Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-15113 Use-After-Free in google (CVE-2026-15113)
vulnerability in google (CVE-2026-15113). Successful exploitation can lead to full system takeover.
CVE-2026-52200 Code Injection in CVE-2026-52200 (CVE-2026-52200)
code injection in CVE-2026-52200 (CVE-2026-52200). Successful exploitation can lead to full system takeover.
CVE-2026-31309 Vulnerability in CVE-2026-31309 (CVE-2026-31309)
vulnerability in CVE-2026-31309 (CVE-2026-31309). Successful exploitation can lead to full system takeover.
CVE-2026-9074 SQL Injection in sqli (CVE-2026-9074)
SQL injection in sqli (CVE-2026-9074). Confidential information can be exposed externally.
CVE-2026-59702 SSRF (Server-Side Request Forgery) in CVE-2026-59702 (CVE-2026-59702)
SSRF in CVE-2026-59702 (CVE-2026-59702). Confidential information can be exposed externally. Exploitable via `POST /api/pack`.
CVE-2026-15062 SQL Injection in sqli (CVE-2026-15062)
SQL injection in sqli (CVE-2026-15062). Confidential information can be exposed externally.
CVE-2026-58480 Unrestricted File Upload in wordpress (CVE-2026-58480)
vulnerability in wordpress (CVE-2026-58480). Successful exploitation can lead to full system takeover.
CVE-2026-54061 Vulnerability in github.com/dgraph-io/dgraph/v25 (CVE-2026-54061)
vulnerability in github.com/dgraph-io/dgraph/v25 (CVE-2026-54061). Data can be tampered with by attackers. Exploitable via ``StreamExtSnapshot``. Mitigation: upgrade to `25.3.5` or later.
CVE-2026-8307 SQL Injection in sqli (CVE-2026-8307)
SQL injection in sqli (CVE-2026-8307). Successful exploitation can lead to full system takeover.
CVE-2026-14454 Vulnerability in tonycoz (CVE-2026-14454)
vulnerability in tonycoz (CVE-2026-14454). Successful exploitation can lead to full system takeover.
CVE-2026-41042 Vulnerability in apache (CVE-2026-41042)
vulnerability in apache (CVE-2026-41042). Confidential information can be exposed externally.
CVE-2026-9695 Authentication Bypass in CVE-2026-9695 (CVE-2026-9695)
authentication bypass in CVE-2026-9695 (CVE-2026-9695). Successful exploitation can lead to full system takeover.
CVE-2026-12153 Vulnerability in wordpress (CVE-2026-12153)
vulnerability in wordpress (CVE-2026-12153). Successful exploitation can lead to full system takeover.
CVE-2026-9701 Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
CVE-2026-14487 Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
CVE-2026-56843 Vulnerability in c (CVE-2026-56843)
vulnerability in c (CVE-2026-56843). Successful exploitation can lead to full system takeover.
CVE-2026-59705 Vulnerability in CVE-2026-59705 (CVE-2026-59705)
vulnerability in CVE-2026-59705 (CVE-2026-59705). Successful exploitation can lead to full system takeover.
CVE-2026-37271 Authentication Bypass in CVE-2026-37271 (CVE-2026-37271)
authentication bypass in CVE-2026-37271 (CVE-2026-37271). Successful exploitation can lead to full system takeover.
CVE-2026-14740 Out-of-Bounds Read in perl (CVE-2026-14740)
vulnerability in perl (CVE-2026-14740). Confidential information can be exposed externally.
CVE-2026-14739 Out-of-Bounds Write in perl (CVE-2026-14739)
out-of-bounds write in perl (CVE-2026-14739). Successful exploitation can lead to full system takeover.
CVE-2026-37270 Authentication Bypass in CVE-2026-37270 (CVE-2026-37270)
authentication bypass in CVE-2026-37270 (CVE-2026-37270). Successful exploitation can lead to full system takeover.
CVE-2026-59706 Vulnerability in ssrf (CVE-2026-59706)
vulnerability in ssrf (CVE-2026-59706). Confidential information can be exposed externally. Exploitable via `GET /api/v1/config/`.
CVE-2026-58473 Vulnerability in CVE-2026-58473 (CVE-2026-58473)
vulnerability in CVE-2026-58473 (CVE-2026-58473). Confidential information can be exposed externally.
CVE-2026-53513 Vulnerability in @better-auth/sso (CVE-2026-53513)
vulnerability in @better-auth/sso (CVE-2026-53513). Confidential information can be exposed externally. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-53512 Authentication Bypass in better-auth (CVE-2026-53512)
authentication bypass in better-auth (CVE-2026-53512). Confidential information can be exposed externally. Exploitable via ``oauthApplication``. Mitigation: upgrade to `1.6.11` or later.
CVE-2026-13019 Vulnerability in esri (CVE-2026-13019)
vulnerability in esri (CVE-2026-13019). Successful exploitation can lead to full system takeover.
CVE-2026-20744 Vulnerability in cisa (CVE-2026-20744)
vulnerability in cisa (CVE-2026-20744). Successful exploitation can lead to full system takeover.
CVE-2026-53481 Path Traversal in path-traversal (CVE-2026-53481)
path traversal in path-traversal (CVE-2026-53481). Successful exploitation can lead to full system takeover.
CVE-2026-53483 Authentication Bypass in dell (CVE-2026-53483)
authentication bypass in dell (CVE-2026-53483). Successful exploitation can lead to full system takeover.
CVE-2011-10043 Vulnerability in CVE-2011-10043 (CVE-2011-10043)
vulnerability in CVE-2011-10043 (CVE-2011-10043). Successful exploitation can lead to full system takeover.
CVE-2026-33264 Unsafe Deserialization in apache (CVE-2026-33264)
vulnerability in apache (CVE-2026-33264). Successful exploitation can lead to full system takeover.
CVE-2026-12375 Vulnerability in wordpress (CVE-2026-12375)
vulnerability in wordpress (CVE-2026-12375). Successful exploitation can lead to full system takeover.
CVE-2026-14345 Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
CVE-2026-4375 Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
CVE-2026-34047 Authorization Flaw in CVE-2026-34047 (CVE-2026-34047)
vulnerability in CVE-2026-34047 (CVE-2026-34047). Successful exploitation can lead to full system takeover.
CVE-2026-34037 Vulnerability in CVE-2026-34037 (CVE-2026-34037)
vulnerability in CVE-2026-34037 (CVE-2026-34037). Confidential information can be exposed externally.
CVE-2026-34048 Vulnerability in CVE-2026-34048 (CVE-2026-34048)
vulnerability in CVE-2026-34048 (CVE-2026-34048). Successful exploitation can lead to full system takeover.
CVE-2026-55500 Information Disclosure in 9router (CVE-2026-55500)
vulnerability in 9router (CVE-2026-55500). Successful exploitation can lead to full system takeover. Exploitable via ``ALWAYS_PROTECTED``.
CVE-2026-54496 Vulnerability in zebrad (CVE-2026-54496)
vulnerability in zebrad (CVE-2026-54496). Data can be tampered with by attackers. Exploitable via ``halo2_gadgets``. Mitigation: upgrade to `5.0.0` or later.
CVE-2026-57572 Vulnerability in kidocode (CVE-2026-57572)
vulnerability in kidocode (CVE-2026-57572). Successful exploitation can lead to full system takeover.
CVE-2026-57571 Path Traversal in kidocode (CVE-2026-57571)
path traversal in kidocode (CVE-2026-57571). Successful exploitation can lead to full system takeover.
CVE-2026-54763 Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763). Confidential information can be exposed externally. Exploitable via ``X_Auth_User``. Mitigation: upgrade to `2.11.42` or later.
CVE-2026-34038 OS Command Injection in CVE-2026-34038 (CVE-2026-34038)
OS command injection in CVE-2026-34038 (CVE-2026-34038). Successful exploitation can lead to full system takeover.
CVE-2026-54769 Code Injection in langroid (CVE-2026-54769)
code injection in langroid (CVE-2026-54769). Successful exploitation can lead to full system takeover. Exploitable via ``TableChatAgent``. Mitigation: upgrade to `0.65.2` or later.
CVE-2026-53486 Path Traversal in @xhmikosr/decompress (CVE-2026-53486)
path traversal in @xhmikosr/decompress (CVE-2026-53486). Confidential information can be exposed externally. Exploitable via ``path.relative``. Mitigation: upgrade to `11.1.3` or later.
CVE-2026-11405 Vulnerability in CVE-2026-11405 (CVE-2026-11405)
vulnerability in CVE-2026-11405 (CVE-2026-11405). Successful exploitation can lead to full system takeover.
CVE-2026-9182 Unrestricted File Upload in esri (CVE-2026-9182)
vulnerability in esri (CVE-2026-9182). Successful exploitation can lead to full system takeover.
CVE-2026-9181 Path Traversal in path-traversal (CVE-2026-9181)
path traversal in path-traversal (CVE-2026-9181). Successful exploitation can lead to full system takeover.
CVE-2026-48614 Code Injection in privilege-escalation (CVE-2026-48614)
code injection in privilege-escalation (CVE-2026-48614). Successful exploitation can lead to full system takeover.
CVE-2026-48316 Vulnerability in adobe (CVE-2026-48316)
vulnerability in adobe (CVE-2026-48316). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →