Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-52vm-mxx8-f227 |
|
Path Traversal in phantom-audio (GHSA-52vm-mxx8-f227)
path traversal in phantom-audio (GHSA-52vm-mxx8-f227). Confidential information can be exposed externally. Exploitable via ``PHANTOM_OUTPUT_DIR``. Mitigation: upgrade to `1.3.1` or later.
|
| GHSA-q6gh-6v2r-hjv3 |
|
Vulnerability in io.micronaut:micronaut-http-client (GHSA-q6gh-6v2r-hjv3)
vulnerability in io.micronaut:micronaut-http-client (GHSA-q6gh-6v2r-hjv3). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `5.0.1` or later.
|
| GHSA-387m-935m-c4vw |
|
Vulnerability in io.micronaut:micronaut-http-client (GHSA-387m-935m-c4vw)
vulnerability in io.micronaut:micronaut-http-client (GHSA-387m-935m-c4vw). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.1` or later.
|
| CVE-2026-48987 |
|
Vulnerability in pyload-ng (CVE-2026-48987)
vulnerability in pyload-ng (CVE-2026-48987). Risk of unauthorized operations or information disclosure. Exploitable via ``EventManager``.
|
| CVE-2026-48737 |
|
SSRF (Server-Side Request Forgery) in pyload-ng (CVE-2026-48737)
SSRF in pyload-ng (CVE-2026-48737). Risk of unauthorized operations or information disclosure. Exploitable via ``is_global_address``.
|
| CGA-2jqc-mmfw-p34x |
|
CGA-2jqc-mmfw-p34x |
| CGA-rg72-8pv4-f9cp |
|
CGA-rg72-8pv4-f9cp |
| SUSE-RU-2026:2815-1 |
|
Vulnerability in apptainer (SUSE-RU-2026:2815-1)
vulnerability in apptainer (SUSE-RU-2026:2815-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.5.1-150600.4.29.1` or later.
|
| USN-8522-1 |
|
Vulnerability in libraw (USN-8522-1)
vulnerability in libraw (USN-8522-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.20.2-2ubuntu2.22.04.3` or later.
|
| USN-8521-1 |
|
Vulnerability in libidn (USN-8521-1)
vulnerability in libidn (USN-8521-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.38-4ubuntu1.1` or later.
|
| CVE-2026-15182 |
|
Buffer Overflow in c (CVE-2026-15182)
vulnerability in c (CVE-2026-15182). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9237 |
|
Vulnerability in wordpress (CVE-2026-9237)
vulnerability in wordpress (CVE-2026-9237). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4275 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-4275)
vulnerability in wordpress (CVE-2026-4275). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9235 |
|
Vulnerability in wordpress (CVE-2026-9235)
vulnerability in wordpress (CVE-2026-9235). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59692 |
|
Vulnerability in dos (CVE-2026-59692)
vulnerability in dos (CVE-2026-59692). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9253 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9253)
cross-site scripting in wordpress (CVE-2026-9253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9028 |
|
Vulnerability in wordpress (CVE-2026-9028)
vulnerability in wordpress (CVE-2026-9028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58307 |
|
Out-of-Bounds Read in CVE-2026-58307 (CVE-2026-58307)
vulnerability in CVE-2026-58307 (CVE-2026-58307). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9027 |
|
Vulnerability in wordpress (CVE-2026-9027)
vulnerability in wordpress (CVE-2026-9027). Risk of unauthorized operations or information disclosure. Exploitable via `POST /wp-json/corvuspay/success/`.
|
| CVE-2026-9021 |
|
Vulnerability in wordpress (CVE-2026-9021)
vulnerability in wordpress (CVE-2026-9021). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58306 |
|
Vulnerability in CVE-2026-58306 (CVE-2026-58306)
vulnerability in CVE-2026-58306 (CVE-2026-58306). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58305 |
|
Vulnerability in CVE-2026-58305 (CVE-2026-58305)
vulnerability in CVE-2026-58305 (CVE-2026-58305). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9240 |
|
Vulnerability in wordpress (CVE-2026-9240)
vulnerability in wordpress (CVE-2026-9240). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59691 |
|
Out-of-Bounds Write in dos (CVE-2026-59691)
out-of-bounds write in dos (CVE-2026-59691). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56291 KEV |
|
[KEV] Unrestricted File Upload in Balbooa forms (CVE-2026-56291)
vulnerability in Balbooa forms (CVE-2026-56291). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-56289 |
|
Vulnerability in dos (CVE-2026-56289)
vulnerability in dos (CVE-2026-56289). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50644 |
|
SQL Injection in sqli (CVE-2026-50644)
SQL injection in sqli (CVE-2026-50644). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14372 |
|
Path Traversal in wordpress (CVE-2026-14372)
path traversal in wordpress (CVE-2026-14372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4298 |
|
Vulnerability in wordpress (CVE-2026-4298)
vulnerability in wordpress (CVE-2026-4298). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58303 |
|
Vulnerability in CVE-2026-58303 (CVE-2026-58303)
vulnerability in CVE-2026-58303 (CVE-2026-58303). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58304 |
|
Out-of-Bounds Read in CVE-2026-58304 (CVE-2026-58304)
vulnerability in CVE-2026-58304 (CVE-2026-58304). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56288 |
|
Vulnerability in dos (CVE-2026-56288)
vulnerability in dos (CVE-2026-56288). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5955 |
|
SQL Injection in sqli (CVE-2026-5955)
SQL injection in sqli (CVE-2026-5955). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13441 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13441)
cross-site scripting in wordpress (CVE-2026-13441). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1989 |
|
Vulnerability in CVE-2026-1989 (CVE-2026-1989)
vulnerability in CVE-2026-1989 (CVE-2026-1989). Confidential information can be exposed externally.
|
| CVE-2026-1365 |
|
Vulnerability in CVE-2026-1365 (CVE-2026-1365)
vulnerability in CVE-2026-1365 (CVE-2026-1365). Confidential information can be exposed externally.
|
| CVE-2026-56458 |
|
Vulnerability in hcltechsw (CVE-2026-56458)
vulnerability in hcltechsw (CVE-2026-56458). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5793 |
|
Cross-Site Scripting (XSS) in CVE-2026-5793 (CVE-2026-5793)
cross-site scripting in CVE-2026-5793 (CVE-2026-5793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56460 |
|
Vulnerability in hcltechsw (CVE-2026-56460)
vulnerability in hcltechsw (CVE-2026-56460). Confidential information can be exposed externally.
|
| CVE-2026-12428 |
|
Vulnerability in wordpress (CVE-2026-12428)
vulnerability in wordpress (CVE-2026-12428). Confidential information can be exposed externally.
|
| CVE-2026-15158 |
|
Unrestricted File Upload in wordpress (CVE-2026-15158)
vulnerability in wordpress (CVE-2026-15158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12433 |
|
Vulnerability in wordpress (CVE-2026-12433)
vulnerability in wordpress (CVE-2026-12433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2342 |
|
Cross-Site Scripting (XSS) in CVE-2026-2342 (CVE-2026-2342)
cross-site scripting in CVE-2026-2342 (CVE-2026-2342). Confidential information can be exposed externally.
|
| CVE-2026-56459 |
|
Vulnerability in hcltechsw (CVE-2026-56459)
vulnerability in hcltechsw (CVE-2026-56459). Confidential information can be exposed externally.
|
| SUSE-SU-2026:2814-1 |
|
Vulnerability in MozillaFirefox (SUSE-SU-2026:2814-1)
vulnerability in MozillaFirefox (SUSE-SU-2026:2814-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `140.12.0-150200.152.245.1` or later.
|
| MAL-2026-10019 |
|
Vulnerability in client-cookies-agent (MAL-2026-10019)
vulnerability in client-cookies-agent (MAL-2026-10019). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-10020 |
|
Vulnerability in playwrightr (MAL-2026-10020)
vulnerability in playwrightr (MAL-2026-10020). Risk of unauthorized operations or information disclosure.
|
| CGA-f72v-p825-9fwv |
|
CGA-f72v-p825-9fwv |
| ROOT-APP-MAVEN-CVE-2026-43514 |
|
Vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43514)
vulnerability in io.root.org.apache.tomcat.embed:tomcat-embed-core (ROOT-APP-MAVEN-CVE-2026-43514). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.0.20-root.io.13, 11.0.20-root.io.14` or later.
|
| GHSA-rxc8-p2w2-g5jg |
|
Vulnerability in n8n-nodes-mcputils (GHSA-rxc8-p2w2-g5jg)
vulnerability in n8n-nodes-mcputils (GHSA-rxc8-p2w2-g5jg). Risk of unauthorized operations or information disclosure.
|