Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-34104 |
|
SQL Injection in sqli (CVE-2026-34104)
SQL injection in sqli (CVE-2026-34104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34102 |
|
SQL Injection in sqli (CVE-2026-34102)
SQL injection in sqli (CVE-2026-34102). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34101 |
|
SQL Injection in sqli (CVE-2026-34101)
SQL injection in sqli (CVE-2026-34101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34100 |
|
SQL Injection in sqli (CVE-2026-34100)
SQL injection in sqli (CVE-2026-34100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8857 |
|
Code Injection in mediawiki (CVE-2026-8857)
code injection in mediawiki (CVE-2026-8857). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58036 |
|
Information Disclosure in mediawiki (CVE-2026-58036)
vulnerability in mediawiki (CVE-2026-58036). Confidential information can be exposed externally.
|
| CVE-2026-13706 |
|
Vulnerability in mediawiki (CVE-2026-13706)
vulnerability in mediawiki (CVE-2026-13706). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13707 |
|
Vulnerability in mediawiki (CVE-2026-13707)
vulnerability in mediawiki (CVE-2026-13707). Confidential information can be exposed externally.
|
| CVE-2026-49857 |
|
SSRF (Server-Side Request Forgery) in auth-fetch-mcp (CVE-2026-49857)
SSRF in auth-fetch-mcp (CVE-2026-49857). Confidential information can be exposed externally. Exploitable via ``false``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-6687 |
|
Vulnerability in c (CVE-2026-6687)
vulnerability in c (CVE-2026-6687). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6688 |
|
Vulnerability in c (CVE-2026-6688)
vulnerability in c (CVE-2026-6688). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6682 |
|
Vulnerability in c (CVE-2026-6682)
vulnerability in c (CVE-2026-6682). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53346 |
|
Out-of-Bounds Read in c (CVE-2026-53346)
vulnerability in c (CVE-2026-53346). Confidential information can be exposed externally.
|
| CVE-2026-12142 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12142)
cross-site scripting in wordpress (CVE-2026-12142). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14181 |
|
Vulnerability in dos (CVE-2026-14181)
vulnerability in dos (CVE-2026-14181). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7829 |
|
Out-of-Bounds Write in c (CVE-2026-7829)
out-of-bounds write in c (CVE-2026-7829). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7831 |
|
Vulnerability in cpp (CVE-2026-7831)
vulnerability in cpp (CVE-2026-7831). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7838 |
|
Vulnerability in cpp (CVE-2026-7838)
vulnerability in cpp (CVE-2026-7838). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7830 |
|
Vulnerability in cpp (CVE-2026-7830)
vulnerability in cpp (CVE-2026-7830). Confidential information can be exposed externally.
|
| CVE-2026-12923 |
|
Vulnerability in wordpress (CVE-2026-12923)
vulnerability in wordpress (CVE-2026-12923). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14191 |
|
Vulnerability in cpp (CVE-2026-14191)
vulnerability in cpp (CVE-2026-14191). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56264 |
|
Code Injection in kidocode (CVE-2026-56264)
code injection in kidocode (CVE-2026-56264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14024 |
|
Use-After-Free in c (CVE-2026-14024)
vulnerability in c (CVE-2026-14024). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13850 |
|
Vulnerability in c (CVE-2026-13850)
vulnerability in c (CVE-2026-13850). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71374 |
|
Unsafe Deserialization in picklescan (CVE-2025-71374)
vulnerability in picklescan (CVE-2025-71374). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.29` or later.
|
| CVE-2025-71352 |
|
Vulnerability in picklescan (CVE-2025-71352)
vulnerability in picklescan (CVE-2025-71352). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.29` or later.
|
| CVE-2025-71350 |
|
Vulnerability in picklescan (CVE-2025-71350)
vulnerability in picklescan (CVE-2025-71350). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.28` or later.
|
| CVE-2026-57585 |
|
Use-After-Free in dos (CVE-2026-57585)
vulnerability in dos (CVE-2026-57585). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10564 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-10564)
SSRF in c (CVE-2026-10564). Confidential information can be exposed externally.
|
| CVE-2026-48808 |
|
Vulnerability in twig/twig (CVE-2026-48808)
vulnerability in twig/twig (CVE-2026-48808). Confidential information can be exposed externally. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-58376 |
|
SQL Injection in sqli (CVE-2026-58376)
SQL injection in sqli (CVE-2026-58376). Confidential information can be exposed externally.
|
| CVE-2026-49473 |
|
Vulnerability in @cedar-policy/authorization-for-expressjs (CVE-2026-49473)
vulnerability in @cedar-policy/authorization-for-expressjs (CVE-2026-49473). Successful exploitation can lead to full system takeover. Exploitable via `GET /users`. Mitigation: upgrade to `0.3.0` or later.
|
| CVE-2026-49451 |
|
Vulnerability in Microsoft.OpenAPI (CVE-2026-49451)
vulnerability in Microsoft.OpenAPI (CVE-2026-49451). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.4` or later.
|
| CVE-2026-58014 |
|
Vulnerability in c (CVE-2026-58014)
vulnerability in c (CVE-2026-58014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58016 |
|
Vulnerability in c (CVE-2026-58016)
vulnerability in c (CVE-2026-58016). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12240 |
|
Unsafe Deserialization in wordpress (CVE-2026-12240)
vulnerability in wordpress (CVE-2026-12240). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11589 |
|
Vulnerability in wordpress (CVE-2026-11589)
vulnerability in wordpress (CVE-2026-11589). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12243 |
|
Path Traversal in nltk (CVE-2026-12243)
path traversal in nltk (CVE-2026-12243). Confidential information can be exposed externally. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-51218 |
|
Vulnerability in cpp (CVE-2026-51218)
vulnerability in cpp (CVE-2026-51218). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7656 |
|
Vulnerability in c (CVE-2026-7656)
vulnerability in c (CVE-2026-7656). Data can be tampered with by attackers.
|
| CVE-2026-8023 |
|
Path Traversal in c (CVE-2026-8023)
path traversal in c (CVE-2026-8023). Confidential information can be exposed externally.
|
| CVE-2026-41896 |
|
Authentication Bypass in CVE-2026-41896 (CVE-2026-41896)
authentication bypass in CVE-2026-41896 (CVE-2026-41896). Data can be tampered with by attackers. Mitigation: upgrade to `4.0.0-beta.474` or later.
|
| CVE-2026-56018 |
|
Vulnerability in dos (CVE-2026-56018)
vulnerability in dos (CVE-2026-56018). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56017 |
|
Out-of-Bounds Read in dos (CVE-2026-56017)
vulnerability in dos (CVE-2026-56017). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13749 |
|
Code Injection in snowflake (CVE-2026-13749)
code injection in snowflake (CVE-2026-13749). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40521 |
|
Path Traversal in path-traversal (CVE-2026-40521)
path traversal in path-traversal (CVE-2026-40521). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13568 |
|
Vulnerability in CVE-2026-13568 (CVE-2026-13568)
vulnerability in CVE-2026-13568 (CVE-2026-13568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13565 |
|
Vulnerability in sqli (CVE-2026-13565)
vulnerability in sqli (CVE-2026-13565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13566 |
|
Vulnerability in sqli (CVE-2026-13566)
vulnerability in sqli (CVE-2026-13566). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12856 |
|
Vulnerability in redhat (CVE-2026-12856)
vulnerability in redhat (CVE-2026-12856). Successful exploitation can lead to full system takeover.
|