Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55852 |
|
Path Traversal in CVE-2026-55852 (CVE-2026-55852)
path traversal in CVE-2026-55852 (CVE-2026-55852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15282 |
|
Unrestricted File Upload in wordpress (CVE-2026-15282)
vulnerability in wordpress (CVE-2026-15282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15070 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15070)
vulnerability in wordpress (CVE-2026-15070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13430 |
|
Unrestricted File Upload in wordpress (CVE-2026-13430)
vulnerability in wordpress (CVE-2026-13430). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14894 |
|
Unrestricted File Upload in wordpress (CVE-2026-14894)
vulnerability in wordpress (CVE-2026-14894). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58123 |
|
Vulnerability in CVE-2026-58123 (CVE-2026-58123)
vulnerability in CVE-2026-58123 (CVE-2026-58123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55420 |
|
OS Command Injection in discourse (CVE-2026-55420)
OS command injection in discourse (CVE-2026-55420). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.6.0` or later.
|
| CVE-2026-14261 |
|
Vulnerability in CVE-2026-14261 (CVE-2026-14261)
vulnerability in CVE-2026-14261 (CVE-2026-14261). Confidential information can be exposed externally.
|
| CVE-2026-12116 |
|
Vulnerability in CVE-2026-12116 (CVE-2026-12116)
vulnerability in CVE-2026-12116 (CVE-2026-12116). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14372 |
|
Path Traversal in wordpress (CVE-2026-14372)
path traversal in wordpress (CVE-2026-14372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56291 KEV |
|
[KEV] Unrestricted File Upload in Balbooa forms (CVE-2026-56291)
vulnerability in Balbooa forms (CVE-2026-56291). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-15158 |
|
Unrestricted File Upload in wordpress (CVE-2026-15158)
vulnerability in wordpress (CVE-2026-15158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8848 |
|
Vulnerability in wordpress (CVE-2026-8848)
vulnerability in wordpress (CVE-2026-8848). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56297 |
|
Vulnerability in dos (CVE-2026-56297)
vulnerability in dos (CVE-2026-56297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58654 |
|
Unrestricted File Upload in path-traversal (CVE-2026-58654)
vulnerability in path-traversal (CVE-2026-58654). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-58480 |
|
Unrestricted File Upload in wordpress (CVE-2026-58480)
vulnerability in wordpress (CVE-2026-58480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12378 |
|
Vulnerability in wordpress (CVE-2026-12378)
vulnerability in wordpress (CVE-2026-12378). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14489 |
|
Unrestricted File Upload in wordpress (CVE-2026-14489)
vulnerability in wordpress (CVE-2026-14489). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14487 |
|
Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
|
| CVE-2026-14158 |
|
Unrestricted File Upload in wordpress (CVE-2026-14158)
vulnerability in wordpress (CVE-2026-14158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55408 |
|
Code Injection in CVE-2026-55408 (CVE-2026-55408)
code injection in CVE-2026-55408 (CVE-2026-55408). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55633 |
|
Unrestricted File Upload in CVE-2026-55633 (CVE-2026-55633)
vulnerability in CVE-2026-55633 (CVE-2026-55633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49471 |
|
Vulnerability in serena-agent (CVE-2026-49471)
vulnerability in serena-agent (CVE-2026-49471). Successful exploitation can lead to full system takeover. Exploitable via `Host header`. Mitigation: upgrade to `1.5.2` or later.
|
| CVE-2026-23698 |
|
Unrestricted File Upload in apache (CVE-2026-23698)
vulnerability in apache (CVE-2026-23698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23697 |
|
Unrestricted File Upload in apache (CVE-2026-23697)
vulnerability in apache (CVE-2026-23697). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6101 |
|
Vulnerability in wordpress (CVE-2026-6101)
vulnerability in wordpress (CVE-2026-6101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40187 |
|
OS Command Injection in egroupware/egroupware (CVE-2026-40187)
OS command injection in egroupware/egroupware (CVE-2026-40187). Risk of unauthorized operations or information disclosure. Exploitable via ``chgrp``. Mitigation: upgrade to `23.1.20260601` or later.
|
| CVE-2026-27823 |
|
Path Traversal in egroupware/egroupware (CVE-2026-27823)
path traversal in egroupware/egroupware (CVE-2026-27823). Risk of unauthorized operations or information disclosure. Exploitable via ``participant_role``. Mitigation: upgrade to `23.1.20260224` or later.
|
| CVE-2026-33264 |
|
Unsafe Deserialization in apache (CVE-2026-33264)
vulnerability in apache (CVE-2026-33264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4375 |
|
Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55615 |
|
Vulnerability in langroid (CVE-2026-55615)
vulnerability in langroid (CVE-2026-55615). Risk of unauthorized operations or information disclosure. Exploitable via ``Neo4jChatAgent``. Mitigation: upgrade to `0.65.5` or later.
|
| CVE-2026-57571 |
|
Path Traversal in kidocode (CVE-2026-57571)
path traversal in kidocode (CVE-2026-57571). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34038 |
|
OS Command Injection in CVE-2026-34038 (CVE-2026-34038)
OS command injection in CVE-2026-34038 (CVE-2026-34038). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54769 |
|
Code Injection in langroid (CVE-2026-54769)
code injection in langroid (CVE-2026-54769). Successful exploitation can lead to full system takeover. Exploitable via ``TableChatAgent``. Mitigation: upgrade to `0.65.2` or later.
|
| CVE-2026-43825 |
|
Unsafe Deserialization in apache (CVE-2026-43825)
vulnerability in apache (CVE-2026-43825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52889 |
|
Vulnerability in verbb/formie (CVE-2026-52889)
vulnerability in verbb/formie (CVE-2026-52889). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.27` or later.
|
| CVE-2026-53913 |
|
Authentication Bypass in org.apache.camel:camel-keycloak (CVE-2026-53913)
authentication bypass in org.apache.camel:camel-keycloak (CVE-2026-53913). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-40859 |
|
Unsafe Deserialization in org.apache.camel:camel-vertx-http (CVE-2026-40859)
vulnerability in org.apache.camel:camel-vertx-http (CVE-2026-40859). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-43865 |
|
Unsafe Deserialization in org.apache.camel:camel-hazelcast (CVE-2026-43865)
vulnerability in org.apache.camel:camel-hazelcast (CVE-2026-43865). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-11962 |
|
Vulnerability in wordpress (CVE-2026-11962)
vulnerability in wordpress (CVE-2026-11962). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12195 |
|
OS Command Injection in CVE-2026-12195 (CVE-2026-12195)
OS command injection in CVE-2026-12195 (CVE-2026-12195). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71364 |
|
Unsafe Deserialization in picklescan (CVE-2025-71364)
vulnerability in picklescan (CVE-2025-71364). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.30` or later.
|
| CVE-2025-71359 |
|
Unsafe Deserialization in picklescan (CVE-2025-71359)
vulnerability in picklescan (CVE-2025-71359). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.29` or later.
|
| CVE-2025-71369 |
|
Unsafe Deserialization in picklescan (CVE-2025-71369)
vulnerability in picklescan (CVE-2025-71369). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.28` or later.
|
| CVE-2025-71345 |
|
Unsafe Deserialization in picklescan (CVE-2025-71345)
vulnerability in picklescan (CVE-2025-71345). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.30` or later.
|
| CVE-2025-71342 |
|
Unsafe Deserialization in picklescan (CVE-2025-71342)
vulnerability in picklescan (CVE-2025-71342). Confidential information can be exposed externally. Mitigation: upgrade to `0.0.30` or later.
|
| CVE-2026-9725 |
|
Path Traversal in wordpress (CVE-2026-9725)
path traversal in wordpress (CVE-2026-9725). Data can be tampered with by attackers.
|
| CVE-2026-50722 |
|
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
|
| CVE-2026-50721 |
|
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
|