Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2023-54366 SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT,...
CVE-2026-9147 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file...
CVE-2026-15631 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
CVE-2026-47868 Privilege Escalation in privilege-escalation (CVE-2026-47868)
vulnerability in privilege-escalation (CVE-2026-47868). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47870 Privilege Escalation in privilege-escalation (CVE-2026-47870)
vulnerability in privilege-escalation (CVE-2026-47870). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47871 Path Traversal in path-traversal (CVE-2026-47871)
path traversal in path-traversal (CVE-2026-47871). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47869 Code Injection in broadcom (CVE-2026-47869)
code injection in broadcom (CVE-2026-47869). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-47867 Code Injection in broadcom (CVE-2026-47867)
code injection in broadcom (CVE-2026-47867). Confidential information can be exposed externally. Mitigation: upgrade to `32.1.2` or later.
CVE-2026-56741 Vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741)
vulnerability in org.jline:jline-remote-telnet (CVE-2026-56741). Risk of unauthorized operations or information disclosure. Exploitable via ``Telnet``. Mitigation: upgrade to `4.2.1` or later.
CVE-2026-7755 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to...
CVE-2026-8056 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters...
CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
CVE-2026-7754 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery ...
CVE-2026-51833 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-51833)
SSRF in ssrf (CVE-2026-51833). Confidential information can be exposed externally.
CVE-2026-13448 Vulnerability in langflow (CVE-2026-13448)
vulnerability in langflow (CVE-2026-13448). Successful exploitation can lead to full system takeover.
CVE-2026-9171 Vulnerability in dos (CVE-2026-9171)
vulnerability in dos (CVE-2026-9171). Risk of unauthorized operations or information disclosure.
CVE-2026-9762 Code Injection in ibm (CVE-2026-9762)
code injection in ibm (CVE-2026-9762). Successful exploitation can lead to full system takeover.
CVE-2026-12691 Vulnerability in CVE-2026-12691 (CVE-2026-12691)
vulnerability in CVE-2026-12691 (CVE-2026-12691). Confidential information can be exposed externally.
CVE-2026-60025 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-60025)
vulnerability in csrf (CVE-2026-60025). Successful exploitation can lead to full system takeover.
CVE-2026-14741 Vulnerability in dos (CVE-2026-14741)
vulnerability in dos (CVE-2026-14741). Risk of unauthorized operations or information disclosure. Exploitable via ``Date``.
CVE-2026-16014 Vulnerability in sqli (CVE-2026-16014)
vulnerability in sqli (CVE-2026-16014). Risk of unauthorized operations or information disclosure.
CVE-2026-13352 Unrestricted File Upload in wordpress (CVE-2026-13352)
vulnerability in wordpress (CVE-2026-13352). Successful exploitation can lead to full system takeover.
CVE-2026-15395 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15395)
cross-site scripting in wordpress (CVE-2026-15395). Risk of unauthorized operations or information disclosure.
CVE-2026-62238 SQL Injection in sqli (CVE-2026-62238)
SQL injection in sqli (CVE-2026-62238). Successful exploitation can lead to full system takeover.
CVE-2026-62232 Vulnerability in csrf (CVE-2026-62232)
vulnerability in csrf (CVE-2026-62232). Confidential information can be exposed externally.
CVE-2026-62215 Vulnerability in openclaw (CVE-2026-62215)
vulnerability in openclaw (CVE-2026-62215). Confidential information can be exposed externally.
CVE-2026-62207 Vulnerability in openclaw (CVE-2026-62207)
vulnerability in openclaw (CVE-2026-62207). Successful exploitation can lead to full system takeover.
CVE-2026-62202 Authorization Flaw in privilege-escalation (CVE-2026-62202)
vulnerability in privilege-escalation (CVE-2026-62202). Successful exploitation can lead to full system takeover.
CVE-2026-39359 Path Traversal in path-traversal (CVE-2026-39359)
path traversal in path-traversal (CVE-2026-39359). Confidential information can be exposed externally.
CVE-2026-44453 Vulnerability in dos (CVE-2026-44453)
vulnerability in dos (CVE-2026-44453). Risk of unauthorized operations or information disclosure.
CVE-2026-44435 Vulnerability in dos (CVE-2026-44435)
vulnerability in dos (CVE-2026-44435). Risk of unauthorized operations or information disclosure.
CVE-2026-44436 Vulnerability in dos (CVE-2026-44436)
vulnerability in dos (CVE-2026-44436). Risk of unauthorized operations or information disclosure.
CVE-2024-32386 Path Traversal in path-traversal (CVE-2024-32386)
path traversal in path-traversal (CVE-2024-32386). Confidential information can be exposed externally.
CVE-2026-61389 Out-of-Bounds Write in privilege-escalation (CVE-2026-61389)
out-of-bounds write in privilege-escalation (CVE-2026-61389). Successful exploitation can lead to full system takeover.
CVE-2026-60063 Out-of-Bounds Write in privilege-escalation (CVE-2026-60063)
out-of-bounds write in privilege-escalation (CVE-2026-60063). Successful exploitation can lead to full system takeover.
CVE-2026-46336 Path Traversal in path-traversal (CVE-2026-46336)
path traversal in path-traversal (CVE-2026-46336). Data can be tampered with by attackers.
CVE-2026-63086 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63086)
SSRF in ssrf (CVE-2026-63086). Confidential information can be exposed externally.
CVE-2026-63088 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63088)
SSRF in ssrf (CVE-2026-63088). Confidential information can be exposed externally.
CVE-2026-13103 Path Traversal in path-traversal (CVE-2026-13103)
path traversal in path-traversal (CVE-2026-13103). Successful exploitation can lead to full system takeover.
CVE-2026-59867 Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867). Confidential information can be exposed externally. Exploitable via ``REMOTE_KIOTA_PROP``. Mitigation: upgrade to `1.29.1` or later.
CVE-2025-45868 SQL Injection in sqli (CVE-2025-45868)
SQL injection in sqli (CVE-2025-45868). Successful exploitation can lead to full system takeover.
CVE-2026-15352 Vulnerability in cisa (CVE-2026-15352)
vulnerability in cisa (CVE-2026-15352). Risk of unauthorized operations or information disclosure.
CVE-2026-35149 Vulnerability in hcltech (CVE-2026-35149)
vulnerability in hcltech (CVE-2026-35149). Confidential information can be exposed externally.
CVE-2026-7543 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7543)
cross-site scripting in wordpress (CVE-2026-7543). Risk of unauthorized operations or information disclosure.
CVE-2026-15103 Privilege Escalation in wordpress (CVE-2026-15103)
vulnerability in wordpress (CVE-2026-15103). Successful exploitation can lead to full system takeover. Exploitable via ``group_id``.
CVE-2026-15008 Unsafe Deserialization in wordpress (CVE-2026-15008)
vulnerability in wordpress (CVE-2026-15008). Successful exploitation can lead to full system takeover.
CVE-2026-13741 Privilege Escalation in wordpress (CVE-2026-13741)
vulnerability in wordpress (CVE-2026-13741). Successful exploitation can lead to full system takeover. Exploitable via ``digits_reg_userrole``.
CVE-2026-12978 Cross-Site Scripting (XSS) in wordpress (CVE-2026-12978)
cross-site scripting in wordpress (CVE-2026-12978). Risk of unauthorized operations or information disclosure.
CVE-2026-13042 Cross-Site Scripting (XSS) in wordpress (CVE-2026-13042)
cross-site scripting in wordpress (CVE-2026-13042). Risk of unauthorized operations or information disclosure.
CVE-2026-12753 SQL Injection in wordpress (CVE-2026-12753)
SQL injection in wordpress (CVE-2026-12753). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →