Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13014 |
|
Path Traversal in django (CVE-2026-13014)
path traversal in django (CVE-2026-13014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14453 |
|
Code Injection in CVE-2026-14453 (CVE-2026-14453)
code injection in CVE-2026-14453 (CVE-2026-14453). Confidential information can be exposed externally.
|
| CVE-2026-15538 |
|
Code Injection in CVE-2026-15538 (CVE-2026-15538)
code injection in CVE-2026-15538 (CVE-2026-15538). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15532 |
|
Cross-Site Scripting (XSS) in CVE-2026-15532 (CVE-2026-15532)
cross-site scripting in CVE-2026-15532 (CVE-2026-15532). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15533 |
|
Vulnerability in CVE-2026-15533 (CVE-2026-15533)
vulnerability in CVE-2026-15533 (CVE-2026-15533). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15512 |
|
Vulnerability in CVE-2026-15512 (CVE-2026-15512)
vulnerability in CVE-2026-15512 (CVE-2026-15512). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15505 |
|
Cross-Site Scripting (XSS) in CVE-2026-15505 (CVE-2026-15505)
cross-site scripting in CVE-2026-15505 (CVE-2026-15505). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15492 |
|
Cross-Site Scripting (XSS) in CVE-2026-15492 (CVE-2026-15492)
cross-site scripting in CVE-2026-15492 (CVE-2026-15492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15497 |
|
Vulnerability in CVE-2026-15497 (CVE-2026-15497)
vulnerability in CVE-2026-15497 (CVE-2026-15497). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15493 |
|
Cross-Site Scripting (XSS) in CVE-2026-15493 (CVE-2026-15493)
cross-site scripting in CVE-2026-15493 (CVE-2026-15493). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61447 |
|
Code Injection in CVE-2026-61447 (CVE-2026-61447)
code injection in CVE-2026-61447 (CVE-2026-61447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13353 |
|
Code Injection in wordpress (CVE-2026-13353)
code injection in wordpress (CVE-2026-13353). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61450 |
|
Code Injection in CVE-2026-61450 (CVE-2026-61450)
code injection in CVE-2026-61450 (CVE-2026-61450). Confidential information can be exposed externally.
|
| CVE-2026-61444 |
|
Code Injection in CVE-2026-61444 (CVE-2026-61444)
code injection in CVE-2026-61444 (CVE-2026-61444). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15321 |
|
Cross-Site Scripting (XSS) in CVE-2026-15321 (CVE-2026-15321)
cross-site scripting in CVE-2026-15321 (CVE-2026-15321). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15311 |
|
Cross-Site Scripting (XSS) in CVE-2026-15311 (CVE-2026-15311)
cross-site scripting in CVE-2026-15311 (CVE-2026-15311). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59858 |
|
Code Injection in c (CVE-2026-59858)
code injection in c (CVE-2026-59858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59856 |
|
Code Injection in vim (CVE-2026-59856)
code injection in vim (CVE-2026-59856). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59833 |
|
Cross-Site Scripting (XSS) in CVE-2026-59833 (CVE-2026-59833)
cross-site scripting in CVE-2026-59833 (CVE-2026-59833). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15202 |
|
Cross-Site Scripting (XSS) in CVE-2026-15202 (CVE-2026-15202)
cross-site scripting in CVE-2026-15202 (CVE-2026-15202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15195 |
|
Code Injection in CVE-2026-15195 (CVE-2026-15195)
code injection in CVE-2026-15195 (CVE-2026-15195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15187 |
|
Code Injection in CVE-2026-15187 (CVE-2026-15187)
code injection in CVE-2026-15187 (CVE-2026-15187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59826 |
|
Code Injection in metabase (CVE-2026-59826)
code injection in metabase (CVE-2026-59826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59216 |
|
Code Injection in open-webui (CVE-2026-59216)
code injection in open-webui (CVE-2026-59216). Confidential information can be exposed externally. Exploitable via `POST /api/v1/chat/completions`. Mitigation: upgrade to `0.10.0` or later.
|
| CVE-2026-52200 |
|
Code Injection in CVE-2026-52200 (CVE-2026-52200)
code injection in CVE-2026-52200 (CVE-2026-52200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35211 |
|
Code Injection in citeum (CVE-2026-35211)
code injection in citeum (CVE-2026-35211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59821 |
|
Code Injection in litellm (CVE-2026-59821)
code injection in litellm (CVE-2026-59821). Successful exploitation can lead to full system takeover. Exploitable via `POST /guardrails`. Mitigation: upgrade to `1.82.0-stable` or later.
|
| CVE-2026-53951 |
|
Path Traversal in copier (CVE-2026-53951)
path traversal in copier (CVE-2026-53951). Risk of unauthorized operations or information disclosure. Exploitable via ``trust``. Mitigation: upgrade to `9.15.2` or later.
|
| CVE-2026-55408 |
|
Code Injection in CVE-2026-55408 (CVE-2026-55408)
code injection in CVE-2026-55408 (CVE-2026-55408). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53751 |
|
Code Injection in CVE-2026-53751 (CVE-2026-53751)
code injection in CVE-2026-53751 (CVE-2026-53751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53511 |
|
Code Injection in CVE-2026-53511 (CVE-2026-53511)
code injection in CVE-2026-53511 (CVE-2026-53511). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43921 |
|
Code Injection in CVE-2026-43921 (CVE-2026-43921)
code injection in CVE-2026-43921 (CVE-2026-43921). Risk of unauthorized operations or information disclosure. Exploitable via ``config.php``.
|
| CVE-2026-57572 |
|
Vulnerability in kidocode (CVE-2026-57572)
vulnerability in kidocode (CVE-2026-57572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54769 |
|
Code Injection in langroid (CVE-2026-54769)
code injection in langroid (CVE-2026-54769). Successful exploitation can lead to full system takeover. Exploitable via ``TableChatAgent``. Mitigation: upgrade to `0.65.2` or later.
|
| CVE-2026-48614 |
|
Code Injection in privilege-escalation (CVE-2026-48614)
code injection in privilege-escalation (CVE-2026-48614). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14791 |
|
Cross-Site Scripting (XSS) in CVE-2026-14791 (CVE-2026-14791)
cross-site scripting in CVE-2026-14791 (CVE-2026-14791). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14752 |
|
Cross-Site Scripting (XSS) in CVE-2026-14752 (CVE-2026-14752)
cross-site scripting in CVE-2026-14752 (CVE-2026-14752). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14749 |
|
Vulnerability in CVE-2026-14749 (CVE-2026-14749)
vulnerability in CVE-2026-14749 (CVE-2026-14749). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14722 |
|
Vulnerability in CVE-2026-14722 (CVE-2026-14722)
vulnerability in CVE-2026-14722 (CVE-2026-14722). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14704 |
|
Cross-Site Scripting (XSS) in CVE-2026-14704 (CVE-2026-14704)
cross-site scripting in CVE-2026-14704 (CVE-2026-14704). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14691 |
|
Vulnerability in CVE-2026-14691 (CVE-2026-14691)
vulnerability in CVE-2026-14691 (CVE-2026-14691). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14655 |
|
Cross-Site Scripting (XSS) in CVE-2026-14655 (CVE-2026-14655)
cross-site scripting in CVE-2026-14655 (CVE-2026-14655). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14656 |
|
Cross-Site Scripting (XSS) in CVE-2026-14656 (CVE-2026-14656)
cross-site scripting in CVE-2026-14656 (CVE-2026-14656). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14634 |
|
Cross-Site Scripting (XSS) in CVE-2026-14634 (CVE-2026-14634)
cross-site scripting in CVE-2026-14634 (CVE-2026-14634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14633 |
|
Cross-Site Scripting (XSS) in CVE-2026-14633 (CVE-2026-14633)
cross-site scripting in CVE-2026-14633 (CVE-2026-14633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12252 |
|
Code Injection in nltk (CVE-2026-12252)
code injection in nltk (CVE-2026-12252). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11778 |
|
Code Injection in wordpress (CVE-2026-11778)
code injection in wordpress (CVE-2026-11778). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57624 |
|
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
|
| CVE-2026-27436 |
|
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
|
| CVE-2026-14439 |
|
Path Traversal in path-traversal (CVE-2026-14439)
path traversal in path-traversal (CVE-2026-14439). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
|