Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15113 |
|
Use-After-Free in google (CVE-2026-15113)
vulnerability in google (CVE-2026-15113). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52200 |
|
Code Injection in CVE-2026-52200 (CVE-2026-52200)
code injection in CVE-2026-52200 (CVE-2026-52200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31309 |
|
Vulnerability in CVE-2026-31309 (CVE-2026-31309)
vulnerability in CVE-2026-31309 (CVE-2026-31309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9074 |
|
SQL Injection in sqli (CVE-2026-9074)
SQL injection in sqli (CVE-2026-9074). Confidential information can be exposed externally.
|
| CVE-2026-59702 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-59702 (CVE-2026-59702)
SSRF in CVE-2026-59702 (CVE-2026-59702). Confidential information can be exposed externally. Exploitable via `POST /api/pack`.
|
| CVE-2026-15062 |
|
SQL Injection in sqli (CVE-2026-15062)
SQL injection in sqli (CVE-2026-15062). Confidential information can be exposed externally.
|
| CVE-2026-58480 |
|
Unrestricted File Upload in wordpress (CVE-2026-58480)
vulnerability in wordpress (CVE-2026-58480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54061 |
|
Vulnerability in github.com/dgraph-io/dgraph/v25 (CVE-2026-54061)
vulnerability in github.com/dgraph-io/dgraph/v25 (CVE-2026-54061). Data can be tampered with by attackers. Exploitable via ``StreamExtSnapshot``. Mitigation: upgrade to `25.3.5` or later.
|
| CVE-2026-8307 |
|
SQL Injection in sqli (CVE-2026-8307)
SQL injection in sqli (CVE-2026-8307). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14454 |
|
Vulnerability in tonycoz (CVE-2026-14454)
vulnerability in tonycoz (CVE-2026-14454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41042 |
|
Vulnerability in apache (CVE-2026-41042)
vulnerability in apache (CVE-2026-41042). Confidential information can be exposed externally.
|
| CVE-2026-9695 |
|
Authentication Bypass in CVE-2026-9695 (CVE-2026-9695)
authentication bypass in CVE-2026-9695 (CVE-2026-9695). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12153 |
|
Vulnerability in wordpress (CVE-2026-12153)
vulnerability in wordpress (CVE-2026-12153). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9701 |
|
Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
|
| CVE-2026-14487 |
|
Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
|
| CVE-2026-56843 |
|
Vulnerability in c (CVE-2026-56843)
vulnerability in c (CVE-2026-56843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59705 |
|
Vulnerability in CVE-2026-59705 (CVE-2026-59705)
vulnerability in CVE-2026-59705 (CVE-2026-59705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37271 |
|
Authentication Bypass in CVE-2026-37271 (CVE-2026-37271)
authentication bypass in CVE-2026-37271 (CVE-2026-37271). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14740 |
|
Out-of-Bounds Read in perl (CVE-2026-14740)
vulnerability in perl (CVE-2026-14740). Confidential information can be exposed externally.
|
| CVE-2026-14739 |
|
Out-of-Bounds Write in perl (CVE-2026-14739)
out-of-bounds write in perl (CVE-2026-14739). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37270 |
|
Authentication Bypass in CVE-2026-37270 (CVE-2026-37270)
authentication bypass in CVE-2026-37270 (CVE-2026-37270). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59706 |
|
Vulnerability in ssrf (CVE-2026-59706)
vulnerability in ssrf (CVE-2026-59706). Confidential information can be exposed externally. Exploitable via `GET /api/v1/config/`.
|
| CVE-2026-58473 |
|
Vulnerability in CVE-2026-58473 (CVE-2026-58473)
vulnerability in CVE-2026-58473 (CVE-2026-58473). Confidential information can be exposed externally.
|
| CVE-2026-53513 |
|
Vulnerability in @better-auth/sso (CVE-2026-53513)
vulnerability in @better-auth/sso (CVE-2026-53513). Confidential information can be exposed externally. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-53512 |
|
Authentication Bypass in better-auth (CVE-2026-53512)
authentication bypass in better-auth (CVE-2026-53512). Confidential information can be exposed externally. Exploitable via ``oauthApplication``. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-13019 |
|
Vulnerability in esri (CVE-2026-13019)
vulnerability in esri (CVE-2026-13019). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20744 |
|
Vulnerability in cisa (CVE-2026-20744)
vulnerability in cisa (CVE-2026-20744). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53481 |
|
Path Traversal in path-traversal (CVE-2026-53481)
path traversal in path-traversal (CVE-2026-53481). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53483 |
|
Authentication Bypass in dell (CVE-2026-53483)
authentication bypass in dell (CVE-2026-53483). Successful exploitation can lead to full system takeover.
|
| CVE-2011-10043 |
|
Vulnerability in CVE-2011-10043 (CVE-2011-10043)
vulnerability in CVE-2011-10043 (CVE-2011-10043). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33264 |
|
Unsafe Deserialization in apache (CVE-2026-33264)
vulnerability in apache (CVE-2026-33264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12375 |
|
Vulnerability in wordpress (CVE-2026-12375)
vulnerability in wordpress (CVE-2026-12375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4375 |
|
Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34047 |
|
Authorization Flaw in CVE-2026-34047 (CVE-2026-34047)
vulnerability in CVE-2026-34047 (CVE-2026-34047). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34037 |
|
Vulnerability in CVE-2026-34037 (CVE-2026-34037)
vulnerability in CVE-2026-34037 (CVE-2026-34037). Confidential information can be exposed externally.
|
| CVE-2026-34048 |
|
Vulnerability in CVE-2026-34048 (CVE-2026-34048)
vulnerability in CVE-2026-34048 (CVE-2026-34048). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55500 |
|
Information Disclosure in 9router (CVE-2026-55500)
vulnerability in 9router (CVE-2026-55500). Successful exploitation can lead to full system takeover. Exploitable via ``ALWAYS_PROTECTED``.
|
| CVE-2026-54496 |
|
Vulnerability in zebrad (CVE-2026-54496)
vulnerability in zebrad (CVE-2026-54496). Data can be tampered with by attackers. Exploitable via ``halo2_gadgets``. Mitigation: upgrade to `5.0.0` or later.
|
| CVE-2026-57572 |
|
Vulnerability in kidocode (CVE-2026-57572)
vulnerability in kidocode (CVE-2026-57572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57571 |
|
Path Traversal in kidocode (CVE-2026-57571)
path traversal in kidocode (CVE-2026-57571). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54763 |
|
Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763). Confidential information can be exposed externally. Exploitable via ``X_Auth_User``. Mitigation: upgrade to `2.11.42` or later.
|
| CVE-2026-34038 |
|
OS Command Injection in CVE-2026-34038 (CVE-2026-34038)
OS command injection in CVE-2026-34038 (CVE-2026-34038). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54769 |
|
Code Injection in langroid (CVE-2026-54769)
code injection in langroid (CVE-2026-54769). Successful exploitation can lead to full system takeover. Exploitable via ``TableChatAgent``. Mitigation: upgrade to `0.65.2` or later.
|
| CVE-2026-53486 |
|
Path Traversal in @xhmikosr/decompress (CVE-2026-53486)
path traversal in @xhmikosr/decompress (CVE-2026-53486). Confidential information can be exposed externally. Exploitable via ``path.relative``. Mitigation: upgrade to `11.1.3` or later.
|
| CVE-2026-11405 |
|
Vulnerability in CVE-2026-11405 (CVE-2026-11405)
vulnerability in CVE-2026-11405 (CVE-2026-11405). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9182 |
|
Unrestricted File Upload in esri (CVE-2026-9182)
vulnerability in esri (CVE-2026-9182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9181 |
|
Path Traversal in path-traversal (CVE-2026-9181)
path traversal in path-traversal (CVE-2026-9181). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48614 |
|
Code Injection in privilege-escalation (CVE-2026-48614)
code injection in privilege-escalation (CVE-2026-48614). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48316 |
|
Vulnerability in adobe (CVE-2026-48316)
vulnerability in adobe (CVE-2026-48316). Confidential information can be exposed externally.
|