Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-64824 Path Traversal in path-traversal (CVE-2026-64824)
path traversal in path-traversal (CVE-2026-64824). Successful exploitation can lead to full system takeover.
CVE-2026-44907 Vulnerability in react-server-dom-webpack (CVE-2026-44907)
vulnerability in react-server-dom-webpack (CVE-2026-44907). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `19.2.8` or later.
CVE-2026-8933 Vulnerability in privilege-escalation (CVE-2026-8933)
vulnerability in privilege-escalation (CVE-2026-8933). Successful exploitation can lead to full system takeover.
CVE-2026-16396 Privilege Escalation in privilege-escalation (CVE-2026-16396)
vulnerability in privilege-escalation (CVE-2026-16396). Successful exploitation can lead to full system takeover.
CVE-2026-16401 Privilege Escalation in privilege-escalation (CVE-2026-16401)
vulnerability in privilege-escalation (CVE-2026-16401). Successful exploitation can lead to full system takeover.
CVE-2026-16379 Privilege Escalation in privilege-escalation (CVE-2026-16379)
vulnerability in privilege-escalation (CVE-2026-16379). Successful exploitation can lead to full system takeover.
CVE-2026-16372 Privilege Escalation in privilege-escalation (CVE-2026-16372)
vulnerability in privilege-escalation (CVE-2026-16372). Successful exploitation can lead to full system takeover.
CVE-2026-16371 Privilege Escalation in privilege-escalation (CVE-2026-16371)
vulnerability in privilege-escalation (CVE-2026-16371). Successful exploitation can lead to full system takeover.
CVE-2026-16365 Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
CVE-2026-16366 Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
CVE-2026-60080 Use-After-Free in apache (CVE-2026-60080)
vulnerability in apache (CVE-2026-60080). Risk of unauthorized operations or information disclosure.
CVE-2026-1771 Vulnerability in wordpress (CVE-2026-1771)
vulnerability in wordpress (CVE-2026-1771). Successful exploitation can lead to full system takeover.
CVE-2026-3183 Vulnerability in CVE-2026-3183 (CVE-2026-3183)
vulnerability in CVE-2026-3183 (CVE-2026-3183). Data can be tampered with by attackers.
CVE-2026-8082 SQL Injection in wordpress (CVE-2026-8082)
SQL injection in wordpress (CVE-2026-8082). Confidential information can be exposed externally.
CVE-2026-11767 Cross-Site Scripting (XSS) in wordpress (CVE-2026-11767)
cross-site scripting in wordpress (CVE-2026-11767). Successful exploitation can lead to full system takeover.
CVE-2026-51031 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51031)
SSRF in ssrf (CVE-2026-51031). Confidential information can be exposed externally.
CVE-2024-51316 Vulnerability in dos (CVE-2024-51316)
vulnerability in dos (CVE-2024-51316). Risk of unauthorized operations or information disclosure.
CVE-2026-56623 Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
CVE-2026-56452 Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
CVE-2026-64194 Vulnerability in c (CVE-2026-64194)
vulnerability in c (CVE-2026-64194). Risk of unauthorized operations or information disclosure.
CVE-2026-64612 Vulnerability in dos (CVE-2026-64612)
vulnerability in dos (CVE-2026-64612). Risk of unauthorized operations or information disclosure.
CVE-2026-46555 Path Traversal in path-traversal (CVE-2026-46555)
path traversal in path-traversal (CVE-2026-46555). Confidential information can be exposed externally. Exploitable via `Host header`.
CVE-2026-44178 Vulnerability in dos (CVE-2026-44178)
vulnerability in dos (CVE-2026-44178). Successful exploitation can lead to full system takeover.
CVE-2026-41521 Vulnerability in dos (CVE-2026-41521)
vulnerability in dos (CVE-2026-41521). Confidential information can be exposed externally.
CVE-2026-39879 Vulnerability in c (CVE-2026-39879)
vulnerability in c (CVE-2026-39879). Risk of unauthorized operations or information disclosure. Exploitable via ``afsql_dd_run_query``.
CVE-2026-32825 Vulnerability in rails (CVE-2026-32825)
vulnerability in rails (CVE-2026-32825). Confidential information can be exposed externally.
CVE-2026-32820 Path Traversal in rails (CVE-2026-32820)
path traversal in rails (CVE-2026-32820). Confidential information can be exposed externally. Exploitable via ``docs``.
CVE-2026-21824 Vulnerability in privilege-escalation (CVE-2026-21824)
vulnerability in privilege-escalation (CVE-2026-21824). Successful exploitation can lead to full system takeover.
CVE-2026-52349 Path Traversal in path-traversal (CVE-2026-52349)
path traversal in path-traversal (CVE-2026-52349). Successful exploitation can lead to full system takeover.
CVE-2026-62418 SSRF (Server-Side Request Forgery) in apache (CVE-2026-62418)
SSRF in apache (CVE-2026-62418). Confidential information can be exposed externally.
CVE-2026-16252 Vulnerability in sqli (CVE-2026-16252)
vulnerability in sqli (CVE-2026-16252). Risk of unauthorized operations or information disclosure.
CVE-2026-54910 Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
CVE-2026-63763 Vulnerability in privilege-escalation (CVE-2026-63763)
vulnerability in privilege-escalation (CVE-2026-63763). Successful exploitation can lead to full system takeover.
CVE-2026-63747 Vulnerability in dos (CVE-2026-63747)
vulnerability in dos (CVE-2026-63747). Risk of unauthorized operations or information disclosure.
CVE-2026-12970 Cross-Site Scripting (XSS) in wordpress (CVE-2026-12970)
cross-site scripting in wordpress (CVE-2026-12970). Risk of unauthorized operations or information disclosure.
CVE-2026-11349 SQL Injection in wordpress (CVE-2026-11349)
SQL injection in wordpress (CVE-2026-11349). Confidential information can be exposed externally.
CVE-2026-12592 Cross-Site Scripting (XSS) in wordpress (CVE-2026-12592)
cross-site scripting in wordpress (CVE-2026-12592). Successful exploitation can lead to full system takeover.
CVE-2026-10081 Cross-Site Scripting (XSS) in wordpress (CVE-2026-10081)
cross-site scripting in wordpress (CVE-2026-10081). Successful exploitation can lead to full system takeover.
CVE-2026-12484 Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
CVE-2026-16221 Vulnerability in fast-uri (CVE-2026-16221)
vulnerability in fast-uri (CVE-2026-16221). Data can be tampered with by attackers. Exploitable via ``URL``. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-16228 Vulnerability in sqli (CVE-2026-16228)
vulnerability in sqli (CVE-2026-16228). Risk of unauthorized operations or information disclosure.
CVE-2026-16227 Vulnerability in sqli (CVE-2026-16227)
vulnerability in sqli (CVE-2026-16227). Risk of unauthorized operations or information disclosure.
CVE-2026-10130 Authorization Flaw in CVE-2026-10130 (CVE-2026-10130)
vulnerability in CVE-2026-10130 (CVE-2026-10130). Confidential information can be exposed externally.
CVE-2026-16154 Vulnerability in sqli (CVE-2026-16154)
vulnerability in sqli (CVE-2026-16154). Risk of unauthorized operations or information disclosure.
CVE-2026-16152 Vulnerability in sqli (CVE-2026-16152)
vulnerability in sqli (CVE-2026-16152). Risk of unauthorized operations or information disclosure.
CVE-2026-53994 Vulnerability in dos (CVE-2026-53994)
vulnerability in dos (CVE-2026-53994). Successful exploitation can lead to full system takeover.
CVE-2026-9323 The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
CVE-2026-11826 OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
CVE-2025-71392 Command Injection in privilege-escalation (CVE-2025-71392)
command injection in privilege-escalation (CVE-2025-71392). Successful exploitation can lead to full system takeover.
CVE-2024-58368 SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →