Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48752 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48752)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48752). Successful exploitation can lead to full system takeover. Exploitable via ``templates``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-0685 |
|
Vulnerability in CVE-2026-0685 (CVE-2026-0685)
vulnerability in CVE-2026-0685 (CVE-2026-0685). Successful exploitation can lead to full system takeover.
|
| CVE-2025-11919 |
|
Vulnerability in CVE-2025-11919 (CVE-2025-11919)
vulnerability in CVE-2025-11919 (CVE-2025-11919). Confidential information can be exposed externally.
|
| CVE-2026-48751 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751). Successful exploitation can lead to full system takeover. Exploitable via ``raw.lxc``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48750 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48750)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48750). Successful exploitation can lead to full system takeover. Exploitable via ``exec_UUID.stdout``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-48749 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48749)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48749). Successful exploitation can lead to full system takeover. Exploitable via ``metadata.yaml``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-54636 |
|
OS Command Injection in dokku (CVE-2026-54636)
OS command injection in dokku (CVE-2026-54636). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.7` or later.
|
| CVE-2026-45408 |
|
OS Command Injection in dokku (CVE-2026-45408)
OS command injection in dokku (CVE-2026-45408). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-45406 |
|
Vulnerability in dokku (CVE-2026-45406)
vulnerability in dokku (CVE-2026-45406). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-45405 |
|
Vulnerability in dokku (CVE-2026-45405)
vulnerability in dokku (CVE-2026-45405). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.38.2` or later.
|
| CVE-2026-44024 |
|
Path Traversal in fluentd (CVE-2026-44024)
path traversal in fluentd (CVE-2026-44024). Successful exploitation can lead to full system takeover. Exploitable via ``path``. Mitigation: upgrade to `1.19.3` or later.
|
| CVE-2026-57658 |
|
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
|
| CVE-2026-56067 |
|
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.
|
| CVE-2026-56070 |
|
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
|
| CVE-2026-56068 |
|
Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
|
| CVE-2026-56033 |
|
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
|
| CVE-2026-56034 |
|
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
|
| CVE-2026-56036 |
|
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
|
| CVE-2026-56027 |
|
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
|
| CVE-2026-56030 |
|
Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
|
| CVE-2026-56028 |
|
Vulnerability in privilege-escalation (CVE-2026-56028)
vulnerability in privilege-escalation (CVE-2026-56028). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56032 |
|
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
|
| CVE-2026-56062 |
|
Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.
Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.
|
| CVE-2026-56059 |
|
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
|
| CVE-2026-56057 |
|
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
|
| CVE-2026-56058 |
|
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
|
| CVE-2026-54827 |
|
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
|
| CVE-2026-54831 |
|
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
|
| CVE-2026-54825 |
|
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
|
| CVE-2026-54820 |
|
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
|
| CVE-2025-64152 |
|
Path Traversal in apache (CVE-2025-64152)
path traversal in apache (CVE-2025-64152). Confidential information can be exposed externally.
|
| CVE-2025-55017 |
|
Path Traversal in apache (CVE-2025-55017)
path traversal in apache (CVE-2025-55017). Confidential information can be exposed externally.
|
| CVE-2026-57878 |
|
Vulnerability in dos (CVE-2026-57878)
vulnerability in dos (CVE-2026-57878). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57879 |
|
Vulnerability in dos (CVE-2026-57879)
vulnerability in dos (CVE-2026-57879). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57880 |
|
Vulnerability in dos (CVE-2026-57880)
vulnerability in dos (CVE-2026-57880). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57881 |
|
Vulnerability in dos (CVE-2026-57881)
vulnerability in dos (CVE-2026-57881). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40702 |
|
Vulnerability in cisa (CVE-2026-40702)
vulnerability in cisa (CVE-2026-40702). Confidential information can be exposed externally.
|
| CVE-2026-48930 |
|
Vulnerability in node (CVE-2026-48930)
vulnerability in node (CVE-2026-48930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `22.23.0, 24.17.0, 26.3.1` or later.
|
| CVE-2025-71338 |
|
Code Injection in flowise (CVE-2025-71338)
code injection in flowise (CVE-2025-71338). Successful exploitation can lead to full system takeover. Exploitable via ``txtFile``.
|
| CVE-2025-71334 |
|
Path Traversal in flowise (CVE-2025-71334)
path traversal in flowise (CVE-2025-71334). Successful exploitation can lead to full system takeover. Exploitable via ``filename``. Mitigation: upgrade to `3.0.6` or later.
|
| CVE-2025-71336 |
|
OS Command Injection in flowise (CVE-2025-71336)
OS command injection in flowise (CVE-2025-71336). Successful exploitation can lead to full system takeover. Exploitable via ``npx``. Mitigation: upgrade to `3.0.6` or later.
|
| CVE-2025-71327 |
|
Authentication Bypass in flowise (CVE-2025-71327)
authentication bypass in flowise (CVE-2025-71327). Confidential information can be exposed externally.
|
| CVE-2025-71333 |
|
Unrestricted File Upload in flowise (CVE-2025-71333)
vulnerability in flowise (CVE-2025-71333). Successful exploitation can lead to full system takeover. Exploitable via ``storageType``.
|
| CVE-2026-55166 |
|
Vulnerability in lemur (CVE-2026-55166)
vulnerability in lemur (CVE-2026-55166). Confidential information can be exposed externally. Exploitable via `POST /api/1/authorities`. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2026-56445 |
|
Path Traversal in c (CVE-2026-56445)
path traversal in c (CVE-2026-56445). Data can be tampered with by attackers.
|
| CVE-2026-7531 |
|
Use-After-Free in wolfssl (CVE-2026-7531)
vulnerability in wolfssl (CVE-2026-7531). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56786 |
|
Out-of-Bounds Write in dos (CVE-2026-56786)
out-of-bounds write in dos (CVE-2026-56786). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57700 |
|
Unrestricted File Upload in CVE-2026-57700 (CVE-2026-57700)
vulnerability in CVE-2026-57700 (CVE-2026-57700). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54917 |
|
Path Traversal in github.com/seaweedfs/seaweedfs (CVE-2026-54917)
path traversal in github.com/seaweedfs/seaweedfs (CVE-2026-54917). Confidential information can be exposed externally. Exploitable via `GET /bucket-A/../evil-bucket/key`. Mitigation: upgrade to `0.0.0-20260526080459-dd1b4287899e` or later.
|
| CVE-2026-54089 |
|
Authentication Bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089)
authentication bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089). Confidential information can be exposed externally. Exploitable via `POST /api/login`.
|