Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Clear
ID Title
CVE-2026-12539 Vulnerability in CVE-2026-12539 (CVE-2026-12539)
vulnerability in CVE-2026-12539 (CVE-2026-12539). Risk of unauthorized operations or information disclosure.
CVE-2026-12039 Vulnerability in CVE-2026-12039 (CVE-2026-12039)
vulnerability in CVE-2026-12039 (CVE-2026-12039). Risk of unauthorized operations or information disclosure.
CVE-2026-40456 OS Command Injection in CVE-2026-40456 (CVE-2026-40456)
OS command injection in CVE-2026-40456 (CVE-2026-40456). Risk of unauthorized operations or information disclosure.
CVE-2026-42489 Vulnerability in flask (CVE-2026-42489)
vulnerability in flask (CVE-2026-42489). Risk of unauthorized operations or information disclosure.
CVE-2026-42490 Vulnerability in flask (CVE-2026-42490)
vulnerability in flask (CVE-2026-42490). Risk of unauthorized operations or information disclosure.
CVE-2026-42487 Vulnerability in c (CVE-2026-42487)
vulnerability in c (CVE-2026-42487). Risk of unauthorized operations or information disclosure.
CVE-2026-42488 Buffer Overflow in CVE-2026-42488 (CVE-2026-42488)
vulnerability in CVE-2026-42488 (CVE-2026-42488). Successful exploitation can lead to full system takeover.
CVE-2026-12527 Vulnerability in CVE-2026-12527 (CVE-2026-12527)
vulnerability in CVE-2026-12527 (CVE-2026-12527). Risk of unauthorized operations or information disclosure.
CVE-2025-10560 Vulnerability in CVE-2025-10560 (CVE-2025-10560)
vulnerability in CVE-2025-10560 (CVE-2025-10560). Risk of unauthorized operations or information disclosure.
CVE-2026-8039 Cross-Site Scripting (XSS) in wordpress (CVE-2026-8039)
cross-site scripting in wordpress (CVE-2026-8039). Risk of unauthorized operations or information disclosure.
CVE-2026-2021 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2021)
cross-site scripting in wordpress (CVE-2026-2021). Risk of unauthorized operations or information disclosure.
CVE-2026-8811 Path Traversal in CVE-2026-8811 (CVE-2026-8811)
path traversal in CVE-2026-8811 (CVE-2026-8811). Risk of unauthorized operations or information disclosure.
CVE-2026-11717 Authentication Bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11717)
authentication bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11717). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
CVE-2026-11718 Authentication Bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11718)
authentication bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11718). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
CVE-2026-50643 Out-of-Bounds Read in CVE-2026-50643 (CVE-2026-50643)
vulnerability in CVE-2026-50643 (CVE-2026-50643). Risk of unauthorized operations or information disclosure.
CVE-2026-55170 Vulnerability in github.com/openfga/openfga (CVE-2026-55170)
vulnerability in github.com/openfga/openfga (CVE-2026-55170). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.18.0` or later.
CVE-2026-54695 Vulnerability in pipecat-ai (CVE-2026-54695)
vulnerability in pipecat-ai (CVE-2026-54695). Risk of unauthorized operations or information disclosure. Exploitable via `POST /start`. Mitigation: upgrade to `1.4.0` or later.
CVE-2026-54005 Vulnerability in getkirby/cms (CVE-2026-54005)
vulnerability in getkirby/cms (CVE-2026-54005). Risk of unauthorized operations or information disclosure. Exploitable via ``pages.access``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-54004 Vulnerability in getkirby/cms (CVE-2026-54004)
vulnerability in getkirby/cms (CVE-2026-54004). Risk of unauthorized operations or information disclosure. Exploitable via ``content.fileRedirects``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-54002 Cross-Site Scripting (XSS) in getkirby/cms (CVE-2026-54002)
cross-site scripting in getkirby/cms (CVE-2026-54002). Risk of unauthorized operations or information disclosure. Exploitable via ``writer``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-50188 Vulnerability in getkirby/cms (CVE-2026-50188)
vulnerability in getkirby/cms (CVE-2026-50188). Risk of unauthorized operations or information disclosure. Exploitable via ``headers``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-49274 Vulnerability in getkirby/cms (CVE-2026-49274)
vulnerability in getkirby/cms (CVE-2026-49274). Risk of unauthorized operations or information disclosure. Exploitable via ``pages``. Mitigation: upgrade to `5.4.4` or later.
CVE-2026-44727 Cross-Site Scripting (XSS) in jupyter-server (CVE-2026-44727)
cross-site scripting in jupyter-server (CVE-2026-44727). Risk of unauthorized operations or information disclosure. Exploitable via ``nbconvert.HTMLExporter``. Mitigation: upgrade to `2.20.0` or later.
CVE-2026-12567 Vulnerability in bbot (CVE-2026-12567)
vulnerability in bbot (CVE-2026-12567). Risk of unauthorized operations or information disclosure. Exploitable via ``github_workflows``. Mitigation: upgrade to `2.8.5` or later.
CVE-2026-12568 Path Traversal in bbot (CVE-2026-12568)
path traversal in bbot (CVE-2026-12568). Data can be tampered with by attackers. Exploitable via ``postman_download``. Mitigation: upgrade to `2.8.6` or later.
CVE-2026-12566 SSRF (Server-Side Request Forgery) in bbot (CVE-2026-12566)
SSRF in bbot (CVE-2026-12566). Risk of unauthorized operations or information disclosure. Exploitable via ``docker_pull``. Mitigation: upgrade to `2.8.5` or later.
CVE-2026-12565 Path Traversal in bbot (CVE-2026-12565)
path traversal in bbot (CVE-2026-12565). Data can be tampered with by attackers. Exploitable via ``unarchive``. Mitigation: upgrade to `2.8.5` or later.
CVE-2026-55890 Cross-Site Scripting (XSS) in getgrav/grav (CVE-2026-55890)
cross-site scripting in getgrav/grav (CVE-2026-55890). Risk of unauthorized operations or information disclosure. Exploitable via ``style``. Mitigation: upgrade to `2.0.0-rc.9` or later.
CVE-2026-55885 Vulnerability in getgrav/grav (CVE-2026-55885)
vulnerability in getgrav/grav (CVE-2026-55885). Confidential information can be exposed externally. Exploitable via ``root``. Mitigation: upgrade to `1.7.53` or later.
CVE-2026-65898 Cross-Site Scripting (XSS) in dompurify (CVE-2026-65898)
cross-site scripting in dompurify (CVE-2026-65898). Risk of unauthorized operations or information disclosure. Exploitable via ``uponSanitizeAttribute``. Mitigation: upgrade to `3.4.11` or later.
CVE-2026-50141 Vulnerability in go.woodpecker-ci.org/woodpecker/v3 (CVE-2026-50141)
vulnerability in go.woodpecker-ci.org/woodpecker/v3 (CVE-2026-50141). Risk of unauthorized operations or information disclosure. Exploitable via ``agent_id``. Mitigation: upgrade to `3.14.1` or later.
CVE-2026-11958 Vulnerability in c (CVE-2026-11958)
vulnerability in c (CVE-2026-11958). Risk of unauthorized operations or information disclosure.
CVE-2026-55672 Authentication Bypass in github.com/zitadel/zitadel (CVE-2026-55672)
authentication bypass in github.com/zitadel/zitadel (CVE-2026-55672). Confidential information can be exposed externally. Mitigation: upgrade to `1.80.0-v2.20.0.20260616131956-0973b074b488` or later.
CVE-2026-55670 Vulnerability in github.com/zitadel/zitadel (CVE-2026-55670)
vulnerability in github.com/zitadel/zitadel (CVE-2026-55670). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.80.0-v2.20.0.20260615092437-6082e59d47c1` or later.
CVE-2026-55661 Cross-Site Scripting (XSS) in tinacms (CVE-2026-55661)
cross-site scripting in tinacms (CVE-2026-55661). Risk of unauthorized operations or information disclosure. Exploitable via ``url``. Mitigation: upgrade to `3.9.3` or later.
CVE-2026-55603 Vulnerability in http-proxy-middleware (CVE-2026-55603)
vulnerability in http-proxy-middleware (CVE-2026-55603). Data can be tampered with by attackers. Exploitable via ``req.body``. Mitigation: upgrade to `4.1.1` or later.
CVE-2026-55602 Vulnerability in http-proxy-middleware (CVE-2026-55602)
vulnerability in http-proxy-middleware (CVE-2026-55602). Data can be tampered with by attackers. Exploitable via ``router``. Mitigation: upgrade to `2.0.10` or later.
CVE-2026-55254 Vulnerability in NCalc.Core (CVE-2026-55254)
vulnerability in NCalc.Core (CVE-2026-55254). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.1` or later.
CVE-2026-55388 Vulnerability in piscina (CVE-2026-55388)
vulnerability in piscina (CVE-2026-55388). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload`. Mitigation: upgrade to `6.0.0-rc.2` or later.
CVE-2026-55886 Vulnerability in jodit (CVE-2026-55886)
vulnerability in jodit (CVE-2026-55886). Risk of unauthorized operations or information disclosure. Exploitable via ``chain``. Mitigation: upgrade to `4.12.26` or later.
CVE-2026-55229 SSRF (Server-Side Request Forgery) in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229)
SSRF in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229). Confidential information can be exposed externally. Exploitable via `GET /secretendpoint`. Mitigation: upgrade to `8.34.0` or later.
CVE-2026-55671 SSRF (Server-Side Request Forgery) in github.com/zitadel/zitadel (CVE-2026-55671)
SSRF in github.com/zitadel/zitadel (CVE-2026-55671). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.80.0-v2.20.0.20260615133614-8e82ec1cb9a2` or later.
CVE-2026-55746 Cross-Site Scripting (XSS) in cotonti/cotonti (CVE-2026-55746)
cross-site scripting in cotonti/cotonti (CVE-2026-55746). Confidential information can be exposed externally.
CVE-2026-55745 Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55745)
vulnerability in cotonti/cotonti (CVE-2026-55745). Risk of unauthorized operations or information disclosure.
CVE-2026-55741 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-55741)
vulnerability in csrf (CVE-2026-55741). Successful exploitation can lead to full system takeover.
CVE-2026-55744 Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55744)
vulnerability in cotonti/cotonti (CVE-2026-55744). Confidential information can be exposed externally.
CVE-2026-55742 Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55742)
vulnerability in cotonti/cotonti (CVE-2026-55742). Successful exploitation can lead to full system takeover.
CVE-2026-28573 Vulnerability in dos (CVE-2026-28573)
vulnerability in dos (CVE-2026-28573). Risk of unauthorized operations or information disclosure.
CVE-2026-11395 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-11395)
SSRF in wordpress (CVE-2026-11395). Risk of unauthorized operations or information disclosure.
CVE-2026-12111 Information Disclosure in wordpress (CVE-2026-12111)
vulnerability in wordpress (CVE-2026-12111). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →