Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-67567 |
|
Vulnerability in c (CVE-2026-67567)
vulnerability in c (CVE-2026-67567). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63643 |
|
Vulnerability in magicmirror (CVE-2026-63643)
vulnerability in magicmirror (CVE-2026-63643). Risk of unauthorized operations or information disclosure. Exploitable via ``ADD_CALENDAR``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-72640 |
|
Vulnerability in CVE-2026-72640 (CVE-2026-72640)
vulnerability in CVE-2026-72640 (CVE-2026-72640). Confidential information can be exposed externally.
|
| CVE-2026-73266 |
|
Vulnerability in CVE-2026-73266 (CVE-2026-73266)
vulnerability in CVE-2026-73266 (CVE-2026-73266). Confidential information can be exposed externally.
|
| CVE-2026-70398 |
|
Vulnerability in CVE-2026-70398 (CVE-2026-70398)
vulnerability in CVE-2026-70398 (CVE-2026-70398). Confidential information can be exposed externally.
|
| CVE-2026-72526 |
|
Vulnerability in privilege-escalation (CVE-2026-72526)
vulnerability in privilege-escalation (CVE-2026-72526). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73079 |
|
Path Traversal in path-traversal (CVE-2026-73079)
path traversal in path-traversal (CVE-2026-73079). Confidential information can be exposed externally. Exploitable via `POST /responses/`. Mitigation: upgrade to `0.1.169` or later.
|
| CVE-2026-16456 |
|
Vulnerability in CVE-2026-16456 (CVE-2026-16456)
vulnerability in CVE-2026-16456 (CVE-2026-16456). Confidential information can be exposed externally. Exploitable via ``loadSecret``.
|
| CVE-2026-44964 |
|
Vulnerability in c (CVE-2026-44964)
vulnerability in c (CVE-2026-44964). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44945 |
|
Vulnerability in privilege-escalation (CVE-2026-44945)
vulnerability in privilege-escalation (CVE-2026-44945). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54663 |
|
Vulnerability in swagger-typescript-api (CVE-2026-54663)
vulnerability in swagger-typescript-api (CVE-2026-54663). Risk of unauthorized operations or information disclosure. Exploitable via `GET /INTERNAL_ONLY_PATH/secret.json`. Mitigation: upgrade to `13.12.2` or later.
|
| CVE-2026-43910 |
|
Vulnerability in io.appium:java-client (CVE-2026-43910)
vulnerability in io.appium:java-client (CVE-2026-43910). Confidential information can be exposed externally. Exploitable via `POST /wd/hub/session`. Mitigation: upgrade to `10.1.1` or later.
|
| CVE-2026-17107 |
|
Vulnerability in CVE-2026-17107 (CVE-2026-17107)
vulnerability in CVE-2026-17107 (CVE-2026-17107). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42933 |
|
Vulnerability in CVE-2026-42933 (CVE-2026-42933)
vulnerability in CVE-2026-42933 (CVE-2026-42933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13062 |
|
Vulnerability in mongodb (CVE-2026-13062)
vulnerability in mongodb (CVE-2026-13062). Data can be tampered with by attackers.
|
| CVE-2026-73424 |
|
Vulnerability in @astrojs/vercel (CVE-2026-73424)
vulnerability in @astrojs/vercel (CVE-2026-73424). Risk of unauthorized operations or information disclosure. Exploitable via `GET /_isr`. Mitigation: upgrade to `10.0.2` or later.
|
| CVE-2026-16158 |
|
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
|
| CVE-2026-15183 |
|
SQL Injection in privilege-escalation (CVE-2026-15183)
SQL injection in privilege-escalation (CVE-2026-15183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56675 |
|
Authentication Bypass in CVE-2026-56675 (CVE-2026-56675)
authentication bypass in CVE-2026-56675 (CVE-2026-56675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12879 |
|
Vulnerability in CVE-2026-12879 (CVE-2026-12879)
vulnerability in CVE-2026-12879 (CVE-2026-12879). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53513 |
|
Vulnerability in @better-auth/sso (CVE-2026-53513)
vulnerability in @better-auth/sso (CVE-2026-53513). Confidential information can be exposed externally. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53514 |
|
Authentication Bypass in better-auth (CVE-2026-53514)
authentication bypass in better-auth (CVE-2026-53514). Confidential information can be exposed externally. Exploitable via ``organization``. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-55430 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-55430)
vulnerability in github.com/coder/coder/v2 (CVE-2026-55430). Confidential information can be exposed externally. Exploitable via ``Host``. Mitigation: upgrade to `2.29.17` or later.
|
| CVE-2026-49086 |
|
Vulnerability in org.apache.camel:camel-dapr (CVE-2026-49086)
vulnerability in org.apache.camel:camel-dapr (CVE-2026-49086). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46592 |
|
Vulnerability in org.apache.camel:camel-cxf-soap (CVE-2026-46592)
vulnerability in org.apache.camel:camel-cxf-soap (CVE-2026-46592). Confidential information can be exposed externally. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-53931 |
|
Vulnerability in nocodb (CVE-2026-53931)
vulnerability in nocodb (CVE-2026-53931). Risk of unauthorized operations or information disclosure. Exploitable via ``axiosRequestMake``.
|
| CVE-2026-50169 |
|
Information Disclosure in @angular/service-worker (CVE-2026-50169)
vulnerability in @angular/service-worker (CVE-2026-50169). Risk of unauthorized operations or information disclosure. Exploitable via ``Request``. Mitigation: upgrade to `21.2.15` or later.
|
| CVE-2026-9595 |
|
Vulnerability in webpack-dev-server (CVE-2026-9595)
vulnerability in webpack-dev-server (CVE-2026-9595). Risk of unauthorized operations or information disclosure. Exploitable via ``Origin``. Mitigation: upgrade to `5.2.5` or later.
|
| CVE-2026-49821 |
|
Vulnerability in github.com/fission/fission (CVE-2026-49821)
vulnerability in github.com/fission/fission (CVE-2026-49821). Confidential information can be exposed externally. Exploitable via ``buildermgr``. Mitigation: upgrade to `1.24.0` or later.
|
| CVE-2026-36608 |
|
Vulnerability in CVE-2026-36608 (CVE-2026-36608)
vulnerability in CVE-2026-36608 (CVE-2026-36608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0098 |
|
Vulnerability in google (CVE-2026-0098)
vulnerability in google (CVE-2026-0098). Successful exploitation can lead to full system takeover.
|
| CVE-2025-48570 |
|
Vulnerability in google (CVE-2025-48570)
vulnerability in google (CVE-2025-48570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47122 |
|
Vulnerability in github.com/sparkle-project/Sparkle (CVE-2026-47122)
vulnerability in github.com/sparkle-project/Sparkle (CVE-2026-47122). Risk of unauthorized operations or information disclosure. Exploitable via ``SPUSentUpdateAppcastItemData``.
|
| CVE-2026-44494 |
|
Vulnerability in axios (CVE-2026-44494)
vulnerability in axios (CVE-2026-44494). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-48522 |
|
Vulnerability in pyjwt (CVE-2026-48522)
vulnerability in pyjwt (CVE-2026-48522). Risk of unauthorized operations or information disclosure. Exploitable via ``uri``. Mitigation: upgrade to `2.13.0` or later.
|
| CVE-2026-3160 |
|
Vulnerability in gitlab (CVE-2026-3160)
vulnerability in gitlab (CVE-2026-3160). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.9.7, 18.10.6, 18.11.3` or later.
|
| CVE-2026-45003 |
|
Vulnerability in openclaw (CVE-2026-45003)
vulnerability in openclaw (CVE-2026-45003). Confidential information can be exposed externally. Mitigation: upgrade to `2026.4.22` or later.
|
| CVE-2026-44992 |
|
Vulnerability in openclaw (CVE-2026-44992)
vulnerability in openclaw (CVE-2026-44992). Confidential information can be exposed externally. Exploitable via ``openclaw``. Mitigation: upgrade to `2026.4.20` or later.
|
| CVE-2026-42313 |
|
Vulnerability in pyload-ng (CVE-2026-42313)
vulnerability in pyload-ng (CVE-2026-42313). Confidential information can be exposed externally. Exploitable via ``ADMIN_ONLY_CORE_OPTIONS``. Mitigation: upgrade to `0.5.0b3.dev100` or later.
|
| CVE-2026-45182 |
|
Vulnerability in CVE-2026-45182 (CVE-2026-45182)
vulnerability in CVE-2026-45182 (CVE-2026-45182). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42043 |
|
Vulnerability in axios (CVE-2026-42043)
vulnerability in axios (CVE-2026-42043). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.15.1` or later.
|
| CVE-2026-39906 |
|
Vulnerability in csharp (CVE-2026-39906)
vulnerability in csharp (CVE-2026-39906). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39961 |
|
Privilege Escalation in github.com/aiven/aiven-operator (CVE-2026-39961)
vulnerability in github.com/aiven/aiven-operator (CVE-2026-39961). Confidential information can be exposed externally. Mitigation: upgrade to `0.37.0` or later.
|
| CVE-2025-62718 |
|
Vulnerability in axios (CVE-2025-62718)
vulnerability in axios (CVE-2025-62718). Confidential information can be exposed externally. Exploitable via ``NO_PROXY``. Mitigation: upgrade to `0.31.0` or later.
|
| CVE-2026-27124 |
|
Vulnerability in jlowin (CVE-2026-27124)
vulnerability in jlowin (CVE-2026-27124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41365 |
|
Vulnerability in openclaw (CVE-2026-41365)
vulnerability in openclaw (CVE-2026-41365). Risk of unauthorized operations or information disclosure. Exploitable via ``openclaw``. Mitigation: upgrade to `2026.3.31` or later.
|
| CVE-2026-0013 |
|
Vulnerability in google (CVE-2026-0013)
vulnerability in google (CVE-2026-0013). Successful exploitation can lead to full system takeover.
|
| CVE-2025-11393 |
|
Vulnerability in CVE-2025-11393 (CVE-2025-11393)
vulnerability in CVE-2025-11393 (CVE-2025-11393). Confidential information can be exposed externally.
|
| CVE-2022-36537 KEV |
|
[KEV] Vulnerability in Zk framework zk-framework (CVE-2022-36537)
vulnerability in Zk framework zk-framework (CVE-2022-36537). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-25740 |
|
Vulnerability in k8s.io/kubernetes (CVE-2021-25740)
vulnerability in k8s.io/kubernetes (CVE-2021-25740). Risk of unauthorized operations or information disclosure.
|