Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14713 |
|
Vulnerability in sqli (CVE-2026-14713)
vulnerability in sqli (CVE-2026-14713). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14705 |
|
Vulnerability in sqli (CVE-2026-14705)
vulnerability in sqli (CVE-2026-14705). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14700 |
|
Vulnerability in sqli (CVE-2026-14700)
vulnerability in sqli (CVE-2026-14700). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14695 |
|
Vulnerability in sqli (CVE-2026-14695)
vulnerability in sqli (CVE-2026-14695). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14690 |
|
Vulnerability in CVE-2026-14690 (CVE-2026-14690)
vulnerability in CVE-2026-14690 (CVE-2026-14690). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14688 |
|
Vulnerability in sqli (CVE-2026-14688)
vulnerability in sqli (CVE-2026-14688). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14660 |
|
Vulnerability in sqli (CVE-2026-14660)
vulnerability in sqli (CVE-2026-14660). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14652 |
|
Vulnerability in sqli (CVE-2026-14652)
vulnerability in sqli (CVE-2026-14652). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14654 |
|
Vulnerability in sqli (CVE-2026-14654)
vulnerability in sqli (CVE-2026-14654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14653 |
|
Vulnerability in sqli (CVE-2026-14653)
vulnerability in sqli (CVE-2026-14653). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14649 |
|
Vulnerability in sqli (CVE-2026-14649)
vulnerability in sqli (CVE-2026-14649). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14648 |
|
Vulnerability in sqli (CVE-2026-14648)
vulnerability in sqli (CVE-2026-14648). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14642 |
|
Vulnerability in sqli (CVE-2026-14642)
vulnerability in sqli (CVE-2026-14642). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14641 |
|
Vulnerability in sqli (CVE-2026-14641)
vulnerability in sqli (CVE-2026-14641). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14640 |
|
Vulnerability in sqli (CVE-2026-14640)
vulnerability in sqli (CVE-2026-14640). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14637 |
|
Vulnerability in deserialization (CVE-2026-14637)
vulnerability in deserialization (CVE-2026-14637). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14635 |
|
Path Traversal in path-traversal (CVE-2026-14635)
path traversal in path-traversal (CVE-2026-14635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14534 |
|
Vulnerability in fickling (CVE-2026-14534)
vulnerability in fickling (CVE-2026-14534). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.11` or later.
|
| CVE-2026-53360 |
|
Out-of-Bounds Read in c (CVE-2026-53360)
vulnerability in c (CVE-2026-53360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14622 |
|
Authentication Bypass in CVE-2026-14622 (CVE-2026-14622)
authentication bypass in CVE-2026-14622 (CVE-2026-14622). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71372 |
|
Unsafe Deserialization in picklescan (CVE-2025-71372)
vulnerability in picklescan (CVE-2025-71372). Confidential information can be exposed externally. Exploitable via ``numpy.f2py.crackfortran.getlincoef``. Mitigation: upgrade to `0.0.33` or later.
|
| CVE-2026-12252 |
|
Code Injection in nltk (CVE-2026-12252)
code injection in nltk (CVE-2026-12252). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.4` or later.
|
| CVE-2026-47896 |
|
Path Traversal in csharp (CVE-2026-47896)
path traversal in csharp (CVE-2026-47896). Confidential information can be exposed externally.
|
| CVE-2026-47897 |
|
Path Traversal in csharp (CVE-2026-47897)
path traversal in csharp (CVE-2026-47897). Data can be tampered with by attackers.
|
| CVE-2026-38972 |
|
Vulnerability in c (CVE-2026-38972)
vulnerability in c (CVE-2026-38972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38969 |
|
Vulnerability in CVE-2026-38969 (CVE-2026-38969)
vulnerability in CVE-2026-38969 (CVE-2026-38969). Data can be tampered with by attackers.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2026-49353 |
|
Vulnerability in 9router (CVE-2026-49353)
vulnerability in 9router (CVE-2026-49353). Data can be tampered with by attackers. Exploitable via `GET /api/mcp/`.
|
| CVE-2026-49289 |
|
Vulnerability in simplesamlphp/saml2 (CVE-2026-49289)
vulnerability in simplesamlphp/saml2 (CVE-2026-49289). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.19.3` or later.
|
| CVE-2026-52829 |
|
Vulnerability in zebra-network (CVE-2026-52829)
vulnerability in zebra-network (CVE-2026-52829). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-49283 |
|
Vulnerability in simplesamlphp/saml2 (CVE-2026-49283)
vulnerability in simplesamlphp/saml2 (CVE-2026-49283). Confidential information can be exposed externally. Exploitable via ``Response``. Mitigation: upgrade to `4.19.3` or later.
|
| CVE-2026-49255 |
|
OS Command Injection in electerm (CVE-2026-49255)
OS command injection in electerm (CVE-2026-49255). Successful exploitation can lead to full system takeover. Exploitable via ``rmrf``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-49253 |
|
Path Traversal in electerm (CVE-2026-49253)
path traversal in electerm (CVE-2026-49253). Data can be tampered with by attackers. Exploitable via ``savedFilePaths``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|
| CVE-2026-58465 |
|
Vulnerability in c (CVE-2026-58465)
vulnerability in c (CVE-2026-58465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44454 |
|
OS Command Injection in github.com/coder/coder/v2 (CVE-2026-44454)
OS command injection in github.com/coder/coder/v2 (CVE-2026-44454). Confidential information can be exposed externally. Exploitable via ``dotfiles``. Mitigation: upgrade to `2.30.2` or later.
|
| CVE-2026-52854 |
|
Cross-Site Scripting (XSS) in mediawiki/maps (CVE-2026-52854)
cross-site scripting in mediawiki/maps (CVE-2026-52854). Confidential information can be exposed externally. Exploitable via ``overlays``. Mitigation: upgrade to `12.1.3` or later.
|
| CVE-2026-27414 |
|
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
|
| CVE-2026-27060 |
|
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
|
| CVE-2026-9834 |
|
Command Injection in wordpress (CVE-2026-9834)
command injection in wordpress (CVE-2026-9834). Successful exploitation can lead to full system takeover. Exploitable via ``wp_db_exclude_table``.
|
| CVE-2026-14249 |
|
Vulnerability in wordpress (CVE-2026-14249)
vulnerability in wordpress (CVE-2026-14249). Data can be tampered with by attackers.
|
| CVE-2026-38891 |
|
Vulnerability in cpp (CVE-2026-38891)
vulnerability in cpp (CVE-2026-38891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50138 |
|
Vulnerability in goshs.de/goshs/v2 (CVE-2026-50138)
vulnerability in goshs.de/goshs/v2 (CVE-2026-50138). Confidential information can be exposed externally. Exploitable via ``goshs``. Mitigation: upgrade to `2.1.0` or later.
|
| CVE-2026-58592 |
|
Out-of-Bounds Write in cpp (CVE-2026-58592)
out-of-bounds write in cpp (CVE-2026-58592). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55153 |
|
Vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153)
vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153). Successful exploitation can lead to full system takeover. Exploitable via ``ObjectFactory``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-14265 |
|
Unsafe Deserialization in Amazon aws (CVE-2026-14265)
vulnerability in Amazon aws (CVE-2026-14265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48815 |
|
Vulnerability in sigstore (CVE-2026-48815)
vulnerability in sigstore (CVE-2026-48815). Data can be tampered with by attackers. Exploitable via ``certificateOIDs``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-49981 |
|
Vulnerability in twig/twig (CVE-2026-49981)
vulnerability in twig/twig (CVE-2026-49981). Confidential information can be exposed externally. Exploitable via ``Template``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-34104 |
|
SQL Injection in sqli (CVE-2026-34104)
SQL injection in sqli (CVE-2026-34104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34103 |
|
SQL Injection in sqli (CVE-2026-34103)
SQL injection in sqli (CVE-2026-34103). Successful exploitation can lead to full system takeover.
|