Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-0092 |
|
Vulnerability in google (CVE-2026-0092)
vulnerability in google (CVE-2026-0092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0071 |
|
Vulnerability in google (CVE-2026-0071)
vulnerability in google (CVE-2026-0071). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11858 |
|
Vulnerability in csharp (CVE-2026-11858)
vulnerability in csharp (CVE-2026-11858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0057 |
|
Vulnerability in google (CVE-2026-0057)
vulnerability in google (CVE-2026-0057). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69103 |
|
Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.
Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.
|
| CVE-2025-69137 |
|
Subscriber Broken Access Control in Genemy <= 1.6.6 versions.
Subscriber Broken Access Control in Genemy <= 1.6.6 versions.
|
| CVE-2024-37496 |
|
Vulnerability in CVE-2024-37496 (CVE-2024-37496)
vulnerability in CVE-2024-37496 (CVE-2024-37496). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-48640 |
|
Vulnerability in google (CVE-2025-48640)
vulnerability in google (CVE-2025-48640). Successful exploitation can lead to full system takeover.
|
| CVE-2025-48617 |
|
Vulnerability in google (CVE-2025-48617)
vulnerability in google (CVE-2025-48617). Successful exploitation can lead to full system takeover.
|
| CVE-2024-37210 |
|
Vulnerability in CVE-2024-37210 (CVE-2024-37210)
vulnerability in CVE-2024-37210 (CVE-2024-37210). Confidential information can be exposed externally.
|
| CVE-2024-33909 |
|
Vulnerability in CVE-2024-33909 (CVE-2024-33909)
vulnerability in CVE-2024-33909 (CVE-2024-33909). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-24709 |
|
Vulnerability in CVE-2024-24709 (CVE-2024-24709)
vulnerability in CVE-2024-24709 (CVE-2024-24709). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-32949 |
|
Vulnerability in CVE-2024-32949 (CVE-2024-32949)
vulnerability in CVE-2024-32949 (CVE-2024-32949). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-33685 |
|
Vulnerability in CVE-2024-33685 (CVE-2024-33685)
vulnerability in CVE-2024-33685 (CVE-2024-33685). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-31435 |
|
Vulnerability in CVE-2024-31435 (CVE-2024-31435)
vulnerability in CVE-2024-31435 (CVE-2024-31435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54019 |
|
Vulnerability in open-webui (CVE-2026-54019)
vulnerability in open-webui (CVE-2026-54019). Confidential information can be exposed externally. Exploitable via `POST /api/v1/retrieval/query/collection`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-54012 |
|
Vulnerability in open-webui (CVE-2026-54012)
vulnerability in open-webui (CVE-2026-54012). Confidential information can be exposed externally. Exploitable via `GET /api/v1/files/{id}/content`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-54010 |
|
Vulnerability in open-webui (CVE-2026-54010)
vulnerability in open-webui (CVE-2026-54010). Confidential information can be exposed externally. Exploitable via `GET /api/v1/files/{id}/content`. Mitigation: upgrade to `>= 0.9.6` or later.
|
| CVE-2026-48783 |
|
Vulnerability in CVE-2026-48783 (CVE-2026-48783)
vulnerability in CVE-2026-48783 (CVE-2026-48783). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48797 |
|
Vulnerability in backpropagate (CVE-2026-48797)
vulnerability in backpropagate (CVE-2026-48797). Risk of unauthorized operations or information disclosure. Exploitable via ``BACKPROPAGATE_UI_AUTH``. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-27783 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-27783)
vulnerability in code.gitea.io/gitea (CVE-2026-27783). Risk of unauthorized operations or information disclosure. Exploitable via `GET /repos/{owner}/{repo}/issue_templates`. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-25714 |
|
Vulnerability in code.gitea.io/gitea (CVE-2026-25714)
vulnerability in code.gitea.io/gitea (CVE-2026-25714). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.26.2` or later.
|
| CVE-2026-0145 |
|
Vulnerability in google (CVE-2026-0145)
vulnerability in google (CVE-2026-0145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0158 |
|
Vulnerability in google (CVE-2026-0158)
vulnerability in google (CVE-2026-0158). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12105 |
|
Vulnerability in devolutions (CVE-2026-12105)
vulnerability in devolutions (CVE-2026-12105). Confidential information can be exposed externally.
|
| CVE-2026-0133 |
|
Vulnerability in c (CVE-2026-0133)
vulnerability in c (CVE-2026-0133). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54322 |
|
Vulnerability in github.com/daytonaio/daytona (CVE-2026-54322)
vulnerability in github.com/daytonaio/daytona (CVE-2026-54322). Data can be tampered with by attackers. Mitigation: upgrade to `0.185.0` or later.
|
| CVE-2026-53866 |
|
OpenClaw: Shell inline-command parsing could miss an allowlist check
OpenClaw: Shell inline-command parsing could miss an allowlist check
|
| CVE-2026-53850 |
|
Vulnerability in openclaw (CVE-2026-53850)
vulnerability in openclaw (CVE-2026-53850). Data can be tampered with by attackers. Mitigation: upgrade to `2026.4.25` or later.
|
| CVE-2026-53851 |
|
Vulnerability in openclaw (CVE-2026-53851)
vulnerability in openclaw (CVE-2026-53851). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.12` or later.
|
| CVE-2026-53844 |
|
Vulnerability in openclaw (CVE-2026-53844)
vulnerability in openclaw (CVE-2026-53844). Confidential information can be exposed externally. Mitigation: upgrade to `2026.4.29` or later.
|
| CVE-2025-14272 |
|
Vulnerability in CVE-2025-14272 (CVE-2025-14272)
vulnerability in CVE-2025-14272 (CVE-2025-14272). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10831 |
|
Vulnerability in CVE-2026-10831 (CVE-2026-10831)
vulnerability in CVE-2026-10831 (CVE-2026-10831). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52714 |
|
Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.
|
| CVE-2026-54190 |
|
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.
|
| CVE-2026-39490 |
|
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
|
| CVE-2026-40809 |
|
Vulnerability in CVE-2026-40809 (CVE-2026-40809)
vulnerability in CVE-2026-40809 (CVE-2026-40809). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52711 |
|
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
|
| CVE-2026-2381 |
|
Vulnerability in wordpress (CVE-2026-2381)
vulnerability in wordpress (CVE-2026-2381). Risk of unauthorized operations or information disclosure. Exploitable via ``wc_stripe_pay_for_order``.
|
| CVE-2025-68045 |
|
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
|
| CVE-2026-9187 |
|
Vulnerability in wordpress (CVE-2026-9187)
vulnerability in wordpress (CVE-2026-9187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6964 |
|
Vulnerability in wordpress (CVE-2026-6964)
vulnerability in wordpress (CVE-2026-6964). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49775 |
|
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
|
| CVE-2026-49065 |
|
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
|
| CVE-2026-49070 |
|
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
|
| CVE-2026-48883 |
|
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
|
| CVE-2026-48835 |
|
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
|
| CVE-2026-48887 |
|
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
|
| CVE-2026-48873 |
|
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
|
| CVE-2026-48881 |
|
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
|