Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Clear
ID Title
CVE-2026-8198 Information Disclosure in wordpress (CVE-2026-8198)
vulnerability in wordpress (CVE-2026-8198). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
CVE-2026-8209 Vulnerability in path-traversal (CVE-2026-8209)
vulnerability in path-traversal (CVE-2026-8209). Risk of unauthorized operations or information disclosure.
CVE-2026-8208 Vulnerability in CVE-2026-8208 (CVE-2026-8208)
vulnerability in CVE-2026-8208 (CVE-2026-8208). Risk of unauthorized operations or information disclosure.
CVE-2026-8207 SQL Injection in sqli (CVE-2026-8207)
SQL injection in sqli (CVE-2026-8207). Risk of unauthorized operations or information disclosure.
CVE-2026-7652 Vulnerability in wordpress (CVE-2026-7652)
vulnerability in wordpress (CVE-2026-7652). Risk of unauthorized operations or information disclosure.
CVE-2026-44313 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-44313)
SSRF in ssrf (CVE-2026-44313). Confidential information can be exposed externally. Exploitable via `GET /api/v1/archives/{linkId}`.
CVE-2026-42454 OS Command Injection in docker (CVE-2026-42454)
OS command injection in docker (CVE-2026-42454). Successful exploitation can lead to full system takeover. Exploitable via `GET /docker/containers/`.
CVE-2026-42298 Code Injection in docker (CVE-2026-42298)
code injection in docker (CVE-2026-42298). Successful exploitation can lead to full system takeover. Exploitable via ``GITHUB_TOKEN``. Mitigation: upgrade to `>= 0` or later.
CVE-2026-42302 Vulnerability in openai-sdk (CVE-2026-42302)
vulnerability in openai-sdk (CVE-2026-42302). Successful exploitation can lead to full system takeover. Exploitable via ``entrypoint.sh``.
CVE-2026-42224 Cross-Site Scripting (XSS) in CVE-2026-42224 (CVE-2026-42224)
cross-site scripting in CVE-2026-42224 (CVE-2026-42224). Successful exploitation can lead to full system takeover.
CVE-2026-42205 Vulnerability in rails (CVE-2026-42205)
vulnerability in rails (CVE-2026-42205). Successful exploitation can lead to full system takeover.
CVE-2026-41517 Unrestricted File Upload in CVE-2026-41517 (CVE-2026-41517)
vulnerability in CVE-2026-41517 (CVE-2026-41517). Risk of unauthorized operations or information disclosure.
CVE-2026-42028 Path Traversal in path-traversal (CVE-2026-42028)
path traversal in path-traversal (CVE-2026-42028). Risk of unauthorized operations or information disclosure.
CVE-2026-41887 Path Traversal in CVE-2026-41887 (CVE-2026-41887)
path traversal in CVE-2026-41887 (CVE-2026-41887). Confidential information can be exposed externally.
CVE-2026-41070 Authentication Bypass in openvpn (CVE-2026-41070)
authentication bypass in openvpn (CVE-2026-41070). Confidential information can be exposed externally. Exploitable via ``plugin``.
CVE-2026-43420 Vulnerability in c (CVE-2026-43420)
vulnerability in c (CVE-2026-43420). Risk of unauthorized operations or information disclosure. Exploitable via ``i_nlink``.
CVE-2026-41524 Cross-Site Scripting (XSS) in laravel (CVE-2026-41524)
cross-site scripting in laravel (CVE-2026-41524). Confidential information can be exposed externally.
CVE-2026-41570 Vulnerability in phpunit-project (CVE-2026-41570)
vulnerability in phpunit-project (CVE-2026-41570). Successful exploitation can lead to full system takeover.
CVE-2026-41576 Cross-Site Scripting (XSS) in CVE-2026-41576 (CVE-2026-41576)
cross-site scripting in CVE-2026-41576 (CVE-2026-41576). Confidential information can be exposed externally.
CVE-2026-37431 SQL Injection in sqli (CVE-2026-37431)
SQL injection in sqli (CVE-2026-37431). Successful exploitation can lead to full system takeover.
CVE-2025-67486 Vulnerability in CVE-2025-67486 (CVE-2025-67486)
vulnerability in CVE-2025-67486 (CVE-2025-67486). Risk of unauthorized operations or information disclosure.
CVE-2026-41512 Code Injection in gem (CVE-2026-41512)
code injection in gem (CVE-2026-41512). Successful exploitation can lead to full system takeover. Exploitable via `POST /targets/auto_detect_selectors`.
CVE-2026-39816 Vulnerability in apache (CVE-2026-39816)
vulnerability in apache (CVE-2026-39816). Successful exploitation can lead to full system takeover.
CVE-2026-32803 Vulnerability in dell (CVE-2026-32803)
vulnerability in dell (CVE-2026-32803). Risk of unauthorized operations or information disclosure.
CVE-2026-25199 Information Disclosure in apache (CVE-2026-25199)
vulnerability in apache (CVE-2026-25199). Confidential information can be exposed externally.
CVE-2026-25077 Code Injection in apache (CVE-2026-25077)
code injection in apache (CVE-2026-25077). Risk of unauthorized operations or information disclosure.
CVE-2025-66467 Vulnerability in apache (CVE-2025-66467)
vulnerability in apache (CVE-2025-66467). Successful exploitation can lead to full system takeover.
CVE-2025-69233 Vulnerability in apache (CVE-2025-69233)
vulnerability in apache (CVE-2025-69233). Risk of unauthorized operations or information disclosure.
CVE-2026-7650 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7650)
cross-site scripting in wordpress (CVE-2026-7650). Risk of unauthorized operations or information disclosure.
CVE-2026-7475 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7475)
cross-site scripting in wordpress (CVE-2026-7475). Risk of unauthorized operations or information disclosure. Exploitable via ``sky_script_content``.
CVE-2026-5341 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5341)
cross-site scripting in wordpress (CVE-2026-5341). Risk of unauthorized operations or information disclosure. Exploitable via ``strava_nmr_connect``.
CVE-2026-7330 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7330)
cross-site scripting in wordpress (CVE-2026-7330). Risk of unauthorized operations or information disclosure.
CVE-2026-5127 Unsafe Deserialization in wordpress (CVE-2026-5127)
vulnerability in wordpress (CVE-2026-5127). Successful exploitation can lead to full system takeover.
CVE-2013-10075 Vulnerability in apache (CVE-2013-10075)
vulnerability in apache (CVE-2013-10075). Confidential information can be exposed externally.
CVE-2026-43284 Vulnerability in linux (CVE-2026-43284)
vulnerability in linux (CVE-2026-43284). Successful exploitation can lead to full system takeover.
CVE-2026-4935 SQL Injection in wordpress (CVE-2026-4935)
SQL injection in wordpress (CVE-2026-4935). Confidential information can be exposed externally.
CVE-2025-67887 Vulnerability in CVE-2025-67887 (CVE-2025-67887)
vulnerability in CVE-2025-67887 (CVE-2025-67887). Risk of unauthorized operations or information disclosure.
CVE-2025-69690 Unsafe Deserialization in deserialization (CVE-2025-69690)
vulnerability in deserialization (CVE-2025-69690). Successful exploitation can lead to full system takeover.
CVE-2025-67888 OS Command Injection in CVE-2025-67888 (CVE-2025-67888)
OS command injection in CVE-2025-67888 (CVE-2025-67888). Risk of unauthorized operations or information disclosure.
CVE-2025-67886 Unrestricted File Upload in CVE-2025-67886 (CVE-2025-67886)
vulnerability in CVE-2025-67886 (CVE-2025-67886). Risk of unauthorized operations or information disclosure.
CVE-2025-69691 Vulnerability in pfsense (CVE-2025-69691)
vulnerability in pfsense (CVE-2025-69691). Successful exploitation can lead to full system takeover.
CVE-2024-51092 OS Command Injection in command-injection (CVE-2024-51092)
OS command injection in command-injection (CVE-2024-51092). Confidential information can be exposed externally. Exploitable via ``version_netsnmp``.
CVE-2024-33722 SQL Injection in sqli (CVE-2024-33722)
SQL injection in sqli (CVE-2024-33722). Risk of unauthorized operations or information disclosure.
CVE-2024-33288 SQL Injection in sqli (CVE-2024-33288)
SQL injection in sqli (CVE-2024-33288). Risk of unauthorized operations or information disclosure.
CVE-2024-33724 Cross-Site Scripting (XSS) in CVE-2024-33724 (CVE-2024-33724)
cross-site scripting in CVE-2024-33724 (CVE-2024-33724). Risk of unauthorized operations or information disclosure.
ROOT-OS-DEBIAN-13-CVE-2019-16234 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2019-16234)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2019-16234). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.85-1.root.io.120, 6.12.85-1.root.io.119, 6.12.85-1.root.io.118, 6.12.85-1.root.io.117` or later.
ROOT-OS-DEBIAN-13-CVE-2025-39789 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-39789)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-39789). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.85-1.root.io.120, 6.12.85-1.root.io.119, 6.12.85-1.root.io.118, 6.12.85-1.root.io.117` or later.
ROOT-OS-DEBIAN-13-CVE-2025-39958 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-39958)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-39958). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.12.85-1.root.io.120, 6.12.85-1.root.io.119, 6.12.85-1.root.io.118, 6.12.85-1.root.io.117` or later.
ROOT-OS-DEBIAN-13-CVE-2025-68171 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-68171)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-68171). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.85-1.root.io.120, 6.12.85-1.root.io.119, 6.12.85-1.root.io.118, 6.12.85-1.root.io.117` or later.
ROOT-OS-DEBIAN-13-CVE-2025-71191 Vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-71191)
vulnerability in rootio-linux (ROOT-OS-DEBIAN-13-CVE-2025-71191). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.85-1.root.io.120, 6.12.85-1.root.io.119, 6.12.85-1.root.io.118, 6.12.85-1.root.io.117` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →