Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2019-25738 |
|
Vulnerability in wordpress (CVE-2019-25738)
vulnerability in wordpress (CVE-2019-25738). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25739 |
|
Cross-Site Scripting (XSS) in CVE-2019-25739 (CVE-2019-25739)
cross-site scripting in CVE-2019-25739 (CVE-2019-25739). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25737 |
|
Cross-Site Scripting (XSS) in CVE-2019-25737 (CVE-2019-25737)
cross-site scripting in CVE-2019-25737 (CVE-2019-25737). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25736 |
|
Vulnerability in CVE-2019-25736 (CVE-2019-25736)
vulnerability in CVE-2019-25736 (CVE-2019-25736). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25735 |
|
Vulnerability in CVE-2019-25735 (CVE-2019-25735)
vulnerability in CVE-2019-25735 (CVE-2019-25735). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25741 |
|
Vulnerability in CVE-2019-25741 (CVE-2019-25741)
vulnerability in CVE-2019-25741 (CVE-2019-25741). Successful exploitation can lead to full system takeover.
|
| CVE-2025-46638 |
|
Vulnerability in dos (CVE-2025-46638)
vulnerability in dos (CVE-2025-46638). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25745 |
|
SQL Injection in wordpress (CVE-2019-25745)
SQL injection in wordpress (CVE-2019-25745). Confidential information can be exposed externally.
|
| CVE-2025-62338 |
|
Vulnerability in CVE-2025-62338 (CVE-2025-62338)
vulnerability in CVE-2025-62338 (CVE-2025-62338). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25733 |
|
Vulnerability in CVE-2019-25733 (CVE-2019-25733)
vulnerability in CVE-2019-25733 (CVE-2019-25733). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25744 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25744)
cross-site scripting in wordpress (CVE-2019-25744). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25742 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25742)
cross-site scripting in wordpress (CVE-2019-25742). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25740 |
|
Path Traversal in path-traversal (CVE-2019-25740)
path traversal in path-traversal (CVE-2019-25740). Confidential information can be exposed externally.
|
| CVE-2019-25734 |
|
Path Traversal in csrf (CVE-2019-25734)
path traversal in csrf (CVE-2019-25734). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25732 |
|
SQL Injection in sqli (CVE-2019-25732)
SQL injection in sqli (CVE-2019-25732). Confidential information can be exposed externally.
|
| CVE-2019-25731 |
|
Cross-Site Scripting (XSS) in CVE-2019-25731 (CVE-2019-25731)
cross-site scripting in CVE-2019-25731 (CVE-2019-25731). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25730 |
|
SQL Injection in sqli (CVE-2019-25730)
SQL injection in sqli (CVE-2019-25730). Confidential information can be exposed externally.
|
| CVE-2019-25726 |
|
SQL Injection in sqli (CVE-2019-25726)
SQL injection in sqli (CVE-2019-25726). Confidential information can be exposed externally.
|
| CVE-2019-25727 |
|
Path Traversal in wordpress (CVE-2019-25727)
path traversal in wordpress (CVE-2019-25727). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25728 |
|
SQL Injection in sqli (CVE-2019-25728)
SQL injection in sqli (CVE-2019-25728). Confidential information can be exposed externally.
|
| CVE-2019-25729 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2019-25729)
vulnerability in csrf (CVE-2019-25729). Successful exploitation can lead to full system takeover.
|
| ROOT-APP-NPM-CVE-2026-23897 |
|
Vulnerability in @rootio/apollo__server (ROOT-APP-NPM-CVE-2026-23897)
vulnerability in @rootio/apollo__server (ROOT-APP-NPM-CVE-2026-23897). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.0-root.io.1, 5.0.0-root.io.2, 5.0.0-root.io.3, 5.0.0-root.io.4, 5.0.0-root.io.5, 5.0.0-root.io.6` or later.
|
| CVE-2026-41065 |
|
Vulnerability in CVE-2026-41065 (CVE-2026-41065)
vulnerability in CVE-2026-41065 (CVE-2026-41065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45730 |
|
Vulnerability in github.com/nuclio/nuclio (CVE-2026-45730)
vulnerability in github.com/nuclio/nuclio (CVE-2026-45730). Data can be tampered with by attackers. Exploitable via `PUT /api/projects/{id}`. Mitigation: upgrade to `0.0.0-20260513101907-1915cd26d514` or later.
|
| CVE-2026-45337 |
|
Vulnerability in better-auth (CVE-2026-45337)
vulnerability in better-auth (CVE-2026-45337). Confidential information can be exposed externally. Exploitable via `POST /device/approve`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-45057 |
|
Vulnerability in matrix-sdk-ui (CVE-2026-45057)
vulnerability in matrix-sdk-ui (CVE-2026-45057). Data can be tampered with by attackers. Mitigation: upgrade to `0.16.1` or later.
|
| CVE-2026-45056 |
|
Vulnerability in matrix-sdk-crypto (CVE-2026-45056)
vulnerability in matrix-sdk-crypto (CVE-2026-45056). Risk of unauthorized operations or information disclosure. Exploitable via ``sender_device_keys``. Mitigation: upgrade to `0.16.1` or later.
|
| CVE-2026-47707 |
|
Vulnerability in strawberry-graphql (CVE-2026-47707)
vulnerability in strawberry-graphql (CVE-2026-47707). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.315.7` or later.
|
| CVE-2026-47706 |
|
Vulnerability in strawberry-graphql (CVE-2026-47706)
vulnerability in strawberry-graphql (CVE-2026-47706). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.315.7` or later.
|
| CVE-2026-44476 |
|
Authentication Bypass in doorkeeper-openid_connect (CVE-2026-44476)
authentication bypass in doorkeeper-openid_connect (CVE-2026-44476). Risk of unauthorized operations or information disclosure. Exploitable via `POST /oauth/registration`. Mitigation: upgrade to `1.10.0` or later.
|
| CVE-2026-44889 |
|
Open Redirect in webob (CVE-2026-44889)
vulnerability in webob (CVE-2026-44889). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.10` or later.
|
| CVE-2026-44496 |
|
Vulnerability in axios (CVE-2026-44496)
vulnerability in axios (CVE-2026-44496). Risk of unauthorized operations or information disclosure. Exploitable via ``document.cookie``. Mitigation: upgrade to `0.32.0` or later.
|
| CGA-2r69-w36g-jxvr |
|
CGA-2r69-w36g-jxvr |
| CGA-5f7q-7pmq-hq3r |
|
CGA-5f7q-7pmq-hq3r |
| CVE-2026-44488 |
|
Vulnerability in axios (CVE-2026-44488)
vulnerability in axios (CVE-2026-44488). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-44487 |
|
Vulnerability in axios (CVE-2026-44487)
vulnerability in axios (CVE-2026-44487). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-43926 |
|
Vulnerability in nginx (CVE-2026-43926)
vulnerability in nginx (CVE-2026-43926). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40605 |
|
Path Traversal in path-traversal (CVE-2026-40605)
path traversal in path-traversal (CVE-2026-40605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44486 |
|
Information Disclosure in axios (CVE-2026-44486)
vulnerability in axios (CVE-2026-44486). Confidential information can be exposed externally. Exploitable via `GET /start`. Mitigation: upgrade to `0.32.0` or later.
|
| USN-8385-1 |
|
Vulnerability in robocode (USN-8385-1)
vulnerability in robocode (USN-8385-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.9.2.5-2ubuntu0.1~esm1` or later.
|
| CGA-mc77-fm5f-6828 |
|
CGA-mc77-fm5f-6828 |
| CGA-rc4r-hg5c-48f9 |
|
CGA-rc4r-hg5c-48f9 |
| CGA-38vc-7rxf-2wpq |
|
CGA-38vc-7rxf-2wpq |
| CGA-p9vx-xgpv-vg88 |
|
CGA-p9vx-xgpv-vg88 |
| CGA-xw53-27gv-q7gg |
|
CGA-xw53-27gv-q7gg |
| ROOT-APP-NPM-CVE-2025-25288 |
|
Vulnerability in @rootio/octokit__plugin-paginate-rest (ROOT-APP-NPM-CVE-2025-25288)
vulnerability in @rootio/octokit__plugin-paginate-rest (ROOT-APP-NPM-CVE-2025-25288). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.2-root.io.1, 6.1.2-root.io.2` or later.
|
| ROOT-APP-NPM-CVE-2025-25289 |
|
Vulnerability in @rootio/octokit__request-error (ROOT-APP-NPM-CVE-2025-25289)
vulnerability in @rootio/octokit__request-error (ROOT-APP-NPM-CVE-2025-25289). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.3-root.io.1, 3.0.3-root.io.2` or later.
|
| ROOT-APP-NPM-CVE-2026-26019 |
|
Vulnerability in @rootio/langchain__community (ROOT-APP-NPM-CVE-2026-26019)
vulnerability in @rootio/langchain__community (ROOT-APP-NPM-CVE-2026-26019). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.3.45-root.io.2, 0.3.45-root.io.3, 0.3.45-root.io.4, 0.3.45-root.io.5` or later.
|
| ROOT-APP-NPM-CVE-2026-27795 |
|
Vulnerability in @rootio/langchain__community (ROOT-APP-NPM-CVE-2026-27795)
vulnerability in @rootio/langchain__community (ROOT-APP-NPM-CVE-2026-27795). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.3.45-root.io.1, 0.3.45-root.io.2, 0.3.45-root.io.3, 0.3.45-root.io.4, 0.3.45-root.io.5, 1.1.14-root.io.1` or later.
|
| ROOT-APP-NPM-CVE-2026-32236 |
|
Vulnerability in @rootio/backstage__plugin-auth-backend (ROOT-APP-NPM-CVE-2026-32236)
vulnerability in @rootio/backstage__plugin-auth-backend (ROOT-APP-NPM-CVE-2026-32236). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.25.7-root.io.1, 0.25.7-root.io.2` or later.
|