Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-43865 |
|
Unsafe Deserialization in org.apache.camel:camel-hazelcast (CVE-2026-43865)
vulnerability in org.apache.camel:camel-hazelcast (CVE-2026-43865). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-24012 |
|
Vulnerability in apache-iotdb (CVE-2026-24012)
vulnerability in apache-iotdb (CVE-2026-24012). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.8` or later.
|
| CVE-2026-24014 |
|
Vulnerability in apache-iotdb (CVE-2026-24014)
vulnerability in apache-iotdb (CVE-2026-24014). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.8` or later.
|
| CVE-2026-46455 |
|
Vulnerability in org.apache.camel:camel-keycloak (CVE-2026-46455)
vulnerability in org.apache.camel:camel-keycloak (CVE-2026-46455). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-42527 |
|
Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-42527)
vulnerability in org.apache.camel:camel-jms (CVE-2026-42527). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-40047 |
|
Vulnerability in org.apache.camel:camel-docling (CVE-2026-40047)
vulnerability in org.apache.camel:camel-docling (CVE-2026-40047). Confidential information can be exposed externally. Exploitable via ``docling``. Mitigation: upgrade to `4.18.3` or later.
|
| CVE-2026-46457 |
|
Vulnerability in org.apache.camel:camel-nats (CVE-2026-46457)
vulnerability in org.apache.camel:camel-nats (CVE-2026-46457). Data can be tampered with by attackers. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46454 |
|
Vulnerability in org.apache.camel:camel-cometd (CVE-2026-46454)
vulnerability in org.apache.camel:camel-cometd (CVE-2026-46454). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-43867 |
|
Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-43867)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-43867). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-24013 |
|
Vulnerability in apache-iotdb (CVE-2026-24013)
vulnerability in apache-iotdb (CVE-2026-24013). Confidential information can be exposed externally. Mitigation: upgrade to `2.0.8` or later.
|
| CVE-2026-43866 |
|
Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-43866)
vulnerability in org.apache.camel:camel-jms (CVE-2026-43866). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46453 |
|
Vulnerability in org.apache.camel:camel-elasticsearch-rest-client (CVE-2026-46453)
vulnerability in org.apache.camel:camel-elasticsearch-rest-client (CVE-2026-46453). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-6382 |
|
Vulnerability in wordpress (CVE-2026-6382)
vulnerability in wordpress (CVE-2026-6382). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11766 |
|
Vulnerability in wordpress (CVE-2026-11766)
vulnerability in wordpress (CVE-2026-11766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11855 |
|
Vulnerability in wordpress (CVE-2026-11855)
vulnerability in wordpress (CVE-2026-11855). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11962 |
|
Vulnerability in wordpress (CVE-2026-11962)
vulnerability in wordpress (CVE-2026-11962). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12083 |
|
Vulnerability in wordpress (CVE-2026-12083)
vulnerability in wordpress (CVE-2026-12083). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14802 |
|
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the...
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the...
|
| CVE-2026-10830 |
|
Vulnerability in wordpress (CVE-2026-10830)
vulnerability in wordpress (CVE-2026-10830). Successful exploitation can lead to full system takeover.
|
| CVE-2024-6228 |
|
Vulnerability in wordpress (CVE-2024-6228)
vulnerability in wordpress (CVE-2024-6228). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5137 |
|
Vulnerability in wordpress (CVE-2026-5137)
vulnerability in wordpress (CVE-2026-5137). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4804 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4804)
cross-site scripting in wordpress (CVE-2026-4804). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9756 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9756)
cross-site scripting in wordpress (CVE-2026-9756). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47896 |
|
Path Traversal in csharp (CVE-2026-47896)
path traversal in csharp (CVE-2026-47896). Confidential information can be exposed externally.
|
| CVE-2026-11900 |
|
Vulnerability in wordpress (CVE-2026-11900)
vulnerability in wordpress (CVE-2026-11900). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11778 |
|
Code Injection in wordpress (CVE-2026-11778)
code injection in wordpress (CVE-2026-11778). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11398 |
|
Vulnerability in wordpress (CVE-2026-11398)
vulnerability in wordpress (CVE-2026-11398). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9230 |
|
Vulnerability in wordpress (CVE-2026-9230)
vulnerability in wordpress (CVE-2026-9230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9148 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9148)
cross-site scripting in wordpress (CVE-2026-9148). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8351 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8351)
cross-site scripting in wordpress (CVE-2026-8351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47897 |
|
Path Traversal in csharp (CVE-2026-47897)
path traversal in csharp (CVE-2026-47897). Data can be tampered with by attackers.
|
| CVE-2026-47898 |
|
XXE (XML External Entity) in csharp (CVE-2026-47898)
vulnerability in csharp (CVE-2026-47898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9725 |
|
Path Traversal in wordpress (CVE-2026-9725)
path traversal in wordpress (CVE-2026-9725). Data can be tampered with by attackers.
|
| CVE-2026-9626 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9626)
cross-site scripting in wordpress (CVE-2026-9626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9180 |
|
Vulnerability in wordpress (CVE-2026-9180)
vulnerability in wordpress (CVE-2026-9180). Risk of unauthorized operations or information disclosure. Exploitable via `POST /motopress/appointment/v1/bookings`.
|
| CVE-2026-8892 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8892)
cross-site scripting in wordpress (CVE-2026-8892). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8489 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8489)
cross-site scripting in wordpress (CVE-2026-8489). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14352 |
|
Path Traversal in wordpress (CVE-2026-14352)
path traversal in wordpress (CVE-2026-14352). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-13040 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13040)
cross-site scripting in wordpress (CVE-2026-13040). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12557 |
|
Vulnerability in wordpress (CVE-2026-12557)
vulnerability in wordpress (CVE-2026-12557). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11397 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-11397)
SSRF in wordpress (CVE-2026-11397). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14327 |
|
Path Traversal in wordpress (CVE-2026-14327)
path traversal in wordpress (CVE-2026-14327). Confidential information can be exposed externally.
|
| CVE-2026-12920 |
|
SQL Injection in wordpress (CVE-2026-12920)
SQL injection in wordpress (CVE-2026-12920). Confidential information can be exposed externally.
|
| CVE-2026-12729 |
|
Vulnerability in wordpress (CVE-2026-12729)
vulnerability in wordpress (CVE-2026-12729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12731 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12731)
cross-site scripting in wordpress (CVE-2026-12731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12734 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12734)
cross-site scripting in wordpress (CVE-2026-12734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58460 |
|
Path Traversal in react (CVE-2026-58460)
path traversal in react (CVE-2026-58460). Data can be tampered with by attackers.
|
| CVE-2026-59102 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-59102)
cross-site scripting in vue (CVE-2026-59102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|