Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42301 |
|
Vulnerability in CVE-2026-42301 (CVE-2026-42301)
vulnerability in CVE-2026-42301 (CVE-2026-42301). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41311 |
|
Vulnerability in dos (CVE-2026-41311)
vulnerability in dos (CVE-2026-41311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42351 |
|
Path Traversal in CVE-2026-42351 (CVE-2026-42351)
path traversal in CVE-2026-42351 (CVE-2026-42351). Confidential information can be exposed externally.
|
| CVE-2026-42352 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-42352 (CVE-2026-42352)
SSRF in CVE-2026-42352 (CVE-2026-42352). Confidential information can be exposed externally.
|
| CVE-2026-42224 |
|
Cross-Site Scripting (XSS) in CVE-2026-42224 (CVE-2026-42224)
cross-site scripting in CVE-2026-42224 (CVE-2026-42224). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42205 |
|
Vulnerability in rails (CVE-2026-42205)
vulnerability in rails (CVE-2026-42205). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42189 |
|
Vulnerability in CVE-2026-42189 (CVE-2026-42189)
vulnerability in CVE-2026-42189 (CVE-2026-42189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42353 |
|
Path Traversal in express (CVE-2026-42353)
path traversal in express (CVE-2026-42353). Confidential information can be exposed externally.
|
| CVE-2026-41886 |
|
Cross-Site Scripting (XSS) in CVE-2026-41886 (CVE-2026-41886)
cross-site scripting in CVE-2026-41886 (CVE-2026-41886). Data can be tampered with by attackers.
|
| CVE-2026-41693 |
|
Path Traversal in CVE-2026-41693 (CVE-2026-41693)
path traversal in CVE-2026-41693 (CVE-2026-41693). Confidential information can be exposed externally.
|
| CVE-2026-41690 |
|
Path Traversal in express (CVE-2026-41690)
path traversal in express (CVE-2026-41690). Data can be tampered with by attackers.
|
| CVE-2026-41683 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-41683)
cross-site scripting in express (CVE-2026-41683). Data can be tampered with by attackers.
|
| CVE-2026-29975 |
|
Vulnerability in c (CVE-2026-29975)
vulnerability in c (CVE-2026-29975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29972 |
|
Vulnerability in c (CVE-2026-29972)
vulnerability in c (CVE-2026-29972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44498 |
|
Vulnerability in zfnd (CVE-2026-44498)
vulnerability in zfnd (CVE-2026-44498). Data can be tampered with by attackers.
|
| CVE-2026-41584 |
|
Vulnerability in zfnd (CVE-2026-41584)
vulnerability in zfnd (CVE-2026-41584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41576 |
|
Cross-Site Scripting (XSS) in CVE-2026-41576 (CVE-2026-41576)
cross-site scripting in CVE-2026-41576 (CVE-2026-41576). Confidential information can be exposed externally.
|
| CVE-2026-41524 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-41524)
cross-site scripting in laravel (CVE-2026-41524). Confidential information can be exposed externally.
|
| CVE-2026-41570 |
|
Vulnerability in phpunit-project (CVE-2026-41570)
vulnerability in phpunit-project (CVE-2026-41570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44338 |
|
Vulnerability in c (CVE-2026-44338)
vulnerability in c (CVE-2026-44338). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5127 |
|
Unsafe Deserialization in wordpress (CVE-2026-5127)
vulnerability in wordpress (CVE-2026-5127). Successful exploitation can lead to full system takeover.
|
| CVE-2025-67888 |
|
OS Command Injection in CVE-2025-67888 (CVE-2025-67888)
OS command injection in CVE-2025-67888 (CVE-2025-67888). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-33288 |
|
SQL Injection in sqli (CVE-2024-33288)
SQL injection in sqli (CVE-2024-33288). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8133 |
|
Vulnerability in sqli (CVE-2026-8133)
vulnerability in sqli (CVE-2026-8133). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8132 |
|
Vulnerability in sqli (CVE-2026-8132)
vulnerability in sqli (CVE-2026-8132). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8131 |
|
Vulnerability in sqli (CVE-2026-8131)
vulnerability in sqli (CVE-2026-8131). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8130 |
|
Vulnerability in sqli (CVE-2026-8130)
vulnerability in sqli (CVE-2026-8130). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8129 |
|
Vulnerability in sqli (CVE-2026-8129)
vulnerability in sqli (CVE-2026-8129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43940 |
|
Path Traversal in electerm (CVE-2026-43940)
path traversal in electerm (CVE-2026-43940). Successful exploitation can lead to full system takeover. Exploitable via ``runWidget``. Mitigation: upgrade to `3.7.16` or later.
|
| CVE-2026-42264 |
|
Vulnerability in CVE-2026-42264 (CVE-2026-42264)
vulnerability in CVE-2026-42264 (CVE-2026-42264). Confidential information can be exposed externally.
|
| CVE-2026-8128 |
|
Vulnerability in sqli (CVE-2026-8128)
vulnerability in sqli (CVE-2026-8128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8126 |
|
Vulnerability in sqli (CVE-2026-8126)
vulnerability in sqli (CVE-2026-8126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42047 |
|
Information Disclosure in express (CVE-2026-42047)
vulnerability in express (CVE-2026-42047). Confidential information can be exposed externally.
|
| CVE-2026-33811 |
|
Vulnerability in c (CVE-2026-33811)
vulnerability in c (CVE-2026-33811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42284 |
|
Vulnerability in GitPython (CVE-2026-42284)
vulnerability in GitPython (CVE-2026-42284). Successful exploitation can lead to full system takeover. Exploitable via ``multi_options``. Mitigation: upgrade to `3.1.47` or later.
|
| CVE-2026-42215 |
|
OS Command Injection in GitPython (CVE-2026-42215)
OS command injection in GitPython (CVE-2026-42215). Successful exploitation can lead to full system takeover. Exploitable via ``upload_pack``. Mitigation: upgrade to `3.1.47` or later.
|
| CVE-2026-41906 |
|
Vulnerability in laravel (CVE-2026-41906)
vulnerability in laravel (CVE-2026-41906). Data can be tampered with by attackers.
|
| CVE-2025-63705 |
|
OS Command Injection in CVE-2025-63705 (CVE-2025-63705)
OS command injection in CVE-2025-63705 (CVE-2025-63705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41139 |
|
Vulnerability in mathjs (CVE-2026-41139)
vulnerability in mathjs (CVE-2026-41139). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `15.2.0` or later.
|
| CVE-2026-43237 |
|
Vulnerability in c (CVE-2026-43237)
vulnerability in c (CVE-2026-43237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43236 |
|
Vulnerability in c (CVE-2026-43236)
vulnerability in c (CVE-2026-43236). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43214 |
|
Vulnerability in c (CVE-2026-43214)
vulnerability in c (CVE-2026-43214). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43213 |
|
Vulnerability in c (CVE-2026-43213)
vulnerability in c (CVE-2026-43213). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43190 |
|
Vulnerability in c (CVE-2026-43190)
vulnerability in c (CVE-2026-43190). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43164 |
|
Vulnerability in c (CVE-2026-43164)
vulnerability in c (CVE-2026-43164). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43134 |
|
Vulnerability in c (CVE-2026-43134)
vulnerability in c (CVE-2026-43134). Confidential information can be exposed externally.
|
| CVE-2026-43084 |
|
Vulnerability in c (CVE-2026-43084)
vulnerability in c (CVE-2026-43084). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43074 |
|
Vulnerability in c (CVE-2026-43074)
vulnerability in c (CVE-2026-43074). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43075 |
|
Vulnerability in c (CVE-2026-43075)
vulnerability in c (CVE-2026-43075). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39383 |
|
SSRF (Server-Side Request Forgery) in github.com/gotenberg/gotenberg/v8 (CVE-2026-39383)
SSRF in github.com/gotenberg/gotenberg/v8 (CVE-2026-39383). Confidential information can be exposed externally. Exploitable via ``FilterDeadline``. Mitigation: upgrade to `8.31.0` or later.
|