Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9139 |
|
Vulnerability in CVE-2026-9139 (CVE-2026-9139)
vulnerability in CVE-2026-9139 (CVE-2026-9139). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9141 |
|
Vulnerability in CVE-2026-9141 (CVE-2026-9141)
vulnerability in CVE-2026-9141 (CVE-2026-9141). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9082 KEV |
|
[KEV] SQL Injection in drupal/core (CVE-2026-9082)
SQL injection in drupal/core (CVE-2026-9082). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `11.3.10` or later.
|
| CVE-2026-45444 |
|
Unrestricted File Upload in CVE-2026-45444 (CVE-2026-45444)
vulnerability in CVE-2026-45444 (CVE-2026-45444). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20223 |
|
Vulnerability in Cisco secure-workload (CVE-2026-20223)
vulnerability in Cisco secure-workload (CVE-2026-20223). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45388 |
|
Vulnerability in tls (CVE-2026-45388)
vulnerability in tls (CVE-2026-45388). Confidential information can be exposed externally. Mitigation: upgrade to `2.1.0, 6a12247b3fbd747972ad2d35b74d9a89f6404952` or later.
|
| CVE-2026-22314 |
|
Code Injection in CVE-2026-22314 (CVE-2026-22314)
code injection in CVE-2026-22314 (CVE-2026-22314). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42960 |
|
Vulnerability in nlnetlabs (CVE-2026-42960)
vulnerability in nlnetlabs (CVE-2026-42960). Data can be tampered with by attackers.
|
| CVE-2026-33278 |
|
Use-After-Free in dos (CVE-2026-33278)
vulnerability in dos (CVE-2026-33278). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7637 |
|
Unsafe Deserialization in wordpress (CVE-2026-7637)
vulnerability in wordpress (CVE-2026-7637). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24207 |
|
Vulnerability in dos (CVE-2026-24207)
vulnerability in dos (CVE-2026-24207). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7284 |
|
Privilege Escalation in wordpress (CVE-2026-7284)
vulnerability in wordpress (CVE-2026-7284). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6555 |
|
Unrestricted File Upload in wordpress (CVE-2026-6555)
vulnerability in wordpress (CVE-2026-6555). Successful exploitation can lead to full system takeover.
|
| CVE-2008-4250 KEV |
|
[KEV] Code Injection in Microsoft windows-2000 (CVE-2008-4250)
code injection in Microsoft windows-2000 (CVE-2008-4250). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34234 |
|
OS Command Injection in CVE-2026-34234 (CVE-2026-34234)
OS command injection in CVE-2026-34234 (CVE-2026-34234). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46412 |
|
Vulnerability in @beproduct/nestjs-auth (CVE-2026-46412)
vulnerability in @beproduct/nestjs-auth (CVE-2026-46412). Successful exploitation can lead to full system takeover. Exploitable via ``tanstack_runner.js``.
|
| CVE-2026-46354 |
|
Vulnerability in github.com/coder/coder/v2 (CVE-2026-46354)
vulnerability in github.com/coder/coder/v2 (CVE-2026-46354). Confidential information can be exposed externally. Exploitable via `POST /api/v2/workspaceagents/azure-instance-identity`. Mitigation: upgrade to `2.24.5` or later.
|
| CVE-2026-46339 |
|
OS Command Injection in 9router (CVE-2026-46339)
OS command injection in 9router (CVE-2026-46339). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/cli-tools/cowork-settings`. Mitigation: upgrade to `0.4.37` or later.
|
| CVE-2026-45695 |
|
OS Command Injection in github.com/kopia/kopia (CVE-2026-45695)
OS command injection in github.com/kopia/kopia (CVE-2026-45695). Successful exploitation can lead to full system takeover. Exploitable via ``blob.NewStorage``. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-33642 |
|
Out-of-Bounds Read in c (CVE-2026-33642)
vulnerability in c (CVE-2026-33642). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8605 |
|
Vulnerability in scadabr (CVE-2026-8605)
vulnerability in scadabr (CVE-2026-8605). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8603 |
|
OS Command Injection in scadabr (CVE-2026-8603)
OS command injection in scadabr (CVE-2026-8603). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36829 |
|
Path Traversal in path-traversal (CVE-2026-36829)
path traversal in path-traversal (CVE-2026-36829). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8602 |
|
Vulnerability in cisa (CVE-2026-8602)
vulnerability in cisa (CVE-2026-8602). Data can be tampered with by attackers.
|
| CVE-2026-8598 |
|
Vulnerability in cisa (CVE-2026-8598)
vulnerability in cisa (CVE-2026-8598). Confidential information can be exposed externally.
|
| CVE-2026-56348 |
|
SSRF (Server-Side Request Forgery) in n8n (CVE-2026-56348)
SSRF in n8n (CVE-2026-56348). Confidential information can be exposed externally. Exploitable via `POST /rest/dynamic-node-parameters/options`. Mitigation: upgrade to `2.20.0` or later.
|
| CVE-2026-37281 |
|
OS Command Injection in express (CVE-2026-37281)
OS command injection in express (CVE-2026-37281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30118 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-30118)
SSRF in ssrf (CVE-2026-30118). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31070 |
|
Privilege Escalation in CVE-2026-31070 (CVE-2026-31070)
vulnerability in CVE-2026-31070 (CVE-2026-31070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31071 |
|
Vulnerability in CVE-2026-31071 (CVE-2026-31071)
vulnerability in CVE-2026-31071 (CVE-2026-31071). Confidential information can be exposed externally.
|
| CVE-2026-31072 |
|
Unsafe Deserialization in apscheduler (CVE-2026-31072)
vulnerability in apscheduler (CVE-2026-31072). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30117 |
|
Code Injection in CVE-2026-30117 (CVE-2026-30117)
code injection in CVE-2026-30117 (CVE-2026-30117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45758 |
|
Vulnerability in guardrails-ai (CVE-2026-45758)
vulnerability in guardrails-ai (CVE-2026-45758). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44159 |
|
Vulnerability in CVE-2026-44159 (CVE-2026-44159)
vulnerability in CVE-2026-44159 (CVE-2026-44159). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2586 |
|
Code Injection in org.glassfish.main.admingui:console-common (CVE-2026-2586)
code injection in org.glassfish.main.admingui:console-common (CVE-2026-2586). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.2` or later.
|
| CVE-2026-2587 |
|
Vulnerability in org.glassfish.main.admingui:admingui (CVE-2026-2587)
vulnerability in org.glassfish.main.admingui:admingui (CVE-2026-2587). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.2` or later.
|
| CVE-2026-45570 |
|
Vulnerability in github.com/go-git/go-git/v5 (CVE-2026-45570)
vulnerability in github.com/go-git/go-git/v5 (CVE-2026-45570). Successful exploitation can lead to full system takeover. Exploitable via ``sq_quote_buf``. Mitigation: upgrade to `5.19.1` or later.
|
| CVE-2026-45568 |
|
Path Traversal in zrok (CVE-2026-45568)
path traversal in zrok (CVE-2026-45568). Confidential information can be exposed externally. Exploitable via ``ProxyShare``.
|
| CVE-2026-45721 |
|
Vulnerability in github.com/xyproto/algernon (CVE-2026-45721)
vulnerability in github.com/xyproto/algernon (CVE-2026-45721). Successful exploitation can lead to full system takeover. Exploitable via ``DirPage``. Mitigation: upgrade to `1.17.7` or later.
|
| CVE-2026-8959 |
|
Vulnerability in mozilla (CVE-2026-8959)
vulnerability in mozilla (CVE-2026-8959). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8948 |
|
Vulnerability in mozilla (CVE-2026-8948)
vulnerability in mozilla (CVE-2026-8948). Confidential information can be exposed externally.
|
| CVE-2026-8950 |
|
Vulnerability in mozilla (CVE-2026-8950)
vulnerability in mozilla (CVE-2026-8950). Confidential information can be exposed externally.
|
| CVE-2026-8953 |
|
Use-After-Free in mozilla (CVE-2026-8953)
vulnerability in mozilla (CVE-2026-8953). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8956 |
|
Vulnerability in mozilla (CVE-2026-8956)
vulnerability in mozilla (CVE-2026-8956). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47323 |
|
Vulnerability in org.apache.camel:camel-cxf-rest (CVE-2026-47323)
vulnerability in org.apache.camel:camel-cxf-rest (CVE-2026-47323). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.18.2` or later.
|
| CVE-2026-43633 |
|
Unsafe Deserialization in deserialization (CVE-2026-43633)
vulnerability in deserialization (CVE-2026-43633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4883 |
|
Unrestricted File Upload in wordpress (CVE-2026-4883)
vulnerability in wordpress (CVE-2026-4883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43493 |
|
Vulnerability in linux (CVE-2026-43493)
vulnerability in linux (CVE-2026-43493). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31986 |
|
Vulnerability in apache (CVE-2026-31986)
vulnerability in apache (CVE-2026-31986). Confidential information can be exposed externally.
|
| CVE-2026-41919 |
|
Vulnerability in apache (CVE-2026-41919)
vulnerability in apache (CVE-2026-41919). Confidential information can be exposed externally.
|