Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48241 |
|
Vulnerability in CVE-2026-48241 (CVE-2026-48241)
vulnerability in CVE-2026-48241 (CVE-2026-48241). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48242 |
|
Vulnerability in CVE-2026-48242 (CVE-2026-48242)
vulnerability in CVE-2026-48242 (CVE-2026-48242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48236 |
|
SQL Injection in sqli (CVE-2026-48236)
SQL injection in sqli (CVE-2026-48236). Confidential information can be exposed externally.
|
| CVE-2026-48239 |
|
SQL Injection in sqli (CVE-2026-48239)
SQL injection in sqli (CVE-2026-48239). Confidential information can be exposed externally.
|
| CVE-2026-48240 |
|
SQL Injection in sqli (CVE-2026-48240)
SQL injection in sqli (CVE-2026-48240). Confidential information can be exposed externally.
|
| CVE-2026-48238 |
|
SQL Injection in sqli (CVE-2026-48238)
SQL injection in sqli (CVE-2026-48238). Confidential information can be exposed externally.
|
| CVE-2026-48232 |
|
SQL Injection in sqli (CVE-2026-48232)
SQL injection in sqli (CVE-2026-48232). Confidential information can be exposed externally.
|
| CVE-2026-48233 |
|
SQL Injection in sqli (CVE-2026-48233)
SQL injection in sqli (CVE-2026-48233). Confidential information can be exposed externally.
|
| CVE-2026-48234 |
|
SQL Injection in sqli (CVE-2026-48234)
SQL injection in sqli (CVE-2026-48234). Confidential information can be exposed externally.
|
| CVE-2026-48231 |
|
SQL Injection in sqli (CVE-2026-48231)
SQL injection in sqli (CVE-2026-48231). Confidential information can be exposed externally.
|
| CVE-2026-46492 |
|
Vulnerability in md-fileserver (CVE-2026-46492)
vulnerability in md-fileserver (CVE-2026-46492). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.10.3` or later.
|
| CVE-2026-46490 |
|
Vulnerability in samlify (CVE-2026-46490)
vulnerability in samlify (CVE-2026-46490). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.13.0` or later.
|
| CVE-2026-44062 |
|
Out-of-Bounds Write in c (CVE-2026-44062)
out-of-bounds write in c (CVE-2026-44062). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9144 |
|
Cross-Site Scripting (XSS) in CVE-2026-9144 (CVE-2026-9144)
cross-site scripting in CVE-2026-9144 (CVE-2026-9144). Confidential information can be exposed externally.
|
| CVE-2026-9137 |
|
Vulnerability in c (CVE-2026-9137)
vulnerability in c (CVE-2026-9137). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35676 |
|
Vulnerability in thorsten/phpmyfaq (CVE-2026-35676)
vulnerability in thorsten/phpmyfaq (CVE-2026-35676). Data can be tampered with by attackers. Exploitable via `PUT /api/index.php/user/password/update`. Mitigation: upgrade to `4.1.3` or later.
|
| CVE-2026-24425 |
|
Vulnerability in twig/twig (CVE-2026-24425)
vulnerability in twig/twig (CVE-2026-24425). Successful exploitation can lead to full system takeover. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-4224 |
|
Vulnerability in libpython (CVE-2026-4224)
vulnerability in libpython (CVE-2026-4224). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.13.13, 3.14.4` or later.
|
| CVE-2026-42959 |
|
Vulnerability in c (CVE-2026-42959)
vulnerability in c (CVE-2026-42959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41054 |
|
Vulnerability in c (CVE-2026-41054)
vulnerability in c (CVE-2026-41054). Successful exploitation can lead to full system takeover. Exploitable via ``socket_handler``.
|
| CVE-2026-7522 |
|
Vulnerability in wordpress (CVE-2026-7522)
vulnerability in wordpress (CVE-2026-7522). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6456 |
|
Authentication Bypass in wordpress (CVE-2026-6456)
authentication bypass in wordpress (CVE-2026-6456). Successful exploitation can lead to full system takeover. Exploitable via ``rememberLogin``.
|
| CVE-2026-34241 |
|
Cross-Site Scripting (XSS) in CVE-2026-34241 (CVE-2026-34241)
cross-site scripting in CVE-2026-34241 (CVE-2026-34241). Confidential information can be exposed externally.
|
| CVE-2026-45783 |
|
Vulnerability in @libp2p/kad-dht (CVE-2026-45783)
vulnerability in @libp2p/kad-dht (CVE-2026-45783). Risk of unauthorized operations or information disclosure. Exploitable via ``PUT_VALUE``. Mitigation: upgrade to `16.2.6` or later.
|
| CVE-2026-45805 |
|
Vulnerability in @penpot/mcp (CVE-2026-45805)
vulnerability in @penpot/mcp (CVE-2026-45805). Successful exploitation can lead to full system takeover. Exploitable via ``ReplServer``. Mitigation: upgrade to `2.15.0` or later.
|
| CVE-2026-45799 |
|
Vulnerability in com.squareup.wire:wire-runtime-jvm (CVE-2026-45799)
vulnerability in com.squareup.wire:wire-runtime-jvm (CVE-2026-45799). Risk of unauthorized operations or information disclosure. Exploitable via ``IOException``. Mitigation: upgrade to `7.0.0-alpha03` or later.
|
| CVE-2026-45784 |
|
Vulnerability in openssl (CVE-2026-45784)
vulnerability in openssl (CVE-2026-45784). Data can be tampered with by attackers. Mitigation: upgrade to `0.10.80` or later.
|
| CVE-2026-46426 |
|
Unrestricted File Upload in budibase (CVE-2026-46426)
vulnerability in budibase (CVE-2026-46426). Confidential information can be exposed externally. Exploitable via `POST /api/attachments/process`. Mitigation: upgrade to `3.38.2` or later.
|
| CVE-2026-45793 |
|
Information Disclosure in composer/composer (CVE-2026-45793)
vulnerability in composer/composer (CVE-2026-45793). Confidential information can be exposed externally. Exploitable via ``GITHUB_TOKEN``. Mitigation: upgrade to `1.10.28` or later.
|
| CVE-2026-45738 |
|
Cross-Site Scripting (XSS) in github.com/argoproj/argo-cd/v3 (CVE-2026-45738)
cross-site scripting in github.com/argoproj/argo-cd/v3 (CVE-2026-45738). Confidential information can be exposed externally. Exploitable via ``href``. Mitigation: upgrade to `3.4.2` or later.
|
| CVE-2026-8711 |
|
Vulnerability in nginx (CVE-2026-8711)
vulnerability in nginx (CVE-2026-8711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47100 |
|
Vulnerability in CVE-2026-47100 (CVE-2026-47100)
vulnerability in CVE-2026-47100 (CVE-2026-47100). Data can be tampered with by attackers.
|
| CVE-2026-8973 |
|
Buffer Overflow in c (CVE-2026-8973)
vulnerability in c (CVE-2026-8973). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42099 |
|
Vulnerability in sparxsystems (CVE-2026-42099)
vulnerability in sparxsystems (CVE-2026-42099). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8912 |
|
SQL Injection in wordpress (CVE-2026-8912)
SQL injection in wordpress (CVE-2026-8912). Confidential information can be exposed externally.
|
| CVE-2026-7504 |
|
Open Redirect in org.keycloak:keycloak-services (CVE-2026-7504)
vulnerability in org.keycloak:keycloak-services (CVE-2026-7504). Confidential information can be exposed externally. Mitigation: upgrade to `26.6.2` or later.
|
| CVE-2026-7307 |
|
Vulnerability in org.keycloak:keycloak-saml-core (CVE-2026-7307)
vulnerability in org.keycloak:keycloak-saml-core (CVE-2026-7307). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.6.2` or later.
|
| CVE-2026-27891 |
|
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the f...
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leadin...
|
| CVE-2026-4137 |
|
Vulnerability in mlflow (CVE-2026-4137)
vulnerability in mlflow (CVE-2026-4137). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.0` or later.
|
| CVE-2026-45367 |
|
Vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-45367)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-45367). Risk of unauthorized operations or information disclosure. Exploitable via ``funcMatches``. Mitigation: upgrade to `6.9.7` or later.
|
| CVE-2026-45553 |
|
Information Disclosure in nicegui (CVE-2026-45553)
vulnerability in nicegui (CVE-2026-45553). Confidential information can be exposed externally. Exploitable via ``include``. Mitigation: upgrade to `3.12.0` or later.
|
| CVE-2026-29962 |
|
Vulnerability in path-traversal (CVE-2026-29962)
vulnerability in path-traversal (CVE-2026-29962). Confidential information can be exposed externally.
|
| CVE-2026-29963 |
|
Path Traversal in path-traversal (CVE-2026-29963)
path traversal in path-traversal (CVE-2026-29963). Confidential information can be exposed externally.
|
| CVE-2026-45300 |
|
Information Disclosure in org.asynchttpclient:async-http-client (CVE-2026-45300)
vulnerability in org.asynchttpclient:async-http-client (CVE-2026-45300). Confidential information can be exposed externally. Exploitable via ``Cookie``. Mitigation: upgrade to `2.15.0` or later.
|
| CVE-2026-45270 |
|
Cross-Site Scripting (XSS) in ci4-cms-erp/ci4ms (CVE-2026-45270)
cross-site scripting in ci4-cms-erp/ci4ms (CVE-2026-45270). Confidential information can be exposed externally. Exploitable via ``Pages``. Mitigation: upgrade to `0.31.9.0` or later.
|
| CVE-2026-39079 |
|
Information Disclosure in CVE-2026-39079 (CVE-2026-39079)
vulnerability in CVE-2026-39079 (CVE-2026-39079). Confidential information can be exposed externally.
|
| CVE-2026-26462 |
|
Vulnerability in CVE-2026-26462 (CVE-2026-26462)
vulnerability in CVE-2026-26462 (CVE-2026-26462). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45627 |
|
Cross-Site Scripting (XSS) in github.com/getarcaneapp/arcane/backend (CVE-2026-45627)
cross-site scripting in github.com/getarcaneapp/arcane/backend (CVE-2026-45627). Confidential information can be exposed externally. Exploitable via `GET /api/app-images/logo`. Mitigation: upgrade to `1.19.0` or later.
|
| CVE-2026-45135 |
|
Vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-45135)
vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-45135). Successful exploitation can lead to full system takeover. Exploitable via ``search.IgnoreCase``. Mitigation: upgrade to `2.11.3` or later.
|
| CVE-2026-46510 |
|
Vulnerability in form-data-objectizer (CVE-2026-46510)
vulnerability in form-data-objectizer (CVE-2026-46510). Data can be tampered with by attackers. Exploitable via ``__proto__``. Mitigation: upgrade to `1.0.1` or later.
|