Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12198 |
|
Path Traversal in microweber/microweber (CVE-2026-12198)
path traversal in microweber/microweber (CVE-2026-12198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12191 |
|
Vulnerability in deserialization (CVE-2026-12191)
vulnerability in deserialization (CVE-2026-12191). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12187 |
|
Vulnerability in CVE-2026-12187 (CVE-2026-12187)
vulnerability in CVE-2026-12187 (CVE-2026-12187). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12186 |
|
Vulnerability in CVE-2026-12186 (CVE-2026-12186)
vulnerability in CVE-2026-12186 (CVE-2026-12186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54412 |
|
Out-of-Bounds Read in c (CVE-2026-54412)
vulnerability in c (CVE-2026-54412). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54413 |
|
Out-of-Bounds Read in c (CVE-2026-54413)
vulnerability in c (CVE-2026-54413). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54410 |
|
Vulnerability in dos (CVE-2026-54410)
vulnerability in dos (CVE-2026-54410). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11527 |
|
Vulnerability in CVE-2026-11527 (CVE-2026-11527)
vulnerability in CVE-2026-11527 (CVE-2026-11527). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54420 KEV |
|
[KEV] Vulnerability in litespeed (CVE-2026-54420)
vulnerability in litespeed (CVE-2026-54420). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-12174 |
|
Buffer Overflow in dlink (CVE-2026-12174)
vulnerability in dlink (CVE-2026-12174). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6428 |
|
SQL Injection in sqli (CVE-2026-6428)
SQL injection in sqli (CVE-2026-6428). Confidential information can be exposed externally. Exploitable via `GET /cgi-bin/koha/reports/catalogue_out.pl`.
|
| CVE-2026-5513 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5513)
cross-site scripting in wordpress (CVE-2026-5513). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9109 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9109)
cross-site scripting in wordpress (CVE-2026-9109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11769 |
|
Information Disclosure in github.com/grafana/grafana-operator (CVE-2026-11769)
vulnerability in github.com/grafana/grafana-operator (CVE-2026-11769). Successful exploitation can lead to full system takeover. Exploitable via ``Dashboard``. Mitigation: upgrade to `5.24.0` or later.
|
| CVE-2026-9848 |
|
SQL Injection in wordpress (CVE-2026-9848)
SQL injection in wordpress (CVE-2026-9848). Confidential information can be exposed externally. Exploitable via ``posts_request``.
|
| CVE-2026-54230 |
|
Vulnerability in abrt-project (CVE-2026-54230)
vulnerability in abrt-project (CVE-2026-54230). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54229 |
|
Vulnerability in CVE-2026-54229 (CVE-2026-54229)
vulnerability in CVE-2026-54229 (CVE-2026-54229). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54228 |
|
Vulnerability in CVE-2026-54228 (CVE-2026-54228)
vulnerability in CVE-2026-54228 (CVE-2026-54228). Successful exploitation can lead to full system takeover.
|
| CVE-2025-9032 |
|
Out-of-Bounds Read in CVE-2025-9032 (CVE-2025-9032)
vulnerability in CVE-2025-9032 (CVE-2025-9032). Successful exploitation can lead to full system takeover.
|
| CVE-2025-14098 |
|
Vulnerability in dos (CVE-2025-14098)
vulnerability in dos (CVE-2025-14098). Successful exploitation can lead to full system takeover.
|
| CVE-2025-9033 |
|
Out-of-Bounds Read in CVE-2025-9033 (CVE-2025-9033)
vulnerability in CVE-2025-9033 (CVE-2025-9033). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12068 |
|
Vulnerability in CVE-2026-12068 (CVE-2026-12068)
vulnerability in CVE-2026-12068 (CVE-2026-12068). Confidential information can be exposed externally.
|
| CVE-2026-6676 |
|
Out-of-Bounds Write in CVE-2026-6676 (CVE-2026-6676)
out-of-bounds write in CVE-2026-6676 (CVE-2026-6676). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53868 |
|
Vulnerability in dos (CVE-2026-53868)
vulnerability in dos (CVE-2026-53868). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53834 |
|
Authorization Flaw in openclaw (CVE-2026-53834)
vulnerability in openclaw (CVE-2026-53834). Data can be tampered with by attackers. Mitigation: upgrade to `2026.4.27` or later.
|
| CVE-2026-53836 |
|
Vulnerability in openclaw (CVE-2026-53836)
vulnerability in openclaw (CVE-2026-53836). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.12` or later.
|
| CVE-2026-53832 |
|
Privilege Escalation in openclaw (CVE-2026-53832)
vulnerability in openclaw (CVE-2026-53832). Confidential information can be exposed externally. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-53829 |
|
Vulnerability in openclaw (CVE-2026-53829)
vulnerability in openclaw (CVE-2026-53829). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-53831 |
|
OS Command Injection in openclaw (CVE-2026-53831)
OS command injection in openclaw (CVE-2026-53831). Confidential information can be exposed externally. Exploitable via ``system.run``. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-53833 |
|
Authorization Flaw in openclaw (CVE-2026-53833)
vulnerability in openclaw (CVE-2026-53833). Confidential information can be exposed externally. Mitigation: upgrade to `2026.4.29` or later.
|
| CVE-2026-53828 |
|
Authorization Flaw in openclaw (CVE-2026-53828)
vulnerability in openclaw (CVE-2026-53828). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.6` or later.
|
| CVE-2026-53822 |
|
Vulnerability in Openclaw (CVE-2026-53822)
vulnerability in Openclaw (CVE-2026-53822). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-53821 |
|
Vulnerability in openclaw (CVE-2026-53821)
vulnerability in openclaw (CVE-2026-53821). Successful exploitation can lead to full system takeover. Exploitable via ``operator.admin``. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-53823 |
|
Vulnerability in openclaw (CVE-2026-53823)
vulnerability in openclaw (CVE-2026-53823). Confidential information can be exposed externally. Mitigation: upgrade to `2026.5.3` or later.
|
| CVE-2026-53608 |
|
Cross-Site Scripting (XSS) in @apostrophecms/seo (CVE-2026-53608)
cross-site scripting in @apostrophecms/seo (CVE-2026-53608). Confidential information can be exposed externally. Exploitable via ``seoGoogleTrackingId``. Mitigation: upgrade to `1.5.0` or later.
|
| CVE-2026-41158 |
|
Use-After-Free in CVE-2026-41158 (CVE-2026-41158)
vulnerability in CVE-2026-41158 (CVE-2026-41158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34195 |
|
Out-of-Bounds Write in CVE-2026-34195 (CVE-2026-34195)
out-of-bounds write in CVE-2026-34195 (CVE-2026-34195). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7011 |
|
Out-of-Bounds Read in CVE-2025-7011 (CVE-2025-7011)
vulnerability in CVE-2025-7011 (CVE-2025-7011). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7017 |
|
Out-of-Bounds Read in CVE-2025-7017 (CVE-2025-7017)
vulnerability in CVE-2025-7017 (CVE-2025-7017). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7002 |
|
Out-of-Bounds Read in CVE-2025-7002 (CVE-2025-7002)
vulnerability in CVE-2025-7002 (CVE-2025-7002). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7003 |
|
Out-of-Bounds Read in CVE-2025-7003 (CVE-2025-7003)
vulnerability in CVE-2025-7003 (CVE-2025-7003). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7004 |
|
Out-of-Bounds Write in CVE-2025-7004 (CVE-2025-7004)
out-of-bounds write in CVE-2025-7004 (CVE-2025-7004). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7008 |
|
Out-of-Bounds Read in csharp (CVE-2025-7008)
vulnerability in csharp (CVE-2025-7008). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7009 |
|
Out-of-Bounds Read in CVE-2025-7009 (CVE-2025-7009)
vulnerability in CVE-2025-7009 (CVE-2025-7009). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54091 |
|
Authorization Flaw in github.com/filebrowser/filebrowser/v2 (CVE-2026-54091)
vulnerability in github.com/filebrowser/filebrowser/v2 (CVE-2026-54091). Confidential information can be exposed externally. Mitigation: upgrade to `2.63.6` or later.
|
| CVE-2026-54094 |
|
Path Traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-54094)
path traversal in github.com/filebrowser/filebrowser/v2 (CVE-2026-54094). Confidential information can be exposed externally. Exploitable via `GET /api/raw/{path}`. Mitigation: upgrade to `2.63.14` or later.
|
| CVE-2026-54057 |
|
Code Injection in kovidgoyal (CVE-2026-54057)
code injection in kovidgoyal (CVE-2026-54057). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54056 |
|
Vulnerability in kovidgoyal (CVE-2026-54056)
vulnerability in kovidgoyal (CVE-2026-54056). Data can be tampered with by attackers. Exploitable via ``O_NOFOLLOW``.
|
| CVE-2026-4870 |
|
Vulnerability in dos (CVE-2026-4870)
vulnerability in dos (CVE-2026-4870). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44786 |
|
Information Disclosure in discourse (CVE-2026-44786)
vulnerability in discourse (CVE-2026-44786). Confidential information can be exposed externally. Mitigation: upgrade to `2026.1.4, 2026.3.1, 2026.4.1` or later.
|