Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12375 |
|
Vulnerability in wordpress (CVE-2026-12375)
vulnerability in wordpress (CVE-2026-12375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12277 |
|
Vulnerability in wordpress (CVE-2026-12277)
vulnerability in wordpress (CVE-2026-12277). Data can be tampered with by attackers.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4375 |
|
Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57871 |
|
Vulnerability in path-traversal (CVE-2026-57871)
vulnerability in path-traversal (CVE-2026-57871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57867 |
|
Vulnerability in CVE-2026-57867 (CVE-2026-57867)
vulnerability in CVE-2026-57867 (CVE-2026-57867). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10834 |
|
Vulnerability in wordpress (CVE-2026-10834)
vulnerability in wordpress (CVE-2026-10834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58315 |
|
Cross-Site Request Forgery (CSRF) in jvn (CVE-2026-58315)
vulnerability in jvn (CVE-2026-58315). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57870 |
|
Vulnerability in CVE-2026-57870 (CVE-2026-57870)
vulnerability in CVE-2026-57870 (CVE-2026-57870). Risk of unauthorized operations or information disclosure.
|
| GHSA-968w-6262-r9f5 |
|
Vulnerability in express-deflect (GHSA-968w-6262-r9f5)
vulnerability in express-deflect (GHSA-968w-6262-r9f5). Risk of unauthorized operations or information disclosure.
|
| GHSA-w3fq-7xj5-8gmv |
|
Vulnerability in chai-spycore (GHSA-w3fq-7xj5-8gmv)
vulnerability in chai-spycore (GHSA-w3fq-7xj5-8gmv). Risk of unauthorized operations or information disclosure. Exploitable via ``eventemitter3``.
|
| GHSA-59r7-h2ch-m4v2 |
|
Vulnerability in express-firegate (GHSA-59r7-h2ch-m4v2)
vulnerability in express-firegate (GHSA-59r7-h2ch-m4v2). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-6910 |
|
Vulnerability in zluri-ad-connector (MAL-2026-6910)
vulnerability in zluri-ad-connector (MAL-2026-6910). Risk of unauthorized operations or information disclosure. Exploitable via ``dns``.
|
| BELL-CVE-2026-14355 |
|
BELL-CVE-2026-14355 |
| RLSA-2026:35839 |
|
Vulnerability in libreoffice (RLSA-2026:35839)
vulnerability in libreoffice (RLSA-2026:35839). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1:6.4.7.2-21.el8_10` or later.
|
| RLSA-2026:35831 |
|
Vulnerability in grafana-pcp (RLSA-2026:35831)
vulnerability in grafana-pcp (RLSA-2026:35831). Confidential information can be exposed externally. Mitigation: upgrade to `0:5.1.1-16.el8_10` or later.
|
| RLSA-2026:35830 |
|
Vulnerability in grafana (RLSA-2026:35830)
vulnerability in grafana (RLSA-2026:35830). Confidential information can be exposed externally. Mitigation: upgrade to `0:9.2.10-31.el8_10` or later.
|
| CVE-2026-42201 |
|
OS Command Injection in CVE-2026-42201 (CVE-2026-42201)
OS command injection in CVE-2026-42201 (CVE-2026-42201). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34158 |
|
OS Command Injection in CVE-2026-34158 (CVE-2026-34158)
OS command injection in CVE-2026-34158 (CVE-2026-34158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27844 |
|
Vulnerability in dos (CVE-2026-27844)
vulnerability in dos (CVE-2026-27844). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27790 |
|
Vulnerability in dos (CVE-2026-27790)
vulnerability in dos (CVE-2026-27790). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26053 |
|
Vulnerability in gallagher (CVE-2026-26053)
vulnerability in gallagher (CVE-2026-26053). Data can be tampered with by attackers.
|
| CVE-2026-42200 |
|
Path Traversal in CVE-2026-42200 (CVE-2026-42200)
path traversal in CVE-2026-42200 (CVE-2026-42200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42172 |
|
Vulnerability in CVE-2026-42172 (CVE-2026-42172)
vulnerability in CVE-2026-42172 (CVE-2026-42172). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42147 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-42147 (CVE-2026-42147)
SSRF in CVE-2026-42147 (CVE-2026-42147). Confidential information can be exposed externally.
|
| CVE-2026-42145 |
|
Unrestricted File Upload in CVE-2026-42145 (CVE-2026-42145)
vulnerability in CVE-2026-42145 (CVE-2026-42145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42143 |
|
OS Command Injection in CVE-2026-42143 (CVE-2026-42143)
OS command injection in CVE-2026-42143 (CVE-2026-42143). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34198 |
|
Vulnerability in CVE-2026-34198 (CVE-2026-34198)
vulnerability in CVE-2026-34198 (CVE-2026-34198). Data can be tampered with by attackers. Exploitable via `Host header`.
|
| CVE-2026-34171 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-34171 (CVE-2026-34171)
vulnerability in CVE-2026-34171 (CVE-2026-34171). Confidential information can be exposed externally. Exploitable via `GET /invitations/{uuid}`.
|
| CVE-2026-34170 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-34170 (CVE-2026-34170)
SSRF in CVE-2026-34170 (CVE-2026-34170). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34168 |
|
OS Command Injection in CVE-2026-34168 (CVE-2026-34168)
OS command injection in CVE-2026-34168 (CVE-2026-34168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34152 |
|
OS Command Injection in CVE-2026-34152 (CVE-2026-34152)
OS command injection in CVE-2026-34152 (CVE-2026-34152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34149 |
|
OS Command Injection in CVE-2026-34149 (CVE-2026-34149)
OS command injection in CVE-2026-34149 (CVE-2026-34149). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34058 |
|
OS Command Injection in CVE-2026-34058 (CVE-2026-34058)
OS command injection in CVE-2026-34058 (CVE-2026-34058). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34057 |
|
OS Command Injection in CVE-2026-34057 (CVE-2026-34057)
OS command injection in CVE-2026-34057 (CVE-2026-34057). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34048 |
|
Vulnerability in CVE-2026-34048 (CVE-2026-34048)
vulnerability in CVE-2026-34048 (CVE-2026-34048). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34047 |
|
Authorization Flaw in CVE-2026-34047 (CVE-2026-34047)
vulnerability in CVE-2026-34047 (CVE-2026-34047). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34044 |
|
Vulnerability in CVE-2026-34044 (CVE-2026-34044)
vulnerability in CVE-2026-34044 (CVE-2026-34044). Confidential information can be exposed externally.
|
| CVE-2026-34037 |
|
Vulnerability in CVE-2026-34037 (CVE-2026-34037)
vulnerability in CVE-2026-34037 (CVE-2026-34037). Confidential information can be exposed externally.
|
| CVE-2026-34035 |
|
OS Command Injection in CVE-2026-34035 (CVE-2026-34035)
OS command injection in CVE-2026-34035 (CVE-2026-34035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34034 |
|
OS Command Injection in CVE-2026-34034 (CVE-2026-34034)
OS command injection in CVE-2026-34034 (CVE-2026-34034). Successful exploitation can lead to full system takeover.
|
| ROOT-APP-NPM-CVE-2026-48815 |
|
Vulnerability in @rootio/sigstore (ROOT-APP-NPM-CVE-2026-48815)
vulnerability in @rootio/sigstore (ROOT-APP-NPM-CVE-2026-48815). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.0-root.io.1, 2.1.0-root.io.1, 1.9.0-root.io.1, 1.5.2-root.io.1, 4.0.0-root.io.1, 3.1.0-root.io.1, 2.3.0-root.io.1, 4.1.0-root.io.1, 2.2.2-root.io.1, 2.3.1-root.io.1` or later.
|
| ROOT-APP-PYPI-CVE-2026-48802 |
|
Vulnerability in rootio-python-engineio (ROOT-APP-PYPI-CVE-2026-48802)
vulnerability in rootio-python-engineio (ROOT-APP-PYPI-CVE-2026-48802). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.13.1+root.io.1` or later.
|
| ROOT-APP-PYPI-CVE-2026-48809 |
|
Vulnerability in rootio-python-engineio (ROOT-APP-PYPI-CVE-2026-48809)
vulnerability in rootio-python-engineio (ROOT-APP-PYPI-CVE-2026-48809). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.13.1+root.io.1` or later.
|
| CVE-2026-11328 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11328)
cross-site scripting in wordpress (CVE-2026-11328). Risk of unauthorized operations or information disclosure.
|
| MINI-f64h-mcjw-qmwm |
|
MINI-f64h-mcjw-qmwm |
| MINI-x2mh-xm9m-7926 |
|
MINI-x2mh-xm9m-7926 |
| MINI-wphr-v4h5-96hr |
|
MINI-wphr-v4h5-96hr |
| MINI-pwfj-r7fr-84rj |
|
MINI-pwfj-r7fr-84rj |
| MINI-cq93-52p9-264v |
|
MINI-cq93-52p9-264v |