Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82475 |
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
| CVE-2026-82476 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82476)
SSRF in ssrf (CVE-2026-82476). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82468 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-82468)
vulnerability in csrf (CVE-2026-82468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82472 |
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
| CVE-2026-82473 |
|
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
|
| CVE-2026-82469 |
|
Vulnerability in CVE-2026-82469 (CVE-2026-82469)
vulnerability in CVE-2026-82469 (CVE-2026-82469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82474 |
|
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-82463 |
|
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
|
| CVE-2026-82461 |
|
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
|
| CVE-2026-82460 |
|
Path Traversal in path-traversal (CVE-2026-82460)
path traversal in path-traversal (CVE-2026-82460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82477 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82477)
SSRF in ssrf (CVE-2026-82477). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82481 |
|
The cohttp package before 6.3.0 for OCaml allows directory traversal.
The cohttp package before 6.3.0 for OCaml allows directory traversal.
|
| CVE-2026-82451 |
|
Cross-Site Scripting (XSS) in CVE-2026-82451 (CVE-2026-82451)
cross-site scripting in CVE-2026-82451 (CVE-2026-82451). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2026-82454 |
|
Vulnerability in CVE-2026-82454 (CVE-2026-82454)
vulnerability in CVE-2026-82454 (CVE-2026-82454). Confidential information can be exposed externally.
|
| CVE-2026-82452 |
|
Vulnerability in c (CVE-2026-82452)
vulnerability in c (CVE-2026-82452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14494 |
|
Unrestricted File Upload in wordpress (CVE-2026-14494)
vulnerability in wordpress (CVE-2026-14494). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80488 |
|
Vulnerability in wordpress (CVE-2026-80488)
vulnerability in wordpress (CVE-2026-80488). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76546 |
|
Vulnerability in wordpress (CVE-2026-76546)
vulnerability in wordpress (CVE-2026-76546). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16061 |
|
Vulnerability in wordpress (CVE-2026-16061)
vulnerability in wordpress (CVE-2026-16061). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55855 |
|
SQL Injection in mariadb (CVE-2026-55855)
SQL injection in mariadb (CVE-2026-55855). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-82333 |
|
Vulnerability in dos (CVE-2026-82333)
vulnerability in dos (CVE-2026-82333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77078 |
|
Vulnerability in dos (CVE-2026-77078)
vulnerability in dos (CVE-2026-77078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77037 |
|
Vulnerability in dos (CVE-2026-77037)
vulnerability in dos (CVE-2026-77037). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3686 |
|
Vulnerability in dos (CVE-2026-3686)
vulnerability in dos (CVE-2026-3686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3627 |
|
Vulnerability in sqli (CVE-2026-3627)
vulnerability in sqli (CVE-2026-3627). Confidential information can be exposed externally.
|
| CVE-2026-18899 |
|
Path Traversal in path-traversal (CVE-2026-18899)
path traversal in path-traversal (CVE-2026-18899). Confidential information can be exposed externally.
|
| CVE-2026-22056 |
|
Vulnerability in dos (CVE-2026-22056)
vulnerability in dos (CVE-2026-22056). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19295 |
|
Vulnerability in privilege-escalation (CVE-2026-19295)
vulnerability in privilege-escalation (CVE-2026-19295). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18545 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-18545)
SSRF in ssrf (CVE-2026-18545). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82343 |
|
Vulnerability in dos (CVE-2026-82343)
vulnerability in dos (CVE-2026-82343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82276 |
|
Vulnerability in CVE-2026-82276 (CVE-2026-82276)
vulnerability in CVE-2026-82276 (CVE-2026-82276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82273 |
|
Vulnerability in CVE-2026-82273 (CVE-2026-82273)
vulnerability in CVE-2026-82273 (CVE-2026-82273). Confidential information can be exposed externally. Exploitable via `GET /api/memory/threads`.
|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-82275 |
|
Path Traversal in path-traversal (CVE-2026-82275)
path traversal in path-traversal (CVE-2026-82275). Confidential information can be exposed externally.
|
| CVE-2026-82277 |
|
Vulnerability in csrf (CVE-2026-82277)
vulnerability in csrf (CVE-2026-82277). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82264 |
|
Path Traversal in path-traversal (CVE-2026-82264)
path traversal in path-traversal (CVE-2026-82264). Data can be tampered with by attackers.
|
| CVE-2026-77939 |
|
Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
|
| CVE-2026-77218 |
|
Vulnerability in dos (CVE-2026-77218)
vulnerability in dos (CVE-2026-77218). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77217 |
|
Vulnerability in dos (CVE-2026-77217)
vulnerability in dos (CVE-2026-77217). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75126 |
|
Vulnerability in dos (CVE-2026-75126)
vulnerability in dos (CVE-2026-75126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75125 |
|
Vulnerability in dos (CVE-2026-75125)
vulnerability in dos (CVE-2026-75125). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75124 |
|
Vulnerability in dos (CVE-2026-75124)
vulnerability in dos (CVE-2026-75124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56100 |
|
Vulnerability in privilege-escalation (CVE-2026-56100)
vulnerability in privilege-escalation (CVE-2026-56100). Confidential information can be exposed externally.
|
| CVE-2026-51376 |
|
Vulnerability in dos (CVE-2026-51376)
vulnerability in dos (CVE-2026-51376). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50980 |
|
Vulnerability in CVE-2026-50980 (CVE-2026-50980)
vulnerability in CVE-2026-50980 (CVE-2026-50980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39071 |
|
Vulnerability in wordpress (CVE-2026-39071)
vulnerability in wordpress (CVE-2026-39071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39070 |
|
Vulnerability in wordpress (CVE-2026-39070)
vulnerability in wordpress (CVE-2026-39070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55511 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55511)
code injection in org.yamcs:yamcs-core (CVE-2026-55511). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|