Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Clear
ID Title
CVE-2026-14955 Path Traversal in wordpress (CVE-2026-14955)
path traversal in wordpress (CVE-2026-14955). Confidential information can be exposed externally.
CVE-2026-15425 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15425)
cross-site scripting in wordpress (CVE-2026-15425). Risk of unauthorized operations or information disclosure.
CVE-2026-10818 Unrestricted File Upload in wordpress (CVE-2026-10818)
vulnerability in wordpress (CVE-2026-10818). Successful exploitation can lead to full system takeover.
CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
CVE-2026-66337 Out-of-Bounds Read in gnome (CVE-2026-66337)
vulnerability in gnome (CVE-2026-66337). Risk of unauthorized operations or information disclosure.
CVE-2026-61892 Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
CVE-2026-66338 Vulnerability in gnome (CVE-2026-66338)
vulnerability in gnome (CVE-2026-66338). Risk of unauthorized operations or information disclosure.
CVE-2026-16280 Vulnerability in imaginationtech (CVE-2026-16280)
vulnerability in imaginationtech (CVE-2026-16280). Successful exploitation can lead to full system takeover.
CVE-2026-73500 Vulnerability in go.etcd.io/etcd/v3 (CVE-2026-73500)
vulnerability in go.etcd.io/etcd/v3 (CVE-2026-73500). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.33` or later.
CVE-2026-73502 Vulnerability in github.com/getkin/kin-openapi (CVE-2026-73502)
vulnerability in github.com/getkin/kin-openapi (CVE-2026-73502). Risk of unauthorized operations or information disclosure. Exploitable via ``HEAD``. Mitigation: upgrade to `0.144.0` or later.
CVE-2026-73499 Authorization Flaw in go.etcd.io/etcd/v3 (CVE-2026-73499)
vulnerability in go.etcd.io/etcd/v3 (CVE-2026-73499). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.33` or later.
CVE-2026-73568 Vulnerability in libp2p (CVE-2026-73568)
vulnerability in libp2p (CVE-2026-73568). Risk of unauthorized operations or information disclosure. Exploitable via ``length``.
CVE-2026-73647 Vulnerability in quasar (CVE-2026-73647)
vulnerability in quasar (CVE-2026-73647). Risk of unauthorized operations or information disclosure. Exploitable via ``__proto__``. Mitigation: upgrade to `2.22.0` or later.
CVE-2026-73505 Code Injection in github.com/jandedobbeleer/oh-my-posh (CVE-2026-73505)
code injection in github.com/jandedobbeleer/oh-my-posh (CVE-2026-73505). Successful exploitation can lead to full system takeover. Exploitable via ``cmd``. Mitigation: upgrade to `29.35.1` or later.
CVE-2026-73413 Vulnerability in shescape (CVE-2026-73413)
vulnerability in shescape (CVE-2026-73413). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-73411 Vulnerability in shescape (CVE-2026-73411)
vulnerability in shescape (CVE-2026-73411). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-73414 OS Command Injection in shescape (CVE-2026-73414)
OS command injection in shescape (CVE-2026-73414). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-73412 OS Command Injection in shescape (CVE-2026-73412)
OS command injection in shescape (CVE-2026-73412). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-73509 Path Traversal in github.com/OpenListTeam/OpenList/v4 (CVE-2026-73509)
path traversal in github.com/OpenListTeam/OpenList/v4 (CVE-2026-73509). Data can be tampered with by attackers. Exploitable via ``new_name``. Mitigation: upgrade to `4.2.4` or later.
CVE-2026-73493 Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `1.0.0-M42` or later.
CVE-2026-73495 Vulnerability in org.http4s:blaze-http_2.13 (CVE-2026-73495)
vulnerability in org.http4s:blaze-http_2.13 (CVE-2026-73495). Confidential information can be exposed externally. Exploitable via ``Request.headers``. Mitigation: upgrade to `1.0.0-M42` or later.
CVE-2025-71408 Vulnerability in nltk (CVE-2025-71408)
vulnerability in nltk (CVE-2025-71408). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.3` or later.
CVE-2026-55985 Vulnerability in CVE-2026-55985 (CVE-2026-55985)
vulnerability in CVE-2026-55985 (CVE-2026-55985). Risk of unauthorized operations or information disclosure.
CVE-2026-73652 Authorization Flaw in vantage6 (CVE-2026-73652)
vulnerability in vantage6 (CVE-2026-73652). Risk of unauthorized operations or information disclosure.
CVE-2026-73564 Vulnerability in github.com/fatedier/frp (CVE-2026-73564)
vulnerability in github.com/fatedier/frp (CVE-2026-73564). Risk of unauthorized operations or information disclosure. Exploitable via ``frps``. Mitigation: upgrade to `0.70.1` or later.
CVE-2026-73561 Vulnerability in @anephenix/hub (CVE-2026-73561)
vulnerability in @anephenix/hub (CVE-2026-73561). Risk of unauthorized operations or information disclosure. Exploitable via ``setInterval``. Mitigation: upgrade to `0.2.16` or later.
CVE-2026-73644 Vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644)
vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644). Confidential information can be exposed externally. Mitigation: upgrade to `5.1.2` or later.
CVE-2026-73307 SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-73307)
SSRF in @budibase/server (CVE-2026-73307). Risk of unauthorized operations or information disclosure.
CVE-2026-73410 Vulnerability in @budibase/server (CVE-2026-73410)
vulnerability in @budibase/server (CVE-2026-73410). Successful exploitation can lead to full system takeover. Exploitable via ``fetchWithBlacklist``.
CVE-2026-73308 Information Disclosure in @budibase/server (CVE-2026-73308)
vulnerability in @budibase/server (CVE-2026-73308). Confidential information can be exposed externally. Exploitable via `GET /api/automations/`.
CVE-2026-73406 Information Disclosure in @budibase/server (CVE-2026-73406)
vulnerability in @budibase/server (CVE-2026-73406). Confidential information can be exposed externally. Exploitable via `GET /api/global/users/tenant/`.
CVE-2026-62323 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-62323)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-62323). Data can be tampered with by attackers. Exploitable via `PUT /api/v4/file/viewerSession`. Mitigation: upgrade to `4.0.0-20260626022433-f3347130ac48` or later.
CVE-2026-73302 Authentication Bypass in @budibase/server (CVE-2026-73302)
authentication bypass in @budibase/server (CVE-2026-73302). Risk of unauthorized operations or information disclosure. Exploitable via `POST /realms/budi/protocol/openid-connect/token`.
CVE-2026-73409 Vulnerability in @budibase/server (CVE-2026-73409)
vulnerability in @budibase/server (CVE-2026-73409). Risk of unauthorized operations or information disclosure. Exploitable via ``tlsCertificateKeyFile``.
CVE-2026-73304 Information Disclosure in @budibase/server (CVE-2026-73304)
vulnerability in @budibase/server (CVE-2026-73304). Confidential information can be exposed externally. Exploitable via `GET /api/users/metadata`. Mitigation: upgrade to `3.39.25` or later.
CVE-2026-73301 Vulnerability in @budibase/server (CVE-2026-73301)
vulnerability in @budibase/server (CVE-2026-73301). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/global/groups`.
CVE-2026-73305 Privilege Escalation in @budibase/server (CVE-2026-73305)
vulnerability in @budibase/server (CVE-2026-73305). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/public/v1/roles/assign`.
CVE-2026-55502 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55502)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55502). Data can be tampered with by attackers. Exploitable via `POST /api/v4/admin/policy/oauth/signin`. Mitigation: upgrade to `4.17.0` or later.
CVE-2026-55499 Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55499)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55499). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4/file/events`. Mitigation: upgrade to `4.0.0-20260613030215-0b00dd308f13` or later.
CVE-2026-55497 Vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55497)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55497). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v4/user/setting/avatar`. Mitigation: upgrade to `4.0.0-20260613024411-3607f79bb44c` or later.
CVE-2026-55496 Information Disclosure in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55496)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55496). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4/user/search`. Mitigation: upgrade to `4.0.0-20260613023921-7e1289d55279` or later.
CVE-2026-55495 Path Traversal in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55495)
path traversal in github.com/cloudreve/Cloudreve/v4 (CVE-2026-55495). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v4/file/wopi/`. Mitigation: upgrade to `4.0.0-20260613023150-7968e50429ef` or later.
CVE-2026-66040 FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
CVE-2026-66041 FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write...
CVE-2026-66039 FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability...
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability...
CVE-2026-66038 Vulnerability in c (CVE-2026-66038)
vulnerability in c (CVE-2026-66038). Confidential information can be exposed externally.
CVE-2026-66036 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
CVE-2026-66037 Vulnerability in c (CVE-2026-66037)
vulnerability in c (CVE-2026-66037). Risk of unauthorized operations or information disclosure.
CVE-2026-62835 Vulnerability in microsoft (CVE-2026-62835)
vulnerability in microsoft (CVE-2026-62835). Confidential information can be exposed externally.
CVE-2026-57531 Cross-Site Scripting (XSS) in CVE-2026-57531 (CVE-2026-57531)
cross-site scripting in CVE-2026-57531 (CVE-2026-57531). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →