Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5865 |
|
Vulnerability in google (CVE-2026-5865)
vulnerability in google (CVE-2026-5865). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5867 |
|
Vulnerability in google (CVE-2026-5867)
vulnerability in google (CVE-2026-5867). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5870 |
|
Vulnerability in google (CVE-2026-5870)
vulnerability in google (CVE-2026-5870). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5866 |
|
Use-After-Free in google (CVE-2026-5866)
vulnerability in google (CVE-2026-5866). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5869 |
|
Vulnerability in google (CVE-2026-5869)
vulnerability in google (CVE-2026-5869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5871 |
|
Vulnerability in google (CVE-2026-5871)
vulnerability in google (CVE-2026-5871). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5872 |
|
Use-After-Free in google (CVE-2026-5872)
vulnerability in google (CVE-2026-5872). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5873 |
|
Out-of-Bounds Read in google (CVE-2026-5873)
vulnerability in google (CVE-2026-5873). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5868 |
|
Vulnerability in google (CVE-2026-5868)
vulnerability in google (CVE-2026-5868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5810 |
|
Cross-Site Scripting (XSS) in CVE-2026-5810 (CVE-2026-5810)
cross-site scripting in CVE-2026-5810 (CVE-2026-5810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5860 |
|
Use-After-Free in google (CVE-2026-5860)
vulnerability in google (CVE-2026-5860). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5858 |
|
Vulnerability in google (CVE-2026-5858)
vulnerability in google (CVE-2026-5858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5859 |
|
Vulnerability in google (CVE-2026-5859)
vulnerability in google (CVE-2026-5859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5861 |
|
Use-After-Free in google (CVE-2026-5861)
vulnerability in google (CVE-2026-5861). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5862 |
|
Vulnerability in google (CVE-2026-5862)
vulnerability in google (CVE-2026-5862). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5864 |
|
Vulnerability in google (CVE-2026-5864)
vulnerability in google (CVE-2026-5864). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5806 |
|
Cross-Site Scripting (XSS) in CVE-2026-5806 (CVE-2026-5806)
cross-site scripting in CVE-2026-5806 (CVE-2026-5806). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5805 |
|
Vulnerability in c (CVE-2026-5805)
vulnerability in c (CVE-2026-5805). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5436 |
|
Path Traversal in wordpress (CVE-2026-5436)
path traversal in wordpress (CVE-2026-5436). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39844 |
|
Path Traversal in nicegui (CVE-2026-39844)
path traversal in nicegui (CVE-2026-39844). Data can be tampered with by attackers. Exploitable via ``PurePosixPath``. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-33458 |
|
SSRF (Server-Side Request Forgery) in elastic (CVE-2026-33458)
SSRF in elastic (CVE-2026-33458). Confidential information can be exposed externally.
|
| CVE-2026-33459 |
|
Vulnerability in dos (CVE-2026-33459)
vulnerability in dos (CVE-2026-33459). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4498 |
|
Vulnerability in elastic (CVE-2026-4498)
vulnerability in elastic (CVE-2026-4498). Confidential information can be exposed externally.
|
| CVE-2026-33461 |
|
Authorization Flaw in elastic (CVE-2026-33461)
vulnerability in elastic (CVE-2026-33461). Confidential information can be exposed externally.
|
| CVE-2026-33460 |
|
Authorization Flaw in elastic (CVE-2026-33460)
vulnerability in elastic (CVE-2026-33460). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35023 |
|
Vulnerability in wimi-teamwork (CVE-2026-35023)
vulnerability in wimi-teamwork (CVE-2026-35023). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3243 |
|
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1....
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
|
| CVE-2026-39684 |
|
Vulnerability in CVE-2026-39684 (CVE-2026-39684)
vulnerability in CVE-2026-39684 (CVE-2026-39684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39677 |
|
Vulnerability in CVE-2026-39677 (CVE-2026-39677)
vulnerability in CVE-2026-39677 (CVE-2026-39677). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39679 |
|
Vulnerability in CVE-2026-39679 (CVE-2026-39679)
vulnerability in CVE-2026-39679 (CVE-2026-39679). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39681 |
|
Vulnerability in CVE-2026-39681 (CVE-2026-39681)
vulnerability in CVE-2026-39681 (CVE-2026-39681). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39623 |
|
Vulnerability in CVE-2026-39623 (CVE-2026-39623)
vulnerability in CVE-2026-39623 (CVE-2026-39623). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39613 |
|
Vulnerability in CVE-2026-39613 (CVE-2026-39613)
vulnerability in CVE-2026-39613 (CVE-2026-39613). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39611 |
|
Vulnerability in CVE-2026-39611 (CVE-2026-39611)
vulnerability in CVE-2026-39611 (CVE-2026-39611). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39544 |
|
Vulnerability in CVE-2026-39544 (CVE-2026-39544)
vulnerability in CVE-2026-39544 (CVE-2026-39544). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39538 |
|
Vulnerability in CVE-2026-39538 (CVE-2026-39538)
vulnerability in CVE-2026-39538 (CVE-2026-39538). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5169 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5169)
cross-site scripting in wordpress (CVE-2026-5169). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3535 |
|
Unrestricted File Upload in wordpress (CVE-2026-3535)
vulnerability in wordpress (CVE-2026-3535). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_``.
|
| CVE-2026-3646 |
|
Vulnerability in wordpress (CVE-2026-3646)
vulnerability in wordpress (CVE-2026-3646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4341 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4341)
cross-site scripting in wordpress (CVE-2026-4341). Risk of unauthorized operations or information disclosure. Exploitable via ``follow_us_text``.
|
| CVE-2026-3296 |
|
Unsafe Deserialization in wordpress (CVE-2026-3296)
vulnerability in wordpress (CVE-2026-3296). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3357 |
|
Unsafe Deserialization in deserialization (CVE-2026-3357)
vulnerability in deserialization (CVE-2026-3357). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39370 |
|
SSRF (Server-Side Request Forgery) in WWBN/AVideo (CVE-2026-39370)
SSRF in WWBN/AVideo (CVE-2026-39370). Confidential information can be exposed externally. Exploitable via `POST /objects/aVideoEncoder.json.php`.
|
| CVE-2026-39369 |
|
Path Traversal in WWBN/AVideo (CVE-2026-39369)
path traversal in WWBN/AVideo (CVE-2026-39369). Confidential information can be exposed externally. Exploitable via `POST /objects/aVideoEncoderReceiveImage.json.php`.
|
| CVE-2026-1340 KEV |
|
[KEV] Code Injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1340)
code injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1340). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-31789 |
|
Out-of-Bounds Write in openssl (CVE-2026-31789)
out-of-bounds write in openssl (CVE-2026-31789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28389 |
|
Vulnerability in dos (CVE-2026-28389)
vulnerability in dos (CVE-2026-28389). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28390 |
|
Vulnerability in dos (CVE-2026-28390)
vulnerability in dos (CVE-2026-28390). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31790 |
|
Vulnerability in openssl (CVE-2026-31790)
vulnerability in openssl (CVE-2026-31790). Confidential information can be exposed externally.
|
| CVE-2026-28387 |
|
Use-After-Free in openssl (CVE-2026-28387)
vulnerability in openssl (CVE-2026-28387). Successful exploitation can lead to full system takeover.
|