Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-12375 Vulnerability in wordpress (CVE-2026-12375)
vulnerability in wordpress (CVE-2026-12375). Successful exploitation can lead to full system takeover.
CVE-2026-12277 Vulnerability in wordpress (CVE-2026-12277)
vulnerability in wordpress (CVE-2026-12277). Data can be tampered with by attackers.
CVE-2026-14345 Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
CVE-2026-4375 Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
CVE-2026-57871 Vulnerability in path-traversal (CVE-2026-57871)
vulnerability in path-traversal (CVE-2026-57871). Risk of unauthorized operations or information disclosure.
CVE-2026-57867 Vulnerability in CVE-2026-57867 (CVE-2026-57867)
vulnerability in CVE-2026-57867 (CVE-2026-57867). Risk of unauthorized operations or information disclosure.
CVE-2026-10834 Vulnerability in wordpress (CVE-2026-10834)
vulnerability in wordpress (CVE-2026-10834). Risk of unauthorized operations or information disclosure.
CVE-2026-58315 Cross-Site Request Forgery (CSRF) in jvn (CVE-2026-58315)
vulnerability in jvn (CVE-2026-58315). Risk of unauthorized operations or information disclosure.
CVE-2026-57870 Vulnerability in CVE-2026-57870 (CVE-2026-57870)
vulnerability in CVE-2026-57870 (CVE-2026-57870). Risk of unauthorized operations or information disclosure.
GHSA-968w-6262-r9f5 Vulnerability in express-deflect (GHSA-968w-6262-r9f5)
vulnerability in express-deflect (GHSA-968w-6262-r9f5). Risk of unauthorized operations or information disclosure.
GHSA-w3fq-7xj5-8gmv Vulnerability in chai-spycore (GHSA-w3fq-7xj5-8gmv)
vulnerability in chai-spycore (GHSA-w3fq-7xj5-8gmv). Risk of unauthorized operations or information disclosure. Exploitable via ``eventemitter3``.
GHSA-59r7-h2ch-m4v2 Vulnerability in express-firegate (GHSA-59r7-h2ch-m4v2)
vulnerability in express-firegate (GHSA-59r7-h2ch-m4v2). Risk of unauthorized operations or information disclosure.
MAL-2026-6910 Vulnerability in zluri-ad-connector (MAL-2026-6910)
vulnerability in zluri-ad-connector (MAL-2026-6910). Risk of unauthorized operations or information disclosure. Exploitable via ``dns``.
BELL-CVE-2026-14355 BELL-CVE-2026-14355
RLSA-2026:35839 Vulnerability in libreoffice (RLSA-2026:35839)
vulnerability in libreoffice (RLSA-2026:35839). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1:6.4.7.2-21.el8_10` or later.
RLSA-2026:35831 Vulnerability in grafana-pcp (RLSA-2026:35831)
vulnerability in grafana-pcp (RLSA-2026:35831). Confidential information can be exposed externally. Mitigation: upgrade to `0:5.1.1-16.el8_10` or later.
RLSA-2026:35830 Vulnerability in grafana (RLSA-2026:35830)
vulnerability in grafana (RLSA-2026:35830). Confidential information can be exposed externally. Mitigation: upgrade to `0:9.2.10-31.el8_10` or later.
CVE-2026-42201 OS Command Injection in CVE-2026-42201 (CVE-2026-42201)
OS command injection in CVE-2026-42201 (CVE-2026-42201). Risk of unauthorized operations or information disclosure.
CVE-2026-34158 OS Command Injection in CVE-2026-34158 (CVE-2026-34158)
OS command injection in CVE-2026-34158 (CVE-2026-34158). Successful exploitation can lead to full system takeover.
CVE-2026-27844 Vulnerability in dos (CVE-2026-27844)
vulnerability in dos (CVE-2026-27844). Risk of unauthorized operations or information disclosure.
CVE-2026-27790 Vulnerability in dos (CVE-2026-27790)
vulnerability in dos (CVE-2026-27790). Risk of unauthorized operations or information disclosure.
CVE-2026-26053 Vulnerability in gallagher (CVE-2026-26053)
vulnerability in gallagher (CVE-2026-26053). Data can be tampered with by attackers.
CVE-2026-42200 Path Traversal in CVE-2026-42200 (CVE-2026-42200)
path traversal in CVE-2026-42200 (CVE-2026-42200). Successful exploitation can lead to full system takeover.
CVE-2026-42172 Vulnerability in CVE-2026-42172 (CVE-2026-42172)
vulnerability in CVE-2026-42172 (CVE-2026-42172). Risk of unauthorized operations or information disclosure.
CVE-2026-42147 SSRF (Server-Side Request Forgery) in CVE-2026-42147 (CVE-2026-42147)
SSRF in CVE-2026-42147 (CVE-2026-42147). Confidential information can be exposed externally.
CVE-2026-42145 Unrestricted File Upload in CVE-2026-42145 (CVE-2026-42145)
vulnerability in CVE-2026-42145 (CVE-2026-42145). Risk of unauthorized operations or information disclosure.
CVE-2026-42143 OS Command Injection in CVE-2026-42143 (CVE-2026-42143)
OS command injection in CVE-2026-42143 (CVE-2026-42143). Successful exploitation can lead to full system takeover.
CVE-2026-34198 Vulnerability in CVE-2026-34198 (CVE-2026-34198)
vulnerability in CVE-2026-34198 (CVE-2026-34198). Data can be tampered with by attackers. Exploitable via `Host header`.
CVE-2026-34171 Cross-Site Request Forgery (CSRF) in CVE-2026-34171 (CVE-2026-34171)
vulnerability in CVE-2026-34171 (CVE-2026-34171). Confidential information can be exposed externally. Exploitable via `GET /invitations/{uuid}`.
CVE-2026-34170 SSRF (Server-Side Request Forgery) in CVE-2026-34170 (CVE-2026-34170)
SSRF in CVE-2026-34170 (CVE-2026-34170). Risk of unauthorized operations or information disclosure.
CVE-2026-34168 OS Command Injection in CVE-2026-34168 (CVE-2026-34168)
OS command injection in CVE-2026-34168 (CVE-2026-34168). Successful exploitation can lead to full system takeover.
CVE-2026-34152 OS Command Injection in CVE-2026-34152 (CVE-2026-34152)
OS command injection in CVE-2026-34152 (CVE-2026-34152). Successful exploitation can lead to full system takeover.
CVE-2026-34149 OS Command Injection in CVE-2026-34149 (CVE-2026-34149)
OS command injection in CVE-2026-34149 (CVE-2026-34149). Risk of unauthorized operations or information disclosure.
CVE-2026-34058 OS Command Injection in CVE-2026-34058 (CVE-2026-34058)
OS command injection in CVE-2026-34058 (CVE-2026-34058). Successful exploitation can lead to full system takeover.
CVE-2026-34057 OS Command Injection in CVE-2026-34057 (CVE-2026-34057)
OS command injection in CVE-2026-34057 (CVE-2026-34057). Successful exploitation can lead to full system takeover.
CVE-2026-34048 Vulnerability in CVE-2026-34048 (CVE-2026-34048)
vulnerability in CVE-2026-34048 (CVE-2026-34048). Successful exploitation can lead to full system takeover.
CVE-2026-34047 Authorization Flaw in CVE-2026-34047 (CVE-2026-34047)
vulnerability in CVE-2026-34047 (CVE-2026-34047). Successful exploitation can lead to full system takeover.
CVE-2026-34044 Vulnerability in CVE-2026-34044 (CVE-2026-34044)
vulnerability in CVE-2026-34044 (CVE-2026-34044). Confidential information can be exposed externally.
CVE-2026-34037 Vulnerability in CVE-2026-34037 (CVE-2026-34037)
vulnerability in CVE-2026-34037 (CVE-2026-34037). Confidential information can be exposed externally.
CVE-2026-34035 OS Command Injection in CVE-2026-34035 (CVE-2026-34035)
OS command injection in CVE-2026-34035 (CVE-2026-34035). Successful exploitation can lead to full system takeover.
CVE-2026-34034 OS Command Injection in CVE-2026-34034 (CVE-2026-34034)
OS command injection in CVE-2026-34034 (CVE-2026-34034). Successful exploitation can lead to full system takeover.
ROOT-APP-NPM-CVE-2026-48815 Vulnerability in @rootio/sigstore (ROOT-APP-NPM-CVE-2026-48815)
vulnerability in @rootio/sigstore (ROOT-APP-NPM-CVE-2026-48815). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.0-root.io.1, 2.1.0-root.io.1, 1.9.0-root.io.1, 1.5.2-root.io.1, 4.0.0-root.io.1, 3.1.0-root.io.1, 2.3.0-root.io.1, 4.1.0-root.io.1, 2.2.2-root.io.1, 2.3.1-root.io.1` or later.
ROOT-APP-PYPI-CVE-2026-48802 Vulnerability in rootio-python-engineio (ROOT-APP-PYPI-CVE-2026-48802)
vulnerability in rootio-python-engineio (ROOT-APP-PYPI-CVE-2026-48802). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.13.1+root.io.1` or later.
ROOT-APP-PYPI-CVE-2026-48809 Vulnerability in rootio-python-engineio (ROOT-APP-PYPI-CVE-2026-48809)
vulnerability in rootio-python-engineio (ROOT-APP-PYPI-CVE-2026-48809). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.13.1+root.io.1` or later.
CVE-2026-11328 Cross-Site Scripting (XSS) in wordpress (CVE-2026-11328)
cross-site scripting in wordpress (CVE-2026-11328). Risk of unauthorized operations or information disclosure.
MINI-f64h-mcjw-qmwm MINI-f64h-mcjw-qmwm
MINI-x2mh-xm9m-7926 MINI-x2mh-xm9m-7926
MINI-wphr-v4h5-96hr MINI-wphr-v4h5-96hr
MINI-pwfj-r7fr-84rj MINI-pwfj-r7fr-84rj
MINI-cq93-52p9-264v MINI-cq93-52p9-264v

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →