Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75807 |
|
Authentication Bypass in wordpress (CVE-2026-75807)
authentication bypass in wordpress (CVE-2026-75807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82475 |
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
| CVE-2026-82474 |
|
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
|
| CVE-2026-82473 |
|
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
|
| CVE-2026-82472 |
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-82463 |
|
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
|
| CVE-2026-82461 |
|
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
|
| CVE-2026-82457 |
|
Vulnerability in CVE-2026-82457 (CVE-2026-82457)
vulnerability in CVE-2026-82457 (CVE-2026-82457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82455 |
|
Vulnerability in CVE-2026-82455 (CVE-2026-82455)
vulnerability in CVE-2026-82455 (CVE-2026-82455). Data can be tampered with by attackers.
|
| CVE-2026-82453 |
|
Vulnerability in CVE-2026-82453 (CVE-2026-82453)
vulnerability in CVE-2026-82453 (CVE-2026-82453). Confidential information can be exposed externally.
|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82447 |
|
Vulnerability in CVE-2026-82447 (CVE-2026-82447)
vulnerability in CVE-2026-82447 (CVE-2026-82447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80192 |
|
Authentication Bypass in CVE-2026-80192 (CVE-2026-80192)
authentication bypass in CVE-2026-80192 (CVE-2026-80192). Confidential information can be exposed externally.
|
| CVE-2026-41012 |
|
Vulnerability in CVE-2026-41012 (CVE-2026-41012)
vulnerability in CVE-2026-41012 (CVE-2026-41012). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55848 |
|
XXE (XML External Entity) in org.mapfish.print:print-lib (CVE-2026-55848)
vulnerability in org.mapfish.print:print-lib (CVE-2026-55848). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-55784 |
|
Vulnerability in github.com/free5gc/ausf (CVE-2026-55784)
vulnerability in github.com/free5gc/ausf (CVE-2026-55784). Risk of unauthorized operations or information disclosure. Exploitable via `POST /nausf-auth/v1/ue-authentications`.
|
| CVE-2026-82333 |
|
Vulnerability in dos (CVE-2026-82333)
vulnerability in dos (CVE-2026-82333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82017 |
|
Vulnerability in CVE-2026-82017 (CVE-2026-82017)
vulnerability in CVE-2026-82017 (CVE-2026-82017). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81533 |
|
Vulnerability in CVE-2026-81533 (CVE-2026-81533)
vulnerability in CVE-2026-81533 (CVE-2026-81533). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81532 |
|
Vulnerability in CVE-2026-81532 (CVE-2026-81532)
vulnerability in CVE-2026-81532 (CVE-2026-81532). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81520 |
|
Vulnerability in CVE-2026-81520 (CVE-2026-81520)
vulnerability in CVE-2026-81520 (CVE-2026-81520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81518 |
|
Vulnerability in CVE-2026-81518 (CVE-2026-81518)
vulnerability in CVE-2026-81518 (CVE-2026-81518). Confidential information can be exposed externally.
|
| CVE-2026-81517 |
|
Vulnerability in CVE-2026-81517 (CVE-2026-81517)
vulnerability in CVE-2026-81517 (CVE-2026-81517). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81490 |
|
Vulnerability in CVE-2026-81490 (CVE-2026-81490)
vulnerability in CVE-2026-81490 (CVE-2026-81490). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77078 |
|
Vulnerability in dos (CVE-2026-77078)
vulnerability in dos (CVE-2026-77078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77037 |
|
Vulnerability in dos (CVE-2026-77037)
vulnerability in dos (CVE-2026-77037). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18904 |
|
Vulnerability in CVE-2026-18904 (CVE-2026-18904)
vulnerability in CVE-2026-18904 (CVE-2026-18904). Confidential information can be exposed externally.
|
| CVE-2026-18899 |
|
Path Traversal in path-traversal (CVE-2026-18899)
path traversal in path-traversal (CVE-2026-18899). Confidential information can be exposed externally.
|
| CVE-2026-18891 |
|
Authentication Bypass in CVE-2026-18891 (CVE-2026-18891)
authentication bypass in CVE-2026-18891 (CVE-2026-18891). Confidential information can be exposed externally.
|
| CVE-2026-18729 |
|
Code Injection in CVE-2026-18729 (CVE-2026-18729)
code injection in CVE-2026-18729 (CVE-2026-18729). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17203 |
|
Authentication Bypass in CVE-2026-17203 (CVE-2026-17203)
authentication bypass in CVE-2026-17203 (CVE-2026-17203). Confidential information can be exposed externally.
|
| CVE-2026-16821 |
|
Vulnerability in CVE-2026-16821 (CVE-2026-16821)
vulnerability in CVE-2026-16821 (CVE-2026-16821). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55841 |
|
Vulnerability in org.graylog2:graylog2-server (CVE-2026-55841)
vulnerability in org.graylog2:graylog2-server (CVE-2026-55841). Data can be tampered with by attackers. Mitigation: upgrade to `7.1.2` or later.
|
| CVE-2026-82291 |
|
Vulnerability in CVE-2026-82291 (CVE-2026-82291)
vulnerability in CVE-2026-82291 (CVE-2026-82291). Confidential information can be exposed externally.
|
| CVE-2026-82289 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82289 (CVE-2026-82289)
SSRF in CVE-2026-82289 (CVE-2026-82289). Confidential information can be exposed externally.
|
| CVE-2026-82288 |
|
Vulnerability in CVE-2026-82288 (CVE-2026-82288)
vulnerability in CVE-2026-82288 (CVE-2026-82288). Confidential information can be exposed externally.
|
| CVE-2026-82287 |
|
Vulnerability in c (CVE-2026-82287)
vulnerability in c (CVE-2026-82287). Confidential information can be exposed externally.
|
| CVE-2026-82286 |
|
Path Traversal in CVE-2026-82286 (CVE-2026-82286)
path traversal in CVE-2026-82286 (CVE-2026-82286). Data can be tampered with by attackers. Exploitable via `POST /crawl`.
|
| CVE-2026-82285 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82285 (CVE-2026-82285)
SSRF in CVE-2026-82285 (CVE-2026-82285). Confidential information can be exposed externally. Exploitable via `POST /api/v1/workflow/report/callback`.
|
| CVE-2026-82284 |
|
Vulnerability in c (CVE-2026-82284)
vulnerability in c (CVE-2026-82284). Confidential information can be exposed externally. Exploitable via `GET /chat/{chat_id}/history`.
|
| CVE-2026-82283 |
|
Vulnerability in CVE-2026-82283 (CVE-2026-82283)
vulnerability in CVE-2026-82283 (CVE-2026-82283). Confidential information can be exposed externally.
|
| CVE-2026-82282 |
|
Vulnerability in CVE-2026-82282 (CVE-2026-82282)
vulnerability in CVE-2026-82282 (CVE-2026-82282). Confidential information can be exposed externally.
|
| CVE-2026-82281 |
|
Vulnerability in CVE-2026-82281 (CVE-2026-82281)
vulnerability in CVE-2026-82281 (CVE-2026-82281). Confidential information can be exposed externally.
|
| CVE-2026-82280 |
|
Vulnerability in CVE-2026-82280 (CVE-2026-82280)
vulnerability in CVE-2026-82280 (CVE-2026-82280). Data can be tampered with by attackers.
|
| CVE-2026-82279 |
|
Vulnerability in CVE-2026-82279 (CVE-2026-82279)
vulnerability in CVE-2026-82279 (CVE-2026-82279). Data can be tampered with by attackers. Exploitable via `PATCH /team/apiKey`.
|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-82275 |
|
Path Traversal in path-traversal (CVE-2026-82275)
path traversal in path-traversal (CVE-2026-82275). Confidential information can be exposed externally.
|
| CVE-2026-82270 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-82270 (CVE-2026-82270)
SSRF in CVE-2026-82270 (CVE-2026-82270). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-82269 |
|
Vulnerability in CVE-2026-82269 (CVE-2026-82269)
vulnerability in CVE-2026-82269 (CVE-2026-82269). Confidential information can be exposed externally.
|