Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73628 |
|
Cross-Site Scripting (XSS) in CVE-2026-73628 (CVE-2026-73628)
cross-site scripting in CVE-2026-73628 (CVE-2026-73628). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2026-73619 |
|
Vulnerability in gitpython-project (CVE-2026-73619)
vulnerability in gitpython-project (CVE-2026-73619). Confidential information can be exposed externally.
|
| CVE-2026-73613 |
|
Vulnerability in CVE-2026-73613 (CVE-2026-73613)
vulnerability in CVE-2026-73613 (CVE-2026-73613). Data can be tampered with by attackers.
|
| CVE-2026-73602 |
|
Vulnerability in path-traversal (CVE-2026-73602)
vulnerability in path-traversal (CVE-2026-73602). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73601 |
|
Vulnerability in CVE-2026-73601 (CVE-2026-73601)
vulnerability in CVE-2026-73601 (CVE-2026-73601). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73607 |
|
Vulnerability in CVE-2026-73607 (CVE-2026-73607)
vulnerability in CVE-2026-73607 (CVE-2026-73607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73605 |
|
Vulnerability in path-traversal (CVE-2026-73605)
vulnerability in path-traversal (CVE-2026-73605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73609 |
|
Vulnerability in CVE-2026-73609 (CVE-2026-73609)
vulnerability in CVE-2026-73609 (CVE-2026-73609). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73608 |
|
Vulnerability in CVE-2026-73608 (CVE-2026-73608)
vulnerability in CVE-2026-73608 (CVE-2026-73608). Confidential information can be exposed externally. Mitigation: upgrade to `3.7.4` or later.
|
| CVE-2026-73603 |
|
Vulnerability in CVE-2026-73603 (CVE-2026-73603)
vulnerability in CVE-2026-73603 (CVE-2026-73603). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16455 |
|
Vulnerability in CVE-2026-16455 (CVE-2026-16455)
vulnerability in CVE-2026-16455 (CVE-2026-16455). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73484 |
|
Vulnerability in flowiseai (CVE-2026-73484)
vulnerability in flowiseai (CVE-2026-73484). Confidential information can be exposed externally.
|
| CVE-2026-45819 |
|
Vulnerability in dos (CVE-2026-45819)
vulnerability in dos (CVE-2026-45819). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73483 |
|
OS Command Injection in flowiseai (CVE-2026-73483)
OS command injection in flowiseai (CVE-2026-73483). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-73487 |
|
Code Injection in ssrf (CVE-2026-73487)
code injection in ssrf (CVE-2026-73487). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73485 |
|
Code Injection in flowiseai (CVE-2026-73485)
code injection in flowiseai (CVE-2026-73485). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73486 |
|
Code Injection in flowiseai (CVE-2026-73486)
code injection in flowiseai (CVE-2026-73486). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18368 |
|
Vulnerability in c (CVE-2026-18368)
vulnerability in c (CVE-2026-18368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12263 |
|
Vulnerability in CVE-2026-12263 (CVE-2026-12263)
vulnerability in CVE-2026-12263 (CVE-2026-12263). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73604 |
|
Information Disclosure in CVE-2026-73604 (CVE-2026-73604)
vulnerability in CVE-2026-73604 (CVE-2026-73604). Confidential information can be exposed externally. Exploitable via `GET /api/v1/credentials/`.
|
| CVE-2026-59503 |
|
Information Disclosure in CVE-2026-59503 (CVE-2026-59503)
vulnerability in CVE-2026-59503 (CVE-2026-59503). Confidential information can be exposed externally.
|
| CVE-2026-59506 |
|
CWE-306: Missing Authentication for Critical Function
CWE-306: Missing Authentication for Critical Function
|
| CVE-2026-59507 |
|
Vulnerability in CVE-2026-59507 (CVE-2026-59507)
vulnerability in CVE-2026-59507 (CVE-2026-59507). Confidential information can be exposed externally.
|
| CVE-2026-59500 |
|
CWE-287: Improper Authentication
CWE-287: Improper Authentication
|
| CVE-2026-59501 |
|
CWE-284: Improper Access Control
CWE-284: Improper Access Control
|
| CVE-2026-59505 |
|
CWE-284: Improper Access Control
CWE-284: Improper Access Control
|
| CVE-2026-59502 |
|
CWE-203: Observable Discrepancy
CWE-203: Observable Discrepancy
|
| CVE-2026-59499 |
|
CWE-200: Exposure of Sensitive
Information to an Unauthorized Actor
CWE-200: Exposure of Sensitive
Information to an Unauthorized Actor
|
| CVE-2026-19484 |
|
Vulnerability in fastify (CVE-2026-19484)
vulnerability in fastify (CVE-2026-19484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11970 |
|
Vulnerability in CVE-2026-11970 (CVE-2026-11970)
vulnerability in CVE-2026-11970 (CVE-2026-11970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19695 |
|
Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service
|
| CVE-2026-19696 |
|
Out-of-Bounds Write in dos (CVE-2026-19696)
out-of-bounds write in dos (CVE-2026-19696). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16458 |
|
Vulnerability in CVE-2026-16458 (CVE-2026-16458)
vulnerability in CVE-2026-16458 (CVE-2026-16458). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16459 |
|
Vulnerability in CVE-2026-16459 (CVE-2026-16459)
vulnerability in CVE-2026-16459 (CVE-2026-16459). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15413 |
|
Vulnerability in wordpress (CVE-2026-15413)
vulnerability in wordpress (CVE-2026-15413). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19694 |
|
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service
|
| CVE-2026-14332 |
|
Vulnerability in wordpress (CVE-2026-14332)
vulnerability in wordpress (CVE-2026-14332). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19481 |
|
Vulnerability in dos (CVE-2026-19481)
vulnerability in dos (CVE-2026-19481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3639 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3639)
cross-site scripting in wordpress (CVE-2026-3639). Risk of unauthorized operations or information disclosure. Exploitable via ``ppwp``.
|
| CVE-2026-11840 |
|
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions...
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions...
|
| CVE-2026-18146 |
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
| CVE-2026-18622 |
|
Vulnerability in CVE-2026-18622 (CVE-2026-18622)
vulnerability in CVE-2026-18622 (CVE-2026-18622). Data can be tampered with by attackers.
|
| CVE-2026-3835 |
|
Vulnerability in wordpress (CVE-2026-3835)
vulnerability in wordpress (CVE-2026-3835). Risk of unauthorized operations or information disclosure. Exploitable via ``LIKE``.
|
| CVE-2026-13610 |
|
Privilege Escalation in wordpress (CVE-2026-13610)
vulnerability in wordpress (CVE-2026-13610). Confidential information can be exposed externally.
|
| CVE-2026-19182 |
|
Authorization Flaw in CVE-2026-19182 (CVE-2026-19182)
vulnerability in CVE-2026-19182 (CVE-2026-19182). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14182 |
|
Authentication Bypass in wordpress (CVE-2026-14182)
authentication bypass in wordpress (CVE-2026-14182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13328 |
|
Vulnerability in wordpress (CVE-2026-13328)
vulnerability in wordpress (CVE-2026-13328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19135 |
|
Vulnerability in CVE-2026-19135 (CVE-2026-19135)
vulnerability in CVE-2026-19135 (CVE-2026-19135). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19088 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-19088)
vulnerability in wordpress (CVE-2026-19088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18728 |
|
Vulnerability in dos (CVE-2026-18728)
vulnerability in dos (CVE-2026-18728). Risk of unauthorized operations or information disclosure. Exploitable via ``iscsiuio``.
|