Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48944 |
|
Path Traversal in joomlaworks (CVE-2026-48944)
path traversal in joomlaworks (CVE-2026-48944). Confidential information can be exposed externally. Exploitable via ``configuration.php``.
|
| CVE-2026-48946 |
|
Unrestricted File Upload in apache (CVE-2026-48946)
vulnerability in apache (CVE-2026-48946). Risk of unauthorized operations or information disclosure. Exploitable via ``shell.php``.
|
| CVE-2026-48945 |
|
Unrestricted File Upload in joomlaworks (CVE-2026-48945)
vulnerability in joomlaworks (CVE-2026-48945). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54448 |
|
Vulnerability in github.com/aquasecurity/trivy (CVE-2026-54448)
vulnerability in github.com/aquasecurity/trivy (CVE-2026-54448). Risk of unauthorized operations or information disclosure. Exploitable via ``archive.LoadArchiveFiles``. Mitigation: upgrade to `0.71.0` or later.
|
| CVE-2026-55092 |
|
Path Traversal in github.com/aquasecurity/trivy (CVE-2026-55092)
path traversal in github.com/aquasecurity/trivy (CVE-2026-55092). Data can be tampered with by attackers. Exploitable via ``org.opencontainers.image.title``. Mitigation: upgrade to `0.71.1` or later.
|
| CVE-2026-56053 |
|
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
|
| CVE-2026-56091 |
|
Vulnerability in apache (CVE-2026-56091)
vulnerability in apache (CVE-2026-56091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56130 |
|
Vulnerability in apache (CVE-2026-56130)
vulnerability in apache (CVE-2026-56130). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54226 |
|
Vulnerability in apache (CVE-2026-54226)
vulnerability in apache (CVE-2026-54226). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46751 |
|
Vulnerability in apache (CVE-2026-46751)
vulnerability in apache (CVE-2026-46751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46752 |
|
Vulnerability in apache (CVE-2026-46752)
vulnerability in apache (CVE-2026-46752). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41566 |
|
Vulnerability in apache (CVE-2026-41566)
vulnerability in apache (CVE-2026-41566). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45188 |
|
Vulnerability in apache (CVE-2026-45188)
vulnerability in apache (CVE-2026-45188). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5952 |
|
Authorization Flaw in gitlab (CVE-2026-5952)
vulnerability in gitlab (CVE-2026-5952). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-5309 |
|
Vulnerability in gitlab (CVE-2026-5309)
vulnerability in gitlab (CVE-2026-5309). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-2238 |
|
Vulnerability in gitlab (CVE-2026-2238)
vulnerability in gitlab (CVE-2026-2238). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-3176 |
|
Vulnerability in gitlab (CVE-2026-3176)
vulnerability in gitlab (CVE-2026-3176). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-8330 |
|
Vulnerability in gitlab (CVE-2026-8330)
vulnerability in gitlab (CVE-2026-8330). Confidential information can be exposed externally. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-5796 |
|
Authorization Flaw in gitlab (CVE-2026-5796)
vulnerability in gitlab (CVE-2026-5796). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-10086 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2026-10086)
cross-site scripting in gitlab (CVE-2026-10086). Confidential information can be exposed externally. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-1606 |
|
Code Injection in gitlab (CVE-2026-1606)
code injection in gitlab (CVE-2026-1606). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-12635 |
|
Vulnerability in gitlab (CVE-2026-12635)
vulnerability in gitlab (CVE-2026-12635). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-11379 |
|
Authorization Flaw in gitlab (CVE-2026-11379)
vulnerability in gitlab (CVE-2026-11379). Confidential information can be exposed externally. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-12053 |
|
Vulnerability in gitlab (CVE-2026-12053)
vulnerability in gitlab (CVE-2026-12053). Confidential information can be exposed externally. Mitigation: upgrade to `19.1.1` or later.
|
| CVE-2026-0934 |
|
Authorization Flaw in gitlab (CVE-2026-0934)
vulnerability in gitlab (CVE-2026-0934). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-10712 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2026-10712)
cross-site scripting in gitlab (CVE-2026-10712). Confidential information can be exposed externally. Mitigation: upgrade to `18.11.6, 19.0.3, 19.1.1` or later.
|
| CVE-2026-9772 |
|
OS Command Injection in unraid (CVE-2026-9772)
OS command injection in unraid (CVE-2026-9772). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9773 |
|
OS Command Injection in unraid (CVE-2026-9773)
OS command injection in unraid (CVE-2026-9773). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47110 |
|
Vulnerability in dos (CVE-2026-47110)
vulnerability in dos (CVE-2026-47110). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40079 |
|
OS Command Injection in cacti (CVE-2026-40079)
OS command injection in cacti (CVE-2026-40079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39951 |
|
SQL Injection in sqli (CVE-2026-39951)
SQL injection in sqli (CVE-2026-39951). Confidential information can be exposed externally.
|
| CVE-2026-39938 |
|
Path Traversal in cacti (CVE-2026-39938)
path traversal in cacti (CVE-2026-39938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39955 |
|
SQL Injection in sqli (CVE-2026-39955)
SQL injection in sqli (CVE-2026-39955). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39948 |
|
SQL Injection in cacti (CVE-2026-39948)
SQL injection in cacti (CVE-2026-39948). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39900 |
|
Cross-Site Scripting (XSS) in cacti (CVE-2026-39900)
cross-site scripting in cacti (CVE-2026-39900). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39899 |
|
Path Traversal in path-traversal (CVE-2026-39899)
path traversal in path-traversal (CVE-2026-39899). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52794 |
|
Vulnerability in dos (CVE-2026-52794)
vulnerability in dos (CVE-2026-52794). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.5.2` or later.
|
| CVE-2026-39893 |
|
SQL Injection in sqli (CVE-2026-39893)
SQL injection in sqli (CVE-2026-39893). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39897 |
|
Cross-Site Scripting (XSS) in cacti (CVE-2026-39897)
cross-site scripting in cacti (CVE-2026-39897). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39894 |
|
Vulnerability in cacti (CVE-2026-39894)
vulnerability in cacti (CVE-2026-39894). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13035 |
|
Use-After-Free in google (CVE-2026-13035)
vulnerability in google (CVE-2026-13035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13034 |
|
Vulnerability in google (CVE-2026-13034)
vulnerability in google (CVE-2026-13034). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13038 |
|
Use-After-Free in google (CVE-2026-13038)
vulnerability in google (CVE-2026-13038). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13036 |
|
Use-After-Free in google (CVE-2026-13036)
vulnerability in google (CVE-2026-13036). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13033 |
|
Out-of-Bounds Read in google (CVE-2026-13033)
vulnerability in google (CVE-2026-13033). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13032 |
|
Use-After-Free in google (CVE-2026-13032)
vulnerability in google (CVE-2026-13032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13037 |
|
Use-After-Free in google (CVE-2026-13037)
vulnerability in google (CVE-2026-13037). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13026 |
|
Use-After-Free in google (CVE-2026-13026)
vulnerability in google (CVE-2026-13026). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13024 |
|
Vulnerability in google (CVE-2026-13024)
vulnerability in google (CVE-2026-13024). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13022 |
|
Vulnerability in google (CVE-2026-13022)
vulnerability in google (CVE-2026-13022). Confidential information can be exposed externally.
|