Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-8927 |
|
Vulnerability in haxx (CVE-2026-8927)
vulnerability in haxx (CVE-2026-8927). Confidential information can be exposed externally. Exploitable via ``proxyA``.
|
| CVE-2026-8925 |
|
Vulnerability in haxx (CVE-2026-8925)
vulnerability in haxx (CVE-2026-8925). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11564 |
|
Vulnerability in haxx (CVE-2026-11564)
vulnerability in haxx (CVE-2026-11564). Confidential information can be exposed externally.
|
| CVE-2026-11856 |
|
Vulnerability in haxx (CVE-2026-11856)
vulnerability in haxx (CVE-2026-11856). Successful exploitation can lead to full system takeover. Exploitable via ``hostA``.
|
| CVE-2026-10536 |
|
Use-After-Free in haxx (CVE-2026-10536)
vulnerability in haxx (CVE-2026-10536). Successful exploitation can lead to full system takeover. Exploitable via ``CURLOPT_STREAM_DEPENDS``.
|
| CVE-2026-9725 |
|
Path Traversal in wordpress (CVE-2026-9725)
path traversal in wordpress (CVE-2026-9725). Data can be tampered with by attackers.
|
| CVE-2026-13768 |
|
Vulnerability in CVE-2026-13768 (CVE-2026-13768)
vulnerability in CVE-2026-13768 (CVE-2026-13768). Confidential information can be exposed externally.
|
| CVE-2026-57100 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57100)
SSRF in ssrf (CVE-2026-57100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45499 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45499)
SSRF in ssrf (CVE-2026-45499). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41106 |
|
Open Redirect in microsoft (CVE-2026-41106)
vulnerability in microsoft (CVE-2026-41106). Confidential information can be exposed externally.
|
| CVE-2026-38971 |
|
Out-of-Bounds Read in cpp (CVE-2026-38971)
vulnerability in cpp (CVE-2026-38971). Confidential information can be exposed externally.
|
| CVE-2026-49352 |
|
Vulnerability in 9router (CVE-2026-49352)
vulnerability in 9router (CVE-2026-49352). Successful exploitation can lead to full system takeover. Exploitable via ``JWT_SECRET``. Mitigation: upgrade to `0.4.45` or later.
|
| CVE-2026-52830 |
|
Path Traversal in fast-mcp-telegram (CVE-2026-52830)
path traversal in fast-mcp-telegram (CVE-2026-52830). Confidential information can be exposed externally. Exploitable via ``telegram``. Mitigation: upgrade to `0.19.1` or later.
|
| CVE-2026-59800 |
|
OS Command Injection in 9router (CVE-2026-59800)
OS command injection in 9router (CVE-2026-59800). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/tunnel/tailscale-install`. Mitigation: upgrade to `0.4.44` or later.
|
| CVE-2024-14037 |
|
Unrestricted File Upload in CVE-2024-14037 (CVE-2024-14037)
vulnerability in CVE-2024-14037 (CVE-2024-14037). Successful exploitation can lead to full system takeover.
|
| CVE-2022-50973 |
|
Unrestricted File Upload in CVE-2022-50973 (CVE-2022-50973)
vulnerability in CVE-2022-50973 (CVE-2022-50973). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58455 |
|
OS Command Injection in CVE-2026-58455 (CVE-2026-58455)
OS command injection in CVE-2026-58455 (CVE-2026-58455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55116 |
|
Vulnerability in ui (CVE-2026-55116)
vulnerability in ui (CVE-2026-55116). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56004 |
|
OS Command Injection in CVE-2026-56004 (CVE-2026-56004)
OS command injection in CVE-2026-56004 (CVE-2026-56004). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55115 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55115)
SSRF in ssrf (CVE-2026-55115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50746 |
|
Vulnerability in ui (CVE-2026-50746)
vulnerability in ui (CVE-2026-50746). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54400 |
|
Vulnerability in ui (CVE-2026-54400)
vulnerability in ui (CVE-2026-54400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4767 |
|
Vulnerability in CVE-2026-4767 (CVE-2026-4767)
vulnerability in CVE-2026-4767 (CVE-2026-4767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50748 |
|
Vulnerability in ui (CVE-2026-50748)
vulnerability in ui (CVE-2026-50748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54402 |
|
Vulnerability in ui (CVE-2026-54402)
vulnerability in ui (CVE-2026-54402). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5524 |
|
Unrestricted File Upload in wordpress (CVE-2026-5524)
vulnerability in wordpress (CVE-2026-5524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50747 |
|
SQL Injection in sqli (CVE-2026-50747)
SQL injection in sqli (CVE-2026-50747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50027 |
|
Vulnerability in mcp-memory-service (CVE-2026-50027)
vulnerability in mcp-memory-service (CVE-2026-50027). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload`. Mitigation: upgrade to `10.67.1` or later.
|
| CVE-2026-57683 |
|
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
|
| CVE-2026-57624 |
|
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
|
| CVE-2026-57625 |
|
Cross-Site Scripting (XSS) in CVE-2026-57625 (CVE-2026-57625)
cross-site scripting in CVE-2026-57625 (CVE-2026-57625). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57679 |
|
Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.
|
| CVE-2026-57677 |
|
Unsafe Deserialization in CVE-2026-57677 (CVE-2026-57677)
vulnerability in CVE-2026-57677 (CVE-2026-57677). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57621 |
|
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
|
| CVE-2026-27419 |
|
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.
|
| CVE-2026-27436 |
|
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.
|
| CVE-2026-14417 |
|
Use-After-Free in google (CVE-2026-14417)
vulnerability in google (CVE-2026-14417). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14425 |
|
Use-After-Free in google (CVE-2026-14425)
vulnerability in google (CVE-2026-14425). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14419 |
|
Use-After-Free in google (CVE-2026-14419)
vulnerability in google (CVE-2026-14419). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14424 |
|
Use-After-Free in google (CVE-2026-14424)
vulnerability in google (CVE-2026-14424). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14423 |
|
Vulnerability in google (CVE-2026-14423)
vulnerability in google (CVE-2026-14423). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14420 |
|
Out-of-Bounds Read in google (CVE-2026-14420)
vulnerability in google (CVE-2026-14420). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14416 |
|
Out-of-Bounds Read in google (CVE-2026-14416)
vulnerability in google (CVE-2026-14416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14387 |
|
Vulnerability in google (CVE-2026-14387)
vulnerability in google (CVE-2026-14387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14397 |
|
Out-of-Bounds Write in google (CVE-2026-14397)
out-of-bounds write in google (CVE-2026-14397). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14390 |
|
Use-After-Free in google (CVE-2026-14390)
vulnerability in google (CVE-2026-14390). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14411 |
|
Vulnerability in google (CVE-2026-14411)
vulnerability in google (CVE-2026-14411). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14392 |
|
Out-of-Bounds Write in google (CVE-2026-14392)
out-of-bounds write in google (CVE-2026-14392). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14398 |
|
Use-After-Free in google (CVE-2026-14398)
vulnerability in google (CVE-2026-14398). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14382 |
|
Vulnerability in google (CVE-2026-14382)
vulnerability in google (CVE-2026-14382). Successful exploitation can lead to full system takeover.
|