Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-3828 |
|
Vulnerability in CVE-2026-3828 (CVE-2026-3828)
vulnerability in CVE-2026-3828 (CVE-2026-3828). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42301 |
|
Vulnerability in CVE-2026-42301 (CVE-2026-42301)
vulnerability in CVE-2026-42301 (CVE-2026-42301). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42296 |
|
Authorization Flaw in CVE-2026-42296 (CVE-2026-42296)
vulnerability in CVE-2026-42296 (CVE-2026-42296). Confidential information can be exposed externally.
|
| CVE-2026-41311 |
|
Vulnerability in dos (CVE-2026-41311)
vulnerability in dos (CVE-2026-41311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6665 |
|
Vulnerability in CVE-2026-6665 (CVE-2026-6665)
vulnerability in CVE-2026-6665 (CVE-2026-6665). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6664 |
|
Vulnerability in CVE-2026-6664 (CVE-2026-6664)
vulnerability in CVE-2026-6664 (CVE-2026-6664). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41705 |
|
Vulnerability in CVE-2026-41705 (CVE-2026-41705)
vulnerability in CVE-2026-41705 (CVE-2026-41705). Confidential information can be exposed externally.
|
| CVE-2026-42556 |
|
Cross-Site Scripting (XSS) in CVE-2026-42556 (CVE-2026-42556)
cross-site scripting in CVE-2026-42556 (CVE-2026-42556). Confidential information can be exposed externally.
|
| CVE-2026-42452 |
|
Vulnerability in CVE-2026-42452 (CVE-2026-42452)
vulnerability in CVE-2026-42452 (CVE-2026-42452). Confidential information can be exposed externally.
|
| CVE-2026-42352 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-42352 (CVE-2026-42352)
SSRF in CVE-2026-42352 (CVE-2026-42352). Confidential information can be exposed externally.
|
| CVE-2026-42351 |
|
Path Traversal in CVE-2026-42351 (CVE-2026-42351)
path traversal in CVE-2026-42351 (CVE-2026-42351). Confidential information can be exposed externally.
|
| CVE-2026-42345 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-42345 (CVE-2026-42345)
SSRF in CVE-2026-42345 (CVE-2026-42345). Confidential information can be exposed externally.
|
| CVE-2026-42224 |
|
Cross-Site Scripting (XSS) in CVE-2026-42224 (CVE-2026-42224)
cross-site scripting in CVE-2026-42224 (CVE-2026-42224). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41520 |
|
Information Disclosure in CVE-2026-41520 (CVE-2026-41520)
vulnerability in CVE-2026-41520 (CVE-2026-41520). Confidential information can be exposed externally.
|
| CVE-2026-41432 |
|
Vulnerability in CVE-2026-41432 (CVE-2026-41432)
vulnerability in CVE-2026-41432 (CVE-2026-41432). Data can be tampered with by attackers.
|
| CVE-2026-42205 |
|
Vulnerability in rails (CVE-2026-42205)
vulnerability in rails (CVE-2026-42205). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44400 |
|
Vulnerability in CVE-2026-44400 (CVE-2026-44400)
vulnerability in CVE-2026-44400 (CVE-2026-44400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7807 |
|
Path Traversal in CVE-2026-7807 (CVE-2026-7807)
path traversal in CVE-2026-7807 (CVE-2026-7807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42189 |
|
Vulnerability in CVE-2026-42189 (CVE-2026-42189)
vulnerability in CVE-2026-42189 (CVE-2026-42189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8178 |
|
Vulnerability in Amazon aws (CVE-2026-8178)
vulnerability in Amazon aws (CVE-2026-8178). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29203 |
|
Vulnerability in privilege-escalation (CVE-2026-29203)
vulnerability in privilege-escalation (CVE-2026-29203). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29202 |
|
Vulnerability in CVE-2026-29202 (CVE-2026-29202)
vulnerability in CVE-2026-29202 (CVE-2026-29202). Successful exploitation can lead to full system takeover. Exploitable via ``plugin``.
|
| CVE-2026-6659 |
|
Vulnerability in CVE-2026-6659 (CVE-2026-6659)
vulnerability in CVE-2026-6659 (CVE-2026-6659). Confidential information can be exposed externally.
|
| CVE-2026-42353 |
|
Path Traversal in express (CVE-2026-42353)
path traversal in express (CVE-2026-42353). Confidential information can be exposed externally.
|
| CVE-2026-41886 |
|
Cross-Site Scripting (XSS) in CVE-2026-41886 (CVE-2026-41886)
cross-site scripting in CVE-2026-41886 (CVE-2026-41886). Data can be tampered with by attackers.
|
| CVE-2026-41883 |
|
Vulnerability in CVE-2026-41883 (CVE-2026-41883)
vulnerability in CVE-2026-41883 (CVE-2026-41883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41693 |
|
Path Traversal in CVE-2026-41693 (CVE-2026-41693)
path traversal in CVE-2026-41693 (CVE-2026-41693). Confidential information can be exposed externally.
|
| CVE-2026-41690 |
|
Path Traversal in express (CVE-2026-41690)
path traversal in express (CVE-2026-41690). Data can be tampered with by attackers.
|
| CVE-2026-41683 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-41683)
cross-site scripting in express (CVE-2026-41683). Data can be tampered with by attackers.
|
| CVE-2026-34354 |
|
Vulnerability in privilege-escalation (CVE-2026-34354)
vulnerability in privilege-escalation (CVE-2026-34354). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29975 |
|
Vulnerability in c (CVE-2026-29975)
vulnerability in c (CVE-2026-29975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29974 |
|
Vulnerability in CVE-2026-29974 (CVE-2026-29974)
vulnerability in CVE-2026-29974 (CVE-2026-29974). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29972 |
|
Vulnerability in c (CVE-2026-29972)
vulnerability in c (CVE-2026-29972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44498 |
|
Vulnerability in zfnd (CVE-2026-44498)
vulnerability in zfnd (CVE-2026-44498). Data can be tampered with by attackers.
|
| CVE-2026-41584 |
|
Vulnerability in zfnd (CVE-2026-41584)
vulnerability in zfnd (CVE-2026-41584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41576 |
|
Cross-Site Scripting (XSS) in CVE-2026-41576 (CVE-2026-41576)
cross-site scripting in CVE-2026-41576 (CVE-2026-41576). Confidential information can be exposed externally.
|
| CVE-2026-41570 |
|
Vulnerability in phpunit-project (CVE-2026-41570)
vulnerability in phpunit-project (CVE-2026-41570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41524 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-41524)
cross-site scripting in laravel (CVE-2026-41524). Confidential information can be exposed externally.
|
| CVE-2026-38361 |
|
Vulnerability in CVE-2026-38361 (CVE-2026-38361)
vulnerability in CVE-2026-38361 (CVE-2026-38361). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44340 |
|
Path Traversal in praison (CVE-2026-44340)
path traversal in praison (CVE-2026-44340). Data can be tampered with by attackers.
|
| CVE-2026-44339 |
|
Vulnerability in praison (CVE-2026-44339)
vulnerability in praison (CVE-2026-44339). Data can be tampered with by attackers.
|
| CVE-2026-44338 |
|
Vulnerability in c (CVE-2026-44338)
vulnerability in c (CVE-2026-44338). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44334 |
|
Code Injection in praison (CVE-2026-44334)
code injection in praison (CVE-2026-44334). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/recipes/run`.
|
| CVE-2026-41496 |
|
SQL Injection in praison (CVE-2026-41496)
SQL injection in praison (CVE-2026-41496). Confidential information can be exposed externally.
|
| CVE-2026-41491 |
|
Path Traversal in path-traversal (CVE-2026-41491)
path traversal in path-traversal (CVE-2026-41491). Confidential information can be exposed externally.
|
| CVE-2026-39816 |
|
Vulnerability in apache (CVE-2026-39816)
vulnerability in apache (CVE-2026-39816). Successful exploitation can lead to full system takeover.
|
| CVE-2025-66467 |
|
Vulnerability in apache (CVE-2025-66467)
vulnerability in apache (CVE-2025-66467). Successful exploitation can lead to full system takeover.
|
| CVE-2022-50994 |
|
OS Command Injection in CVE-2022-50994 (CVE-2022-50994)
OS command injection in CVE-2022-50994 (CVE-2022-50994). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7330 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7330)
cross-site scripting in wordpress (CVE-2026-7330). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5127 |
|
Unsafe Deserialization in wordpress (CVE-2026-5127)
vulnerability in wordpress (CVE-2026-5127). Successful exploitation can lead to full system takeover.
|