Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-28304 |
|
Vulnerability in solarwinds (CVE-2026-28304)
vulnerability in solarwinds (CVE-2026-28304). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28308 |
|
Vulnerability in solarwinds (CVE-2026-28308)
vulnerability in solarwinds (CVE-2026-28308). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28302 |
|
Vulnerability in privilege-escalation (CVE-2026-28302)
vulnerability in privilege-escalation (CVE-2026-28302). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44907 |
|
Vulnerability in react-server-dom-webpack (CVE-2026-44907)
vulnerability in react-server-dom-webpack (CVE-2026-44907). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `19.2.8` or later.
|
| CVE-2026-8933 |
|
Vulnerability in privilege-escalation (CVE-2026-8933)
vulnerability in privilege-escalation (CVE-2026-8933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65048 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-65048)
cross-site scripting in wordpress (CVE-2026-65048). Confidential information can be exposed externally.
|
| CVE-2026-59849 |
|
Vulnerability in dos (CVE-2026-59849)
vulnerability in dos (CVE-2026-59849). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59848 |
|
Vulnerability in dos (CVE-2026-59848)
vulnerability in dos (CVE-2026-59848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9499 |
|
Out-of-Bounds Read in dos (CVE-2026-9499)
vulnerability in dos (CVE-2026-9499). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16396 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16396)
vulnerability in privilege-escalation (CVE-2026-16396). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16401 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16401)
vulnerability in privilege-escalation (CVE-2026-16401). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16379 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16379)
vulnerability in privilege-escalation (CVE-2026-16379). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16372 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16372)
vulnerability in privilege-escalation (CVE-2026-16372). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16371 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16371)
vulnerability in privilege-escalation (CVE-2026-16371). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16365 |
|
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-16366 |
|
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-65007 |
|
Vulnerability in privilege-escalation (CVE-2026-65007)
vulnerability in privilege-escalation (CVE-2026-65007). Confidential information can be exposed externally.
|
| CVE-2026-59845 |
|
Vulnerability in dos (CVE-2026-59845)
vulnerability in dos (CVE-2026-59845). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60080 |
|
Use-After-Free in apache (CVE-2026-60080)
vulnerability in apache (CVE-2026-60080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64628 |
|
Cross-Site Scripting (XSS) in CVE-2026-64628 (CVE-2026-64628)
cross-site scripting in CVE-2026-64628 (CVE-2026-64628). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65008 |
|
Code Injection in CVE-2026-65008 (CVE-2026-65008)
code injection in CVE-2026-65008 (CVE-2026-65008). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.7` or later.
|
| CVE-2026-1617 |
|
SQL Injection in sqli (CVE-2026-1617)
SQL injection in sqli (CVE-2026-1617). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16461 |
|
Vulnerability in dos (CVE-2026-16461)
vulnerability in dos (CVE-2026-16461). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59843 |
|
Vulnerability in dos (CVE-2026-59843)
vulnerability in dos (CVE-2026-59843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64606 |
|
Unsafe Deserialization in apache (CVE-2026-64606)
vulnerability in apache (CVE-2026-64606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64609 |
|
Out-of-Bounds Read in apache (CVE-2026-64609)
vulnerability in apache (CVE-2026-64609). Confidential information can be exposed externally.
|
| CVE-2026-15145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15145)
cross-site scripting in wordpress (CVE-2026-15145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1771 |
|
Vulnerability in wordpress (CVE-2026-1771)
vulnerability in wordpress (CVE-2026-1771). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3183 |
|
Vulnerability in CVE-2026-3183 (CVE-2026-3183)
vulnerability in CVE-2026-3183 (CVE-2026-3183). Data can be tampered with by attackers.
|
| CVE-2026-8082 |
|
SQL Injection in wordpress (CVE-2026-8082)
SQL injection in wordpress (CVE-2026-8082). Confidential information can be exposed externally.
|
| CVE-2026-11767 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11767)
cross-site scripting in wordpress (CVE-2026-11767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15782 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15782)
cross-site scripting in wordpress (CVE-2026-15782). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15927 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-15927)
SSRF in ssrf (CVE-2026-15927). Confidential information can be exposed externally.
|
| CVE-2026-13439 |
|
Privilege Escalation in wordpress (CVE-2026-13439)
vulnerability in wordpress (CVE-2026-13439). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15156 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15156)
cross-site scripting in wordpress (CVE-2026-15156). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-37508 |
|
Cross-Site Scripting (XSS) in hcltech (CVE-2023-37508)
cross-site scripting in hcltech (CVE-2023-37508). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16334 |
|
Vulnerability in sqli (CVE-2026-16334)
vulnerability in sqli (CVE-2026-16334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0770 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-0770)
vulnerability in langflow (CVE-2026-0770). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-59729 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-59729)
cross-site scripting in astro (CVE-2026-59729). Risk of unauthorized operations or information disclosure. Exploitable via ``INVALID_ATTR_NAME_CHAR``. Mitigation: upgrade to `7.0.6` or later.
|
| CVE-2026-59727 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-59727)
cross-site scripting in astro (CVE-2026-59727). Risk of unauthorized operations or information disclosure. Exploitable via ``attrs``. Mitigation: upgrade to `7.0.4` or later.
|
| CVE-2026-64626 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-64626)
SSRF in ssrf (CVE-2026-64626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57852 |
|
Vulnerability in CVE-2026-57852 (CVE-2026-57852)
vulnerability in CVE-2026-57852 (CVE-2026-57852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51025 |
|
Cross-Site Scripting (XSS) in CVE-2026-51025 (CVE-2026-51025)
cross-site scripting in CVE-2026-51025 (CVE-2026-51025). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51031 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51031)
SSRF in ssrf (CVE-2026-51031). Confidential information can be exposed externally.
|
| CVE-2026-12900 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12900)
cross-site scripting in wordpress (CVE-2026-12900). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-51316 |
|
Vulnerability in dos (CVE-2024-51316)
vulnerability in dos (CVE-2024-51316). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53596 |
|
Vulnerability in laravel (CVE-2026-53596)
vulnerability in laravel (CVE-2026-53596). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56623 |
|
Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
|
| CVE-2026-56452 |
|
Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
|
| CVE-2026-63767 |
|
Unsafe Deserialization in deserialization (CVE-2026-63767)
vulnerability in deserialization (CVE-2026-63767). Successful exploitation can lead to full system takeover.
|