Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13079 |
|
Vulnerability in privilege-escalation (CVE-2026-13079)
vulnerability in privilege-escalation (CVE-2026-13079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13084 |
|
Vulnerability in dos (CVE-2026-13084)
vulnerability in dos (CVE-2026-13084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13054 |
|
Path Traversal in path-traversal (CVE-2026-13054)
path traversal in path-traversal (CVE-2026-13054). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57100 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57100)
SSRF in ssrf (CVE-2026-57100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45499 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45499)
SSRF in ssrf (CVE-2026-45499). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54998 |
|
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
|
| CVE-2026-50721 |
|
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
|
| CVE-2026-50722 |
|
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
|
| CVE-2026-12413 |
|
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart....
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart....
|
| CVE-2026-58460 |
|
Path Traversal in react (CVE-2026-58460)
path traversal in react (CVE-2026-58460). Data can be tampered with by attackers.
|
| CVE-2026-52191 |
|
Vulnerability in dos (CVE-2026-52191)
vulnerability in dos (CVE-2026-52191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52188 |
|
Buffer Overflow in dos (CVE-2026-52188)
vulnerability in dos (CVE-2026-52188). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52189 |
|
Vulnerability in dos (CVE-2026-52189)
vulnerability in dos (CVE-2026-52189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52192 |
|
Vulnerability in dos (CVE-2026-52192)
vulnerability in dos (CVE-2026-52192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59102 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-59102)
cross-site scripting in vue (CVE-2026-59102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59101 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59101)
SSRF in ssrf (CVE-2026-59101). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/setup/test-downloader`.
|
| CVE-2026-59095 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59095)
SSRF in ssrf (CVE-2026-59095). Confidential information can be exposed externally.
|
| CVE-2026-59092 |
|
Vulnerability in dos (CVE-2026-59092)
vulnerability in dos (CVE-2026-59092). Confidential information can be exposed externally.
|
| CVE-2026-58578 |
|
Vulnerability in dos (CVE-2026-58578)
vulnerability in dos (CVE-2026-58578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58381 |
|
Vulnerability in dos (CVE-2026-58381)
vulnerability in dos (CVE-2026-58381). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2025-71385 |
|
Cross-Site Scripting (XSS) in netdata (CVE-2025-71385)
cross-site scripting in netdata (CVE-2025-71385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52187 |
|
Vulnerability in dos (CVE-2026-52187)
vulnerability in dos (CVE-2026-52187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49360 |
|
Vulnerability in recce (CVE-2026-49360)
vulnerability in recce (CVE-2026-49360). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.50.0` or later.
|
| CVE-2026-52746 |
|
Vulnerability in jsonata (CVE-2026-52746)
vulnerability in jsonata (CVE-2026-52746). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.9` or later.
|
| CVE-2026-49255 |
|
OS Command Injection in electerm (CVE-2026-49255)
OS command injection in electerm (CVE-2026-49255). Successful exploitation can lead to full system takeover. Exploitable via ``rmrf``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|
| CVE-2026-58465 |
|
Vulnerability in c (CVE-2026-58465)
vulnerability in c (CVE-2026-58465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50181 |
|
Path Traversal in langroid (CVE-2026-50181)
path traversal in langroid (CVE-2026-50181). Confidential information can be exposed externally. Exploitable via ``ReadFileTool``. Mitigation: upgrade to `0.64.0` or later.
|
| CVE-2026-8699 |
|
Cross-Site Scripting (XSS) in CVE-2026-8699 (CVE-2026-8699)
cross-site scripting in CVE-2026-8699 (CVE-2026-8699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54886 |
|
Vulnerability in dos (CVE-2026-54886)
vulnerability in dos (CVE-2026-54886). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55950 |
|
Vulnerability in dos (CVE-2026-55950)
vulnerability in dos (CVE-2026-55950). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-14037 |
|
Unrestricted File Upload in CVE-2024-14037 (CVE-2024-14037)
vulnerability in CVE-2024-14037 (CVE-2024-14037). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58352 |
|
Vulnerability in CVE-2024-58352 (CVE-2024-58352)
vulnerability in CVE-2024-58352 (CVE-2024-58352). Confidential information can be exposed externally.
|
| CVE-2022-50973 |
|
Unrestricted File Upload in CVE-2022-50973 (CVE-2022-50973)
vulnerability in CVE-2022-50973 (CVE-2022-50973). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44941 |
|
Vulnerability in path-traversal (CVE-2026-44941)
vulnerability in path-traversal (CVE-2026-44941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55117 |
|
Path Traversal in path-traversal (CVE-2026-55117)
path traversal in path-traversal (CVE-2026-55117). Confidential information can be exposed externally.
|
| CVE-2026-56841 |
|
SQL Injection in sqli (CVE-2026-56841)
SQL injection in sqli (CVE-2026-56841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55111 |
|
Path Traversal in path-traversal (CVE-2026-55111)
path traversal in path-traversal (CVE-2026-55111). Confidential information can be exposed externally.
|
| CVE-2026-55113 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55113)
SSRF in ssrf (CVE-2026-55113). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55115 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55115)
SSRF in ssrf (CVE-2026-55115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4770 |
|
Cross-Site Scripting (XSS) in CVE-2026-4770 (CVE-2026-4770)
cross-site scripting in CVE-2026-4770 (CVE-2026-4770). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4772 |
|
Cross-Site Scripting (XSS) in CVE-2026-4772 (CVE-2026-4772)
cross-site scripting in CVE-2026-4772 (CVE-2026-4772). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54403 |
|
Path Traversal in path-traversal (CVE-2026-54403)
path traversal in path-traversal (CVE-2026-54403). Confidential information can be exposed externally.
|
| CVE-2026-54406 |
|
Path Traversal in path-traversal (CVE-2026-54406)
path traversal in path-traversal (CVE-2026-54406). Data can be tampered with by attackers.
|
| CVE-2026-5524 |
|
Unrestricted File Upload in wordpress (CVE-2026-5524)
vulnerability in wordpress (CVE-2026-5524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54401 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-54401)
SSRF in ssrf (CVE-2026-54401). Confidential information can be exposed externally.
|
| CVE-2026-54404 |
|
SQL Injection in sqli (CVE-2026-54404)
SQL injection in sqli (CVE-2026-54404). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50747 |
|
SQL Injection in sqli (CVE-2026-50747)
SQL injection in sqli (CVE-2026-50747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12166 |
|
Vulnerability in dos (CVE-2026-12166)
vulnerability in dos (CVE-2026-12166). Risk of unauthorized operations or information disclosure. Exploitable via ``GFAC_Sys_x64.sys``.
|