Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-1606 |
|
Code Injection in gitlab (CVE-2026-1606)
code injection in gitlab (CVE-2026-1606). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-12635 |
|
Vulnerability in gitlab (CVE-2026-12635)
vulnerability in gitlab (CVE-2026-12635). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-11379 |
|
Authorization Flaw in gitlab (CVE-2026-11379)
vulnerability in gitlab (CVE-2026-11379). Confidential information can be exposed externally. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-12053 |
|
Vulnerability in gitlab (CVE-2026-12053)
vulnerability in gitlab (CVE-2026-12053). Confidential information can be exposed externally. Mitigation: upgrade to `19.1.1` or later.
|
| CVE-2026-2508 |
|
SQL Injection in wordpress (CVE-2026-2508)
SQL injection in wordpress (CVE-2026-2508). Confidential information can be exposed externally.
|
| CVE-2026-0934 |
|
Authorization Flaw in gitlab (CVE-2026-0934)
vulnerability in gitlab (CVE-2026-0934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-10712 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2026-10712)
cross-site scripting in gitlab (CVE-2026-10712). Confidential information can be exposed externally. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-12077 |
|
SQL Injection in wordpress (CVE-2026-12077)
SQL injection in wordpress (CVE-2026-12077). Confidential information can be exposed externally.
|
| CVE-2026-10833 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10833)
cross-site scripting in wordpress (CVE-2026-10833). Risk of unauthorized operations or information disclosure.
|
| BELL-CVE-2026-56117 |
|
BELL-CVE-2026-56117 |
| BELL-CVE-2026-56116 |
|
BELL-CVE-2026-56116 |
| BELL-CVE-2026-56114 |
|
BELL-CVE-2026-56114 |
| BELL-CVE-2026-57062 |
|
BELL-CVE-2026-57062 |
| BELL-CVE-2026-56113 |
|
BELL-CVE-2026-56113 |
| BELL-CVE-2026-11940 |
|
BELL-CVE-2026-11940 |
| BELL-CVE-2026-52937 |
|
BELL-CVE-2026-52937 |
| BELL-CVE-2026-52941 |
|
BELL-CVE-2026-52941 |
| BELL-CVE-2026-52940 |
|
BELL-CVE-2026-52940 |
| BELL-CVE-2026-52939 |
|
BELL-CVE-2026-52939 |
| BELL-CVE-2026-53129 |
|
BELL-CVE-2026-53129 |
| BELL-CVE-2026-52935 |
|
BELL-CVE-2026-52935 |
| BELL-CVE-2026-52929 |
|
BELL-CVE-2026-52929 |
| BELL-CVE-2026-52943 |
|
BELL-CVE-2026-52943 |
| BELL-CVE-2026-52942 |
|
BELL-CVE-2026-52942 |
| BELL-CVE-2026-52933 |
|
BELL-CVE-2026-52933 |
| BELL-CVE-2026-53100 |
|
BELL-CVE-2026-53100 |
| BELL-CVE-2026-52925 |
|
BELL-CVE-2026-52925 |
| BELL-CVE-2026-52928 |
|
BELL-CVE-2026-52928 |
| BELL-CVE-2026-52924 |
|
BELL-CVE-2026-52924 |
| BELL-CVE-2026-52917 |
|
BELL-CVE-2026-52917 |
| BELL-CVE-2026-53091 |
|
BELL-CVE-2026-53091 |
| BELL-CVE-2026-52912 |
|
BELL-CVE-2026-52912 |
| BELL-CVE-2026-52921 |
|
BELL-CVE-2026-52921 |
| BELL-CVE-2026-52936 |
|
BELL-CVE-2026-52936 |
| BELL-CVE-2026-52930 |
|
BELL-CVE-2026-52930 |
| BELL-CVE-2026-52927 |
|
BELL-CVE-2026-52927 |
| BELL-CVE-2026-52923 |
|
BELL-CVE-2026-52923 |
| BELL-CVE-2026-52918 |
|
BELL-CVE-2026-52918 |
| BELL-CVE-2026-52915 |
|
BELL-CVE-2026-52915 |
| BELL-CVE-2026-52920 |
|
BELL-CVE-2026-52920 |
| RLSA-2026:27812 |
|
Vulnerability in kernel-rt (RLSA-2026:27812)
vulnerability in kernel-rt (RLSA-2026:27812). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:4.18.0-553.137.1.rt7.478.el8_10` or later.
|
| RLSA-2026:28998 |
|
Vulnerability in evince (RLSA-2026:28998)
vulnerability in evince (RLSA-2026:28998). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:3.28.4-17.el8_10` or later.
|
| RLSA-2026:28922 |
|
Vulnerability in libreoffice (RLSA-2026:28922)
vulnerability in libreoffice (RLSA-2026:28922). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:6.4.7.2-20.el8_10` or later.
|
| RLSA-2026:28923 |
|
Vulnerability in tigervnc (RLSA-2026:28923)
vulnerability in tigervnc (RLSA-2026:28923). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:1.15.0-10.el8_10` or later.
|
| RLSA-2026:27717 |
|
Vulnerability in firefox (RLSA-2026:27717)
vulnerability in firefox (RLSA-2026:27717). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:140.12.0-1.el8_10` or later.
|
| RLSA-2026:28553 |
|
Vulnerability in vim (RLSA-2026:28553)
vulnerability in vim (RLSA-2026:28553). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2:8.0.1763-24.el8_10` or later.
|
| RLSA-2026:27811 |
|
Vulnerability in kernel (RLSA-2026:27811)
vulnerability in kernel (RLSA-2026:27811). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0:4.18.0-553.137.1.el8_10` or later.
|
| GHSA-g6fx-78q6-3hqv |
|
Vulnerability in easy-time-format (GHSA-g6fx-78q6-3hqv)
vulnerability in easy-time-format (GHSA-g6fx-78q6-3hqv). Risk of unauthorized operations or information disclosure.
|
| GHSA-wp9r-fqrq-cg5h |
|
Vulnerability in tokenization-util (GHSA-wp9r-fqrq-cg5h)
vulnerability in tokenization-util (GHSA-wp9r-fqrq-cg5h). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13311 |
|
Vulnerability in shell-quote (CVE-2026-13311)
vulnerability in shell-quote (CVE-2026-13311). Risk of unauthorized operations or information disclosure. Exploitable via `GET /ping`. Mitigation: upgrade to `1.9.0` or later.
|