Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10595 |
|
Vulnerability in path-traversal (CVE-2026-10595)
vulnerability in path-traversal (CVE-2026-10595). Confidential information can be exposed externally. Exploitable via ``pathlib``.
|
| CVE-2026-67620 |
|
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
|
| CVE-2026-42170 |
|
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file...
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file...
|
| CVE-2026-16589 |
|
SQL Injection in wordpress (CVE-2026-16589)
SQL injection in wordpress (CVE-2026-16589). Confidential information can be exposed externally.
|
| CVE-2026-48120 |
|
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell comma...
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, ad...
|
| CVE-2026-48026 |
|
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
|
| CVE-2026-15972 |
|
Vulnerability in dos (CVE-2026-15972)
vulnerability in dos (CVE-2026-15972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19231 |
|
Vulnerability in sqli (CVE-2026-19231)
vulnerability in sqli (CVE-2026-19231). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11430 |
|
Vulnerability in CVE-2026-11430 (CVE-2026-11430)
vulnerability in CVE-2026-11430 (CVE-2026-11430). Risk of unauthorized operations or information disclosure. Exploitable via `POST /scheduler/webhook`.
|
| CVE-2025-63235 |
|
Vulnerability in dos (CVE-2025-63235)
vulnerability in dos (CVE-2025-63235). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64636 |
|
SQL Injection in sqli (CVE-2026-64636)
SQL injection in sqli (CVE-2026-64636). Confidential information can be exposed externally.
|
| CVE-2026-68772 |
|
Unsafe Deserialization in CVE-2026-68772 (CVE-2026-68772)
vulnerability in CVE-2026-68772 (CVE-2026-68772). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20345 |
|
Vulnerability in dos (CVE-2026-20345)
vulnerability in dos (CVE-2026-20345). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20346 |
|
Out-of-Bounds Read in dos (CVE-2026-20346)
vulnerability in dos (CVE-2026-20346). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20347 |
|
Out-of-Bounds Read in dos (CVE-2026-20347)
vulnerability in dos (CVE-2026-20347). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20348 |
|
Vulnerability in dos (CVE-2026-20348)
vulnerability in dos (CVE-2026-20348). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19211 |
|
Vulnerability in sqli (CVE-2026-19211)
vulnerability in sqli (CVE-2026-19211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20338 |
|
Vulnerability in dos (CVE-2026-20338)
vulnerability in dos (CVE-2026-20338). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20339 |
|
Vulnerability in dos (CVE-2026-20339)
vulnerability in dos (CVE-2026-20339). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20337 |
|
Vulnerability in Cisco dos (CVE-2026-20337)
vulnerability in Cisco dos (CVE-2026-20337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66838 |
|
SQL Injection in sqli (CVE-2026-66838)
SQL injection in sqli (CVE-2026-66838). Confidential information can be exposed externally.
|
| CVE-2026-71559 |
|
Unsafe Deserialization in apache (CVE-2026-71559)
vulnerability in apache (CVE-2026-71559). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19196 |
|
Vulnerability in sqli (CVE-2026-19196)
vulnerability in sqli (CVE-2026-19196). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15361 |
|
SQL Injection in wordpress (CVE-2026-15361)
SQL injection in wordpress (CVE-2026-15361). Confidential information can be exposed externally.
|
| CVE-2026-16262 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16262)
vulnerability in wordpress (CVE-2026-16262). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15215 |
|
Privilege Escalation in wordpress (CVE-2026-15215)
vulnerability in wordpress (CVE-2026-15215). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49163 |
|
Path Traversal in path-traversal (CVE-2026-49163)
path traversal in path-traversal (CVE-2026-49163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7867 |
|
Authorization Flaw in privilege-escalation (CVE-2026-7867)
vulnerability in privilege-escalation (CVE-2026-7867). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70638 |
|
Vulnerability in cpp (CVE-2026-70638)
vulnerability in cpp (CVE-2026-70638). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70636 |
|
Vulnerability in CVE-2026-70636 (CVE-2026-70636)
vulnerability in CVE-2026-70636 (CVE-2026-70636). Data can be tampered with by attackers.
|
| CVE-2026-70640 |
|
Vulnerability in cpp (CVE-2026-70640)
vulnerability in cpp (CVE-2026-70640). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67422 |
|
Vulnerability in pymdown-extensions (CVE-2026-67422)
vulnerability in pymdown-extensions (CVE-2026-67422). Risk of unauthorized operations or information disclosure. Exploitable via ``caret``. Mitigation: upgrade to `10.16.1` or later.
|
| CVE-2026-5857 |
|
Out-of-Bounds Write in c (CVE-2026-5857)
out-of-bounds write in c (CVE-2026-5857). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53983 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-53983)
SSRF in c (CVE-2026-53983). Confidential information can be exposed externally.
|
| CVE-2026-48080 |
|
Information Disclosure in ssrf (CVE-2026-48080)
vulnerability in ssrf (CVE-2026-48080). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/tenants/{id}`.
|
| CVE-2026-43631 |
|
Vulnerability in cpp (CVE-2026-43631)
vulnerability in cpp (CVE-2026-43631). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43628 |
|
Out-of-Bounds Read in cpp (CVE-2026-43628)
vulnerability in cpp (CVE-2026-43628). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19169 |
|
Vulnerability in privilege-escalation (CVE-2026-19169)
vulnerability in privilege-escalation (CVE-2026-19169). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19139 |
|
Vulnerability in privilege-escalation (CVE-2026-19139)
vulnerability in privilege-escalation (CVE-2026-19139). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19062 |
|
Vulnerability in sqli (CVE-2026-19062)
vulnerability in sqli (CVE-2026-19062). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-39024 |
|
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
|
| CVE-2026-53977 |
|
Vulnerability in express (CVE-2026-53977)
vulnerability in express (CVE-2026-53977). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3430 |
|
SQL Injection in wordpress (CVE-2026-3430)
SQL injection in wordpress (CVE-2026-3430). Confidential information can be exposed externally.
|
| CVE-2026-43622 |
|
Vulnerability in c (CVE-2026-43622)
vulnerability in c (CVE-2026-43622). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66711 |
|
Cross-Site Scripting (XSS) in CVE-2026-66711 (CVE-2026-66711)
cross-site scripting in CVE-2026-66711 (CVE-2026-66711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66702 |
|
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
|
| CVE-2026-66705 |
|
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
|
| CVE-2026-66707 |
|
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
|
| CVE-2026-66694 |
|
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
|
| CVE-2026-66690 |
|
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
|