Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-58016 |
|
Vulnerability in c (CVE-2026-58016)
vulnerability in c (CVE-2026-58016). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13474 |
|
Vulnerability in dos (CVE-2026-13474)
vulnerability in dos (CVE-2026-13474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53433 |
|
Vulnerability in dos (CVE-2026-53433)
vulnerability in dos (CVE-2026-53433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50734 |
|
Vulnerability in activemq (CVE-2026-50734)
vulnerability in activemq (CVE-2026-50734). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-50750 |
|
Vulnerability in activemq (CVE-2026-50750)
vulnerability in activemq (CVE-2026-50750). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-53917 |
|
Vulnerability in activemq (CVE-2026-53917)
vulnerability in activemq (CVE-2026-53917). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-8141 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8141)
cross-site scripting in wordpress (CVE-2026-8141). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7406 |
|
Privilege Escalation in privilege-escalation (CVE-2025-7406)
vulnerability in privilege-escalation (CVE-2025-7406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14164 |
|
Vulnerability in dos (CVE-2026-14164)
vulnerability in dos (CVE-2026-14164). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11590 |
|
Vulnerability in wordpress (CVE-2026-11590)
vulnerability in wordpress (CVE-2026-11590). Confidential information can be exposed externally.
|
| CVE-2026-11589 |
|
Vulnerability in wordpress (CVE-2026-11589)
vulnerability in wordpress (CVE-2026-11589). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12240 |
|
Unsafe Deserialization in wordpress (CVE-2026-12240)
vulnerability in wordpress (CVE-2026-12240). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58302 |
|
Path Traversal in path-traversal (CVE-2026-58302)
path traversal in path-traversal (CVE-2026-58302). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12243 |
|
Path Traversal in nltk (CVE-2026-12243)
path traversal in nltk (CVE-2026-12243). Confidential information can be exposed externally. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-51219 |
|
Vulnerability in dos (CVE-2026-51219)
vulnerability in dos (CVE-2026-51219). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51218 |
|
Vulnerability in cpp (CVE-2026-51218)
vulnerability in cpp (CVE-2026-51218). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7656 |
|
Vulnerability in c (CVE-2026-7656)
vulnerability in c (CVE-2026-7656). Data can be tampered with by attackers.
|
| CVE-2026-51221 |
|
Vulnerability in dos (CVE-2026-51221)
vulnerability in dos (CVE-2026-51221). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34594 |
|
OS Command Injection in CVE-2026-34594 (CVE-2026-34594)
OS command injection in CVE-2026-34594 (CVE-2026-34594). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.0-beta.471` or later.
|
| CVE-2026-34597 |
|
OS Command Injection in CVE-2026-34597 (CVE-2026-34597)
OS command injection in CVE-2026-34597 (CVE-2026-34597). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.0-beta.470` or later.
|
| CVE-2026-57919 |
|
Vulnerability in privilege-escalation (CVE-2026-57919)
vulnerability in privilege-escalation (CVE-2026-57919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56018 |
|
Vulnerability in dos (CVE-2026-56018)
vulnerability in dos (CVE-2026-56018). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56017 |
|
Out-of-Bounds Read in dos (CVE-2026-56017)
vulnerability in dos (CVE-2026-56017). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57950 |
|
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control...
|
| CVE-2026-57947 |
|
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook...
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook...
|
| CVE-2026-57955 |
|
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers...
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers...
|
| CVE-2026-36848 |
|
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
|
| CVE-2026-56285 |
|
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and...
|
| CVE-2026-56780 |
|
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api...
Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api...
|
| CVE-2026-12912 |
|
Vulnerability in dos (CVE-2026-12912)
vulnerability in dos (CVE-2026-12912). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57320 |
|
Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.
Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.
|
| CVE-2026-57333 |
|
Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.
|
| CVE-2026-57337 |
|
Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.
|
| CVE-2026-57336 |
|
Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.
|
| CVE-2026-57338 |
|
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
|
| CVE-2026-54371 |
|
Vulnerability in privilege-escalation (CVE-2026-54371)
vulnerability in privilege-escalation (CVE-2026-54371). Confidential information can be exposed externally.
|
| CVE-2026-54369 |
|
Vulnerability in privilege-escalation (CVE-2026-54369)
vulnerability in privilege-escalation (CVE-2026-54369). Confidential information can be exposed externally.
|
| CVE-2026-40523 |
|
SQL Injection in sqli (CVE-2026-40523)
SQL injection in sqli (CVE-2026-40523). Confidential information can be exposed externally.
|
| CVE-2026-40524 |
|
SQL Injection in sqli (CVE-2026-40524)
SQL injection in sqli (CVE-2026-40524). Confidential information can be exposed externally.
|
| CVE-2026-40521 |
|
Path Traversal in path-traversal (CVE-2026-40521)
path traversal in path-traversal (CVE-2026-40521). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40522 |
|
SQL Injection in sqli (CVE-2026-40522)
SQL injection in sqli (CVE-2026-40522). Confidential information can be exposed externally.
|
| CVE-2026-13565 |
|
Vulnerability in sqli (CVE-2026-13565)
vulnerability in sqli (CVE-2026-13565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13566 |
|
Vulnerability in sqli (CVE-2026-13566)
vulnerability in sqli (CVE-2026-13566). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13559 |
|
Vulnerability in sqli (CVE-2026-13559)
vulnerability in sqli (CVE-2026-13559). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57346 |
|
Path Traversal in path-traversal (CVE-2026-57346)
path traversal in path-traversal (CVE-2026-57346). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25707 |
|
Vulnerability in path-traversal (CVE-2026-25707)
vulnerability in path-traversal (CVE-2026-25707). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13555 |
|
Vulnerability in sqli (CVE-2026-13555)
vulnerability in sqli (CVE-2026-13555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13552 |
|
Vulnerability in sqli (CVE-2026-13552)
vulnerability in sqli (CVE-2026-13552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13551 |
|
Vulnerability in sqli (CVE-2026-13551)
vulnerability in sqli (CVE-2026-13551). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13550 |
|
Vulnerability in sqli (CVE-2026-13550)
vulnerability in sqli (CVE-2026-13550). Risk of unauthorized operations or information disclosure.
|