Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-8198 |
|
Information Disclosure in wordpress (CVE-2026-8198)
vulnerability in wordpress (CVE-2026-8198). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
|
| CVE-2026-8209 |
|
Vulnerability in path-traversal (CVE-2026-8209)
vulnerability in path-traversal (CVE-2026-8209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8208 |
|
Vulnerability in CVE-2026-8208 (CVE-2026-8208)
vulnerability in CVE-2026-8208 (CVE-2026-8208). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42294 |
|
Vulnerability in dos (CVE-2026-42294)
vulnerability in dos (CVE-2026-42294). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42183 |
|
Vulnerability in dos (CVE-2026-42183)
vulnerability in dos (CVE-2026-42183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41311 |
|
Vulnerability in dos (CVE-2026-41311)
vulnerability in dos (CVE-2026-41311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8207 |
|
SQL Injection in sqli (CVE-2026-8207)
SQL injection in sqli (CVE-2026-8207). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44313 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44313)
SSRF in ssrf (CVE-2026-44313). Confidential information can be exposed externally. Exploitable via `GET /api/v1/archives/{linkId}`.
|
| CVE-2026-42454 |
|
OS Command Injection in docker (CVE-2026-42454)
OS command injection in docker (CVE-2026-42454). Successful exploitation can lead to full system takeover. Exploitable via `GET /docker/containers/`.
|
| CVE-2026-44286 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44286)
SSRF in ssrf (CVE-2026-44286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44284 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44284)
SSRF in ssrf (CVE-2026-44284). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42354 |
|
Vulnerability in sso (CVE-2026-42354)
vulnerability in sso (CVE-2026-42354). Confidential information can be exposed externally. Exploitable via ``Moved``.
|
| CVE-2026-42451 |
|
Cross-Site Scripting (XSS) in CVE-2026-42451 (CVE-2026-42451)
cross-site scripting in CVE-2026-42451 (CVE-2026-42451). Confidential information can be exposed externally.
|
| CVE-2026-42343 |
|
Vulnerability in dos (CVE-2026-42343)
vulnerability in dos (CVE-2026-42343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42346 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-42346)
SSRF in ssrf (CVE-2026-42346). Confidential information can be exposed externally.
|
| CVE-2026-42298 |
|
Code Injection in docker (CVE-2026-42298)
code injection in docker (CVE-2026-42298). Successful exploitation can lead to full system takeover. Exploitable via ``GITHUB_TOKEN``. Mitigation: upgrade to `>= 0` or later.
|
| CVE-2026-42302 |
|
Vulnerability in openai-sdk (CVE-2026-42302)
vulnerability in openai-sdk (CVE-2026-42302). Successful exploitation can lead to full system takeover. Exploitable via ``entrypoint.sh``.
|
| CVE-2026-42339 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-42339)
SSRF in ssrf (CVE-2026-42339). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42287 |
|
SQL Injection in sqli (CVE-2026-42287)
SQL injection in sqli (CVE-2026-42287). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42212 |
|
Vulnerability in csharp (CVE-2026-42212)
vulnerability in csharp (CVE-2026-42212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42209 |
|
Vulnerability in dos (CVE-2026-42209)
vulnerability in dos (CVE-2026-42209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42286 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-42286)
vulnerability in csrf (CVE-2026-42286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42205 |
|
Vulnerability in rails (CVE-2026-42205)
vulnerability in rails (CVE-2026-42205). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42192 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-42192)
cross-site scripting in react (CVE-2026-42192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29203 |
|
Vulnerability in privilege-escalation (CVE-2026-29203)
vulnerability in privilege-escalation (CVE-2026-29203). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42030 |
|
Vulnerability in CVE-2026-42030 (CVE-2026-42030)
vulnerability in CVE-2026-42030 (CVE-2026-42030). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41889 |
|
SQL Injection in sqli (CVE-2026-41889)
SQL injection in sqli (CVE-2026-41889). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42028 |
|
Path Traversal in path-traversal (CVE-2026-42028)
path traversal in path-traversal (CVE-2026-42028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38360 |
|
Path Traversal in path-traversal (CVE-2026-38360)
path traversal in path-traversal (CVE-2026-38360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42353 |
|
Path Traversal in express (CVE-2026-42353)
path traversal in express (CVE-2026-42353). Confidential information can be exposed externally.
|
| CVE-2026-42793 |
|
Vulnerability in dos (CVE-2026-42793)
vulnerability in dos (CVE-2026-42793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43967 |
|
Vulnerability in dos (CVE-2026-43967)
vulnerability in dos (CVE-2026-43967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42794 |
|
Cross-Site Scripting (XSS) in CVE-2026-42794 (CVE-2026-42794)
cross-site scripting in CVE-2026-42794 (CVE-2026-42794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41070 |
|
Authentication Bypass in openvpn (CVE-2026-41070)
authentication bypass in openvpn (CVE-2026-41070). Confidential information can be exposed externally. Exploitable via ``plugin``.
|
| CVE-2026-41690 |
|
Path Traversal in express (CVE-2026-41690)
path traversal in express (CVE-2026-41690). Data can be tampered with by attackers.
|
| CVE-2026-41591 |
|
Cross-Site Scripting (XSS) in CVE-2026-41591 (CVE-2026-41591)
cross-site scripting in CVE-2026-41591 (CVE-2026-41591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41883 |
|
Vulnerability in CVE-2026-41883 (CVE-2026-41883)
vulnerability in CVE-2026-41883 (CVE-2026-41883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29975 |
|
Vulnerability in c (CVE-2026-29975)
vulnerability in c (CVE-2026-29975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34354 |
|
Vulnerability in privilege-escalation (CVE-2026-34354)
vulnerability in privilege-escalation (CVE-2026-34354). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29972 |
|
Vulnerability in c (CVE-2026-29972)
vulnerability in c (CVE-2026-29972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44500 |
|
Vulnerability in deserialization (CVE-2026-44500)
vulnerability in deserialization (CVE-2026-44500). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43424 |
|
Vulnerability in dos (CVE-2026-43424)
vulnerability in dos (CVE-2026-43424). Risk of unauthorized operations or information disclosure. Exploitable via ``tv_nexus``.
|
| CVE-2026-41570 |
|
Vulnerability in phpunit-project (CVE-2026-41570)
vulnerability in phpunit-project (CVE-2026-41570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41575 |
|
Cross-Site Scripting (XSS) in CVE-2026-41575 (CVE-2026-41575)
cross-site scripting in CVE-2026-41575 (CVE-2026-41575). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37431 |
|
SQL Injection in sqli (CVE-2026-37431)
SQL injection in sqli (CVE-2026-37431). Successful exploitation can lead to full system takeover.
|
| CVE-2025-67486 |
|
Vulnerability in CVE-2025-67486 (CVE-2025-67486)
vulnerability in CVE-2025-67486 (CVE-2025-67486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44335 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44335)
SSRF in ssrf (CVE-2026-44335). Successful exploitation can lead to full system takeover. Exploitable via ``requests``. Mitigation: upgrade to `>= 1.6.32` or later.
|
| CVE-2026-44129 |
|
Vulnerability in CVE-2026-44129 (CVE-2026-44129)
vulnerability in CVE-2026-44129 (CVE-2026-44129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44336 |
|
Vulnerability in praison (CVE-2026-44336)
vulnerability in praison (CVE-2026-44336). Successful exploitation can lead to full system takeover. Exploitable via ``praisonai.rules.create``.
|
| CVE-2026-44127 |
|
Vulnerability in path-traversal (CVE-2026-44127)
vulnerability in path-traversal (CVE-2026-44127). Risk of unauthorized operations or information disclosure.
|