Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-4104 SQL Injection in sqli (CVE-2026-4104)
SQL injection in sqli (CVE-2026-4104). Successful exploitation can lead to full system takeover.
CVE-2026-50225 Vulnerability in acer (CVE-2026-50225)
vulnerability in acer (CVE-2026-50225). Data can be tampered with by attackers.
CVE-2026-50214 Vulnerability in acer (CVE-2026-50214)
vulnerability in acer (CVE-2026-50214). Successful exploitation can lead to full system takeover.
CVE-2026-50211 Vulnerability in acer (CVE-2026-50211)
vulnerability in acer (CVE-2026-50211). Successful exploitation can lead to full system takeover.
CVE-2026-50208 Vulnerability in acer (CVE-2026-50208)
vulnerability in acer (CVE-2026-50208). Confidential information can be exposed externally.
CVE-2026-49191 Authentication Bypass in acer (CVE-2026-49191)
authentication bypass in acer (CVE-2026-49191). Successful exploitation can lead to full system takeover.
CVE-2026-49188 Vulnerability in acer (CVE-2026-49188)
vulnerability in acer (CVE-2026-49188). Successful exploitation can lead to full system takeover.
CVE-2026-49186 Authentication Bypass in acer (CVE-2026-49186)
authentication bypass in acer (CVE-2026-49186). Successful exploitation can lead to full system takeover.
CVE-2026-49185 OS Command Injection in acer (CVE-2026-49185)
OS command injection in acer (CVE-2026-49185). Successful exploitation can lead to full system takeover.
CVE-2026-41283 Authorization Flaw in mistral (CVE-2026-41283)
vulnerability in mistral (CVE-2026-41283). Successful exploitation can lead to full system takeover.
CVE-2026-44182 Vulnerability in jupyter_enterprise_gateway (CVE-2026-44182)
vulnerability in jupyter_enterprise_gateway (CVE-2026-44182). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/kernels`. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-44181 Vulnerability in jupyter_enterprise_gateway (CVE-2026-44181)
vulnerability in jupyter_enterprise_gateway (CVE-2026-44181). Successful exploitation can lead to full system takeover. Exploitable via ``KERNEL_XXX``. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-44180 Vulnerability in jupyter_enterprise_gateway (CVE-2026-44180)
vulnerability in jupyter_enterprise_gateway (CVE-2026-44180). Successful exploitation can lead to full system takeover. Exploitable via ``KERNEL_UID``. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-46266 Vulnerability in linux (CVE-2026-46266)
vulnerability in linux (CVE-2026-46266). Data can be tampered with by attackers.
CVE-2026-46244 Vulnerability in c (CVE-2026-46244)
vulnerability in c (CVE-2026-46244). Confidential information can be exposed externally.
CVE-2026-36748 Cross-Site Scripting (XSS) in CVE-2026-36748 (CVE-2026-36748)
cross-site scripting in CVE-2026-36748 (CVE-2026-36748). Successful exploitation can lead to full system takeover.
CVE-2026-36576 OS Command Injection in CVE-2026-36576 (CVE-2026-36576)
OS command injection in CVE-2026-36576 (CVE-2026-36576). Successful exploitation can lead to full system takeover.
CVE-2026-10768 Vulnerability in drupal/localgov_workflows (CVE-2026-10768)
vulnerability in drupal/localgov_workflows (CVE-2026-10768). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.6.0` or later.
CVE-2026-5241 Vulnerability in transformers (CVE-2026-5241)
vulnerability in transformers (CVE-2026-5241). Successful exploitation can lead to full system takeover. Exploitable via ``trust_remote_code``. Mitigation: upgrade to `5.5.0` or later.
CVE-2026-9648 Vulnerability in crypton-x509-validation (CVE-2026-9648)
vulnerability in crypton-x509-validation (CVE-2026-9648). Confidential information can be exposed externally. Mitigation: upgrade to `1.9.1` or later.
CVE-2026-35075 Vulnerability in mbs-solutions (CVE-2026-35075)
vulnerability in mbs-solutions (CVE-2026-35075). Successful exploitation can lead to full system takeover.
CVE-2026-47065 Unsafe Deserialization in org.apache.mina:mina-core (CVE-2026-47065)
vulnerability in org.apache.mina:mina-core (CVE-2026-47065). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.0.29` or later.
CVE-2025-14771 Vulnerability in abb (CVE-2025-14771)
vulnerability in abb (CVE-2025-14771). Successful exploitation can lead to full system takeover.
CVE-2026-32625 Information Disclosure in librechat (CVE-2026-32625)
vulnerability in librechat (CVE-2026-32625). Confidential information can be exposed externally.
CVE-2026-49448 Authentication Bypass in authentik (CVE-2026-49448)
authentication bypass in authentik (CVE-2026-49448). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2025.12.6, 2026.2.4, 2026.5.1` or later.
CVE-2026-42849 Cross-Site Scripting (XSS) in authentik (CVE-2026-42849)
cross-site scripting in authentik (CVE-2026-42849). Confidential information can be exposed externally. Mitigation: upgrade to `2025.12.5, 2026.2.3` or later.
CVE-2026-5076 Authentication Bypass in wordpress (CVE-2026-5076)
authentication bypass in wordpress (CVE-2026-5076). Successful exploitation can lead to full system takeover. Exploitable via ``arm_reset_password_key``.
CVE-2026-38967 Vulnerability in CVE-2026-38967 (CVE-2026-38967)
vulnerability in CVE-2026-38967 (CVE-2026-38967). Successful exploitation can lead to full system takeover.
CVE-2026-0611 Vulnerability in csharp (CVE-2026-0611)
vulnerability in csharp (CVE-2026-0611). Successful exploitation can lead to full system takeover.
CVE-2026-47117 Code Injection in openmed (CVE-2026-47117)
code injection in openmed (CVE-2026-47117). Successful exploitation can lead to full system takeover. Exploitable via ``model_name``. Mitigation: upgrade to `1.5.2` or later.
CVE-2026-7312 Vulnerability in progress (CVE-2026-7312)
vulnerability in progress (CVE-2026-7312). Confidential information can be exposed externally.
CVE-2026-7198 Vulnerability in progress (CVE-2026-7198)
vulnerability in progress (CVE-2026-7198). Successful exploitation can lead to full system takeover.
CVE-2026-10611 Authentication Bypass in misp (CVE-2026-10611)
authentication bypass in misp (CVE-2026-10611). Successful exploitation can lead to full system takeover.
CVE-2026-42684 SQL Injection in sqli (CVE-2026-42684)
SQL injection in sqli (CVE-2026-42684). Confidential information can be exposed externally.
CVE-2025-53209 Vulnerability in privilege-escalation (CVE-2025-53209)
vulnerability in privilege-escalation (CVE-2025-53209). Successful exploitation can lead to full system takeover.
CVE-2026-8206 Privilege Escalation in wordpress (CVE-2026-8206)
vulnerability in wordpress (CVE-2026-8206). Successful exploitation can lead to full system takeover.
CVE-2026-40965 Information Disclosure in CVE-2026-40965 (CVE-2026-40965)
vulnerability in CVE-2026-40965 (CVE-2026-40965). Confidential information can be exposed externally. Mitigation: upgrade to `78.13.0` or later.
CVE-2018-25427 Vulnerability in CVE-2018-25427 (CVE-2018-25427)
vulnerability in CVE-2018-25427 (CVE-2018-25427). Successful exploitation can lead to full system takeover.
CVE-2026-8644 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-9311 Code Injection in ibm (CVE-2026-9311)
code injection in ibm (CVE-2026-9311). Successful exploitation can lead to full system takeover.
CVE-2026-9319 Unsafe Deserialization in deserialization (CVE-2026-9319)
vulnerability in deserialization (CVE-2026-9319). Successful exploitation can lead to full system takeover.
CVE-2026-45131 Code Injection in CVE-2026-45131 (CVE-2026-45131)
code injection in CVE-2026-45131 (CVE-2026-45131). Confidential information can be exposed externally.
CVE-2026-45132 Code Injection in CVE-2026-45132 (CVE-2026-45132)
code injection in CVE-2026-45132 (CVE-2026-45132). Confidential information can be exposed externally.
CVE-2026-42672 SQL Injection in sqli (CVE-2026-42672)
SQL injection in sqli (CVE-2026-42672). Confidential information can be exposed externally.
CVE-2026-48866 Path Traversal in path-traversal (CVE-2026-48866)
path traversal in path-traversal (CVE-2026-48866). Successful exploitation can lead to full system takeover.
CVE-2026-42682 Vulnerability in CVE-2026-42682 (CVE-2026-42682)
vulnerability in CVE-2026-42682 (CVE-2026-42682). Data can be tampered with by attackers.
CVE-2026-42680 Vulnerability in privilege-escalation (CVE-2026-42680)
vulnerability in privilege-escalation (CVE-2026-42680). Successful exploitation can lead to full system takeover.
CVE-2026-48879 Vulnerability in privilege-escalation (CVE-2026-48879)
vulnerability in privilege-escalation (CVE-2026-48879). Successful exploitation can lead to full system takeover.
CVE-2026-47413 Privilege Escalation in praisonai-platform (CVE-2026-47413)
vulnerability in praisonai-platform (CVE-2026-47413). Confidential information can be exposed externally. Exploitable via `POST /workspaces/{workspace_id}/members`. Mitigation: upgrade to `0.1.4` or later.
CVE-2026-47428 Cross-Site Scripting (XSS) in @vitest/browser (CVE-2026-47428)
cross-site scripting in @vitest/browser (CVE-2026-47428). Successful exploitation can lead to full system takeover. Exploitable via ``otelCarrier``. Mitigation: upgrade to `5.0.0-beta.3` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →