Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14895 |
|
Vulnerability in dos (CVE-2026-14895)
vulnerability in dos (CVE-2026-14895). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50810 |
|
Vulnerability in c (CVE-2026-50810)
vulnerability in c (CVE-2026-50810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36162 |
|
Cross-Site Scripting (XSS) in CVE-2026-36162 (CVE-2026-36162)
cross-site scripting in CVE-2026-36162 (CVE-2026-36162). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59706 |
|
Vulnerability in ssrf (CVE-2026-59706)
vulnerability in ssrf (CVE-2026-59706). Confidential information can be exposed externally. Exploitable via `GET /api/v1/config/`.
|
| CVE-2026-55408 |
|
Code Injection in CVE-2026-55408 (CVE-2026-55408)
code injection in CVE-2026-55408 (CVE-2026-55408). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58583 |
|
Privilege Escalation in privilege-escalation (CVE-2026-58583)
vulnerability in privilege-escalation (CVE-2026-58583). Confidential information can be exposed externally.
|
| CVE-2026-55633 |
|
Unrestricted File Upload in CVE-2026-55633 (CVE-2026-55633)
vulnerability in CVE-2026-55633 (CVE-2026-55633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55631 |
|
Path Traversal in path-traversal (CVE-2026-55631)
path traversal in path-traversal (CVE-2026-55631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49471 |
|
Vulnerability in serena-agent (CVE-2026-49471)
vulnerability in serena-agent (CVE-2026-49471). Successful exploitation can lead to full system takeover. Exploitable via `Host header`. Mitigation: upgrade to `1.5.2` or later.
|
| CVE-2026-53509 |
|
SSRF (Server-Side Request Forgery) in @aborruso/ckan-mcp-server (CVE-2026-53509)
SSRF in @aborruso/ckan-mcp-server (CVE-2026-53509). Confidential information can be exposed externally. Exploitable via ``localhost``. Mitigation: upgrade to `0.4.106` or later.
|
| CVE-2026-48954 |
|
Joomla! Core - [20260708] - XSS through language overrides
Joomla! Core - [20260708] - XSS through language overrides
|
| CVE-2026-48953 |
|
Joomla! Core - [20260707] - XSS in the generic image output layout
Joomla! Core - [20260707] - XSS in the generic image output layout
|
| CVE-2026-48952 |
|
Joomla! Core - [20260706] - XSS in com_installer
Joomla! Core - [20260706] - XSS in com_installer
|
| CVE-2026-48951 |
|
Joomla! Core - [20260705] - XSS in various modalreturn layouts
Joomla! Core - [20260705] - XSS in various modalreturn layouts
|
| CVE-2026-48950 |
|
Joomla! Core - [20260704] - XSS in com_templates
Joomla! Core - [20260704] - XSS in com_templates
|
| CVE-2026-48949 |
|
Joomla! Core - [20260703] - XSS in MFA method management
Joomla! Core - [20260703] - XSS in MFA method management
|
| CVE-2026-23698 |
|
Unrestricted File Upload in apache (CVE-2026-23698)
vulnerability in apache (CVE-2026-23698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57851 |
|
Vulnerability in privilege-escalation (CVE-2026-57851)
vulnerability in privilege-escalation (CVE-2026-57851). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23697 |
|
Unrestricted File Upload in apache (CVE-2026-23697)
vulnerability in apache (CVE-2026-23697). Successful exploitation can lead to full system takeover.
|
| CVE-2025-12799 |
|
Cross-Site Scripting (XSS) in CVE-2025-12799 (CVE-2025-12799)
cross-site scripting in CVE-2025-12799 (CVE-2025-12799). Data can be tampered with by attackers.
|
| CVE-2026-20744 |
|
Vulnerability in cisa (CVE-2026-20744)
vulnerability in cisa (CVE-2026-20744). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56811 |
|
Vulnerability in dos (CVE-2026-56811)
vulnerability in dos (CVE-2026-56811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56812 |
|
Vulnerability in dos (CVE-2026-56812)
vulnerability in dos (CVE-2026-56812). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14940 |
|
Vulnerability in dos (CVE-2026-14940)
vulnerability in dos (CVE-2026-14940). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12948 |
|
Cross-Site Scripting (XSS) in CVE-2026-12948 (CVE-2026-12948)
cross-site scripting in CVE-2026-12948 (CVE-2026-12948). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6101 |
|
Vulnerability in wordpress (CVE-2026-6101)
vulnerability in wordpress (CVE-2026-6101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53481 |
|
Path Traversal in path-traversal (CVE-2026-53481)
path traversal in path-traversal (CVE-2026-53481). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10659 |
|
Vulnerability in c (CVE-2026-10659)
vulnerability in c (CVE-2026-10659). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44512 |
|
Vulnerability in onnx (CVE-2026-44512)
vulnerability in onnx (CVE-2026-44512). Risk of unauthorized operations or information disclosure. Exploitable via ``width_scale``. Mitigation: upgrade to `1.22.0` or later.
|
| CVE-2026-40187 |
|
OS Command Injection in egroupware/egroupware (CVE-2026-40187)
OS command injection in egroupware/egroupware (CVE-2026-40187). Risk of unauthorized operations or information disclosure. Exploitable via ``chgrp``. Mitigation: upgrade to `23.1.20260601` or later.
|
| CVE-2026-33655 |
|
SSRF (Server-Side Request Forgery) in github.com/QuantumNous/new-api (CVE-2026-33655)
SSRF in github.com/QuantumNous/new-api (CVE-2026-33655). Confidential information can be exposed externally. Exploitable via ``ApplyIPFilterForDomain``. Mitigation: upgrade to `0.12.0-alpha.1` or later.
|
| CVE-2026-27823 |
|
Path Traversal in egroupware/egroupware (CVE-2026-27823)
path traversal in egroupware/egroupware (CVE-2026-27823). Risk of unauthorized operations or information disclosure. Exploitable via ``participant_role``. Mitigation: upgrade to `23.1.20260224` or later.
|
| CVE-2026-33264 |
|
Unsafe Deserialization in airflow (CVE-2026-33264)
vulnerability in airflow (CVE-2026-33264). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-14476 |
|
Vulnerability in path-traversal (CVE-2026-14476)
vulnerability in path-traversal (CVE-2026-14476). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11610 |
|
Vulnerability in c (CVE-2026-11610)
vulnerability in c (CVE-2026-11610). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58384 |
|
Vulnerability in dos (CVE-2026-58384)
vulnerability in dos (CVE-2026-58384). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8309 |
|
Cross-Site Scripting (XSS) in CVE-2026-8309 (CVE-2026-8309)
cross-site scripting in CVE-2026-8309 (CVE-2026-8309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8306 |
|
Cross-Site Scripting (XSS) in CVE-2026-8306 (CVE-2026-8306)
cross-site scripting in CVE-2026-8306 (CVE-2026-8306). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7380 |
|
Vulnerability in CVE-2026-7380 (CVE-2026-7380)
vulnerability in CVE-2026-7380 (CVE-2026-7380). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4375 |
|
Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57871 |
|
Vulnerability in path-traversal (CVE-2026-57871)
vulnerability in path-traversal (CVE-2026-57871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27790 |
|
Vulnerability in dos (CVE-2026-27790)
vulnerability in dos (CVE-2026-27790). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27844 |
|
Vulnerability in dos (CVE-2026-27844)
vulnerability in dos (CVE-2026-27844). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11328 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11328)
cross-site scripting in wordpress (CVE-2026-11328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53645 |
|
Privilege Escalation in privilege-escalation (CVE-2026-53645)
vulnerability in privilege-escalation (CVE-2026-53645). Risk of unauthorized operations or information disclosure. Exploitable via ``staff.create_and_edit_staff``.
|
| CVE-2026-53641 |
|
Cross-Site Scripting (XSS) in CVE-2026-53641 (CVE-2026-53641)
cross-site scripting in CVE-2026-53641 (CVE-2026-53641). Risk of unauthorized operations or information disclosure. Exploitable via ``content_html``.
|
| CVE-2026-59710 |
|
Cross-Site Scripting (XSS) in showdown (CVE-2026-59710)
cross-site scripting in showdown (CVE-2026-59710). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59713 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-59713)
vulnerability in csrf (CVE-2026-59713). Confidential information can be exposed externally.
|
| CVE-2026-59711 |
|
Cross-Site Scripting (XSS) in showdown (CVE-2026-59711)
cross-site scripting in showdown (CVE-2026-59711). Risk of unauthorized operations or information disclosure.
|