Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12452 |
|
Use-After-Free in google (CVE-2026-12452)
vulnerability in google (CVE-2026-12452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12456 |
|
Vulnerability in google (CVE-2026-12456)
vulnerability in google (CVE-2026-12456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12453 |
|
Vulnerability in google (CVE-2026-12453)
vulnerability in google (CVE-2026-12453). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12446 |
|
Authorization Flaw in google (CVE-2026-12446)
vulnerability in google (CVE-2026-12446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12444 |
|
Out-of-Bounds Read in google (CVE-2026-12444)
vulnerability in google (CVE-2026-12444). Confidential information can be exposed externally.
|
| CVE-2026-12450 |
|
Privilege Escalation in google (CVE-2026-12450)
vulnerability in google (CVE-2026-12450). Confidential information can be exposed externally.
|
| CVE-2026-12445 |
|
Use-After-Free in google (CVE-2026-12445)
vulnerability in google (CVE-2026-12445). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12443 |
|
Use-After-Free in google (CVE-2026-12443)
vulnerability in google (CVE-2026-12443). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12459 |
|
Cross-Site Scripting (XSS) in google (CVE-2026-12459)
cross-site scripting in google (CVE-2026-12459). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12455 |
|
Use-After-Free in google (CVE-2026-12455)
vulnerability in google (CVE-2026-12455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12438 |
|
Vulnerability in google (CVE-2026-12438)
vulnerability in google (CVE-2026-12438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12441 |
|
Use-After-Free in google (CVE-2026-12441)
vulnerability in google (CVE-2026-12441). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12442 |
|
Use-After-Free in google (CVE-2026-12442)
vulnerability in google (CVE-2026-12442). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12439 |
|
Use-After-Free in google (CVE-2026-12439)
vulnerability in google (CVE-2026-12439). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12440 |
|
Use-After-Free in google (CVE-2026-12440)
vulnerability in google (CVE-2026-12440). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12115 |
|
Unsafe Deserialization in wordpress (CVE-2026-12115)
vulnerability in wordpress (CVE-2026-12115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12256 |
|
Contributor PHP Object Injection in Avada <= 3.15.3 versions.
Contributor PHP Object Injection in Avada <= 3.15.3 versions.
|
| CVE-2026-12165 |
|
Privilege Escalation in wordpress (CVE-2026-12165)
vulnerability in wordpress (CVE-2026-12165). Successful exploitation can lead to full system takeover. Exploitable via ``RegistryUserRole``.
|
| CVE-2025-69108 |
|
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
|
| CVE-2025-69122 |
|
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
|
| CVE-2025-60205 |
|
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions.
|
| CVE-2026-48294 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48294)
cross-site scripting in adobe (CVE-2026-48294). Confidential information can be exposed externally.
|
| CVE-2026-46978 |
|
Vulnerability in c (CVE-2026-46978)
vulnerability in c (CVE-2026-46978). Confidential information can be exposed externally.
|
| CVE-2026-46938 |
|
Vulnerability in c (CVE-2026-46938)
vulnerability in c (CVE-2026-46938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46940 |
|
Privilege Escalation in c (CVE-2026-46940)
vulnerability in c (CVE-2026-46940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46939 |
|
Vulnerability in c (CVE-2026-46939)
vulnerability in c (CVE-2026-46939). Confidential information can be exposed externally.
|
| CVE-2026-46929 |
|
Privilege Escalation in c (CVE-2026-46929)
vulnerability in c (CVE-2026-46929). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46914 |
|
Privilege Escalation in c (CVE-2026-46914)
vulnerability in c (CVE-2026-46914). Confidential information can be exposed externally.
|
| CVE-2026-46848 |
|
Vulnerability in c (CVE-2026-46848)
vulnerability in c (CVE-2026-46848). Confidential information can be exposed externally.
|
| CVE-2026-35311 |
|
Vulnerability in c (CVE-2026-35311)
vulnerability in c (CVE-2026-35311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35299 |
|
Vulnerability in c (CVE-2026-35299)
vulnerability in c (CVE-2026-35299). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35303 |
|
Vulnerability in c (CVE-2026-35303)
vulnerability in c (CVE-2026-35303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35302 |
|
Open Redirect in c (CVE-2026-35302)
vulnerability in c (CVE-2026-35302). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35300 |
|
Unsafe Deserialization in c (CVE-2026-35300)
vulnerability in c (CVE-2026-35300). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35301 |
|
Vulnerability in c (CVE-2026-35301)
vulnerability in c (CVE-2026-35301). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35291 |
|
Privilege Escalation in c (CVE-2026-35291)
vulnerability in c (CVE-2026-35291). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35292 |
|
Vulnerability in c (CVE-2026-35292)
vulnerability in c (CVE-2026-35292). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35298 |
|
Vulnerability in c (CVE-2026-35298)
vulnerability in c (CVE-2026-35298). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35258 |
|
Open Redirect in c (CVE-2026-35258)
vulnerability in c (CVE-2026-35258). Confidential information can be exposed externally.
|
| CVE-2026-35263 |
|
Vulnerability in c (CVE-2026-35263)
vulnerability in c (CVE-2026-35263). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35259 |
|
Open Redirect in c (CVE-2026-35259)
vulnerability in c (CVE-2026-35259). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20181 |
|
Path Traversal in Cisco dos (CVE-2026-20181)
path traversal in Cisco dos (CVE-2026-20181). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12437 |
|
Use-After-Free in Google chrome (CVE-2026-12437)
vulnerability in Google chrome (CVE-2026-12437). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49468 |
|
Vulnerability in litellm (CVE-2026-49468)
vulnerability in litellm (CVE-2026-49468). Successful exploitation can lead to full system takeover. Exploitable via ``request.url.path``. Mitigation: upgrade to `1.84.0` or later.
|
| CVE-2026-54304 |
|
Information Disclosure in n8n (CVE-2026-54304)
vulnerability in n8n (CVE-2026-54304). Confidential information can be exposed externally. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54309 |
|
Vulnerability in n8n (CVE-2026-54309)
vulnerability in n8n (CVE-2026-54309). Confidential information can be exposed externally. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54305 |
|
Information Disclosure in n8n (CVE-2026-54305)
vulnerability in n8n (CVE-2026-54305). Confidential information can be exposed externally. Exploitable via ``N8N_ENV_FEAT_DYNAMIC_CREDENTIALS``. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54307 |
|
Authorization Flaw in n8n (CVE-2026-54307)
vulnerability in n8n (CVE-2026-54307). Confidential information can be exposed externally. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54314 |
|
Vulnerability in n8n (CVE-2026-54314)
vulnerability in n8n (CVE-2026-54314). Risk of unauthorized operations or information disclosure. Exploitable via ``N8N_COMPRESSION_NODE_MAX_ZIP_ENTRIES``. Mitigation: upgrade to `2.24.0` or later.
|
| CVE-2026-54302 |
|
Cross-Site Scripting (XSS) in n8n (CVE-2026-54302)
cross-site scripting in n8n (CVE-2026-54302). Risk of unauthorized operations or information disclosure. Exploitable via ``webhookId``. Mitigation: upgrade to `2.25.7` or later.
|