Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-3018 |
|
SQL Injection in wordpress (CVE-2026-3018)
SQL injection in wordpress (CVE-2026-3018). Confidential information can be exposed externally.
|
| CVE-2026-8071 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8071)
cross-site scripting in wordpress (CVE-2026-8071). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3326 |
|
SQL Injection in wordpress (CVE-2026-3326)
SQL injection in wordpress (CVE-2026-3326). Confidential information can be exposed externally.
|
| CVE-2026-10846 |
|
Vulnerability in nlnetlabs (CVE-2026-10846)
vulnerability in nlnetlabs (CVE-2026-10846). Data can be tampered with by attackers.
|
| CVE-2026-11837 |
|
Vulnerability in privilege-escalation (CVE-2026-11837)
vulnerability in privilege-escalation (CVE-2026-11837). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26239 |
|
Vulnerability in qnap (CVE-2026-26239)
vulnerability in qnap (CVE-2026-26239). Data can be tampered with by attackers.
|
| CVE-2026-26237 |
|
Vulnerability in qnap (CVE-2026-26237)
vulnerability in qnap (CVE-2026-26237). Confidential information can be exposed externally.
|
| CVE-2026-24724 |
|
Authorization Flaw in qnap (CVE-2026-24724)
vulnerability in qnap (CVE-2026-24724). Confidential information can be exposed externally.
|
| CVE-2026-24719 |
|
OS Command Injection in qnap (CVE-2026-24719)
OS command injection in qnap (CVE-2026-24719). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24716 |
|
Vulnerability in dos (CVE-2026-24716)
vulnerability in dos (CVE-2026-24716). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22893 |
|
OS Command Injection in qnap (CVE-2026-22893)
OS command injection in qnap (CVE-2026-22893). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66281 |
|
Vulnerability in dos (CVE-2025-66281)
vulnerability in dos (CVE-2025-66281). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66273 |
|
OS Command Injection in qnap (CVE-2025-66273)
OS command injection in qnap (CVE-2025-66273). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66279 |
|
OS Command Injection in qnap (CVE-2025-66279)
OS command injection in qnap (CVE-2025-66279). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66280 |
|
Vulnerability in qnap (CVE-2025-66280)
vulnerability in qnap (CVE-2025-66280). Successful exploitation can lead to full system takeover.
|
| CVE-2025-62850 |
|
Vulnerability in dos (CVE-2025-62850)
vulnerability in dos (CVE-2025-62850). Successful exploitation can lead to full system takeover.
|
| CVE-2025-58468 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-58468)
vulnerability in csrf (CVE-2025-58468). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45542 |
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup p...
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/pro...
|
| CVE-2026-45541 |
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation pat...
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation path of the esp_http_server component. While parsing the client-supplied Sec-WebSocket-Protocol request...
|
| CVE-2026-45329 |
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c vali...
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c validated only some of the caller-supplied pointer arguments, leaving input pointer arguments unchecked....
|
| CVE-2026-53674 |
|
Vulnerability in dos (CVE-2026-53674)
vulnerability in dos (CVE-2026-53674). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53673 |
|
Vulnerability in buddypress/buddypress (CVE-2026-53673)
vulnerability in buddypress/buddypress (CVE-2026-53673). Confidential information can be exposed externally. Mitigation: upgrade to `14.5.0` or later.
|
| CVE-2026-41732 |
|
Unsafe Deserialization in org.springframework.pulsar:spring-pulsar (CVE-2026-41732)
vulnerability in org.springframework.pulsar:spring-pulsar (CVE-2026-41732). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41729 |
|
Vulnerability in org.springframework.data:spring-data-rest-core (CVE-2026-41729)
vulnerability in org.springframework.data:spring-data-rest-core (CVE-2026-41729). Confidential information can be exposed externally.
|
| CVE-2026-41728 |
|
Vulnerability in org.springframework.data:spring-data-rest-core (CVE-2026-41728)
vulnerability in org.springframework.data:spring-data-rest-core (CVE-2026-41728). Data can be tampered with by attackers.
|
| CVE-2026-41731 |
|
Unsafe Deserialization in org.springframework.kafka:spring-kafka (CVE-2026-41731)
vulnerability in org.springframework.kafka:spring-kafka (CVE-2026-41731). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40988 |
|
Vulnerability in org.springframework.security:spring-security-saml2-service-provider (CVE-2026-40988)
vulnerability in org.springframework.security:spring-security-saml2-service-provider (CVE-2026-40988). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40993 |
|
Unsafe Deserialization in org.springframework.security:spring-security-saml2-service-provider (CVE-2026-40993)
vulnerability in org.springframework.security:spring-security-saml2-service-provider (CVE-2026-40993). Data can be tampered with by attackers. Mitigation: upgrade to `7.0.6` or later.
|
| CVE-2026-41717 |
|
Vulnerability in org.springframework.data:spring-data-mongodb (CVE-2026-41717)
vulnerability in org.springframework.data:spring-data-mongodb (CVE-2026-41717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41716 |
|
Vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41716)
vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41716). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41003 |
|
Cross-Site Scripting (XSS) in org.springframework.security:spring-security-saml2-service-provider (CVE-2026-41003)
cross-site scripting in org.springframework.security:spring-security-saml2-service-provider (CVE-2026-41003). Confidential information can be exposed externally.
|
| CVE-2026-9753 |
|
Vulnerability in mongodb (CVE-2026-9753)
vulnerability in mongodb (CVE-2026-9753). Confidential information can be exposed externally. Mitigation: upgrade to `7.0.35, 8.0.24, 8.2.10, 8.3.3` or later.
|
| CVE-2026-9740 |
|
Vulnerability in mongodb (CVE-2026-9740)
vulnerability in mongodb (CVE-2026-9740). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.0.35, 8.0.24, 8.2.10, 8.3.3` or later.
|
| CVE-2026-9742 |
|
Vulnerability in mongodb (CVE-2026-9742)
vulnerability in mongodb (CVE-2026-9742). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.2.10, 8.3.3` or later.
|
| CVE-2026-46541 |
|
Vulnerability in CVE-2026-46541 (CVE-2026-46541)
vulnerability in CVE-2026-46541 (CVE-2026-46541). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46518 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-46518)
cross-site scripting in csrf (CVE-2026-46518). Confidential information can be exposed externally.
|
| CVE-2026-41695 |
|
Vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41695)
vulnerability in org.springframework.data:spring-data-commons (CVE-2026-41695). Risk of unauthorized operations or information disclosure. Exploitable via `GET /things`.
|
| CVE-2026-34713 |
|
Vulnerability in adobe (CVE-2026-34713)
vulnerability in adobe (CVE-2026-34713). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34712 |
|
Vulnerability in adobe (CVE-2026-34712)
vulnerability in adobe (CVE-2026-34712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34711 |
|
Vulnerability in adobe (CVE-2026-34711)
vulnerability in adobe (CVE-2026-34711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47929 |
|
Authorization Flaw in adobe (CVE-2026-47929)
vulnerability in adobe (CVE-2026-47929). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48291 |
|
Vulnerability in adobe (CVE-2026-48291)
vulnerability in adobe (CVE-2026-48291). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48292 |
|
Vulnerability in adobe (CVE-2026-48292)
vulnerability in adobe (CVE-2026-48292). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47960 |
|
XXE (XML External Entity) in adobe (CVE-2026-47960)
vulnerability in adobe (CVE-2026-47960). Confidential information can be exposed externally.
|
| CVE-2026-47959 |
|
Vulnerability in adobe (CVE-2026-47959)
vulnerability in adobe (CVE-2026-47959). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47955 |
|
Use-After-Free in adobe (CVE-2026-47955)
vulnerability in adobe (CVE-2026-47955). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47937 |
|
Vulnerability in adobe (CVE-2026-47937)
vulnerability in adobe (CVE-2026-47937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47932 |
|
Path Traversal in path-traversal (CVE-2026-47932)
path traversal in path-traversal (CVE-2026-47932). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47952 |
|
Vulnerability in adobe (CVE-2026-47952)
vulnerability in adobe (CVE-2026-47952). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47931 |
|
Vulnerability in adobe (CVE-2026-47931)
vulnerability in adobe (CVE-2026-47931). Successful exploitation can lead to full system takeover.
|