Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9388 |
|
Command Injection in CVE-2026-9388 (CVE-2026-9388)
command injection in CVE-2026-9388 (CVE-2026-9388). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9384 |
|
Command Injection in CVE-2026-9384 (CVE-2026-9384)
command injection in CVE-2026-9384 (CVE-2026-9384). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9386 |
|
Command Injection in CVE-2026-9386 (CVE-2026-9386)
command injection in CVE-2026-9386 (CVE-2026-9386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9385 |
|
Command Injection in CVE-2026-9385 (CVE-2026-9385)
command injection in CVE-2026-9385 (CVE-2026-9385). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25350 |
|
Vulnerability in CVE-2018-25350 (CVE-2018-25350)
vulnerability in CVE-2018-25350 (CVE-2018-25350). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25357 |
|
Code Injection in dolibarr/dolibarr (CVE-2018-25357)
code injection in dolibarr/dolibarr (CVE-2018-25357). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.0.8` or later.
|
| CVE-2026-42901 |
|
Vulnerability in microsoft (CVE-2026-42901)
vulnerability in microsoft (CVE-2026-42901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47280 |
|
Authentication Bypass in microsoft (CVE-2026-47280)
authentication bypass in microsoft (CVE-2026-47280). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40411 |
|
Vulnerability in microsoft (CVE-2026-40411)
vulnerability in microsoft (CVE-2026-40411). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40412 |
|
Unrestricted File Upload in microsoft (CVE-2026-40412)
vulnerability in microsoft (CVE-2026-40412). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41104 |
|
Unsafe Deserialization in deserialization (CVE-2026-41104)
vulnerability in deserialization (CVE-2026-41104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41090 |
|
Command Injection in microsoft (CVE-2026-41090)
command injection in microsoft (CVE-2026-41090). Confidential information can be exposed externally.
|
| CVE-2026-23652 |
|
Command Injection in microsoft (CVE-2026-23652)
command injection in microsoft (CVE-2026-23652). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33843 |
|
Vulnerability in microsoft (CVE-2026-33843)
vulnerability in microsoft (CVE-2026-33843). Confidential information can be exposed externally.
|
| CVE-2026-8670 |
|
Vulnerability in avantra (CVE-2026-8670)
vulnerability in avantra (CVE-2026-8670). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44930 |
|
Vulnerability in org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (CVE-2026-44930)
vulnerability in org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (CVE-2026-44930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.11` or later.
|
| CVE-2026-46716 |
|
Privilege Escalation in github.com/nezhahq/nezha (CVE-2026-46716)
vulnerability in github.com/nezhahq/nezha (CVE-2026-46716). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/cron`. Mitigation: upgrade to `1.14.15-0.20260517022419-d7526351cf97` or later.
|
| CVE-2026-45390 |
|
Path Traversal in tar (CVE-2026-45390)
path traversal in tar (CVE-2026-45390). Confidential information can be exposed externally. Mitigation: upgrade to `3.5.0, 51ceb0a15982993503c169b9d84456fd50eabe99` or later.
|
| CVE-2026-33712 |
|
Vulnerability in ssrf (CVE-2026-33712)
vulnerability in ssrf (CVE-2026-33712). Confidential information can be exposed externally. Exploitable via `POST /api/v1/typebots/{typebotId}/preview/startChat`.
|
| CVE-2026-32253 |
|
Authentication Bypass in cpp (CVE-2026-32253)
authentication bypass in cpp (CVE-2026-32253). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46670 |
|
SQL Injection in yeswiki/yeswiki (CVE-2026-46670)
SQL injection in yeswiki/yeswiki (CVE-2026-46670). Successful exploitation can lead to full system takeover. Exploitable via ``INSERT``. Mitigation: upgrade to `4.6.4` or later.
|
| CVE-2026-42508 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-42508)
vulnerability in golang.org/x/crypto (CVE-2026-42508). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-46595 |
|
Authorization Flaw in golang.org/x/crypto (CVE-2026-46595)
vulnerability in golang.org/x/crypto (CVE-2026-46595). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39834 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39834)
vulnerability in golang.org/x/crypto (CVE-2026-39834). Data can be tampered with by attackers. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39830 |
|
Buffer Overflow in golang.org/x/crypto (CVE-2026-39830)
vulnerability in golang.org/x/crypto (CVE-2026-39830). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39831 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39831)
vulnerability in golang.org/x/crypto (CVE-2026-39831). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39832 |
|
Unsafe Deserialization in golang.org/x/crypto (CVE-2026-39832)
vulnerability in golang.org/x/crypto (CVE-2026-39832). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39833 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39833)
vulnerability in golang.org/x/crypto (CVE-2026-39833). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39821 |
|
Vulnerability in golang.org/x/net (CVE-2026-39821)
vulnerability in golang.org/x/net (CVE-2026-39821). Confidential information can be exposed externally. Mitigation: upgrade to `0.55.0` or later.
|
| CVE-2026-9264 |
|
Code Injection in CVE-2026-9264 (CVE-2026-9264)
code injection in CVE-2026-9264 (CVE-2026-9264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34908 KEV |
|
[KEV] Vulnerability in Ubiquiti ui (CVE-2026-34908)
vulnerability in Ubiquiti ui (CVE-2026-34908). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34909 KEV |
|
[KEV] Path Traversal in Ubiquiti path-traversal (CVE-2026-34909)
path traversal in Ubiquiti path-traversal (CVE-2026-34909). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34910 KEV |
|
[KEV] Vulnerability in Ubiquiti ui (CVE-2026-34910)
vulnerability in Ubiquiti ui (CVE-2026-34910). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-33000 |
|
Vulnerability in ui (CVE-2026-33000)
vulnerability in ui (CVE-2026-33000). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6960 |
|
Unrestricted File Upload in wordpress (CVE-2026-6960)
vulnerability in wordpress (CVE-2026-6960). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46634 |
|
Vulnerability in twig/twig (CVE-2026-46634)
vulnerability in twig/twig (CVE-2026-46634). Successful exploitation can lead to full system takeover. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-46633 |
|
Code Injection in twig/twig (CVE-2026-46633)
code injection in twig/twig (CVE-2026-46633). Successful exploitation can lead to full system takeover. Exploitable via ``SecurityPolicy``. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-46614 |
|
Vulnerability in github.com/fission/fission (CVE-2026-46614)
vulnerability in github.com/fission/fission (CVE-2026-46614). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v2/foo`. Mitigation: upgrade to `1.23.0` or later.
|
| CVE-2026-48207 |
|
Unsafe Deserialization in pyfory (CVE-2026-48207)
vulnerability in pyfory (CVE-2026-48207). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.0` or later.
|
| CVE-2026-39531 |
|
SQL Injection in sqli (CVE-2026-39531)
SQL injection in sqli (CVE-2026-39531). Confidential information can be exposed externally.
|
| CVE-2025-71210 |
|
Path Traversal in trendmicro (CVE-2025-71210)
path traversal in trendmicro (CVE-2025-71210). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71211 |
|
Path Traversal in trendmicro (CVE-2025-71211)
path traversal in trendmicro (CVE-2025-71211). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5118 |
|
Privilege Escalation in wordpress (CVE-2026-5118)
vulnerability in wordpress (CVE-2026-5118). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43501 |
|
Out-of-Bounds Write in linux (CVE-2026-43501)
out-of-bounds write in linux (CVE-2026-43501). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5433 |
|
Command Injection in CVE-2026-5433 (CVE-2026-5433)
command injection in CVE-2026-5433 (CVE-2026-5433). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44050 |
|
Vulnerability in dos (CVE-2026-44050)
vulnerability in dos (CVE-2026-44050). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6279 |
|
Vulnerability in wordpress (CVE-2026-6279)
vulnerability in wordpress (CVE-2026-6279). Successful exploitation can lead to full system takeover. Exploitable via ``wp_conditional_tags``.
|
| CVE-2026-48172 KEV |
|
[KEV] Vulnerability in Litespeed privilege-escalation (CVE-2026-48172)
vulnerability in Litespeed privilege-escalation (CVE-2026-48172). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-47372 |
|
Vulnerability in CVE-2026-47372 (CVE-2026-47372)
vulnerability in CVE-2026-47372 (CVE-2026-47372). Confidential information can be exposed externally.
|
| CVE-2026-8631 |
|
Vulnerability in hp (CVE-2026-8631)
vulnerability in hp (CVE-2026-8631). Successful exploitation can lead to full system takeover.
|