Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-7326 |
|
Cross-Site Request Forgery (CSRF) in progress (CVE-2026-7326)
vulnerability in progress (CVE-2026-7326). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60023 |
|
Information Disclosure in apache (CVE-2026-60023)
vulnerability in apache (CVE-2026-60023). Confidential information can be exposed externally.
|
| CVE-2026-48911 |
|
Vulnerability in apache (CVE-2026-48911)
vulnerability in apache (CVE-2026-48911). Data can be tampered with by attackers.
|
| CVE-2026-50749 |
|
Authorization Flaw in apache (CVE-2026-50749)
vulnerability in apache (CVE-2026-50749). Data can be tampered with by attackers.
|
| CVE-2026-53992 |
|
Cross-Site Scripting (XSS) in CVE-2026-53992 (CVE-2026-53992)
cross-site scripting in CVE-2026-53992 (CVE-2026-53992). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48834 |
|
Vulnerability in apache (CVE-2026-48834)
vulnerability in apache (CVE-2026-48834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39923 |
|
Vulnerability in CVE-2026-39923 (CVE-2026-39923)
vulnerability in CVE-2026-39923 (CVE-2026-39923). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18531 |
|
Vulnerability in ibm (CVE-2026-18531)
vulnerability in ibm (CVE-2026-18531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15572 |
|
Vulnerability in redhat (CVE-2026-15572)
vulnerability in redhat (CVE-2026-15572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10025 |
|
XXE (XML External Entity) in ibm (CVE-2026-10025)
vulnerability in ibm (CVE-2026-10025). Confidential information can be exposed externally.
|
| CVE-2026-13477 |
|
OS Command Injection in ibm (CVE-2026-13477)
OS command injection in ibm (CVE-2026-13477). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70606 |
|
Vulnerability in electron (CVE-2026-70606)
vulnerability in electron (CVE-2026-70606). Confidential information can be exposed externally. Exploitable via ``ProtocolResponse``. Mitigation: upgrade to `40.10.6` or later.
|
| CVE-2026-70605 |
|
SSRF (Server-Side Request Forgery) in electron (CVE-2026-70605)
SSRF in electron (CVE-2026-70605). Confidential information can be exposed externally. Exploitable via ``net``. Mitigation: upgrade to `42.0.0-beta.3` or later.
|
| CVE-2026-70602 |
|
Vulnerability in electron (CVE-2026-70602)
vulnerability in electron (CVE-2026-70602). Confidential information can be exposed externally. Exploitable via ``session``. Mitigation: upgrade to `42.0.0-beta.3` or later.
|
| CVE-2026-70603 |
|
Vulnerability in electron (CVE-2026-70603)
vulnerability in electron (CVE-2026-70603). Confidential information can be exposed externally. Mitigation: upgrade to `39.8.6` or later.
|
| CVE-2026-70601 |
|
Vulnerability in electron (CVE-2026-70601)
vulnerability in electron (CVE-2026-70601). Confidential information can be exposed externally. Exploitable via ``contextBridge``. Mitigation: upgrade to `42.0.0-beta.5` or later.
|
| CVE-2026-16100 |
|
Vulnerability in redhat (CVE-2026-16100)
vulnerability in redhat (CVE-2026-16100). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17613 |
|
Vulnerability in CVE-2026-17613 (CVE-2026-17613)
vulnerability in CVE-2026-17613 (CVE-2026-17613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16102 |
|
Vulnerability in redhat (CVE-2026-16102)
vulnerability in redhat (CVE-2026-16102). Confidential information can be exposed externally.
|
| CVE-2026-12410 |
|
Vulnerability in CVE-2026-12410 (CVE-2026-12410)
vulnerability in CVE-2026-12410 (CVE-2026-12410). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54876 |
|
Vulnerability in dos (CVE-2026-54876)
vulnerability in dos (CVE-2026-54876). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15573 |
|
Vulnerability in redhat (CVE-2026-15573)
vulnerability in redhat (CVE-2026-15573). Confidential information can be exposed externally.
|
| CVE-2026-16071 |
|
Vulnerability in redhat (CVE-2026-16071)
vulnerability in redhat (CVE-2026-16071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70598 |
|
Out-of-Bounds Read in electron (CVE-2026-70598)
vulnerability in electron (CVE-2026-70598). Risk of unauthorized operations or information disclosure. Exploitable via ``paint``. Mitigation: upgrade to `42.0.0-beta.3` or later.
|
| CVE-2026-70597 |
|
Vulnerability in electron (CVE-2026-70597)
vulnerability in electron (CVE-2026-70597). Confidential information can be exposed externally. Exploitable via ``ELECTRON_RUN_AS_NODE``. Mitigation: upgrade to `42.0.0-beta.3` or later.
|
| CVE-2026-70596 |
|
Cross-Site Scripting (XSS) in ghost (CVE-2026-70596)
cross-site scripting in ghost (CVE-2026-70596). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70595 |
|
SSRF (Server-Side Request Forgery) in ghost (CVE-2026-70595)
SSRF in ghost (CVE-2026-70595). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-7529 |
|
Vulnerability in wordpress (CVE-2026-7529)
vulnerability in wordpress (CVE-2026-7529). Data can be tampered with by attackers.
|
| CVE-2026-7456 |
|
Vulnerability in wordpress (CVE-2026-7456)
vulnerability in wordpress (CVE-2026-7456). Data can be tampered with by attackers.
|
| CVE-2026-67623 |
|
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
|
| CVE-2026-17506 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17506)
cross-site scripting in wordpress (CVE-2026-17506). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16443 |
|
Vulnerability in redhat (CVE-2026-16443)
vulnerability in redhat (CVE-2026-16443). Confidential information can be exposed externally.
|
| CVE-2026-15979 |
|
Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
|
| CVE-2025-70962 |
|
Vulnerability in CVE-2025-70962 (CVE-2025-70962)
vulnerability in CVE-2025-70962 (CVE-2025-70962). Confidential information can be exposed externally.
|
| CVE-2026-71294 |
|
Unsafe Deserialization in CVE-2026-71294 (CVE-2026-71294)
vulnerability in CVE-2026-71294 (CVE-2026-71294). Confidential information can be exposed externally. Exploitable via ``allowed_classes``.
|
| CVE-2026-71293 |
|
Information Disclosure in CVE-2026-71293 (CVE-2026-71293)
vulnerability in CVE-2026-71293 (CVE-2026-71293). Confidential information can be exposed externally. Exploitable via ``two_factor_recovery_codes``.
|
| CVE-2026-71289 |
|
Vulnerability in c (CVE-2026-71289)
vulnerability in c (CVE-2026-71289). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71286 |
|
Vulnerability in CVE-2026-71286 (CVE-2026-71286)
vulnerability in CVE-2026-71286 (CVE-2026-71286). Risk of unauthorized operations or information disclosure. Exploitable via ``templateString``.
|
| CVE-2026-71291 |
|
Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
|
| CVE-2026-71287 |
|
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
|
| CVE-2026-71288 |
|
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
|
| CVE-2026-71292 |
|
SQL Injection in CVE-2026-71292 (CVE-2026-71292)
SQL injection in CVE-2026-71292 (CVE-2026-71292). Successful exploitation can lead to full system takeover. Exploitable via ``dir``.
|
| CVE-2026-71285 |
|
Cross-Site Scripting (XSS) in CVE-2026-71285 (CVE-2026-71285)
cross-site scripting in CVE-2026-71285 (CVE-2026-71285). Confidential information can be exposed externally. Exploitable via ``siteId``.
|
| CVE-2026-71284 |
|
OS Command Injection in CVE-2026-71284 (CVE-2026-71284)
OS command injection in CVE-2026-71284 (CVE-2026-71284). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71278 |
|
Code Injection in CVE-2026-71278 (CVE-2026-71278)
code injection in CVE-2026-71278 (CVE-2026-71278). Successful exploitation can lead to full system takeover. Exploitable via `POST /calc-rule/create`.
|
| CVE-2026-71276 |
|
SQL Injection in sqli (CVE-2026-71276)
SQL injection in sqli (CVE-2026-71276). Confidential information can be exposed externally. Exploitable via ``format``.
|
| CVE-2026-71282 |
|
SQL Injection in CVE-2026-71282 (CVE-2026-71282)
SQL injection in CVE-2026-71282 (CVE-2026-71282). Confidential information can be exposed externally.
|
| CVE-2026-71281 |
|
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
|
| CVE-2026-71280 |
|
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
|
| CVE-2026-71279 |
|
Path Traversal in CVE-2026-71279 (CVE-2026-71279)
path traversal in CVE-2026-71279 (CVE-2026-71279). Successful exploitation can lead to full system takeover. Exploitable via ``name``.
|