Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39545 |
|
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
|
| CVE-2026-39446 |
|
Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.
Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.
|
| CVE-2026-39443 |
|
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.
Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.
|
| CVE-2026-12466 |
|
Vulnerability in google (CVE-2026-12466)
vulnerability in google (CVE-2026-12466). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12467 |
|
Use-After-Free in Google chrome (CVE-2026-12467)
vulnerability in Google chrome (CVE-2026-12467). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12468 |
|
Vulnerability in google (CVE-2026-12468)
vulnerability in google (CVE-2026-12468). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12445 |
|
Use-After-Free in google (CVE-2026-12445)
vulnerability in google (CVE-2026-12445). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12443 |
|
Use-After-Free in google (CVE-2026-12443)
vulnerability in google (CVE-2026-12443). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12455 |
|
Use-After-Free in google (CVE-2026-12455)
vulnerability in google (CVE-2026-12455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12452 |
|
Use-After-Free in google (CVE-2026-12452)
vulnerability in google (CVE-2026-12452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12448 |
|
Privilege Escalation in privilege-escalation (CVE-2026-12448)
vulnerability in privilege-escalation (CVE-2026-12448). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12449 |
|
Use-After-Free in privilege-escalation (CVE-2026-12449)
vulnerability in privilege-escalation (CVE-2026-12449). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12447 |
|
Vulnerability in google (CVE-2026-12447)
vulnerability in google (CVE-2026-12447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12464 |
|
Use-After-Free in google (CVE-2026-12464)
vulnerability in google (CVE-2026-12464). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12454 |
|
Vulnerability in google (CVE-2026-12454)
vulnerability in google (CVE-2026-12454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12462 |
|
Use-After-Free in google (CVE-2026-12462)
vulnerability in google (CVE-2026-12462). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12451 |
|
Use-After-Free in google (CVE-2026-12451)
vulnerability in google (CVE-2026-12451). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12465 |
|
Vulnerability in google (CVE-2026-12465)
vulnerability in google (CVE-2026-12465). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12439 |
|
Use-After-Free in google (CVE-2026-12439)
vulnerability in google (CVE-2026-12439). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12256 |
|
Contributor PHP Object Injection in Avada <= 3.15.3 versions.
Contributor PHP Object Injection in Avada <= 3.15.3 versions.
|
| CVE-2026-12165 |
|
Privilege Escalation in wordpress (CVE-2026-12165)
vulnerability in wordpress (CVE-2026-12165). Successful exploitation can lead to full system takeover. Exploitable via ``RegistryUserRole``.
|
| CVE-2026-12441 |
|
Use-After-Free in google (CVE-2026-12441)
vulnerability in google (CVE-2026-12441). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12438 |
|
Vulnerability in google (CVE-2026-12438)
vulnerability in google (CVE-2026-12438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12442 |
|
Use-After-Free in google (CVE-2026-12442)
vulnerability in google (CVE-2026-12442). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48294 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-48294)
cross-site scripting in adobe (CVE-2026-48294). Confidential information can be exposed externally.
|
| CVE-2026-46929 |
|
Privilege Escalation in c (CVE-2026-46929)
vulnerability in c (CVE-2026-46929). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46939 |
|
Vulnerability in c (CVE-2026-46939)
vulnerability in c (CVE-2026-46939). Confidential information can be exposed externally.
|
| CVE-2026-46940 |
|
Privilege Escalation in c (CVE-2026-46940)
vulnerability in c (CVE-2026-46940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46938 |
|
Vulnerability in c (CVE-2026-46938)
vulnerability in c (CVE-2026-46938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46914 |
|
Privilege Escalation in c (CVE-2026-46914)
vulnerability in c (CVE-2026-46914). Confidential information can be exposed externally.
|
| CVE-2026-46848 |
|
Vulnerability in c (CVE-2026-46848)
vulnerability in c (CVE-2026-46848). Confidential information can be exposed externally.
|
| CVE-2026-35302 |
|
Open Redirect in c (CVE-2026-35302)
vulnerability in c (CVE-2026-35302). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35303 |
|
Vulnerability in c (CVE-2026-35303)
vulnerability in c (CVE-2026-35303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35299 |
|
Vulnerability in c (CVE-2026-35299)
vulnerability in c (CVE-2026-35299). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35311 |
|
Vulnerability in c (CVE-2026-35311)
vulnerability in c (CVE-2026-35311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35259 |
|
Open Redirect in c (CVE-2026-35259)
vulnerability in c (CVE-2026-35259). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35258 |
|
Open Redirect in c (CVE-2026-35258)
vulnerability in c (CVE-2026-35258). Confidential information can be exposed externally.
|
| CVE-2026-12437 |
|
Use-After-Free in Google chrome (CVE-2026-12437)
vulnerability in Google chrome (CVE-2026-12437). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54304 |
|
Information Disclosure in n8n (CVE-2026-54304)
vulnerability in n8n (CVE-2026-54304). Confidential information can be exposed externally. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54314 |
|
Vulnerability in n8n (CVE-2026-54314)
vulnerability in n8n (CVE-2026-54314). Risk of unauthorized operations or information disclosure. Exploitable via ``N8N_COMPRESSION_NODE_MAX_ZIP_ENTRIES``. Mitigation: upgrade to `2.24.0` or later.
|
| CVE-2026-54312 |
|
Vulnerability in n8n (CVE-2026-54312)
vulnerability in n8n (CVE-2026-54312). Risk of unauthorized operations or information disclosure. Exploitable via ``Object.prototype``. Mitigation: upgrade to `2.24.0` or later.
|
| CVE-2026-52845 |
|
Authentication Bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845)
authentication bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845). Confidential information can be exposed externally. Exploitable via `GET /index.php`. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-52844 |
|
Path Traversal in github.com/caddyserver/caddy/v2 (CVE-2026-52844)
path traversal in github.com/caddyserver/caddy/v2 (CVE-2026-52844). Confidential information can be exposed externally. Exploitable via `GET /private/secret.txt`. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-53853 |
|
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
|
| CVE-2026-50656 |
|
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in...
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in...
|
| CVE-2026-49401 |
|
Vulnerability in deno (CVE-2026-49401)
vulnerability in deno (CVE-2026-49401). Data can be tampered with by attackers. Mitigation: upgrade to `2.7.14` or later.
|
| CVE-2026-49402 |
|
OS Command Injection in deno (CVE-2026-49402)
OS command injection in deno (CVE-2026-49402). Successful exploitation can lead to full system takeover. Exploitable via ``spawn``. Mitigation: upgrade to `2.7.10` or later.
|
| CVE-2026-54311 |
|
Vulnerability in n8n (CVE-2026-54311)
vulnerability in n8n (CVE-2026-54311). Confidential information can be exposed externally. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54308 |
|
Vulnerability in n8n (CVE-2026-54308)
vulnerability in n8n (CVE-2026-54308). Risk of unauthorized operations or information disclosure. Exploitable via ``MicrosoftAgent365Trigger``. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54313 |
|
SQL Injection in n8n (CVE-2026-54313)
SQL injection in n8n (CVE-2026-54313). Data can be tampered with by attackers. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.24.0` or later.
|