Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-54563 |
|
Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54563)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54563). Confidential information can be exposed externally. Exploitable via `GET /dav/`. Mitigation: upgrade to `4.0.0-20260606032813-26b6b1044b02` or later.
|
| CVE-2026-54560 |
|
Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54560)
vulnerability in github.com/cloudreve/Cloudreve/v4 (CVE-2026-54560). Confidential information can be exposed externally. Exploitable via `POST /api/v4/session/oauth/token`. Mitigation: upgrade to `4.0.0-20260606015557-ed20843dc3df` or later.
|
| CVE-2026-61873 |
|
Vulnerability in path-traversal (CVE-2026-61873)
vulnerability in path-traversal (CVE-2026-61873). Data can be tampered with by attackers.
|
| CVE-2026-61457 |
|
Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
vulnerability in CVE-2026-61457 (CVE-2026-61457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61446 |
|
Code Injection in path-traversal (CVE-2026-61446)
code injection in path-traversal (CVE-2026-61446). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61438 |
|
OS Command Injection in CVE-2026-61438 (CVE-2026-61438)
OS command injection in CVE-2026-61438 (CVE-2026-61438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61443 |
|
Path Traversal in CVE-2026-61443 (CVE-2026-61443)
path traversal in CVE-2026-61443 (CVE-2026-61443). Confidential information can be exposed externally.
|
| CVE-2026-60085 |
|
Vulnerability in CVE-2026-60085 (CVE-2026-60085)
vulnerability in CVE-2026-60085 (CVE-2026-60085). Confidential information can be exposed externally.
|
| CVE-2026-61430 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61430)
SSRF in ssrf (CVE-2026-61430). Confidential information can be exposed externally.
|
| CVE-2026-61427 |
|
Vulnerability in CVE-2026-61427 (CVE-2026-61427)
vulnerability in CVE-2026-61427 (CVE-2026-61427). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
|
| CVE-2026-61435 |
|
Authentication Bypass in CVE-2026-61435 (CVE-2026-61435)
authentication bypass in CVE-2026-61435 (CVE-2026-61435). Data can be tampered with by attackers. Exploitable via `GET /api/v1/agents`.
|
| CVE-2026-61436 |
|
Authentication Bypass in CVE-2026-61436 (CVE-2026-61436)
authentication bypass in CVE-2026-61436 (CVE-2026-61436). Data can be tampered with by attackers.
|
| CVE-2026-61433 |
|
Code Injection in CVE-2026-61433 (CVE-2026-61433)
code injection in CVE-2026-61433 (CVE-2026-61433). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58655 |
|
Code Injection in CVE-2026-58655 (CVE-2026-58655)
code injection in CVE-2026-58655 (CVE-2026-58655). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56398 |
|
Vulnerability in openwebui (CVE-2026-56398)
vulnerability in openwebui (CVE-2026-56398). Confidential information can be exposed externally.
|
| CVE-2026-56400 |
|
Vulnerability in openwebui (CVE-2026-56400)
vulnerability in openwebui (CVE-2026-56400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57996 |
|
Privilege Escalation in privilege-escalation (CVE-2026-57996)
vulnerability in privilege-escalation (CVE-2026-57996). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/api/user/add`.
|
| CVE-2026-56339 |
|
Vulnerability in CVE-2026-56339 (CVE-2026-56339)
vulnerability in CVE-2026-56339 (CVE-2026-56339). Confidential information can be exposed externally.
|
| CVE-2026-40633 |
|
Vulnerability in dell (CVE-2026-40633)
vulnerability in dell (CVE-2026-40633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57821 |
|
SQL Injection in apache (CVE-2026-57821)
SQL injection in apache (CVE-2026-57821). Confidential information can be exposed externally. Exploitable via `GET /api/v1/offices`.
|
| CVE-2026-56287 |
|
SQL Injection in apache (CVE-2026-56287)
SQL injection in apache (CVE-2026-56287). Confidential information can be exposed externally. Exploitable via `GET /api/v1/clients`.
|
| CVE-2026-35152 |
|
SQL Injection in apache (CVE-2026-35152)
SQL injection in apache (CVE-2026-35152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14251 |
|
Vulnerability in dos (CVE-2026-14251)
vulnerability in dos (CVE-2026-14251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15583 |
|
Vulnerability in ssrf (CVE-2026-15583)
vulnerability in ssrf (CVE-2026-15583). Confidential information can be exposed externally.
|
| CVE-2026-15804 |
|
SQL Injection in sqli (CVE-2026-15804)
SQL injection in sqli (CVE-2026-15804). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42936 |
|
Vulnerability in jvn (CVE-2026-42936)
vulnerability in jvn (CVE-2026-42936). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12512 |
|
SQL Injection in wordpress (CVE-2026-12512)
SQL injection in wordpress (CVE-2026-12512). Confidential information can be exposed externally.
|
| CVE-2026-12281 |
|
Authentication Bypass in wordpress (CVE-2026-12281)
authentication bypass in wordpress (CVE-2026-12281). Successful exploitation can lead to full system takeover.
|
| CVE-2023-4346 KEV |
|
[KEV] Vulnerability in Knx association knx (CVE-2023-4346)
vulnerability in Knx association knx (CVE-2023-4346). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-15752 |
|
Vulnerability in CVE-2026-15752 (CVE-2026-15752)
vulnerability in CVE-2026-15752 (CVE-2026-15752). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56365 |
|
Vulnerability in csa-iot (CVE-2025-56365)
vulnerability in csa-iot (CVE-2025-56365). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56364 |
|
Vulnerability in dos (CVE-2025-56364)
vulnerability in dos (CVE-2025-56364). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56363 |
|
Vulnerability in dos (CVE-2025-56363)
vulnerability in dos (CVE-2025-56363). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56362 |
|
Vulnerability in dos (CVE-2025-56362)
vulnerability in dos (CVE-2025-56362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59733 |
|
Path Traversal in github.com/rclone/rclone (CVE-2026-59733)
path traversal in github.com/rclone/rclone (CVE-2026-59733). Successful exploitation can lead to full system takeover. Exploitable via `GET /test/../victim/config`. Mitigation: upgrade to `1.74.4` or later.
|
| CVE-2026-54684 |
|
Path Traversal in CVE-2026-54684 (CVE-2026-54684)
path traversal in CVE-2026-54684 (CVE-2026-54684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54572 |
|
Vulnerability in github.com/rclone/rclone (CVE-2026-54572)
vulnerability in github.com/rclone/rclone (CVE-2026-54572). Data can be tampered with by attackers. Exploitable via ``mkdirAll``. Mitigation: upgrade to `1.74.4` or later.
|
| CVE-2026-50130 |
|
Vulnerability in pi-hole (CVE-2026-50130)
vulnerability in pi-hole (CVE-2026-50130). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48352 |
|
Vulnerability in adobe (CVE-2026-48352)
vulnerability in adobe (CVE-2026-48352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48351 |
|
Vulnerability in adobe (CVE-2026-48351)
vulnerability in adobe (CVE-2026-48351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48337 |
|
Out-of-Bounds Write in adobe (CVE-2026-48337)
out-of-bounds write in adobe (CVE-2026-48337). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48335 |
|
Out-of-Bounds Write in adobe (CVE-2026-48335)
out-of-bounds write in adobe (CVE-2026-48335). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48336 |
|
Out-of-Bounds Write in adobe (CVE-2026-48336)
out-of-bounds write in adobe (CVE-2026-48336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48275 |
|
Vulnerability in adobe (CVE-2026-48275)
vulnerability in adobe (CVE-2026-48275). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48287 |
|
Vulnerability in adobe (CVE-2026-48287)
vulnerability in adobe (CVE-2026-48287). Confidential information can be exposed externally.
|
| CVE-2026-48295 |
|
Vulnerability in adobe (CVE-2026-48295)
vulnerability in adobe (CVE-2026-48295). Confidential information can be exposed externally.
|
| CVE-2026-48290 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48290)
SSRF in ssrf (CVE-2026-48290). Confidential information can be exposed externally.
|
| CVE-2025-56361 |
|
Vulnerability in dos (CVE-2025-56361)
vulnerability in dos (CVE-2025-56361). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47976 |
|
Out-of-Bounds Write in adobe (CVE-2026-47976)
out-of-bounds write in adobe (CVE-2026-47976). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47471 |
|
Vulnerability in dos (CVE-2026-47471)
vulnerability in dos (CVE-2026-47471). Successful exploitation can lead to full system takeover.
|