Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75583 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75583)
SSRF in ssrf (CVE-2026-75583). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75147 |
|
Out-of-Bounds Read in c (CVE-2026-75147)
vulnerability in c (CVE-2026-75147). Confidential information can be exposed externally.
|
| CVE-2026-75146 |
|
Out-of-Bounds Read in c (CVE-2026-75146)
vulnerability in c (CVE-2026-75146). Confidential information can be exposed externally.
|
| CVE-2026-75145 |
|
Vulnerability in c (CVE-2026-75145)
vulnerability in c (CVE-2026-75145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75144 |
|
Vulnerability in c (CVE-2026-75144)
vulnerability in c (CVE-2026-75144). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75143 |
|
Vulnerability in c (CVE-2026-75143)
vulnerability in c (CVE-2026-75143). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75142 |
|
Vulnerability in c (CVE-2026-75142)
vulnerability in c (CVE-2026-75142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75141 |
|
Vulnerability in CVE-2026-75141 (CVE-2026-75141)
vulnerability in CVE-2026-75141 (CVE-2026-75141). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72530 KEV |
|
[KEV] Code Injection in trueconf (CVE-2026-72530)
code injection in trueconf (CVE-2026-72530). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-72529 KEV |
|
[KEV] Vulnerability in trueconf (CVE-2026-72529)
vulnerability in trueconf (CVE-2026-72529). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-71470 |
|
Vulnerability in privilege-escalation (CVE-2026-71470)
vulnerability in privilege-escalation (CVE-2026-71470). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50173 |
|
Authorization Flaw in CVE-2026-50173 (CVE-2026-50173)
vulnerability in CVE-2026-50173 (CVE-2026-50173). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/apps/{app_id}/invoke/presign`.
|
| CVE-2026-49441 |
|
Vulnerability in CVE-2026-49441 (CVE-2026-49441)
vulnerability in CVE-2026-49441 (CVE-2026-49441). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49392 |
|
Vulnerability in cpp (CVE-2026-49392)
vulnerability in cpp (CVE-2026-49392). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48162 |
|
Vulnerability in CVE-2026-48162 (CVE-2026-48162)
vulnerability in CVE-2026-48162 (CVE-2026-48162). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48024 |
|
Path Traversal in CVE-2026-48024 (CVE-2026-48024)
path traversal in CVE-2026-48024 (CVE-2026-48024). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45798 |
|
Vulnerability in c (CVE-2026-45798)
vulnerability in c (CVE-2026-45798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44901 |
|
Unsafe Deserialization in CVE-2026-44901 (CVE-2026-44901)
vulnerability in CVE-2026-44901 (CVE-2026-44901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44256 |
|
Vulnerability in CVE-2026-44256 (CVE-2026-44256)
vulnerability in CVE-2026-44256 (CVE-2026-44256). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44255 |
|
Vulnerability in CVE-2026-44255 (CVE-2026-44255)
vulnerability in CVE-2026-44255 (CVE-2026-44255). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41424 |
|
Authorization Flaw in CVE-2026-41424 (CVE-2026-41424)
vulnerability in CVE-2026-41424 (CVE-2026-41424). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /security/users/{user_id}`.
|
| CVE-2026-20359 |
|
Vulnerability in CVE-2026-20359 (CVE-2026-20359)
vulnerability in CVE-2026-20359 (CVE-2026-20359). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20358 |
|
Vulnerability in CVE-2026-20358 (CVE-2026-20358)
vulnerability in CVE-2026-20358 (CVE-2026-20358). Data can be tampered with by attackers.
|
| CVE-2026-20357 |
|
Vulnerability in CVE-2026-20357 (CVE-2026-20357)
vulnerability in CVE-2026-20357 (CVE-2026-20357). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20319 |
|
Buffer Overflow in CVE-2026-20319 (CVE-2026-20319)
vulnerability in CVE-2026-20319 (CVE-2026-20319). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20318 |
|
Vulnerability in CVE-2026-20318 (CVE-2026-20318)
vulnerability in CVE-2026-20318 (CVE-2026-20318). Data can be tampered with by attackers.
|
| CVE-2026-20317 |
|
Authentication Bypass in CVE-2026-20317 (CVE-2026-20317)
authentication bypass in CVE-2026-20317 (CVE-2026-20317). Data can be tampered with by attackers.
|
| CVE-2026-20315 |
|
Vulnerability in CVE-2026-20315 (CVE-2026-20315)
vulnerability in CVE-2026-20315 (CVE-2026-20315). Successful exploitation can lead to full system takeover.
|
| CVE-2024-13942 |
|
Vulnerability in CVE-2024-13942 (CVE-2024-13942)
vulnerability in CVE-2024-13942 (CVE-2024-13942). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64852 |
|
Vulnerability in CVE-2026-64852 (CVE-2026-64852)
vulnerability in CVE-2026-64852 (CVE-2026-64852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64851 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-64851)
cross-site scripting in wordpress (CVE-2026-64851). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64850 |
|
Code Injection in CVE-2026-64850 (CVE-2026-64850)
code injection in CVE-2026-64850 (CVE-2026-64850). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63408 |
|
Vulnerability in apache (CVE-2026-63408)
vulnerability in apache (CVE-2026-63408). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-63407 |
|
Vulnerability in CVE-2026-63407 (CVE-2026-63407)
vulnerability in CVE-2026-63407 (CVE-2026-63407). Confidential information can be exposed externally.
|
| CVE-2026-62673 |
|
Vulnerability in getgrav/grav (CVE-2026-62673)
vulnerability in getgrav/grav (CVE-2026-62673). Risk of unauthorized operations or information disclosure. Exploitable via `GET /user/plugins/my-plugin/my-plugin.YAML`. Mitigation: upgrade to `2.0.4` or later.
|
| CVE-2026-62672 |
|
Vulnerability in CVE-2026-62672 (CVE-2026-62672)
vulnerability in CVE-2026-62672 (CVE-2026-62672). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62671 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-62671 (CVE-2026-62671)
vulnerability in CVE-2026-62671 (CVE-2026-62671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62670 |
|
Vulnerability in CVE-2026-62670 (CVE-2026-62670)
vulnerability in CVE-2026-62670 (CVE-2026-62670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62669 |
|
Authentication Bypass in CVE-2026-62669 (CVE-2026-62669)
authentication bypass in CVE-2026-62669 (CVE-2026-62669). Confidential information can be exposed externally.
|
| CVE-2026-62668 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-62668 (CVE-2026-62668)
SSRF in CVE-2026-62668 (CVE-2026-62668). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62667 |
|
Vulnerability in CVE-2026-62667 (CVE-2026-62667)
vulnerability in CVE-2026-62667 (CVE-2026-62667). Confidential information can be exposed externally.
|
| CVE-2026-62666 |
|
Vulnerability in CVE-2026-62666 (CVE-2026-62666)
vulnerability in CVE-2026-62666 (CVE-2026-62666). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61842 |
|
Information Disclosure in CVE-2026-61842 (CVE-2026-61842)
vulnerability in CVE-2026-61842 (CVE-2026-61842). Confidential information can be exposed externally.
|
| CVE-2026-61690 |
|
Vulnerability in CVE-2026-61690 (CVE-2026-61690)
vulnerability in CVE-2026-61690 (CVE-2026-61690). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61607 |
|
Cross-Site Scripting (XSS) in CVE-2026-61607 (CVE-2026-61607)
cross-site scripting in CVE-2026-61607 (CVE-2026-61607). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/media`.
|
| CVE-2026-53654 |
|
Open Redirect in CVE-2026-53654 (CVE-2026-53654)
vulnerability in CVE-2026-53654 (CVE-2026-53654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46343 |
|
Path Traversal in CVE-2026-46343 (CVE-2026-46343)
path traversal in CVE-2026-46343 (CVE-2026-46343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44254 |
|
Vulnerability in c (CVE-2026-44254)
vulnerability in c (CVE-2026-44254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44253 |
|
Vulnerability in CVE-2026-44253 (CVE-2026-44253)
vulnerability in CVE-2026-44253 (CVE-2026-44253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44252 |
|
Authorization Flaw in CVE-2026-44252 (CVE-2026-44252)
vulnerability in CVE-2026-44252 (CVE-2026-44252). Risk of unauthorized operations or information disclosure. Exploitable via `GET /manager/configuration`.
|