Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-78939 Use-After-Free in google (CVE-2026-78939)
vulnerability in google (CVE-2026-78939). Successful exploitation can lead to full system takeover.
CVE-2026-78937 Use-After-Free in c (CVE-2026-78937)
vulnerability in c (CVE-2026-78937). Successful exploitation can lead to full system takeover.
CVE-2026-78909 Use-After-Free in google (CVE-2026-78909)
vulnerability in google (CVE-2026-78909). Successful exploitation can lead to full system takeover.
CVE-2026-78900 Vulnerability in google (CVE-2026-78900)
vulnerability in google (CVE-2026-78900). Successful exploitation can lead to full system takeover.
CVE-2026-78904 Vulnerability in google (CVE-2026-78904)
vulnerability in google (CVE-2026-78904). Successful exploitation can lead to full system takeover.
CVE-2026-78935 Vulnerability in google (CVE-2026-78935)
vulnerability in google (CVE-2026-78935). Successful exploitation can lead to full system takeover.
CVE-2026-65093 Vulnerability in CVE-2026-65093 (CVE-2026-65093)
vulnerability in CVE-2026-65093 (CVE-2026-65093). Successful exploitation can lead to full system takeover.
CVE-2026-65083 Vulnerability in dos (CVE-2026-65083)
vulnerability in dos (CVE-2026-65083). Successful exploitation can lead to full system takeover.
CVE-2026-79787 Authentication Bypass in CVE-2026-79787 (CVE-2026-79787)
authentication bypass in CVE-2026-79787 (CVE-2026-79787). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`.
CVE-2026-79282 Use-After-Free in Google chrome (CVE-2026-79282)
vulnerability in Google chrome (CVE-2026-79282). Successful exploitation can lead to full system takeover.
CVE-2026-73125 Vulnerability in cisa (CVE-2026-73125)
vulnerability in cisa (CVE-2026-73125). Successful exploitation can lead to full system takeover.
CVE-2026-45018 OS Command Injection in chainlit (CVE-2026-45018)
OS command injection in chainlit (CVE-2026-45018). Successful exploitation can lead to full system takeover. Exploitable via `POST /mcp`. Mitigation: upgrade to `2.12.0` or later.
CVE-2026-76193 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-76193)
SSRF in ssrf (CVE-2026-76193). Successful exploitation can lead to full system takeover.
CVE-2026-76197 OS Command Injection in CVE-2026-76197 (CVE-2026-76197)
OS command injection in CVE-2026-76197 (CVE-2026-76197). Successful exploitation can lead to full system takeover.
CVE-2026-76195 OS Command Injection in CVE-2026-76195 (CVE-2026-76195)
OS command injection in CVE-2026-76195 (CVE-2026-76195). Successful exploitation can lead to full system takeover.
CVE-2026-79675 Vulnerability in CVE-2026-79675 (CVE-2026-79675)
vulnerability in CVE-2026-79675 (CVE-2026-79675). Successful exploitation can lead to full system takeover.
CVE-2025-71407 Out-of-Bounds Write in dos (CVE-2025-71407)
out-of-bounds write in dos (CVE-2025-71407). Successful exploitation can lead to full system takeover.
CVE-2024-58378 Use-After-Free in CVE-2024-58378 (CVE-2024-58378)
vulnerability in CVE-2024-58378 (CVE-2024-58378). Successful exploitation can lead to full system takeover.
CVE-2022-51000 Use-After-Free in dos (CVE-2022-51000)
vulnerability in dos (CVE-2022-51000). Successful exploitation can lead to full system takeover.
CVE-2026-55640 Vulnerability in nextcloud-mcp-server (CVE-2026-55640)
vulnerability in nextcloud-mcp-server (CVE-2026-55640). Data can be tampered with by attackers. Exploitable via `POST /webhooks/nextcloud`. Mitigation: upgrade to `0.117.2` or later.
CVE-2026-16286 Unrestricted File Upload in CVE-2026-16286 (CVE-2026-16286)
vulnerability in CVE-2026-16286 (CVE-2026-16286). Successful exploitation can lead to full system takeover.
CVE-2026-55546 Code Injection in qwed-mcp (CVE-2026-55546)
code injection in qwed-mcp (CVE-2026-55546). Successful exploitation can lead to full system takeover. Exploitable via ``global_dict``. Mitigation: upgrade to `0.2.1` or later.
CVE-2026-55536 Vulnerability in PraisonAI (CVE-2026-55536)
vulnerability in PraisonAI (CVE-2026-55536). Confidential information can be exposed externally. Exploitable via ``start_session``. Mitigation: upgrade to `4.6.58` or later.
CVE-2026-79657 Unsafe Deserialization in CVE-2026-79657 (CVE-2026-79657)
vulnerability in CVE-2026-79657 (CVE-2026-79657). Successful exploitation can lead to full system takeover.
CVE-2026-49845 Code Injection in apache (CVE-2026-49845)
code injection in apache (CVE-2026-49845). Successful exploitation can lead to full system takeover.
CVE-2026-55976 SSRF (Server-Side Request Forgery) in apache (CVE-2026-55976)
SSRF in apache (CVE-2026-55976). Confidential information can be exposed externally.
CVE-2026-78570 Privilege Escalation in wordpress (CVE-2026-78570)
vulnerability in wordpress (CVE-2026-78570). Successful exploitation can lead to full system takeover.
CVE-2026-78568 SQL Injection in wordpress (CVE-2026-78568)
SQL injection in wordpress (CVE-2026-78568). Successful exploitation can lead to full system takeover.
CVE-2026-63586 OS Command Injection in CVE-2026-63586 (CVE-2026-63586)
OS command injection in CVE-2026-63586 (CVE-2026-63586). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`.
CVE-2026-59769 Vulnerability in cisa (CVE-2026-59769)
vulnerability in cisa (CVE-2026-59769). Data can be tampered with by attackers.
CVE-2026-78477 Vulnerability in wordpress (CVE-2026-78477)
vulnerability in wordpress (CVE-2026-78477). Successful exploitation can lead to full system takeover.
CVE-2026-13214 Out-of-Bounds Write in c (CVE-2026-13214)
out-of-bounds write in c (CVE-2026-13214). Successful exploitation can lead to full system takeover.
CVE-2026-78683 Unsafe Deserialization in deserialization (CVE-2026-78683)
vulnerability in deserialization (CVE-2026-78683). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
CVE-2026-78676 Vulnerability in CVE-2026-78676 (CVE-2026-78676)
vulnerability in CVE-2026-78676 (CVE-2026-78676). Successful exploitation can lead to full system takeover.
CVE-2026-56710 Authorization Flaw in CVE-2026-56710 (CVE-2026-56710)
vulnerability in CVE-2026-56710 (CVE-2026-56710). Successful exploitation can lead to full system takeover.
CVE-2026-56705 Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
CVE-2026-60004 KEV [KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-78267 Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78265 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78262 Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-32563 Unsafe Deserialization in wordpress (CVE-2026-32563)
vulnerability in wordpress (CVE-2026-32563). Successful exploitation can lead to full system takeover.
CVE-2026-32559 Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CVE-2026-32555 Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
CVE-2026-32554 Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
CVE-2026-52490 Code Injection in c (CVE-2026-52490)
code injection in c (CVE-2026-52490). Successful exploitation can lead to full system takeover.
CVE-2026-76835 Vulnerability in CVE-2026-76835 (CVE-2026-76835)
vulnerability in CVE-2026-76835 (CVE-2026-76835). Confidential information can be exposed externally.
CVE-2026-71933 Vulnerability in CVE-2026-71933 (CVE-2026-71933)
vulnerability in CVE-2026-71933 (CVE-2026-71933). Data can be tampered with by attackers.
CVE-2026-71921 OS Command Injection in CVE-2026-71921 (CVE-2026-71921)
OS command injection in CVE-2026-71921 (CVE-2026-71921). Successful exploitation can lead to full system takeover.
CVE-2026-71914 OS Command Injection in CVE-2026-71914 (CVE-2026-71914)
OS command injection in CVE-2026-71914 (CVE-2026-71914). Successful exploitation can lead to full system takeover.
CVE-2026-78329 Vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329)
vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →