Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-33382 |
|
Vulnerability in dos (CVE-2026-33382)
vulnerability in dos (CVE-2026-33382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61434 |
|
OS Command Injection in CVE-2026-61434 (CVE-2026-61434)
OS command injection in CVE-2026-61434 (CVE-2026-61434). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61437 |
|
Vulnerability in CVE-2026-61437 (CVE-2026-61437)
vulnerability in CVE-2026-61437 (CVE-2026-61437). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59796 |
|
Vulnerability in jetbrains (CVE-2026-59796)
vulnerability in jetbrains (CVE-2026-59796). Confidential information can be exposed externally.
|
| CVE-2026-60091 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-60091)
SSRF in ssrf (CVE-2026-60091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59793 |
|
Vulnerability in jetbrains (CVE-2026-59793)
vulnerability in jetbrains (CVE-2026-59793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59794 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-59794)
cross-site scripting in jetbrains (CVE-2026-59794). Confidential information can be exposed externally.
|
| CVE-2026-59795 |
|
Cross-Site Scripting (XSS) in jetbrains (CVE-2026-59795)
cross-site scripting in jetbrains (CVE-2026-59795). Confidential information can be exposed externally.
|
| CVE-2026-38057 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-38057)
vulnerability in csrf (CVE-2026-38057). Data can be tampered with by attackers.
|
| CVE-2026-56279 |
|
Vulnerability in CVE-2026-56279 (CVE-2026-56279)
vulnerability in CVE-2026-56279 (CVE-2026-56279). Confidential information can be exposed externally.
|
| CVE-2026-38059 |
|
Vulnerability in CVE-2026-38059 (CVE-2026-38059)
vulnerability in CVE-2026-38059 (CVE-2026-38059). Confidential information can be exposed externally.
|
| CVE-2026-56254 |
|
Vulnerability in CVE-2026-56254 (CVE-2026-56254)
vulnerability in CVE-2026-56254 (CVE-2026-56254). Data can be tampered with by attackers.
|
| CVE-2026-29519 |
|
Cross-Site Scripting (XSS) in CVE-2026-29519 (CVE-2026-29519)
cross-site scripting in CVE-2026-29519 (CVE-2026-29519). Confidential information can be exposed externally.
|
| CVE-2026-56305 |
|
Vulnerability in CVE-2026-56305 (CVE-2026-56305)
vulnerability in CVE-2026-56305 (CVE-2026-56305). Confidential information can be exposed externally.
|
| CVE-2026-56261 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-56261)
SSRF in ssrf (CVE-2026-56261). Confidential information can be exposed externally.
|
| CVE-2026-22660 |
|
Vulnerability in CVE-2026-22660 (CVE-2026-22660)
vulnerability in CVE-2026-22660 (CVE-2026-22660). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22659 |
|
Authorization Flaw in CVE-2026-22659 (CVE-2026-22659)
vulnerability in CVE-2026-22659 (CVE-2026-22659). Data can be tampered with by attackers.
|
| CVE-2026-54469 |
|
Unsafe Deserialization in deserialization (CVE-2026-54469)
vulnerability in deserialization (CVE-2026-54469). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56689 |
|
SQL Injection in sqli (CVE-2026-56689)
SQL injection in sqli (CVE-2026-56689). Confidential information can be exposed externally.
|
| CVE-2026-56690 |
|
SQL Injection in sqli (CVE-2026-56690)
SQL injection in sqli (CVE-2026-56690). Confidential information can be exposed externally.
|
| CVE-2026-40006 |
|
Vulnerability in apache (CVE-2026-40006)
vulnerability in apache (CVE-2026-40006). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40454 |
|
Vulnerability in c (CVE-2026-40454)
vulnerability in c (CVE-2026-40454). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40007 |
|
Vulnerability in apache (CVE-2026-40007)
vulnerability in apache (CVE-2026-40007). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40452 |
|
Vulnerability in apache (CVE-2026-40452)
vulnerability in apache (CVE-2026-40452). Confidential information can be exposed externally.
|
| CVE-2026-12685 |
|
Vulnerability in wordpress (CVE-2026-12685)
vulnerability in wordpress (CVE-2026-12685). Data can be tampered with by attackers.
|
| CVE-2026-13347 |
|
Path Traversal in wordpress (CVE-2026-13347)
path traversal in wordpress (CVE-2026-13347). Confidential information can be exposed externally.
|
| CVE-2026-15330 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15330 (CVE-2026-15330)
SSRF in CVE-2026-15330 (CVE-2026-15330). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15298 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15298)
cross-site scripting in wordpress (CVE-2026-15298). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15293 |
|
Vulnerability in wordpress (CVE-2026-15293)
vulnerability in wordpress (CVE-2026-15293). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15291 |
|
Vulnerability in wordpress (CVE-2026-15291)
vulnerability in wordpress (CVE-2026-15291). Confidential information can be exposed externally.
|
| CVE-2026-54423 |
|
Vulnerability in CVE-2026-54423 (CVE-2026-54423)
vulnerability in CVE-2026-54423 (CVE-2026-54423). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13430 |
|
Unrestricted File Upload in wordpress (CVE-2026-13430)
vulnerability in wordpress (CVE-2026-13430). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15070 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15070)
vulnerability in wordpress (CVE-2026-15070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15290 |
|
SQL Injection in wordpress (CVE-2026-15290)
SQL injection in wordpress (CVE-2026-15290). Confidential information can be exposed externally.
|
| CVE-2026-15288 |
|
Vulnerability in wordpress (CVE-2026-15288)
vulnerability in wordpress (CVE-2026-15288). Data can be tampered with by attackers.
|
| CVE-2026-15319 |
|
Vulnerability in CVE-2026-15319 (CVE-2026-15319)
vulnerability in CVE-2026-15319 (CVE-2026-15319). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12598 |
|
Authentication Bypass in wordpress (CVE-2026-12598)
authentication bypass in wordpress (CVE-2026-12598). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12597 |
|
Authentication Bypass in wordpress (CVE-2026-12597)
authentication bypass in wordpress (CVE-2026-12597). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12595 |
|
Authentication Bypass in wordpress (CVE-2026-12595)
authentication bypass in wordpress (CVE-2026-12595). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59856 |
|
Code Injection in vim (CVE-2026-59856)
code injection in vim (CVE-2026-59856). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59858 |
|
Code Injection in c (CVE-2026-59858)
code injection in c (CVE-2026-59858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59832 |
|
Path Traversal in CVE-2026-59832 (CVE-2026-59832)
path traversal in CVE-2026-59832 (CVE-2026-59832). Confidential information can be exposed externally.
|
| CVE-2026-59834 |
|
SQL Injection in CVE-2026-59834 (CVE-2026-59834)
SQL injection in CVE-2026-59834 (CVE-2026-59834). Confidential information can be exposed externally. Exploitable via `POST /api/search/fullTextSearchBlock`.
|
| CVE-2026-58143 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-58143)
vulnerability in csrf (CVE-2026-58143). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57028 |
|
Vulnerability in juniper (CVE-2026-57028)
vulnerability in juniper (CVE-2026-57028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57023 |
|
Vulnerability in dos (CVE-2026-57023)
vulnerability in dos (CVE-2026-57023). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57026 |
|
Vulnerability in dos (CVE-2026-57026)
vulnerability in dos (CVE-2026-57026). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55604 |
|
Vulnerability in @arikusi/deepseek-mcp-server (CVE-2026-55604)
vulnerability in @arikusi/deepseek-mcp-server (CVE-2026-55604). Confidential information can be exposed externally. Exploitable via ``session_id``. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-53963 |
|
Cross-Site Scripting (XSS) in discourse (CVE-2026-53963)
cross-site scripting in discourse (CVE-2026-53963). Confidential information can be exposed externally.
|
| CVE-2026-49256 |
|
Information Disclosure in discourse (CVE-2026-49256)
vulnerability in discourse (CVE-2026-49256). Confidential information can be exposed externally.
|