Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-20175 |
|
Vulnerability in cisco (CVE-2026-20175)
vulnerability in cisco (CVE-2026-20175). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35079 |
|
Vulnerability in mbs-solutions (CVE-2026-35079)
vulnerability in mbs-solutions (CVE-2026-35079). Data can be tampered with by attackers.
|
| CVE-2026-35080 |
|
Vulnerability in mbs-solutions (CVE-2026-35080)
vulnerability in mbs-solutions (CVE-2026-35080). Data can be tampered with by attackers.
|
| CVE-2026-35076 |
|
Vulnerability in mbs-solutions (CVE-2026-35076)
vulnerability in mbs-solutions (CVE-2026-35076). Data can be tampered with by attackers.
|
| CVE-2026-35077 |
|
Vulnerability in mbs-solutions (CVE-2026-35077)
vulnerability in mbs-solutions (CVE-2026-35077). Data can be tampered with by attackers.
|
| CVE-2026-35078 |
|
Vulnerability in mbs-solutions (CVE-2026-35078)
vulnerability in mbs-solutions (CVE-2026-35078). Data can be tampered with by attackers.
|
| CVE-2026-10694 |
|
Vulnerability in CVE-2026-10694 (CVE-2026-10694)
vulnerability in CVE-2026-10694 (CVE-2026-10694). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41412 |
|
Path Traversal in CVE-2026-41412 (CVE-2026-41412)
path traversal in CVE-2026-41412 (CVE-2026-41412). Confidential information can be exposed externally. Exploitable via ``simpleHttpClient``.
|
| CVE-2026-10558 |
|
Vulnerability in CVE-2026-10558 (CVE-2026-10558)
vulnerability in CVE-2026-10558 (CVE-2026-10558). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10559 |
|
Vulnerability in CVE-2026-10559 (CVE-2026-10559)
vulnerability in CVE-2026-10559 (CVE-2026-10559). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47425 |
|
Path Traversal in rattler (CVE-2026-47425)
path traversal in rattler (CVE-2026-47425). Risk of unauthorized operations or information disclosure. Exploitable via ``rattler_conda_types``. Mitigation: upgrade to `0.43.2` or later.
|
| CVE-2026-9559 |
|
Path Traversal in mautic/core (CVE-2026-9559)
path traversal in mautic/core (CVE-2026-9559). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.2` or later.
|
| CVE-2026-46345 |
|
Path Traversal in compliance-trestle (CVE-2026-46345)
path traversal in compliance-trestle (CVE-2026-46345). Successful exploitation can lead to full system takeover. Exploitable via ``trestle``. Mitigation: upgrade to `3.12.2` or later.
|
| CVE-2026-46402 |
|
Path Traversal in path-traversal (CVE-2026-46402)
path traversal in path-traversal (CVE-2026-46402). Data can be tampered with by attackers.
|
| CVE-2026-45725 |
|
Vulnerability in compliance-trestle (CVE-2026-45725)
vulnerability in compliance-trestle (CVE-2026-45725). Risk of unauthorized operations or information disclosure. Exploitable via ``sys.path``. Mitigation: upgrade to `3.12.2` or later.
|
| CVE-2026-48920 |
|
Vulnerability in org.jenkins-ci.plugins:email-ext (CVE-2026-48920)
vulnerability in org.jenkins-ci.plugins:email-ext (CVE-2026-48920). Successful exploitation can lead to full system takeover. Exploitable via ``base64``. Mitigation: upgrade to `1933.1935.v276319e3cc47` or later.
|
| CVE-2025-0898 |
|
Vulnerability in wordpress (CVE-2025-0898)
vulnerability in wordpress (CVE-2025-0898). Confidential information can be exposed externally.
|
| CVE-2026-8450 |
|
Vulnerability in CVE-2026-8450 (CVE-2026-8450)
vulnerability in CVE-2026-8450 (CVE-2026-8450). Confidential information can be exposed externally.
|
| CVE-2026-35593 |
|
Path Traversal in CVE-2026-35593 (CVE-2026-35593)
path traversal in CVE-2026-35593 (CVE-2026-35593). Confidential information can be exposed externally.
|
| CVE-2026-47358 |
|
Vulnerability in ssrf (CVE-2026-47358)
vulnerability in ssrf (CVE-2026-47358). Confidential information can be exposed externally.
|
| CVE-2026-47357 |
|
Vulnerability in ssrf (CVE-2026-47357)
vulnerability in ssrf (CVE-2026-47357). Confidential information can be exposed externally. Exploitable via `POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/scan`.
|
| CVE-2026-29962 |
|
Vulnerability in path-traversal (CVE-2026-29962)
vulnerability in path-traversal (CVE-2026-29962). Confidential information can be exposed externally.
|
| CVE-2026-45139 |
|
Vulnerability in ci4-cms-erp/ci4ms (CVE-2026-45139)
vulnerability in ci4-cms-erp/ci4ms (CVE-2026-45139). Data can be tampered with by attackers. Exploitable via ``saveFile``. Mitigation: upgrade to `0.31.9.0` or later.
|
| CVE-2026-45008 |
|
Path Traversal in phpMyFAQ/phpMyFAQ (CVE-2026-45008)
path traversal in phpMyFAQ/phpMyFAQ (CVE-2026-45008). Data can be tampered with by attackers. Exploitable via ``clientFolder``. Mitigation: upgrade to `4.1.2` or later.
|
| CVE-2026-46383 |
|
Path Traversal in apm-cli (CVE-2026-46383)
path traversal in apm-cli (CVE-2026-46383). Data can be tampered with by attackers. Exploitable via ``main``. Mitigation: upgrade to `0.13.0` or later.
|
| CVE-2026-44641 |
|
Path Traversal in apm-cli (CVE-2026-44641)
path traversal in apm-cli (CVE-2026-44641). Confidential information can be exposed externally. Exploitable via ``agents``. Mitigation: upgrade to `0.8.12` or later.
|
| CVE-2026-42597 |
|
Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-42597)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-42597). Confidential information can be exposed externally. Mitigation: upgrade to `8.32.0` or later.
|
| CVE-2026-42593 |
|
Path Traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-42593)
path traversal in github.com/gotenberg/gotenberg/v8 (CVE-2026-42593). Risk of unauthorized operations or information disclosure. Exploitable via ``stamp``.
|
| CVE-2026-40893 |
|
Vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-40893)
vulnerability in github.com/gotenberg/gotenberg/v8 (CVE-2026-40893). Data can be tampered with by attackers. Exploitable via ``FileName``.
|
| CVE-2026-42881 |
|
Path Traversal in CVE-2026-42881 (CVE-2026-42881)
path traversal in CVE-2026-42881 (CVE-2026-42881). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.2.7` or later.
|
| CVE-2026-3892 |
|
Vulnerability in wordpress (CVE-2026-3892)
vulnerability in wordpress (CVE-2026-3892). Data can be tampered with by attackers.
|
| CVE-2026-30905 |
|
Vulnerability in zoom (CVE-2026-30905)
vulnerability in zoom (CVE-2026-30905). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0259 |
|
Vulnerability in paloaltonetworks (CVE-2026-0259)
vulnerability in paloaltonetworks (CVE-2026-0259). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41107 |
|
Vulnerability in microsoft (CVE-2026-41107)
vulnerability in microsoft (CVE-2026-41107). Confidential information can be exposed externally.
|
| CVE-2026-40421 |
|
Vulnerability in microsoft (CVE-2026-40421)
vulnerability in microsoft (CVE-2026-40421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41088 |
|
Vulnerability in microsoft (CVE-2026-41088)
vulnerability in microsoft (CVE-2026-41088). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40370 |
|
Vulnerability in microsoft (CVE-2026-40370)
vulnerability in microsoft (CVE-2026-40370). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32204 |
|
Vulnerability in microsoft (CVE-2026-32204)
vulnerability in microsoft (CVE-2026-32204). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43891 |
|
Vulnerability in changedetection.io (CVE-2026-43891)
vulnerability in changedetection.io (CVE-2026-43891). Confidential information can be exposed externally. Exploitable via ``history.txt``. Mitigation: upgrade to `0.55.1` or later.
|
| CVE-2026-43989 |
|
Vulnerability in CVE-2026-43989 (CVE-2026-43989)
vulnerability in CVE-2026-43989 (CVE-2026-43989). Confidential information can be exposed externally. Mitigation: upgrade to `0.x.y-security-1` or later.
|
| CVE-2026-8043 |
|
Vulnerability in ivanti (CVE-2026-8043)
vulnerability in ivanti (CVE-2026-8043). Confidential information can be exposed externally.
|
| CVE-2026-45089 |
|
Vulnerability in github.com/hahwul/dalfox/v2 (CVE-2026-45089)
vulnerability in github.com/hahwul/dalfox/v2 (CVE-2026-45089). Data can be tampered with by attackers. Exploitable via ``output``. Mitigation: upgrade to `2.13.0` or later.
|
| CVE-2026-45088 |
|
Vulnerability in github.com/hahwul/dalfox/v2 (CVE-2026-45088)
vulnerability in github.com/hahwul/dalfox/v2 (CVE-2026-45088). Confidential information can be exposed externally. Exploitable via ``model.Options``. Mitigation: upgrade to `2.13.0` or later.
|
| CVE-2026-42866 |
|
Path Traversal in CVE-2026-42866 (CVE-2026-42866)
path traversal in CVE-2026-42866 (CVE-2026-42866). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1fix` or later.
|
| CVE-2026-42845 |
|
Vulnerability in getgrav/grav-plugin-form (CVE-2026-42845)
vulnerability in getgrav/grav-plugin-form (CVE-2026-42845). Risk of unauthorized operations or information disclosure. Exploitable via `GET /upload`. Mitigation: upgrade to `9.1.0` or later.
|
| CVE-2026-41693 |
|
Path Traversal in i18next-fs-backend (CVE-2026-41693)
path traversal in i18next-fs-backend (CVE-2026-41693). Confidential information can be exposed externally. Exploitable via ``lng``. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-44127 |
|
Vulnerability in path-traversal (CVE-2026-44127)
vulnerability in path-traversal (CVE-2026-44127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35032 |
|
Vulnerability in ssrf (CVE-2026-35032)
vulnerability in ssrf (CVE-2026-35032). Confidential information can be exposed externally. Exploitable via `POST /LiveTv/TunerHosts`.
|
| CVE-2026-39907 |
|
Vulnerability in privilege-escalation (CVE-2026-39907)
vulnerability in privilege-escalation (CVE-2026-39907). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35174 |
|
Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
|