Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64266 |
|
Use-After-Free in linux (CVE-2026-64266)
vulnerability in linux (CVE-2026-64266). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64265 |
|
Use-After-Free in linux (CVE-2026-64265)
vulnerability in linux (CVE-2026-64265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64264 |
|
Vulnerability in linux (CVE-2026-64264)
vulnerability in linux (CVE-2026-64264). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64263 |
|
Vulnerability in linux (CVE-2026-64263)
vulnerability in linux (CVE-2026-64263). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64262 |
|
Vulnerability in linux (CVE-2026-64262)
vulnerability in linux (CVE-2026-64262). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64261 |
|
Use-After-Free in linux (CVE-2026-64261)
vulnerability in linux (CVE-2026-64261). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64260 |
|
Vulnerability in linux (CVE-2026-64260)
vulnerability in linux (CVE-2026-64260). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64259 |
|
Use-After-Free in linux (CVE-2026-64259)
vulnerability in linux (CVE-2026-64259). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64258 |
|
Vulnerability in linux (CVE-2026-64258)
vulnerability in linux (CVE-2026-64258). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64257 |
|
Vulnerability in linux (CVE-2026-64257)
vulnerability in linux (CVE-2026-64257). Confidential information can be exposed externally.
|
| CVE-2026-64256 |
|
Vulnerability in linux (CVE-2026-64256)
vulnerability in linux (CVE-2026-64256). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16766 |
|
OS Command Injection in CVE-2026-16766 (CVE-2026-16766)
OS command injection in CVE-2026-16766 (CVE-2026-16766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15425 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15425)
cross-site scripting in wordpress (CVE-2026-15425). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14955 |
|
Path Traversal in wordpress (CVE-2026-14955)
path traversal in wordpress (CVE-2026-14955). Confidential information can be exposed externally.
|
| CVE-2026-10818 |
|
Unrestricted File Upload in wordpress (CVE-2026-10818)
vulnerability in wordpress (CVE-2026-10818). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66374 |
|
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
|
| CVE-2026-66373 |
|
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
|
| CVE-2026-66337 |
|
Out-of-Bounds Read in gnome (CVE-2026-66337)
vulnerability in gnome (CVE-2026-66337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66339 |
|
Vulnerability in gnome (CVE-2026-66339)
vulnerability in gnome (CVE-2026-66339). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-61892 |
|
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
|
| CVE-2026-66338 |
|
Vulnerability in gnome (CVE-2026-66338)
vulnerability in gnome (CVE-2026-66338). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61886 |
|
Weintek cMT3092X HMI stores user account passwords in plaintext.
Weintek cMT3092X HMI stores user account passwords in plaintext.
|
| CVE-2026-60135 |
|
An attacker can modify data that should be restricted to read‑only access.
An attacker can modify data that should be restricted to read‑only access.
|
| CVE-2026-60134 |
|
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
|
| CVE-2026-16280 |
|
Vulnerability in imaginationtech (CVE-2026-16280)
vulnerability in imaginationtech (CVE-2026-16280). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73500 |
|
Vulnerability in go.etcd.io/etcd/v3 (CVE-2026-73500)
vulnerability in go.etcd.io/etcd/v3 (CVE-2026-73500). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.33` or later.
|
| GHSA-8q49-2h5h-434x |
|
SSRF (Server-Side Request Forgery) in @frontmcp/adapters (GHSA-8q49-2h5h-434x)
SSRF in @frontmcp/adapters (GHSA-8q49-2h5h-434x). Risk of unauthorized operations or information disclosure. Exploitable via ``OpenApiSpecPoller``. Mitigation: upgrade to `1.5.6` or later.
|
| CVE-2026-73502 |
|
Vulnerability in github.com/getkin/kin-openapi (CVE-2026-73502)
vulnerability in github.com/getkin/kin-openapi (CVE-2026-73502). Risk of unauthorized operations or information disclosure. Exploitable via ``HEAD``. Mitigation: upgrade to `0.144.0` or later.
|
| CVE-2026-73499 |
|
Authorization Flaw in go.etcd.io/etcd/v3 (CVE-2026-73499)
vulnerability in go.etcd.io/etcd/v3 (CVE-2026-73499). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.33` or later.
|
| CVE-2026-73568 |
|
Vulnerability in libp2p (CVE-2026-73568)
vulnerability in libp2p (CVE-2026-73568). Risk of unauthorized operations or information disclosure. Exploitable via ``length``.
|
| CVE-2026-73647 |
|
Vulnerability in quasar (CVE-2026-73647)
vulnerability in quasar (CVE-2026-73647). Risk of unauthorized operations or information disclosure. Exploitable via ``__proto__``. Mitigation: upgrade to `2.22.0` or later.
|
| CVE-2026-73505 |
|
Code Injection in github.com/jandedobbeleer/oh-my-posh (CVE-2026-73505)
code injection in github.com/jandedobbeleer/oh-my-posh (CVE-2026-73505). Successful exploitation can lead to full system takeover. Exploitable via ``cmd``. Mitigation: upgrade to `29.35.1` or later.
|
| CVE-2026-73506 |
|
Vulnerability in github.com/jandedobbeleer/oh-my-posh (CVE-2026-73506)
vulnerability in github.com/jandedobbeleer/oh-my-posh (CVE-2026-73506). Risk of unauthorized operations or information disclosure. Exploitable via ``formats.EscapeSequences``. Mitigation: upgrade to `29.35.1` or later.
|
| GHSA-fp43-vj7g-pg92 |
|
Cross-Site Scripting (XSS) in org.omnifaces:omnifaces (GHSA-fp43-vj7g-pg92)
cross-site scripting in org.omnifaces:omnifaces (GHSA-fp43-vj7g-pg92). Risk of unauthorized operations or information disclosure. Exploitable via ``CombinedResourceInfo``. Mitigation: upgrade to `5.4.2` or later.
|
| CVE-2026-73413 |
|
Vulnerability in shescape (CVE-2026-73413)
vulnerability in shescape (CVE-2026-73413). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73411 |
|
Vulnerability in shescape (CVE-2026-73411)
vulnerability in shescape (CVE-2026-73411). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73414 |
|
OS Command Injection in shescape (CVE-2026-73414)
OS command injection in shescape (CVE-2026-73414). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73412 |
|
OS Command Injection in shescape (CVE-2026-73412)
OS command injection in shescape (CVE-2026-73412). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-69160 |
|
Vulnerability in github.com/OpenListTeam/OpenList/v4 (CVE-2026-69160)
vulnerability in github.com/OpenListTeam/OpenList/v4 (CVE-2026-69160). Confidential information can be exposed externally. Exploitable via `POST /api/share/create`. Mitigation: upgrade to `4.2.4` or later.
|
| GHSA-p6ph-3jx2-3337 |
|
Information Disclosure in github.com/OpenListTeam/OpenList/v4 (GHSA-p6ph-3jx2-3337)
vulnerability in github.com/OpenListTeam/OpenList/v4 (GHSA-p6ph-3jx2-3337). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/fs/search`. Mitigation: upgrade to `4.2.4` or later.
|
| CVE-2026-73509 |
|
Path Traversal in github.com/OpenListTeam/OpenList/v4 (CVE-2026-73509)
path traversal in github.com/OpenListTeam/OpenList/v4 (CVE-2026-73509). Data can be tampered with by attackers. Exploitable via ``new_name``. Mitigation: upgrade to `4.2.4` or later.
|
| CVE-2026-73493 |
|
Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `1.0.0-M42` or later.
|
| CVE-2026-73495 |
|
Vulnerability in org.http4s:blaze-http_2.13 (CVE-2026-73495)
vulnerability in org.http4s:blaze-http_2.13 (CVE-2026-73495). Confidential information can be exposed externally. Exploitable via ``Request.headers``. Mitigation: upgrade to `1.0.0-M42` or later.
|
| CVE-2026-73494 |
|
Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73494)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73494). Risk of unauthorized operations or information disclosure. Exploitable via ``BlazeServerBuilder``. Mitigation: upgrade to `0.23.18` or later.
|
| CVE-2026-55985 |
|
Vulnerability in CVE-2026-55985 (CVE-2026-55985)
vulnerability in CVE-2026-55985 (CVE-2026-55985). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71408 |
|
Vulnerability in nltk (CVE-2025-71408)
vulnerability in nltk (CVE-2025-71408). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.3` or later.
|
| GHSA-cmwh-g2h8-c222 |
|
Authentication Bypass in poweradmin/poweradmin (GHSA-cmwh-g2h8-c222)
authentication bypass in poweradmin/poweradmin (GHSA-cmwh-g2h8-c222). Risk of unauthorized operations or information disclosure. Exploitable via `GET /oidc/login`. Mitigation: upgrade to `4.2.5` or later.
|
| GHSA-rm67-g9ch-vxff |
|
Vulnerability in poweradmin/poweradmin (GHSA-rm67-g9ch-vxff)
vulnerability in poweradmin/poweradmin (GHSA-rm67-g9ch-vxff). Risk of unauthorized operations or information disclosure. Exploitable via `POST /zones/3/edit`. Mitigation: upgrade to `4.3.4` or later.
|
| GHSA-h4hf-v6w5-897x |
|
Vulnerability in poweradmin/poweradmin (GHSA-h4hf-v6w5-897x)
vulnerability in poweradmin/poweradmin (GHSA-h4hf-v6w5-897x). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/v2/users/{id}`. Mitigation: upgrade to `4.3.4` or later.
|
| GHSA-f25v-x6vr-962g |
|
Vulnerability in pheditor/pheditor (GHSA-f25v-x6vr-962g)
vulnerability in pheditor/pheditor (GHSA-f25v-x6vr-962g). Risk of unauthorized operations or information disclosure. Exploitable via ``admin``. Mitigation: upgrade to `2.0.7` or later.
|