Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-18322 |
|
Privilege Escalation in wordpress (CVE-2026-18322)
vulnerability in wordpress (CVE-2026-18322). Successful exploitation can lead to full system takeover. Exploitable via ``save``.
|
| CVE-2026-16143 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16143)
cross-site scripting in wordpress (CVE-2026-16143). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18902 |
|
Vulnerability in CVE-2026-18902 (CVE-2026-18902)
vulnerability in CVE-2026-18902 (CVE-2026-18902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18901 |
|
Vulnerability in CVE-2026-18901 (CVE-2026-18901)
vulnerability in CVE-2026-18901 (CVE-2026-18901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18900 |
|
Command Injection in CVE-2026-18900 (CVE-2026-18900)
command injection in CVE-2026-18900 (CVE-2026-18900). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18898 |
|
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the...
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the...
|
| CVE-2026-18907 |
|
Vulnerability in path-traversal (CVE-2026-18907)
vulnerability in path-traversal (CVE-2026-18907). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18897 |
|
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted...
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted...
|
| CVE-2026-18895 |
|
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function...
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function...
|
| CVE-2026-18859 |
|
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of...
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of...
|
| CVE-2026-18854 |
|
Vulnerability in sqli (CVE-2026-18854)
vulnerability in sqli (CVE-2026-18854). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70619 |
|
Vulnerability in CVE-2026-70619 (CVE-2026-70619)
vulnerability in CVE-2026-70619 (CVE-2026-70619). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67862 |
|
Vulnerability in c (CVE-2026-67862)
vulnerability in c (CVE-2026-67862). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67861 |
|
Vulnerability in dos (CVE-2026-67861)
vulnerability in dos (CVE-2026-67861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67860 |
|
Vulnerability in CVE-2026-67860 (CVE-2026-67860)
vulnerability in CVE-2026-67860 (CVE-2026-67860). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67859 |
|
Vulnerability in dos (CVE-2026-67859)
vulnerability in dos (CVE-2026-67859). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67858 |
|
Vulnerability in dos (CVE-2026-67858)
vulnerability in dos (CVE-2026-67858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67857 |
|
Out-of-Bounds Read in c (CVE-2026-67857)
vulnerability in c (CVE-2026-67857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67856 |
|
Vulnerability in dos (CVE-2026-67856)
vulnerability in dos (CVE-2026-67856). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67855 |
|
Vulnerability in dos (CVE-2026-67855)
vulnerability in dos (CVE-2026-67855). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45103 |
|
Vulnerability in CVE-2026-45103 (CVE-2026-45103)
vulnerability in CVE-2026-45103 (CVE-2026-45103). Data can be tampered with by attackers.
|
| CVE-2026-18814 |
|
Vulnerability in CVE-2026-18814 (CVE-2026-18814)
vulnerability in CVE-2026-18814 (CVE-2026-18814). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66901 |
|
Vulnerability in CVE-2026-66901 (CVE-2026-66901)
vulnerability in CVE-2026-66901 (CVE-2026-66901). Confidential information can be exposed externally.
|
| CVE-2026-51401 |
|
Code Injection in c (CVE-2026-51401)
code injection in c (CVE-2026-51401). Confidential information can be exposed externally.
|
| CVE-2026-18811 |
|
Vulnerability in CVE-2026-18811 (CVE-2026-18811)
vulnerability in CVE-2026-18811 (CVE-2026-18811). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51400 |
|
Vulnerability in c (CVE-2026-51400)
vulnerability in c (CVE-2026-51400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18813 |
|
Vulnerability in c (CVE-2026-18813)
vulnerability in c (CVE-2026-18813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18812 |
|
Vulnerability in CVE-2026-18812 (CVE-2026-18812)
vulnerability in CVE-2026-18812 (CVE-2026-18812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70494 |
|
Vulnerability in open-webui (CVE-2026-70494)
vulnerability in open-webui (CVE-2026-70494). Data can be tampered with by attackers. Exploitable via `DELETE /api/v1/folders/{id}`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70492 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-70492)
cross-site scripting in open-webui (CVE-2026-70492). Confidential information can be exposed externally. Exploitable via ``catch``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-18656 |
|
Vulnerability in Amazon aws (CVE-2026-18656)
vulnerability in Amazon aws (CVE-2026-18656). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18810 |
|
Authentication Bypass in CVE-2026-18810 (CVE-2026-18810)
authentication bypass in CVE-2026-18810 (CVE-2026-18810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18657 |
|
Vulnerability in amazon (CVE-2026-18657)
vulnerability in amazon (CVE-2026-18657). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16793 |
|
Vulnerability in CVE-2026-16793 (CVE-2026-16793)
vulnerability in CVE-2026-16793 (CVE-2026-16793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70486 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-70486)
cross-site scripting in open-webui (CVE-2026-70486). Confidential information can be exposed externally. Exploitable via ``TERMINAL_SERVER_CONNECTIONS``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70485 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70485)
SSRF in open-webui (CVE-2026-70485). Confidential information can be exposed externally. Exploitable via `POST /api/v1/retrieval/process/web`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70482 |
|
Authentication Bypass in open-webui (CVE-2026-70482)
authentication bypass in open-webui (CVE-2026-70482). Confidential information can be exposed externally. Exploitable via `POST /api/v1/auths/oauth/{provider}/token/exchange`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70479 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70479)
SSRF in open-webui (CVE-2026-70479). Confidential information can be exposed externally. Exploitable via ``PLAYWRIGHT_WS_URL``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-47623 |
|
Unsafe Deserialization in dos (CVE-2026-47623)
vulnerability in dos (CVE-2026-47623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24255 |
|
Vulnerability in nvidia (CVE-2026-24255)
vulnerability in nvidia (CVE-2026-24255). Data can be tampered with by attackers.
|
| CVE-2026-47618 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47618)
SSRF in nvidia (CVE-2026-47618). Confidential information can be exposed externally.
|
| CVE-2026-47617 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47617)
SSRF in nvidia (CVE-2026-47617). Confidential information can be exposed externally.
|
| CVE-2026-47613 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47613)
SSRF in nvidia (CVE-2026-47613). Confidential information can be exposed externally.
|
| CVE-2026-18788 |
|
Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24253 |
|
Out-of-Bounds Write in dos (CVE-2026-24253)
out-of-bounds write in dos (CVE-2026-24253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47614 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47614)
SSRF in nvidia (CVE-2026-47614). Confidential information can be exposed externally.
|
| CVE-2026-47616 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47616)
SSRF in nvidia (CVE-2026-47616). Confidential information can be exposed externally.
|
| CVE-2026-47612 |
|
Path Traversal in nvidia (CVE-2026-47612)
path traversal in nvidia (CVE-2026-47612). Confidential information can be exposed externally.
|
| CVE-2026-47615 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47615)
SSRF in nvidia (CVE-2026-47615). Confidential information can be exposed externally.
|
| CVE-2026-15314 |
|
Vulnerability in tp-link (CVE-2026-15314)
vulnerability in tp-link (CVE-2026-15314). Risk of unauthorized operations or information disclosure.
|