 |
|
Vulnerability in dos (CVE-2026-69111)
vulnerability in dos (CVE-2026-69111). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8446 |
|
Vulnerability in langflow (CVE-2026-8446)
vulnerability in langflow (CVE-2026-8446). Confidential information can be exposed externally.
|
| CVE-2026-48911 |
|
Vulnerability in apache (CVE-2026-48911)
vulnerability in apache (CVE-2026-48911). Data can be tampered with by attackers.
|
| CVE-2026-71289 |
|
Vulnerability in c (CVE-2026-71289)
vulnerability in c (CVE-2026-71289). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71262 |
|
Vulnerability in path-traversal (CVE-2026-71262)
vulnerability in path-traversal (CVE-2026-71262). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61891 |
|
Path Traversal in eclipse (CVE-2026-61891)
path traversal in eclipse (CVE-2026-61891). Confidential information can be exposed externally. Exploitable via `GET /file`.
|
| CVE-2026-71241 |
|
Vulnerability in flask (CVE-2026-71241)
vulnerability in flask (CVE-2026-71241). Confidential information can be exposed externally.
|