Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-13171 Vulnerability in wordpress (CVE-2026-13171)
vulnerability in wordpress (CVE-2026-13171). Data can be tampered with by attackers.
CVE-2026-13613 SQL Injection in wordpress (CVE-2026-13613)
SQL injection in wordpress (CVE-2026-13613). Successful exploitation can lead to full system takeover.
CVE-2026-64954 Vulnerability in CVE-2026-64954 (CVE-2026-64954)
vulnerability in CVE-2026-64954 (CVE-2026-64954). Confidential information can be exposed externally.
CVE-2026-12234 Vulnerability in c (CVE-2026-12234)
vulnerability in c (CVE-2026-12234). Successful exploitation can lead to full system takeover.
CVE-2026-18961 Authentication Bypass in wordpress (CVE-2026-18961)
authentication bypass in wordpress (CVE-2026-18961). Successful exploitation can lead to full system takeover.
CVE-2026-73122 Privilege Escalation in CVE-2026-73122 (CVE-2026-73122)
vulnerability in CVE-2026-73122 (CVE-2026-73122). Confidential information can be exposed externally.
CVE-2026-66878 Vulnerability in CVE-2026-66878 (CVE-2026-66878)
vulnerability in CVE-2026-66878 (CVE-2026-66878). Confidential information can be exposed externally.
CVE-2026-6484 In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
CVE-2026-68447 Vulnerability in CVE-2026-68447 (CVE-2026-68447)
vulnerability in CVE-2026-68447 (CVE-2026-68447). Confidential information can be exposed externally.
CVE-2026-68445 Vulnerability in CVE-2026-68445 (CVE-2026-68445)
vulnerability in CVE-2026-68445 (CVE-2026-68445). Successful exploitation can lead to full system takeover.
CVE-2026-68442 Vulnerability in CVE-2026-68442 (CVE-2026-68442)
vulnerability in CVE-2026-68442 (CVE-2026-68442). Successful exploitation can lead to full system takeover.
CVE-2026-68446 Vulnerability in CVE-2026-68446 (CVE-2026-68446)
vulnerability in CVE-2026-68446 (CVE-2026-68446). Successful exploitation can lead to full system takeover.
CVE-2026-68440 Vulnerability in CVE-2026-68440 (CVE-2026-68440)
vulnerability in CVE-2026-68440 (CVE-2026-68440). Successful exploitation can lead to full system takeover.
CVE-2026-68433 Vulnerability in CVE-2026-68433 (CVE-2026-68433)
vulnerability in CVE-2026-68433 (CVE-2026-68433). Risk of unauthorized operations or information disclosure.
CVE-2026-68432 Vulnerability in CVE-2026-68432 (CVE-2026-68432)
vulnerability in CVE-2026-68432 (CVE-2026-68432). Successful exploitation can lead to full system takeover.
CVE-2026-73249 Vulnerability in CVE-2026-73249 (CVE-2026-73249)
vulnerability in CVE-2026-73249 (CVE-2026-73249). Data can be tampered with by attackers. Exploitable via `POST /book-update-annotations/{library_id}/{book_id}/{fmt}`.
CVE-2026-73247 SSRF (Server-Side Request Forgery) in CVE-2026-73247 (CVE-2026-73247)
SSRF in CVE-2026-73247 (CVE-2026-73247). Confidential information can be exposed externally.
CVE-2026-73246 Information Disclosure in CVE-2026-73246 (CVE-2026-73246)
vulnerability in CVE-2026-73246 (CVE-2026-73246). Confidential information can be exposed externally. Exploitable via `GET /worker`. Mitigation: upgrade to `2.0.0-rc6` or later.
CVE-2026-67558 Vulnerability in CVE-2026-67558 (CVE-2026-67558)
vulnerability in CVE-2026-67558 (CVE-2026-67558). Confidential information can be exposed externally.
CVE-2026-66875 Vulnerability in CVE-2026-66875 (CVE-2026-66875)
vulnerability in CVE-2026-66875 (CVE-2026-66875). Successful exploitation can lead to full system takeover.
CVE-2026-5917 OS Command Injection in c (CVE-2026-5917)
OS command injection in c (CVE-2026-5917). Successful exploitation can lead to full system takeover.
CVE-2026-29036 Vulnerability in c (CVE-2026-29036)
vulnerability in c (CVE-2026-29036). Data can be tampered with by attackers.
CVE-2026-19560 Use-After-Free in google (CVE-2026-19560)
vulnerability in google (CVE-2026-19560). Successful exploitation can lead to full system takeover.
CVE-2026-19559 Use-After-Free in google (CVE-2026-19559)
vulnerability in google (CVE-2026-19559). Successful exploitation can lead to full system takeover.
CVE-2026-19558 Use-After-Free in google (CVE-2026-19558)
vulnerability in google (CVE-2026-19558). Successful exploitation can lead to full system takeover.
CVE-2026-19557 Use-After-Free in google (CVE-2026-19557)
vulnerability in google (CVE-2026-19557). Successful exploitation can lead to full system takeover.
CVE-2026-19556 Use-After-Free in Google chrome (CVE-2026-19556)
vulnerability in Google chrome (CVE-2026-19556). Successful exploitation can lead to full system takeover.
CVE-2026-66154 Vulnerability in CVE-2026-66154 (CVE-2026-66154)
vulnerability in CVE-2026-66154 (CVE-2026-66154). Successful exploitation can lead to full system takeover.
CVE-2026-66149 Code Injection in CVE-2026-66149 (CVE-2026-66149)
code injection in CVE-2026-66149 (CVE-2026-66149). Successful exploitation can lead to full system takeover.
CVE-2026-66150 Code Injection in CVE-2026-66150 (CVE-2026-66150)
code injection in CVE-2026-66150 (CVE-2026-66150). Successful exploitation can lead to full system takeover.
CVE-2026-15606 Vulnerability in wordpress (CVE-2026-15606)
vulnerability in wordpress (CVE-2026-15606). Successful exploitation can lead to full system takeover.
CVE-2026-19550 Authorization Flaw in redhat (CVE-2026-19550)
vulnerability in redhat (CVE-2026-19550). Confidential information can be exposed externally.
CVE-2026-18634 Unsafe Deserialization in CVE-2026-18634 (CVE-2026-18634)
vulnerability in CVE-2026-18634 (CVE-2026-18634). Successful exploitation can lead to full system takeover.
CVE-2026-14863 OS Command Injection in CVE-2026-14863 (CVE-2026-14863)
OS command injection in CVE-2026-14863 (CVE-2026-14863). Successful exploitation can lead to full system takeover.
CVE-2026-63177 Authorization Flaw in nginx (CVE-2026-63177)
vulnerability in nginx (CVE-2026-63177). Confidential information can be exposed externally. Exploitable via ``ngx.var.request_uri``.
CVE-2026-55676 Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
CVE-2026-48763 Vulnerability in CVE-2026-48763 (CVE-2026-48763)
vulnerability in CVE-2026-48763 (CVE-2026-48763). Data can be tampered with by attackers. Exploitable via `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url`.
CVE-2026-73234 Path Traversal in cpp (CVE-2026-73234)
path traversal in cpp (CVE-2026-73234). Successful exploitation can lead to full system takeover.
CVE-2026-73232 Vulnerability in dos (CVE-2026-73232)
vulnerability in dos (CVE-2026-73232). Risk of unauthorized operations or information disclosure.
CVE-2026-73231 Vulnerability in CVE-2026-73231 (CVE-2026-73231)
vulnerability in CVE-2026-73231 (CVE-2026-73231). Successful exploitation can lead to full system takeover.
CVE-2026-73031 telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
CVE-2026-71467 Authentication Bypass in CVE-2026-71467 (CVE-2026-71467)
authentication bypass in CVE-2026-71467 (CVE-2026-71467). Confidential information can be exposed externally.
CVE-2026-19091 Path Traversal in wordpress (CVE-2026-19091)
path traversal in wordpress (CVE-2026-19091). Data can be tampered with by attackers.
CVE-2026-18844 Vulnerability in CVE-2026-18844 (CVE-2026-18844)
vulnerability in CVE-2026-18844 (CVE-2026-18844). Data can be tampered with by attackers.
CVE-2026-13457 Unrestricted File Upload in wordpress (CVE-2026-13457)
vulnerability in wordpress (CVE-2026-13457). Confidential information can be exposed externally.
CVE-2026-73227 Path Traversal in CVE-2026-73227 (CVE-2026-73227)
path traversal in CVE-2026-73227 (CVE-2026-73227). Data can be tampered with by attackers.
CVE-2026-73226 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions t...
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handle...
CVE-2026-73225 Path Traversal in CVE-2026-73225 (CVE-2026-73225)
path traversal in CVE-2026-73225 (CVE-2026-73225). Data can be tampered with by attackers.
CVE-2026-73224 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user do...
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties and Calculate Size because calcLocal in src/client/c...
CVE-2026-73223 Path Traversal in CVE-2026-73223 (CVE-2026-73223)
path traversal in CVE-2026-73223 (CVE-2026-73223). Data can be tampered with by attackers.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →