Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-44544
gittuf's policy can be rolled back to prior valid versions
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header)
CVE-2026-44542
FileBrowser Public Share DELETE API Path Traversal Allows Unauthenticated Arbitrary File Deletion
CVE-2026-44283
etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
CVE-2026-44426
ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
Daptin's Session Management Vulnerability Leads to Insufficient Session Expiration After Password Change
Talos Linux has a local privilege escalation from untrusted workloads
CVE-2026-44514
Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read Kubernetes logs from authenticated users
CVE-2026-42459
Free5GC UDM has Improper Input Validation and Generation of Error Messages Containing Sensitive Information
CVE-2026-42328
go-ipld-prime's DAG-CBOR and DAG-JSON decoders have unbounded recursion depth
CVE-2026-42083
Free5GC PCF: Missing authentication middleware in Npcf_SMPolicyControl allows access to SM policy handlers and disclosure of subscriber SUPI
CVE-2026-42880
ArgoCD ServerSideDiff is vulnerable to Kubernetes Secret Extraction
CVE-2026-42082
Free5GC AMF has Missing Concurrent NAS SMC Validation During NGAP Handover
CVE-2026-42081
Free5GC AMF Bypasses UE Security Capabilities on NGAP PathSwitchRequest
CVE-2026-44503
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
CVE-2026-41050
Fleet: Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template rendering
CVE-2026-25705
Rancher Extensions have arbitrary file access via path traversal
Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure
CVE-2026-42597
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
CVE-2026-42596
Gotenberg vulnerable to unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook
Showing 1 - 20 of 1,000+ results