Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14633 |
|
Cross-Site Scripting (XSS) in CVE-2026-14633 (CVE-2026-14633)
cross-site scripting in CVE-2026-14633 (CVE-2026-14633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14629 |
|
Vulnerability in c (CVE-2026-14629)
vulnerability in c (CVE-2026-14629). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14534 |
|
Vulnerability in fickling (CVE-2026-14534)
vulnerability in fickling (CVE-2026-14534). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.11` or later.
|
| CVE-2026-53360 |
|
Out-of-Bounds Read in c (CVE-2026-53360)
vulnerability in c (CVE-2026-53360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14622 |
|
Authentication Bypass in CVE-2026-14622 (CVE-2026-14622)
authentication bypass in CVE-2026-14622 (CVE-2026-14622). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14621 |
|
Vulnerability in CVE-2026-14621 (CVE-2026-14621)
vulnerability in CVE-2026-14621 (CVE-2026-14621). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14619 |
|
Vulnerability in sqli (CVE-2026-14619)
vulnerability in sqli (CVE-2026-14619). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12194 |
|
Vulnerability in CVE-2026-12194 (CVE-2026-12194)
vulnerability in CVE-2026-12194 (CVE-2026-12194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14618 |
|
Vulnerability in c (CVE-2026-14618)
vulnerability in c (CVE-2026-14618). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71372 |
|
Unsafe Deserialization in picklescan (CVE-2025-71372)
vulnerability in picklescan (CVE-2025-71372). Confidential information can be exposed externally. Exploitable via ``numpy.f2py.crackfortran.getlincoef``. Mitigation: upgrade to `0.0.33` or later.
|
| CVE-2026-12252 |
|
Code Injection in nltk (CVE-2026-12252)
code injection in nltk (CVE-2026-12252). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.4` or later.
|
| CVE-2026-14610 |
|
Buffer Overflow in cpp (CVE-2026-14610)
vulnerability in cpp (CVE-2026-14610). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14355 |
|
Vulnerability in php (CVE-2026-14355)
vulnerability in php (CVE-2026-14355). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.2.32, 8.3.32, 8.4.23, 8.5.8` or later.
|
| CVE-2026-14608 |
|
Vulnerability in CVE-2026-14608 (CVE-2026-14608)
vulnerability in CVE-2026-14608 (CVE-2026-14608). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14607 |
|
Buffer Overflow in c (CVE-2026-14607)
vulnerability in c (CVE-2026-14607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14604 |
|
Buffer Overflow in cpp (CVE-2026-14604)
vulnerability in cpp (CVE-2026-14604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14631 |
|
Vulnerability in webpack-dev-server (CVE-2026-14631)
vulnerability in webpack-dev-server (CVE-2026-14631). Risk of unauthorized operations or information disclosure. Exploitable via ``Host``. Mitigation: upgrade to `5.2.6` or later.
|
| CVE-2026-59234 |
|
Vulnerability in CVE-2026-59234 (CVE-2026-59234)
vulnerability in CVE-2026-59234 (CVE-2026-59234). Risk of unauthorized operations or information disclosure. Exploitable via `GET /calendar/event/delete/{id}`.
|
| CVE-2026-5137 |
|
Vulnerability in wordpress (CVE-2026-5137)
vulnerability in wordpress (CVE-2026-5137). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9756 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9756)
cross-site scripting in wordpress (CVE-2026-9756). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47896 |
|
Path Traversal in csharp (CVE-2026-47896)
path traversal in csharp (CVE-2026-47896). Confidential information can be exposed externally.
|
| CVE-2026-47897 |
|
Path Traversal in csharp (CVE-2026-47897)
path traversal in csharp (CVE-2026-47897). Data can be tampered with by attackers.
|
| CVE-2026-47898 |
|
XXE (XML External Entity) in csharp (CVE-2026-47898)
vulnerability in csharp (CVE-2026-47898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9725 |
|
Path Traversal in wordpress (CVE-2026-9725)
path traversal in wordpress (CVE-2026-9725). Data can be tampered with by attackers.
|
| CVE-2026-9180 |
|
Vulnerability in wordpress (CVE-2026-9180)
vulnerability in wordpress (CVE-2026-9180). Risk of unauthorized operations or information disclosure. Exploitable via `POST /motopress/appointment/v1/bookings`.
|
| CVE-2026-38972 |
|
Vulnerability in c (CVE-2026-38972)
vulnerability in c (CVE-2026-38972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38971 |
|
Out-of-Bounds Read in cpp (CVE-2026-38971)
vulnerability in cpp (CVE-2026-38971). Confidential information can be exposed externally.
|
| CVE-2026-38968 |
|
Vulnerability in cpp (CVE-2026-38968)
vulnerability in cpp (CVE-2026-38968). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59102 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-59102)
cross-site scripting in vue (CVE-2026-59102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38969 |
|
Vulnerability in CVE-2026-38969 (CVE-2026-38969)
vulnerability in CVE-2026-38969 (CVE-2026-38969). Data can be tampered with by attackers.
|
| CVE-2026-58578 |
|
Vulnerability in dos (CVE-2026-58578)
vulnerability in dos (CVE-2026-58578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58579 |
|
Cross-Site Scripting (XSS) in CVE-2026-58579 (CVE-2026-58579)
cross-site scripting in CVE-2026-58579 (CVE-2026-58579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2026-49353 |
|
Vulnerability in 9router (CVE-2026-49353)
vulnerability in 9router (CVE-2026-49353). Data can be tampered with by attackers. Exploitable via `GET /api/mcp/`.
|
| CVE-2026-49352 |
|
Vulnerability in 9router (CVE-2026-49352)
vulnerability in 9router (CVE-2026-49352). Successful exploitation can lead to full system takeover. Exploitable via ``JWT_SECRET``. Mitigation: upgrade to `0.4.45` or later.
|
| CVE-2026-49289 |
|
Vulnerability in simplesamlphp/saml2 (CVE-2026-49289)
vulnerability in simplesamlphp/saml2 (CVE-2026-49289). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.19.3` or later.
|
| CVE-2026-52829 |
|
Vulnerability in zebra-network (CVE-2026-52829)
vulnerability in zebra-network (CVE-2026-52829). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-49283 |
|
Vulnerability in simplesamlphp/saml2 (CVE-2026-49283)
vulnerability in simplesamlphp/saml2 (CVE-2026-49283). Confidential information can be exposed externally. Exploitable via ``Response``. Mitigation: upgrade to `4.19.3` or later.
|
| CVE-2026-52734 |
|
Vulnerability in zebrad (CVE-2026-52734)
vulnerability in zebrad (CVE-2026-52734). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `4.5.0` or later.
|
| CVE-2026-52733 |
|
Vulnerability in zebra-state (CVE-2026-52733)
vulnerability in zebra-state (CVE-2026-52733). Data can be tampered with by attackers. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-52739 |
|
Vulnerability in zebra-state (CVE-2026-52739)
vulnerability in zebra-state (CVE-2026-52739). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-52738 |
|
Vulnerability in zebra-state (CVE-2026-52738)
vulnerability in zebra-state (CVE-2026-52738). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-52737 |
|
Vulnerability in zebra-consensus (CVE-2026-52737)
vulnerability in zebra-consensus (CVE-2026-52737). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-52735 |
|
Vulnerability in zebra-script (CVE-2026-52735)
vulnerability in zebra-script (CVE-2026-52735). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-52736 |
|
Vulnerability in zebra-state (CVE-2026-52736)
vulnerability in zebra-state (CVE-2026-52736). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-52732 |
|
Vulnerability in zebrad (CVE-2026-52732)
vulnerability in zebrad (CVE-2026-52732). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `4.5.0` or later.
|
| CVE-2026-52731 |
|
Vulnerability in zebra-rpc (CVE-2026-52731)
vulnerability in zebra-rpc (CVE-2026-52731). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `8.0.0` or later.
|
| CVE-2026-49255 |
|
OS Command Injection in electerm (CVE-2026-49255)
OS command injection in electerm (CVE-2026-49255). Successful exploitation can lead to full system takeover. Exploitable via ``rmrf``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-49253 |
|
Path Traversal in electerm (CVE-2026-49253)
path traversal in electerm (CVE-2026-49253). Data can be tampered with by attackers. Exploitable via ``savedFilePaths``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|