Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-56260 |
|
Path Traversal in dos (CVE-2026-56260)
path traversal in dos (CVE-2026-56260). Data can be tampered with by attackers.
|
| CVE-2026-61447 |
|
Code Injection in CVE-2026-61447 (CVE-2026-61447)
code injection in CVE-2026-61447 (CVE-2026-61447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61445 |
|
Path Traversal in CVE-2026-61445 (CVE-2026-61445)
path traversal in CVE-2026-61445 (CVE-2026-61445). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60090 |
|
SQL Injection in CVE-2026-60090 (CVE-2026-60090)
SQL injection in CVE-2026-60090 (CVE-2026-60090). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57827 |
|
Unrestricted File Upload in rsjoomla (CVE-2026-57827)
vulnerability in rsjoomla (CVE-2026-57827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15089 |
|
Authentication Bypass in drupal/commerce_guest_registration (CVE-2026-15089)
authentication bypass in drupal/commerce_guest_registration (CVE-2026-15089). Confidential information can be exposed externally.
|
| CVE-2026-12535 |
|
Vulnerability in drupal/formatter_field (CVE-2026-12535)
vulnerability in drupal/formatter_field (CVE-2026-12535). Successful exploitation can lead to full system takeover. Exploitable via ``formatter_field``. Mitigation: upgrade to `2.0.0` or later.
|
| CVE-2026-57807 |
|
Vulnerability in CVE-2026-57807 (CVE-2026-57807)
vulnerability in CVE-2026-57807 (CVE-2026-57807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12761 |
|
Authentication Bypass in wordpress (CVE-2026-12761)
authentication bypass in wordpress (CVE-2026-12761). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55879 |
|
Cross-Site Scripting (XSS) in CVE-2026-55879 (CVE-2026-55879)
cross-site scripting in CVE-2026-55879 (CVE-2026-55879). Confidential information can be exposed externally.
|
| CVE-2026-54159 |
|
Vulnerability in prestashop/ps_facetedsearch (CVE-2026-54159)
vulnerability in prestashop/ps_facetedsearch (CVE-2026-54159). Successful exploitation can lead to full system takeover. Exploitable via ``ps_facetedsearch``. Mitigation: upgrade to `4.0.4` or later.
|
| CVE-2026-57156 |
|
Vulnerability in c (CVE-2026-57156)
vulnerability in c (CVE-2026-57156). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57158 |
|
Out-of-Bounds Read in c (CVE-2026-57158)
vulnerability in c (CVE-2026-57158). Confidential information can be exposed externally.
|
| CVE-2026-61459 |
|
Vulnerability in mcp-server-kubernetes (CVE-2026-61459)
vulnerability in mcp-server-kubernetes (CVE-2026-61459). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.0` or later.
|
| CVE-2026-5801 |
|
SQL Injection in sqli (CVE-2026-5801)
SQL injection in sqli (CVE-2026-5801). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59151 |
|
Authentication Bypass in prowler (CVE-2026-59151)
authentication bypass in prowler (CVE-2026-59151). Confidential information can be exposed externally.
|
| CVE-2026-2397 |
|
SQL Injection in sqli (CVE-2026-2397)
SQL injection in sqli (CVE-2026-2397). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51119 |
|
Privilege Escalation in CVE-2026-51119 (CVE-2026-51119)
vulnerability in CVE-2026-51119 (CVE-2026-51119). Confidential information can be exposed externally.
|
| CVE-2026-15143 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15143 (CVE-2026-15143)
SSRF in CVE-2026-15143 (CVE-2026-15143). Confidential information can be exposed externally.
|
| CVE-2026-61444 |
|
Code Injection in CVE-2026-61444 (CVE-2026-61444)
code injection in CVE-2026-61444 (CVE-2026-61444). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59792 |
|
Vulnerability in path-traversal (CVE-2026-59792)
vulnerability in path-traversal (CVE-2026-59792). Confidential information can be exposed externally.
|
| CVE-2026-56765 |
|
Vulnerability in CVE-2026-56765 (CVE-2026-56765)
vulnerability in CVE-2026-56765 (CVE-2026-56765). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56688 |
|
OS Command Injection in dell (CVE-2026-56688)
OS command injection in dell (CVE-2026-56688). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53363 |
|
Vulnerability in linux (CVE-2026-53363)
vulnerability in linux (CVE-2026-53363). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15378 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-15378)
SSRF in ssrf (CVE-2026-15378). Confidential information can be exposed externally.
|
| CVE-2026-40008 |
|
Vulnerability in c (CVE-2026-40008)
vulnerability in c (CVE-2026-40008). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40005 |
|
Path Traversal in apache (CVE-2026-40005)
path traversal in apache (CVE-2026-40005). Confidential information can be exposed externally.
|
| CVE-2026-28564 |
|
Vulnerability in apache (CVE-2026-28564)
vulnerability in apache (CVE-2026-28564). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15300 |
|
SQL Injection in wordpress (CVE-2026-15300)
SQL injection in wordpress (CVE-2026-15300). Data can be tampered with by attackers. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-15282 |
|
Unrestricted File Upload in wordpress (CVE-2026-15282)
vulnerability in wordpress (CVE-2026-15282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14894 |
|
Unrestricted File Upload in wordpress (CVE-2026-14894)
vulnerability in wordpress (CVE-2026-14894). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58122 |
|
Vulnerability in CVE-2026-58122 (CVE-2026-58122)
vulnerability in CVE-2026-58122 (CVE-2026-58122). Confidential information can be exposed externally.
|
| CVE-2026-58123 |
|
Vulnerability in CVE-2026-58123 (CVE-2026-58123)
vulnerability in CVE-2026-58123 (CVE-2026-58123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0284 |
|
Vulnerability in paloaltonetworks (CVE-2026-0284)
vulnerability in paloaltonetworks (CVE-2026-0284). Confidential information can be exposed externally.
|
| CVE-2026-51599 |
|
Vulnerability in CVE-2026-51599 (CVE-2026-51599)
vulnerability in CVE-2026-51599 (CVE-2026-51599). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13461 |
|
Vulnerability in CVE-2026-13461 (CVE-2026-13461)
vulnerability in CVE-2026-13461 (CVE-2026-13461). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51597 |
|
Vulnerability in CVE-2026-51597 (CVE-2026-51597)
vulnerability in CVE-2026-51597 (CVE-2026-51597). Confidential information can be exposed externally.
|
| CVE-2026-59826 |
|
Code Injection in metabase (CVE-2026-59826)
code injection in metabase (CVE-2026-59826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59827 |
|
Unsafe Deserialization in metabase (CVE-2026-59827)
vulnerability in metabase (CVE-2026-59827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59726 |
|
OS Command Injection in CVE-2026-59726 (CVE-2026-59726)
OS command injection in CVE-2026-59726 (CVE-2026-59726). Successful exploitation can lead to full system takeover. Exploitable via `POST /mcp`.
|
| CVE-2026-14480 |
|
Vulnerability in cisa (CVE-2026-14480)
vulnerability in cisa (CVE-2026-14480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14261 |
|
Vulnerability in CVE-2026-14261 (CVE-2026-14261)
vulnerability in CVE-2026-14261 (CVE-2026-14261). Confidential information can be exposed externally.
|
| CVE-2026-12116 |
|
Vulnerability in CVE-2026-12116 (CVE-2026-12116)
vulnerability in CVE-2026-12116 (CVE-2026-12116). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56291 KEV |
|
[KEV] Unrestricted File Upload in Balbooa forms (CVE-2026-56291)
vulnerability in Balbooa forms (CVE-2026-56291). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-5955 |
|
SQL Injection in sqli (CVE-2026-5955)
SQL injection in sqli (CVE-2026-5955). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15158 |
|
Unrestricted File Upload in wordpress (CVE-2026-15158)
vulnerability in wordpress (CVE-2026-15158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2342 |
|
Cross-Site Scripting (XSS) in CVE-2026-2342 (CVE-2026-2342)
cross-site scripting in CVE-2026-2342 (CVE-2026-2342). Confidential information can be exposed externally.
|
| CVE-2026-14245 |
|
Vulnerability in wordpress (CVE-2026-14245)
vulnerability in wordpress (CVE-2026-14245). Successful exploitation can lead to full system takeover. Exploitable via ``form_nonce``.
|
| CVE-2026-47826 |
|
Path Traversal in cloudfoundry (CVE-2026-47826)
path traversal in cloudfoundry (CVE-2026-47826). Confidential information can be exposed externally.
|
| CVE-2026-47646 |
|
Cross-Site Scripting (XSS) in microsoft (CVE-2026-47646)
cross-site scripting in microsoft (CVE-2026-47646). Confidential information can be exposed externally.
|