Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: products Clear
ID Title
CVE-2026-48955 Vulnerability in joomla (CVE-2026-48955)
vulnerability in joomla (CVE-2026-48955). Confidential information can be exposed externally. Mitigation: upgrade to `6.1.2` or later.
CVE-2026-48956 Joomla! Core - [20260710] - Incorrect Access Control in com_modules
Joomla! Core - [20260710] - Incorrect Access Control in com_modules
CVE-2026-48957 Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints
CVE-2026-48958 Vulnerability in joomla (CVE-2026-48958)
vulnerability in joomla (CVE-2026-48958). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.7, 6.1.2` or later.
CVE-2026-48949 Joomla! Core - [20260703] - XSS in MFA method management
Joomla! Core - [20260703] - XSS in MFA method management
CVE-2026-48950 Joomla! Core - [20260704] - XSS in com_templates
Joomla! Core - [20260704] - XSS in com_templates
CVE-2026-48951 Joomla! Core - [20260705] - XSS in various modalreturn layouts
Joomla! Core - [20260705] - XSS in various modalreturn layouts
CVE-2026-48952 Joomla! Core - [20260706] - XSS in com_installer
Joomla! Core - [20260706] - XSS in com_installer
CVE-2026-48953 Joomla! Core - [20260707] - XSS in the generic image output layout
Joomla! Core - [20260707] - XSS in the generic image output layout
CVE-2026-48947 Vulnerability in joomla (CVE-2026-48947)
vulnerability in joomla (CVE-2026-48947). Data can be tampered with by attackers. Mitigation: upgrade to `5.4.7, 6.1.2` or later.
CVE-2026-48948 Vulnerability in joomla (CVE-2026-48948)
vulnerability in joomla (CVE-2026-48948). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.7, 6.1.2` or later.
CVE-2026-23698 Unrestricted File Upload in apache (CVE-2026-23698)
vulnerability in apache (CVE-2026-23698). Successful exploitation can lead to full system takeover.
CVE-2026-13020 Vulnerability in esri (CVE-2026-13020)
vulnerability in esri (CVE-2026-13020). Successful exploitation can lead to full system takeover.
CVE-2026-13019 Vulnerability in esri (CVE-2026-13019)
vulnerability in esri (CVE-2026-13019). Successful exploitation can lead to full system takeover.
CVE-2026-23697 Unrestricted File Upload in apache (CVE-2026-23697)
vulnerability in apache (CVE-2026-23697). Successful exploitation can lead to full system takeover.
CVE-2026-6101 Vulnerability in wordpress (CVE-2026-6101)
vulnerability in wordpress (CVE-2026-6101). Successful exploitation can lead to full system takeover.
CVE-2026-40187 OS Command Injection in egroupware/egroupware (CVE-2026-40187)
OS command injection in egroupware/egroupware (CVE-2026-40187). Risk of unauthorized operations or information disclosure. Exploitable via ``chgrp``. Mitigation: upgrade to `23.1.20260601` or later.
CVE-2026-49487 Information Disclosure in airflow (CVE-2026-49487)
vulnerability in airflow (CVE-2026-49487). Confidential information can be exposed externally. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-49296 Vulnerability in apache-airflow (CVE-2026-49296)
vulnerability in apache-airflow (CVE-2026-49296). Confidential information can be exposed externally. Exploitable via `GET /api/v2/dagSources/{dag_id}`. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-48892 Information Disclosure in airflow (CVE-2026-48892)
vulnerability in airflow (CVE-2026-48892). Confidential information can be exposed externally. Exploitable via ``sensitive_config_values``. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-48891 Information Disclosure in airflow (CVE-2026-48891)
vulnerability in airflow (CVE-2026-48891). Risk of unauthorized operations or information disclosure. Exploitable via ``dep.source``. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-48828 Information Disclosure in airflow (CVE-2026-48828)
vulnerability in airflow (CVE-2026-48828). Confidential information can be exposed externally. Exploitable via ``should_hide_value_for_key``. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-33264 Unsafe Deserialization in airflow (CVE-2026-33264)
vulnerability in airflow (CVE-2026-33264). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-14345 Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
CVE-2026-12277 Vulnerability in wordpress (CVE-2026-12277)
vulnerability in wordpress (CVE-2026-12277). Data can be tampered with by attackers.
CVE-2026-42200 Path Traversal in CVE-2026-42200 (CVE-2026-42200)
path traversal in CVE-2026-42200 (CVE-2026-42200). Successful exploitation can lead to full system takeover.
CVE-2026-42145 Unrestricted File Upload in CVE-2026-42145 (CVE-2026-42145)
vulnerability in CVE-2026-42145 (CVE-2026-42145). Risk of unauthorized operations or information disclosure.
CVE-2026-34037 Vulnerability in CVE-2026-34037 (CVE-2026-34037)
vulnerability in CVE-2026-34037 (CVE-2026-34037). Confidential information can be exposed externally.
CVE-2026-34057 OS Command Injection in CVE-2026-34057 (CVE-2026-34057)
OS command injection in CVE-2026-34057 (CVE-2026-34057). Successful exploitation can lead to full system takeover.
CVE-2026-13356 Vulnerability in mozilla (CVE-2026-13356)
vulnerability in mozilla (CVE-2026-13356). Risk of unauthorized operations or information disclosure.
CVE-2026-53646 Vulnerability in nginx (CVE-2026-53646)
vulnerability in nginx (CVE-2026-53646). Risk of unauthorized operations or information disclosure. Exploitable via ``ClientPasswordReset``.
CVE-2026-42148 OS Command Injection in CVE-2026-42148 (CVE-2026-42148)
OS command injection in CVE-2026-42148 (CVE-2026-42148). Risk of unauthorized operations or information disclosure.
CVE-2026-43918 Vulnerability in CVE-2026-43918 (CVE-2026-43918)
vulnerability in CVE-2026-43918 (CVE-2026-43918). Risk of unauthorized operations or information disclosure.
CVE-2026-43921 Code Injection in CVE-2026-43921 (CVE-2026-43921)
code injection in CVE-2026-43921 (CVE-2026-43921). Risk of unauthorized operations or information disclosure. Exploitable via ``config.php``.
CVE-2026-42341 Vulnerability in CVE-2026-42341 (CVE-2026-42341)
vulnerability in CVE-2026-42341 (CVE-2026-42341). Risk of unauthorized operations or information disclosure.
CVE-2026-9182 Unrestricted File Upload in esri (CVE-2026-9182)
vulnerability in esri (CVE-2026-9182). Successful exploitation can lead to full system takeover.
CVE-2026-9181 Path Traversal in path-traversal (CVE-2026-9181)
path traversal in path-traversal (CVE-2026-9181). Successful exploitation can lead to full system takeover.
CVE-2026-48316 Vulnerability in adobe (CVE-2026-48316)
vulnerability in adobe (CVE-2026-48316). Confidential information can be exposed externally.
CVE-2026-43825 Unsafe Deserialization in apache (CVE-2026-43825)
vulnerability in apache (CVE-2026-43825). Risk of unauthorized operations or information disclosure.
CVE-2026-49042 Vulnerability in org.apache.camel:camel-langchain4j-tools (CVE-2026-49042)
vulnerability in org.apache.camel:camel-langchain4j-tools (CVE-2026-49042). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-49297 Path Traversal in apache-airflow-providers-google (CVE-2026-49297)
path traversal in apache-airflow-providers-google (CVE-2026-49297). Data can be tampered with by attackers. Exploitable via ``GCSToSFTPOperator``. Mitigation: upgrade to `22.2.1` or later.
CVE-2026-46587 Vulnerability in org.apache.camel:camel-couchbase (CVE-2026-46587)
vulnerability in org.apache.camel:camel-couchbase (CVE-2026-46587). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-46588 Vulnerability in org.apache.camel:camel-couchdb (CVE-2026-46588)
vulnerability in org.apache.camel:camel-couchdb (CVE-2026-46588). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-56139 Vulnerability in org.apache.camel:camel-undertow (CVE-2026-56139)
vulnerability in org.apache.camel:camel-undertow (CVE-2026-56139). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-53913 Authentication Bypass in org.apache.camel:camel-keycloak (CVE-2026-53913)
authentication bypass in org.apache.camel:camel-keycloak (CVE-2026-53913). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-49097 Vulnerability in org.apache.camel:camel-irc (CVE-2026-49097)
vulnerability in org.apache.camel:camel-irc (CVE-2026-49097). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-49086 Vulnerability in org.apache.camel:camel-dapr (CVE-2026-49086)
vulnerability in org.apache.camel:camel-dapr (CVE-2026-49086). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-49098 Vulnerability in org.apache.camel:camel-kafka (CVE-2026-49098)
vulnerability in org.apache.camel:camel-kafka (CVE-2026-49098). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-48205 Vulnerability in org.apache.camel:camel-dns (CVE-2026-48205)
vulnerability in org.apache.camel:camel-dns (CVE-2026-48205). Confidential information can be exposed externally. Mitigation: upgrade to `4.21.0` or later.
CVE-2026-48206 Vulnerability in org.apache.camel:camel-jira (CVE-2026-48206)
vulnerability in org.apache.camel:camel-jira (CVE-2026-48206). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →