Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-45434 Authentication Bypass in apache (CVE-2026-45434)
authentication bypass in apache (CVE-2026-45434). Successful exploitation can lead to full system takeover.
CVE-2026-2611 Vulnerability in mlflow (CVE-2026-2611)
vulnerability in mlflow (CVE-2026-2611). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
CVE-2026-4885 Unrestricted File Upload in wordpress (CVE-2026-4885)
vulnerability in wordpress (CVE-2026-4885). Successful exploitation can lead to full system takeover.
CVE-2026-27130 OS Command Injection in CVE-2026-27130 (CVE-2026-27130)
OS command injection in CVE-2026-27130 (CVE-2026-27130). Successful exploitation can lead to full system takeover.
CVE-2026-8838 Code Injection in Amazon redshift-connector (CVE-2026-8838)
code injection in Amazon redshift-connector (CVE-2026-8838). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.14` or later.
CVE-2026-8836 Buffer Overflow in c (CVE-2026-8836)
vulnerability in c (CVE-2026-8836). Successful exploitation can lead to full system takeover.
CVE-2026-42822 Authentication Bypass in microsoft (CVE-2026-42822)
authentication bypass in microsoft (CVE-2026-42822). Successful exploitation can lead to full system takeover.
CVE-2023-24215 Vulnerability in CVE-2023-24215 (CVE-2023-24215)
vulnerability in CVE-2023-24215 (CVE-2023-24215). Confidential information can be exposed externally.
CVE-2026-45230 Path Traversal in path-traversal (CVE-2026-45230)
path traversal in path-traversal (CVE-2026-45230). Data can be tampered with by attackers. Exploitable via `POST /api/delete-file`.
CVE-2026-45363 Vulnerability in jwt (CVE-2026-45363)
vulnerability in jwt (CVE-2026-45363). Confidential information can be exposed externally. Exploitable via ``enforce_hmac_key_length``. Mitigation: upgrade to `2.10.3` or later.
CVE-2026-45697 Code Injection in verbb/formie (CVE-2026-45697)
code injection in verbb/formie (CVE-2026-45697). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.2.20` or later.
CVE-2026-45829 Code Injection in chromadb (CVE-2026-45829)
code injection in chromadb (CVE-2026-45829). Successful exploitation can lead to full system takeover.
CVE-2026-41947 Vulnerability in dify (CVE-2026-41947)
vulnerability in dify (CVE-2026-41947). Confidential information can be exposed externally.
CVE-2026-41948 Vulnerability in path-traversal (CVE-2026-41948)
vulnerability in path-traversal (CVE-2026-41948). Confidential information can be exposed externally.
CVE-2026-45625 Vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-45625)
vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-45625). Successful exploitation can lead to full system takeover. Exploitable via `PUT /customize/git-repositories/{id}`. Mitigation: upgrade to `1.19.0` or later.
CVE-2026-7304 Unsafe Deserialization in sglang (CVE-2026-7304)
vulnerability in sglang (CVE-2026-7304). Successful exploitation can lead to full system takeover.
CVE-2026-7301 Unsafe Deserialization in sglang (CVE-2026-7301)
vulnerability in sglang (CVE-2026-7301). Successful exploitation can lead to full system takeover.
CVE-2026-7302 Vulnerability in sglang (CVE-2026-7302)
vulnerability in sglang (CVE-2026-7302). Data can be tampered with by attackers.
CVE-2026-8721 Vulnerability in c (CVE-2026-8721)
vulnerability in c (CVE-2026-8721). Successful exploitation can lead to full system takeover.
CVE-2026-8507 Out-of-Bounds Write in CVE-2026-8507 (CVE-2026-8507)
out-of-bounds write in CVE-2026-8507 (CVE-2026-8507). Successful exploitation can lead to full system takeover.
CVE-2018-25335 Vulnerability in wordpress (CVE-2018-25335)
vulnerability in wordpress (CVE-2018-25335). Successful exploitation can lead to full system takeover.
CVE-2018-25332 Vulnerability in gitbucket (CVE-2018-25332)
vulnerability in gitbucket (CVE-2018-25332). Successful exploitation can lead to full system takeover.
CVE-2018-25320 Code Injection in CVE-2018-25320 (CVE-2018-25320)
code injection in CVE-2018-25320 (CVE-2018-25320). Successful exploitation can lead to full system takeover.
CVE-2021-47952 Code Injection in deserialization (CVE-2021-47952)
code injection in deserialization (CVE-2021-47952). Successful exploitation can lead to full system takeover.
CVE-2020-37239 Vulnerability in CVE-2020-37239 (CVE-2020-37239)
vulnerability in CVE-2020-37239 (CVE-2020-37239). Successful exploitation can lead to full system takeover.
CVE-2020-37228 Vulnerability in CVE-2020-37228 (CVE-2020-37228)
vulnerability in CVE-2020-37228 (CVE-2020-37228). Successful exploitation can lead to full system takeover.
CVE-2026-46695 Vulnerability in boxlite (CVE-2026-46695)
vulnerability in boxlite (CVE-2026-46695). Confidential information can be exposed externally. Exploitable via ``VolumeSpec``. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-46703 Path Traversal in boxlite (CVE-2026-46703)
path traversal in boxlite (CVE-2026-46703). Successful exploitation can lead to full system takeover. Exploitable via ``apply_oci_layer``. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-46364 SQL Injection in thorsten/phpmyfaq (CVE-2026-46364)
SQL injection in thorsten/phpmyfaq (CVE-2026-46364). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/captcha`. Mitigation: upgrade to `4.1.2` or later.
CVE-2026-45010 Vulnerability in thorsten/phpmyfaq (CVE-2026-45010)
vulnerability in thorsten/phpmyfaq (CVE-2026-45010). Confidential information can be exposed externally. Exploitable via `POST /admin/check`. Mitigation: upgrade to `4.1.2` or later.
CVE-2021-47965 Unrestricted File Upload in wordpress (CVE-2021-47965)
vulnerability in wordpress (CVE-2021-47965). Successful exploitation can lead to full system takeover.
CVE-2026-44717 Code Injection in CVE-2026-44717 (CVE-2026-44717)
code injection in CVE-2026-44717 (CVE-2026-44717). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.1.1` or later.
CVE-2026-41258 Code Injection in org.openmrs.api:openmrs-api (CVE-2026-41258)
code injection in org.openmrs.api:openmrs-api (CVE-2026-41258). Successful exploitation can lead to full system takeover. Exploitable via ``VelocityEngine``. Mitigation: upgrade to `2.8.6` or later.
CVE-2026-45772 Vulnerability in turbo (CVE-2026-45772)
vulnerability in turbo (CVE-2026-45772). Successful exploitation can lead to full system takeover. Exploitable via ``yarnPath``. Mitigation: upgrade to `2.9.14` or later.
CVE-2026-41553 OS Command Injection in dhtmlx (CVE-2026-41553)
OS command injection in dhtmlx (CVE-2026-41553). Successful exploitation can lead to full system takeover.
CVE-2026-5229 Authentication Bypass in wordpress (CVE-2026-5229)
authentication bypass in wordpress (CVE-2026-5229). Successful exploitation can lead to full system takeover.
CVE-2026-8398 KEV [KEV] Vulnerability in Daemon disc-soft (CVE-2026-8398)
vulnerability in Daemon disc-soft (CVE-2026-8398). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-8634 Code Injection in github.com/openclaw/crabbox (CVE-2026-8634)
code injection in github.com/openclaw/crabbox (CVE-2026-8634). Confidential information can be exposed externally. Mitigation: upgrade to `0.12.0` or later.
CVE-2026-8580 Use-After-Free in google (CVE-2026-8580)
vulnerability in google (CVE-2026-8580). Successful exploitation can lead to full system takeover.
CVE-2026-8511 Use-After-Free in google (CVE-2026-8511)
vulnerability in google (CVE-2026-8511). Successful exploitation can lead to full system takeover.
CVE-2026-45288 SQL Injection in Marten (CVE-2026-45288)
SQL injection in Marten (CVE-2026-45288). Successful exploitation can lead to full system takeover. Exploitable via ``regConfig``. Mitigation: upgrade to `8.37.0` or later.
CVE-2026-45787 Vulnerability in electerm (CVE-2026-45787)
vulnerability in electerm (CVE-2026-45787). Confidential information can be exposed externally. Mitigation: upgrade to `3.9.5` or later.
CVE-2026-45374 Code Injection in deepseek-tui (CVE-2026-45374)
code injection in deepseek-tui (CVE-2026-45374). Successful exploitation can lead to full system takeover. Exploitable via ``task_create``. Mitigation: upgrade to `0.8.26` or later.
CVE-2026-45311 Code Injection in deepseek-tui (CVE-2026-45311)
code injection in deepseek-tui (CVE-2026-45311). Successful exploitation can lead to full system takeover. Exploitable via ``run_tests``. Mitigation: upgrade to `0.8.23` or later.
CVE-2026-44592 Vulnerability in CVE-2026-44592 (CVE-2026-44592)
vulnerability in CVE-2026-44592 (CVE-2026-44592). Data can be tampered with by attackers. Mitigation: upgrade to `1.1.1` or later.
CVE-2026-44523 Vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44523)
vulnerability in github.com/enchant97/note-mark/backend (CVE-2026-44523). Confidential information can be exposed externally. Exploitable via ``JWT_SECRET``. Mitigation: upgrade to `0.0.0-20260501152247-18b587758667` or later.
CVE-2026-41315 OS Command Injection in midoks (CVE-2026-41315)
OS command injection in midoks (CVE-2026-41315). Successful exploitation can lead to full system takeover.
CVE-2026-41615 Information Disclosure in microsoft (CVE-2026-41615)
vulnerability in microsoft (CVE-2026-41615). Successful exploitation can lead to full system takeover.
CVE-2026-44990 Cross-Site Scripting (XSS) in sanitize-html (CVE-2026-44990)
cross-site scripting in sanitize-html (CVE-2026-44990). Confidential information can be exposed externally. Exploitable via ``xmp``. Mitigation: upgrade to `2.17.4` or later.
CVE-2026-44542 Path Traversal in github.com/gtsteffaniak/filebrowser (CVE-2026-44542)
path traversal in github.com/gtsteffaniak/filebrowser (CVE-2026-44542). Data can be tampered with by attackers. Exploitable via `DELETE /public/api/resources`. Mitigation: upgrade to `0.0.0-20260501183844-112740bdd41d` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →