Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14817 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14817)
cross-site scripting in wordpress (CVE-2026-14817). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14841 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14841)
cross-site scripting in wordpress (CVE-2026-14841). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13389 |
|
Vulnerability in wordpress (CVE-2026-13389)
vulnerability in wordpress (CVE-2026-13389). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12586 |
|
Authentication Bypass in wordpress (CVE-2026-12586)
authentication bypass in wordpress (CVE-2026-12586). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11872 |
|
Vulnerability in wordpress (CVE-2026-11872)
vulnerability in wordpress (CVE-2026-11872). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15675 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-15675)
cross-site scripting in wordpress (CVE-2025-15675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9335 |
|
Path Traversal in keras (CVE-2026-9335)
path traversal in keras (CVE-2026-9335). Confidential information can be exposed externally. Exploitable via ``KerasFileEditor``. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-13339 |
|
Path Traversal in wordpress (CVE-2026-13339)
path traversal in wordpress (CVE-2026-13339). Confidential information can be exposed externally.
|
| CVE-2026-18352 |
|
Path Traversal in wordpress (CVE-2026-18352)
path traversal in wordpress (CVE-2026-18352). Confidential information can be exposed externally.
|
| CVE-2026-18556 KEV |
|
[KEV] Vulnerability in N-able n-central (CVE-2026-18556)
vulnerability in N-able n-central (CVE-2026-18556). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-55733 |
|
Vulnerability in dos (CVE-2026-55733)
vulnerability in dos (CVE-2026-55733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55734 |
|
Vulnerability in dos (CVE-2026-55734)
vulnerability in dos (CVE-2026-55734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55735 |
|
Vulnerability in dos (CVE-2026-55735)
vulnerability in dos (CVE-2026-55735). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54894 |
|
Vulnerability in dos (CVE-2026-54894)
vulnerability in dos (CVE-2026-54894). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67353 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-67353)
vulnerability in guzzlehttp/guzzle (CVE-2026-67353). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.15.1` or later.
|
| CVE-2026-67344 |
|
Vulnerability in CVE-2026-67344 (CVE-2026-67344)
vulnerability in CVE-2026-67344 (CVE-2026-67344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67341 |
|
Authorization Flaw in CVE-2026-67341 (CVE-2026-67341)
vulnerability in CVE-2026-67341 (CVE-2026-67341). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67343 |
|
Information Disclosure in CVE-2026-67343 (CVE-2026-67343)
vulnerability in CVE-2026-67343 (CVE-2026-67343). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/server`.
|
| CVE-2026-67352 |
|
Cross-Site Scripting (XSS) in CVE-2026-67352 (CVE-2026-67352)
cross-site scripting in CVE-2026-67352 (CVE-2026-67352). Confidential information can be exposed externally.
|
| CVE-2026-67340 |
|
Code Injection in CVE-2026-67340 (CVE-2026-67340)
code injection in CVE-2026-67340 (CVE-2026-67340). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67339 |
|
Information Disclosure in guzzlehttp/guzzle (CVE-2026-67339)
vulnerability in guzzlehttp/guzzle (CVE-2026-67339). Risk of unauthorized operations or information disclosure. Exploitable via ``CurlHandler``. Mitigation: upgrade to `7.14.2` or later.
|
| CVE-2026-67335 |
|
Authentication Bypass in CVE-2026-67335 (CVE-2026-67335)
authentication bypass in CVE-2026-67335 (CVE-2026-67335). Data can be tampered with by attackers.
|
| CVE-2026-67334 |
|
Vulnerability in CVE-2026-67334 (CVE-2026-67334)
vulnerability in CVE-2026-67334 (CVE-2026-67334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67337 |
|
Vulnerability in CVE-2026-67337 (CVE-2026-67337)
vulnerability in CVE-2026-67337 (CVE-2026-67337). Confidential information can be exposed externally.
|
| CVE-2026-67333 |
|
Cross-Site Scripting (XSS) in CVE-2026-67333 (CVE-2026-67333)
cross-site scripting in CVE-2026-67333 (CVE-2026-67333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67326 |
|
Vulnerability in CVE-2026-67326 (CVE-2026-67326)
vulnerability in CVE-2026-67326 (CVE-2026-67326). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67330 |
|
Vulnerability in CVE-2026-67330 (CVE-2026-67330)
vulnerability in CVE-2026-67330 (CVE-2026-67330). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.6.22` or later.
|
| CVE-2026-67328 |
|
Cross-Site Scripting (XSS) in CVE-2026-67328 (CVE-2026-67328)
cross-site scripting in CVE-2026-67328 (CVE-2026-67328). Confidential information can be exposed externally.
|
| CVE-2026-67327 |
|
Authentication Bypass in CVE-2026-67327 (CVE-2026-67327)
authentication bypass in CVE-2026-67327 (CVE-2026-67327). Confidential information can be exposed externally. Mitigation: upgrade to `1.6.22` or later.
|
| CVE-2026-67332 |
|
Vulnerability in CVE-2026-67332 (CVE-2026-67332)
vulnerability in CVE-2026-67332 (CVE-2026-67332). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67319 |
|
Vulnerability in axios (CVE-2026-67319)
vulnerability in axios (CVE-2026-67319). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67320 |
|
Information Disclosure in axios (CVE-2026-67320)
vulnerability in axios (CVE-2026-67320). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `0.33.0` or later.
|
| CVE-2026-67322 |
|
Information Disclosure in gitpython-project (CVE-2026-67322)
vulnerability in gitpython-project (CVE-2026-67322). Confidential information can be exposed externally.
|
| CVE-2026-67324 |
|
OS Command Injection in gitpython-project (CVE-2026-67324)
OS command injection in gitpython-project (CVE-2026-67324). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.1.51` or later.
|
| CVE-2026-67325 |
|
OS Command Injection in gitpython-project (CVE-2026-67325)
OS command injection in gitpython-project (CVE-2026-67325). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67323 |
|
Command Injection in gitpython-project (CVE-2026-67323)
command injection in gitpython-project (CVE-2026-67323). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67317 |
|
Vulnerability in axios (CVE-2026-67317)
vulnerability in axios (CVE-2026-67317). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67312 |
|
Vulnerability in dos (CVE-2026-67312)
vulnerability in dos (CVE-2026-67312). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67313 |
|
Vulnerability in axios (CVE-2026-67313)
vulnerability in axios (CVE-2026-67313). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67318 |
|
Vulnerability in axios (CVE-2026-67318)
vulnerability in axios (CVE-2026-67318). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67311 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-67311 (CVE-2026-67311)
SSRF in CVE-2026-67311 (CVE-2026-67311). Confidential information can be exposed externally.
|
| CVE-2026-67314 |
|
Vulnerability in axios (CVE-2026-67314)
vulnerability in axios (CVE-2026-67314). Risk of unauthorized operations or information disclosure. Exploitable via ``auth``. Mitigation: upgrade to `1.15.2` or later.
|
| CVE-2026-67316 |
|
Vulnerability in axios (CVE-2026-67316)
vulnerability in axios (CVE-2026-67316). Confidential information can be exposed externally.
|
| CVE-2026-67305 |
|
Vulnerability in CVE-2026-67305 (CVE-2026-67305)
vulnerability in CVE-2026-67305 (CVE-2026-67305). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67310 |
|
Authorization Flaw in CVE-2026-67310 (CVE-2026-67310)
vulnerability in CVE-2026-67310 (CVE-2026-67310). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-67309 |
|
Path Traversal in github.com/traefik/traefik/v3 (CVE-2026-67309)
path traversal in github.com/traefik/traefik/v3 (CVE-2026-67309). Risk of unauthorized operations or information disclosure. Exploitable via ``RewriteTarget``. Mitigation: upgrade to `3.7.8` or later.
|
| CVE-2026-67306 |
|
Out-of-Bounds Read in c (CVE-2026-67306)
vulnerability in c (CVE-2026-67306). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67308 |
|
OS Command Injection in CVE-2026-67308 (CVE-2026-67308)
OS command injection in CVE-2026-67308 (CVE-2026-67308). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67301 |
|
Out-of-Bounds Read in CVE-2026-67301 (CVE-2026-67301)
vulnerability in CVE-2026-67301 (CVE-2026-67301). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67299 |
|
Use-After-Free in CVE-2026-67299 (CVE-2026-67299)
vulnerability in CVE-2026-67299 (CVE-2026-67299). Risk of unauthorized operations or information disclosure.
|