Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-54280 |
|
Vulnerability in aiohttp (CVE-2026-54280)
vulnerability in aiohttp (CVE-2026-54280). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2026-54273 |
|
Vulnerability in aiohttp (CVE-2026-54273)
vulnerability in aiohttp (CVE-2026-54273). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2026-54278 |
|
Vulnerability in aiohttp (CVE-2026-54278)
vulnerability in aiohttp (CVE-2026-54278). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2026-54277 |
|
Vulnerability in aiohttp (CVE-2026-54277)
vulnerability in aiohttp (CVE-2026-54277). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2026-54279 |
|
Vulnerability in aiohttp (CVE-2026-54279)
vulnerability in aiohttp (CVE-2026-54279). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2026-50269 |
|
Vulnerability in aiohttp (CVE-2026-50269)
vulnerability in aiohttp (CVE-2026-50269). Risk of unauthorized operations or information disclosure. Exploitable via ``Payload.headers``. Mitigation: upgrade to `3.14.0` or later.
|
| CVE-2026-8357 |
|
Vulnerability in CVE-2026-8357 (CVE-2026-8357)
vulnerability in CVE-2026-8357 (CVE-2026-8357). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6040 |
|
Use-After-Free in CVE-2026-6040 (CVE-2026-6040)
vulnerability in CVE-2026-6040 (CVE-2026-6040). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47777 |
|
Vulnerability in mastodon (CVE-2026-47777)
vulnerability in mastodon (CVE-2026-47777). Data can be tampered with by attackers. Mitigation: upgrade to `4.6.0` or later.
|
| CVE-2026-48736 |
|
Vulnerability in symfony/http-client (CVE-2026-48736)
vulnerability in symfony/http-client (CVE-2026-48736). Confidential information can be exposed externally. Exploitable via ``NoPrivateNetworkHttpClient``. Mitigation: upgrade to `5.4.53` or later.
|
| CVE-2026-48712 |
|
Vulnerability in protobufjs (CVE-2026-48712)
vulnerability in protobufjs (CVE-2026-48712). Risk of unauthorized operations or information disclosure. Exploitable via ``google.protobuf.Any``. Mitigation: upgrade to `8.4.1` or later.
|
| CVE-2026-48489 |
|
Authorization Flaw in symfony/security-http (CVE-2026-48489)
vulnerability in symfony/security-http (CVE-2026-48489). Confidential information can be exposed externally. Exploitable via ``DefaultAuthenticationFailureHandler``. Mitigation: upgrade to `8.0.13` or later.
|
| CVE-2026-54268 |
|
Vulnerability in @angular/common (CVE-2026-54268)
vulnerability in @angular/common (CVE-2026-54268). Risk of unauthorized operations or information disclosure. Exploitable via ``formatDate``.
|
| CVE-2026-53571 |
|
Path Traversal in vite (CVE-2026-53571)
path traversal in vite (CVE-2026-53571). Confidential information can be exposed externally. Exploitable via ``server.fs.deny``. Mitigation: upgrade to `6.4.3` or later.
|
| CVE-2026-50170 |
|
Vulnerability in @angular/common (CVE-2026-50170)
vulnerability in @angular/common (CVE-2026-50170). Confidential information can be exposed externally. Exploitable via ``HttpTransferCache``. Mitigation: upgrade to `21.2.15` or later.
|
| CVE-2026-50168 |
|
Vulnerability in @angular/platform-server (CVE-2026-50168)
vulnerability in @angular/platform-server (CVE-2026-50168). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `21.2.15` or later.
|
| CVE-2026-48779 |
|
Vulnerability in ws (CVE-2026-48779)
vulnerability in ws (CVE-2026-48779). Risk of unauthorized operations or information disclosure. Exploitable via ``maxPayload``. Mitigation: upgrade to `8.21.0` or later.
|
| CVE-2026-9863 |
|
OS Command Injection in forta (CVE-2026-9863)
OS command injection in forta (CVE-2026-9863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5230 |
|
Vulnerability in CVE-2026-5230 (CVE-2026-5230)
vulnerability in CVE-2026-5230 (CVE-2026-5230). Confidential information can be exposed externally.
|
| CVE-2026-5233 |
|
Vulnerability in CVE-2026-5233 (CVE-2026-5233)
vulnerability in CVE-2026-5233 (CVE-2026-5233). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5242 |
|
Vulnerability in CVE-2026-5242 (CVE-2026-5242)
vulnerability in CVE-2026-5242 (CVE-2026-5242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5079 |
|
Vulnerability in multer (CVE-2026-5079)
vulnerability in multer (CVE-2026-5079). Risk of unauthorized operations or information disclosure. Exploitable via ``limits.fieldNestingDepth``. Mitigation: upgrade to `3.0.0-alpha.2` or later.
|
| CVE-2026-49062 |
|
Vulnerability in CVE-2026-49062 (CVE-2026-49062)
vulnerability in CVE-2026-49062 (CVE-2026-49062). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49064 |
|
Vulnerability in CVE-2026-49064 (CVE-2026-49064)
vulnerability in CVE-2026-49064 (CVE-2026-49064). Confidential information can be exposed externally.
|
| CVE-2026-49111 |
|
Vulnerability in privilege-escalation (CVE-2026-49111)
vulnerability in privilege-escalation (CVE-2026-49111). Successful exploitation can lead to full system takeover.
|
| CVE-2016-20084 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2016-20084)
cross-site scripting in wordpress (CVE-2016-20084). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25437 |
|
Vulnerability in wordpress (CVE-2018-25437)
vulnerability in wordpress (CVE-2018-25437). Confidential information can be exposed externally.
|
| CVE-2019-25746 |
|
SQL Injection in wordpress (CVE-2019-25746)
SQL injection in wordpress (CVE-2019-25746). Confidential information can be exposed externally.
|
| CVE-2016-20081 |
|
Path Traversal in wordpress (CVE-2016-20081)
path traversal in wordpress (CVE-2016-20081). Confidential information can be exposed externally.
|
| CVE-2016-20072 |
|
SQL Injection in wordpress (CVE-2016-20072)
SQL injection in wordpress (CVE-2016-20072). Confidential information can be exposed externally.
|
| CVE-2016-20071 |
|
SQL Injection in wordpress (CVE-2016-20071)
SQL injection in wordpress (CVE-2016-20071). Confidential information can be exposed externally.
|
| CVE-2016-20073 |
|
SQL Injection in wordpress (CVE-2016-20073)
SQL injection in wordpress (CVE-2016-20073). Confidential information can be exposed externally.
|
| CVE-2016-20075 |
|
Authorization Flaw in wordpress (CVE-2016-20075)
vulnerability in wordpress (CVE-2016-20075). Successful exploitation can lead to full system takeover.
|
| CVE-2016-20076 |
|
Path Traversal in wordpress (CVE-2016-20076)
path traversal in wordpress (CVE-2016-20076). Confidential information can be exposed externally.
|
| CVE-2016-20068 |
|
SQL Injection in wordpress (CVE-2016-20068)
SQL injection in wordpress (CVE-2016-20068). Confidential information can be exposed externally.
|
| CVE-2016-20069 |
|
SQL Injection in wordpress (CVE-2016-20069)
SQL injection in wordpress (CVE-2016-20069). Confidential information can be exposed externally.
|
| CVE-2016-20066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2016-20066)
cross-site scripting in wordpress (CVE-2016-20066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12057 |
|
Vulnerability in foxit (CVE-2026-12057)
vulnerability in foxit (CVE-2026-12057). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50100 |
|
Vulnerability in jvn (CVE-2026-50100)
vulnerability in jvn (CVE-2026-50100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12221 |
|
Buffer Overflow in CVE-2026-12221 (CVE-2026-12221)
vulnerability in CVE-2026-12221 (CVE-2026-12221). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12222 |
|
Buffer Overflow in CVE-2026-12222 (CVE-2026-12222)
vulnerability in CVE-2026-12222 (CVE-2026-12222). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12220 |
|
Buffer Overflow in CVE-2026-12220 (CVE-2026-12220)
vulnerability in CVE-2026-12220 (CVE-2026-12220). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12218 |
|
Buffer Overflow in CVE-2026-12218 (CVE-2026-12218)
vulnerability in CVE-2026-12218 (CVE-2026-12218). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12217 |
|
Vulnerability in CVE-2026-12217 (CVE-2026-12217)
vulnerability in CVE-2026-12217 (CVE-2026-12217). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12214 |
|
Vulnerability in CVE-2026-12214 (CVE-2026-12214)
vulnerability in CVE-2026-12214 (CVE-2026-12214). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12204 |
|
Vulnerability in CVE-2026-12204 (CVE-2026-12204)
vulnerability in CVE-2026-12204 (CVE-2026-12204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12200 |
|
Buffer Overflow in CVE-2026-12200 (CVE-2026-12200)
vulnerability in CVE-2026-12200 (CVE-2026-12200). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12197 |
|
Vulnerability in CVE-2026-12197 (CVE-2026-12197)
vulnerability in CVE-2026-12197 (CVE-2026-12197). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12193 |
|
Buffer Overflow in CVE-2026-12193 (CVE-2026-12193)
vulnerability in CVE-2026-12193 (CVE-2026-12193). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12198 |
|
Path Traversal in microweber/microweber (CVE-2026-12198)
path traversal in microweber/microweber (CVE-2026-12198). Risk of unauthorized operations or information disclosure.
|