Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-43637 |
|
Path Traversal in path-traversal (CVE-2026-43637)
path traversal in path-traversal (CVE-2026-43637). Data can be tampered with by attackers.
|
| CVE-2026-58559 |
|
Vulnerability in dos (CVE-2026-58559)
vulnerability in dos (CVE-2026-58559). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52865 |
|
Vulnerability in nginx (CVE-2026-52865)
vulnerability in nginx (CVE-2026-52865). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59762 |
|
Vulnerability in dos (CVE-2026-59762)
vulnerability in dos (CVE-2026-59762). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42533 |
|
Vulnerability in nginx (CVE-2026-42533)
vulnerability in nginx (CVE-2026-42533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15779 |
|
Vulnerability in privilege-escalation (CVE-2026-15779)
vulnerability in privilege-escalation (CVE-2026-15779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61835 |
|
SSRF (Server-Side Request Forgery) in directus (CVE-2026-61835)
SSRF in directus (CVE-2026-61835). Confidential information can be exposed externally. Exploitable via ``IMPORT_IP_DENY_LIST``. Mitigation: upgrade to `12.0.0` or later.
|
| CVE-2026-61646 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61646)
SSRF in ssrf (CVE-2026-61646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61873 |
|
Vulnerability in path-traversal (CVE-2026-61873)
vulnerability in path-traversal (CVE-2026-61873). Data can be tampered with by attackers.
|
| CVE-2026-61868 |
|
Vulnerability in dos (CVE-2026-61868)
vulnerability in dos (CVE-2026-61868). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61867 |
|
Vulnerability in dos (CVE-2026-61867)
vulnerability in dos (CVE-2026-61867). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61869 |
|
Vulnerability in dos (CVE-2026-61869)
vulnerability in dos (CVE-2026-61869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61871 |
|
Vulnerability in dos (CVE-2026-61871)
vulnerability in dos (CVE-2026-61871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61860 |
|
Use-After-Free in dos (CVE-2026-61860)
vulnerability in dos (CVE-2026-61860). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61464 |
|
Vulnerability in dos (CVE-2026-61464)
vulnerability in dos (CVE-2026-61464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61453 |
|
Cross-Site Scripting (XSS) in CVE-2026-61453 (CVE-2026-61453)
cross-site scripting in CVE-2026-61453 (CVE-2026-61453). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.1` or later.
|
| CVE-2026-61457 |
|
Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
vulnerability in CVE-2026-61457 (CVE-2026-61457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61443 |
|
Path Traversal in CVE-2026-61443 (CVE-2026-61443)
path traversal in CVE-2026-61443 (CVE-2026-61443). Confidential information can be exposed externally.
|
| CVE-2026-61438 |
|
OS Command Injection in CVE-2026-61438 (CVE-2026-61438)
OS command injection in CVE-2026-61438 (CVE-2026-61438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61446 |
|
Code Injection in path-traversal (CVE-2026-61446)
code injection in path-traversal (CVE-2026-61446). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61430 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61430)
SSRF in ssrf (CVE-2026-61430). Confidential information can be exposed externally.
|
| CVE-2026-61435 |
|
Authentication Bypass in CVE-2026-61435 (CVE-2026-61435)
authentication bypass in CVE-2026-61435 (CVE-2026-61435). Data can be tampered with by attackers. Exploitable via `GET /api/v1/agents`.
|
| CVE-2026-56353 |
|
Authentication Bypass in n8n (CVE-2026-56353)
authentication bypass in n8n (CVE-2026-56353). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.123.22` or later.
|
| CVE-2026-57996 |
|
Privilege Escalation in privilege-escalation (CVE-2026-57996)
vulnerability in privilege-escalation (CVE-2026-57996). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/api/user/add`.
|
| CVE-2026-56375 |
|
Vulnerability in dos (CVE-2026-56375)
vulnerability in dos (CVE-2026-56375). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56398 |
|
Vulnerability in openwebui (CVE-2026-56398)
vulnerability in openwebui (CVE-2026-56398). Confidential information can be exposed externally.
|
| CVE-2026-58077 |
|
Cross-Site Scripting (XSS) in CVE-2026-58077 (CVE-2026-58077)
cross-site scripting in CVE-2026-58077 (CVE-2026-58077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57833 |
|
Cross-Site Scripting (XSS) in CVE-2026-57833 (CVE-2026-57833)
cross-site scripting in CVE-2026-57833 (CVE-2026-57833). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35152 |
|
SQL Injection in apache (CVE-2026-35152)
SQL injection in apache (CVE-2026-35152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56287 |
|
SQL Injection in apache (CVE-2026-56287)
SQL injection in apache (CVE-2026-56287). Confidential information can be exposed externally. Exploitable via `GET /api/v1/clients`.
|
| CVE-2026-57821 |
|
SQL Injection in apache (CVE-2026-57821)
SQL injection in apache (CVE-2026-57821). Confidential information can be exposed externally. Exploitable via `GET /api/v1/offices`.
|
| CVE-2026-15583 |
|
Vulnerability in ssrf (CVE-2026-15583)
vulnerability in ssrf (CVE-2026-15583). Confidential information can be exposed externally.
|
| CVE-2026-15804 |
|
SQL Injection in sqli (CVE-2026-15804)
SQL injection in sqli (CVE-2026-15804). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57832 |
|
The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
|
| CVE-2026-57831 |
|
The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
|
| CVE-2026-14251 |
|
Vulnerability in dos (CVE-2026-14251)
vulnerability in dos (CVE-2026-14251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12512 |
|
SQL Injection in wordpress (CVE-2026-12512)
SQL injection in wordpress (CVE-2026-12512). Confidential information can be exposed externally.
|
| CVE-2026-11851 |
|
SQL Injection in sqli (CVE-2026-11851)
SQL injection in sqli (CVE-2026-11851). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13585 |
|
Vulnerability in dos (CVE-2026-13585)
vulnerability in dos (CVE-2026-13585). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5270 |
|
Authentication Bypass in CVE-2026-5270 (CVE-2026-5270)
authentication bypass in CVE-2026-5270 (CVE-2026-5270). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36035 |
|
Vulnerability in dos (CVE-2026-36035)
vulnerability in dos (CVE-2026-36035). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15751 |
|
Path Traversal in path-traversal (CVE-2026-15751)
path traversal in path-traversal (CVE-2026-15751). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56362 |
|
Vulnerability in dos (CVE-2025-56362)
vulnerability in dos (CVE-2025-56362). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56363 |
|
Vulnerability in dos (CVE-2025-56363)
vulnerability in dos (CVE-2025-56363). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56364 |
|
Vulnerability in dos (CVE-2025-56364)
vulnerability in dos (CVE-2025-56364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48290 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48290)
SSRF in ssrf (CVE-2026-48290). Confidential information can be exposed externally.
|
| CVE-2025-56361 |
|
Vulnerability in dos (CVE-2025-56361)
vulnerability in dos (CVE-2025-56361). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48338 |
|
Path Traversal in path-traversal (CVE-2026-48338)
path traversal in path-traversal (CVE-2026-48338). Confidential information can be exposed externally.
|
| CVE-2026-24229 |
|
Vulnerability in dos (CVE-2026-24229)
vulnerability in dos (CVE-2026-24229). Confidential information can be exposed externally.
|
| CVE-2026-24234 |
|
SSRF (Server-Side Request Forgery) in dos (CVE-2026-24234)
SSRF in dos (CVE-2026-24234). Risk of unauthorized operations or information disclosure.
|