Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-58176 |
|
Vulnerability in vue (CVE-2026-58176)
vulnerability in vue (CVE-2026-58176). Data can be tampered with by attackers.
|
| CVE-2026-49473 |
|
Vulnerability in @cedar-policy/authorization-for-expressjs (CVE-2026-49473)
vulnerability in @cedar-policy/authorization-for-expressjs (CVE-2026-49473). Successful exploitation can lead to full system takeover. Exploitable via `GET /users`. Mitigation: upgrade to `0.3.0` or later.
|
| CVE-2025-53648 |
|
SQL Injection in apache (CVE-2025-53648)
SQL injection in apache (CVE-2025-53648). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6556 |
|
Vulnerability in express (CVE-2026-6556)
vulnerability in express (CVE-2026-6556). Confidential information can be exposed externally.
|
| CVE-2026-49877 |
|
Vulnerability in activemq (CVE-2026-49877)
vulnerability in activemq (CVE-2026-49877). Confidential information can be exposed externally. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-49434 |
|
Vulnerability in activemq (CVE-2026-49434)
vulnerability in activemq (CVE-2026-49434). Data can be tampered with by attackers. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-50734 |
|
Vulnerability in activemq (CVE-2026-50734)
vulnerability in activemq (CVE-2026-50734). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-52760 |
|
Cross-Site Scripting (XSS) in activemq (CVE-2026-52760)
cross-site scripting in activemq (CVE-2026-52760). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-53916 |
|
Vulnerability in activemq (CVE-2026-53916)
vulnerability in activemq (CVE-2026-53916). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-50750 |
|
Vulnerability in activemq (CVE-2026-50750)
vulnerability in activemq (CVE-2026-50750). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-53917 |
|
Vulnerability in activemq (CVE-2026-53917)
vulnerability in activemq (CVE-2026-53917). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-54475 |
|
Vulnerability in activemq (CVE-2026-54475)
vulnerability in activemq (CVE-2026-54475). Data can be tampered with by attackers. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-49432 |
|
Vulnerability in activemq (CVE-2026-49432)
vulnerability in activemq (CVE-2026-49432). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-8141 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8141)
cross-site scripting in wordpress (CVE-2026-8141). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9711 |
|
SQL Injection in wordpress (CVE-2026-9711)
SQL injection in wordpress (CVE-2026-9711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11589 |
|
Vulnerability in wordpress (CVE-2026-11589)
vulnerability in wordpress (CVE-2026-11589). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11590 |
|
Vulnerability in wordpress (CVE-2026-11590)
vulnerability in wordpress (CVE-2026-11590). Confidential information can be exposed externally.
|
| CVE-2026-11581 |
|
Vulnerability in wordpress (CVE-2026-11581)
vulnerability in wordpress (CVE-2026-11581). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12240 |
|
Unsafe Deserialization in wordpress (CVE-2026-12240)
vulnerability in wordpress (CVE-2026-12240). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9576 |
|
Vulnerability in wordpress (CVE-2026-9576)
vulnerability in wordpress (CVE-2026-9576). Confidential information can be exposed externally.
|
| CVE-2026-12349 |
|
Vulnerability in c (CVE-2026-12349)
vulnerability in c (CVE-2026-12349). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12560 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12560)
cross-site scripting in wordpress (CVE-2026-12560). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8944 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-8944)
vulnerability in wordpress (CVE-2026-8944). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12073 |
|
Vulnerability in wordpress (CVE-2026-12073)
vulnerability in wordpress (CVE-2026-12073). Successful exploitation can lead to full system takeover. Exploitable via ``user_login``.
|
| CVE-2026-11367 |
|
Path Traversal in wordpress (CVE-2026-11367)
path traversal in wordpress (CVE-2026-11367). Confidential information can be exposed externally.
|
| CVE-2026-12114 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12114)
cross-site scripting in wordpress (CVE-2026-12114). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53404 |
|
Vulnerability in tomcat (CVE-2026-53404)
vulnerability in tomcat (CVE-2026-53404). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-50229 |
|
Vulnerability in tomcat (CVE-2026-50229)
vulnerability in tomcat (CVE-2026-50229). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-53434 |
|
Vulnerability in tomcat (CVE-2026-53434)
vulnerability in tomcat (CVE-2026-53434). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-55955 |
|
Authentication Bypass in tomcat (CVE-2026-55955)
authentication bypass in tomcat (CVE-2026-55955). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-55956 |
|
Vulnerability in tomcat (CVE-2026-55956)
vulnerability in tomcat (CVE-2026-55956). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-55276 |
|
Vulnerability in tomcat (CVE-2026-55276)
vulnerability in tomcat (CVE-2026-55276). Confidential information can be exposed externally. Mitigation: upgrade to `9.0.119, 10.1.56, 11.0.23` or later.
|
| CVE-2026-55957 |
|
Vulnerability in tomcat (CVE-2026-55957)
vulnerability in tomcat (CVE-2026-55957). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.101, 10.1.37, 11.0.5` or later.
|
| CVE-2026-57958 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-57958)
cross-site scripting in laravel (CVE-2026-57958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57949 |
|
Vulnerability in vue (CVE-2026-57949)
vulnerability in vue (CVE-2026-57949). Confidential information can be exposed externally. Exploitable via `GET /admin-api/crm/follow-up-record/get`.
|
| CVE-2026-57950 |
|
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
|
| CVE-2026-36848 |
|
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
|
| CVE-2026-9676 |
|
Vulnerability in wordpress (CVE-2026-9676)
vulnerability in wordpress (CVE-2026-9676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10083 |
|
Vulnerability in wordpress (CVE-2026-10083)
vulnerability in wordpress (CVE-2026-10083). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13528 |
|
Path Traversal in vue (CVE-2026-13528)
path traversal in vue (CVE-2026-13528). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8095 |
|
Vulnerability in wordpress (CVE-2026-8095)
vulnerability in wordpress (CVE-2026-8095). Data can be tampered with by attackers.
|
| CVE-2026-11773 |
|
Vulnerability in wordpress (CVE-2026-11773)
vulnerability in wordpress (CVE-2026-11773). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11597 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11597)
cross-site scripting in wordpress (CVE-2026-11597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11783 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11783)
cross-site scripting in wordpress (CVE-2026-11783). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12399 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12399)
cross-site scripting in wordpress (CVE-2026-12399). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9242 |
|
Vulnerability in wordpress (CVE-2026-9242)
vulnerability in wordpress (CVE-2026-9242). Risk of unauthorized operations or information disclosure. Exploitable via ``callback``.
|
| CVE-2026-12471 |
|
Vulnerability in wordpress (CVE-2026-12471)
vulnerability in wordpress (CVE-2026-12471). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13295 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13295)
cross-site scripting in wordpress (CVE-2026-13295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11987 |
|
Vulnerability in wordpress (CVE-2026-11987)
vulnerability in wordpress (CVE-2026-11987). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9233 |
|
Vulnerability in wordpress (CVE-2026-9233)
vulnerability in wordpress (CVE-2026-9233). Risk of unauthorized operations or information disclosure.
|