Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-45057 |
|
Vulnerability in dos (CVE-2025-45057)
vulnerability in dos (CVE-2025-45057). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-45058 |
|
Vulnerability in dos (CVE-2025-45058)
vulnerability in dos (CVE-2025-45058). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-45059 |
|
Vulnerability in dos (CVE-2025-45059)
vulnerability in dos (CVE-2025-45059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27806 |
|
OS Command Injection in github.com/fleetdm/fleet/v4 (CVE-2026-27806)
OS command injection in github.com/fleetdm/fleet/v4 (CVE-2026-27806). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.81.1` or later.
|
| CVE-2026-4498 |
|
Vulnerability in elastic (CVE-2026-4498)
vulnerability in elastic (CVE-2026-4498). Confidential information can be exposed externally.
|
| CVE-2026-33461 |
|
Authorization Flaw in elastic (CVE-2026-33461)
vulnerability in elastic (CVE-2026-33461). Confidential information can be exposed externally.
|
| CVE-2026-30075 |
|
Vulnerability in dos (CVE-2026-30075)
vulnerability in dos (CVE-2026-30075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30080 |
|
Vulnerability in openairinterface (CVE-2026-30080)
vulnerability in openairinterface (CVE-2026-30080). Data can be tampered with by attackers.
|
| CVE-2026-39393 |
|
Vulnerability in ci4-cms-erp (CVE-2026-39393)
vulnerability in ci4-cms-erp (CVE-2026-39393). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.31.4.0` or later.
|
| CVE-2026-39394 |
|
Vulnerability in csrf (CVE-2026-39394)
vulnerability in csrf (CVE-2026-39394). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.31.4.0` or later.
|
| CVE-2026-39408 |
|
Path Traversal in path-traversal (CVE-2026-39408)
path traversal in path-traversal (CVE-2026-39408). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-5795 |
|
Vulnerability in privilege-escalation (CVE-2026-5795)
vulnerability in privilege-escalation (CVE-2026-5795). Confidential information can be exposed externally.
|
| CVE-2026-5301 |
|
Cross-Site Scripting (XSS) in coolercontrol (CVE-2026-5301)
cross-site scripting in coolercontrol (CVE-2026-5301). Data can be tampered with by attackers.
|
| CVE-2026-28261 |
|
Vulnerability in dell (CVE-2026-28261)
vulnerability in dell (CVE-2026-28261). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5208 |
|
OS Command Injection in coolercontrol (CVE-2026-5208)
OS command injection in coolercontrol (CVE-2026-5208). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3243 |
|
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1....
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
|
| CVE-2026-3396 |
|
SQL Injection in sqli (CVE-2026-3396)
SQL injection in sqli (CVE-2026-3396). Confidential information can be exposed externally.
|
| CVE-2026-39684 |
|
Vulnerability in CVE-2026-39684 (CVE-2026-39684)
vulnerability in CVE-2026-39684 (CVE-2026-39684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39677 |
|
Vulnerability in CVE-2026-39677 (CVE-2026-39677)
vulnerability in CVE-2026-39677 (CVE-2026-39677). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39679 |
|
Vulnerability in CVE-2026-39679 (CVE-2026-39679)
vulnerability in CVE-2026-39679 (CVE-2026-39679). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39681 |
|
Vulnerability in CVE-2026-39681 (CVE-2026-39681)
vulnerability in CVE-2026-39681 (CVE-2026-39681). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39671 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39671)
vulnerability in csrf (CVE-2026-39671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39621 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39621)
vulnerability in csrf (CVE-2026-39621). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39623 |
|
Vulnerability in CVE-2026-39623 (CVE-2026-39623)
vulnerability in CVE-2026-39623 (CVE-2026-39623). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39613 |
|
Vulnerability in CVE-2026-39613 (CVE-2026-39613)
vulnerability in CVE-2026-39613 (CVE-2026-39613). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39611 |
|
Vulnerability in CVE-2026-39611 (CVE-2026-39611)
vulnerability in CVE-2026-39611 (CVE-2026-39611). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39544 |
|
Vulnerability in CVE-2026-39544 (CVE-2026-39544)
vulnerability in CVE-2026-39544 (CVE-2026-39544). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39538 |
|
Vulnerability in CVE-2026-39538 (CVE-2026-39538)
vulnerability in CVE-2026-39538 (CVE-2026-39538). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39497 |
|
SQL Injection in sqli (CVE-2026-39497)
SQL injection in sqli (CVE-2026-39497). Confidential information can be exposed externally.
|
| CVE-2026-39486 |
|
SQL Injection in sqli (CVE-2026-39486)
SQL injection in sqli (CVE-2026-39486). Confidential information can be exposed externally.
|
| CVE-2026-39487 |
|
SQL Injection in sqli (CVE-2026-39487)
SQL injection in sqli (CVE-2026-39487). Confidential information can be exposed externally.
|
| CVE-2026-39495 |
|
SQL Injection in sqli (CVE-2026-39495)
SQL injection in sqli (CVE-2026-39495). Confidential information can be exposed externally.
|
| CVE-2026-39496 |
|
SQL Injection in sqli (CVE-2026-39496)
SQL injection in sqli (CVE-2026-39496). Confidential information can be exposed externally.
|
| CVE-2026-39475 |
|
SQL Injection in sqli (CVE-2026-39475)
SQL injection in sqli (CVE-2026-39475). Confidential information can be exposed externally.
|
| CVE-2026-39479 |
|
SQL Injection in sqli (CVE-2026-39479)
SQL injection in sqli (CVE-2026-39479). Confidential information can be exposed externally.
|
| CVE-2026-39466 |
|
SQL Injection in wordpress (CVE-2026-39466)
SQL injection in wordpress (CVE-2026-39466). Confidential information can be exposed externally.
|
| CVE-2026-4808 |
|
Unrestricted File Upload in wordpress (CVE-2026-4808)
vulnerability in wordpress (CVE-2026-4808). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4338 |
|
Vulnerability in wordpress (CVE-2026-4338)
vulnerability in wordpress (CVE-2026-4338). Confidential information can be exposed externally.
|
| CVE-2026-33273 |
|
Unrestricted File Upload in icz (CVE-2026-33273)
vulnerability in icz (CVE-2026-33273). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24913 |
|
SQL Injection in sqli (CVE-2026-24913)
SQL injection in sqli (CVE-2026-24913). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5726 |
|
ASDA-Soft Stack-based Buffer Overflow Vulnerability
ASDA-Soft Stack-based Buffer Overflow Vulnerability
|
| CVE-2026-3499 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-3499)
vulnerability in wordpress (CVE-2026-3499). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4788 |
|
Vulnerability in ibm (CVE-2026-4788)
vulnerability in ibm (CVE-2026-4788). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3357 |
|
Unsafe Deserialization in deserialization (CVE-2026-3357)
vulnerability in deserialization (CVE-2026-3357). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1343 |
|
SSRF (Server-Side Request Forgery) in ibm (CVE-2026-1343)
SSRF in ibm (CVE-2026-1343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39376 |
|
Vulnerability in fastfeedparser (CVE-2026-39376)
vulnerability in fastfeedparser (CVE-2026-39376). Risk of unauthorized operations or information disclosure. Exploitable via ``ValueError``. Mitigation: upgrade to `0.5.10` or later.
|
| CVE-2026-39370 |
|
SSRF (Server-Side Request Forgery) in WWBN/AVideo (CVE-2026-39370)
SSRF in WWBN/AVideo (CVE-2026-39370). Confidential information can be exposed externally. Exploitable via `POST /objects/aVideoEncoder.json.php`.
|
| CVE-2026-39369 |
|
Path Traversal in WWBN/AVideo (CVE-2026-39369)
path traversal in WWBN/AVideo (CVE-2026-39369). Confidential information can be exposed externally. Exploitable via `POST /objects/aVideoEncoderReceiveImage.json.php`.
|
| CVE-2026-35585 |
|
OS Command Injection in github.com/filebrowser/filebrowser/v2 (CVE-2026-35585)
OS command injection in github.com/filebrowser/filebrowser/v2 (CVE-2026-35585). Successful exploitation can lead to full system takeover. Exploitable via ``os.Expand``. Mitigation: upgrade to `2.33.8` or later.
|
| CVE-2026-1340 KEV |
|
[KEV] Code Injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1340)
code injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1340). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|