Filter and search through 392,104 vulnerabilities
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-24048 | ### Impact The `FetchUrlReader` component, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. T... | 3.5 | 225 | Neutral | No |
| Yes |
| CVE-2026-24047 | ### Impact The `resolveSafeChildPath` utility function in `@backstage/backend-plugin-api`, which is used to prevent path traversal attacks, failed to... | 6.3 | 186 | Neutral | No | Yes |
| CVE-2026-24046 | ### Impact Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with acc... | 7.1 | 429 | Neutral | No | Yes |
| CVE-2026-24042 | Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticat... | 9.4 | 587 | Neutral | No | No |
| CVE-2026-24039 | Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, allowing low-privileged employee... | 4.3 | 107 | Neutral | No | No |
| CVE-2026-24038 | Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that c... | 8.1 | 484 | Neutral | No | No |
| CVE-2026-24037 | Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function attempts to block XSS by matching ... | 4.8 | 103 | Neutral | No | No |
| CVE-2026-24036 | Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recru... | 5.3 | 132 | Neutral | No | No |
| CVE-2026-24035 | Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exists in Horilla HR Software star... | 4.3 | 107 | Neutral | No | No |
| CVE-2026-24034 | Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be tri... | 5.4 | 129 | Neutral | No | No |
| CVE-2026-24026 | Rejected reason: Not used | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24025 | Rejected reason: Not used | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24024 | Rejected reason: Not used | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24023 | Rejected reason: Not used | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24022 | Rejected reason: Not used | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24021 | Rejected reason: Not used | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24020 | Rejected reason: Not used | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24016 | The installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary code may be ex... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24010 | Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versions prior to 1.5.0, with Socia... | 0.0 | 0 | Neutral | No | No |
| CVE-2026-24009 | ### Impact A PyYAML-related Remote Code Execution (RCE) vulnerability, namely CVE-2020-14343, is exposed in `docling-core >=2.21.0, <2.48.4` and, spe... | 8.1 | 611 | Neutral | No | Yes |