Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48900 |
|
Vulnerability in joomla (CVE-2026-48900)
vulnerability in joomla (CVE-2026-48900). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-48899 |
|
Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
Joomla! Core - [20260515] - Incorrect Access Control in sample data plugins
|
| CVE-2026-48898 |
|
Joomla! Core - [20260513] - Privilege escalation through com_users batch task
Joomla! Core - [20260513] - Privilege escalation through com_users batch task
|
| CVE-2026-48897 |
|
Joomla! Core - [20260512] - MFA Authentication Bypass
Joomla! Core - [20260512] - MFA Authentication Bypass
|
| CVE-2026-48896 |
|
Joomla! Core - [20260511] - MFA Authentication Bypass
Joomla! Core - [20260511] - MFA Authentication Bypass
|
| CVE-2026-48864 |
|
Out-of-Bounds Write in dos (CVE-2026-48864)
out-of-bounds write in dos (CVE-2026-48864). Successful exploitation can lead to full system takeover.
|
| DEBIAN-CVE-2026-48690 |
|
Vulnerability in fastnetmon (DEBIAN-CVE-2026-48690)
vulnerability in fastnetmon (DEBIAN-CVE-2026-48690). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.9-1` or later.
|
| DEBIAN-CVE-2026-48693 |
|
Vulnerability in fastnetmon (DEBIAN-CVE-2026-48693)
vulnerability in fastnetmon (DEBIAN-CVE-2026-48693). Data can be tampered with by attackers.
|
| DEBIAN-CVE-2026-48691 |
|
Vulnerability in fastnetmon (DEBIAN-CVE-2026-48691)
vulnerability in fastnetmon (DEBIAN-CVE-2026-48691). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.2.9-1` or later.
|
| DEBIAN-CVE-2026-48697 |
|
Vulnerability in fastnetmon (DEBIAN-CVE-2026-48697)
vulnerability in fastnetmon (DEBIAN-CVE-2026-48697). Confidential information can be exposed externally.
|
| CVE-2026-48697 |
|
Vulnerability in cpp (CVE-2026-48697)
vulnerability in cpp (CVE-2026-48697). Confidential information can be exposed externally.
|
| CVE-2026-48693 |
|
Vulnerability in cpp (CVE-2026-48693)
vulnerability in cpp (CVE-2026-48693). Data can be tampered with by attackers.
|
| CVE-2026-48691 |
|
Vulnerability in pavel-odintsov (CVE-2026-48691)
vulnerability in pavel-odintsov (CVE-2026-48691). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48690 |
|
Vulnerability in pavel-odintsov (CVE-2026-48690)
vulnerability in pavel-odintsov (CVE-2026-48690). Confidential information can be exposed externally.
|
| CVE-2026-48126 |
|
Path Traversal in github.com/xyproto/algernon (CVE-2026-48126)
path traversal in github.com/xyproto/algernon (CVE-2026-48126). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `1.17.8` or later.
|
| CVE-2026-48091 |
|
Rejected reason: Further research determined the issue is not a vulnerability.
Rejected reason: Further research determined the issue is not a vulnerability.
|
| CVE-2026-47728 |
|
Vulnerability in bugsink (CVE-2026-47728)
vulnerability in bugsink (CVE-2026-47728). Risk of unauthorized operations or information disclosure. Exploitable via ``FEATURE_MINIDUMPS``. Mitigation: upgrade to `2.2.0` or later.
|
| CVE-2026-47716 |
|
Vulnerability in bugsink (CVE-2026-47716)
vulnerability in bugsink (CVE-2026-47716). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.2.0` or later.
|
| CVE-2026-47715 |
|
Vulnerability in bugsink (CVE-2026-47715)
vulnerability in bugsink (CVE-2026-47715). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.2.0` or later.
|
| DEBIAN-CVE-2026-45836 |
|
Vulnerability in linux (DEBIAN-CVE-2026-45836)
vulnerability in linux (DEBIAN-CVE-2026-45836). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.90-1` or later.
|
| CVE-2026-45836 |
|
Vulnerability in linux (CVE-2026-45836)
vulnerability in linux (CVE-2026-45836). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-45834 |
|
Vulnerability in linux (DEBIAN-CVE-2026-45834)
vulnerability in linux (DEBIAN-CVE-2026-45834). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.88-1` or later.
|
| DEBIAN-CVE-2026-45835 |
|
Vulnerability in linux (DEBIAN-CVE-2026-45835)
vulnerability in linux (DEBIAN-CVE-2026-45835). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.88-1` or later.
|
| CVE-2026-45835 |
|
Vulnerability in linux (CVE-2026-45835)
vulnerability in linux (CVE-2026-45835). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45834 |
|
Vulnerability in linux (CVE-2026-45834)
vulnerability in linux (CVE-2026-45834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44729 |
|
Cross-Site Scripting (XSS) in twenty (CVE-2026-44729)
cross-site scripting in twenty (CVE-2026-44729). Confidential information can be exposed externally.
|
| CVE-2026-44723 |
|
OS Command Injection in vowpalwabbit (CVE-2026-44723)
OS command injection in vowpalwabbit (CVE-2026-44723). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44314 |
|
Authorization Flaw in traccar (CVE-2026-44314)
vulnerability in traccar (CVE-2026-44314). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.13.0` or later.
|
| CVE-2026-43982 |
|
Path Traversal in CVE-2026-43982 (CVE-2026-43982)
path traversal in CVE-2026-43982 (CVE-2026-43982). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.17.6` or later.
|
| CVE-2026-43981 |
|
Vulnerability in c (CVE-2026-43981)
vulnerability in c (CVE-2026-43981). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.17.6` or later.
|
| CVE-2026-40384 |
|
Path Traversal in joomla (CVE-2026-40384)
path traversal in joomla (CVE-2026-40384). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-40383 |
|
Joomla! Core - [20260509] - LFI in HTMLView layout parameter
Joomla! Core - [20260509] - LFI in HTMLView layout parameter
|
| CVE-2026-35223 |
|
Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
|
| CVE-2026-35222 |
|
Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
|
| CVE-2026-35221 |
|
SQL Injection in joomla (CVE-2026-35221)
SQL injection in joomla (CVE-2026-35221). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-35220 |
|
Cross-Site Request Forgery (CSRF) in joomla (CVE-2026-35220)
vulnerability in joomla (CVE-2026-35220). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.1` or later.
|
| CVE-2026-30895 |
|
Joomla! Core - [20260504] - XSS in readmore links
Joomla! Core - [20260504] - XSS in readmore links
|
| CVE-2026-30894 |
|
Joomla! Core - [20260503] - XSS in com_contenthistory
Joomla! Core - [20260503] - XSS in com_contenthistory
|
| CVE-2026-2264 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-2264)
SSRF in ssrf (CVE-2026-2264). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25901 |
|
Joomla! Core - [20260502] - XSS in com_associations
Joomla! Core - [20260502] - XSS in com_associations
|
| CVE-2026-25900 |
|
Joomla! Core - [20260501] - XSS in feed modules
Joomla! Core - [20260501] - XSS in feed modules
|
| CVE-2026-24212 |
|
Vulnerability in nvidia (CVE-2026-24212)
vulnerability in nvidia (CVE-2026-24212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24162 |
|
Unsafe Deserialization in deserialization (CVE-2026-24162)
vulnerability in deserialization (CVE-2026-24162). Successful exploitation can lead to full system takeover.
|
| CVE-2025-36221 |
|
Vulnerability in ibm (CVE-2025-36221)
vulnerability in ibm (CVE-2025-36221). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-36220 |
|
SQL Injection in sqli (CVE-2025-36220)
SQL injection in sqli (CVE-2025-36220). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-36148 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2025-36148)
cross-site scripting in ibm (CVE-2025-36148). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-36145 |
|
Vulnerability in ibm (CVE-2025-36145)
vulnerability in ibm (CVE-2025-36145). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-36126 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2025-36126)
cross-site scripting in ibm (CVE-2025-36126). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-14290 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-14290)
SSRF in ssrf (CVE-2025-14290). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13755 |
|
Vulnerability in ibm (CVE-2025-13755)
vulnerability in ibm (CVE-2025-13755). Confidential information can be exposed externally.
|