Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-81849 |
|
Vulnerability in Amazon aws (CVE-2026-81849)
vulnerability in Amazon aws (CVE-2026-81849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55485 |
|
Information Disclosure in piccolo-admin (CVE-2026-55485)
vulnerability in piccolo-admin (CVE-2026-55485). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/tables/piccolo_user/2/`. Mitigation: upgrade to `1.14.0` or later.
|
| CVE-2026-55509 |
|
SQL Injection in WsgiDAV (CVE-2026-55509)
SQL injection in WsgiDAV (CVE-2026-55509). Risk of unauthorized operations or information disclosure. Exploitable via ``MySQLBrowserProvider``. Mitigation: upgrade to `4.3.5` or later.
|
| CVE-2026-55425 |
|
Vulnerability in org.graylog2:graylog2-server (CVE-2026-55425)
vulnerability in org.graylog2:graylog2-server (CVE-2026-55425). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `7.1.4` or later.
|
| CVE-2026-55566 |
|
Cross-Site Scripting (XSS) in org.yamcs:yamcs-core (CVE-2026-55566)
cross-site scripting in org.yamcs:yamcs-core (CVE-2026-55566). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55565 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55565)
code injection in org.yamcs:yamcs-core (CVE-2026-55565). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55559 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55559)
code injection in org.yamcs:yamcs-core (CVE-2026-55559). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/instances`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55552 |
|
Path Traversal in org.yamcs:yamcs-core (CVE-2026-55552)
path traversal in org.yamcs:yamcs-core (CVE-2026-55552). Confidential information can be exposed externally. Mitigation: upgrade to `5.12.0` or later.
|
| CVE-2026-55549 |
|
Cross-Site Scripting (XSS) in org.yamcs:yamcs-core (CVE-2026-55549)
cross-site scripting in org.yamcs:yamcs-core (CVE-2026-55549). Confidential information can be exposed externally. Exploitable via ``fetch``. Mitigation: upgrade to `5.9.4` or later.
|
| CVE-2026-55547 |
|
Vulnerability in org.yamcs:yamcs-core (CVE-2026-55547)
vulnerability in org.yamcs:yamcs-core (CVE-2026-55547). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/roles`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55545 |
|
Vulnerability in org.yamcs:yamcs-core (CVE-2026-55545)
vulnerability in org.yamcs:yamcs-core (CVE-2026-55545). Confidential information can be exposed externally. Exploitable via ``packets``. Mitigation: upgrade to `5.13.2` or later.
|
| CVE-2026-55521 |
|
Vulnerability in org.yamcs:yamcs-core (CVE-2026-55521)
vulnerability in org.yamcs:yamcs-core (CVE-2026-55521). Successful exploitation can lead to full system takeover. Exploitable via ``SystemPrivilege``. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55511 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55511)
code injection in org.yamcs:yamcs-core (CVE-2026-55511). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55068 |
|
Vulnerability in github.com/free5gc/free5gc (CVE-2026-55068)
vulnerability in github.com/free5gc/free5gc (CVE-2026-55068). Risk of unauthorized operations or information disclosure. Exploitable via ``RegisterNFInstance``. Mitigation: upgrade to `4.2.2` or later.
|
| CVE-2026-55067 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-55067)
vulnerability in code.vikunja.io/api (CVE-2026-55067). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}`. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-55066 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-55066)
vulnerability in code.vikunja.io/api (CVE-2026-55066). Confidential information can be exposed externally. Exploitable via `POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks`. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-55065 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-55065)
vulnerability in code.vikunja.io/api (CVE-2026-55065). Data can be tampered with by attackers. Exploitable via `GET /api/v1/projects/`. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-55064 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-55064)
vulnerability in code.vikunja.io/api (CVE-2026-55064). Risk of unauthorized operations or information disclosure. Exploitable via ``ParentProjectID``. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-54766 |
|
Vulnerability in code.vikunja.io/api (CVE-2026-54766)
vulnerability in code.vikunja.io/api (CVE-2026-54766). Risk of unauthorized operations or information disclosure. Exploitable via `POST /projects`. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-54788 |
|
Vulnerability in datadog-opentelemetry (CVE-2026-54788)
vulnerability in datadog-opentelemetry (CVE-2026-54788). Risk of unauthorized operations or information disclosure. Exploitable via ``tracecontext``. Mitigation: upgrade to `0.3.3` or later.
|
| CVE-2026-55834 |
|
Open Redirect in github.com/pocket-id/pocket-id/backend (CVE-2026-55834)
vulnerability in github.com/pocket-id/pocket-id/backend (CVE-2026-55834). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.0` or later.
|
| CVE-2026-55569 |
|
Path Traversal in github.com/aquaproj/aqua/v2 (CVE-2026-55569)
path traversal in github.com/aquaproj/aqua/v2 (CVE-2026-55569). Data can be tampered with by attackers. Exploitable via ``tar.gz``. Mitigation: upgrade to `2.60.1` or later.
|
| CVE-2026-54755 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-54755)
vulnerability in github.com/klever-io/klever-go (CVE-2026-54755). Data can be tampered with by attackers. Exploitable via ``uint32``. Mitigation: upgrade to `1.7.19` or later.
|
| CVE-2026-54754 |
|
Vulnerability in github.com/klever-io/klever-go (CVE-2026-54754)
vulnerability in github.com/klever-io/klever-go (CVE-2026-54754). Data can be tampered with by attackers. Exploitable via ``MarketBuy``. Mitigation: upgrade to `1.7.19` or later.
|
| CVE-2026-82330 |
|
Out-of-Bounds Read in dos (CVE-2026-82330)
vulnerability in dos (CVE-2026-82330). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82328 |
|
Out-of-Bounds Read in dos (CVE-2026-82328)
vulnerability in dos (CVE-2026-82328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82327 |
|
Vulnerability in dos (CVE-2026-82327)
vulnerability in dos (CVE-2026-82327). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82324 |
|
Out-of-Bounds Read in dos (CVE-2026-82324)
vulnerability in dos (CVE-2026-82324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82227 |
|
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
|
| CVE-2026-82220 |
|
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.
|
| CVE-2026-82181 |
|
Vulnerability in CVE-2026-82181 (CVE-2026-82181)
vulnerability in CVE-2026-82181 (CVE-2026-82181). Confidential information can be exposed externally.
|
| CVE-2026-82112 |
|
Path Traversal in path-traversal (CVE-2026-82112)
path traversal in path-traversal (CVE-2026-82112). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82078 |
|
Vulnerability in CVE-2026-82078 (CVE-2026-82078)
vulnerability in CVE-2026-82078 (CVE-2026-82078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81767 |
|
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
|
| CVE-2026-81761 |
|
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
|
| CVE-2026-81760 |
|
Cross-Site Scripting (XSS) in CVE-2026-81760 (CVE-2026-81760)
cross-site scripting in CVE-2026-81760 (CVE-2026-81760). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81759 |
|
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
|
| CVE-2026-81757 |
|
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
|
| CVE-2026-81578 |
|
Vulnerability in CVE-2026-81578 (CVE-2026-81578)
vulnerability in CVE-2026-81578 (CVE-2026-81578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81341 |
|
Vulnerability in CVE-2026-81341 (CVE-2026-81341)
vulnerability in CVE-2026-81341 (CVE-2026-81341). Confidential information can be exposed externally.
|
| CVE-2026-81299 |
|
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.
|
| CVE-2026-81285 |
|
Vulnerability in dos (CVE-2026-81285)
vulnerability in dos (CVE-2026-81285). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81284 |
|
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.
|
| CVE-2026-81020 |
|
Vulnerability in CVE-2026-81020 (CVE-2026-81020)
vulnerability in CVE-2026-81020 (CVE-2026-81020). Confidential information can be exposed externally.
|
| CVE-2026-81019 |
|
Vulnerability in CVE-2026-81019 (CVE-2026-81019)
vulnerability in CVE-2026-81019 (CVE-2026-81019). Confidential information can be exposed externally.
|
| CVE-2026-75758 |
|
Vulnerability in CVE-2026-75758 (CVE-2026-75758)
vulnerability in CVE-2026-75758 (CVE-2026-75758). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6176 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6176)
cross-site scripting in wordpress (CVE-2026-6176). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5953 |
|
Cross-Site Scripting (XSS) in CVE-2026-5953 (CVE-2026-5953)
cross-site scripting in CVE-2026-5953 (CVE-2026-5953). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5934 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5934)
cross-site scripting in wordpress (CVE-2026-5934). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5800 |
|
Cross-Site Scripting (XSS) in CVE-2026-5800 (CVE-2026-5800)
cross-site scripting in CVE-2026-5800 (CVE-2026-5800). Risk of unauthorized operations or information disclosure.
|