Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48317 |
|
Vulnerability in adobe (CVE-2026-48317)
vulnerability in adobe (CVE-2026-48317). Confidential information can be exposed externally.
|
| CVE-2026-39932 |
|
Vulnerability in CVE-2026-39932 (CVE-2026-39932)
vulnerability in CVE-2026-39932 (CVE-2026-39932). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45293 |
|
Vulnerability in wp-coding-standards/wpcs (CVE-2026-45293)
vulnerability in wp-coding-standards/wpcs (CVE-2026-45293). Successful exploitation can lead to full system takeover. Exploitable via ``WordPress.WP.EnqueuedResourceParameters``. Mitigation: upgrade to `3.4.1` or later.
|
| CVE-2026-61511 |
|
Vulnerability in CVE-2026-61511 (CVE-2026-61511)
vulnerability in CVE-2026-61511 (CVE-2026-61511). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14380 |
|
Vulnerability in perl (CVE-2026-14380)
vulnerability in perl (CVE-2026-14380). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40187 |
|
OS Command Injection in egroupware/egroupware (CVE-2026-40187)
OS command injection in egroupware/egroupware (CVE-2026-40187). Risk of unauthorized operations or information disclosure. Exploitable via ``chgrp``. Mitigation: upgrade to `23.1.20260601` or later.
|
| CVE-2026-46562 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-46562)
code injection in org.yamcs:yamcs-core (CVE-2026-46562). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/mdb/{instance}/{processor}/algorithms/{name`. Mitigation: upgrade to `5.12.7` or later.
|
| CVE-2026-46586 |
|
Code Injection in apache (CVE-2026-46586)
code injection in apache (CVE-2026-46586). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22666 |
|
Vulnerability in dolibarr (CVE-2026-22666)
vulnerability in dolibarr (CVE-2026-22666). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33017 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-33017)
vulnerability in langflow (CVE-2026-33017). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/build_public_tmp/{flow_id}/flow`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2025-24893 KEV |
|
[KEV] Vulnerability in Xwiki platform (CVE-2025-24893)
vulnerability in Xwiki platform (CVE-2025-24893). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-36401 KEV |
|
[KEV] Vulnerability in Osgeo geoserver (CVE-2024-36401)
vulnerability in Osgeo geoserver (CVE-2024-36401). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-7101 KEV |
|
[KEV] Vulnerability in Spreadsheet::parseexcel spreadsheetparseexcel (CVE-2023-7101)
vulnerability in Spreadsheet::parseexcel spreadsheetparseexcel (CVE-2023-7101). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22204 KEV |
|
[KEV] Vulnerability in Perl exiftool (CVE-2021-22204)
vulnerability in Perl exiftool (CVE-2021-22204). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2021-22205 KEV |
|
[KEV] Code Injection in Gitlab community-and-enterprise-editions (CVE-2021-22205)
code injection in Gitlab community-and-enterprise-editions (CVE-2021-22205). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|