Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12064 |
|
Vulnerability in haxx (CVE-2026-12064)
vulnerability in haxx (CVE-2026-12064). Data can be tampered with by attackers.
|
| CVE-2026-8286 |
|
Vulnerability in haxx (CVE-2026-8286)
vulnerability in haxx (CVE-2026-8286). Confidential information can be exposed externally.
|
| CVE-2026-4967 |
|
Vulnerability in dos (CVE-2026-4967)
vulnerability in dos (CVE-2026-4967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11586 |
|
Vulnerability in haxx (CVE-2026-11586)
vulnerability in haxx (CVE-2026-11586). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11352 |
|
Vulnerability in dos (CVE-2026-11352)
vulnerability in dos (CVE-2026-11352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13040 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13040)
cross-site scripting in wordpress (CVE-2026-13040). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14352 |
|
Path Traversal in wordpress (CVE-2026-14352)
path traversal in wordpress (CVE-2026-14352). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-14327 |
|
Path Traversal in wordpress (CVE-2026-14327)
path traversal in wordpress (CVE-2026-14327). Confidential information can be exposed externally.
|
| CVE-2026-8247 |
|
Vulnerability in watchguard (CVE-2026-8247)
vulnerability in watchguard (CVE-2026-8247). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13368 |
|
Use-After-Free in watchguard (CVE-2026-13368)
vulnerability in watchguard (CVE-2026-13368). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13722 |
|
Vulnerability in watchguard (CVE-2026-13722)
vulnerability in watchguard (CVE-2026-13722). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13383 |
|
Out-of-Bounds Write in watchguard (CVE-2026-13383)
out-of-bounds write in watchguard (CVE-2026-13383). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13384 |
|
Out-of-Bounds Write in watchguard (CVE-2026-13384)
out-of-bounds write in watchguard (CVE-2026-13384). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13053 |
|
Out-of-Bounds Write in watchguard (CVE-2026-13053)
out-of-bounds write in watchguard (CVE-2026-13053). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13054 |
|
Path Traversal in path-traversal (CVE-2026-13054)
path traversal in path-traversal (CVE-2026-13054). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13050 |
|
Out-of-Bounds Write in watchguard (CVE-2026-13050)
out-of-bounds write in watchguard (CVE-2026-13050). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13079 |
|
Vulnerability in privilege-escalation (CVE-2026-13079)
vulnerability in privilege-escalation (CVE-2026-13079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13084 |
|
Vulnerability in dos (CVE-2026-13084)
vulnerability in dos (CVE-2026-13084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54998 |
|
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
|
| CVE-2026-50722 |
|
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly...
|
| CVE-2026-50721 |
|
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify...
|
| CVE-2026-12413 |
|
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart....
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart....
|
| CVE-2026-52192 |
|
Vulnerability in dos (CVE-2026-52192)
vulnerability in dos (CVE-2026-52192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38970 |
|
Vulnerability in CVE-2026-38970 (CVE-2026-38970)
vulnerability in CVE-2026-38970 (CVE-2026-38970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52191 |
|
Vulnerability in dos (CVE-2026-52191)
vulnerability in dos (CVE-2026-52191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38972 |
|
Vulnerability in c (CVE-2026-38972)
vulnerability in c (CVE-2026-38972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52189 |
|
Vulnerability in dos (CVE-2026-52189)
vulnerability in dos (CVE-2026-52189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58460 |
|
Path Traversal in react (CVE-2026-58460)
path traversal in react (CVE-2026-58460). Data can be tampered with by attackers.
|
| CVE-2026-38969 |
|
Vulnerability in CVE-2026-38969 (CVE-2026-38969)
vulnerability in CVE-2026-38969 (CVE-2026-38969). Data can be tampered with by attackers.
|
| CVE-2026-59095 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59095)
SSRF in ssrf (CVE-2026-59095). Confidential information can be exposed externally.
|
| CVE-2026-59096 |
|
Vulnerability in CVE-2026-59096 (CVE-2026-59096)
vulnerability in CVE-2026-59096 (CVE-2026-59096). Data can be tampered with by attackers. Exploitable via `Host header`.
|
| CVE-2026-59094 |
|
Vulnerability in CVE-2026-59094 (CVE-2026-59094)
vulnerability in CVE-2026-59094 (CVE-2026-59094). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59092 |
|
Vulnerability in dos (CVE-2026-59092)
vulnerability in dos (CVE-2026-59092). Confidential information can be exposed externally.
|
| CVE-2026-59093 |
|
Vulnerability in weaviate (CVE-2026-59093)
vulnerability in weaviate (CVE-2026-59093). Successful exploitation can lead to full system takeover. Exploitable via `POST /authz/users/{id}/assign`.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2026-52187 |
|
Vulnerability in dos (CVE-2026-52187)
vulnerability in dos (CVE-2026-52187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49353 |
|
Vulnerability in 9router (CVE-2026-49353)
vulnerability in 9router (CVE-2026-49353). Data can be tampered with by attackers. Exploitable via `GET /api/mcp/`.
|
| CVE-2026-49284 |
|
Vulnerability in simplesamlphp/simplesamlphp (CVE-2026-49284)
vulnerability in simplesamlphp/simplesamlphp (CVE-2026-49284). Data can be tampered with by attackers. Exploitable via ``SubjectConfirmationData``. Mitigation: upgrade to `2.4.7` or later.
|
| CVE-2026-49289 |
|
Vulnerability in simplesamlphp/saml2 (CVE-2026-49289)
vulnerability in simplesamlphp/saml2 (CVE-2026-49289). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.19.3` or later.
|
| CVE-2026-52829 |
|
Vulnerability in zebra-network (CVE-2026-52829)
vulnerability in zebra-network (CVE-2026-52829). Risk of unauthorized operations or information disclosure. Exploitable via ``zebrad``. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-49283 |
|
Vulnerability in simplesamlphp/saml2 (CVE-2026-49283)
vulnerability in simplesamlphp/saml2 (CVE-2026-49283). Confidential information can be exposed externally. Exploitable via ``Response``. Mitigation: upgrade to `4.19.3` or later.
|
| CVE-2026-52746 |
|
Vulnerability in jsonata (CVE-2026-52746)
vulnerability in jsonata (CVE-2026-52746). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.9` or later.
|
| CVE-2026-49255 |
|
OS Command Injection in electerm (CVE-2026-49255)
OS command injection in electerm (CVE-2026-49255). Successful exploitation can lead to full system takeover. Exploitable via ``rmrf``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-49253 |
|
Path Traversal in electerm (CVE-2026-49253)
path traversal in electerm (CVE-2026-49253). Data can be tampered with by attackers. Exploitable via ``savedFilePaths``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|
| CVE-2026-58465 |
|
Vulnerability in c (CVE-2026-58465)
vulnerability in c (CVE-2026-58465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44454 |
|
OS Command Injection in github.com/coder/coder/v2 (CVE-2026-44454)
OS command injection in github.com/coder/coder/v2 (CVE-2026-44454). Confidential information can be exposed externally. Exploitable via ``dotfiles``. Mitigation: upgrade to `2.30.2` or later.
|
| CVE-2026-52854 |
|
Cross-Site Scripting (XSS) in mediawiki/maps (CVE-2026-52854)
cross-site scripting in mediawiki/maps (CVE-2026-52854). Confidential information can be exposed externally. Exploitable via ``overlays``. Mitigation: upgrade to `12.1.3` or later.
|
| CVE-2026-50181 |
|
Path Traversal in langroid (CVE-2026-50181)
path traversal in langroid (CVE-2026-50181). Confidential information can be exposed externally. Exploitable via ``ReadFileTool``. Mitigation: upgrade to `0.64.0` or later.
|
| CVE-2026-55952 |
|
Vulnerability in erlang (CVE-2026-55952)
vulnerability in erlang (CVE-2026-55952). Risk of unauthorized operations or information disclosure.
|