Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-2902 |
|
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.
...
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.
...
|
| CVE-2026-10083 |
|
Vulnerability in wordpress (CVE-2026-10083)
vulnerability in wordpress (CVE-2026-10083). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13528 |
|
Path Traversal in vue (CVE-2026-13528)
path traversal in vue (CVE-2026-13528). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13527 |
|
Vulnerability in sqli (CVE-2026-13527)
vulnerability in sqli (CVE-2026-13527). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13526 |
|
Vulnerability in sqli (CVE-2026-13526)
vulnerability in sqli (CVE-2026-13526). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13519 |
|
A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function...
A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function...
|
| CVE-2026-13521 |
|
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php....
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php....
|
| CVE-2026-13518 |
|
A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function...
A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function...
|
| CVE-2026-13517 |
|
A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function...
A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function...
|
| CVE-2026-13515 |
|
Buffer Overflow in CVE-2026-13515 (CVE-2026-13515)
vulnerability in CVE-2026-13515 (CVE-2026-13515). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13516 |
|
Buffer Overflow in CVE-2026-13516 (CVE-2026-13516)
vulnerability in CVE-2026-13516 (CVE-2026-13516). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13500 |
|
Vulnerability in CVE-2026-13500 (CVE-2026-13500)
vulnerability in CVE-2026-13500 (CVE-2026-13500). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13498 |
|
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an...
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an...
|
| CVE-2026-13487 |
|
Vulnerability in sqli (CVE-2026-13487)
vulnerability in sqli (CVE-2026-13487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13488 |
|
Vulnerability in sqli (CVE-2026-13488)
vulnerability in sqli (CVE-2026-13488). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13486 |
|
Vulnerability in sqli (CVE-2026-13486)
vulnerability in sqli (CVE-2026-13486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13485 |
|
Vulnerability in sqli (CVE-2026-13485)
vulnerability in sqli (CVE-2026-13485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10646 |
|
Use-After-Free in c (CVE-2026-10646)
vulnerability in c (CVE-2026-10646). Data can be tampered with by attackers.
|
| CVE-2026-58050 |
|
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey...
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey...
|
| CVE-2026-58054 |
|
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
|
| CVE-2026-58056 |
|
RustDesk gates incoming control messages on per-capability flags rather than on the session's...
RustDesk gates incoming control messages on per-capability flags rather than on the session's...
|
| CVE-2026-58049 |
|
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes...
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes...
|
| CVE-2026-8095 |
|
Vulnerability in wordpress (CVE-2026-8095)
vulnerability in wordpress (CVE-2026-8095). Data can be tampered with by attackers.
|
| CVE-2026-10643 |
|
Out-of-Bounds Write in c (CVE-2026-10643)
out-of-bounds write in c (CVE-2026-10643). Data can be tampered with by attackers.
|
| CVE-2026-49416 |
|
Vulnerability in freebsd (CVE-2026-49416)
vulnerability in freebsd (CVE-2026-49416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49414 |
|
Vulnerability in freebsd (CVE-2026-49414)
vulnerability in freebsd (CVE-2026-49414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49417 |
|
Use-After-Free in dos (CVE-2026-49417)
vulnerability in dos (CVE-2026-49417). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49413 |
|
Vulnerability in freebsd (CVE-2026-49413)
vulnerability in freebsd (CVE-2026-49413). Data can be tampered with by attackers.
|
| CVE-2026-49412 |
|
Use-After-Free in freebsd (CVE-2026-49412)
vulnerability in freebsd (CVE-2026-49412). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45258 |
|
Out-of-Bounds Read in dos (CVE-2026-45258)
vulnerability in dos (CVE-2026-45258). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10820 |
|
Vulnerability in wordpress (CVE-2026-10820)
vulnerability in wordpress (CVE-2026-10820). Data can be tampered with by attackers.
|
| CVE-2023-37524 |
|
Vulnerability in csharp (CVE-2023-37524)
vulnerability in csharp (CVE-2023-37524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56414 |
|
Unrestricted File Upload in CVE-2026-56414 (CVE-2026-56414)
vulnerability in CVE-2026-56414 (CVE-2026-56414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33560 |
|
Unrestricted File Upload in daktronics (CVE-2026-33560)
vulnerability in daktronics (CVE-2026-33560). Data can be tampered with by attackers.
|
| CVE-2026-31928 |
|
Vulnerability in daktronics (CVE-2026-31928)
vulnerability in daktronics (CVE-2026-31928). Confidential information can be exposed externally.
|
| CVE-2026-36478 |
|
Vulnerability in csharp (CVE-2026-36478)
vulnerability in csharp (CVE-2026-36478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55700 |
|
Path Traversal in pnpm (CVE-2026-55700)
path traversal in pnpm (CVE-2026-55700). Data can be tampered with by attackers. Exploitable via ``main``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-55698 |
|
Vulnerability in pnpm (CVE-2026-55698)
vulnerability in pnpm (CVE-2026-55698). Successful exploitation can lead to full system takeover. Exploitable via ``a93449314f398cf4bdf2e28d033c02d37395ad22``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-55697 |
|
OS Command Injection in pnpm (CVE-2026-55697)
OS command injection in pnpm (CVE-2026-55697). Successful exploitation can lead to full system takeover. Exploitable via ``a93449314f398cf4bdf2e28d033c02d37395ad22``. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-55487 |
|
Vulnerability in pnpm (CVE-2026-55487)
vulnerability in pnpm (CVE-2026-55487). Successful exploitation can lead to full system takeover. Exploitable via ``bf1b731ee6``. Mitigation: upgrade to `10.34.2` or later.
|
| CVE-2026-50015 |
|
Path Traversal in pnpm (CVE-2026-50015)
path traversal in pnpm (CVE-2026-50015). Data can be tampered with by attackers. Exploitable via ``patchedDependencies``. Mitigation: upgrade to `11.4.0` or later.
|
| CVE-2026-50016 |
|
Vulnerability in pnpm (CVE-2026-50016)
vulnerability in pnpm (CVE-2026-50016). Successful exploitation can lead to full system takeover. Exploitable via ``node_modules``. Mitigation: upgrade to `11.4.0` or later.
|
| CVE-2026-55069 |
|
Vulnerability in privilege-escalation (CVE-2026-55069)
vulnerability in privilege-escalation (CVE-2026-55069). Confidential information can be exposed externally. Mitigation: upgrade to `1.3.24` or later.
|
| CVE-2026-49984 |
|
Path Traversal in kestra (CVE-2026-49984)
path traversal in kestra (CVE-2026-49984). Confidential information can be exposed externally. Exploitable via `GET /api/v1/{tenant}/executions/{executionId}/file`. Mitigation: upgrade to `1.0.45` or later.
|
| CVE-2026-45807 |
|
Path Traversal in kestra (CVE-2026-45807)
path traversal in kestra (CVE-2026-45807). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.43` or later.
|
| CVE-2026-48995 |
|
Vulnerability in pnpm (CVE-2026-48995)
vulnerability in pnpm (CVE-2026-48995). Successful exploitation can lead to full system takeover. Exploitable via ``codeload.github.com``. Mitigation: upgrade to `11.0.7` or later.
|
| CVE-2026-38639 |
|
Vulnerability in dos (CVE-2026-38639)
vulnerability in dos (CVE-2026-38639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38641 |
|
Vulnerability in dos (CVE-2026-38641)
vulnerability in dos (CVE-2026-38641). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53322 |
|
Vulnerability in linux (CVE-2026-53322)
vulnerability in linux (CVE-2026-53322). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53294 |
|
Vulnerability in linux (CVE-2026-53294)
vulnerability in linux (CVE-2026-53294). Successful exploitation can lead to full system takeover.
|