Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39967 |
|
Vulnerability in CVE-2026-39967 (CVE-2026-39967)
vulnerability in CVE-2026-39967 (CVE-2026-39967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39966 |
|
Authorization Flaw in CVE-2026-39966 (CVE-2026-39966)
vulnerability in CVE-2026-39966 (CVE-2026-39966). Confidential information can be exposed externally.
|
| CVE-2026-39969 |
|
Authentication Bypass in CVE-2026-39969 (CVE-2026-39969)
authentication bypass in CVE-2026-39969 (CVE-2026-39969). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook`.
|
| CVE-2026-39968 |
|
Vulnerability in CVE-2026-39968 (CVE-2026-39968)
vulnerability in CVE-2026-39968 (CVE-2026-39968). Confidential information can be exposed externally.
|
| CVE-2026-39970 |
|
Cross-Site Scripting (XSS) in CVE-2026-39970 (CVE-2026-39970)
cross-site scripting in CVE-2026-39970 (CVE-2026-39970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39824 |
|
Vulnerability in golang.org/x/sys (CVE-2026-39824)
vulnerability in golang.org/x/sys (CVE-2026-39824). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.44.0` or later.
|
| CVE-2026-39965 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39965)
SSRF in ssrf (CVE-2026-39965). Confidential information can be exposed externally.
|
| CVE-2026-46715 |
|
Authentication Bypass in Flask-Security-Too (CVE-2026-46715)
authentication bypass in Flask-Security-Too (CVE-2026-46715). Risk of unauthorized operations or information disclosure. Exploitable via `POST /change-username`. Mitigation: upgrade to `5.8.1` or later.
|
| CVE-2026-9255 |
|
Vulnerability in Amazon aws (CVE-2026-9255)
vulnerability in Amazon aws (CVE-2026-9255). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70646 |
|
Vulnerability in aiosend (CVE-2026-70646)
vulnerability in aiosend (CVE-2026-70646). Risk of unauthorized operations or information disclosure. Exploitable via ``aiosend``. Mitigation: upgrade to `3.0.7` or later.
|
| CVE-2026-48777 |
|
Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-48777)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-48777). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /public/api/resources`. Mitigation: upgrade to `0.0.0-20260518193514-28e9b81e438e` or later.
|
| CVE-2026-33712 |
|
Vulnerability in ssrf (CVE-2026-33712)
vulnerability in ssrf (CVE-2026-33712). Confidential information can be exposed externally. Exploitable via `POST /api/v1/typebots/{typebotId}/preview/startChat`.
|
| CVE-2026-32253 |
|
Authentication Bypass in cpp (CVE-2026-32253)
authentication bypass in cpp (CVE-2026-32253). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34207 |
|
Vulnerability in ssrf (CVE-2026-34207)
vulnerability in ssrf (CVE-2026-34207). Confidential information can be exposed externally.
|
| CVE-2026-46670 |
|
SQL Injection in yeswiki/yeswiki (CVE-2026-46670)
SQL injection in yeswiki/yeswiki (CVE-2026-46670). Successful exploitation can lead to full system takeover. Exploitable via ``INSERT``. Mitigation: upgrade to `4.6.4` or later.
|
| CVE-2026-47166 |
|
Out-of-Bounds Read in Magick.NET-Q16-AnyCPU (CVE-2026-47166)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-47166). Confidential information can be exposed externally. Mitigation: upgrade to `14.12.0` or later.
|
| CVE-2026-47165 |
|
Information Disclosure in Magick.NET-Q16-AnyCPU (CVE-2026-47165)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-47165). Confidential information can be exposed externally. Mitigation: upgrade to `14.12.0` or later.
|
| CVE-2026-46693 |
|
Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-46693)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-46693). Confidential information can be exposed externally. Mitigation: upgrade to `14.12.0` or later.
|
| CVE-2026-46692 |
|
Vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-46692)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-46692). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.12.0` or later.
|
| CVE-2026-25606 |
|
SQL Injection in sqli (CVE-2026-25606)
SQL injection in sqli (CVE-2026-25606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7636 |
|
Information Disclosure in wordpress (CVE-2026-7636)
vulnerability in wordpress (CVE-2026-7636). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7615 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-7615)
vulnerability in wordpress (CVE-2026-7615). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8381 |
|
Vulnerability in CVE-2026-8381 (CVE-2026-8381)
vulnerability in CVE-2026-8381 (CVE-2026-8381). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8684 |
|
Vulnerability in wordpress (CVE-2026-8684)
vulnerability in wordpress (CVE-2026-8684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8692 |
|
Vulnerability in wordpress (CVE-2026-8692)
vulnerability in wordpress (CVE-2026-8692). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9011 |
|
Vulnerability in wordpress (CVE-2026-9011)
vulnerability in wordpress (CVE-2026-9011). Confidential information can be exposed externally.
|
| CVE-2026-7798 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-7798)
SSRF in wordpress (CVE-2026-7798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5072 |
|
Vulnerability in c (CVE-2026-5072)
vulnerability in c (CVE-2026-5072). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9104 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9104)
cross-site scripting in wordpress (CVE-2026-9104). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9018 |
|
Privilege Escalation in wordpress (CVE-2026-9018)
vulnerability in wordpress (CVE-2026-9018). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_eel_register``.
|
| CVE-2026-4070 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-4070)
vulnerability in wordpress (CVE-2026-4070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7249 |
|
Vulnerability in wordpress (CVE-2026-7249)
vulnerability in wordpress (CVE-2026-7249). Risk of unauthorized operations or information disclosure. Exploitable via ``init``.
|
| CVE-2026-6864 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6864)
cross-site scripting in wordpress (CVE-2026-6864). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7509 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7509)
cross-site scripting in wordpress (CVE-2026-7509). Risk of unauthorized operations or information disclosure. Exploitable via ``before``.
|
| CVE-2026-44409 |
|
Information Disclosure in zte (CVE-2026-44409)
vulnerability in zte (CVE-2026-44409). Confidential information can be exposed externally.
|
| CVE-2026-3481 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3481)
cross-site scripting in wordpress (CVE-2026-3481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2518 |
|
Vulnerability in wordpress (CVE-2026-2518)
vulnerability in wordpress (CVE-2026-2518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9054 |
|
Vulnerability in CVE-2026-9054 (CVE-2026-9054)
vulnerability in CVE-2026-9054 (CVE-2026-9054). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9053 |
|
Unrestricted File Upload in CVE-2026-9053 (CVE-2026-9053)
vulnerability in CVE-2026-9053 (CVE-2026-9053). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46597 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-46597)
vulnerability in golang.org/x/crypto (CVE-2026-46597). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-4834 |
|
SQL Injection in wordpress (CVE-2026-4834)
SQL injection in wordpress (CVE-2026-4834). Confidential information can be exposed externally.
|
| CVE-2026-42508 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-42508)
vulnerability in golang.org/x/crypto (CVE-2026-42508). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-46595 |
|
Authorization Flaw in golang.org/x/crypto (CVE-2026-46595)
vulnerability in golang.org/x/crypto (CVE-2026-46595). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39834 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39834)
vulnerability in golang.org/x/crypto (CVE-2026-39834). Data can be tampered with by attackers. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39835 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39835)
vulnerability in golang.org/x/crypto (CVE-2026-39835). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39831 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39831)
vulnerability in golang.org/x/crypto (CVE-2026-39831). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39833 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39833)
vulnerability in golang.org/x/crypto (CVE-2026-39833). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39832 |
|
Unsafe Deserialization in golang.org/x/crypto (CVE-2026-39832)
vulnerability in golang.org/x/crypto (CVE-2026-39832). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39828 |
|
Vulnerability in golang.org/x/crypto (CVE-2026-39828)
vulnerability in golang.org/x/crypto (CVE-2026-39828). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.52.0` or later.
|
| CVE-2026-39830 |
|
Buffer Overflow in golang.org/x/crypto (CVE-2026-39830)
vulnerability in golang.org/x/crypto (CVE-2026-39830). Confidential information can be exposed externally. Mitigation: upgrade to `0.52.0` or later.
|