Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64824 |
|
Path Traversal in path-traversal (CVE-2026-64824)
path traversal in path-traversal (CVE-2026-64824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44907 |
|
Vulnerability in react-server-dom-webpack (CVE-2026-44907)
vulnerability in react-server-dom-webpack (CVE-2026-44907). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `19.2.8` or later.
|
| CVE-2026-8933 |
|
Vulnerability in privilege-escalation (CVE-2026-8933)
vulnerability in privilege-escalation (CVE-2026-8933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16396 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16396)
vulnerability in privilege-escalation (CVE-2026-16396). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16401 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16401)
vulnerability in privilege-escalation (CVE-2026-16401). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16379 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16379)
vulnerability in privilege-escalation (CVE-2026-16379). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16372 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16372)
vulnerability in privilege-escalation (CVE-2026-16372). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16371 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16371)
vulnerability in privilege-escalation (CVE-2026-16371). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16365 |
|
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-16366 |
|
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-60080 |
|
Use-After-Free in apache (CVE-2026-60080)
vulnerability in apache (CVE-2026-60080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1771 |
|
Vulnerability in wordpress (CVE-2026-1771)
vulnerability in wordpress (CVE-2026-1771). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3183 |
|
Vulnerability in CVE-2026-3183 (CVE-2026-3183)
vulnerability in CVE-2026-3183 (CVE-2026-3183). Data can be tampered with by attackers.
|
| CVE-2026-8082 |
|
SQL Injection in wordpress (CVE-2026-8082)
SQL injection in wordpress (CVE-2026-8082). Confidential information can be exposed externally.
|
| CVE-2026-11767 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11767)
cross-site scripting in wordpress (CVE-2026-11767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51031 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51031)
SSRF in ssrf (CVE-2026-51031). Confidential information can be exposed externally.
|
| CVE-2024-51316 |
|
Vulnerability in dos (CVE-2024-51316)
vulnerability in dos (CVE-2024-51316). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56623 |
|
Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
|
| CVE-2026-56452 |
|
Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
|
| CVE-2026-64194 |
|
Vulnerability in c (CVE-2026-64194)
vulnerability in c (CVE-2026-64194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64612 |
|
Vulnerability in dos (CVE-2026-64612)
vulnerability in dos (CVE-2026-64612). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46555 |
|
Path Traversal in path-traversal (CVE-2026-46555)
path traversal in path-traversal (CVE-2026-46555). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| CVE-2026-44178 |
|
Vulnerability in dos (CVE-2026-44178)
vulnerability in dos (CVE-2026-44178). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41521 |
|
Vulnerability in dos (CVE-2026-41521)
vulnerability in dos (CVE-2026-41521). Confidential information can be exposed externally.
|
| CVE-2026-39879 |
|
Vulnerability in c (CVE-2026-39879)
vulnerability in c (CVE-2026-39879). Risk of unauthorized operations or information disclosure. Exploitable via ``afsql_dd_run_query``.
|
| CVE-2026-32825 |
|
Vulnerability in rails (CVE-2026-32825)
vulnerability in rails (CVE-2026-32825). Confidential information can be exposed externally.
|
| CVE-2026-32820 |
|
Path Traversal in rails (CVE-2026-32820)
path traversal in rails (CVE-2026-32820). Confidential information can be exposed externally. Exploitable via ``docs``.
|
| CVE-2026-21824 |
|
Vulnerability in privilege-escalation (CVE-2026-21824)
vulnerability in privilege-escalation (CVE-2026-21824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52349 |
|
Path Traversal in path-traversal (CVE-2026-52349)
path traversal in path-traversal (CVE-2026-52349). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62418 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-62418)
SSRF in apache (CVE-2026-62418). Confidential information can be exposed externally.
|
| CVE-2026-16252 |
|
Vulnerability in sqli (CVE-2026-16252)
vulnerability in sqli (CVE-2026-16252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54910 |
|
Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
|
| CVE-2026-63763 |
|
Vulnerability in privilege-escalation (CVE-2026-63763)
vulnerability in privilege-escalation (CVE-2026-63763). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63747 |
|
Vulnerability in dos (CVE-2026-63747)
vulnerability in dos (CVE-2026-63747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12970 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12970)
cross-site scripting in wordpress (CVE-2026-12970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11349 |
|
SQL Injection in wordpress (CVE-2026-11349)
SQL injection in wordpress (CVE-2026-11349). Confidential information can be exposed externally.
|
| CVE-2026-12592 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12592)
cross-site scripting in wordpress (CVE-2026-12592). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10081 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10081)
cross-site scripting in wordpress (CVE-2026-10081). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12484 |
|
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
|
| CVE-2026-16221 |
|
Vulnerability in fast-uri (CVE-2026-16221)
vulnerability in fast-uri (CVE-2026-16221). Data can be tampered with by attackers. Exploitable via ``URL``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-16228 |
|
Vulnerability in sqli (CVE-2026-16228)
vulnerability in sqli (CVE-2026-16228). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16227 |
|
Vulnerability in sqli (CVE-2026-16227)
vulnerability in sqli (CVE-2026-16227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10130 |
|
Authorization Flaw in CVE-2026-10130 (CVE-2026-10130)
vulnerability in CVE-2026-10130 (CVE-2026-10130). Confidential information can be exposed externally.
|
| CVE-2026-16154 |
|
Vulnerability in sqli (CVE-2026-16154)
vulnerability in sqli (CVE-2026-16154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16152 |
|
Vulnerability in sqli (CVE-2026-16152)
vulnerability in sqli (CVE-2026-16152). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53994 |
|
Vulnerability in dos (CVE-2026-53994)
vulnerability in dos (CVE-2026-53994). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9323 |
|
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id)...
|
| CVE-2026-11826 |
|
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core...
|
| CVE-2025-71392 |
|
Command Injection in privilege-escalation (CVE-2025-71392)
command injection in privilege-escalation (CVE-2025-71392). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58368 |
|
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
SurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST...
|