Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-56375 |
|
Vulnerability in dos (CVE-2026-56375)
vulnerability in dos (CVE-2026-56375). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56349 |
|
Vulnerability in CVE-2026-56349 (CVE-2026-56349)
vulnerability in CVE-2026-56349 (CVE-2026-56349). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56353 |
|
Authentication Bypass in n8n (CVE-2026-56353)
authentication bypass in n8n (CVE-2026-56353). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.123.22` or later.
|
| CVE-2026-56352 |
|
Path Traversal in CVE-2026-56352 (CVE-2026-56352)
path traversal in CVE-2026-56352 (CVE-2026-56352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8281 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-58077 |
|
Cross-Site Scripting (XSS) in CVE-2026-58077 (CVE-2026-58077)
cross-site scripting in CVE-2026-58077 (CVE-2026-58077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40633 |
|
Vulnerability in dell (CVE-2026-40633)
vulnerability in dell (CVE-2026-40633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57821 |
|
SQL Injection in apache (CVE-2026-57821)
SQL injection in apache (CVE-2026-57821). Confidential information can be exposed externally. Exploitable via `GET /api/v1/offices`.
|
| CVE-2026-57833 |
|
Cross-Site Scripting (XSS) in CVE-2026-57833 (CVE-2026-57833)
cross-site scripting in CVE-2026-57833 (CVE-2026-57833). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49501 |
|
Privilege Escalation in dell (CVE-2026-49501)
vulnerability in dell (CVE-2026-49501). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56287 |
|
SQL Injection in apache (CVE-2026-56287)
SQL injection in apache (CVE-2026-56287). Confidential information can be exposed externally. Exploitable via `GET /api/v1/clients`.
|
| CVE-2026-59235 |
|
Vulnerability in CVE-2026-59235 (CVE-2026-59235)
vulnerability in CVE-2026-59235 (CVE-2026-59235). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/bank-account`.
|
| CVE-2026-35152 |
|
SQL Injection in apache (CVE-2026-35152)
SQL injection in apache (CVE-2026-35152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57831 |
|
The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
|
| CVE-2026-14251 |
|
Vulnerability in dos (CVE-2026-14251)
vulnerability in dos (CVE-2026-14251). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57832 |
|
The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection.
|
| CVE-2026-15583 |
|
Vulnerability in ssrf (CVE-2026-15583)
vulnerability in ssrf (CVE-2026-15583). Confidential information can be exposed externally.
|
| CVE-2026-15804 |
|
SQL Injection in sqli (CVE-2026-15804)
SQL injection in sqli (CVE-2026-15804). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42936 |
|
Vulnerability in jvn (CVE-2026-42936)
vulnerability in jvn (CVE-2026-42936). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12512 |
|
SQL Injection in wordpress (CVE-2026-12512)
SQL injection in wordpress (CVE-2026-12512). Confidential information can be exposed externally.
|
| CVE-2026-12281 |
|
Authentication Bypass in wordpress (CVE-2026-12281)
authentication bypass in wordpress (CVE-2026-12281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11579 |
|
Unrestricted File Upload in wordpress (CVE-2026-11579)
vulnerability in wordpress (CVE-2026-11579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11580 |
|
Vulnerability in wordpress (CVE-2026-11580)
vulnerability in wordpress (CVE-2026-11580). Confidential information can be exposed externally.
|
| CVE-2026-13385 |
|
Vulnerability in CVE-2026-13385 (CVE-2026-13385)
vulnerability in CVE-2026-13385 (CVE-2026-13385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8919 |
|
Vulnerability in CVE-2026-8919 (CVE-2026-8919)
vulnerability in CVE-2026-8919 (CVE-2026-8919). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11851 |
|
SQL Injection in sqli (CVE-2026-11851)
SQL injection in sqli (CVE-2026-11851). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8920 |
|
Vulnerability in CVE-2026-8920 (CVE-2026-8920)
vulnerability in CVE-2026-8920 (CVE-2026-8920). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13585 |
|
Vulnerability in dos (CVE-2026-13585)
vulnerability in dos (CVE-2026-13585). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15030 |
|
Out-of-Bounds Read in CVE-2026-15030 (CVE-2026-15030)
vulnerability in CVE-2026-15030 (CVE-2026-15030). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15029 |
|
Vulnerability in CVE-2026-15029 (CVE-2026-15029)
vulnerability in CVE-2026-15029 (CVE-2026-15029). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9770 |
|
Vulnerability in tp-link (CVE-2026-9770)
vulnerability in tp-link (CVE-2026-9770). Confidential information can be exposed externally.
|
| CVE-2026-13230 |
|
Information Disclosure in tp-link (CVE-2026-13230)
vulnerability in tp-link (CVE-2026-13230). Confidential information can be exposed externally.
|
| CVE-2023-4346 KEV |
|
[KEV] Vulnerability in Knx association knx (CVE-2023-4346)
vulnerability in Knx association knx (CVE-2023-4346). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-5270 |
|
Authentication Bypass in CVE-2026-5270 (CVE-2026-5270)
authentication bypass in CVE-2026-5270 (CVE-2026-5270). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5269 |
|
Vulnerability in CVE-2026-5269 (CVE-2026-5269)
vulnerability in CVE-2026-5269 (CVE-2026-5269). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51808 |
|
Vulnerability in cpp (CVE-2026-51808)
vulnerability in cpp (CVE-2026-51808). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51807 |
|
Vulnerability in cpp (CVE-2026-51807)
vulnerability in cpp (CVE-2026-51807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36035 |
|
Vulnerability in dos (CVE-2026-36035)
vulnerability in dos (CVE-2026-36035). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15753 |
|
Vulnerability in CVE-2026-15753 (CVE-2026-15753)
vulnerability in CVE-2026-15753 (CVE-2026-15753). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15752 |
|
Vulnerability in CVE-2026-15752 (CVE-2026-15752)
vulnerability in CVE-2026-15752 (CVE-2026-15752). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15751 |
|
Path Traversal in path-traversal (CVE-2026-15751)
path traversal in path-traversal (CVE-2026-15751). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56365 |
|
Vulnerability in csa-iot (CVE-2025-56365)
vulnerability in csa-iot (CVE-2025-56365). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56364 |
|
Vulnerability in dos (CVE-2025-56364)
vulnerability in dos (CVE-2025-56364). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56363 |
|
Vulnerability in dos (CVE-2025-56363)
vulnerability in dos (CVE-2025-56363). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56362 |
|
Vulnerability in dos (CVE-2025-56362)
vulnerability in dos (CVE-2025-56362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59733 |
|
Path Traversal in github.com/rclone/rclone (CVE-2026-59733)
path traversal in github.com/rclone/rclone (CVE-2026-59733). Successful exploitation can lead to full system takeover. Exploitable via `GET /test/../victim/config`. Mitigation: upgrade to `1.74.4` or later.
|
| CVE-2026-59732 |
|
Path Traversal in github.com/rclone/rclone (CVE-2026-59732)
path traversal in github.com/rclone/rclone (CVE-2026-59732). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /bucket/safe/prefix/escaped-from-prefix.txt`. Mitigation: upgrade to `1.74.4` or later.
|
| CVE-2026-54684 |
|
Path Traversal in CVE-2026-54684 (CVE-2026-54684)
path traversal in CVE-2026-54684 (CVE-2026-54684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54572 |
|
Vulnerability in github.com/rclone/rclone (CVE-2026-54572)
vulnerability in github.com/rclone/rclone (CVE-2026-54572). Data can be tampered with by attackers. Exploitable via ``mkdirAll``. Mitigation: upgrade to `1.74.4` or later.
|
| CVE-2026-50130 |
|
Vulnerability in pi-hole (CVE-2026-50130)
vulnerability in pi-hole (CVE-2026-50130). Successful exploitation can lead to full system takeover.
|