Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-39581 Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
CVE-2026-39574 Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
CVE-2026-39490 Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
CVE-2026-39437 Cross-Site Scripting (XSS) in CVE-2026-39437 (CVE-2026-39437)
cross-site scripting in CVE-2026-39437 (CVE-2026-39437). Risk of unauthorized operations or information disclosure.
CVE-2026-2381 Vulnerability in wordpress (CVE-2026-2381)
vulnerability in wordpress (CVE-2026-2381). Risk of unauthorized operations or information disclosure. Exploitable via ``wc_stripe_pay_for_order``.
CVE-2026-10825 Vulnerability in CVE-2026-10825 (CVE-2026-10825)
vulnerability in CVE-2026-10825 (CVE-2026-10825). Risk of unauthorized operations or information disclosure.
CVE-2025-68045 Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
RHSA-2026:26192 Red Hat Security Advisory: libexif security update
Red Hat Security Advisory: libexif security update
RHSA-2026:26191 Red Hat Security Advisory: libexif security update
Red Hat Security Advisory: libexif security update
MAL-2026-5876 Vulnerability in temp-development-package-test (MAL-2026-5876)
vulnerability in temp-development-package-test (MAL-2026-5876). Risk of unauthorized operations or information disclosure.
DEBIAN-CVE-2026-39043 DEBIAN-CVE-2026-39043
DEBIAN-CVE-2026-39044 DEBIAN-CVE-2026-39044
SUSE-SU-2026:22139-1 Vulnerability in opensc (SUSE-SU-2026:22139-1)
vulnerability in opensc (SUSE-SU-2026:22139-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.24.0-slfo.1.1_4.1` or later.
GHSA-266v-958f-g596 Vulnerability in check-ulid (GHSA-266v-958f-g596)
vulnerability in check-ulid (GHSA-266v-958f-g596). Risk of unauthorized operations or information disclosure. Exploitable via ``ulid``.
CVE-2025-9912 Privilege Escalation in privilege-escalation (CVE-2025-9912)
vulnerability in privilege-escalation (CVE-2025-9912). Data can be tampered with by attackers.
CVE-2026-46331 Vulnerability in linux (CVE-2026-46331)
vulnerability in linux (CVE-2026-46331). Successful exploitation can lead to full system takeover.
CVE-2026-10093 Cross-Site Scripting (XSS) in wordpress (CVE-2026-10093)
cross-site scripting in wordpress (CVE-2026-10093). Risk of unauthorized operations or information disclosure.
CVE-2026-8444 SQL Injection in wordpress (CVE-2026-8444)
SQL injection in wordpress (CVE-2026-8444). Successful exploitation can lead to full system takeover.
SUSE-SU-2026:22138-1 Vulnerability in python-PyJWT (SUSE-SU-2026:22138-1)
vulnerability in python-PyJWT (SUSE-SU-2026:22138-1). Risk of unauthorized operations or information disclosure. Exploitable via ``PyJWKClient``. Mitigation: upgrade to `2.12.1-slfo.1.1_2.1` or later.
MAL-2026-5875 Vulnerability in myfirstpackagetestaaa (MAL-2026-5875)
vulnerability in myfirstpackagetestaaa (MAL-2026-5875). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:22238-1 Vulnerability in python-PyJWT (SUSE-SU-2026:22238-1)
vulnerability in python-PyJWT (SUSE-SU-2026:22238-1). Risk of unauthorized operations or information disclosure. Exploitable via ``PyJWKClient``. Mitigation: upgrade to `2.9.0-3.1` or later.
DEBIAN-CVE-2026-52717 DEBIAN-CVE-2026-52717
MAL-2026-5874 Vulnerability in aaaazzzzaz (MAL-2026-5874)
vulnerability in aaaazzzzaz (MAL-2026-5874). Risk of unauthorized operations or information disclosure.
USN-8432-1 Vulnerability in freerdp2 (USN-8432-1)
vulnerability in freerdp2 (USN-8432-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.2.0+dfsg1-0ubuntu0.18.04.4+esm6` or later.
CVE-2026-5667 Vulnerability in jvn (CVE-2026-5667)
vulnerability in jvn (CVE-2026-5667). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:2412-1 Vulnerability in openssl-1_1-livepatches (SUSE-SU-2026:2412-1)
vulnerability in openssl-1_1-livepatches (SUSE-SU-2026:2412-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6-150700.13.6.1` or later.
SUSE-SU-2026:2411-1 Vulnerability in openssl-3-livepatches (SUSE-SU-2026:2411-1)
vulnerability in openssl-3-livepatches (SUSE-SU-2026:2411-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.4-150600.13.11.1` or later.
SUSE-SU-2026:2410-1 Vulnerability in openssl-1_1-livepatches (SUSE-SU-2026:2410-1)
vulnerability in openssl-1_1-livepatches (SUSE-SU-2026:2410-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6-150600.11.6.1` or later.
SUSE-SU-2026:2409-1 Vulnerability in openssl-1_1-livepatches (SUSE-SU-2026:2409-1)
vulnerability in openssl-1_1-livepatches (SUSE-SU-2026:2409-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.6-150500.6.14.1` or later.
SUSE-SU-2026:2408-1 Vulnerability in perl-HTTP-Daemon (SUSE-SU-2026:2408-1)
vulnerability in perl-HTTP-Daemon (SUSE-SU-2026:2408-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.01-9.8.1` or later.
SUSE-SU-2026:2407-1 Vulnerability in containerized-data-importer (SUSE-SU-2026:2407-1)
vulnerability in containerized-data-importer (SUSE-SU-2026:2407-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.64.0-150700.9.8.1` or later.
MAL-2026-5868 Vulnerability in datacamp-light (MAL-2026-5868)
vulnerability in datacamp-light (MAL-2026-5868). Risk of unauthorized operations or information disclosure.
USN-8349-3 Vulnerability in rsync (USN-8349-3)
vulnerability in rsync (USN-8349-3). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.0-2ubuntu0.4+esm4` or later.
ROOT-APP-NPM-CVE-2026-46490 Vulnerability in @rootio/samlify (ROOT-APP-NPM-CVE-2026-46490)
vulnerability in @rootio/samlify (ROOT-APP-NPM-CVE-2026-46490). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.0-root.io.1` or later.
ROOT-APP-NPM-CVE-2025-47949 Vulnerability in @rootio/samlify (ROOT-APP-NPM-CVE-2025-47949)
vulnerability in @rootio/samlify (ROOT-APP-NPM-CVE-2025-47949). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.0-root.io.1` or later.
SUSE-SU-2026:2406-1 Vulnerability in qemu (SUSE-SU-2026:2406-1)
vulnerability in qemu (SUSE-SU-2026:2406-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.1.1-84.1` or later.
SUSE-SU-2026:2405-1 Vulnerability in openssl-1_1 (SUSE-SU-2026:2405-1)
vulnerability in openssl-1_1 (SUSE-SU-2026:2405-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.1l-150500.17.57.2` or later.
SUSE-SU-2026:2404-1 Vulnerability in openssl-1_1 (SUSE-SU-2026:2404-1)
vulnerability in openssl-1_1 (SUSE-SU-2026:2404-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.1w-150600.5.32.1` or later.
SUSE-SU-2026:2403-1 Vulnerability in openssl-1_1 (SUSE-SU-2026:2403-1)
vulnerability in openssl-1_1 (SUSE-SU-2026:2403-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.1.1d-2.131.1` or later.
openSUSE-SU-2026:20980-1 Vulnerability in chromium (openSUSE-SU-2026:20980-1)
vulnerability in chromium (openSUSE-SU-2026:20980-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `149.0.7827.114-bp160.1.1` or later.
CVE-2026-6933 Unrestricted File Upload in wordpress (CVE-2026-6933)
vulnerability in wordpress (CVE-2026-6933). Successful exploitation can lead to full system takeover.
CVE-2026-9187 Vulnerability in wordpress (CVE-2026-9187)
vulnerability in wordpress (CVE-2026-9187). Risk of unauthorized operations or information disclosure.
CVE-2026-10780 Vulnerability in wordpress (CVE-2026-10780)
vulnerability in wordpress (CVE-2026-10780). Risk of unauthorized operations or information disclosure.
CVE-2026-5149 Authorization Flaw in wordpress (CVE-2026-5149)
vulnerability in wordpress (CVE-2026-5149). Confidential information can be exposed externally.
CVE-2026-50255 Vulnerability in CVE-2026-50255 (CVE-2026-50255)
vulnerability in CVE-2026-50255 (CVE-2026-50255). Successful exploitation can lead to full system takeover.
CVE-2026-8443 SQL Injection in wordpress (CVE-2026-8443)
SQL injection in wordpress (CVE-2026-8443). Successful exploitation can lead to full system takeover.
CVE-2025-10262 Vulnerability in privilege-escalation (CVE-2025-10262)
vulnerability in privilege-escalation (CVE-2025-10262). Data can be tampered with by attackers.
CVE-2026-10635 Use-After-Free in c (CVE-2026-10635)
vulnerability in c (CVE-2026-10635). Data can be tampered with by attackers.
BELL-CVE-2026-41579 BELL-CVE-2026-41579
GHSA-gqhv-66pr-h35f Vulnerability in lucide-next (GHSA-gqhv-66pr-h35f)
vulnerability in lucide-next (GHSA-gqhv-66pr-h35f). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →