Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19670 |
|
Authorization Flaw in nginx (CVE-2026-19670)
vulnerability in nginx (CVE-2026-19670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19728 |
|
Vulnerability in wordpress (CVE-2026-19728)
vulnerability in wordpress (CVE-2026-19728). Confidential information can be exposed externally.
|
| CVE-2026-55676 |
|
Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
|
| CVE-2026-16993 |
|
Information Disclosure in wordpress (CVE-2026-16993)
vulnerability in wordpress (CVE-2026-16993). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60005 |
|
Vulnerability in nginx (CVE-2026-60005)
vulnerability in nginx (CVE-2026-60005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56434 |
|
Use-After-Free in nginx (CVE-2026-56434)
vulnerability in nginx (CVE-2026-56434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55723 |
|
Vulnerability in nginx (CVE-2026-55723)
vulnerability in nginx (CVE-2026-55723). Confidential information can be exposed externally.
|
| CVE-2026-42533 |
|
Vulnerability in nginx (CVE-2026-42533)
vulnerability in nginx (CVE-2026-42533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52865 |
|
Vulnerability in nginx (CVE-2026-52865)
vulnerability in nginx (CVE-2026-52865). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60065 |
|
Out-of-Bounds Read in nginx (CVE-2026-60065)
vulnerability in nginx (CVE-2026-60065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60062 |
|
Path Traversal in nginx (CVE-2026-60062)
path traversal in nginx (CVE-2026-60062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49972 |
|
Unrestricted File Upload in laravel (CVE-2026-49972)
vulnerability in laravel (CVE-2026-49972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52761 |
|
Vulnerability in nginx (CVE-2026-52761)
vulnerability in nginx (CVE-2026-52761). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52747 |
|
Vulnerability in nginx (CVE-2026-52747)
vulnerability in nginx (CVE-2026-52747). Data can be tampered with by attackers.
|
| CVE-2026-53646 |
|
Vulnerability in nginx (CVE-2026-53646)
vulnerability in nginx (CVE-2026-53646). Risk of unauthorized operations or information disclosure. Exploitable via ``ClientPasswordReset``.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2026-5524 |
|
Unrestricted File Upload in wordpress (CVE-2026-5524)
vulnerability in wordpress (CVE-2026-5524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50107 |
|
Vulnerability in nginx-gateway-fabric (CVE-2026-50107)
vulnerability in nginx-gateway-fabric (CVE-2026-50107). Confidential information can be exposed externally. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-32682 |
|
Vulnerability in nginx-gateway-fabric (CVE-2026-32682)
vulnerability in nginx-gateway-fabric (CVE-2026-32682). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-42055 |
|
Vulnerability in nginx (CVE-2026-42055)
vulnerability in nginx (CVE-2026-42055). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42530 |
|
Use-After-Free in nginx (CVE-2026-42530)
vulnerability in nginx (CVE-2026-42530). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48142 |
|
Out-of-Bounds Read in nginx (CVE-2026-48142)
vulnerability in nginx (CVE-2026-48142). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11311 |
|
Vulnerability in nginx-gateway-fabric (CVE-2026-11311)
vulnerability in nginx-gateway-fabric (CVE-2026-11311). Confidential information can be exposed externally. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-45569 |
|
Path Traversal in c (CVE-2026-45569)
path traversal in c (CVE-2026-45569). Confidential information can be exposed externally.
|
| CVE-2026-45567 |
|
Authentication Bypass in nginx (CVE-2026-45567)
authentication bypass in nginx (CVE-2026-45567). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45566 |
|
Open Redirect in nginx (CVE-2026-45566)
vulnerability in nginx (CVE-2026-45566). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45565 |
|
Vulnerability in nginx (CVE-2026-45565)
vulnerability in nginx (CVE-2026-45565). Confidential information can be exposed externally.
|
| CVE-2026-45563 |
|
Vulnerability in nginx (CVE-2026-45563)
vulnerability in nginx (CVE-2026-45563). Risk of unauthorized operations or information disclosure. Exploitable via `GET /history/`.
|
| CVE-2026-45564 |
|
OS Command Injection in c (CVE-2026-45564)
OS command injection in c (CVE-2026-45564). Successful exploitation can lead to full system takeover. Exploitable via `POST /config/versions/`.
|
| CVE-2026-45561 |
|
SSRF (Server-Side Request Forgery) in flask (CVE-2026-45561)
SSRF in flask (CVE-2026-45561). Confidential information can be exposed externally.
|
| CVE-2026-45560 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-45560)
cross-site scripting in c (CVE-2026-45560). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45559 |
|
Vulnerability in nginx (CVE-2026-45559)
vulnerability in nginx (CVE-2026-45559). Confidential information can be exposed externally.
|
| CVE-2026-45558 |
|
Vulnerability in c (CVE-2026-45558)
vulnerability in c (CVE-2026-45558). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/service/haproxy/`.
|
| CVE-2026-45556 |
|
Vulnerability in nginx (CVE-2026-45556)
vulnerability in nginx (CVE-2026-45556). Successful exploitation can lead to full system takeover. Exploitable via `POST /waf/`.
|
| CVE-2026-45552 |
|
Vulnerability in nginx (CVE-2026-45552)
vulnerability in nginx (CVE-2026-45552). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45550 |
|
Vulnerability in nginx (CVE-2026-45550)
vulnerability in nginx (CVE-2026-45550). Data can be tampered with by attackers. Exploitable via `PUT /smon/check`.
|
| CVE-2026-45549 |
|
Vulnerability in nginx (CVE-2026-45549)
vulnerability in nginx (CVE-2026-45549). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49975 |
|
Vulnerability in apache (CVE-2026-49975)
vulnerability in apache (CVE-2026-49975). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.4.68` or later.
|
| CVE-2026-43926 |
|
Vulnerability in nginx (CVE-2026-43926)
vulnerability in nginx (CVE-2026-43926). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41017 |
|
Vulnerability in apache-airflow (CVE-2026-41017)
vulnerability in apache-airflow (CVE-2026-41017). Confidential information can be exposed externally. Exploitable via ``JWTRefreshMiddleware``. Mitigation: upgrade to `3.2.2` or later.
|
| CVE-2026-9256 |
|
Vulnerability in nginx (CVE-2026-9256)
vulnerability in nginx (CVE-2026-9256). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.24.0, 1.30.2, 1.31.1` or later.
|
| CVE-2026-8711 |
|
Vulnerability in nginx (CVE-2026-8711)
vulnerability in nginx (CVE-2026-8711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42945 |
|
Vulnerability in nginx (CVE-2026-42945)
vulnerability in nginx (CVE-2026-42945). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.30.1` or later.
|
| CVE-2026-42946 |
|
Vulnerability in nginx (CVE-2026-42946)
vulnerability in nginx (CVE-2026-42946). Confidential information can be exposed externally. Mitigation: upgrade to `1.30.1` or later.
|
| CVE-2026-42926 |
|
Vulnerability in nginx (CVE-2026-42926)
vulnerability in nginx (CVE-2026-42926). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.30.1` or later.
|
| CVE-2026-42934 |
|
Out-of-Bounds Read in nginx (CVE-2026-42934)
vulnerability in nginx (CVE-2026-42934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.30.1` or later.
|
| CVE-2026-40701 |
|
Use-After-Free in nginx (CVE-2026-40701)
vulnerability in nginx (CVE-2026-40701). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.30.1` or later.
|
| CVE-2026-40460 |
|
Vulnerability in nginx (CVE-2026-40460)
vulnerability in nginx (CVE-2026-40460). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.30.1` or later.
|
| CVE-2026-42268 |
|
Vulnerability in modsecurity (CVE-2026-42268)
vulnerability in modsecurity (CVE-2026-42268). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.15` or later.
|
| CVE-2026-30923 |
|
Out-of-Bounds Read in modsecurity2 (CVE-2026-30923)
vulnerability in modsecurity2 (CVE-2026-30923). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.15` or later.
|