Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-28317 |
|
Vulnerability in privilege-escalation (CVE-2026-28317)
vulnerability in privilege-escalation (CVE-2026-28317). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28312 |
|
Vulnerability in privilege-escalation (CVE-2026-28312)
vulnerability in privilege-escalation (CVE-2026-28312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28307 |
|
Vulnerability in privilege-escalation (CVE-2026-28307)
vulnerability in privilege-escalation (CVE-2026-28307). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28305 |
|
Vulnerability in solarwinds (CVE-2026-28305)
vulnerability in solarwinds (CVE-2026-28305). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28309 |
|
Vulnerability in solarwinds (CVE-2026-28309)
vulnerability in solarwinds (CVE-2026-28309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16449 |
|
Vulnerability in sqli (CVE-2026-16449)
vulnerability in sqli (CVE-2026-16449). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28310 |
|
Vulnerability in privilege-escalation (CVE-2026-28310)
vulnerability in privilege-escalation (CVE-2026-28310). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28306 |
|
Vulnerability in privilege-escalation (CVE-2026-28306)
vulnerability in privilege-escalation (CVE-2026-28306). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28304 |
|
Vulnerability in solarwinds (CVE-2026-28304)
vulnerability in solarwinds (CVE-2026-28304). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16450 |
|
Vulnerability in CVE-2026-16450 (CVE-2026-16450)
vulnerability in CVE-2026-16450 (CVE-2026-16450). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28308 |
|
Vulnerability in solarwinds (CVE-2026-28308)
vulnerability in solarwinds (CVE-2026-28308). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28302 |
|
Vulnerability in privilege-escalation (CVE-2026-28302)
vulnerability in privilege-escalation (CVE-2026-28302). Successful exploitation can lead to full system takeover.
|
| GHSA-frvp-7c67-39w9 |
|
Path Traversal in @hono/node-server (GHSA-frvp-7c67-39w9)
path traversal in @hono/node-server (GHSA-frvp-7c67-39w9). Risk of unauthorized operations or information disclosure. Exploitable via ``hono``. Mitigation: upgrade to `1.19.15` or later.
|
| CVE-2026-47657 |
|
Vulnerability in CVE-2026-47657 (CVE-2026-47657)
vulnerability in CVE-2026-47657 (CVE-2026-47657). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44907 |
|
Vulnerability in react-server-dom-webpack (CVE-2026-44907)
vulnerability in react-server-dom-webpack (CVE-2026-44907). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `19.2.8` or later.
|
| CVE-2026-15793 |
|
Vulnerability in mobyproject (CVE-2026-15793)
vulnerability in mobyproject (CVE-2026-15793). Data can be tampered with by attackers.
|
| CVE-2026-15792 |
|
Vulnerability in mobyproject (CVE-2026-15792)
vulnerability in mobyproject (CVE-2026-15792). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15791 |
|
Path Traversal in c (CVE-2026-15791)
path traversal in c (CVE-2026-15791). Data can be tampered with by attackers.
|
| CVE-2026-15789 |
|
Path Traversal in mobyproject (CVE-2026-15789)
path traversal in mobyproject (CVE-2026-15789). Data can be tampered with by attackers.
|
| CVE-2026-61884 |
|
Vulnerability in cisa (CVE-2026-61884)
vulnerability in cisa (CVE-2026-61884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65052 |
|
Vulnerability in wordpress (CVE-2026-65052)
vulnerability in wordpress (CVE-2026-65052). Data can be tampered with by attackers.
|
| CVE-2026-8933 |
|
Vulnerability in privilege-escalation (CVE-2026-8933)
vulnerability in privilege-escalation (CVE-2026-8933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65051 |
|
Vulnerability in wordpress (CVE-2026-65051)
vulnerability in wordpress (CVE-2026-65051). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65050 |
|
Vulnerability in wordpress (CVE-2026-65050)
vulnerability in wordpress (CVE-2026-65050). Confidential information can be exposed externally. Exploitable via ``wp_localize_script``.
|
| CVE-2026-65048 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-65048)
cross-site scripting in wordpress (CVE-2026-65048). Confidential information can be exposed externally.
|
| CVE-2026-65049 |
|
Authorization Flaw in wordpress (CVE-2026-65049)
vulnerability in wordpress (CVE-2026-65049). Data can be tampered with by attackers.
|
| CVE-2026-56584 |
|
Information Disclosure in nginx (CVE-2026-56584)
vulnerability in nginx (CVE-2026-56584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15226 |
|
Vulnerability in CVE-2026-15226 (CVE-2026-15226)
vulnerability in CVE-2026-15226 (CVE-2026-15226). Confidential information can be exposed externally.
|
| CVE-2026-56587 |
|
Vulnerability in hcltech (CVE-2026-56587)
vulnerability in hcltech (CVE-2026-56587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59849 |
|
Vulnerability in dos (CVE-2026-59849)
vulnerability in dos (CVE-2026-59849). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16448 |
|
Vulnerability in CVE-2026-16448 (CVE-2026-16448)
vulnerability in CVE-2026-16448 (CVE-2026-16448). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-5300 |
|
Vulnerability in CVE-2024-5300 (CVE-2024-5300)
vulnerability in CVE-2024-5300 (CVE-2024-5300). Confidential information can be exposed externally.
|
| CVE-2026-59850 |
|
Use-After-Free in libssh (CVE-2026-59850)
vulnerability in libssh (CVE-2026-59850). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59851 |
|
Authorization Flaw in libssh (CVE-2026-59851)
vulnerability in libssh (CVE-2026-59851). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11876 |
|
Vulnerability in CVE-2026-11876 (CVE-2026-11876)
vulnerability in CVE-2026-11876 (CVE-2026-11876). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/stack-deployment/stack`.
|
| CVE-2026-59847 |
|
Vulnerability in libssh (CVE-2026-59847)
vulnerability in libssh (CVE-2026-59847). Data can be tampered with by attackers.
|
| CVE-2025-66390 |
|
Vulnerability in CVE-2025-66390 (CVE-2025-66390)
vulnerability in CVE-2025-66390 (CVE-2025-66390). Successful exploitation can lead to full system takeover. Exploitable via `Host header`.
|
| CVE-2026-8285 |
|
Vulnerability in CVE-2026-8285 (CVE-2026-8285)
vulnerability in CVE-2026-8285 (CVE-2026-8285). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16412 |
|
Buffer Overflow in mozilla (CVE-2026-16412)
vulnerability in mozilla (CVE-2026-16412). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9499 |
|
Out-of-Bounds Read in dos (CVE-2026-9499)
vulnerability in dos (CVE-2026-9499). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16447 |
|
Vulnerability in CVE-2026-16447 (CVE-2026-16447)
vulnerability in CVE-2026-16447 (CVE-2026-16447). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59848 |
|
Vulnerability in dos (CVE-2026-59848)
vulnerability in dos (CVE-2026-59848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6792 |
|
Vulnerability in CVE-2026-6792 (CVE-2026-6792)
vulnerability in CVE-2026-6792 (CVE-2026-6792). Confidential information can be exposed externally.
|
| CVE-2026-16445 |
|
OS Command Injection in CVE-2026-16445 (CVE-2026-16445)
OS command injection in CVE-2026-16445 (CVE-2026-16445). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59846 |
|
Command Injection in libssh (CVE-2026-59846)
command injection in libssh (CVE-2026-59846). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8284 |
|
Open Redirect in CVE-2026-8284 (CVE-2026-8284)
vulnerability in CVE-2026-8284 (CVE-2026-8284). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16409 |
|
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153.
Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153.
|
| CVE-2026-16410 |
|
Vulnerability in mozilla (CVE-2026-16410)
vulnerability in mozilla (CVE-2026-16410). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16407 |
|
Vulnerability in mozilla (CVE-2026-16407)
vulnerability in mozilla (CVE-2026-16407). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16406 |
|
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
|