Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2025-59322 Vulnerability in CVE-2025-59322 (CVE-2025-59322)
vulnerability in CVE-2025-59322 (CVE-2025-59322). Confidential information can be exposed externally.
CVE-2025-59323 Vulnerability in CVE-2025-59323 (CVE-2025-59323)
vulnerability in CVE-2025-59323 (CVE-2025-59323). Successful exploitation can lead to full system takeover.
CVE-2026-48798 Path Traversal in SSH.NET (CVE-2026-48798)
path traversal in SSH.NET (CVE-2026-48798). Data can be tampered with by attackers. Exploitable via ``ScpException``. Mitigation: upgrade to `2026.0.0` or later.
CVE-2026-73291 Path Traversal in CVE-2026-73291 (CVE-2026-73291)
path traversal in CVE-2026-73291 (CVE-2026-73291). Data can be tampered with by attackers. Exploitable via `GET /avatarproxy/`.
CVE-2026-73289 Authorization Flaw in CVE-2026-73289 (CVE-2026-73289)
vulnerability in CVE-2026-73289 (CVE-2026-73289). Confidential information can be exposed externally.
CVE-2026-73286 Authorization Flaw in CVE-2026-73286 (CVE-2026-73286)
vulnerability in CVE-2026-73286 (CVE-2026-73286). Confidential information can be exposed externally.
CVE-2026-73285 Authorization Flaw in CVE-2026-73285 (CVE-2026-73285)
vulnerability in CVE-2026-73285 (CVE-2026-73285). Successful exploitation can lead to full system takeover.
CVE-2026-73284 Privilege Escalation in CVE-2026-73284 (CVE-2026-73284)
vulnerability in CVE-2026-73284 (CVE-2026-73284). Successful exploitation can lead to full system takeover.
CVE-2026-73264 SSRF (Server-Side Request Forgery) in CVE-2026-73264 (CVE-2026-73264)
SSRF in CVE-2026-73264 (CVE-2026-73264). Confidential information can be exposed externally. Exploitable via `POST /api/v1/lighthouse/providers`.
CVE-2026-46369 Vulnerability in nimiq-blockchain (CVE-2026-46369)
vulnerability in nimiq-blockchain (CVE-2026-46369). Data can be tampered with by attackers. Mitigation: upgrade to `1.5.1` or later.
CVE-2026-32258 Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32258)
cross-site scripting in winter/wn-backend-module (CVE-2026-32258). Confidential information can be exposed externally. Exploitable via ``backend.manage_editor``. Mitigation: upgrade to `1.2.13` or later.
CVE-2026-32257 Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32257)
cross-site scripting in winter/wn-backend-module (CVE-2026-32257). Confidential information can be exposed externally. Exploitable via ``backend.manage_branding``. Mitigation: upgrade to `1.2.13` or later.
CVE-2025-59327 Vulnerability in CVE-2025-59327 (CVE-2025-59327)
vulnerability in CVE-2025-59327 (CVE-2025-59327). Confidential information can be exposed externally.
CVE-2025-59325 Vulnerability in CVE-2025-59325 (CVE-2025-59325)
vulnerability in CVE-2025-59325 (CVE-2025-59325). Confidential information can be exposed externally.
CVE-2026-70468 Vulnerability in CVE-2026-70468 (CVE-2026-70468)
vulnerability in CVE-2026-70468 (CVE-2026-70468). Successful exploitation can lead to full system takeover.
CVE-2026-57858 Cross-Site Scripting (XSS) in csrf (CVE-2026-57858)
cross-site scripting in csrf (CVE-2026-57858). Confidential information can be exposed externally.
CVE-2026-53996 Vulnerability in c (CVE-2026-53996)
vulnerability in c (CVE-2026-53996). Successful exploitation can lead to full system takeover.
CVE-2026-70465 Vulnerability in CVE-2026-70465 (CVE-2026-70465)
vulnerability in CVE-2026-70465 (CVE-2026-70465). Successful exploitation can lead to full system takeover.
CVE-2026-11325 OS Command Injection in CVE-2026-11325 (CVE-2026-11325)
OS command injection in CVE-2026-11325 (CVE-2026-11325). Successful exploitation can lead to full system takeover.
CVE-2026-19566 Vulnerability in CVE-2026-19566 (CVE-2026-19566)
vulnerability in CVE-2026-19566 (CVE-2026-19566). Risk of unauthorized operations or information disclosure.
CVE-2026-19426 Vulnerability in CVE-2026-19426 (CVE-2026-19426)
vulnerability in CVE-2026-19426 (CVE-2026-19426). Data can be tampered with by attackers.
CVE-2025-41770 Vulnerability in CVE-2025-41770 (CVE-2025-41770)
vulnerability in CVE-2025-41770 (CVE-2025-41770). Risk of unauthorized operations or information disclosure.
CVE-2026-19594 Path Traversal in path-traversal (CVE-2026-19594)
path traversal in path-traversal (CVE-2026-19594). Data can be tampered with by attackers. Exploitable via ``snowflake.core``.
CVE-2026-18057 SQL Injection in wordpress (CVE-2026-18057)
SQL injection in wordpress (CVE-2026-18057). Confidential information can be exposed externally.
CVE-2026-18230 SQL Injection in wordpress (CVE-2026-18230)
SQL injection in wordpress (CVE-2026-18230). Confidential information can be exposed externally.
CVE-2026-18049 Information Disclosure in wordpress (CVE-2026-18049)
vulnerability in wordpress (CVE-2026-18049). Confidential information can be exposed externally.
CVE-2026-16294 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16294)
SSRF in wordpress (CVE-2026-16294). Confidential information can be exposed externally.
CVE-2026-18789 Vulnerability in wordpress (CVE-2026-18789)
vulnerability in wordpress (CVE-2026-18789). Confidential information can be exposed externally.
CVE-2026-18474 SQL Injection in wordpress (CVE-2026-18474)
SQL injection in wordpress (CVE-2026-18474). Confidential information can be exposed externally.
CVE-2026-18048 Vulnerability in wordpress (CVE-2026-18048)
vulnerability in wordpress (CVE-2026-18048). Data can be tampered with by attackers.
CVE-2026-16977 SQL Injection in wordpress (CVE-2026-16977)
SQL injection in wordpress (CVE-2026-16977). Confidential information can be exposed externally.
CVE-2026-16253 Information Disclosure in wordpress (CVE-2026-16253)
vulnerability in wordpress (CVE-2026-16253). Confidential information can be exposed externally.
CVE-2026-14925 Information Disclosure in wordpress (CVE-2026-14925)
vulnerability in wordpress (CVE-2026-14925). Confidential information can be exposed externally.
CVE-2026-13171 Vulnerability in wordpress (CVE-2026-13171)
vulnerability in wordpress (CVE-2026-13171). Data can be tampered with by attackers.
CVE-2026-13613 SQL Injection in wordpress (CVE-2026-13613)
SQL injection in wordpress (CVE-2026-13613). Successful exploitation can lead to full system takeover.
CVE-2026-64954 Vulnerability in CVE-2026-64954 (CVE-2026-64954)
vulnerability in CVE-2026-64954 (CVE-2026-64954). Confidential information can be exposed externally.
CVE-2026-12234 Vulnerability in c (CVE-2026-12234)
vulnerability in c (CVE-2026-12234). Successful exploitation can lead to full system takeover.
CVE-2026-18961 Authentication Bypass in wordpress (CVE-2026-18961)
authentication bypass in wordpress (CVE-2026-18961). Successful exploitation can lead to full system takeover.
CVE-2026-73122 Privilege Escalation in CVE-2026-73122 (CVE-2026-73122)
vulnerability in CVE-2026-73122 (CVE-2026-73122). Confidential information can be exposed externally.
CVE-2026-66878 Vulnerability in CVE-2026-66878 (CVE-2026-66878)
vulnerability in CVE-2026-66878 (CVE-2026-66878). Confidential information can be exposed externally.
CVE-2026-6484 In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
CVE-2026-68447 Vulnerability in CVE-2026-68447 (CVE-2026-68447)
vulnerability in CVE-2026-68447 (CVE-2026-68447). Confidential information can be exposed externally.
CVE-2026-68445 Vulnerability in CVE-2026-68445 (CVE-2026-68445)
vulnerability in CVE-2026-68445 (CVE-2026-68445). Successful exploitation can lead to full system takeover.
CVE-2026-68442 Vulnerability in CVE-2026-68442 (CVE-2026-68442)
vulnerability in CVE-2026-68442 (CVE-2026-68442). Successful exploitation can lead to full system takeover.
CVE-2026-68446 Vulnerability in CVE-2026-68446 (CVE-2026-68446)
vulnerability in CVE-2026-68446 (CVE-2026-68446). Successful exploitation can lead to full system takeover.
CVE-2026-68440 Vulnerability in CVE-2026-68440 (CVE-2026-68440)
vulnerability in CVE-2026-68440 (CVE-2026-68440). Successful exploitation can lead to full system takeover.
CVE-2026-68433 Vulnerability in CVE-2026-68433 (CVE-2026-68433)
vulnerability in CVE-2026-68433 (CVE-2026-68433). Risk of unauthorized operations or information disclosure.
CVE-2026-68432 Vulnerability in CVE-2026-68432 (CVE-2026-68432)
vulnerability in CVE-2026-68432 (CVE-2026-68432). Successful exploitation can lead to full system takeover.
CVE-2026-73249 Vulnerability in CVE-2026-73249 (CVE-2026-73249)
vulnerability in CVE-2026-73249 (CVE-2026-73249). Data can be tampered with by attackers. Exploitable via `POST /book-update-annotations/{library_id}/{book_id}/{fmt}`.
CVE-2026-73247 SSRF (Server-Side Request Forgery) in CVE-2026-73247 (CVE-2026-73247)
SSRF in CVE-2026-73247 (CVE-2026-73247). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →