Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-58465 |
|
Vulnerability in c (CVE-2026-58465)
vulnerability in c (CVE-2026-58465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49852 |
|
Authentication Bypass in joserfc (CVE-2026-49852)
authentication bypass in joserfc (CVE-2026-49852). Risk of unauthorized operations or information disclosure. Exploitable via ``joserfc.jwt.decode``. Mitigation: upgrade to `1.6.8` or later.
|
| CVE-2026-50290 |
|
Cross-Site Scripting (XSS) in @asymmetric-effort/specifyjs (CVE-2026-50290)
cross-site scripting in @asymmetric-effort/specifyjs (CVE-2026-50290). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.2.136` or later.
|
| CVE-2026-44454 |
|
OS Command Injection in github.com/coder/coder/v2 (CVE-2026-44454)
OS command injection in github.com/coder/coder/v2 (CVE-2026-44454). Confidential information can be exposed externally. Exploitable via ``dotfiles``. Mitigation: upgrade to `2.30.2` or later.
|
| CVE-2026-52854 |
|
Cross-Site Scripting (XSS) in mediawiki/maps (CVE-2026-52854)
cross-site scripting in mediawiki/maps (CVE-2026-52854). Confidential information can be exposed externally. Exploitable via ``overlays``. Mitigation: upgrade to `12.1.3` or later.
|
| CVE-2026-8699 |
|
Cross-Site Scripting (XSS) in CVE-2026-8699 (CVE-2026-8699)
cross-site scripting in CVE-2026-8699 (CVE-2026-8699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50281 |
|
Vulnerability in craftcms/cms (CVE-2026-50281)
vulnerability in craftcms/cms (CVE-2026-50281). Risk of unauthorized operations or information disclosure. Exploitable via ``newAttributes``. Mitigation: upgrade to `5.9.21` or later.
|
| CVE-2026-58455 |
|
OS Command Injection in CVE-2026-58455 (CVE-2026-58455)
OS command injection in CVE-2026-58455 (CVE-2026-58455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5524 |
|
Unrestricted File Upload in wordpress (CVE-2026-5524)
vulnerability in wordpress (CVE-2026-5524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57621 |
|
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
|
| CVE-2026-57677 |
|
Unsafe Deserialization in CVE-2026-57677 (CVE-2026-57677)
vulnerability in CVE-2026-57677 (CVE-2026-57677). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27060 |
|
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
|
| CVE-2026-27414 |
|
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
|
| CVE-2026-9834 |
|
Command Injection in wordpress (CVE-2026-9834)
command injection in wordpress (CVE-2026-9834). Successful exploitation can lead to full system takeover. Exploitable via ``wp_db_exclude_table``.
|
| CVE-2026-9145 |
|
Path Traversal in wordpress (CVE-2026-9145)
path traversal in wordpress (CVE-2026-9145). Confidential information can be exposed externally.
|
| CVE-2026-14249 |
|
Vulnerability in wordpress (CVE-2026-14249)
vulnerability in wordpress (CVE-2026-14249). Data can be tampered with by attackers.
|
| CVE-2026-38891 |
|
Vulnerability in cpp (CVE-2026-38891)
vulnerability in cpp (CVE-2026-38891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55790 |
|
Cross-Site Scripting (XSS) in craftcms/cms (CVE-2026-55790)
cross-site scripting in craftcms/cms (CVE-2026-55790). Risk of unauthorized operations or information disclosure. Exploitable via ``CraftSupportWidget.js``. Mitigation: upgrade to `4.17.16` or later.
|
| CVE-2026-54704 |
|
Vulnerability in io.opentelemetry.javaagent:opentelemetry-javaagent (CVE-2026-54704)
vulnerability in io.opentelemetry.javaagent:opentelemetry-javaagent (CVE-2026-54704). Confidential information can be exposed externally. Mitigation: upgrade to `2.28.0-alpha` or later.
|
| CVE-2026-54712 |
|
Vulnerability in io.opentelemetry.javaagent:opentelemetry-javaagent (CVE-2026-54712)
vulnerability in io.opentelemetry.javaagent:opentelemetry-javaagent (CVE-2026-54712). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.27.0` or later.
|
| CVE-2026-55793 |
|
Cross-Site Scripting (XSS) in craftcms/cms (CVE-2026-55793)
cross-site scripting in craftcms/cms (CVE-2026-55793). Risk of unauthorized operations or information disclosure. Exploitable via ``saveEntries``. Mitigation: upgrade to `5.9.53` or later.
|
| CVE-2026-50138 |
|
Vulnerability in goshs.de/goshs/v2 (CVE-2026-50138)
vulnerability in goshs.de/goshs/v2 (CVE-2026-50138). Confidential information can be exposed externally. Exploitable via ``goshs``. Mitigation: upgrade to `2.1.0` or later.
|
| CVE-2026-58451 |
|
Path Traversal in csrf (CVE-2026-58451)
path traversal in csrf (CVE-2026-58451). Confidential information can be exposed externally.
|
| CVE-2026-58592 |
|
Out-of-Bounds Write in cpp (CVE-2026-58592)
out-of-bounds write in cpp (CVE-2026-58592). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54720 |
|
Cross-Site Scripting (XSS) in silverstripe/framework (CVE-2026-54720)
cross-site scripting in silverstripe/framework (CVE-2026-54720). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.2` or later.
|
| CVE-2026-55153 |
|
Vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153)
vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153). Successful exploitation can lead to full system takeover. Exploitable via ``ObjectFactory``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-14265 |
|
Unsafe Deserialization in Amazon aws (CVE-2026-14265)
vulnerability in Amazon aws (CVE-2026-14265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55688 |
|
Vulnerability in org.asynchttpclient:async-http-client (CVE-2026-55688)
vulnerability in org.asynchttpclient:async-http-client (CVE-2026-55688). Risk of unauthorized operations or information disclosure. Exploitable via ``ThreadSafeCookieStore``. Mitigation: upgrade to `3.0.11` or later.
|
| CVE-2026-54164 |
|
Vulnerability in api-platform/core (CVE-2026-54164)
vulnerability in api-platform/core (CVE-2026-54164). Data can be tampered with by attackers. Exploitable via ``AbstractItemNormalizer``. Mitigation: upgrade to `4.3.12` or later.
|
| CVE-2026-48815 |
|
Vulnerability in sigstore (CVE-2026-48815)
vulnerability in sigstore (CVE-2026-48815). Data can be tampered with by attackers. Exploitable via ``certificateOIDs``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-48816 |
|
Vulnerability in @sigstore/verify (CVE-2026-48816)
vulnerability in @sigstore/verify (CVE-2026-48816). Data can be tampered with by attackers. Exploitable via ``timestampThreshold``. Mitigation: upgrade to `3.1.1` or later.
|
| CVE-2026-49981 |
|
Vulnerability in twig/twig (CVE-2026-49981)
vulnerability in twig/twig (CVE-2026-49981). Confidential information can be exposed externally. Exploitable via ``Template``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-34112 |
|
OS Command Injection in CVE-2026-34112 (CVE-2026-34112)
OS command injection in CVE-2026-34112 (CVE-2026-34112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34114 |
|
OS Command Injection in CVE-2026-34114 (CVE-2026-34114)
OS command injection in CVE-2026-34114 (CVE-2026-34114). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34117 |
|
OS Command Injection in CVE-2026-34117 (CVE-2026-34117)
OS command injection in CVE-2026-34117 (CVE-2026-34117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34110 |
|
OS Command Injection in CVE-2026-34110 (CVE-2026-34110)
OS command injection in CVE-2026-34110 (CVE-2026-34110). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34113 |
|
OS Command Injection in CVE-2026-34113 (CVE-2026-34113)
OS command injection in CVE-2026-34113 (CVE-2026-34113). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34108 |
|
OS Command Injection in CVE-2026-34108 (CVE-2026-34108)
OS command injection in CVE-2026-34108 (CVE-2026-34108). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34111 |
|
OS Command Injection in CVE-2026-34111 (CVE-2026-34111)
OS command injection in CVE-2026-34111 (CVE-2026-34111). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34116 |
|
OS Command Injection in CVE-2026-34116 (CVE-2026-34116)
OS command injection in CVE-2026-34116 (CVE-2026-34116). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34115 |
|
OS Command Injection in CVE-2026-34115 (CVE-2026-34115)
OS command injection in CVE-2026-34115 (CVE-2026-34115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34104 |
|
SQL Injection in sqli (CVE-2026-34104)
SQL injection in sqli (CVE-2026-34104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34103 |
|
SQL Injection in sqli (CVE-2026-34103)
SQL injection in sqli (CVE-2026-34103). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34106 |
|
OS Command Injection in CVE-2026-34106 (CVE-2026-34106)
OS command injection in CVE-2026-34106 (CVE-2026-34106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34109 |
|
OS Command Injection in CVE-2026-34109 (CVE-2026-34109)
OS command injection in CVE-2026-34109 (CVE-2026-34109). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34105 |
|
SQL Injection in sqli (CVE-2026-34105)
SQL injection in sqli (CVE-2026-34105). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34107 |
|
OS Command Injection in CVE-2026-34107 (CVE-2026-34107)
OS command injection in CVE-2026-34107 (CVE-2026-34107). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34100 |
|
SQL Injection in sqli (CVE-2026-34100)
SQL injection in sqli (CVE-2026-34100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34098 |
|
Cross-Site Scripting (XSS) in CVE-2026-34098 (CVE-2026-34098)
cross-site scripting in CVE-2026-34098 (CVE-2026-34098). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34097 |
|
Cross-Site Scripting (XSS) in CVE-2026-34097 (CVE-2026-34097)
cross-site scripting in CVE-2026-34097 (CVE-2026-34097). Risk of unauthorized operations or information disclosure.
|