Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12539 |
|
Vulnerability in CVE-2026-12539 (CVE-2026-12539)
vulnerability in CVE-2026-12539 (CVE-2026-12539). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12039 |
|
Vulnerability in CVE-2026-12039 (CVE-2026-12039)
vulnerability in CVE-2026-12039 (CVE-2026-12039). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40456 |
|
OS Command Injection in CVE-2026-40456 (CVE-2026-40456)
OS command injection in CVE-2026-40456 (CVE-2026-40456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42489 |
|
Vulnerability in flask (CVE-2026-42489)
vulnerability in flask (CVE-2026-42489). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42490 |
|
Vulnerability in flask (CVE-2026-42490)
vulnerability in flask (CVE-2026-42490). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42487 |
|
Vulnerability in c (CVE-2026-42487)
vulnerability in c (CVE-2026-42487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42488 |
|
Buffer Overflow in CVE-2026-42488 (CVE-2026-42488)
vulnerability in CVE-2026-42488 (CVE-2026-42488). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12527 |
|
Vulnerability in CVE-2026-12527 (CVE-2026-12527)
vulnerability in CVE-2026-12527 (CVE-2026-12527). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10560 |
|
Vulnerability in CVE-2025-10560 (CVE-2025-10560)
vulnerability in CVE-2025-10560 (CVE-2025-10560). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8039 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8039)
cross-site scripting in wordpress (CVE-2026-8039). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2021 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2021)
cross-site scripting in wordpress (CVE-2026-2021). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8811 |
|
Path Traversal in CVE-2026-8811 (CVE-2026-8811)
path traversal in CVE-2026-8811 (CVE-2026-8811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11717 |
|
Authentication Bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11717)
authentication bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11717). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-11718 |
|
Authentication Bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11718)
authentication bypass in github.com/googleapis/mcp-toolbox (CVE-2026-11718). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-50643 |
|
Out-of-Bounds Read in CVE-2026-50643 (CVE-2026-50643)
vulnerability in CVE-2026-50643 (CVE-2026-50643). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55170 |
|
Vulnerability in github.com/openfga/openfga (CVE-2026-55170)
vulnerability in github.com/openfga/openfga (CVE-2026-55170). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-54695 |
|
Vulnerability in pipecat-ai (CVE-2026-54695)
vulnerability in pipecat-ai (CVE-2026-54695). Risk of unauthorized operations or information disclosure. Exploitable via `POST /start`. Mitigation: upgrade to `1.4.0` or later.
|
| CVE-2026-54005 |
|
Vulnerability in getkirby/cms (CVE-2026-54005)
vulnerability in getkirby/cms (CVE-2026-54005). Risk of unauthorized operations or information disclosure. Exploitable via ``pages.access``. Mitigation: upgrade to `5.4.4` or later.
|
| CVE-2026-54004 |
|
Vulnerability in getkirby/cms (CVE-2026-54004)
vulnerability in getkirby/cms (CVE-2026-54004). Risk of unauthorized operations or information disclosure. Exploitable via ``content.fileRedirects``. Mitigation: upgrade to `5.4.4` or later.
|
| CVE-2026-54002 |
|
Cross-Site Scripting (XSS) in getkirby/cms (CVE-2026-54002)
cross-site scripting in getkirby/cms (CVE-2026-54002). Risk of unauthorized operations or information disclosure. Exploitable via ``writer``. Mitigation: upgrade to `5.4.4` or later.
|
| CVE-2026-50188 |
|
Vulnerability in getkirby/cms (CVE-2026-50188)
vulnerability in getkirby/cms (CVE-2026-50188). Risk of unauthorized operations or information disclosure. Exploitable via ``headers``. Mitigation: upgrade to `5.4.4` or later.
|
| CVE-2026-49274 |
|
Vulnerability in getkirby/cms (CVE-2026-49274)
vulnerability in getkirby/cms (CVE-2026-49274). Risk of unauthorized operations or information disclosure. Exploitable via ``pages``. Mitigation: upgrade to `5.4.4` or later.
|
| CVE-2026-44727 |
|
Cross-Site Scripting (XSS) in jupyter-server (CVE-2026-44727)
cross-site scripting in jupyter-server (CVE-2026-44727). Risk of unauthorized operations or information disclosure. Exploitable via ``nbconvert.HTMLExporter``. Mitigation: upgrade to `2.20.0` or later.
|
| CVE-2026-12567 |
|
Vulnerability in bbot (CVE-2026-12567)
vulnerability in bbot (CVE-2026-12567). Risk of unauthorized operations or information disclosure. Exploitable via ``github_workflows``. Mitigation: upgrade to `2.8.5` or later.
|
| CVE-2026-12568 |
|
Path Traversal in bbot (CVE-2026-12568)
path traversal in bbot (CVE-2026-12568). Data can be tampered with by attackers. Exploitable via ``postman_download``. Mitigation: upgrade to `2.8.6` or later.
|
| CVE-2026-12566 |
|
SSRF (Server-Side Request Forgery) in bbot (CVE-2026-12566)
SSRF in bbot (CVE-2026-12566). Risk of unauthorized operations or information disclosure. Exploitable via ``docker_pull``. Mitigation: upgrade to `2.8.5` or later.
|
| CVE-2026-12565 |
|
Path Traversal in bbot (CVE-2026-12565)
path traversal in bbot (CVE-2026-12565). Data can be tampered with by attackers. Exploitable via ``unarchive``. Mitigation: upgrade to `2.8.5` or later.
|
| CVE-2026-55890 |
|
Cross-Site Scripting (XSS) in getgrav/grav (CVE-2026-55890)
cross-site scripting in getgrav/grav (CVE-2026-55890). Risk of unauthorized operations or information disclosure. Exploitable via ``style``. Mitigation: upgrade to `2.0.0-rc.9` or later.
|
| CVE-2026-55885 |
|
Vulnerability in getgrav/grav (CVE-2026-55885)
vulnerability in getgrav/grav (CVE-2026-55885). Confidential information can be exposed externally. Exploitable via ``root``. Mitigation: upgrade to `1.7.53` or later.
|
| CVE-2026-65898 |
|
Cross-Site Scripting (XSS) in dompurify (CVE-2026-65898)
cross-site scripting in dompurify (CVE-2026-65898). Risk of unauthorized operations or information disclosure. Exploitable via ``uponSanitizeAttribute``. Mitigation: upgrade to `3.4.11` or later.
|
| CVE-2026-50141 |
|
Vulnerability in go.woodpecker-ci.org/woodpecker/v3 (CVE-2026-50141)
vulnerability in go.woodpecker-ci.org/woodpecker/v3 (CVE-2026-50141). Risk of unauthorized operations or information disclosure. Exploitable via ``agent_id``. Mitigation: upgrade to `3.14.1` or later.
|
| CVE-2026-11958 |
|
Vulnerability in c (CVE-2026-11958)
vulnerability in c (CVE-2026-11958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55672 |
|
Authentication Bypass in github.com/zitadel/zitadel (CVE-2026-55672)
authentication bypass in github.com/zitadel/zitadel (CVE-2026-55672). Confidential information can be exposed externally. Mitigation: upgrade to `1.80.0-v2.20.0.20260616131956-0973b074b488` or later.
|
| CVE-2026-55670 |
|
Vulnerability in github.com/zitadel/zitadel (CVE-2026-55670)
vulnerability in github.com/zitadel/zitadel (CVE-2026-55670). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.80.0-v2.20.0.20260615092437-6082e59d47c1` or later.
|
| CVE-2026-55661 |
|
Cross-Site Scripting (XSS) in tinacms (CVE-2026-55661)
cross-site scripting in tinacms (CVE-2026-55661). Risk of unauthorized operations or information disclosure. Exploitable via ``url``. Mitigation: upgrade to `3.9.3` or later.
|
| CVE-2026-55603 |
|
Vulnerability in http-proxy-middleware (CVE-2026-55603)
vulnerability in http-proxy-middleware (CVE-2026-55603). Data can be tampered with by attackers. Exploitable via ``req.body``. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-55602 |
|
Vulnerability in http-proxy-middleware (CVE-2026-55602)
vulnerability in http-proxy-middleware (CVE-2026-55602). Data can be tampered with by attackers. Exploitable via ``router``. Mitigation: upgrade to `2.0.10` or later.
|
| CVE-2026-55254 |
|
Vulnerability in NCalc.Core (CVE-2026-55254)
vulnerability in NCalc.Core (CVE-2026-55254). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.1` or later.
|
| CVE-2026-55388 |
|
Vulnerability in piscina (CVE-2026-55388)
vulnerability in piscina (CVE-2026-55388). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload`. Mitigation: upgrade to `6.0.0-rc.2` or later.
|
| CVE-2026-55886 |
|
Vulnerability in jodit (CVE-2026-55886)
vulnerability in jodit (CVE-2026-55886). Risk of unauthorized operations or information disclosure. Exploitable via ``chain``. Mitigation: upgrade to `4.12.26` or later.
|
| CVE-2026-55229 |
|
SSRF (Server-Side Request Forgery) in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229)
SSRF in github.com/gotenberg/gotenberg/v8 (CVE-2026-55229). Confidential information can be exposed externally. Exploitable via `GET /secretendpoint`. Mitigation: upgrade to `8.34.0` or later.
|
| CVE-2026-55671 |
|
SSRF (Server-Side Request Forgery) in github.com/zitadel/zitadel (CVE-2026-55671)
SSRF in github.com/zitadel/zitadel (CVE-2026-55671). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.80.0-v2.20.0.20260615133614-8e82ec1cb9a2` or later.
|
| CVE-2026-55746 |
|
Cross-Site Scripting (XSS) in cotonti/cotonti (CVE-2026-55746)
cross-site scripting in cotonti/cotonti (CVE-2026-55746). Confidential information can be exposed externally.
|
| CVE-2026-55745 |
|
Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55745)
vulnerability in cotonti/cotonti (CVE-2026-55745). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55741 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-55741)
vulnerability in csrf (CVE-2026-55741). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55744 |
|
Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55744)
vulnerability in cotonti/cotonti (CVE-2026-55744). Confidential information can be exposed externally.
|
| CVE-2026-55742 |
|
Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55742)
vulnerability in cotonti/cotonti (CVE-2026-55742). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28573 |
|
Vulnerability in dos (CVE-2026-28573)
vulnerability in dos (CVE-2026-28573). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11395 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-11395)
SSRF in wordpress (CVE-2026-11395). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12111 |
|
Information Disclosure in wordpress (CVE-2026-12111)
vulnerability in wordpress (CVE-2026-12111). Risk of unauthorized operations or information disclosure.
|