Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-41042 |
|
Vulnerability in apache (CVE-2026-41042)
vulnerability in apache (CVE-2026-41042). Confidential information can be exposed externally.
|
| CVE-2026-9701 |
|
Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
|
| CVE-2026-14487 |
|
Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
|
| CVE-2026-56843 |
|
Vulnerability in c (CVE-2026-56843)
vulnerability in c (CVE-2026-56843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14740 |
|
Out-of-Bounds Read in perl (CVE-2026-14740)
vulnerability in perl (CVE-2026-14740). Confidential information can be exposed externally.
|
| CVE-2026-14739 |
|
Out-of-Bounds Write in perl (CVE-2026-14739)
out-of-bounds write in perl (CVE-2026-14739). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34037 |
|
Vulnerability in CVE-2026-34037 (CVE-2026-34037)
vulnerability in CVE-2026-34037 (CVE-2026-34037). Confidential information can be exposed externally.
|
| CVE-2026-54496 |
|
Vulnerability in zebrad (CVE-2026-54496)
vulnerability in zebrad (CVE-2026-54496). Data can be tampered with by attackers. Exploitable via ``halo2_gadgets``. Mitigation: upgrade to `5.0.0` or later.
|
| CVE-2026-54769 |
|
Code Injection in langroid (CVE-2026-54769)
code injection in langroid (CVE-2026-54769). Successful exploitation can lead to full system takeover. Exploitable via ``TableChatAgent``. Mitigation: upgrade to `0.65.2` or later.
|
| CVE-2026-53486 |
|
Path Traversal in @xhmikosr/decompress (CVE-2026-53486)
path traversal in @xhmikosr/decompress (CVE-2026-53486). Confidential information can be exposed externally. Exploitable via ``path.relative``. Mitigation: upgrade to `11.1.3` or later.
|
| CVE-2026-40047 |
|
Vulnerability in org.apache.camel:camel-docling (CVE-2026-40047)
vulnerability in org.apache.camel:camel-docling (CVE-2026-40047). Confidential information can be exposed externally. Exploitable via ``docling``. Mitigation: upgrade to `4.18.3` or later.
|
| CVE-2026-43867 |
|
Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-43867)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-43867). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-6382 |
|
Vulnerability in wordpress (CVE-2026-6382)
vulnerability in wordpress (CVE-2026-6382). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47898 |
|
XXE (XML External Entity) in csharp (CVE-2026-47898)
vulnerability in csharp (CVE-2026-47898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9725 |
|
Path Traversal in wordpress (CVE-2026-9725)
path traversal in wordpress (CVE-2026-9725). Data can be tampered with by attackers.
|
| CVE-2026-38971 |
|
Out-of-Bounds Read in cpp (CVE-2026-38971)
vulnerability in cpp (CVE-2026-38971). Confidential information can be exposed externally.
|
| CVE-2026-38968 |
|
Vulnerability in cpp (CVE-2026-38968)
vulnerability in cpp (CVE-2026-38968). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49352 |
|
Vulnerability in 9router (CVE-2026-49352)
vulnerability in 9router (CVE-2026-49352). Successful exploitation can lead to full system takeover. Exploitable via ``JWT_SECRET``. Mitigation: upgrade to `0.4.45` or later.
|
| CVE-2026-58455 |
|
OS Command Injection in CVE-2026-58455 (CVE-2026-58455)
OS command injection in CVE-2026-58455 (CVE-2026-58455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5524 |
|
Unrestricted File Upload in wordpress (CVE-2026-5524)
vulnerability in wordpress (CVE-2026-5524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57677 |
|
Unsafe Deserialization in CVE-2026-57677 (CVE-2026-57677)
vulnerability in CVE-2026-57677 (CVE-2026-57677). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57621 |
|
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.
|
| CVE-2026-34115 |
|
OS Command Injection in CVE-2026-34115 (CVE-2026-34115)
OS command injection in CVE-2026-34115 (CVE-2026-34115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34116 |
|
OS Command Injection in CVE-2026-34116 (CVE-2026-34116)
OS command injection in CVE-2026-34116 (CVE-2026-34116). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34111 |
|
OS Command Injection in CVE-2026-34111 (CVE-2026-34111)
OS command injection in CVE-2026-34111 (CVE-2026-34111). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34108 |
|
OS Command Injection in CVE-2026-34108 (CVE-2026-34108)
OS command injection in CVE-2026-34108 (CVE-2026-34108). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34113 |
|
OS Command Injection in CVE-2026-34113 (CVE-2026-34113)
OS command injection in CVE-2026-34113 (CVE-2026-34113). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34112 |
|
OS Command Injection in CVE-2026-34112 (CVE-2026-34112)
OS command injection in CVE-2026-34112 (CVE-2026-34112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34114 |
|
OS Command Injection in CVE-2026-34114 (CVE-2026-34114)
OS command injection in CVE-2026-34114 (CVE-2026-34114). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34117 |
|
OS Command Injection in CVE-2026-34117 (CVE-2026-34117)
OS command injection in CVE-2026-34117 (CVE-2026-34117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34110 |
|
OS Command Injection in CVE-2026-34110 (CVE-2026-34110)
OS command injection in CVE-2026-34110 (CVE-2026-34110). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34107 |
|
OS Command Injection in CVE-2026-34107 (CVE-2026-34107)
OS command injection in CVE-2026-34107 (CVE-2026-34107). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34106 |
|
OS Command Injection in CVE-2026-34106 (CVE-2026-34106)
OS command injection in CVE-2026-34106 (CVE-2026-34106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34109 |
|
OS Command Injection in CVE-2026-34109 (CVE-2026-34109)
OS command injection in CVE-2026-34109 (CVE-2026-34109). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34099 |
|
SQL Injection in sqli (CVE-2026-34099)
SQL injection in sqli (CVE-2026-34099). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58126 |
|
Vulnerability in csharp (CVE-2026-58126)
vulnerability in csharp (CVE-2026-58126). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58127 |
|
Vulnerability in csharp (CVE-2026-58127)
vulnerability in csharp (CVE-2026-58127). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57517 |
|
SQL Injection in sqli (CVE-2026-57517)
SQL injection in sqli (CVE-2026-57517). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58025 |
|
Code Injection in deserialization (CVE-2026-58025)
code injection in deserialization (CVE-2026-58025). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6070 |
|
Vulnerability in wordpress (CVE-2026-6070)
vulnerability in wordpress (CVE-2026-6070). Data can be tampered with by attackers.
|
| CVE-2026-7840 |
|
Out-of-Bounds Write in c (CVE-2026-7840)
out-of-bounds write in c (CVE-2026-7840). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7839 |
|
Vulnerability in c (CVE-2026-7839)
vulnerability in c (CVE-2026-7839). Confidential information can be exposed externally.
|
| CVE-2026-56700 |
|
OS Command Injection in CVE-2026-56700 (CVE-2026-56700)
OS command injection in CVE-2026-56700 (CVE-2026-56700). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-13782 |
|
Use-After-Free in c (CVE-2026-13782)
vulnerability in c (CVE-2026-13782). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50003 |
|
Path Traversal in c (CVE-2026-50003)
path traversal in c (CVE-2026-50003). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37106 |
|
Vulnerability in CVE-2026-37106 (CVE-2026-37106)
vulnerability in CVE-2026-37106 (CVE-2026-37106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58138 |
|
Code Injection in CVE-2026-58138 (CVE-2026-58138)
code injection in CVE-2026-58138 (CVE-2026-58138). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48807 |
|
Vulnerability in twig/twig (CVE-2026-48807)
vulnerability in twig/twig (CVE-2026-48807). Confidential information can be exposed externally. Exploitable via ``Traversable``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48806 |
|
Vulnerability in twig/twig (CVE-2026-48806)
vulnerability in twig/twig (CVE-2026-48806). Confidential information can be exposed externally. Exploitable via ``CheckToStringNode``. Mitigation: upgrade to `3.27.0` or later.
|