Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13084 |
|
Vulnerability in dos (CVE-2026-13084)
vulnerability in dos (CVE-2026-13084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13079 |
|
Vulnerability in privilege-escalation (CVE-2026-13079)
vulnerability in privilege-escalation (CVE-2026-13079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13054 |
|
Path Traversal in path-traversal (CVE-2026-13054)
path traversal in path-traversal (CVE-2026-13054). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13053 |
|
Out-of-Bounds Write in watchguard (CVE-2026-13053)
out-of-bounds write in watchguard (CVE-2026-13053). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54998 |
|
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
|
| CVE-2026-50722 |
|
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
|
| CVE-2026-50721 |
|
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
|
| CVE-2026-12413 |
|
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart....
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart....
|
| CVE-2026-38972 |
|
Vulnerability in c (CVE-2026-38972)
vulnerability in c (CVE-2026-38972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52191 |
|
Vulnerability in dos (CVE-2026-52191)
vulnerability in dos (CVE-2026-52191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38970 |
|
Vulnerability in CVE-2026-38970 (CVE-2026-38970)
vulnerability in CVE-2026-38970 (CVE-2026-38970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58460 |
|
Path Traversal in react (CVE-2026-58460)
path traversal in react (CVE-2026-58460). Data can be tampered with by attackers.
|
| CVE-2026-52189 |
|
Vulnerability in dos (CVE-2026-52189)
vulnerability in dos (CVE-2026-52189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52192 |
|
Vulnerability in dos (CVE-2026-52192)
vulnerability in dos (CVE-2026-52192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38969 |
|
Vulnerability in CVE-2026-38969 (CVE-2026-38969)
vulnerability in CVE-2026-38969 (CVE-2026-38969). Data can be tampered with by attackers.
|
| CVE-2026-59096 |
|
Vulnerability in CVE-2026-59096 (CVE-2026-59096)
vulnerability in CVE-2026-59096 (CVE-2026-59096). Data can be tampered with by attackers. Exploitable via `Host header`.
|
| CVE-2026-59095 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59095)
SSRF in ssrf (CVE-2026-59095). Confidential information can be exposed externally.
|
| CVE-2026-59094 |
|
Vulnerability in CVE-2026-59094 (CVE-2026-59094)
vulnerability in CVE-2026-59094 (CVE-2026-59094). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59092 |
|
Vulnerability in dos (CVE-2026-59092)
vulnerability in dos (CVE-2026-59092). Confidential information can be exposed externally.
|
| CVE-2026-59093 |
|
Vulnerability in weaviate (CVE-2026-59093)
vulnerability in weaviate (CVE-2026-59093). Successful exploitation can lead to full system takeover. Exploitable via `POST /authz/users/{id}/assign`.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2026-52187 |
|
Vulnerability in dos (CVE-2026-52187)
vulnerability in dos (CVE-2026-52187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49353 |
|
Vulnerability in 9router (CVE-2026-49353)
vulnerability in 9router (CVE-2026-49353). Data can be tampered with by attackers. Exploitable via `GET /api/mcp/`.
|
| CVE-2026-49284 |
|
Vulnerability in simplesamlphp/simplesamlphp (CVE-2026-49284)
vulnerability in simplesamlphp/simplesamlphp (CVE-2026-49284). Data can be tampered with by attackers. Exploitable via ``SubjectConfirmationData``. Mitigation: upgrade to `2.4.7` or later.
|
| CVE-2026-49289 |
|
Vulnerability in simplesamlphp/saml2 (CVE-2026-49289)
vulnerability in simplesamlphp/saml2 (CVE-2026-49289). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.19.3` or later.
|
| CVE-2026-52829 |
|
Vulnerability in zebra-network (CVE-2026-52829)
vulnerability in zebra-network (CVE-2026-52829). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-49283 |
|
Vulnerability in simplesamlphp/saml2 (CVE-2026-49283)
vulnerability in simplesamlphp/saml2 (CVE-2026-49283). Confidential information can be exposed externally. Exploitable via ``Response``. Mitigation: upgrade to `4.19.3` or later.
|
| CVE-2026-52746 |
|
Vulnerability in jsonata (CVE-2026-52746)
vulnerability in jsonata (CVE-2026-52746). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.9` or later.
|
| CVE-2026-49255 |
|
OS Command Injection in electerm (CVE-2026-49255)
OS command injection in electerm (CVE-2026-49255). Successful exploitation can lead to full system takeover. Exploitable via ``rmrf``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-49253 |
|
Path Traversal in electerm (CVE-2026-49253)
path traversal in electerm (CVE-2026-49253). Data can be tampered with by attackers. Exploitable via ``savedFilePaths``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|
| CVE-2026-58465 |
|
Vulnerability in c (CVE-2026-58465)
vulnerability in c (CVE-2026-58465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44454 |
|
OS Command Injection in github.com/coder/coder/v2 (CVE-2026-44454)
OS command injection in github.com/coder/coder/v2 (CVE-2026-44454). Confidential information can be exposed externally. Exploitable via ``dotfiles``. Mitigation: upgrade to `2.30.2` or later.
|
| CVE-2026-52854 |
|
Cross-Site Scripting (XSS) in mediawiki/maps (CVE-2026-52854)
cross-site scripting in mediawiki/maps (CVE-2026-52854). Confidential information can be exposed externally. Exploitable via ``overlays``. Mitigation: upgrade to `12.1.3` or later.
|
| CVE-2026-50181 |
|
Path Traversal in langroid (CVE-2026-50181)
path traversal in langroid (CVE-2026-50181). Confidential information can be exposed externally. Exploitable via ``ReadFileTool``. Mitigation: upgrade to `0.64.0` or later.
|
| CVE-2026-55952 |
|
Vulnerability in erlang (CVE-2026-55952)
vulnerability in erlang (CVE-2026-55952). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58352 |
|
Vulnerability in CVE-2024-58352 (CVE-2024-58352)
vulnerability in CVE-2024-58352 (CVE-2024-58352). Confidential information can be exposed externally.
|
| CVE-2026-44941 |
|
Vulnerability in path-traversal (CVE-2026-44941)
vulnerability in path-traversal (CVE-2026-44941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55119 |
|
Vulnerability in ui (CVE-2026-55119)
vulnerability in ui (CVE-2026-55119). Confidential information can be exposed externally.
|
| CVE-2026-55118 |
|
Vulnerability in ui (CVE-2026-55118)
vulnerability in ui (CVE-2026-55118). Data can be tampered with by attackers.
|
| CVE-2026-55117 |
|
Path Traversal in path-traversal (CVE-2026-55117)
path traversal in path-traversal (CVE-2026-55117). Confidential information can be exposed externally.
|
| CVE-2026-56841 |
|
SQL Injection in sqli (CVE-2026-56841)
SQL injection in sqli (CVE-2026-56841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56842 |
|
Authorization Flaw in ui (CVE-2026-56842)
vulnerability in ui (CVE-2026-56842). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9272 |
|
SQL Injection in progress (CVE-2026-9272)
SQL injection in progress (CVE-2026-9272). Confidential information can be exposed externally.
|
| CVE-2026-8079 |
|
Authorization Flaw in progress (CVE-2026-8079)
vulnerability in progress (CVE-2026-8079). Confidential information can be exposed externally.
|
| CVE-2026-55110 |
|
Vulnerability in ui (CVE-2026-55110)
vulnerability in ui (CVE-2026-55110). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54409 |
|
Vulnerability in ui (CVE-2026-54409)
vulnerability in ui (CVE-2026-54409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54408 |
|
Vulnerability in ui (CVE-2026-54408)
vulnerability in ui (CVE-2026-54408). Confidential information can be exposed externally.
|
| CVE-2026-55111 |
|
Path Traversal in path-traversal (CVE-2026-55111)
path traversal in path-traversal (CVE-2026-55111). Confidential information can be exposed externally.
|
| CVE-2026-55112 |
|
Vulnerability in ui (CVE-2026-55112)
vulnerability in ui (CVE-2026-55112). Successful exploitation can lead to full system takeover.
|