Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2021-47941 |
|
SQL Injection in wordpress (CVE-2021-47941)
SQL injection in wordpress (CVE-2021-47941). Confidential information can be exposed externally.
|
| CVE-2021-47937 |
|
Unrestricted File Upload in CVE-2021-47937 (CVE-2021-47937)
vulnerability in CVE-2021-47937 (CVE-2021-47937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7263 |
|
Vulnerability in libphp (CVE-2026-7263)
vulnerability in libphp (CVE-2026-7263). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.4.21, 8.5.6` or later.
|
| CVE-2026-7258 |
|
Out-of-Bounds Read in libphp (CVE-2026-7258)
vulnerability in libphp (CVE-2026-7258). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.2.31, 8.3.31, 8.4.21, 8.5.6` or later.
|
| CVE-2026-7262 |
|
Vulnerability in libphp (CVE-2026-7262)
vulnerability in libphp (CVE-2026-7262). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.2.31, 8.3.31, 8.4.21, 8.5.6` or later.
|
| CVE-2026-7568 |
|
Out-of-Bounds Read in libphp (CVE-2026-7568)
vulnerability in libphp (CVE-2026-7568). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.2.31, 8.3.31, 8.4.21, 8.5.6` or later.
|
| CVE-2026-8216 |
|
Authentication Bypass in CVE-2026-8216 (CVE-2026-8216)
authentication bypass in CVE-2026-8216 (CVE-2026-8216). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42605 |
|
Path Traversal in azuracast/azuracast (CVE-2026-42605)
path traversal in azuracast/azuracast (CVE-2026-42605). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/station/{station_id}/files/upload`. Mitigation: upgrade to `0.23.6` or later.
|
| CVE-2026-42562 |
|
Privilege Escalation in CVE-2026-42562 (CVE-2026-42562)
vulnerability in CVE-2026-42562 (CVE-2026-42562). Confidential information can be exposed externally. Exploitable via `PUT /api.php/v1/users/{id}.`.
|
| CVE-2026-5485 |
|
OS Command Injection in Amazon aws (CVE-2026-5485)
OS command injection in Amazon aws (CVE-2026-5485). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.5.1` or later.
|
| CVE-2026-20040 |
|
OS Command Injection in Cisco ios-xr (CVE-2026-20040)
OS command injection in Cisco ios-xr (CVE-2026-20040). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20151 |
|
Vulnerability in Cisco smart-software-manager-on-prem (CVE-2026-20151)
vulnerability in Cisco smart-software-manager-on-prem (CVE-2026-20151). Confidential information can be exposed externally.
|
| CVE-2026-20155 |
|
Vulnerability in Cisco evolved-programmable-network-manager (CVE-2026-20155)
vulnerability in Cisco evolved-programmable-network-manager (CVE-2026-20155). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20094 |
|
Command Injection in Cisco unified-computing-system (CVE-2026-20094)
command injection in Cisco unified-computing-system (CVE-2026-20094). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20034 |
|
Vulnerability in Cisco unity-connection (CVE-2026-20034)
vulnerability in Cisco unity-connection (CVE-2026-20034). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20167 |
|
Vulnerability in Cisco dos (CVE-2026-20167)
vulnerability in Cisco dos (CVE-2026-20167). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6297 |
|
Use-After-Free in Google chrome (CVE-2026-6297)
vulnerability in Google chrome (CVE-2026-6297). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7363 |
|
Use-After-Free in Google chrome (CVE-2026-7363)
vulnerability in Google chrome (CVE-2026-7363). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20074 |
|
Vulnerability in Cisco dos (CVE-2026-20074)
vulnerability in Cisco dos (CVE-2026-20074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41705 |
|
Vulnerability in org.springframework.ai:spring-ai-milvus-store (CVE-2026-41705)
vulnerability in org.springframework.ai:spring-ai-milvus-store (CVE-2026-41705). Confidential information can be exposed externally. Mitigation: upgrade to `1.1.6` or later.
|
| CVE-2026-44966 |
|
Vulnerability in velocityjs (CVE-2026-44966)
vulnerability in velocityjs (CVE-2026-44966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44900 |
|
Vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-44900)
vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-44900). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.1` or later.
|
| CVE-2026-42224 |
|
Cross-Site Scripting (XSS) in ipl/web (CVE-2026-42224)
cross-site scripting in ipl/web (CVE-2026-42224). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.10.3` or later.
|
| CVE-2026-42205 |
|
Vulnerability in avo (CVE-2026-42205)
vulnerability in avo (CVE-2026-42205). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/resources/posts/actions`. Mitigation: upgrade to `3.31.2` or later.
|
| CVE-2026-7807 |
|
Path Traversal in smartertools (CVE-2026-7807)
path traversal in smartertools (CVE-2026-7807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44714 |
|
Vulnerability in org.bitcoinj:bitcoinj-core (CVE-2026-44714)
vulnerability in org.bitcoinj:bitcoinj-core (CVE-2026-44714). Data can be tampered with by attackers. Exploitable via ``P2PKH``. Mitigation: upgrade to `0.17.1` or later.
|
| CVE-2026-43462 |
|
Vulnerability in linux (CVE-2026-43462)
vulnerability in linux (CVE-2026-43462). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43464 |
|
Vulnerability in linux (CVE-2026-43464)
vulnerability in linux (CVE-2026-43464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43466 |
|
Vulnerability in c (CVE-2026-43466)
vulnerability in c (CVE-2026-43466). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43469 |
|
Vulnerability in linux (CVE-2026-43469)
vulnerability in linux (CVE-2026-43469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43453 |
|
Out-of-Bounds Read in linux (CVE-2026-43453)
vulnerability in linux (CVE-2026-43453). Confidential information can be exposed externally.
|
| CVE-2026-43454 |
|
Vulnerability in linux (CVE-2026-43454)
vulnerability in linux (CVE-2026-43454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43456 |
|
Vulnerability in c (CVE-2026-43456)
vulnerability in c (CVE-2026-43456). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43458 |
|
Use-After-Free in linux (CVE-2026-43458)
vulnerability in linux (CVE-2026-43458). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43459 |
|
Use-After-Free in linux (CVE-2026-43459)
vulnerability in linux (CVE-2026-43459). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43460 |
|
Vulnerability in linux (CVE-2026-43460)
vulnerability in linux (CVE-2026-43460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43461 |
|
Vulnerability in linux (CVE-2026-43461)
vulnerability in linux (CVE-2026-43461). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43447 |
|
Use-After-Free in linux (CVE-2026-43447)
vulnerability in linux (CVE-2026-43447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43449 |
|
Out-of-Bounds Read in c (CVE-2026-43449)
vulnerability in c (CVE-2026-43449). Confidential information can be exposed externally.
|
| CVE-2026-43450 |
|
Out-of-Bounds Read in linux (CVE-2026-43450)
vulnerability in linux (CVE-2026-43450). Confidential information can be exposed externally.
|
| CVE-2026-43452 |
|
Vulnerability in linux (CVE-2026-43452)
vulnerability in linux (CVE-2026-43452). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43437 |
|
Use-After-Free in linux (CVE-2026-43437)
vulnerability in linux (CVE-2026-43437). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43438 |
|
Use-After-Free in linux (CVE-2026-43438)
vulnerability in linux (CVE-2026-43438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43440 |
|
Use-After-Free in linux (CVE-2026-43440)
vulnerability in linux (CVE-2026-43440). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43441 |
|
Vulnerability in linux (CVE-2026-43441)
vulnerability in linux (CVE-2026-43441). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43442 |
|
Vulnerability in linux (CVE-2026-43442)
vulnerability in linux (CVE-2026-43442). Confidential information can be exposed externally.
|
| CVE-2026-43426 |
|
Use-After-Free in linux (CVE-2026-43426)
vulnerability in linux (CVE-2026-43426). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43427 |
|
Out-of-Bounds Read in linux (CVE-2026-43427)
vulnerability in linux (CVE-2026-43427). Confidential information can be exposed externally.
|
| CVE-2026-43405 |
|
Vulnerability in linux (CVE-2026-43405)
vulnerability in linux (CVE-2026-43405). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43408 |
|
Vulnerability in c (CVE-2026-43408)
vulnerability in c (CVE-2026-43408). Successful exploitation can lead to full system takeover.
|