Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9580 |
|
Vulnerability in CVE-2026-9580 (CVE-2026-9580)
vulnerability in CVE-2026-9580 (CVE-2026-9580). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8676 |
|
Vulnerability in CVE-2026-8676 (CVE-2026-8676)
vulnerability in CVE-2026-8676 (CVE-2026-8676). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44847 |
|
Authentication Bypass in django (CVE-2026-44847)
authentication bypass in django (CVE-2026-44847). Data can be tampered with by attackers. Mitigation: upgrade to `2.9.0` or later.
|
| CVE-2025-14361 |
|
Vulnerability in CVE-2025-14361 (CVE-2025-14361)
vulnerability in CVE-2025-14361 (CVE-2025-14361). Data can be tampered with by attackers.
|
| CVE-2026-48048 |
|
Vulnerability in org.xwiki.platform:xwiki-platform-livetable-ui (CVE-2026-48048)
vulnerability in org.xwiki.platform:xwiki-platform-livetable-ui (CVE-2026-48048). Confidential information can be exposed externally. Exploitable via ``LiveTableResults``. Mitigation: upgrade to `17.10.3` or later.
|
| CVE-2026-9573 |
|
Vulnerability in sqli (CVE-2026-9573)
vulnerability in sqli (CVE-2026-9573). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9574 |
|
Vulnerability in sqli (CVE-2026-9574)
vulnerability in sqli (CVE-2026-9574). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9575 |
|
Vulnerability in sqli (CVE-2026-9575)
vulnerability in sqli (CVE-2026-9575). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8890 |
|
Vulnerability in CVE-2026-8890 (CVE-2026-8890)
vulnerability in CVE-2026-8890 (CVE-2026-8890). Confidential information can be exposed externally.
|
| CVE-2026-4051 |
|
Vulnerability in ibm (CVE-2026-4051)
vulnerability in ibm (CVE-2026-4051). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3603 |
|
XXE (XML External Entity) in ibm (CVE-2026-3603)
vulnerability in ibm (CVE-2026-3603). Confidential information can be exposed externally.
|
| CVE-2026-8835 |
|
Vulnerability in dos (CVE-2026-8835)
vulnerability in dos (CVE-2026-8835). Confidential information can be exposed externally.
|
| CVE-2026-8834 |
|
Vulnerability in dos (CVE-2026-8834)
vulnerability in dos (CVE-2026-8834). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7454 |
|
Vulnerability in autodesk (CVE-2026-7454)
vulnerability in autodesk (CVE-2026-7454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8620 |
|
Vulnerability in ibm (CVE-2026-8620)
vulnerability in ibm (CVE-2026-8620). Confidential information can be exposed externally.
|
| CVE-2026-8856 |
|
Vulnerability in dos (CVE-2026-8856)
vulnerability in dos (CVE-2026-8856). Data can be tampered with by attackers.
|
| CVE-2026-8854 |
|
Vulnerability in dos (CVE-2026-8854)
vulnerability in dos (CVE-2026-8854). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8855 |
|
Code Injection in dos (CVE-2026-8855)
code injection in dos (CVE-2026-8855). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9560 |
|
OS Command Injection in privilege-escalation (CVE-2026-9560)
OS command injection in privilege-escalation (CVE-2026-9560). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48695 |
|
OS Command Injection in pavel-odintsov (CVE-2026-48695)
OS command injection in pavel-odintsov (CVE-2026-48695). Confidential information can be exposed externally. Exploitable via ``date``.
|
| CVE-2026-48694 |
|
Command Injection in pavel-odintsov (CVE-2026-48694)
command injection in pavel-odintsov (CVE-2026-48694). Confidential information can be exposed externally.
|
| CVE-2026-7452 |
|
Vulnerability in autodesk (CVE-2026-7452)
vulnerability in autodesk (CVE-2026-7452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7451 |
|
Out-of-Bounds Write in autodesk (CVE-2026-7451)
out-of-bounds write in autodesk (CVE-2026-7451). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24191 |
|
Vulnerability in dos (CVE-2026-24191)
vulnerability in dos (CVE-2026-24191). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24196 |
|
Out-of-Bounds Read in dos (CVE-2026-24196)
vulnerability in dos (CVE-2026-24196). Confidential information can be exposed externally.
|
| CVE-2026-24195 |
|
Vulnerability in dos (CVE-2026-24195)
vulnerability in dos (CVE-2026-24195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24200 |
|
Use-After-Free in dos (CVE-2026-24200)
vulnerability in dos (CVE-2026-24200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24190 |
|
Vulnerability in dos (CVE-2026-24190)
vulnerability in dos (CVE-2026-24190). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24187 |
|
Use-After-Free in dos (CVE-2026-24187)
vulnerability in dos (CVE-2026-24187). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24192 |
|
Vulnerability in dos (CVE-2026-24192)
vulnerability in dos (CVE-2026-24192). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24193 |
|
Out-of-Bounds Write in dos (CVE-2026-24193)
out-of-bounds write in dos (CVE-2026-24193). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24194 |
|
Vulnerability in dos (CVE-2026-24194)
vulnerability in dos (CVE-2026-24194). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44730 |
|
Vulnerability in pycti (CVE-2026-44730)
vulnerability in pycti (CVE-2026-44730). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.9.7` or later.
|
| CVE-2026-44667 |
|
Cross-Site Scripting (XSS) in CVE-2026-44667 (CVE-2026-44667)
cross-site scripting in CVE-2026-44667 (CVE-2026-44667). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.3` or later.
|
| CVE-2026-44669 |
|
Cross-Site Scripting (XSS) in CVE-2026-44669 (CVE-2026-44669)
cross-site scripting in CVE-2026-44669 (CVE-2026-44669). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.3` or later.
|
| CVE-2026-44706 |
|
SQL Injection in sqli (CVE-2026-44706)
SQL injection in sqli (CVE-2026-44706). Confidential information can be exposed externally. Mitigation: upgrade to `4.11.2` or later.
|
| CVE-2026-28445 |
|
Cross-Site Scripting (XSS) in @typebot.io/js (CVE-2026-28445)
cross-site scripting in @typebot.io/js (CVE-2026-28445). Confidential information can be exposed externally. Exploitable via ``customIcon.svg``. Mitigation: upgrade to `0.10.1` or later.
|
| CVE-2026-9562 |
|
Vulnerability in CVE-2026-9562 (CVE-2026-9562)
vulnerability in CVE-2026-9562 (CVE-2026-9562). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8850 |
|
Vulnerability in dos (CVE-2026-8850)
vulnerability in dos (CVE-2026-8850). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48864 |
|
Out-of-Bounds Write in dos (CVE-2026-48864)
out-of-bounds write in dos (CVE-2026-48864). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48896 |
|
Joomla! Core - [20260511] - MFA Authentication Bypass
Joomla! Core - [20260511] - MFA Authentication Bypass
|
| CVE-2026-48897 |
|
Joomla! Core - [20260512] - MFA Authentication Bypass
Joomla! Core - [20260512] - MFA Authentication Bypass
|
| CVE-2026-48901 |
|
Vulnerability in joomla (CVE-2026-48901)
vulnerability in joomla (CVE-2026-48901). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-48690 |
|
Vulnerability in pavel-odintsov (CVE-2026-48690)
vulnerability in pavel-odintsov (CVE-2026-48690). Confidential information can be exposed externally.
|
| CVE-2026-48697 |
|
Vulnerability in cpp (CVE-2026-48697)
vulnerability in cpp (CVE-2026-48697). Confidential information can be exposed externally.
|
| CVE-2026-48126 |
|
Path Traversal in github.com/xyproto/algernon (CVE-2026-48126)
path traversal in github.com/xyproto/algernon (CVE-2026-48126). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `1.17.8` or later.
|
| CVE-2026-44729 |
|
Cross-Site Scripting (XSS) in twenty (CVE-2026-44729)
cross-site scripting in twenty (CVE-2026-44729). Confidential information can be exposed externally.
|
| CVE-2026-40384 |
|
Path Traversal in joomla (CVE-2026-40384)
path traversal in joomla (CVE-2026-40384). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-24212 |
|
Vulnerability in nvidia (CVE-2026-24212)
vulnerability in nvidia (CVE-2026-24212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24162 |
|
Unsafe Deserialization in deserialization (CVE-2026-24162)
vulnerability in deserialization (CVE-2026-24162). Successful exploitation can lead to full system takeover.
|