Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42742 |
|
SQL Injection in sqli (CVE-2026-42742)
SQL injection in sqli (CVE-2026-42742). Confidential information can be exposed externally.
|
| CVE-2026-45211 |
|
SQL Injection in sqli (CVE-2026-45211)
SQL injection in sqli (CVE-2026-45211). Confidential information can be exposed externally.
|
| CVE-2026-45213 |
|
SQL Injection in sqli (CVE-2026-45213)
SQL injection in sqli (CVE-2026-45213). Confidential information can be exposed externally.
|
| CVE-2026-45214 |
|
SQL Injection in sqli (CVE-2026-45214)
SQL injection in sqli (CVE-2026-45214). Confidential information can be exposed externally.
|
| CVE-2026-2465 |
|
Authorization Flaw in privilege-escalation (CVE-2026-2465)
vulnerability in privilege-escalation (CVE-2026-2465). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41712 |
|
Vulnerability in org.springframework.ai:spring-ai-client-chat (CVE-2026-41712)
vulnerability in org.springframework.ai:spring-ai-client-chat (CVE-2026-41712). Confidential information can be exposed externally. Mitigation: upgrade to `2.0.0-M6` or later.
|
| CVE-2026-41713 |
|
Vulnerability in org.springframework.ai:spring-ai-client-chat (CVE-2026-41713)
vulnerability in org.springframework.ai:spring-ai-client-chat (CVE-2026-41713). Data can be tampered with by attackers. Mitigation: upgrade to `1.1.6` or later.
|
| CVE-2026-8162 |
|
Vulnerability in multiparty (CVE-2026-8162)
vulnerability in multiparty (CVE-2026-8162). Risk of unauthorized operations or information disclosure. Exploitable via ``decodeURI``. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2026-6001 |
|
Vulnerability in CVE-2026-6001 (CVE-2026-6001)
vulnerability in CVE-2026-6001 (CVE-2026-6001). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8159 |
|
Vulnerability in multiparty (CVE-2026-8159)
vulnerability in multiparty (CVE-2026-8159). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2026-8161 |
|
Vulnerability in multiparty (CVE-2026-8161)
vulnerability in multiparty (CVE-2026-8161). Risk of unauthorized operations or information disclosure. Exploitable via ``Object.prototype``. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2026-44411 |
|
Vulnerability in siemens (CVE-2026-44411)
vulnerability in siemens (CVE-2026-44411). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44412 |
|
Vulnerability in CVE-2026-44412 (CVE-2026-44412)
vulnerability in CVE-2026-44412 (CVE-2026-44412). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25789 |
|
Cross-Site Scripting (XSS) in CVE-2026-25789 (CVE-2026-25789)
cross-site scripting in CVE-2026-25789 (CVE-2026-25789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27662 |
|
Vulnerability in CVE-2026-27662 (CVE-2026-27662)
vulnerability in CVE-2026-27662 (CVE-2026-27662). Data can be tampered with by attackers.
|
| CVE-2026-33862 |
|
Cross-Site Scripting (XSS) in siemens (CVE-2026-33862)
cross-site scripting in siemens (CVE-2026-33862). Confidential information can be exposed externally.
|
| CVE-2026-33893 |
|
Vulnerability in siemens (CVE-2026-33893)
vulnerability in siemens (CVE-2026-33893). Confidential information can be exposed externally.
|
| CVE-2026-22925 |
|
Vulnerability in siemens (CVE-2026-22925)
vulnerability in siemens (CVE-2026-22925). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-40947 |
|
OS Command Injection in siemens (CVE-2025-40947)
OS command injection in siemens (CVE-2025-40947). Successful exploitation can lead to full system takeover.
|
| CVE-2025-40946 |
|
Vulnerability in CVE-2025-40946 (CVE-2025-40946)
vulnerability in CVE-2025-40946 (CVE-2025-40946). Data can be tampered with by attackers.
|
| CVE-2025-40833 |
|
Vulnerability in dos (CVE-2025-40833)
vulnerability in dos (CVE-2025-40833). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6690 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6690)
cross-site scripting in wordpress (CVE-2026-6690). Risk of unauthorized operations or information disclosure. Exploitable via ``wp_ajax_nopriv_lp_update_mds``.
|
| CVE-2026-39432 |
|
Vulnerability in CVE-2026-39432 (CVE-2026-39432)
vulnerability in CVE-2026-39432 (CVE-2026-39432). Confidential information can be exposed externally.
|
| CVE-2026-2993 |
|
SQL Injection in wordpress (CVE-2026-2993)
SQL injection in wordpress (CVE-2026-2993). Confidential information can be exposed externally.
|
| CVE-2026-7256 |
|
OS Command Injection in zyxel (CVE-2026-7256)
OS command injection in zyxel (CVE-2026-7256). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7287 |
|
Vulnerability in dos (CVE-2026-7287)
vulnerability in dos (CVE-2026-7287). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45430 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-45430)
vulnerability in csrf (CVE-2026-45430). Confidential information can be exposed externally.
|
| CVE-2026-34259 |
|
Command Injection in CVE-2026-34259 (CVE-2026-34259)
command injection in CVE-2026-34259 (CVE-2026-34259). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45391 |
|
Reserved. Details will be published at disclosure.
Reserved. Details will be published at disclosure.
|
| CVE-2026-45392 |
|
Reserved. Details will be published at disclosure.
Reserved. Details will be published at disclosure.
|
| CVE-2026-45393 |
|
Reserved. Details will be published at disclosure.
Reserved. Details will be published at disclosure.
|
| CVE-2026-34963 |
|
Vulnerability in c (CVE-2026-34963)
vulnerability in c (CVE-2026-34963). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43913 |
|
Authorization Flaw in dani-garcia (CVE-2026-43913)
vulnerability in dani-garcia (CVE-2026-43913). Data can be tampered with by attackers. Exploitable via `POST /api/ciphers/purge`. Mitigation: upgrade to `1.35.5` or later.
|
| CVE-2026-43914 |
|
Vulnerability in dani-garcia (CVE-2026-43914)
vulnerability in dani-garcia (CVE-2026-43914). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.35.4` or later.
|
| CVE-2026-43912 |
|
Vulnerability in dani-garcia (CVE-2026-43912)
vulnerability in dani-garcia (CVE-2026-43912). Confidential information can be exposed externally. Mitigation: upgrade to `1.35.5` or later.
|
| CVE-2026-43893 |
|
Vulnerability in exiftool-vendored (CVE-2026-43893)
vulnerability in exiftool-vendored (CVE-2026-43893). Data can be tampered with by attackers. Exploitable via ``WriteTask``. Mitigation: upgrade to `35.19.0` or later.
|
| CVE-2026-43884 |
|
SSRF (Server-Side Request Forgery) in wwbn/avideo (CVE-2026-43884)
SSRF in wwbn/avideo (CVE-2026-43884). Confidential information can be exposed externally. Exploitable via `POST /plugin/AI/receiveAsync.json.php`.
|
| CVE-2026-43886 |
|
Privilege Escalation in CVE-2026-43886 (CVE-2026-43886)
vulnerability in CVE-2026-43886 (CVE-2026-43886). Data can be tampered with by attackers. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-43887 |
|
Cross-Site Scripting (XSS) in CVE-2026-43887 (CVE-2026-43887)
cross-site scripting in CVE-2026-43887 (CVE-2026-43887). Confidential information can be exposed externally. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-43888 |
|
Path Traversal in CVE-2026-43888 (CVE-2026-43888)
path traversal in CVE-2026-43888 (CVE-2026-43888). Data can be tampered with by attackers. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-43890 |
|
Vulnerability in CVE-2026-43890 (CVE-2026-43890)
vulnerability in CVE-2026-43890 (CVE-2026-43890). Confidential information can be exposed externally. Mitigation: upgrade to `1.7.1` or later.
|
| CVE-2026-42046 |
|
Vulnerability in CVE-2026-42046 (CVE-2026-42046)
vulnerability in CVE-2026-42046 (CVE-2026-42046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42564 |
|
Path Traversal in path-traversal (CVE-2026-42564)
path traversal in path-traversal (CVE-2026-42564). Confidential information can be exposed externally. Mitigation: upgrade to `1.22.0` or later.
|
| CVE-2026-43873 |
|
Vulnerability in wwbn/avideo (CVE-2026-43873)
vulnerability in wwbn/avideo (CVE-2026-43873). Confidential information can be exposed externally. Exploitable via ``cloneSiteURL``.
|
| CVE-2026-39871 |
|
Vulnerability in apple (CVE-2026-39871)
vulnerability in apple (CVE-2026-39871). Confidential information can be exposed externally.
|
| CVE-2026-43661 |
|
Vulnerability in apple (CVE-2026-43661)
vulnerability in apple (CVE-2026-43661). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43654 |
|
Vulnerability in apple (CVE-2026-43654)
vulnerability in apple (CVE-2026-43654). Confidential information can be exposed externally.
|
| CVE-2026-43668 |
|
Use-After-Free in apple (CVE-2026-43668)
vulnerability in apple (CVE-2026-43668). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43660 |
|
Vulnerability in apple (CVE-2026-43660)
vulnerability in apple (CVE-2026-43660). Confidential information can be exposed externally.
|
| CVE-2026-43656 |
|
Out-of-Bounds Write in apple (CVE-2026-43656)
out-of-bounds write in apple (CVE-2026-43656). Risk of unauthorized operations or information disclosure.
|