Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-24210 |
|
Vulnerability in dos (CVE-2026-24210)
vulnerability in dos (CVE-2026-24210). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24213 |
|
Out-of-Bounds Read in dos (CVE-2026-24213)
vulnerability in dos (CVE-2026-24213). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24163 |
|
Unsafe Deserialization in dos (CVE-2026-24163)
vulnerability in dos (CVE-2026-24163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24206 |
|
Vulnerability in dos (CVE-2026-24206)
vulnerability in dos (CVE-2026-24206). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-33255 |
|
Unsafe Deserialization in dos (CVE-2025-33255)
vulnerability in dos (CVE-2025-33255). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7467 |
|
Privilege Escalation in wordpress (CVE-2026-7467)
vulnerability in wordpress (CVE-2026-7467). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6456 |
|
Authentication Bypass in wordpress (CVE-2026-6456)
authentication bypass in wordpress (CVE-2026-6456). Successful exploitation can lead to full system takeover. Exploitable via ``rememberLogin``.
|
| CVE-2026-43618 |
|
Out-of-Bounds Read in samba (CVE-2026-43618)
vulnerability in samba (CVE-2026-43618). Confidential information can be exposed externally.
|
| CVE-2026-3985 |
|
SQL Injection in wordpress (CVE-2026-3985)
SQL injection in wordpress (CVE-2026-3985). Confidential information can be exposed externally.
|
| CVE-2009-1537 KEV |
|
[KEV] Vulnerability in Microsoft directx (CVE-2009-1537)
vulnerability in Microsoft directx (CVE-2009-1537). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2009-3459 KEV |
|
[KEV] Buffer Overflow in Adobe acrobat (CVE-2009-3459)
vulnerability in Adobe acrobat (CVE-2009-3459). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2010-0806 KEV |
|
[KEV] Vulnerability in Microsoft internet-explorer (CVE-2010-0806)
vulnerability in Microsoft internet-explorer (CVE-2010-0806). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34241 |
|
Cross-Site Scripting (XSS) in CVE-2026-34241 (CVE-2026-34241)
cross-site scripting in CVE-2026-34241 (CVE-2026-34241). Confidential information can be exposed externally.
|
| CVE-2026-34358 |
|
Vulnerability in privilege-escalation (CVE-2026-34358)
vulnerability in privilege-escalation (CVE-2026-34358). Confidential information can be exposed externally.
|
| CVE-2026-39250 |
|
Vulnerability in CVE-2026-39250 (CVE-2026-39250)
vulnerability in CVE-2026-39250 (CVE-2026-39250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32741 |
|
Vulnerability in CVE-2026-32741 (CVE-2026-32741)
vulnerability in CVE-2026-32741 (CVE-2026-32741). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32882 |
|
Out-of-Bounds Read in dos (CVE-2026-32882)
vulnerability in dos (CVE-2026-32882). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46415 |
|
Vulnerability in pkg.jsn.cam/caddy-defender (CVE-2026-46415)
vulnerability in pkg.jsn.cam/caddy-defender (CVE-2026-46415). Confidential information can be exposed externally. Exploitable via ``r.RemoteAddr``. Mitigation: upgrade to `0.10.1` or later.
|
| CVE-2026-32740 |
|
Out-of-Bounds Write in struktur (CVE-2026-32740)
out-of-bounds write in struktur (CVE-2026-32740). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27173 |
|
Vulnerability in apache-airflow-providers-cncf-kubernetes (CVE-2026-27173)
vulnerability in apache-airflow-providers-cncf-kubernetes (CVE-2026-27173). Confidential information can be exposed externally. Mitigation: upgrade to `10.17.0` or later.
|
| CVE-2026-46374 |
|
Vulnerability in sqlfluff (CVE-2026-46374)
vulnerability in sqlfluff (CVE-2026-46374). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.2.0` or later.
|
| CVE-2026-46373 |
|
Vulnerability in sqlfluff (CVE-2026-46373)
vulnerability in sqlfluff (CVE-2026-46373). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.0` or later.
|
| CVE-2026-46372 |
|
SSRF (Server-Side Request Forgery) in sillytavern (CVE-2026-46372)
SSRF in sillytavern (CVE-2026-46372). Confidential information can be exposed externally. Exploitable via `POST /api/search/searxng`. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-45783 |
|
Vulnerability in @libp2p/kad-dht (CVE-2026-45783)
vulnerability in @libp2p/kad-dht (CVE-2026-45783). Risk of unauthorized operations or information disclosure. Exploitable via ``PUT_VALUE``. Mitigation: upgrade to `16.2.6` or later.
|
| CVE-2026-45805 |
|
Vulnerability in @penpot/mcp (CVE-2026-45805)
vulnerability in @penpot/mcp (CVE-2026-45805). Successful exploitation can lead to full system takeover. Exploitable via ``ReplServer``. Mitigation: upgrade to `2.15.0` or later.
|
| CVE-2026-45799 |
|
Vulnerability in com.squareup.wire:wire-runtime-jvm (CVE-2026-45799)
vulnerability in com.squareup.wire:wire-runtime-jvm (CVE-2026-45799). Risk of unauthorized operations or information disclosure. Exploitable via ``IOException``. Mitigation: upgrade to `7.0.0-alpha03` or later.
|
| CVE-2026-45784 |
|
Vulnerability in openssl (CVE-2026-45784)
vulnerability in openssl (CVE-2026-45784). Data can be tampered with by attackers. Mitigation: upgrade to `0.10.80` or later.
|
| CVE-2026-8073 |
|
Vulnerability in wordpress (CVE-2026-8073)
vulnerability in wordpress (CVE-2026-8073). Confidential information can be exposed externally.
|
| CVE-2026-8604 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-8604)
vulnerability in csrf (CVE-2026-8604). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47107 |
|
Vulnerability in CVE-2026-47107 (CVE-2026-47107)
vulnerability in CVE-2026-47107 (CVE-2026-47107). Confidential information can be exposed externally.
|
| CVE-2026-33633 |
|
Vulnerability in dos (CVE-2026-33633)
vulnerability in dos (CVE-2026-33633). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61081 |
|
Vulnerability in CVE-2025-61081 (CVE-2025-61081)
vulnerability in CVE-2025-61081 (CVE-2025-61081). Data can be tampered with by attackers.
|
| CVE-2026-47358 |
|
Vulnerability in ssrf (CVE-2026-47358)
vulnerability in ssrf (CVE-2026-47358). Confidential information can be exposed externally.
|
| CVE-2026-36828 |
|
OS Command Injection in CVE-2026-36828 (CVE-2026-36828)
OS command injection in CVE-2026-36828 (CVE-2026-36828). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47356 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-47356)
SSRF in ssrf (CVE-2026-47356). Confidential information can be exposed externally. Exploitable via `POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan`.
|
| CVE-2026-47357 |
|
Vulnerability in ssrf (CVE-2026-47357)
vulnerability in ssrf (CVE-2026-47357). Confidential information can be exposed externally. Exploitable via `POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan`.
|
| CVE-2026-46426 |
|
Unrestricted File Upload in budibase (CVE-2026-46426)
vulnerability in budibase (CVE-2026-46426). Confidential information can be exposed externally. Exploitable via `POST /api/attachments/process`. Mitigation: upgrade to `3.38.2` or later.
|
| CVE-2026-45793 |
|
Information Disclosure in composer/composer (CVE-2026-45793)
vulnerability in composer/composer (CVE-2026-45793). Confidential information can be exposed externally. Exploitable via ``GITHUB_TOKEN``. Mitigation: upgrade to `1.10.28` or later.
|
| CVE-2026-5804 |
|
Vulnerability in CVE-2026-5804 (CVE-2026-5804)
vulnerability in CVE-2026-5804 (CVE-2026-5804). Confidential information can be exposed externally.
|
| CVE-2026-31069 |
|
SQL Injection in billabear/billabear (CVE-2026-31069)
SQL injection in billabear/billabear (CVE-2026-31069). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45738 |
|
Cross-Site Scripting (XSS) in github.com/argoproj/argo-cd/v3 (CVE-2026-45738)
cross-site scripting in github.com/argoproj/argo-cd/v3 (CVE-2026-45738). Confidential information can be exposed externally. Exploitable via ``href``. Mitigation: upgrade to `3.4.2` or later.
|
| CVE-2026-45713 |
|
Vulnerability in github.com/axllent/mailpit (CVE-2026-45713)
vulnerability in github.com/axllent/mailpit (CVE-2026-45713). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/send`. Mitigation: upgrade to `1.30.0` or later.
|
| CVE-2026-45576 |
|
Path Traversal in github.com/openziti/zrok/v2 (CVE-2026-45576)
path traversal in github.com/openziti/zrok/v2 (CVE-2026-45576). Data can be tampered with by attackers. Exploitable via ``href``. Mitigation: upgrade to `2.0.3` or later.
|
| CVE-2026-47100 |
|
Vulnerability in CVE-2026-47100 (CVE-2026-47100)
vulnerability in CVE-2026-47100 (CVE-2026-47100). Data can be tampered with by attackers.
|
| CVE-2026-8711 |
|
Vulnerability in nginx (CVE-2026-8711)
vulnerability in nginx (CVE-2026-8711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43634 |
|
Vulnerability in CVE-2026-43634 (CVE-2026-43634)
vulnerability in CVE-2026-43634 (CVE-2026-43634). Data can be tampered with by attackers.
|
| CVE-2025-51427 |
|
Code Injection in modelscope (CVE-2025-51427)
code injection in modelscope (CVE-2025-51427). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2025-70950 |
|
Path Traversal in github.com/itang/gohttp (CVE-2025-70950)
path traversal in github.com/itang/gohttp (CVE-2025-70950). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45728 |
|
Vulnerability in github.com/xyproto/algernon (CVE-2026-45728)
vulnerability in github.com/xyproto/algernon (CVE-2026-45728). Confidential information can be exposed externally. Exploitable via ``singleFileMode``. Mitigation: upgrade to `1.17.7` or later.
|
| CVE-2026-8975 |
|
Buffer Overflow in mozilla (CVE-2026-8975)
vulnerability in mozilla (CVE-2026-8975). Successful exploitation can lead to full system takeover.
|