Strobes VIStrobes VI
CVE DatabaseThreat ActorsResearchAPI Docs
Visit Strobes.coSign Up for Strobes
CVE DatabaseThreat ActorsResearchAPI Docs
Tools
KB Lookup
Visit Strobes.coSign Up for Strobes

Do you like the insights?

Strobes vulnerability intelligence is a key component of their Exposure Management platform that helps organizations understand, prioritize, and address security vulnerabilities more effectively.

© 2026 Strobes Security. All rights reserved.
HomeExplore CVEs

Explore CVEs

Filter and search through 392,252 vulnerabilities

Filters
0
01000
Showing 20 of 392,252 results
CVE IDDescriptionCVSSPriorityTrendExploitPatch
CVE-2026-24061

GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the ...

9.8690ViralYes
Page 13
PreviousNext
Yes
CVE-2026-24058

### Impact _What kind of vulnerability is it? Who is impacted?_ This issue impacts every Soft Serve instance. A critical authentication bypass allow...

0.00NeutralNoYes
CVE-2026-24056

### Summary When pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining th...

0.00NeutralNoYes
CVE-2026-24055

Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates ...

0.00NeutralNoNo
CVE-2026-24049

### Summary - **Vulnerability Type:** Path Traversal (CWE-22) leading to Arbitrary File Permission Modification. - **Root Cause Component:** wheel...

7.1427NeutralNoYes
CVE-2026-24048

### Impact The `FetchUrlReader` component, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. T...

3.5225NeutralNoYes
CVE-2026-24047

### Impact The `resolveSafeChildPath` utility function in `@backstage/backend-plugin-api`, which is used to prevent path traversal attacks, failed to...

6.3186NeutralNoYes
CVE-2026-24046

### Impact Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with acc...

7.1429NeutralNoYes
CVE-2026-24042

Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticat...

9.4587NeutralNoNo
CVE-2026-24039

Horilla is a free and open source Human Resource Management System (HRMS). Version 1.4.0 has Improper Access Control, allowing low-privileged employee...

4.3107NeutralNoNo
CVE-2026-24038

Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that c...

8.1484NeutralNoNo
CVE-2026-24037

Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the has_xss() function attempts to block XSS by matching ...

4.8103NeutralNoNo
CVE-2026-24036

Horilla is a free and open source Human Resource Management System (HRMS). Versions 1.4.0 and above expose unpublished job postings through the /recru...

5.3132NeutralNoNo
CVE-2026-24035

Horilla is a free and open source Human Resource Management System (HRMS). An Improper Access Control vulnerability exists in Horilla HR Software star...

4.3107NeutralNoNo
CVE-2026-24034

Horilla is a free and open source Human Resource Management System (HRMS). In versions prior to 1.5.0, a cross-site scripting vulnerability can be tri...

5.4129NeutralNoNo
CVE-2026-24026

Rejected reason: Not used

0.00NeutralNoNo
CVE-2026-24025

Rejected reason: Not used

0.00NeutralNoNo
CVE-2026-24024

Rejected reason: Not used

0.00NeutralNoNo
CVE-2026-24023

Rejected reason: Not used

0.00NeutralNoNo
CVE-2026-24022

Rejected reason: Not used

0.00NeutralNoNo