Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-61863 |
|
Vulnerability in imagemagick (CVE-2026-61863)
vulnerability in imagemagick (CVE-2026-61863). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61862 |
|
Out-of-Bounds Read in CVE-2026-61862 (CVE-2026-61862)
vulnerability in CVE-2026-61862 (CVE-2026-61862). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61860 |
|
Use-After-Free in dos (CVE-2026-61860)
vulnerability in dos (CVE-2026-61860). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61457 |
|
Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
vulnerability in CVE-2026-61457 (CVE-2026-61457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59236 |
|
Vulnerability in CVE-2026-59236 (CVE-2026-59236)
vulnerability in CVE-2026-59236 (CVE-2026-59236). Risk of unauthorized operations or information disclosure. Exploitable via `POST /customer/import/excel/save`.
|
| CVE-2026-61435 |
|
Authentication Bypass in CVE-2026-61435 (CVE-2026-61435)
authentication bypass in CVE-2026-61435 (CVE-2026-61435). Data can be tampered with by attackers. Exploitable via `GET /api/v1/agents`.
|
| CVE-2026-61436 |
|
Authentication Bypass in CVE-2026-61436 (CVE-2026-61436)
authentication bypass in CVE-2026-61436 (CVE-2026-61436). Data can be tampered with by attackers.
|
| CVE-2026-61433 |
|
Code Injection in CVE-2026-61433 (CVE-2026-61433)
code injection in CVE-2026-61433 (CVE-2026-61433). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60085 |
|
Vulnerability in CVE-2026-60085 (CVE-2026-60085)
vulnerability in CVE-2026-60085 (CVE-2026-60085). Confidential information can be exposed externally.
|
| CVE-2026-59254 |
|
Vulnerability in n8n (CVE-2026-59254)
vulnerability in n8n (CVE-2026-59254). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.27.4` or later.
|
| CVE-2026-61430 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61430)
SSRF in ssrf (CVE-2026-61430). Confidential information can be exposed externally.
|
| CVE-2026-61427 |
|
Vulnerability in CVE-2026-61427 (CVE-2026-61427)
vulnerability in CVE-2026-61427 (CVE-2026-61427). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
|
| CVE-2026-60087 |
|
Authorization Flaw in CVE-2026-60087 (CVE-2026-60087)
vulnerability in CVE-2026-60087 (CVE-2026-60087). Data can be tampered with by attackers.
|
| CVE-2026-59259 |
|
Vulnerability in n8n (CVE-2026-59259)
vulnerability in n8n (CVE-2026-59259). Confidential information can be exposed externally. Mitigation: upgrade to `2.27.4` or later.
|
| CVE-2026-57996 |
|
Privilege Escalation in privilege-escalation (CVE-2026-57996)
vulnerability in privilege-escalation (CVE-2026-57996). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/api/user/add`.
|
| CVE-2026-56339 |
|
Vulnerability in CVE-2026-56339 (CVE-2026-56339)
vulnerability in CVE-2026-56339 (CVE-2026-56339). Confidential information can be exposed externally.
|
| CVE-2026-58655 |
|
Code Injection in CVE-2026-58655 (CVE-2026-58655)
code injection in CVE-2026-58655 (CVE-2026-58655). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56764 |
|
Vulnerability in CVE-2026-56764 (CVE-2026-56764)
vulnerability in CVE-2026-56764 (CVE-2026-56764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56699 |
|
Vulnerability in CVE-2026-56699 (CVE-2026-56699)
vulnerability in CVE-2026-56699 (CVE-2026-56699). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56398 |
|
Vulnerability in openwebui (CVE-2026-56398)
vulnerability in openwebui (CVE-2026-56398). Confidential information can be exposed externally.
|
| CVE-2026-56400 |
|
Vulnerability in openwebui (CVE-2026-56400)
vulnerability in openwebui (CVE-2026-56400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56375 |
|
Vulnerability in dos (CVE-2026-56375)
vulnerability in dos (CVE-2026-56375). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56349 |
|
Vulnerability in CVE-2026-56349 (CVE-2026-56349)
vulnerability in CVE-2026-56349 (CVE-2026-56349). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56353 |
|
Authentication Bypass in n8n (CVE-2026-56353)
authentication bypass in n8n (CVE-2026-56353). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.123.22` or later.
|
| CVE-2026-56352 |
|
Path Traversal in CVE-2026-56352 (CVE-2026-56352)
path traversal in CVE-2026-56352 (CVE-2026-56352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8281 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-58077 |
|
Cross-Site Scripting (XSS) in CVE-2026-58077 (CVE-2026-58077)
cross-site scripting in CVE-2026-58077 (CVE-2026-58077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40633 |
|
Vulnerability in dell (CVE-2026-40633)
vulnerability in dell (CVE-2026-40633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57821 |
|
SQL Injection in apache (CVE-2026-57821)
SQL injection in apache (CVE-2026-57821). Confidential information can be exposed externally. Exploitable via `GET /api/v1/offices`.
|
| CVE-2026-57833 |
|
Cross-Site Scripting (XSS) in CVE-2026-57833 (CVE-2026-57833)
cross-site scripting in CVE-2026-57833 (CVE-2026-57833). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49501 |
|
Privilege Escalation in dell (CVE-2026-49501)
vulnerability in dell (CVE-2026-49501). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56287 |
|
SQL Injection in apache (CVE-2026-56287)
SQL injection in apache (CVE-2026-56287). Confidential information can be exposed externally. Exploitable via `GET /api/v1/clients`.
|
| CVE-2026-59235 |
|
Vulnerability in CVE-2026-59235 (CVE-2026-59235)
vulnerability in CVE-2026-59235 (CVE-2026-59235). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/bank-account`.
|
| CVE-2026-35152 |
|
SQL Injection in apache (CVE-2026-35152)
SQL injection in apache (CVE-2026-35152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57831 |
|
The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
|
| CVE-2026-14251 |
|
Vulnerability in dos (CVE-2026-14251)
vulnerability in dos (CVE-2026-14251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57832 |
|
The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
|
| CVE-2026-15583 |
|
Vulnerability in ssrf (CVE-2026-15583)
vulnerability in ssrf (CVE-2026-15583). Confidential information can be exposed externally.
|
| CVE-2026-15804 |
|
SQL Injection in sqli (CVE-2026-15804)
SQL injection in sqli (CVE-2026-15804). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42936 |
|
Vulnerability in jvn (CVE-2026-42936)
vulnerability in jvn (CVE-2026-42936). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12512 |
|
SQL Injection in wordpress (CVE-2026-12512)
SQL injection in wordpress (CVE-2026-12512). Confidential information can be exposed externally.
|
| CVE-2026-12281 |
|
Authentication Bypass in wordpress (CVE-2026-12281)
authentication bypass in wordpress (CVE-2026-12281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11579 |
|
Unrestricted File Upload in wordpress (CVE-2026-11579)
vulnerability in wordpress (CVE-2026-11579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11580 |
|
Vulnerability in wordpress (CVE-2026-11580)
vulnerability in wordpress (CVE-2026-11580). Confidential information can be exposed externally.
|
| CVE-2026-13385 |
|
Vulnerability in CVE-2026-13385 (CVE-2026-13385)
vulnerability in CVE-2026-13385 (CVE-2026-13385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8919 |
|
Vulnerability in CVE-2026-8919 (CVE-2026-8919)
vulnerability in CVE-2026-8919 (CVE-2026-8919). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11851 |
|
SQL Injection in sqli (CVE-2026-11851)
SQL injection in sqli (CVE-2026-11851). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8920 |
|
Vulnerability in CVE-2026-8920 (CVE-2026-8920)
vulnerability in CVE-2026-8920 (CVE-2026-8920). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13585 |
|
Vulnerability in dos (CVE-2026-13585)
vulnerability in dos (CVE-2026-13585). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15030 |
|
Out-of-Bounds Read in CVE-2026-15030 (CVE-2026-15030)
vulnerability in CVE-2026-15030 (CVE-2026-15030). Risk of unauthorized operations or information disclosure.
|