Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-34771 |
|
Use-After-Free in electronjs (CVE-2026-34771)
vulnerability in electronjs (CVE-2026-34771). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34766 |
|
Vulnerability in electronjs (CVE-2026-34766)
vulnerability in electronjs (CVE-2026-34766). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34767 |
|
Vulnerability in electronjs (CVE-2026-34767)
vulnerability in electronjs (CVE-2026-34767). Data can be tampered with by attackers.
|
| CVE-2026-34768 |
|
Vulnerability in electronjs (CVE-2026-34768)
vulnerability in electronjs (CVE-2026-34768). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34770 |
|
Use-After-Free in electronjs (CVE-2026-34770)
vulnerability in electronjs (CVE-2026-34770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34937 |
|
OS Command Injection in praisonaiagents (CVE-2026-34937)
OS command injection in praisonaiagents (CVE-2026-34937). Successful exploitation can lead to full system takeover. Exploitable via ``praisonai``. Mitigation: upgrade to `1.5.90` or later.
|
| CVE-2026-34938 |
|
Vulnerability in praisonaiagents (CVE-2026-34938)
vulnerability in praisonaiagents (CVE-2026-34938). Successful exploitation can lead to full system takeover. Exploitable via ``str``. Mitigation: upgrade to `1.5.90` or later.
|
| CVE-2026-34939 |
|
Vulnerability in praisonai (CVE-2026-34939)
vulnerability in praisonai (CVE-2026-34939). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.5.90` or later.
|
| CVE-2026-35468 |
|
Vulnerability in nimiq (CVE-2026-35468)
vulnerability in nimiq (CVE-2026-35468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34788 |
|
SQL Injection in sqli (CVE-2026-34788)
SQL injection in sqli (CVE-2026-34788). Confidential information can be exposed externally.
|
| CVE-2026-34824 |
|
Out-of-Bounds Read in mesop (CVE-2026-34824)
vulnerability in mesop (CVE-2026-34824). Risk of unauthorized operations or information disclosure. Exploitable via ``handle_websocket``. Mitigation: upgrade to `1.2.5` or later.
|
| CVE-2026-34607 |
|
Path Traversal in path-traversal (CVE-2026-34607)
path traversal in path-traversal (CVE-2026-34607). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34787 |
|
Vulnerability in csrf (CVE-2026-34787)
vulnerability in csrf (CVE-2026-34787). Confidential information can be exposed externally.
|
| CVE-2026-33184 |
|
Vulnerability in nimiq (CVE-2026-33184)
vulnerability in nimiq (CVE-2026-33184). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34061 |
|
Vulnerability in nimiq (CVE-2026-34061)
vulnerability in nimiq (CVE-2026-34061). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28797 |
|
Vulnerability in infiniflow (CVE-2026-28797)
vulnerability in infiniflow (CVE-2026-28797). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26058 |
|
Path Traversal in path-traversal (CVE-2026-26058)
path traversal in path-traversal (CVE-2026-26058). Confidential information can be exposed externally.
|
| CVE-2026-5484 |
|
Vulnerability in CVE-2026-5484 (CVE-2026-5484)
vulnerability in CVE-2026-5484 (CVE-2026-5484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2625 |
|
Vulnerability in dos (CVE-2026-2625)
vulnerability in dos (CVE-2026-2625). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23462 |
|
Use-After-Free in c (CVE-2026-23462)
vulnerability in c (CVE-2026-23462). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23465 |
|
Vulnerability in c (CVE-2026-23465)
vulnerability in c (CVE-2026-23465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5475 |
|
Buffer Overflow in c (CVE-2026-5475)
vulnerability in c (CVE-2026-5475). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5476 |
|
Vulnerability in c (CVE-2026-5476)
vulnerability in c (CVE-2026-5476). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5474 |
|
Buffer Overflow in c (CVE-2026-5474)
vulnerability in c (CVE-2026-5474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5472 |
|
Vulnerability in CVE-2026-5472 (CVE-2026-5472)
vulnerability in CVE-2026-5472 (CVE-2026-5472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35214 |
|
Path Traversal in path-traversal (CVE-2026-35214)
path traversal in path-traversal (CVE-2026-35214). Data can be tampered with by attackers. Exploitable via `POST /api/plugin/upload`.
|
| CVE-2026-31398 |
|
Vulnerability in c (CVE-2026-31398)
vulnerability in c (CVE-2026-31398). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31396 |
|
Use-After-Free in c (CVE-2026-31396)
vulnerability in c (CVE-2026-31396). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23474 |
|
Vulnerability in c (CVE-2026-23474)
vulnerability in c (CVE-2026-23474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23469 |
|
Vulnerability in c (CVE-2026-23469)
vulnerability in c (CVE-2026-23469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23449 |
|
Vulnerability in c (CVE-2026-23449)
vulnerability in c (CVE-2026-23449). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23439 |
|
Vulnerability in c (CVE-2026-23439)
vulnerability in c (CVE-2026-23439). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26477 |
|
Vulnerability in dos (CVE-2026-26477)
vulnerability in dos (CVE-2026-26477). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-59709 |
|
Path Traversal in c (CVE-2025-59709)
path traversal in c (CVE-2025-59709). Confidential information can be exposed externally.
|
| CVE-2026-4350 |
|
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verifi...
|
| CVE-2026-5462 |
|
Vulnerability in CVE-2026-5462 (CVE-2026-5462)
vulnerability in CVE-2026-5462 (CVE-2026-5462). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5458 |
|
Vulnerability in CVE-2026-5458 (CVE-2026-5458)
vulnerability in CVE-2026-5458 (CVE-2026-5458). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5456 |
|
Vulnerability in CVE-2026-5456 (CVE-2026-5456)
vulnerability in CVE-2026-5456 (CVE-2026-5456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5457 |
|
Vulnerability in CVE-2026-5457 (CVE-2026-5457)
vulnerability in CVE-2026-5457 (CVE-2026-5457). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5453 |
|
Vulnerability in CVE-2026-5453 (CVE-2026-5453)
vulnerability in CVE-2026-5453 (CVE-2026-5453). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5452 |
|
Vulnerability in CVE-2026-5452 (CVE-2026-5452)
vulnerability in CVE-2026-5452 (CVE-2026-5452). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65912 |
|
Cross-Site Scripting (XSS) in dompurify (CVE-2026-65912)
cross-site scripting in dompurify (CVE-2026-65912). Risk of unauthorized operations or information disclosure. Exploitable via ``ADD_ATTR``. Mitigation: upgrade to `3.3.2` or later.
|
| CVE-2026-28815 |
|
Out-of-Bounds Read in c (CVE-2026-28815)
vulnerability in c (CVE-2026-28815). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47099 |
|
Cross-Site Scripting (XSS) in telejson (CVE-2026-47099)
cross-site scripting in telejson (CVE-2026-47099). Risk of unauthorized operations or information disclosure. Exploitable via ``postMessage``. Mitigation: upgrade to `6.0.0` or later.
|
| CVE-2026-30251 |
|
Cross-Site Scripting (XSS) in interzen (CVE-2026-30251)
cross-site scripting in interzen (CVE-2026-30251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30252 |
|
Cross-Site Scripting (XSS) in interzen (CVE-2026-30252)
cross-site scripting in interzen (CVE-2026-30252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35466 |
|
Cross-Site Scripting (XSS) in cmu (CVE-2026-35466)
cross-site scripting in cmu (CVE-2026-35466). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34835 |
|
Vulnerability in rack (CVE-2026-34835)
vulnerability in rack (CVE-2026-34835). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `3.2.6` or later.
|
| CVE-2026-34831 |
|
Vulnerability in rack (CVE-2026-34831)
vulnerability in rack (CVE-2026-34831). Risk of unauthorized operations or information disclosure. Exploitable via ``body.size``. Mitigation: upgrade to `3.2.6` or later.
|
| CVE-2026-34830 |
|
Vulnerability in rack (CVE-2026-34830)
vulnerability in rack (CVE-2026-34830). Confidential information can be exposed externally. Exploitable via ``internal``. Mitigation: upgrade to `3.2.6` or later.
|