Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-32639 |
|
Vulnerability in winter/wn-cms-module (CVE-2026-32639)
vulnerability in winter/wn-cms-module (CVE-2026-32639). Confidential information can be exposed externally. Exploitable via ``cms.manage_pages``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-8457 |
|
Vulnerability in wordpress (CVE-2026-8457)
vulnerability in wordpress (CVE-2026-8457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9701 |
|
Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
|
| CVE-2026-48618 |
|
Vulnerability in nodejs (CVE-2026-48618)
vulnerability in nodejs (CVE-2026-48618). Confidential information can be exposed externally.
|
| CVE-2026-44492 |
|
SSRF (Server-Side Request Forgery) in axios (CVE-2026-44492)
SSRF in axios (CVE-2026-44492). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2025-55130 |
|
Vulnerability in node-min (CVE-2025-55130)
vulnerability in node-min (CVE-2025-55130). Confidential information can be exposed externally. Mitigation: upgrade to `20.20.0, 22.22.0, 24.13.0, 25.3.0` or later.
|