Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-3012 |
|
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate...
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate...
|
| CVE-2026-47202 |
|
Authentication Bypass in CVE-2026-47202 (CVE-2026-47202)
authentication bypass in CVE-2026-47202 (CVE-2026-47202). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0.2` or later.
|
| CVE-2026-41164 |
|
Vulnerability in github.com/nuts-foundation/nuts-node (CVE-2026-41164)
vulnerability in github.com/nuts-foundation/nuts-node (CVE-2026-41164). Risk of unauthorized operations or information disclosure. Exploitable via ``iss``.
|
| CVE-2026-39969 |
|
Authentication Bypass in CVE-2026-39969 (CVE-2026-39969)
authentication bypass in CVE-2026-39969 (CVE-2026-39969). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook`.
|
| CVE-2026-46654 |
|
Vulnerability in p3-challenger (CVE-2026-46654)
vulnerability in p3-challenger (CVE-2026-46654). Risk of unauthorized operations or information disclosure. Exploitable via ``transcript_malleability``. Mitigation: upgrade to `0.5.3` or later.
|
| CVE-2026-46539 |
|
Vulnerability in nimiq-primitives (CVE-2026-46539)
vulnerability in nimiq-primitives (CVE-2026-46539). Data can be tampered with by attackers. Exploitable via ``get_interlink_hops``.
|
| CVE-2026-45792 |
|
Vulnerability in rtk (CVE-2026-45792)
vulnerability in rtk (CVE-2026-45792). Data can be tampered with by attackers. Exploitable via ``strip_lines_matching``. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-25602 |
|
Vulnerability in CVE-2026-25602 (CVE-2026-25602)
vulnerability in CVE-2026-25602 (CVE-2026-25602). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33233 |
|
Code Injection in deserialization (CVE-2026-33233)
code injection in deserialization (CVE-2026-33233). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32323 |
|
Privilege Escalation in privilege-escalation (CVE-2026-32323)
vulnerability in privilege-escalation (CVE-2026-32323). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45058 |
|
Vulnerability in electerm (CVE-2026-45058)
vulnerability in electerm (CVE-2026-45058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44592 |
|
Vulnerability in CVE-2026-44592 (CVE-2026-44592)
vulnerability in CVE-2026-44592 (CVE-2026-44592). Data can be tampered with by attackers. Mitigation: upgrade to `1.1.1` or later.
|
| CVE-2026-44523 |
|
Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44523)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44523). Confidential information can be exposed externally. Exploitable via ``JWT_SECRET``. Mitigation: upgrade to `0.0.0-20260501152247-18b587758667` or later.
|
| CVE-2026-44308 |
|
Vulnerability in io.awspring.cloud:spring-cloud-aws-sns (CVE-2026-44308)
vulnerability in io.awspring.cloud:spring-cloud-aws-sns (CVE-2026-44308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45055 |
|
Vulnerability in CVE-2026-45055 (CVE-2026-45055)
vulnerability in CVE-2026-45055 (CVE-2026-45055). Confidential information can be exposed externally. Exploitable via `POST /index.php`. Mitigation: upgrade to `6.7.2` or later.
|
| CVE-2026-44999 |
|
Vulnerability in openclaw (CVE-2026-44999)
vulnerability in openclaw (CVE-2026-44999). Risk of unauthorized operations or information disclosure. Exploitable via ``openclaw``. Mitigation: upgrade to `2026.4.20` or later.
|
| CVE-2026-45022 |
|
Vulnerability in github.com/go-git/go-git/v6 (CVE-2026-45022)
vulnerability in github.com/go-git/go-git/v6 (CVE-2026-45022). Data can be tampered with by attackers. Exploitable via ``commit``. Mitigation: upgrade to `6.0.0-alpha.3` or later.
|
| CVE-2026-42575 |
|
Vulnerability in chainguard.dev/apko (CVE-2026-42575)
vulnerability in chainguard.dev/apko (CVE-2026-42575). Data can be tampered with by attackers. Exploitable via ``APKINDEX.tar.gz``. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-41432 |
|
Vulnerability in github.com/QuantumNous/new-api (CVE-2026-41432)
vulnerability in github.com/QuantumNous/new-api (CVE-2026-41432). Data can be tampered with by attackers. Exploitable via `POST /api/user/pay`. Mitigation: upgrade to `0.12.10` or later.
|
| CVE-2026-42206 |
|
Vulnerability in roadiz/openid (CVE-2026-42206)
vulnerability in roadiz/openid (CVE-2026-42206). Risk of unauthorized operations or information disclosure. Exploitable via ``OpenIdJwtConfigurationFactory``. Mitigation: upgrade to `2.7.10` or later.
|
| CVE-2026-31835 |
|
Vulnerability in dos (CVE-2026-31835)
vulnerability in dos (CVE-2026-31835). Risk of unauthorized operations or information disclosure. Exploitable via ``authenticatorData``.
|
| CVE-2026-35051 |
|
Vulnerability in github.com/traefik/traefik (CVE-2026-35051)
vulnerability in github.com/traefik/traefik (CVE-2026-35051). Confidential information can be exposed externally. Exploitable via ``ForwardAuth``. Mitigation: upgrade to `2.11.43` or later.
|
| CVE-2026-40323 |
|
Vulnerability in succinct (CVE-2026-40323)
vulnerability in succinct (CVE-2026-40323). Data can be tampered with by attackers.
|
| CVE-2026-39411 |
|
Authentication Bypass in lobehub (CVE-2026-39411)
authentication bypass in lobehub (CVE-2026-39411). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.1.48` or later.
|
| CVE-2026-39366 |
|
Vulnerability in wwbn (CVE-2026-39366)
vulnerability in wwbn (CVE-2026-39366). Data can be tampered with by attackers.
|
| CVE-2026-34778 |
|
Vulnerability in electronjs (CVE-2026-34778)
vulnerability in electronjs (CVE-2026-34778). Data can be tampered with by attackers.
|
| CVE-2026-34061 |
|
Vulnerability in nimiq (CVE-2026-34061)
vulnerability in nimiq (CVE-2026-34061). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30603 |
|
Vulnerability in CVE-2026-30603 (CVE-2026-30603)
vulnerability in CVE-2026-30603 (CVE-2026-30603). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4984 |
|
Vulnerability in botpress (CVE-2026-4984)
vulnerability in botpress (CVE-2026-4984). Confidential information can be exposed externally.
|
| CVE-2026-4115 |
|
Vulnerability in c (CVE-2026-4115)
vulnerability in c (CVE-2026-4115). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33221 |
|
Vulnerability in github.com/nhost/nhost (CVE-2026-33221)
vulnerability in github.com/nhost/nhost (CVE-2026-33221). Risk of unauthorized operations or information disclosure. Exploitable via ``getMultipartFile``. Mitigation: upgrade to `0.0.0-20260318074820-c4bd53f042d7` or later.
|
| CVE-2026-28500 |
|
Vulnerability in onnx (CVE-2026-28500)
vulnerability in onnx (CVE-2026-28500). Confidential information can be exposed externally. Mitigation: upgrade to `1.21.0rc1` or later.
|
| CVE-2026-32597 |
|
Vulnerability in pyjwt (CVE-2026-32597)
vulnerability in pyjwt (CVE-2026-32597). Data can be tampered with by attackers. Exploitable via ``crit``. Mitigation: upgrade to `2.12.0` or later.
|
| CVE-2026-30798 |
|
Vulnerability in rustdesk (CVE-2026-30798)
vulnerability in rustdesk (CVE-2026-30798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30792 |
|
Vulnerability in rustdesk (CVE-2026-30792)
vulnerability in rustdesk (CVE-2026-30792). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71057 |
|
Authentication Bypass in CVE-2025-71057 (CVE-2025-71057)
authentication bypass in CVE-2025-71057 (CVE-2025-71057). Data can be tampered with by attackers.
|
| CVE-2026-26007 |
|
Vulnerability in cryptography (CVE-2026-26007)
vulnerability in cryptography (CVE-2026-26007). Confidential information can be exposed externally. Exploitable via ``public_key_from_numbers``. Mitigation: upgrade to `46.0.5` or later.
|
| CVE-2026-21527 |
|
Vulnerability in microsoft (CVE-2026-21527)
vulnerability in microsoft (CVE-2026-21527). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-59700 |
|
Vulnerability in entrust (CVE-2025-59700)
vulnerability in entrust (CVE-2025-59700). Data can be tampered with by attackers.
|
| CVE-2025-34337 |
|
Vulnerability in CVE-2025-34337 (CVE-2025-34337)
vulnerability in CVE-2025-34337 (CVE-2025-34337). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56438 |
|
Vulnerability in CVE-2025-56438 (CVE-2025-56438)
vulnerability in CVE-2025-56438 (CVE-2025-56438). Successful exploitation can lead to full system takeover.
|
| CVE-2024-12369 |
|
Vulnerability in CVE-2024-12369 (CVE-2024-12369)
vulnerability in CVE-2024-12369 (CVE-2024-12369). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-37370 |
|
Vulnerability in mit (CVE-2024-37370)
vulnerability in mit (CVE-2024-37370). Confidential information can be exposed externally.
|
| CVE-2023-48238 |
|
Vulnerability in json-web-token (CVE-2023-48238)
vulnerability in json-web-token (CVE-2023-48238). Data can be tampered with by attackers. Exploitable via ``decode``. Mitigation: upgrade to `4.0.0` or later.
|
| CVE-2023-38831 KEV |
|
[KEV] Vulnerability in Rarlab winrar (CVE-2023-38831)
vulnerability in Rarlab winrar (CVE-2023-38831). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2022-31877 |
|
Vulnerability in msi (CVE-2022-31877)
vulnerability in msi (CVE-2022-31877). Successful exploitation can lead to full system takeover.
|
| CVE-2018-10626 |
|
Vulnerability in medtronic (CVE-2018-10626)
vulnerability in medtronic (CVE-2018-10626). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-7798 |
|
Vulnerability in schneider-electric (CVE-2018-7798)
vulnerability in schneider-electric (CVE-2018-7798). Data can be tampered with by attackers.
|
| CVE-2022-20795 |
|
Vulnerability in dos (CVE-2022-20795)
vulnerability in dos (CVE-2022-20795). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-0715 |
|
Authentication Bypass in schneider-electric (CVE-2022-0715)
authentication bypass in schneider-electric (CVE-2022-0715). Data can be tampered with by attackers.
|