Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-78329 |
|
Vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329)
vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-66906 |
|
Vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906)
vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-71300 |
|
Vulnerability in org.apache.camel:camel-atmosphere-websocket (CVE-2026-71300)
vulnerability in org.apache.camel:camel-atmosphere-websocket (CVE-2026-71300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-76071 |
|
Vulnerability in CVE-2026-76071 (CVE-2026-76071)
vulnerability in CVE-2026-76071 (CVE-2026-76071). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76070 |
|
Vulnerability in CVE-2026-76070 (CVE-2026-76070)
vulnerability in CVE-2026-76070 (CVE-2026-76070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19874 |
|
Vulnerability in CVE-2026-19874 (CVE-2026-19874)
vulnerability in CVE-2026-19874 (CVE-2026-19874). Data can be tampered with by attackers.
|
| CVE-2026-67602 |
|
Vulnerability in CVE-2026-67602 (CVE-2026-67602)
vulnerability in CVE-2026-67602 (CVE-2026-67602). Confidential information can be exposed externally.
|
| CVE-2026-59568 |
|
Vulnerability in CVE-2026-59568 (CVE-2026-59568)
vulnerability in CVE-2026-59568 (CVE-2026-59568). Confidential information can be exposed externally.
|
| CVE-2026-76840 |
|
Vulnerability in c (CVE-2026-76840)
vulnerability in c (CVE-2026-76840). Data can be tampered with by attackers.
|
| CVE-2026-66650 |
|
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
|
| CVE-2026-66587 |
|
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.
|
| CVE-2026-32551 |
|
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
|
| CVE-2026-66897 |
|
Path Traversal in path-traversal (CVE-2026-66897)
path traversal in path-traversal (CVE-2026-66897). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78211 |
|
OS Command Injection in CVE-2026-78211 (CVE-2026-78211)
OS command injection in CVE-2026-78211 (CVE-2026-78211). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78169 |
|
Buffer Overflow in CVE-2026-78169 (CVE-2026-78169)
vulnerability in CVE-2026-78169 (CVE-2026-78169). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78167 |
|
Authentication Bypass in CVE-2026-78167 (CVE-2026-78167)
authentication bypass in CVE-2026-78167 (CVE-2026-78167). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78168 |
|
Authentication Bypass in CVE-2026-78168 (CVE-2026-78168)
authentication bypass in CVE-2026-78168 (CVE-2026-78168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78207 |
|
Vulnerability in c (CVE-2026-78207)
vulnerability in c (CVE-2026-78207). Confidential information can be exposed externally.
|
| CVE-2026-21962 KEV |
|
[KEV] Vulnerability in Oracle c (CVE-2026-21962)
vulnerability in Oracle c (CVE-2026-21962). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-78183 |
|
Out-of-Bounds Write in c (CVE-2026-78183)
out-of-bounds write in c (CVE-2026-78183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8445 |
|
Cross-Site Scripting (XSS) in CVE-2026-8445 (CVE-2026-8445)
cross-site scripting in CVE-2026-8445 (CVE-2026-8445). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.12.0` or later.
|
| CVE-2026-7808 |
|
Vulnerability in CVE-2026-7808 (CVE-2026-7808)
vulnerability in CVE-2026-7808 (CVE-2026-7808). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-5388 |
|
Vulnerability in CVE-2026-5388 (CVE-2026-5388)
vulnerability in CVE-2026-5388 (CVE-2026-5388). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78155 |
|
Vulnerability in privilege-escalation (CVE-2026-78155)
vulnerability in privilege-escalation (CVE-2026-78155). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13598 |
|
Privilege Escalation in wordpress (CVE-2026-13598)
vulnerability in wordpress (CVE-2026-13598). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78050 |
|
Buffer Overflow in CVE-2026-78050 (CVE-2026-78050)
vulnerability in CVE-2026-78050 (CVE-2026-78050). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4703 |
|
Unsafe Deserialization in wordpress (CVE-2026-4703)
vulnerability in wordpress (CVE-2026-4703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75866 |
|
Vulnerability in CVE-2026-75866 (CVE-2026-75866)
vulnerability in CVE-2026-75866 (CVE-2026-75866). Confidential information can be exposed externally.
|
| CVE-2026-77946 |
|
Buffer Overflow in CVE-2026-77946 (CVE-2026-77946)
vulnerability in CVE-2026-77946 (CVE-2026-77946). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78003 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-78003)
SSRF in wordpress (CVE-2026-78003). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77002 |
|
Authentication Bypass in wordpress (CVE-2026-77002)
authentication bypass in wordpress (CVE-2026-77002). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77000 |
|
Authentication Bypass in wordpress (CVE-2026-77000)
authentication bypass in wordpress (CVE-2026-77000). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77001 |
|
Authentication Bypass in wordpress (CVE-2026-77001)
authentication bypass in wordpress (CVE-2026-77001). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49849 |
|
Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62283 |
|
Vulnerability in CVE-2026-62283 (CVE-2026-62283)
vulnerability in CVE-2026-62283 (CVE-2026-62283). Successful exploitation can lead to full system takeover. Exploitable via `GET /ws/terminal/`.
|
| CVE-2026-61539 |
|
Vulnerability in xinference (CVE-2026-61539)
vulnerability in xinference (CVE-2026-61539). Successful exploitation can lead to full system takeover. Exploitable via ``tools``. Mitigation: upgrade to `2.7.0` or later.
|
| CVE-2026-76904 |
|
SQL Injection in org.geotools.jdbc:gt-jdbc-postgis (CVE-2026-76904)
SQL injection in org.geotools.jdbc:gt-jdbc-postgis (CVE-2026-76904). Successful exploitation can lead to full system takeover. Exploitable via ``jsonArrayContains``. Mitigation: upgrade to `33.6` or later.
|
| CVE-2026-77810 |
|
Vulnerability in Amazon aws (CVE-2026-77810)
vulnerability in Amazon aws (CVE-2026-77810). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62674 |
|
Code Injection in CVE-2026-62674 (CVE-2026-62674)
code injection in CVE-2026-62674 (CVE-2026-62674). Successful exploitation can lead to full system takeover. Exploitable via `PUT /sessions/{session_id}/agent`.
|
| CVE-2026-69502 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-69502)
SSRF in ssrf (CVE-2026-69502). Confidential information can be exposed externally.
|
| CVE-2026-77087 |
|
Vulnerability in CVE-2026-77087 (CVE-2026-77087)
vulnerability in CVE-2026-77087 (CVE-2026-77087). Successful exploitation can lead to full system takeover. Exploitable via `Host header`.
|
| CVE-2026-62867 |
|
Vulnerability in CVE-2026-62867 (CVE-2026-62867)
vulnerability in CVE-2026-62867 (CVE-2026-62867). Successful exploitation can lead to full system takeover. Exploitable via ``block.create_options``.
|
| CVE-2026-62941 |
|
Authorization Flaw in CVE-2026-62941 (CVE-2026-62941)
vulnerability in CVE-2026-62941 (CVE-2026-62941). Successful exploitation can lead to full system takeover. Exploitable via ``AllowInstanceCreation``.
|
| CVE-2026-63343 |
|
Vulnerability in CVE-2026-63343 (CVE-2026-63343)
vulnerability in CVE-2026-63343 (CVE-2026-63343). Successful exploitation can lead to full system takeover. Exploitable via ``metadata.yaml``.
|
| CVE-2026-62940 |
|
Vulnerability in CVE-2026-62940 (CVE-2026-62940)
vulnerability in CVE-2026-62940 (CVE-2026-62940). Successful exploitation can lead to full system takeover. Exploitable via ``security.privileged``.
|
| CVE-2026-63125 |
|
Vulnerability in CVE-2026-63125 (CVE-2026-63125)
vulnerability in CVE-2026-63125 (CVE-2026-63125). Successful exploitation can lead to full system takeover. Exploitable via ``can_create_images``.
|
| CVE-2026-77806 |
|
Code Injection in CVE-2026-77806 (CVE-2026-77806)
code injection in CVE-2026-77806 (CVE-2026-77806). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77086 |
|
Path Traversal in path-traversal (CVE-2026-77086)
path traversal in path-traversal (CVE-2026-77086). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77683 |
|
Vulnerability in CVE-2026-77683 (CVE-2026-77683)
vulnerability in CVE-2026-77683 (CVE-2026-77683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61398 |
|
Vulnerability in apache (CVE-2026-61398)
vulnerability in apache (CVE-2026-61398). Confidential information can be exposed externally.
|