Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12005 |
|
OS Command Injection in ibm (CVE-2026-12005)
OS command injection in ibm (CVE-2026-12005). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12004 |
|
Vulnerability in dos (CVE-2026-12004)
vulnerability in dos (CVE-2026-12004). Confidential information can be exposed externally.
|
| CVE-2026-11923 |
|
Authentication Bypass in ibm (CVE-2026-11923)
authentication bypass in ibm (CVE-2026-11923). Confidential information can be exposed externally.
|
| CVE-2026-18713 |
|
Privilege Escalation in privilege-escalation (CVE-2026-18713)
vulnerability in privilege-escalation (CVE-2026-18713). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18669 |
|
Vulnerability in privilege-escalation (CVE-2026-18669)
vulnerability in privilege-escalation (CVE-2026-18669). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18235 |
|
OS Command Injection in ibm (CVE-2026-18235)
OS command injection in ibm (CVE-2026-18235). Confidential information can be exposed externally.
|
| CVE-2026-17418 |
|
SQL Injection in dos (CVE-2026-17418)
SQL injection in dos (CVE-2026-17418). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73327 |
|
Path Traversal in path-traversal (CVE-2026-73327)
path traversal in path-traversal (CVE-2026-73327). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16627 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2026-16627)
cross-site scripting in gitlab (CVE-2026-16627). Confidential information can be exposed externally.
|
| CVE-2026-15423 |
|
Authorization Flaw in gitlab (CVE-2026-15423)
vulnerability in gitlab (CVE-2026-15423). Data can be tampered with by attackers.
|
| CVE-2026-17248 |
|
OS Command Injection in dos (CVE-2026-17248)
OS command injection in dos (CVE-2026-17248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17110 |
|
Vulnerability in ibm (CVE-2026-17110)
vulnerability in ibm (CVE-2026-17110). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17271 |
|
Vulnerability in dos (CVE-2026-17271)
vulnerability in dos (CVE-2026-17271). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16906 |
|
OS Command Injection in ibm (CVE-2026-16906)
OS command injection in ibm (CVE-2026-16906). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16907 |
|
Out-of-Bounds Write in ibm (CVE-2026-16907)
out-of-bounds write in ibm (CVE-2026-16907). Data can be tampered with by attackers.
|
| CVE-2026-16863 |
|
Out-of-Bounds Read in ibm (CVE-2026-16863)
vulnerability in ibm (CVE-2026-16863). Confidential information can be exposed externally.
|
| CVE-2026-16931 |
|
Vulnerability in dos (CVE-2026-16931)
vulnerability in dos (CVE-2026-16931). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16856 |
|
OS Command Injection in ibm (CVE-2026-16856)
OS command injection in ibm (CVE-2026-16856). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16904 |
|
Privilege Escalation in ibm (CVE-2026-16904)
vulnerability in ibm (CVE-2026-16904). Confidential information can be exposed externally.
|
| CVE-2026-18683 |
|
OS Command Injection in privilege-escalation (CVE-2026-18683)
OS command injection in privilege-escalation (CVE-2026-18683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18098 |
|
Vulnerability in ibm (CVE-2026-18098)
vulnerability in ibm (CVE-2026-18098). Confidential information can be exposed externally.
|
| CVE-2026-18847 |
|
Vulnerability in ibm (CVE-2026-18847)
vulnerability in ibm (CVE-2026-18847). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17095 |
|
Vulnerability in ibm (CVE-2026-17095)
vulnerability in ibm (CVE-2026-17095). Confidential information can be exposed externally.
|
| CVE-2026-18499 |
|
Vulnerability in privilege-escalation (CVE-2026-18499)
vulnerability in privilege-escalation (CVE-2026-18499). Confidential information can be exposed externally.
|
| CVE-2026-68968 |
|
Vulnerability in apache (CVE-2026-68968)
vulnerability in apache (CVE-2026-68968). Confidential information can be exposed externally. Exploitable via ``backfill_id``.
|
| CVE-2026-67587 |
|
Unsafe Deserialization in apache (CVE-2026-67587)
vulnerability in apache (CVE-2026-67587). Successful exploitation can lead to full system takeover. Exploitable via ``Callback``.
|
| CVE-2026-67260 |
|
Unsafe Deserialization in apache (CVE-2026-67260)
vulnerability in apache (CVE-2026-67260). Risk of unauthorized operations or information disclosure. Exploitable via ``awaiting_input``.
|
| CVE-2026-58076 |
|
Unsafe Deserialization in apache (CVE-2026-58076)
vulnerability in apache (CVE-2026-58076). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v2/dags/{dag_id}/details`.
|
| CVE-2026-32258 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32258)
cross-site scripting in winter/wn-backend-module (CVE-2026-32258). Confidential information can be exposed externally. Exploitable via ``backend.manage_editor``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32257 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32257)
cross-site scripting in winter/wn-backend-module (CVE-2026-32257). Confidential information can be exposed externally. Exploitable via ``backend.manage_branding``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-16253 |
|
Information Disclosure in wordpress (CVE-2026-16253)
vulnerability in wordpress (CVE-2026-16253). Confidential information can be exposed externally.
|
| CVE-2026-16977 |
|
SQL Injection in wordpress (CVE-2026-16977)
SQL injection in wordpress (CVE-2026-16977). Confidential information can be exposed externally.
|
| CVE-2026-18048 |
|
Vulnerability in wordpress (CVE-2026-18048)
vulnerability in wordpress (CVE-2026-18048). Data can be tampered with by attackers.
|
| CVE-2026-18474 |
|
SQL Injection in wordpress (CVE-2026-18474)
SQL injection in wordpress (CVE-2026-18474). Confidential information can be exposed externally.
|
| CVE-2026-18789 |
|
Vulnerability in wordpress (CVE-2026-18789)
vulnerability in wordpress (CVE-2026-18789). Confidential information can be exposed externally.
|
| CVE-2026-16294 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16294)
SSRF in wordpress (CVE-2026-16294). Confidential information can be exposed externally.
|
| CVE-2026-18049 |
|
Information Disclosure in wordpress (CVE-2026-18049)
vulnerability in wordpress (CVE-2026-18049). Confidential information can be exposed externally.
|
| CVE-2026-18230 |
|
SQL Injection in wordpress (CVE-2026-18230)
SQL injection in wordpress (CVE-2026-18230). Confidential information can be exposed externally.
|
| CVE-2026-18057 |
|
SQL Injection in wordpress (CVE-2026-18057)
SQL injection in wordpress (CVE-2026-18057). Confidential information can be exposed externally.
|
| CVE-2026-13613 |
|
SQL Injection in wordpress (CVE-2026-13613)
SQL injection in wordpress (CVE-2026-13613). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13171 |
|
Vulnerability in wordpress (CVE-2026-13171)
vulnerability in wordpress (CVE-2026-13171). Data can be tampered with by attackers.
|
| CVE-2026-14925 |
|
Information Disclosure in wordpress (CVE-2026-14925)
vulnerability in wordpress (CVE-2026-14925). Confidential information can be exposed externally.
|
| CVE-2026-18961 |
|
Authentication Bypass in wordpress (CVE-2026-18961)
authentication bypass in wordpress (CVE-2026-18961). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73247 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-73247 (CVE-2026-73247)
SSRF in CVE-2026-73247 (CVE-2026-73247). Confidential information can be exposed externally.
|
| CVE-2026-73246 |
|
Information Disclosure in CVE-2026-73246 (CVE-2026-73246)
vulnerability in CVE-2026-73246 (CVE-2026-73246). Confidential information can be exposed externally. Exploitable via `GET /worker`. Mitigation: upgrade to `2.0.0-rc6` or later.
|
| CVE-2026-19560 |
|
Use-After-Free in google (CVE-2026-19560)
vulnerability in google (CVE-2026-19560). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19559 |
|
Use-After-Free in google (CVE-2026-19559)
vulnerability in google (CVE-2026-19559). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19558 |
|
Use-After-Free in google (CVE-2026-19558)
vulnerability in google (CVE-2026-19558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19557 |
|
Use-After-Free in google (CVE-2026-19557)
vulnerability in google (CVE-2026-19557). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19556 |
|
Use-After-Free in Google chrome (CVE-2026-19556)
vulnerability in Google chrome (CVE-2026-19556). Successful exploitation can lead to full system takeover.
|