Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44129 |
|
Vulnerability in CVE-2026-44129 (CVE-2026-44129)
vulnerability in CVE-2026-44129 (CVE-2026-44129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44339 |
|
Vulnerability in praison (CVE-2026-44339)
vulnerability in praison (CVE-2026-44339). Data can be tampered with by attackers.
|
| CVE-2026-44126 |
|
Unsafe Deserialization in CVE-2026-44126 (CVE-2026-44126)
vulnerability in CVE-2026-44126 (CVE-2026-44126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44128 |
|
Vulnerability in CVE-2026-44128 (CVE-2026-44128)
vulnerability in CVE-2026-44128 (CVE-2026-44128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44127 |
|
Vulnerability in path-traversal (CVE-2026-44127)
vulnerability in path-traversal (CVE-2026-44127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44125 |
|
Vulnerability in CVE-2026-44125 (CVE-2026-44125)
vulnerability in CVE-2026-44125 (CVE-2026-44125). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41507 |
|
Code Injection in remote (CVE-2026-41507)
code injection in remote (CVE-2026-41507). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41512 |
|
Code Injection in gem (CVE-2026-41512)
code injection in gem (CVE-2026-41512). Successful exploitation can lead to full system takeover. Exploitable via `POST /targets/auto_detect_selectors`.
|
| CVE-2026-41509 |
|
Vulnerability in CVE-2026-41509 (CVE-2026-41509)
vulnerability in CVE-2026-41509 (CVE-2026-41509). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41493 |
|
Path Traversal in path-traversal (CVE-2026-41493)
path traversal in path-traversal (CVE-2026-41493). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41161 |
|
Vulnerability in CVE-2026-41161 (CVE-2026-41161)
vulnerability in CVE-2026-41161 (CVE-2026-41161). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41497 |
|
Command Injection in praison (CVE-2026-41497)
command injection in praison (CVE-2026-41497). Successful exploitation can lead to full system takeover. Exploitable via ``bash``. Mitigation: upgrade to `>= 4.6.9` or later.
|
| CVE-2026-41496 |
|
SQL Injection in praison (CVE-2026-41496)
SQL injection in praison (CVE-2026-41496). Confidential information can be exposed externally.
|
| CVE-2026-41506 |
|
Vulnerability in CVE-2026-41506 (CVE-2026-41506)
vulnerability in CVE-2026-41506 (CVE-2026-41506). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41491 |
|
Path Traversal in path-traversal (CVE-2026-41491)
path traversal in path-traversal (CVE-2026-41491). Confidential information can be exposed externally.
|
| CVE-2026-41423 |
|
SSRF (Server-Side Request Forgery) in express (CVE-2026-41423)
SSRF in express (CVE-2026-41423). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39816 |
|
Vulnerability in apache (CVE-2026-39816)
vulnerability in apache (CVE-2026-39816). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32803 |
|
Vulnerability in dell (CVE-2026-32803)
vulnerability in dell (CVE-2026-32803). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8077 |
|
Vulnerability in CVE-2026-8077 (CVE-2026-8077)
vulnerability in CVE-2026-8077 (CVE-2026-8077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25077 |
|
Code Injection in apache (CVE-2026-25077)
code injection in apache (CVE-2026-25077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25199 |
|
Information Disclosure in apache (CVE-2026-25199)
vulnerability in apache (CVE-2026-25199). Confidential information can be exposed externally.
|
| CVE-2025-66170 |
|
Authorization Flaw in CVE-2025-66170 (CVE-2025-66170)
vulnerability in CVE-2025-66170 (CVE-2025-66170). Confidential information can be exposed externally.
|
| CVE-2025-69233 |
|
Vulnerability in apache (CVE-2025-69233)
vulnerability in apache (CVE-2025-69233). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-66467 |
|
Vulnerability in apache (CVE-2025-66467)
vulnerability in apache (CVE-2025-66467). Successful exploitation can lead to full system takeover.
|
| CVE-2022-50994 |
|
OS Command Injection in CVE-2022-50994 (CVE-2022-50994)
OS command injection in CVE-2022-50994 (CVE-2022-50994). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8076 |
|
Vulnerability in CVE-2026-8076 (CVE-2026-8076)
vulnerability in CVE-2026-8076 (CVE-2026-8076). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8153 |
|
OS Command Injection in iot-embedded (CVE-2026-8153)
OS command injection in iot-embedded (CVE-2026-8153). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3318 |
|
Open Redirect in CVE-2026-3318 (CVE-2026-3318)
vulnerability in CVE-2026-3318 (CVE-2026-3318). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7650 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7650)
cross-site scripting in wordpress (CVE-2026-7650). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7475 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7475)
cross-site scripting in wordpress (CVE-2026-7475). Risk of unauthorized operations or information disclosure. Exploitable via ``sky_script_content``.
|
| CVE-2026-6213 |
|
Vulnerability in CVE-2026-6213 (CVE-2026-6213)
vulnerability in CVE-2026-6213 (CVE-2026-6213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5341 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5341)
cross-site scripting in wordpress (CVE-2026-5341). Risk of unauthorized operations or information disclosure. Exploitable via ``strava_nmr_connect``.
|
| CVE-2026-7330 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7330)
cross-site scripting in wordpress (CVE-2026-7330). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5127 |
|
Unsafe Deserialization in wordpress (CVE-2026-5127)
vulnerability in wordpress (CVE-2026-5127). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44928 |
|
Vulnerability in CVE-2026-44928 (CVE-2026-44928)
vulnerability in CVE-2026-44928 (CVE-2026-44928). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44927 |
|
Vulnerability in CVE-2026-44927 (CVE-2026-44927)
vulnerability in CVE-2026-44927 (CVE-2026-44927). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43284 |
|
Vulnerability in linux (CVE-2026-43284)
vulnerability in linux (CVE-2026-43284). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4935 |
|
SQL Injection in wordpress (CVE-2026-4935)
SQL injection in wordpress (CVE-2026-4935). Confidential information can be exposed externally.
|
| CVE-2026-44916 |
|
Vulnerability in CVE-2026-44916 (CVE-2026-44916)
vulnerability in CVE-2026-44916 (CVE-2026-44916). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8149 |
|
Vulnerability in CVE-2026-8149 (CVE-2026-8149)
vulnerability in CVE-2026-8149 (CVE-2026-8149). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8069 |
|
Path Traversal in privilege-escalation (CVE-2026-8069)
path traversal in privilege-escalation (CVE-2026-8069). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-67886 |
|
Unrestricted File Upload in CVE-2025-67886 (CVE-2025-67886)
vulnerability in CVE-2025-67886 (CVE-2025-67886). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-67888 |
|
OS Command Injection in CVE-2025-67888 (CVE-2025-67888)
OS command injection in CVE-2025-67888 (CVE-2025-67888). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-55449 |
|
Vulnerability in CVE-2025-55449 (CVE-2025-55449)
vulnerability in CVE-2025-55449 (CVE-2025-55449). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69691 |
|
Vulnerability in pfsense (CVE-2025-69691)
vulnerability in pfsense (CVE-2025-69691). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69690 |
|
Unsafe Deserialization in deserialization (CVE-2025-69690)
vulnerability in deserialization (CVE-2025-69690). Successful exploitation can lead to full system takeover.
|
| CVE-2023-46453 |
|
SQL Injection in network-device (CVE-2023-46453)
SQL injection in network-device (CVE-2023-46453). Successful exploitation can lead to full system takeover.
|
| CVE-2024-51092 |
|
OS Command Injection in command-injection (CVE-2024-51092)
OS command injection in command-injection (CVE-2024-51092). Confidential information can be exposed externally. Exploitable via ``version_netsnmp``.
|
| CVE-2024-53326 |
|
Unsafe Deserialization in deserialization (CVE-2024-53326)
vulnerability in deserialization (CVE-2024-53326). Successful exploitation can lead to full system takeover.
|
| CVE-2024-33288 |
|
SQL Injection in sqli (CVE-2024-33288)
SQL injection in sqli (CVE-2024-33288). Risk of unauthorized operations or information disclosure.
|