Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72538 |
|
Vulnerability in CVE-2026-72538 (CVE-2026-72538)
vulnerability in CVE-2026-72538 (CVE-2026-72538). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72533 |
|
Authentication Bypass in CVE-2026-72533 (CVE-2026-72533)
authentication bypass in CVE-2026-72533 (CVE-2026-72533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72534 |
|
Privilege Escalation in privilege-escalation (CVE-2026-72534)
vulnerability in privilege-escalation (CVE-2026-72534). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50237 |
|
SSRF (Server-Side Request Forgery) in privilege-escalation (CVE-2026-50237)
SSRF in privilege-escalation (CVE-2026-50237). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50236 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-50236)
SSRF in ssrf (CVE-2026-50236). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72693 |
|
Vulnerability in privilege-escalation (CVE-2026-72693)
vulnerability in privilege-escalation (CVE-2026-72693). Successful exploitation can lead to full system takeover. Exploitable via ``login``.
|
| CVE-2026-72694 |
|
Vulnerability in privilege-escalation (CVE-2026-72694)
vulnerability in privilege-escalation (CVE-2026-72694). Confidential information can be exposed externally.
|
| CVE-2026-15555 |
|
Unsafe Deserialization in deserialization (CVE-2026-15555)
vulnerability in deserialization (CVE-2026-15555). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71217 |
|
Vulnerability in dos (CVE-2026-71217)
vulnerability in dos (CVE-2026-71217). Risk of unauthorized operations or information disclosure. Exploitable via ``parallel``.
|
| CVE-2026-15563 |
|
Vulnerability in dos (CVE-2026-15563)
vulnerability in dos (CVE-2026-15563). Confidential information can be exposed externally.
|
| CVE-2026-15561 |
|
Vulnerability in dos (CVE-2026-15561)
vulnerability in dos (CVE-2026-15561). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15565 |
|
Vulnerability in dos (CVE-2026-15565)
vulnerability in dos (CVE-2026-15565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15562 |
|
Vulnerability in dos (CVE-2026-15562)
vulnerability in dos (CVE-2026-15562). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16053 |
|
Vulnerability in path-traversal (CVE-2026-16053)
vulnerability in path-traversal (CVE-2026-16053). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4757 |
|
Vulnerability in privilege-escalation (CVE-2026-4757)
vulnerability in privilege-escalation (CVE-2026-4757). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73030 |
|
Path Traversal in path-traversal (CVE-2026-73030)
path traversal in path-traversal (CVE-2026-73030). Data can be tampered with by attackers.
|
| CVE-2026-63622 |
|
Vulnerability in privilege-escalation (CVE-2026-63622)
vulnerability in privilege-escalation (CVE-2026-63622). Successful exploitation can lead to full system takeover. Exploitable via ``swtpm``.
|
| CVE-2026-18950 |
|
Privilege Escalation in privilege-escalation (CVE-2026-18950)
vulnerability in privilege-escalation (CVE-2026-18950). Successful exploitation can lead to full system takeover. Exploitable via ``roleRef``.
|
| CVE-2026-18941 |
|
Vulnerability in dos (CVE-2026-18941)
vulnerability in dos (CVE-2026-18941). Confidential information can be exposed externally.
|
| CVE-2026-18947 |
|
Vulnerability in dos (CVE-2026-18947)
vulnerability in dos (CVE-2026-18947). Data can be tampered with by attackers.
|
| CVE-2026-18617 |
|
Vulnerability in privilege-escalation (CVE-2026-18617)
vulnerability in privilege-escalation (CVE-2026-18617). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18618 |
|
Vulnerability in dos (CVE-2026-18618)
vulnerability in dos (CVE-2026-18618). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11810 |
|
Vulnerability in c (CVE-2026-11810)
vulnerability in c (CVE-2026-11810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71965 |
|
Vulnerability in CVE-2026-71965 (CVE-2026-71965)
vulnerability in CVE-2026-71965 (CVE-2026-71965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69118 |
|
Authorization Flaw in CVE-2026-69118 (CVE-2026-69118)
vulnerability in CVE-2026-69118 (CVE-2026-69118). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69112 |
|
Path Traversal in path-traversal (CVE-2026-69112)
path traversal in path-traversal (CVE-2026-69112). Confidential information can be exposed externally.
|
| CVE-2026-72730 |
|
Cross-Site Scripting (XSS) in CVE-2026-72730 (CVE-2026-72730)
cross-site scripting in CVE-2026-72730 (CVE-2026-72730). Confidential information can be exposed externally.
|
| CVE-2026-72691 |
|
Vulnerability in CVE-2026-72691 (CVE-2026-72691)
vulnerability in CVE-2026-72691 (CVE-2026-72691). Confidential information can be exposed externally.
|
| CVE-2026-19429 |
|
Vulnerability in CVE-2026-19429 (CVE-2026-19429)
vulnerability in CVE-2026-19429 (CVE-2026-19429). Successful exploitation can lead to full system takeover. Exploitable via `POST /job/{name}/build`.
|
| CVE-2026-72594 |
|
Cross-Site Scripting (XSS) in CVE-2026-72594 (CVE-2026-72594)
cross-site scripting in CVE-2026-72594 (CVE-2026-72594). Confidential information can be exposed externally.
|
| CVE-2026-72591 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72591)
SSRF in ssrf (CVE-2026-72591). Confidential information can be exposed externally. Exploitable via `PATCH /apis/web/v1/album/{id}/image`.
|
| CVE-2026-72581 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72581)
SSRF in ssrf (CVE-2026-72581). Confidential information can be exposed externally.
|
| CVE-2026-72578 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-72578)
vulnerability in csrf (CVE-2026-72578). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72566 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72566)
SSRF in ssrf (CVE-2026-72566). Confidential information can be exposed externally.
|
| CVE-2026-72571 |
|
Path Traversal in path-traversal (CVE-2026-72571)
path traversal in path-traversal (CVE-2026-72571). Confidential information can be exposed externally.
|
| CVE-2026-72572 |
|
Path Traversal in path-traversal (CVE-2026-72572)
path traversal in path-traversal (CVE-2026-72572). Confidential information can be exposed externally.
|
| CVE-2026-72568 |
|
Out-of-Bounds Read in dos (CVE-2026-72568)
vulnerability in dos (CVE-2026-72568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59087 |
|
Out-of-Bounds Write in dos (CVE-2026-59087)
out-of-bounds write in dos (CVE-2026-59087). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44630 |
|
Vulnerability in apache (CVE-2026-44630)
vulnerability in apache (CVE-2026-44630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17540 |
|
Vulnerability in wordpress (CVE-2026-17540)
vulnerability in wordpress (CVE-2026-17540). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16985 |
|
Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19389 |
|
Vulnerability in dos (CVE-2026-19389)
vulnerability in dos (CVE-2026-19389). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19387 |
|
Out-of-Bounds Write in dos (CVE-2026-19387)
out-of-bounds write in dos (CVE-2026-19387). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19384 |
|
Vulnerability in sqli (CVE-2026-19384)
vulnerability in sqli (CVE-2026-19384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19355 |
|
Vulnerability in sqli (CVE-2026-19355)
vulnerability in sqli (CVE-2026-19355). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19351 |
|
Vulnerability in sqli (CVE-2026-19351)
vulnerability in sqli (CVE-2026-19351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19344 |
|
Vulnerability in sqli (CVE-2026-19344)
vulnerability in sqli (CVE-2026-19344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19343 |
|
Vulnerability in sqli (CVE-2026-19343)
vulnerability in sqli (CVE-2026-19343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17017 |
|
SQL Injection in wordpress (CVE-2026-17017)
SQL injection in wordpress (CVE-2026-17017). Confidential information can be exposed externally.
|
| CVE-2026-18464 |
|
Vulnerability in wordpress (CVE-2026-18464)
vulnerability in wordpress (CVE-2026-18464). Risk of unauthorized operations or information disclosure.
|