Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73502 |
|
Vulnerability in github.com/getkin/kin-openapi (CVE-2026-73502)
vulnerability in github.com/getkin/kin-openapi (CVE-2026-73502). Risk of unauthorized operations or information disclosure. Exploitable via ``HEAD``. Mitigation: upgrade to `0.144.0` or later.
|
| CVE-2026-73647 |
|
Vulnerability in quasar (CVE-2026-73647)
vulnerability in quasar (CVE-2026-73647). Risk of unauthorized operations or information disclosure. Exploitable via ``__proto__``. Mitigation: upgrade to `2.22.0` or later.
|
| CVE-2026-73413 |
|
Vulnerability in shescape (CVE-2026-73413)
vulnerability in shescape (CVE-2026-73413). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73493 |
|
Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `1.0.0-M42` or later.
|
| CVE-2026-66040 |
|
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
|
| CVE-2026-66036 |
|
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
|
| CVE-2026-57531 |
|
Cross-Site Scripting (XSS) in CVE-2026-57531 (CVE-2026-57531)
cross-site scripting in CVE-2026-57531 (CVE-2026-57531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57530 |
|
Cross-Site Scripting (XSS) in CVE-2026-57530 (CVE-2026-57530)
cross-site scripting in CVE-2026-57530 (CVE-2026-57530). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65707 |
|
SQL Injection in sqli (CVE-2026-65707)
SQL injection in sqli (CVE-2026-65707). Confidential information can be exposed externally.
|
| CVE-2026-65623 |
|
Vulnerability in dos (CVE-2026-65623)
vulnerability in dos (CVE-2026-65623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73507 |
|
Vulnerability in io.netty:netty-codec-xml (CVE-2026-73507)
vulnerability in io.netty:netty-codec-xml (CVE-2026-73507). Risk of unauthorized operations or information disclosure. Exploitable via ``maxFrameLength``. Mitigation: upgrade to `4.1.136.Final` or later.
|
| CVE-2026-73508 |
|
Vulnerability in io.netty:netty-codec-dns (CVE-2026-73508)
vulnerability in io.netty:netty-codec-dns (CVE-2026-73508). Risk of unauthorized operations or information disclosure. Exploitable via ``IDN.toASCII``. Mitigation: upgrade to `4.1.136.Final` or later.
|
| CVE-2026-73489 |
|
Vulnerability in russh (CVE-2026-73489)
vulnerability in russh (CVE-2026-73489). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.0` or later.
|
| CVE-2026-73430 |
|
Vulnerability in russh (CVE-2026-73430)
vulnerability in russh (CVE-2026-73430). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.62.4` or later.
|
| CVE-2026-61632 |
|
Path Traversal in pymdown-extensions (CVE-2026-61632)
path traversal in pymdown-extensions (CVE-2026-61632). Risk of unauthorized operations or information disclosure. Exploitable via ``b64``. Mitigation: upgrade to `11.0.0` or later.
|
| CVE-2026-73428 |
|
Cross-Site Scripting (XSS) in trix (CVE-2026-73428)
cross-site scripting in trix (CVE-2026-73428). Risk of unauthorized operations or information disclosure. Exploitable via ``HTMLParser``. Mitigation: upgrade to `2.1.18` or later.
|
| CVE-2026-59940 |
|
Unsafe Deserialization in seroval (CVE-2026-59940)
vulnerability in seroval (CVE-2026-59940). Successful exploitation can lead to full system takeover. Exploitable via ``seroval``. Mitigation: upgrade to `1.5.3` or later.
|
| CVE-2026-66004 |
|
Path Traversal in path-traversal (CVE-2026-66004)
path traversal in path-traversal (CVE-2026-66004). Data can be tampered with by attackers.
|
| CVE-2026-8308 |
|
Cross-Site Scripting (XSS) in CVE-2026-8308 (CVE-2026-8308)
cross-site scripting in CVE-2026-8308 (CVE-2026-8308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66007 |
|
Path Traversal in path-traversal (CVE-2026-66007)
path traversal in path-traversal (CVE-2026-66007). Confidential information can be exposed externally.
|
| CVE-2026-66006 |
|
Vulnerability in lakefs (CVE-2026-66006)
vulnerability in lakefs (CVE-2026-66006). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55731 |
|
Vulnerability in dos (CVE-2026-55731)
vulnerability in dos (CVE-2026-55731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55730 |
|
Cross-Site Scripting (XSS) in CVE-2026-55730 (CVE-2026-55730)
cross-site scripting in CVE-2026-55730 (CVE-2026-55730). Risk of unauthorized operations or information disclosure. Exploitable via ``project``.
|
| CVE-2026-57106 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57106)
SSRF in ssrf (CVE-2026-57106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66010 |
|
Cross-Site Scripting (XSS) in cure53 (CVE-2026-66010)
cross-site scripting in cure53 (CVE-2026-66010). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12496 |
|
Cross-Site Scripting (XSS) in CVE-2026-12496 (CVE-2026-12496)
cross-site scripting in CVE-2026-12496 (CVE-2026-12496). Risk of unauthorized operations or information disclosure. Exploitable via `POST /da`.
|
| CVE-2026-12503 |
|
Vulnerability in privilege-escalation (CVE-2026-12503)
vulnerability in privilege-escalation (CVE-2026-12503). Risk of unauthorized operations or information disclosure. Exploitable via ``larmapp``.
|
| CVE-2026-9765 |
|
Vulnerability in privilege-escalation (CVE-2026-9765)
vulnerability in privilege-escalation (CVE-2026-9765). Data can be tampered with by attackers.
|
| CVE-2026-66143 |
|
Vulnerability in apache (CVE-2026-66143)
vulnerability in apache (CVE-2026-66143). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66142 |
|
Vulnerability in apache (CVE-2026-66142)
vulnerability in apache (CVE-2026-66142). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66144 |
|
Vulnerability in dos (CVE-2026-66144)
vulnerability in dos (CVE-2026-66144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7007 |
|
Vulnerability in c (CVE-2026-7007)
vulnerability in c (CVE-2026-7007). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10610 |
|
Privilege Escalation in privilege-escalation (CVE-2026-10610)
vulnerability in privilege-escalation (CVE-2026-10610). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15810 |
|
Cross-Site Scripting (XSS) in CVE-2026-15810 (CVE-2026-15810)
cross-site scripting in CVE-2026-15810 (CVE-2026-15810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7483 |
|
Privilege Escalation in privilege-escalation (CVE-2026-7483)
vulnerability in privilege-escalation (CVE-2026-7483). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15401 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15401)
cross-site scripting in wordpress (CVE-2026-15401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15663 |
|
SQL Injection in wordpress (CVE-2026-15663)
SQL injection in wordpress (CVE-2026-15663). Confidential information can be exposed externally.
|
| CVE-2026-15821 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15821)
cross-site scripting in wordpress (CVE-2026-15821). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15739 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15739)
cross-site scripting in wordpress (CVE-2026-15739). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15346 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15346)
cross-site scripting in wordpress (CVE-2026-15346). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63317 |
|
Vulnerability in apache (CVE-2026-63317)
vulnerability in apache (CVE-2026-63317). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49744 |
|
Vulnerability in privilege-escalation (CVE-2026-49744)
vulnerability in privilege-escalation (CVE-2026-49744). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15464 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15464)
cross-site scripting in wordpress (CVE-2026-15464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15648 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15648)
cross-site scripting in wordpress (CVE-2026-15648). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15653 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15653)
cross-site scripting in wordpress (CVE-2026-15653). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15665 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15665)
cross-site scripting in wordpress (CVE-2026-15665). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15755 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15755)
cross-site scripting in wordpress (CVE-2026-15755). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16910 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-16910)
SSRF in ssrf (CVE-2026-16910). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15333 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15333)
cross-site scripting in wordpress (CVE-2026-15333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15334 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15334)
cross-site scripting in wordpress (CVE-2026-15334). Risk of unauthorized operations or information disclosure.
|