Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-3183 |
|
Vulnerability in CVE-2026-3183 (CVE-2026-3183)
vulnerability in CVE-2026-3183 (CVE-2026-3183). Data can be tampered with by attackers.
|
| CVE-2026-15812 |
|
Vulnerability in CVE-2026-15812 (CVE-2026-15812)
vulnerability in CVE-2026-15812 (CVE-2026-15812). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16076 |
|
Authentication Bypass in CVE-2026-16076 (CVE-2026-16076)
authentication bypass in CVE-2026-16076 (CVE-2026-16076). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62224 |
|
Vulnerability in CVE-2026-62224 (CVE-2026-62224)
vulnerability in CVE-2026-62224 (CVE-2026-62224). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55652 |
|
Authentication Bypass in CVE-2026-55652 (CVE-2026-55652)
authentication bypass in CVE-2026-55652 (CVE-2026-55652). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12382 |
|
Vulnerability in CVE-2026-12382 (CVE-2026-12382)
vulnerability in CVE-2026-12382 (CVE-2026-12382). Data can be tampered with by attackers.
|
| CVE-2026-62644 |
|
Vulnerability in roundcube (CVE-2026-62644)
vulnerability in roundcube (CVE-2026-62644). Confidential information can be exposed externally.
|
| CVE-2026-55954 |
|
Vulnerability in CVE-2026-55954 (CVE-2026-55954)
vulnerability in CVE-2026-55954 (CVE-2026-55954). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58488 |
|
Vulnerability in CVE-2026-58488 (CVE-2026-58488)
vulnerability in CVE-2026-58488 (CVE-2026-58488). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61428 |
|
Vulnerability in CVE-2026-61428 (CVE-2026-61428)
vulnerability in CVE-2026-61428 (CVE-2026-61428). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56675 |
|
Authentication Bypass in CVE-2026-56675 (CVE-2026-56675)
authentication bypass in CVE-2026-56675 (CVE-2026-56675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55641 |
|
Vulnerability in 9router (CVE-2026-55641)
vulnerability in 9router (CVE-2026-55641). Confidential information can be exposed externally. Exploitable via `POST /v1/search`. Mitigation: upgrade to `0.5.2` or later.
|
| CVE-2026-59224 |
|
Authentication Bypass in open-webui (CVE-2026-59224)
authentication bypass in open-webui (CVE-2026-59224). Successful exploitation can lead to full system takeover. Exploitable via ``proxy_terminal``. Mitigation: upgrade to `0.10.0` or later.
|
| CVE-2026-8651 |
|
Vulnerability in progress (CVE-2026-8651)
vulnerability in progress (CVE-2026-8651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56360 |
|
Vulnerability in n8n (CVE-2026-56360)
vulnerability in n8n (CVE-2026-56360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54763 |
|
Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-54763). Confidential information can be exposed externally. Exploitable via ``X_Auth_User``. Mitigation: upgrade to `2.11.42` or later.
|
| CVE-2026-24013 |
|
Vulnerability in apache (CVE-2026-24013)
vulnerability in apache (CVE-2026-24013). Confidential information can be exposed externally.
|
| CVE-2026-45489 |
|
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
|
| CVE-2026-49353 |
|
Vulnerability in 9router (CVE-2026-49353)
vulnerability in 9router (CVE-2026-49353). Data can be tampered with by attackers. Exploitable via `GET /api/mcp/`.
|
| CVE-2026-45045 |
|
Vulnerability in github.com/gofiber/fiber/v3 (CVE-2026-45045)
vulnerability in github.com/gofiber/fiber/v3 (CVE-2026-45045). Risk of unauthorized operations or information disclosure. Exploitable via ``BalancerForward``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-14381 |
|
Vulnerability in google (CVE-2026-14381)
vulnerability in google (CVE-2026-14381). Data can be tampered with by attackers.
|
| CVE-2026-58593 |
|
Vulnerability in nodebb (CVE-2026-58593)
vulnerability in nodebb (CVE-2026-58593). Data can be tampered with by attackers.
|
| CVE-2026-24270 |
|
Vulnerability in dos (CVE-2026-24270)
vulnerability in dos (CVE-2026-24270). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14118 |
|
Vulnerability in google (CVE-2026-14118)
vulnerability in google (CVE-2026-14118). Data can be tampered with by attackers.
|
| CVE-2026-13985 |
|
Vulnerability in google (CVE-2026-13985)
vulnerability in google (CVE-2026-13985). Data can be tampered with by attackers.
|
| CVE-2026-13984 |
|
Vulnerability in google (CVE-2026-13984)
vulnerability in google (CVE-2026-13984). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13207 |
|
Vulnerability in CVE-2026-13207 (CVE-2026-13207)
vulnerability in CVE-2026-13207 (CVE-2026-13207). Confidential information can be exposed externally.
|
| CVE-2026-58370 |
|
Vulnerability in CVE-2026-58370 (CVE-2026-58370)
vulnerability in CVE-2026-58370 (CVE-2026-58370). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7656 |
|
Vulnerability in c (CVE-2026-7656)
vulnerability in c (CVE-2026-7656). Data can be tampered with by attackers.
|
| CVE-2026-54089 |
|
Authentication Bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089)
authentication bypass in github.com/filebrowser/filebrowser/v2 (CVE-2026-54089). Confidential information can be exposed externally. Exploitable via `POST /api/login`.
|
| CVE-2026-52690 |
|
Vulnerability in CVE-2026-52690 (CVE-2026-52690)
vulnerability in CVE-2026-52690 (CVE-2026-52690). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25119 |
|
Vulnerability in gogs.io/gogs (CVE-2026-25119)
vulnerability in gogs.io/gogs (CVE-2026-25119). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54782 |
|
Vulnerability in CoreWCF.Primitives (CVE-2026-54782)
vulnerability in CoreWCF.Primitives (CVE-2026-54782). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-49231 |
|
Vulnerability in apache (CVE-2026-49231)
vulnerability in apache (CVE-2026-49231). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39999 |
|
Vulnerability in apisix (CVE-2026-39999)
vulnerability in apisix (CVE-2026-39999). Confidential information can be exposed externally. Mitigation: upgrade to `3.17.0` or later.
|
| CVE-2026-56020 |
|
Vulnerability in CVE-2026-56020 (CVE-2026-56020)
vulnerability in CVE-2026-56020 (CVE-2026-56020). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.641` or later.
|
| CVE-2026-50141 |
|
Vulnerability in go.woodpecker-ci.org/woodpecker/v3 (CVE-2026-50141)
vulnerability in go.woodpecker-ci.org/woodpecker/v3 (CVE-2026-50141). Risk of unauthorized operations or information disclosure. Exploitable via ``agent_id``. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2026-55202 |
|
Vulnerability in CVE-2026-55202 (CVE-2026-55202)
vulnerability in CVE-2026-55202 (CVE-2026-55202). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| CVE-2026-49468 |
|
Vulnerability in litellm (CVE-2026-49468)
vulnerability in litellm (CVE-2026-49468). Successful exploitation can lead to full system takeover. Exploitable via ``request.url.path``. Mitigation: upgrade to `1.84.0` or later.
|
| CVE-2026-52845 |
|
Authentication Bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845)
authentication bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845). Confidential information can be exposed externally. Exploitable via `GET /index.php`. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-53857 |
|
OpenClaw: Zalo allowFrom could bind to mutable display names
OpenClaw: Zalo allowFrom could bind to mutable display names
|
| CVE-2026-53849 |
|
OpenClaw: Discord allowFrom could bind to mutable display names
OpenClaw: Discord allowFrom could bind to mutable display names
|
| CVE-2026-54308 |
|
Vulnerability in n8n (CVE-2026-54308)
vulnerability in n8n (CVE-2026-54308). Risk of unauthorized operations or information disclosure. Exploitable via ``MicrosoftAgent365Trigger``. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-42662 |
|
Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.
Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.
|
| CVE-2026-27089 |
|
Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.
Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.
|
| CVE-2026-36537 |
|
Vulnerability in CVE-2026-36537 (CVE-2026-36537)
vulnerability in CVE-2026-36537 (CVE-2026-36537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49757 |
|
Vulnerability in ash_authentication (CVE-2026-49757)
vulnerability in ash_authentication (CVE-2026-49757). Risk of unauthorized operations or information disclosure. Exploitable via ``iss``. Mitigation: upgrade to `4.14.0, 5.0.0-rc.10` or later.
|
| CVE-2026-34025 |
|
Vulnerability in CVE-2026-34025 (CVE-2026-34025)
vulnerability in CVE-2026-34025 (CVE-2026-34025). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53832 |
|
Privilege Escalation in openclaw (CVE-2026-53832)
vulnerability in openclaw (CVE-2026-53832). Confidential information can be exposed externally. Mitigation: upgrade to `2026.5.18` or later.
|
| CVE-2026-53833 |
|
Authorization Flaw in openclaw (CVE-2026-53833)
vulnerability in openclaw (CVE-2026-53833). Confidential information can be exposed externally. Mitigation: upgrade to `2026.4.29` or later.
|