Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-18353 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18353 (CVE-2026-18353)
SSRF in CVE-2026-18353 (CVE-2026-18353). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/upload/sbom`.
|
| CVE-2026-7849 |
|
Command Injection in CVE-2026-7849 (CVE-2026-7849)
command injection in CVE-2026-7849 (CVE-2026-7849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44108 |
|
Vulnerability in CVE-2026-44108 (CVE-2026-44108)
vulnerability in CVE-2026-44108 (CVE-2026-44108). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44107 |
|
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
|
| CVE-2026-44106 |
|
A privilege escalation vulnerability in the init-script for user-applications allows a low...
A privilege escalation vulnerability in the init-script for user-applications allows a low...
|
| CVE-2026-44105 |
|
Vulnerability in CVE-2026-44105 (CVE-2026-44105)
vulnerability in CVE-2026-44105 (CVE-2026-44105). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44104 |
|
Vulnerability in CVE-2026-44104 (CVE-2026-44104)
vulnerability in CVE-2026-44104 (CVE-2026-44104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44103 |
|
Unrestricted File Upload in CVE-2026-44103 (CVE-2026-44103)
vulnerability in CVE-2026-44103 (CVE-2026-44103). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44102 |
|
Vulnerability in CVE-2026-44102 (CVE-2026-44102)
vulnerability in CVE-2026-44102 (CVE-2026-44102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44101 |
|
Vulnerability in CVE-2026-44101 (CVE-2026-44101)
vulnerability in CVE-2026-44101 (CVE-2026-44101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44100 |
|
Vulnerability in CVE-2026-44100 (CVE-2026-44100)
vulnerability in CVE-2026-44100 (CVE-2026-44100). Data can be tampered with by attackers.
|
| CVE-2026-44099 |
|
A privilege escalation vulnerability in the system configuration allows a low-privileged local...
A privilege escalation vulnerability in the system configuration allows a low-privileged local...
|
| CVE-2026-44098 |
|
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
|
| CVE-2026-44097 |
|
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
|
| CVE-2026-44096 |
|
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute...
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute...
|
| CVE-2026-44095 |
|
A privilege escalation vulnerability in a script used for network configuration allows a low...
A privilege escalation vulnerability in a script used for network configuration allows a low...
|
| CVE-2026-44094 |
|
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
|
| CVE-2026-44093 |
|
A local privilege escalation vulnerability in the init-script for user-applications allows a low...
A local privilege escalation vulnerability in the init-script for user-applications allows a low...
|
| CVE-2026-44092 |
|
Vulnerability in CVE-2026-44092 (CVE-2026-44092)
vulnerability in CVE-2026-44092 (CVE-2026-44092). Data can be tampered with by attackers.
|
| CVE-2026-44091 |
|
Vulnerability in CVE-2026-44091 (CVE-2026-44091)
vulnerability in CVE-2026-44091 (CVE-2026-44091). Data can be tampered with by attackers.
|
| CVE-2026-44090 |
|
Vulnerability in CVE-2026-44090 (CVE-2026-44090)
vulnerability in CVE-2026-44090 (CVE-2026-44090). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13584 |
|
Vulnerability in dos (CVE-2026-13584)
vulnerability in dos (CVE-2026-13584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58046 |
|
SQL Injection in sqli (CVE-2026-58046)
SQL injection in sqli (CVE-2026-58046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58066 |
|
Authentication Bypass in rocketchat (CVE-2026-58066)
authentication bypass in rocketchat (CVE-2026-58066). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59327 |
|
Vulnerability in spring (CVE-2026-59327)
vulnerability in spring (CVE-2026-59327). Confidential information can be exposed externally.
|
| CVE-2026-58040 |
|
Vulnerability in CVE-2026-58040 (CVE-2026-58040)
vulnerability in CVE-2026-58040 (CVE-2026-58040). Confidential information can be exposed externally.
|
| CVE-2026-59326 |
|
Vulnerability in spring (CVE-2026-59326)
vulnerability in spring (CVE-2026-59326). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58043 |
|
Vulnerability in nodejs (CVE-2026-58043)
vulnerability in nodejs (CVE-2026-58043). Confidential information can be exposed externally.
|
| CVE-2026-16531 |
|
Path Traversal in path-traversal (CVE-2026-16531)
path traversal in path-traversal (CVE-2026-16531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16529 |
|
Vulnerability in dos (CVE-2026-16529)
vulnerability in dos (CVE-2026-16529). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47873 |
|
Vulnerability in CVE-2026-47873 (CVE-2026-47873)
vulnerability in CVE-2026-47873 (CVE-2026-47873). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56847 |
|
Vulnerability in nodejs (CVE-2026-56847)
vulnerability in nodejs (CVE-2026-56847). Confidential information can be exposed externally.
|
| CVE-2026-47882 |
|
Vulnerability in spring (CVE-2026-47882)
vulnerability in spring (CVE-2026-47882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16527 |
|
Vulnerability in CVE-2026-16527 (CVE-2026-16527)
vulnerability in CVE-2026-16527 (CVE-2026-16527). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56850 |
|
Authentication Bypass in nodejs (CVE-2026-56850)
authentication bypass in nodejs (CVE-2026-56850). Data can be tampered with by attackers.
|
| CVE-2026-16530 |
|
Out-of-Bounds Read in dos (CVE-2026-16530)
vulnerability in dos (CVE-2026-16530). Risk of unauthorized operations or information disclosure. Exploitable via ``pmproxy``.
|
| CVE-2026-16524 |
|
OS Command Injection in CVE-2026-16524 (CVE-2026-16524)
OS command injection in CVE-2026-16524 (CVE-2026-16524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16526 |
|
Vulnerability in CVE-2026-16526 (CVE-2026-16526)
vulnerability in CVE-2026-16526 (CVE-2026-16526). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47858 |
|
Vulnerability in spring (CVE-2026-47858)
vulnerability in spring (CVE-2026-47858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64635 |
|
Vulnerability in CVE-2026-64635 (CVE-2026-64635)
vulnerability in CVE-2026-64635 (CVE-2026-64635). Confidential information can be exposed externally.
|
| CVE-2026-59328 |
|
Cross-Site Scripting (XSS) in spring (CVE-2026-59328)
cross-site scripting in spring (CVE-2026-59328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15257 |
|
Vulnerability in wordpress (CVE-2026-15257)
vulnerability in wordpress (CVE-2026-15257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14318 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14318)
cross-site scripting in wordpress (CVE-2026-14318). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15382 |
|
Vulnerability in wordpress (CVE-2026-15382)
vulnerability in wordpress (CVE-2026-15382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15252 |
|
Vulnerability in wordpress (CVE-2026-15252)
vulnerability in wordpress (CVE-2026-15252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14592 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14592)
cross-site scripting in wordpress (CVE-2026-14592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15240 |
|
Authentication Bypass in c (CVE-2026-15240)
authentication bypass in c (CVE-2026-15240). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15054 |
|
Vulnerability in wordpress (CVE-2026-15054)
vulnerability in wordpress (CVE-2026-15054). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14923 |
|
Authorization Flaw in wordpress (CVE-2026-14923)
vulnerability in wordpress (CVE-2026-14923). Confidential information can be exposed externally.
|
| CVE-2026-14223 |
|
Vulnerability in wordpress (CVE-2026-14223)
vulnerability in wordpress (CVE-2026-14223). Risk of unauthorized operations or information disclosure.
|