Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-57242 |
|
Use-After-Free in foxit (CVE-2026-57242)
vulnerability in foxit (CVE-2026-57242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57243 |
|
Out-of-Bounds Read in foxit (CVE-2026-57243)
vulnerability in foxit (CVE-2026-57243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57244 |
|
Use-After-Free in foxit (CVE-2026-57244)
vulnerability in foxit (CVE-2026-57244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57245 |
|
Use-After-Free in foxit (CVE-2026-57245)
vulnerability in foxit (CVE-2026-57245). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57246 |
|
Vulnerability in foxit (CVE-2026-57246)
vulnerability in foxit (CVE-2026-57246). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57247 |
|
Use-After-Free in foxit (CVE-2026-57247)
vulnerability in foxit (CVE-2026-57247). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57248 |
|
Vulnerability in foxit (CVE-2026-57248)
vulnerability in foxit (CVE-2026-57248). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57249 |
|
Use-After-Free in foxit (CVE-2026-57249)
vulnerability in foxit (CVE-2026-57249). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57237 |
|
Use-After-Free in foxit (CVE-2026-57237)
vulnerability in foxit (CVE-2026-57237). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57238 |
|
Use-After-Free in foxit (CVE-2026-57238)
vulnerability in foxit (CVE-2026-57238). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57239 |
|
Vulnerability in foxit (CVE-2026-57239)
vulnerability in foxit (CVE-2026-57239). Confidential information can be exposed externally.
|
| CVE-2026-57240 |
|
Use-After-Free in foxit (CVE-2026-57240)
vulnerability in foxit (CVE-2026-57240). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13126 |
|
Use-After-Free in foxit (CVE-2026-13126)
vulnerability in foxit (CVE-2026-13126). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13127 |
|
Use-After-Free in foxit (CVE-2026-13127)
vulnerability in foxit (CVE-2026-13127). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13128 |
|
Use-After-Free in foxit (CVE-2026-13128)
vulnerability in foxit (CVE-2026-13128). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13129 |
|
Use-After-Free in foxit (CVE-2026-13129)
vulnerability in foxit (CVE-2026-13129). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12378 |
|
Vulnerability in wordpress (CVE-2026-12378)
vulnerability in wordpress (CVE-2026-12378). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9701 |
|
Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
|
| CVE-2026-14487 |
|
Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
|
| CVE-2026-28378 |
|
Vulnerability in grafana (CVE-2026-28378)
vulnerability in grafana (CVE-2026-28378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48954 |
|
Improper validation leads to a generic XSS vector in the language override feature.
Improper validation leads to a generic XSS vector in the language override feature.
|
| CVE-2026-48955 |
|
Vulnerability in joomla (CVE-2026-48955)
vulnerability in joomla (CVE-2026-48955). Confidential information can be exposed externally.
|
| CVE-2026-48956 |
|
An improper access check allows users to display a list of modules in the frontend.
An improper access check allows users to display a list of modules in the frontend.
|
| CVE-2026-48957 |
|
An improper access check allows unauthorized users to access com_privacy datasets.
An improper access check allows unauthorized users to access com_privacy datasets.
|
| CVE-2026-48958 |
|
Vulnerability in joomla (CVE-2026-48958)
vulnerability in joomla (CVE-2026-48958). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48950 |
|
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
|
| CVE-2026-48949 |
|
Lack of validation leads to an XSS vulnerability in the MFA management views.
Lack of validation leads to an XSS vulnerability in the MFA management views.
|
| CVE-2026-48951 |
|
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
|
| CVE-2026-48952 |
|
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
|
| CVE-2026-48953 |
|
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
|
| CVE-2026-48948 |
|
Vulnerability in joomla (CVE-2026-48948)
vulnerability in joomla (CVE-2026-48948). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48947 |
|
Vulnerability in joomla (CVE-2026-48947)
vulnerability in joomla (CVE-2026-48947). Data can be tampered with by attackers.
|
| CVE-2026-23698 |
|
Unrestricted File Upload in apache (CVE-2026-23698)
vulnerability in apache (CVE-2026-23698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23697 |
|
Unrestricted File Upload in apache (CVE-2026-23697)
vulnerability in apache (CVE-2026-23697). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13019 |
|
Vulnerability in esri (CVE-2026-13019)
vulnerability in esri (CVE-2026-13019). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13020 |
|
Vulnerability in esri (CVE-2026-13020)
vulnerability in esri (CVE-2026-13020). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6101 |
|
Vulnerability in wordpress (CVE-2026-6101)
vulnerability in wordpress (CVE-2026-6101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40187 |
|
OS Command Injection in egroupware/egroupware (CVE-2026-40187)
OS command injection in egroupware/egroupware (CVE-2026-40187). Risk of unauthorized operations or information disclosure. Exploitable via ``chgrp``. Mitigation: upgrade to `23.1.20260601` or later.
|
| CVE-2026-48828 |
|
Information Disclosure in apache (CVE-2026-48828)
vulnerability in apache (CVE-2026-48828). Confidential information can be exposed externally. Exploitable via ``should_hide_value_for_key``.
|
| CVE-2026-48891 |
|
Information Disclosure in apache (CVE-2026-48891)
vulnerability in apache (CVE-2026-48891). Risk of unauthorized operations or information disclosure. Exploitable via ``dep.source``.
|
| CVE-2026-48892 |
|
Information Disclosure in apache (CVE-2026-48892)
vulnerability in apache (CVE-2026-48892). Confidential information can be exposed externally. Exploitable via ``sensitive_config_values``.
|
| CVE-2026-49296 |
|
Vulnerability in apache-airflow (CVE-2026-49296)
vulnerability in apache-airflow (CVE-2026-49296). Confidential information can be exposed externally. Exploitable via `GET /api/v2/dagSources/{dag_id}`. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-49487 |
|
Information Disclosure in apache (CVE-2026-49487)
vulnerability in apache (CVE-2026-49487). Confidential information can be exposed externally.
|
| CVE-2026-33264 |
|
Unsafe Deserialization in apache (CVE-2026-33264)
vulnerability in apache (CVE-2026-33264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12277 |
|
Vulnerability in wordpress (CVE-2026-12277)
vulnerability in wordpress (CVE-2026-12277). Data can be tampered with by attackers.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42200 |
|
Path Traversal in CVE-2026-42200 (CVE-2026-42200)
path traversal in CVE-2026-42200 (CVE-2026-42200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42145 |
|
Unrestricted File Upload in CVE-2026-42145 (CVE-2026-42145)
vulnerability in CVE-2026-42145 (CVE-2026-42145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34057 |
|
OS Command Injection in CVE-2026-34057 (CVE-2026-34057)
OS command injection in CVE-2026-34057 (CVE-2026-34057). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34037 |
|
Vulnerability in CVE-2026-34037 (CVE-2026-34037)
vulnerability in CVE-2026-34037 (CVE-2026-34037). Confidential information can be exposed externally.
|