Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-82453 |
|
Vulnerability in CVE-2026-82453 (CVE-2026-82453)
vulnerability in CVE-2026-82453 (CVE-2026-82453). Confidential information can be exposed externally.
|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55848 |
|
XXE (XML External Entity) in org.mapfish.print:print-lib (CVE-2026-55848)
vulnerability in org.mapfish.print:print-lib (CVE-2026-55848). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-82333 |
|
Vulnerability in dos (CVE-2026-82333)
vulnerability in dos (CVE-2026-82333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77037 |
|
Vulnerability in dos (CVE-2026-77037)
vulnerability in dos (CVE-2026-77037). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77078 |
|
Vulnerability in dos (CVE-2026-77078)
vulnerability in dos (CVE-2026-77078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55841 |
|
Vulnerability in org.graylog2:graylog2-server (CVE-2026-55841)
vulnerability in org.graylog2:graylog2-server (CVE-2026-55841). Data can be tampered with by attackers. Mitigation: upgrade to `7.1.2` or later.
|
| CVE-2026-82287 |
|
Vulnerability in c (CVE-2026-82287)
vulnerability in c (CVE-2026-82287). Confidential information can be exposed externally.
|
| CVE-2026-82284 |
|
Vulnerability in c (CVE-2026-82284)
vulnerability in c (CVE-2026-82284). Confidential information can be exposed externally. Exploitable via `GET /chat/{chat_id}/history`.
|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-55215 |
|
Vulnerability in mariadb (CVE-2026-55215)
vulnerability in mariadb (CVE-2026-55215). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-55584 |
|
Vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584)
vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584). Confidential information can be exposed externally. Exploitable via ``PSI_ALLOWED``. Mitigation: upgrade to `3.4.6` or later.
|
| CVE-2026-55485 |
|
Information Disclosure in piccolo-admin (CVE-2026-55485)
vulnerability in piccolo-admin (CVE-2026-55485). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/tables/piccolo_user/2/`. Mitigation: upgrade to `1.14.0` or later.
|
| CVE-2026-55552 |
|
Path Traversal in org.yamcs:yamcs-core (CVE-2026-55552)
path traversal in org.yamcs:yamcs-core (CVE-2026-55552). Confidential information can be exposed externally. Mitigation: upgrade to `5.12.0` or later.
|
| CVE-2026-54788 |
|
Vulnerability in datadog-opentelemetry (CVE-2026-54788)
vulnerability in datadog-opentelemetry (CVE-2026-54788). Risk of unauthorized operations or information disclosure. Exploitable via ``tracecontext``. Mitigation: upgrade to `0.3.3` or later.
|
| CVE-2026-82253 |
|
Path Traversal in path-traversal (CVE-2026-82253)
path traversal in path-traversal (CVE-2026-82253). Confidential information can be exposed externally.
|
| CVE-2026-80720 |
|
Vulnerability in c (CVE-2026-80720)
vulnerability in c (CVE-2026-80720). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80702 |
|
Vulnerability in c (CVE-2026-80702)
vulnerability in c (CVE-2026-80702). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80682 |
|
Vulnerability in c (CVE-2026-80682)
vulnerability in c (CVE-2026-80682). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80653 |
|
Vulnerability in c (CVE-2026-80653)
vulnerability in c (CVE-2026-80653). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80656 |
|
Vulnerability in c (CVE-2026-80656)
vulnerability in c (CVE-2026-80656). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80631 |
|
Vulnerability in c (CVE-2026-80631)
vulnerability in c (CVE-2026-80631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80633 |
|
Vulnerability in c (CVE-2026-80633)
vulnerability in c (CVE-2026-80633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80615 |
|
Vulnerability in c (CVE-2026-80615)
vulnerability in c (CVE-2026-80615). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80606 |
|
Vulnerability in c (CVE-2026-80606)
vulnerability in c (CVE-2026-80606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80590 |
|
Vulnerability in c (CVE-2026-80590)
vulnerability in c (CVE-2026-80590). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6286 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14558 |
|
Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18983 |
|
Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38821 |
|
Vulnerability in c (CVE-2026-38821)
vulnerability in c (CVE-2026-38821). Confidential information can be exposed externally.
|
| CVE-2026-75417 |
|
SQL Injection in sqli (CVE-2026-75417)
SQL injection in sqli (CVE-2026-75417). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38350 |
|
Vulnerability in c (CVE-2026-38350)
vulnerability in c (CVE-2026-38350). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38348 |
|
Vulnerability in c (CVE-2026-38348)
vulnerability in c (CVE-2026-38348). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38346 |
|
Vulnerability in c (CVE-2026-38346)
vulnerability in c (CVE-2026-38346). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38349 |
|
Vulnerability in c (CVE-2026-38349)
vulnerability in c (CVE-2026-38349). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54085 |
|
Vulnerability in c (CVE-2026-54085)
vulnerability in c (CVE-2026-54085). Data can be tampered with by attackers.
|
| CVE-2026-54083 |
|
Path Traversal in c (CVE-2026-54083)
path traversal in c (CVE-2026-54083). Data can be tampered with by attackers.
|
| CVE-2025-30156 |
|
Vulnerability in c (CVE-2025-30156)
vulnerability in c (CVE-2025-30156). Confidential information can be exposed externally.
|
| CVE-2026-81728 |
|
SQL Injection in sqli (CVE-2026-81728)
SQL injection in sqli (CVE-2026-81728). Confidential information can be exposed externally.
|
| CVE-2026-81730 |
|
Path Traversal in CVE-2026-81730 (CVE-2026-81730)
path traversal in CVE-2026-81730 (CVE-2026-81730). Data can be tampered with by attackers.
|
| CVE-2026-81529 |
|
Vulnerability in c (CVE-2026-81529)
vulnerability in c (CVE-2026-81529). Confidential information can be exposed externally.
|
| CVE-2026-81522 |
|
Vulnerability in c (CVE-2026-81522)
vulnerability in c (CVE-2026-81522). Confidential information can be exposed externally.
|
| CVE-2026-81525 |
|
Vulnerability in CVE-2026-81525 (CVE-2026-81525)
vulnerability in CVE-2026-81525 (CVE-2026-81525). Confidential information can be exposed externally.
|
| CVE-2026-10036 |
|
Unsafe Deserialization in CVE-2026-10036 (CVE-2026-10036)
vulnerability in CVE-2026-10036 (CVE-2026-10036). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81698 |
|
OS Command Injection in c (CVE-2026-81698)
OS command injection in c (CVE-2026-81698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81097 |
|
OS Command Injection in CVE-2026-81097 (CVE-2026-81097)
OS command injection in CVE-2026-81097 (CVE-2026-81097). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80212 |
|
Vulnerability in CVE-2026-80212 (CVE-2026-80212)
vulnerability in CVE-2026-80212 (CVE-2026-80212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54718 |
|
Vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718)
vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-81573 |
|
Vulnerability in c (CVE-2026-81573)
vulnerability in c (CVE-2026-81573). Data can be tampered with by attackers.
|