Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-51080 XXE (XML External Entity) in proxmox (CVE-2026-51080)
vulnerability in proxmox (CVE-2026-51080). Successful exploitation can lead to full system takeover.
CVE-2024-23564 Vulnerability in CVE-2024-23564 (CVE-2024-23564)
vulnerability in CVE-2024-23564 (CVE-2024-23564). Confidential information can be exposed externally.
CVE-2026-9810 Privilege Escalation in wordpress (CVE-2026-9810)
vulnerability in wordpress (CVE-2026-9810). Successful exploitation can lead to full system takeover.
CVE-2026-15982 Privilege Escalation in wordpress (CVE-2026-15982)
vulnerability in wordpress (CVE-2026-15982). Successful exploitation can lead to full system takeover.
CVE-2026-62241 Vulnerability in mohibshaikh (CVE-2026-62241)
vulnerability in mohibshaikh (CVE-2026-62241). Confidential information can be exposed externally. Exploitable via `GET /api/v1/scans`.
CVE-2026-14956 Privilege Escalation in wordpress (CVE-2026-14956)
vulnerability in wordpress (CVE-2026-14956). Successful exploitation can lead to full system takeover.
CVE-2026-57075 Out-of-Bounds Read in CVE-2026-57075 (CVE-2026-57075)
vulnerability in CVE-2026-57075 (CVE-2026-57075). Confidential information can be exposed externally.
CVE-2026-53412 Vulnerability in zoom (CVE-2026-53412)
vulnerability in zoom (CVE-2026-53412). Successful exploitation can lead to full system takeover.
CVE-2026-38158 SQL Injection in sqli (CVE-2026-38158)
SQL injection in sqli (CVE-2026-38158). Successful exploitation can lead to full system takeover.
CVE-2026-63089 Vulnerability in CVE-2026-63089 (CVE-2026-63089)
vulnerability in CVE-2026-63089 (CVE-2026-63089). Confidential information can be exposed externally.
CVE-2026-55579 Vulnerability in pheditor/pheditor (CVE-2026-55579)
vulnerability in pheditor/pheditor (CVE-2026-55579). Successful exploitation can lead to full system takeover. Exploitable via ``admin``. Mitigation: upgrade to `2.0.6` or later.
CVE-2026-54526 Vulnerability in github.com/argoproj/argo-workflows/v4 (CVE-2026-54526)
vulnerability in github.com/argoproj/argo-workflows/v4 (CVE-2026-54526). Successful exploitation can lead to full system takeover. Exploitable via ``hostNetwork``. Mitigation: upgrade to `4.0.6` or later.
CVE-2026-46512 Code Injection in CVE-2026-46512 (CVE-2026-46512)
code injection in CVE-2026-46512 (CVE-2026-46512). Successful exploitation can lead to full system takeover.
CVE-2026-45336 Vulnerability in flask (CVE-2026-45336)
vulnerability in flask (CVE-2026-45336). Confidential information can be exposed externally.
CVE-2026-57074 Out-of-Bounds Read in CVE-2026-57074 (CVE-2026-57074)
vulnerability in CVE-2026-57074 (CVE-2026-57074). Confidential information can be exposed externally.
CVE-2026-63087 Vulnerability in CVE-2026-63087 (CVE-2026-63087)
vulnerability in CVE-2026-63087 (CVE-2026-63087). Successful exploitation can lead to full system takeover.
CVE-2026-57073 Out-of-Bounds Read in CVE-2026-57073 (CVE-2026-57073)
vulnerability in CVE-2026-57073 (CVE-2026-57073). Confidential information can be exposed externally.
CVE-2026-3031 Vulnerability in CVE-2026-3031 (CVE-2026-3031)
vulnerability in CVE-2026-3031 (CVE-2026-3031). Successful exploitation can lead to full system takeover.
CVE-2026-14890 Unsafe Deserialization in deserialization (CVE-2026-14890)
vulnerability in deserialization (CVE-2026-14890). Confidential information can be exposed externally.
CVE-2026-11386 Vulnerability in CVE-2026-11386 (CVE-2026-11386)
vulnerability in CVE-2026-11386 (CVE-2026-11386). Successful exploitation can lead to full system takeover.
CVE-2023-49900 OS Command Injection in CVE-2023-49900 (CVE-2023-49900)
OS command injection in CVE-2023-49900 (CVE-2023-49900). Successful exploitation can lead to full system takeover.
CVE-2023-49899 Vulnerability in CVE-2023-49899 (CVE-2023-49899)
vulnerability in CVE-2023-49899 (CVE-2023-49899). Successful exploitation can lead to full system takeover.
CVE-2026-22752 Authentication Bypass in CVE-2026-22752 (CVE-2026-22752)
authentication bypass in CVE-2026-22752 (CVE-2026-22752). Confidential information can be exposed externally.
CVE-2026-12492 Authentication Bypass in wordpress (CVE-2026-12492)
authentication bypass in wordpress (CVE-2026-12492). Successful exploitation can lead to full system takeover.
CVE-2026-15013 Vulnerability in wordpress (CVE-2026-15013)
vulnerability in wordpress (CVE-2026-15013). Successful exploitation can lead to full system takeover. Exploitable via ``SignatureMethod``.
CVE-2026-39808 KEV [KEV] OS Command Injection in Fortinet fortisandbox (CVE-2026-39808)
OS command injection in Fortinet fortisandbox (CVE-2026-39808). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-55652 Authentication Bypass in CVE-2026-55652 (CVE-2026-55652)
authentication bypass in CVE-2026-55652 (CVE-2026-55652). Successful exploitation can lead to full system takeover.
CVE-2026-52891 OS Command Injection in CVE-2026-52891 (CVE-2026-52891)
OS command injection in CVE-2026-52891 (CVE-2026-52891). Successful exploitation can lead to full system takeover.
CVE-2026-30618 Code Injection in CVE-2026-30618 (CVE-2026-30618)
code injection in CVE-2026-30618 (CVE-2026-30618). Successful exploitation can lead to full system takeover.
CVE-2026-30623 Command Injection in c (CVE-2026-30623)
command injection in c (CVE-2026-30623). Successful exploitation can lead to full system takeover.
CVE-2026-26718 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-26718)
vulnerability in csrf (CVE-2026-26718). Confidential information can be exposed externally.
CVE-2025-65720 Command Injection in CVE-2025-65720 (CVE-2025-65720)
command injection in CVE-2025-65720 (CVE-2025-65720). Successful exploitation can lead to full system takeover.
CVE-2026-51380 Vulnerability in dos (CVE-2026-51380)
vulnerability in dos (CVE-2026-51380). Successful exploitation can lead to full system takeover.
CVE-2026-52887 SQL Injection in @nocobase/plugin-notification-in-app-message (CVE-2026-52887)
SQL injection in @nocobase/plugin-notification-in-app-message (CVE-2026-52887). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/myInAppChannels`. Mitigation: upgrade to `2.0.61` or later.
CVE-2026-14960 Privilege Escalation in CVE-2026-14960 (CVE-2026-14960)
vulnerability in CVE-2026-14960 (CVE-2026-14960). Successful exploitation can lead to full system takeover. Exploitable via ``Tdelo64.sys``.
CVE-2026-62948 Cross-Site Scripting (XSS) in c (CVE-2026-62948)
cross-site scripting in c (CVE-2026-62948). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `25.12.5` or later.
CVE-2026-62378 Cross-Site Scripting (XSS) in CVE-2026-62378 (CVE-2026-62378)
cross-site scripting in CVE-2026-62378 (CVE-2026-62378). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.10` or later.
CVE-2026-52842 Vulnerability in CVE-2026-52842 (CVE-2026-52842)
vulnerability in CVE-2026-52842 (CVE-2026-52842). Confidential information can be exposed externally.
CVE-2026-52843 Vulnerability in CVE-2026-52843 (CVE-2026-52843)
vulnerability in CVE-2026-52843 (CVE-2026-52843). Confidential information can be exposed externally.
CVE-2026-50148 Vulnerability in metabase (CVE-2026-50148)
vulnerability in metabase (CVE-2026-50148). Successful exploitation can lead to full system takeover.
CVE-2026-44986 Authentication Bypass in CVE-2026-44986 (CVE-2026-44986)
authentication bypass in CVE-2026-44986 (CVE-2026-44986). Successful exploitation can lead to full system takeover.
CVE-2026-43637 Path Traversal in path-traversal (CVE-2026-43637)
path traversal in path-traversal (CVE-2026-43637). Data can be tampered with by attackers.
CVE-2026-61736 Vulnerability in lightrag-hku (CVE-2026-61736)
vulnerability in lightrag-hku (CVE-2026-61736). Confidential information can be exposed externally. Mitigation: upgrade to `1.5.4` or later.
CVE-2026-61451 Open Redirect in CVE-2026-61451 (CVE-2026-61451)
vulnerability in CVE-2026-61451 (CVE-2026-61451). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/auth/forgot-password`.
CVE-2026-56699 Vulnerability in CVE-2026-56699 (CVE-2026-56699)
vulnerability in CVE-2026-56699 (CVE-2026-56699). Successful exploitation can lead to full system takeover.
CVE-2026-5269 Vulnerability in CVE-2026-5269 (CVE-2026-5269)
vulnerability in CVE-2026-5269 (CVE-2026-5269). Successful exploitation can lead to full system takeover.
CVE-2026-5270 Authentication Bypass in CVE-2026-5270 (CVE-2026-5270)
authentication bypass in CVE-2026-5270 (CVE-2026-5270). Successful exploitation can lead to full system takeover.
CVE-2026-51808 Vulnerability in cpp (CVE-2026-51808)
vulnerability in cpp (CVE-2026-51808). Successful exploitation can lead to full system takeover.
CVE-2026-51807 Vulnerability in cpp (CVE-2026-51807)
vulnerability in cpp (CVE-2026-51807). Successful exploitation can lead to full system takeover.
CVE-2026-48334 Vulnerability in adobe (CVE-2026-48334)
vulnerability in adobe (CVE-2026-48334). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →