Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
SUSE-SU-2026:21628-1 Vulnerability in SUSE-SU-2026:21628-1 (SUSE-SU-2026:21628-1)
vulnerability in SUSE-SU-2026:21628-1 (SUSE-SU-2026:21628-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:21626-1 Vulnerability in SUSE-SU-2026:21626-1 (SUSE-SU-2026:21626-1)
vulnerability in SUSE-SU-2026:21626-1 (SUSE-SU-2026:21626-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:21627-1 Security update for openssh
Security update for openssh
CVE-2026-7661 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7661)
cross-site scripting in wordpress (CVE-2026-7661). Risk of unauthorized operations or information disclosure. Exploitable via ``box``.
CVE-2026-6913 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6913)
cross-site scripting in wordpress (CVE-2026-6913). Risk of unauthorized operations or information disclosure.
CVE-2026-7659 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7659)
cross-site scripting in wordpress (CVE-2026-7659). Risk of unauthorized operations or information disclosure. Exploitable via ``social``.
CVE-2026-7561 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-7561)
vulnerability in wordpress (CVE-2026-7561). Risk of unauthorized operations or information disclosure.
CVE-2026-7626 Information Disclosure in wordpress (CVE-2026-7626)
vulnerability in wordpress (CVE-2026-7626). Risk of unauthorized operations or information disclosure.
CVE-2026-6709 Vulnerability in wordpress (CVE-2026-6709)
vulnerability in wordpress (CVE-2026-6709). Risk of unauthorized operations or information disclosure.
CVE-2026-7464 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7464)
cross-site scripting in wordpress (CVE-2026-7464). Risk of unauthorized operations or information disclosure. Exploitable via ``page``.
CVE-2026-7616 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-7616)
vulnerability in wordpress (CVE-2026-7616). Risk of unauthorized operations or information disclosure.
CVE-2026-6808 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6808)
cross-site scripting in wordpress (CVE-2026-6808). Risk of unauthorized operations or information disclosure.
CVE-2026-7562 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-7562)
vulnerability in wordpress (CVE-2026-7562). Risk of unauthorized operations or information disclosure.
CVE-2026-7050 Vulnerability in wordpress (CVE-2026-7050)
vulnerability in wordpress (CVE-2026-7050). Risk of unauthorized operations or information disclosure.
CVE-2026-6710 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-6710)
vulnerability in wordpress (CVE-2026-6710). Risk of unauthorized operations or information disclosure.
CVE-2026-7437 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7437)
cross-site scripting in wordpress (CVE-2026-7437). Risk of unauthorized operations or information disclosure. Exploitable via ``editpos_hidden``.
CVE-2026-6663 Vulnerability in wordpress (CVE-2026-6663)
vulnerability in wordpress (CVE-2026-6663). Risk of unauthorized operations or information disclosure.
CVE-2026-6708 Vulnerability in wordpress (CVE-2026-6708)
vulnerability in wordpress (CVE-2026-6708). Risk of unauthorized operations or information disclosure.
CVE-2026-6932 Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-6932)
vulnerability in wordpress (CVE-2026-6932). Risk of unauthorized operations or information disclosure.
CVE-2026-6690 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6690)
cross-site scripting in wordpress (CVE-2026-6690). Risk of unauthorized operations or information disclosure. Exploitable via ``wp_ajax_nopriv_lp_update_mds``.
CVE-2026-6256 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6256)
cross-site scripting in wordpress (CVE-2026-6256). Risk of unauthorized operations or information disclosure.
CVE-2026-5028 SQL Injection in wordpress (CVE-2026-5028)
SQL injection in wordpress (CVE-2026-5028). Confidential information can be exposed externally.
CVE-2026-6247 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6247)
cross-site scripting in wordpress (CVE-2026-6247). Risk of unauthorized operations or information disclosure.
CVE-2026-5715 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5715)
cross-site scripting in wordpress (CVE-2026-5715). Risk of unauthorized operations or information disclosure.
CVE-2026-5340 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5340)
cross-site scripting in wordpress (CVE-2026-5340). Risk of unauthorized operations or information disclosure.
CVE-2026-6237 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6237)
cross-site scripting in wordpress (CVE-2026-6237). Risk of unauthorized operations or information disclosure.
CVE-2026-5693 Vulnerability in wordpress (CVE-2026-5693)
vulnerability in wordpress (CVE-2026-5693). Risk of unauthorized operations or information disclosure.
CVE-2026-4301 Vulnerability in wordpress (CVE-2026-4301)
vulnerability in wordpress (CVE-2026-4301). Risk of unauthorized operations or information disclosure.
CVE-2026-4663 Vulnerability in wordpress (CVE-2026-4663)
vulnerability in wordpress (CVE-2026-4663). Risk of unauthorized operations or information disclosure.
CVE-2026-4920 Cross-Site Scripting (XSS) in wordpress (CVE-2026-4920)
cross-site scripting in wordpress (CVE-2026-4920). Risk of unauthorized operations or information disclosure.
CVE-2026-4859 Cross-Site Scripting (XSS) in wordpress (CVE-2026-4859)
cross-site scripting in wordpress (CVE-2026-4859). Risk of unauthorized operations or information disclosure. Exploitable via ``wpsbd_post_carousel``.
CVE-2026-2993 SQL Injection in wordpress (CVE-2026-2993)
SQL injection in wordpress (CVE-2026-2993). Confidential information can be exposed externally.
CVE-2026-3604 Cross-Site Scripting (XSS) in wordpress (CVE-2026-3604)
cross-site scripting in wordpress (CVE-2026-3604). Risk of unauthorized operations or information disclosure. Exploitable via ``_kcseo_ative_tab``.
CVE-2026-2300 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2300)
cross-site scripting in wordpress (CVE-2026-2300). Risk of unauthorized operations or information disclosure. Exploitable via ``preg_replace``.
CVE-2026-39432 Vulnerability in CVE-2026-39432 (CVE-2026-39432)
vulnerability in CVE-2026-39432 (CVE-2026-39432). Confidential information can be exposed externally.
ROOT-OS-DEBIAN-12-CVE-2026-32775 Vulnerability in rootio-libexif (ROOT-OS-DEBIAN-12-CVE-2026-32775)
vulnerability in rootio-libexif (ROOT-OS-DEBIAN-12-CVE-2026-32775). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.6.24-1.root.io.3, 0.6.24-1.root.io.1, 0.6.24-1.root.io.2` or later.
ROOT-OS-DEBIAN-12-CVE-2026-40385 Vulnerability in rootio-libexif (ROOT-OS-DEBIAN-12-CVE-2026-40385)
vulnerability in rootio-libexif (ROOT-OS-DEBIAN-12-CVE-2026-40385). Confidential information can be exposed externally. Mitigation: upgrade to `0.6.24-1.root.io.3, 0.6.24-1.root.io.2` or later.
ROOT-OS-DEBIAN-12-CVE-2026-40386 Vulnerability in rootio-libexif (ROOT-OS-DEBIAN-12-CVE-2026-40386)
vulnerability in rootio-libexif (ROOT-OS-DEBIAN-12-CVE-2026-40386). Confidential information can be exposed externally. Mitigation: upgrade to `0.6.24-1.root.io.3` or later.
SUSE-SU-2026:21624-1 Security update for kernel-livepatch-MICRO-6-0_Update_20
Security update for kernel-livepatch-MICRO-6-0_Update_20
SUSE-SU-2026:21638-1 Security update for kernel-livepatch-MICRO-6-0_Update_20
Security update for kernel-livepatch-MICRO-6-0_Update_20
SUSE-SU-2026:21633-1 Vulnerability in SUSE-SU-2026:21633-1 (SUSE-SU-2026:21633-1)
vulnerability in SUSE-SU-2026:21633-1 (SUSE-SU-2026:21633-1). Risk of unauthorized operations or information disclosure.
USN-8268-1 Vulnerability in dnsmasq (USN-8268-1)
vulnerability in dnsmasq (USN-8268-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.68-1ubuntu0.2+esm5` or later.
ROOT-APP-PYPI-CVE-2023-43804 Vulnerability in rootio-urllib3 (ROOT-APP-PYPI-CVE-2023-43804)
vulnerability in rootio-urllib3 (ROOT-APP-PYPI-CVE-2023-43804). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.9+root.io.1, 1.23+root.io.1, 1.26.16+root.io.1, 1.26.16+root.io.2, 1.26.5+root.io.2, 1.26.5+root.io.3, 1.26.5+root.io.4, 1.26.5+root.io.5, 1.26.5+root.io.6, 1.26.16+root.io.3, 1.23+root.io.2, 1.23+root.io.5, 1.23+root.io.6, 1.23+root.io.7, 1.23+root.io.8, 1.23+root.io.9, 1.26.9+root.io.2, 1.26.9+root.io.3, 1.25.6+root.io.1, 1.25.6+root.io.2, 2.0.2+root.io.1, 1.26.7+root.io.1, 1.25.11+root.io.1, 2.0.2+root.io.2, 1.25.6+root.io.3, 1.25.7+root.io.1, 1.26.15+root.io.1, 1.26.6+root.io.1, 1.25.10+root.io.3, 1.25.4+root.io.4, 1.25.6+root.io.4, 2.0.5+root.io.2, 1.26.2+root.io.1, 1.25.9+root.io.1, 1.26.3+root.io.1, 1.26.2+root.io.2, 1.25.8+root.io.1, 1.26.10+root.io.1, 1.26.8+root.io.1, 1.26.12+root.io.1, 1.26.11+root.io.1, 1.26.9+root.io.4, 1.25.9+root.io.2, 1.26.6+root.io.2, 1.26.3+root.io.2, 2.0.3+root.io.2, 2.0.4+root.io.2, 1.26.4+root.io.2, 1.26.13+root.io.2, 1.26.5+root.io.7, 1.26.8+root.io.2, 1.26.16+root.io.4, 1.26.1+root.io.3, 1.26.2+root.io.3, 1.26.0+root.io.3, 1.26.9+root.io.5, 1.26.11+root.io.2, 1.25.11+root.io.2, 1.25.6+root.io.5, 2.0.2+root.io.3, 1.25.5+root.io.4, 1.26.14+root.io.3, 1.26.2+root.io.4, 1.26.3+root.io.3, 1.26.11+root.io.3, 1.25.8+root.io.2, 1.26.10+root.io.2, 1.26.8+root.io.3, 1.26.7+root.io.2, 1.26.6+root.io.3, 1.26.12+root.io.2, 1.26.4+root.io.3, 1.25.5+root.io.5, 1.26.4+root.io.4, 1.25.4+root.io.5, 1.26.14+root.io.4, 1.25.8+root.io.3, 1.25.10+root.io.4, 1.26.13+root.io.3, 1.25.7+root.io.2, 1.25.9+root.io.3, 1.25.10+root.io.5, 1.25.7+root.io.3, 1.26.0+root.io.4, 1.26.15+root.io.2, 1.26.13+root.io.4, 1.26.1+root.io.4, 1.25.8+root.io.4, 1.25.4+root.io.6, 1.26.4+root.io.5, 1.26.2+root.io.5, 1.25.7+root.io.4, 1.26.6+root.io.4, 2.0.3+root.io.3, 2.0.4+root.io.3, 1.26.7+root.io.3, 2.0.5+root.io.3, 1.26.14+root.io.5, 1.26.10+root.io.3, 1.26.13+root.io.5, 1.26.3+root.io.4, 1.25.6+root.io.6, 1.26.0+root.io.5, 1.25.9+root.io.4, 2.0.2+root.io.4, 1.25.7+root.io.5, 1.26.4+root.io.6, 1.25.5+root.io.6, 1.26.1+root.io.5, 1.26.11+root.io.4, 1.25.4+root.io.7, 1.26.14+root.io.6, 1.26.9+root.io.6, 1.26.8+root.io.4, 1.26.15+root.io.3, 1.26.12+root.io.3, 1.26.16+root.io.5, 1.26.2+root.io.6, 1.26.4+root.io.7, 1.25.11+root.io.3, 1.25.8+root.io.5, 1.26.9+root.io.7, 1.26.4+root.io.8, 1.26.16+root.io.6, 1.25.6+root.io.7, 1.26.0+root.io.6, 1.26.5+root.io.8, 1.26.4+root.io.9, 1.25.10+root.io.6, 1.26.14+root.io.7, 1.21.1+root.io.1, 1.25.10+root.io.7, 1.25.6+root.io.8, 1.25.11+root.io.4, 1.23+root.io.10, 1.25.5+root.io.7, 1.25.4+root.io.8, 1.21.1+root.io.2, 1.25.11+root.io.5, 1.25.10+root.io.8, 1.25.5+root.io.8, 1.23+root.io.11, 1.25.7+root.io.6, 1.21.1+root.io.3, 1.26.10+root.io.4, 1.25.6+root.io.9, 1.25.4+root.io.9, 1.25.9+root.io.5, 1.26.14+root.io.8, 1.26.1+root.io.6, 1.25.8+root.io.6, 1.26.15+root.io.4, 1.26.4+root.io.10, 1.26.12+root.io.4, 1.26.13+root.io.6, 1.26.0+root.io.7, 1.26.3+root.io.5, 1.26.5+root.io.9, 1.26.11+root.io.5, 1.26.6+root.io.5, 2.0.2+root.io.5, 1.26.16+root.io.7, 1.26.7+root.io.4, 1.26.2+root.io.7, 2.0.4+root.io.4, 2.0.3+root.io.4, 1.26.8+root.io.5, 2.0.5+root.io.4, 1.26.9+root.io.8, 1.21.1+root.io.4` or later.
ROOT-APP-PYPI-CVE-2023-45803 Vulnerability in rootio-urllib3 (ROOT-APP-PYPI-CVE-2023-45803)
vulnerability in rootio-urllib3 (ROOT-APP-PYPI-CVE-2023-45803). Confidential information can be exposed externally. Mitigation: upgrade to `1.26.5+root.io.4, 1.26.5+root.io.5, 1.26.5+root.io.6, 1.26.16+root.io.3, 1.25.5+root.io.1, 2.0.3+root.io.1, 1.25.5+root.io.2, 2.0.5+root.io.2, 2.0.3+root.io.2, 2.0.4+root.io.2, 1.26.5+root.io.7, 1.26.16+root.io.4, 1.25.5+root.io.3, 1.25.11+root.io.2, 1.25.6+root.io.5, 2.0.6+root.io.3, 2.0.2+root.io.3, 1.25.5+root.io.4, 1.26.2+root.io.4, 1.26.3+root.io.3, 1.26.11+root.io.3, 1.26.10+root.io.2, 1.26.8+root.io.3, 1.26.7+root.io.2, 1.26.6+root.io.3, 1.26.12+root.io.2, 1.25.5+root.io.5, 1.25.4+root.io.5, 1.25.8+root.io.3, 1.25.9+root.io.3, 1.25.10+root.io.5, 1.26.0+root.io.4, 1.26.15+root.io.2, 1.26.13+root.io.4, 1.26.1+root.io.4, 1.25.8+root.io.4, 1.25.4+root.io.6, 1.26.17+root.io.2, 1.26.4+root.io.5, 1.26.2+root.io.5, 1.25.7+root.io.4, 1.26.6+root.io.4, 2.0.3+root.io.3, 2.0.4+root.io.3, 1.26.7+root.io.3, 2.0.5+root.io.3, 1.26.10+root.io.3, 1.26.13+root.io.5, 1.26.3+root.io.4, 1.26.17+root.io.3, 1.25.6+root.io.6, 1.26.0+root.io.5, 1.25.9+root.io.4, 2.0.6+root.io.4, 2.0.2+root.io.4, 1.25.7+root.io.5, 1.26.4+root.io.6, 1.25.5+root.io.6, 1.26.1+root.io.5, 1.26.11+root.io.4, 1.25.4+root.io.7, 1.26.14+root.io.6, 1.26.8+root.io.4, 1.26.15+root.io.3, 1.26.12+root.io.3, 1.26.16+root.io.5, 1.26.2+root.io.6, 1.26.4+root.io.7, 1.25.11+root.io.3, 1.25.8+root.io.5, 1.26.9+root.io.7, 1.26.4+root.io.8, 1.26.16+root.io.6, 1.25.6+root.io.7, 1.26.0+root.io.6, 1.26.5+root.io.8, 1.26.4+root.io.9, 1.25.10+root.io.6, 1.26.14+root.io.7, 1.25.10+root.io.7, 1.25.6+root.io.8, 1.25.11+root.io.4, 1.25.5+root.io.7, 1.25.4+root.io.8, 1.25.11+root.io.5, 1.25.10+root.io.8, 1.25.5+root.io.8, 1.25.7+root.io.6, 1.26.10+root.io.4, 1.25.6+root.io.9, 1.25.4+root.io.9, 1.25.9+root.io.5, 1.26.14+root.io.8, 1.26.1+root.io.6, 1.25.8+root.io.6, 1.26.15+root.io.4, 1.26.4+root.io.10, 1.26.12+root.io.4, 1.26.13+root.io.6, 1.26.0+root.io.7, 1.26.17+root.io.4, 1.26.3+root.io.5, 1.26.5+root.io.9, 1.26.11+root.io.5, 1.26.6+root.io.5, 2.0.2+root.io.5, 1.26.16+root.io.7, 2.0.6+root.io.5, 1.26.7+root.io.4, 1.26.2+root.io.7, 2.0.4+root.io.4, 2.0.3+root.io.4, 1.26.8+root.io.5, 2.0.5+root.io.4, 1.26.9+root.io.8, 1.21.1+root.io.4` or later.
ROOT-APP-PYPI-CVE-2026-44432 Vulnerability in rootio-urllib3 (ROOT-APP-PYPI-CVE-2026-44432)
vulnerability in rootio-urllib3 (ROOT-APP-PYPI-CVE-2026-44432). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.0+root.io.2, 2.6.1+root.io.2, 2.6.2+root.io.2, 2.6.3+root.io.1, 2.6.0+root.io.3, 2.6.1+root.io.3, 2.6.3+root.io.2, 2.6.2+root.io.3` or later.
CVE-2026-6402 Vulnerability in webpack-dev-server (CVE-2026-6402)
vulnerability in webpack-dev-server (CVE-2026-6402). Confidential information can be exposed externally. Mitigation: upgrade to `5.2.4` or later.
ROOT-APP-NPM-GHSA-r4q5-vmmm-2653 Vulnerability in @rootio/follow-redirects (ROOT-APP-NPM-GHSA-r4q5-vmmm-2653)
vulnerability in @rootio/follow-redirects (ROOT-APP-NPM-GHSA-r4q5-vmmm-2653). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.15.11-root.io.1, 1.15.6-root.io.1, 1.15.11-root.io.2, 1.15.6-root.io.2, 1.15.9-root.io.1` or later.
SUSE-SU-2026:1828-1 Vulnerability in SUSE-SU-2026:1828-1 (SUSE-SU-2026:1828-1)
vulnerability in SUSE-SU-2026:1828-1 (SUSE-SU-2026:1828-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:1827-1 Vulnerability in SUSE-SU-2026:1827-1 (SUSE-SU-2026:1827-1)
vulnerability in SUSE-SU-2026:1827-1 (SUSE-SU-2026:1827-1). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:1826-1 Vulnerability in SUSE-SU-2026:1826-1 (SUSE-SU-2026:1826-1)
vulnerability in SUSE-SU-2026:1826-1 (SUSE-SU-2026:1826-1). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →