Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-57311 |
|
Unrestricted File Upload in CVE-2026-57311 (CVE-2026-57311)
vulnerability in CVE-2026-57311 (CVE-2026-57311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57309 |
|
SQL Injection in sqli (CVE-2026-57309)
SQL injection in sqli (CVE-2026-57309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16244 |
|
Vulnerability in sqli (CVE-2026-16244)
vulnerability in sqli (CVE-2026-16244). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54910 |
|
Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
|
| CVE-2026-63763 |
|
Vulnerability in privilege-escalation (CVE-2026-63763)
vulnerability in privilege-escalation (CVE-2026-63763). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64620 |
|
Vulnerability in c (CVE-2026-64620)
vulnerability in c (CVE-2026-64620). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63762 |
|
Vulnerability in dos (CVE-2026-63762)
vulnerability in dos (CVE-2026-63762). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63754 |
|
Vulnerability in dos (CVE-2026-63754)
vulnerability in dos (CVE-2026-63754). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63749 |
|
Authorization Flaw in surrealdb (CVE-2026-63749)
vulnerability in surrealdb (CVE-2026-63749). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63747 |
|
Vulnerability in dos (CVE-2026-63747)
vulnerability in dos (CVE-2026-63747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16254 |
|
Out-of-Bounds Read in dos (CVE-2026-16254)
vulnerability in dos (CVE-2026-16254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63737 |
|
Vulnerability in dos (CVE-2026-63737)
vulnerability in dos (CVE-2026-63737). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63734 |
|
Vulnerability in dos (CVE-2026-63734)
vulnerability in dos (CVE-2026-63734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12970 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12970)
cross-site scripting in wordpress (CVE-2026-12970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12592 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12592)
cross-site scripting in wordpress (CVE-2026-12592). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11349 |
|
SQL Injection in wordpress (CVE-2026-11349)
SQL injection in wordpress (CVE-2026-11349). Confidential information can be exposed externally.
|
| CVE-2026-10081 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10081)
cross-site scripting in wordpress (CVE-2026-10081). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12484 |
|
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
|
| CVE-2026-63880 |
|
Vulnerability in dos (CVE-2026-63880)
vulnerability in dos (CVE-2026-63880). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16221 |
|
Vulnerability in fast-uri (CVE-2026-16221)
vulnerability in fast-uri (CVE-2026-16221). Data can be tampered with by attackers. Exploitable via ``URL``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-16229 |
|
Cross-Site Scripting (XSS) in CVE-2026-16229 (CVE-2026-16229)
cross-site scripting in CVE-2026-16229 (CVE-2026-16229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16228 |
|
Vulnerability in sqli (CVE-2026-16228)
vulnerability in sqli (CVE-2026-16228). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16227 |
|
Vulnerability in sqli (CVE-2026-16227)
vulnerability in sqli (CVE-2026-16227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16220 |
|
Cross-Site Scripting (XSS) in CVE-2026-16220 (CVE-2026-16220)
cross-site scripting in CVE-2026-16220 (CVE-2026-16220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16219 |
|
Path Traversal in path-traversal (CVE-2026-16219)
path traversal in path-traversal (CVE-2026-16219). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16205 |
|
Cross-Site Scripting (XSS) in CVE-2026-16205 (CVE-2026-16205)
cross-site scripting in CVE-2026-16205 (CVE-2026-16205). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16203 |
|
Cross-Site Scripting (XSS) in CVE-2026-16203 (CVE-2026-16203)
cross-site scripting in CVE-2026-16203 (CVE-2026-16203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16202 |
|
Cross-Site Scripting (XSS) in CVE-2026-16202 (CVE-2026-16202)
cross-site scripting in CVE-2026-16202 (CVE-2026-16202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10130 |
|
Authorization Flaw in CVE-2026-10130 (CVE-2026-10130)
vulnerability in CVE-2026-10130 (CVE-2026-10130). Confidential information can be exposed externally.
|
| CVE-2026-16198 |
|
Authentication Bypass in CVE-2026-16198 (CVE-2026-16198)
authentication bypass in CVE-2026-16198 (CVE-2026-16198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16156 |
|
Cross-Site Scripting (XSS) in CVE-2026-16156 (CVE-2026-16156)
cross-site scripting in CVE-2026-16156 (CVE-2026-16156). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57857 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-57857)
cross-site scripting in wordpress (CVE-2026-57857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16155 |
|
Cross-Site Scripting (XSS) in CVE-2026-16155 (CVE-2026-16155)
cross-site scripting in CVE-2026-16155 (CVE-2026-16155). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16154 |
|
Vulnerability in sqli (CVE-2026-16154)
vulnerability in sqli (CVE-2026-16154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12228 |
|
Cross-Site Scripting (XSS) in lollms (CVE-2026-12228)
cross-site scripting in lollms (CVE-2026-12228). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/prompts/share`.
|
| CVE-2026-16152 |
|
Vulnerability in sqli (CVE-2026-16152)
vulnerability in sqli (CVE-2026-16152). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53994 |
|
Vulnerability in dos (CVE-2026-53994)
vulnerability in dos (CVE-2026-53994). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16131 |
|
Vulnerability in sqli (CVE-2026-16131)
vulnerability in sqli (CVE-2026-16131). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9323 |
|
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
|
| CVE-2026-11826 |
|
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
|
| CVE-2025-71396 |
|
Vulnerability in dos (CVE-2025-71396)
vulnerability in dos (CVE-2025-71396). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71392 |
|
Command Injection in privilege-escalation (CVE-2025-71392)
command injection in privilege-escalation (CVE-2025-71392). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58369 |
|
Vulnerability in dos (CVE-2024-58369)
vulnerability in dos (CVE-2024-58369). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71395 |
|
Vulnerability in dos (CVE-2025-71395)
vulnerability in dos (CVE-2025-71395). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58364 |
|
Vulnerability in dos (CVE-2024-58364)
vulnerability in dos (CVE-2024-58364). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58368 |
|
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
|
| CVE-2024-58362 |
|
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the...
|
| CVE-2024-58366 |
|
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...
|
| CVE-2024-58357 |
|
Vulnerability in dos (CVE-2024-58357)
vulnerability in dos (CVE-2024-58357). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58358 |
|
Vulnerability in dos (CVE-2024-58358)
vulnerability in dos (CVE-2024-58358). Risk of unauthorized operations or information disclosure.
|