Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-9388 Command Injection in CVE-2026-9388 (CVE-2026-9388)
command injection in CVE-2026-9388 (CVE-2026-9388). Successful exploitation can lead to full system takeover.
CVE-2026-9384 Command Injection in CVE-2026-9384 (CVE-2026-9384)
command injection in CVE-2026-9384 (CVE-2026-9384). Successful exploitation can lead to full system takeover.
CVE-2026-9386 Command Injection in CVE-2026-9386 (CVE-2026-9386)
command injection in CVE-2026-9386 (CVE-2026-9386). Successful exploitation can lead to full system takeover.
CVE-2026-9385 Command Injection in CVE-2026-9385 (CVE-2026-9385)
command injection in CVE-2026-9385 (CVE-2026-9385). Successful exploitation can lead to full system takeover.
CVE-2018-25350 Vulnerability in CVE-2018-25350 (CVE-2018-25350)
vulnerability in CVE-2018-25350 (CVE-2018-25350). Successful exploitation can lead to full system takeover.
CVE-2018-25357 Code Injection in dolibarr/dolibarr (CVE-2018-25357)
code injection in dolibarr/dolibarr (CVE-2018-25357). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.0.8` or later.
CVE-2026-42901 Vulnerability in microsoft (CVE-2026-42901)
vulnerability in microsoft (CVE-2026-42901). Successful exploitation can lead to full system takeover.
CVE-2026-47280 Authentication Bypass in microsoft (CVE-2026-47280)
authentication bypass in microsoft (CVE-2026-47280). Successful exploitation can lead to full system takeover.
CVE-2026-40411 Vulnerability in microsoft (CVE-2026-40411)
vulnerability in microsoft (CVE-2026-40411). Successful exploitation can lead to full system takeover.
CVE-2026-40412 Unrestricted File Upload in microsoft (CVE-2026-40412)
vulnerability in microsoft (CVE-2026-40412). Successful exploitation can lead to full system takeover.
CVE-2026-41104 Unsafe Deserialization in deserialization (CVE-2026-41104)
vulnerability in deserialization (CVE-2026-41104). Successful exploitation can lead to full system takeover.
CVE-2026-41090 Command Injection in microsoft (CVE-2026-41090)
command injection in microsoft (CVE-2026-41090). Confidential information can be exposed externally.
CVE-2026-23652 Command Injection in microsoft (CVE-2026-23652)
command injection in microsoft (CVE-2026-23652). Successful exploitation can lead to full system takeover.
CVE-2026-33843 Vulnerability in microsoft (CVE-2026-33843)
vulnerability in microsoft (CVE-2026-33843). Confidential information can be exposed externally.
CVE-2026-8670 Vulnerability in avantra (CVE-2026-8670)
vulnerability in avantra (CVE-2026-8670). Successful exploitation can lead to full system takeover.
CVE-2026-44930 Vulnerability in org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (CVE-2026-44930)
vulnerability in org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (CVE-2026-44930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.11` or later.
CVE-2026-46716 Privilege Escalation in github.com/nezhahq/nezha (CVE-2026-46716)
vulnerability in github.com/nezhahq/nezha (CVE-2026-46716). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/cron`. Mitigation: upgrade to `1.14.15-0.20260517022419-d7526351cf97` or later.
CVE-2026-45390 Path Traversal in tar (CVE-2026-45390)
path traversal in tar (CVE-2026-45390). Confidential information can be exposed externally. Mitigation: upgrade to `3.5.0, 51ceb0a15982993503c169b9d84456fd50eabe99` or later.
CVE-2026-33712 Vulnerability in ssrf (CVE-2026-33712)
vulnerability in ssrf (CVE-2026-33712). Confidential information can be exposed externally. Exploitable via `POST /api/v1/typebots/{typebotId}/preview/startChat`.
CVE-2026-32253 Authentication Bypass in cpp (CVE-2026-32253)
authentication bypass in cpp (CVE-2026-32253). Successful exploitation can lead to full system takeover.
CVE-2026-46670 SQL Injection in yeswiki/yeswiki (CVE-2026-46670)
SQL injection in yeswiki/yeswiki (CVE-2026-46670). Successful exploitation can lead to full system takeover. Exploitable via ``INSERT``. Mitigation: upgrade to `4.6.4` or later.
CVE-2026-42508 Vulnerability in golang.org/x/crypto (CVE-2026-42508)
vulnerability in golang.org/x/crypto (CVE-2026-42508). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
CVE-2026-46595 Authorization Flaw in golang.org/x/crypto (CVE-2026-46595)
vulnerability in golang.org/x/crypto (CVE-2026-46595). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
CVE-2026-39834 Vulnerability in golang.org/x/crypto (CVE-2026-39834)
vulnerability in golang.org/x/crypto (CVE-2026-39834). Data can be tampered with by attackers. Mitigation: upgrade to `0.52.0` or later.
CVE-2026-39830 Buffer Overflow in golang.org/x/crypto (CVE-2026-39830)
vulnerability in golang.org/x/crypto (CVE-2026-39830). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
CVE-2026-39831 Vulnerability in golang.org/x/crypto (CVE-2026-39831)
vulnerability in golang.org/x/crypto (CVE-2026-39831). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
CVE-2026-39832 Unsafe Deserialization in golang.org/x/crypto (CVE-2026-39832)
vulnerability in golang.org/x/crypto (CVE-2026-39832). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
CVE-2026-39833 Vulnerability in golang.org/x/crypto (CVE-2026-39833)
vulnerability in golang.org/x/crypto (CVE-2026-39833). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
CVE-2026-39821 Vulnerability in golang.org/x/net (CVE-2026-39821)
vulnerability in golang.org/x/net (CVE-2026-39821). Confidential information can be exposed externally. Mitigation: upgrade to `0.55.0` or later.
CVE-2026-9264 Code Injection in CVE-2026-9264 (CVE-2026-9264)
code injection in CVE-2026-9264 (CVE-2026-9264). Successful exploitation can lead to full system takeover.
CVE-2026-34908 KEV [KEV] Vulnerability in Ubiquiti ui (CVE-2026-34908)
vulnerability in Ubiquiti ui (CVE-2026-34908). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-34909 KEV [KEV] Path Traversal in Ubiquiti path-traversal (CVE-2026-34909)
path traversal in Ubiquiti path-traversal (CVE-2026-34909). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-34910 KEV [KEV] Vulnerability in Ubiquiti ui (CVE-2026-34910)
vulnerability in Ubiquiti ui (CVE-2026-34910). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-33000 Vulnerability in ui (CVE-2026-33000)
vulnerability in ui (CVE-2026-33000). Successful exploitation can lead to full system takeover.
CVE-2026-6960 Unrestricted File Upload in wordpress (CVE-2026-6960)
vulnerability in wordpress (CVE-2026-6960). Successful exploitation can lead to full system takeover.
CVE-2026-46634 Vulnerability in twig/twig (CVE-2026-46634)
vulnerability in twig/twig (CVE-2026-46634). Successful exploitation can lead to full system takeover. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46633 Code Injection in twig/twig (CVE-2026-46633)
code injection in twig/twig (CVE-2026-46633). Successful exploitation can lead to full system takeover. Exploitable via ``SecurityPolicy``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-46614 Vulnerability in github.com/fission/fission (CVE-2026-46614)
vulnerability in github.com/fission/fission (CVE-2026-46614). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v2/foo`. Mitigation: upgrade to `1.23.0` or later.
CVE-2026-48207 Unsafe Deserialization in pyfory (CVE-2026-48207)
vulnerability in pyfory (CVE-2026-48207). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.0` or later.
CVE-2026-39531 SQL Injection in sqli (CVE-2026-39531)
SQL injection in sqli (CVE-2026-39531). Confidential information can be exposed externally.
CVE-2025-71210 Path Traversal in trendmicro (CVE-2025-71210)
path traversal in trendmicro (CVE-2025-71210). Successful exploitation can lead to full system takeover.
CVE-2025-71211 Path Traversal in trendmicro (CVE-2025-71211)
path traversal in trendmicro (CVE-2025-71211). Successful exploitation can lead to full system takeover.
CVE-2026-5118 Privilege Escalation in wordpress (CVE-2026-5118)
vulnerability in wordpress (CVE-2026-5118). Successful exploitation can lead to full system takeover.
CVE-2026-43501 Out-of-Bounds Write in linux (CVE-2026-43501)
out-of-bounds write in linux (CVE-2026-43501). Successful exploitation can lead to full system takeover.
CVE-2026-5433 Command Injection in CVE-2026-5433 (CVE-2026-5433)
command injection in CVE-2026-5433 (CVE-2026-5433). Successful exploitation can lead to full system takeover.
CVE-2026-44050 Vulnerability in dos (CVE-2026-44050)
vulnerability in dos (CVE-2026-44050). Successful exploitation can lead to full system takeover.
CVE-2026-6279 Vulnerability in wordpress (CVE-2026-6279)
vulnerability in wordpress (CVE-2026-6279). Successful exploitation can lead to full system takeover. Exploitable via ``wp_conditional_tags``.
CVE-2026-48172 KEV [KEV] Vulnerability in Litespeed privilege-escalation (CVE-2026-48172)
vulnerability in Litespeed privilege-escalation (CVE-2026-48172). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-47372 Vulnerability in CVE-2026-47372 (CVE-2026-47372)
vulnerability in CVE-2026-47372 (CVE-2026-47372). Confidential information can be exposed externally.
CVE-2026-8631 Vulnerability in hp (CVE-2026-8631)
vulnerability in hp (CVE-2026-8631). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →