Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-45289 |
|
Authentication Bypass in CVE-2026-45289 (CVE-2026-45289)
authentication bypass in CVE-2026-45289 (CVE-2026-45289). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5076 |
|
Authentication Bypass in wordpress (CVE-2026-5076)
authentication bypass in wordpress (CVE-2026-5076). Successful exploitation can lead to full system takeover. Exploitable via ``arm_reset_password_key``.
|
| CVE-2026-10617 |
|
Authentication Bypass in CVE-2026-10617 (CVE-2026-10617)
authentication bypass in CVE-2026-10617 (CVE-2026-10617). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10611 |
|
Authentication Bypass in misp (CVE-2026-10611)
authentication bypass in misp (CVE-2026-10611). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8293 |
|
Authentication Bypass in wordpress (CVE-2026-8293)
authentication bypass in wordpress (CVE-2026-8293). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10548 |
|
Authentication Bypass in CVE-2026-10548 (CVE-2026-10548)
authentication bypass in CVE-2026-10548 (CVE-2026-10548). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-0492 KEV |
|
[KEV] Authentication Bypass in Linux c (CVE-2022-0492)
authentication bypass in Linux c (CVE-2022-0492). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-40964 |
|
Authentication Bypass in CVE-2026-40964 (CVE-2026-40964)
authentication bypass in CVE-2026-40964 (CVE-2026-40964). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.7` or later.
|
| CVE-2026-10288 |
|
Authentication Bypass in CVE-2026-10288 (CVE-2026-10288)
authentication bypass in CVE-2026-10288 (CVE-2026-10288). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45690 |
|
Authentication Bypass in nextcloud (CVE-2026-45690)
authentication bypass in nextcloud (CVE-2026-45690). Data can be tampered with by attackers.
|
| CVE-2026-45691 |
|
Authentication Bypass in nextcloud (CVE-2026-45691)
authentication bypass in nextcloud (CVE-2026-45691). Data can be tampered with by attackers.
|
| CVE-2026-45283 |
|
Authentication Bypass in nextcloud (CVE-2026-45283)
authentication bypass in nextcloud (CVE-2026-45283). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10281 |
|
Authentication Bypass in @enderfga/claw-orchestrator (CVE-2026-10281)
authentication bypass in @enderfga/claw-orchestrator (CVE-2026-10281). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.5.6` or later.
|
| CVE-2026-10283 |
|
Authentication Bypass in CVE-2026-10283 (CVE-2026-10283)
authentication bypass in CVE-2026-10283 (CVE-2026-10283). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45156 |
|
Authentication Bypass in CVE-2026-45156 (CVE-2026-45156)
authentication bypass in CVE-2026-45156 (CVE-2026-45156). Confidential information can be exposed externally.
|
| CVE-2026-45153 |
|
Authentication Bypass in CVE-2026-45153 (CVE-2026-45153)
authentication bypass in CVE-2026-45153 (CVE-2026-45153). Confidential information can be exposed externally.
|
| CVE-2026-10243 |
|
Authentication Bypass in CVE-2026-10243 (CVE-2026-10243)
authentication bypass in CVE-2026-10243 (CVE-2026-10243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10167 |
|
Authentication Bypass in CVE-2026-10167 (CVE-2026-10167)
authentication bypass in CVE-2026-10167 (CVE-2026-10167). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10157 |
|
Authentication Bypass in c (CVE-2026-10157)
authentication bypass in c (CVE-2026-10157). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46705 |
|
Authentication Bypass in russh (CVE-2026-46705)
authentication bypass in russh (CVE-2026-46705). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.0` or later.
|
| CVE-2026-46579 |
|
Authentication Bypass in redhat (CVE-2026-46579)
authentication bypass in redhat (CVE-2026-46579). Confidential information can be exposed externally. Exploitable via ``insecureEdgeTerminationPolicy``.
|
| CVE-2026-49197 |
|
Authentication Bypass in acer (CVE-2026-49197)
authentication bypass in acer (CVE-2026-49197). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`.
|
| CVE-2026-3655 |
|
Authentication Bypass in wordpress (CVE-2026-3655)
authentication bypass in wordpress (CVE-2026-3655). Successful exploitation can lead to full system takeover. Exploitable via ``lwp_ajax_register``.
|
| CVE-2026-46840 |
|
Vulnerability in c (CVE-2026-46840)
vulnerability in c (CVE-2026-46840). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46827 |
|
Privilege Escalation in c (CVE-2026-46827)
vulnerability in c (CVE-2026-46827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46817 KEV |
|
[KEV] Privilege Escalation in Oracle c (CVE-2026-46817)
vulnerability in Oracle c (CVE-2026-46817). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-47718 |
|
Authentication Bypass in fuxa-server (CVE-2026-47718)
authentication bypass in fuxa-server (CVE-2026-47718). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/project`. Mitigation: upgrade to `1.3.1` or later.
|
| CVE-2026-45754 |
|
Authentication Bypass in symfony/lox24-notifier (CVE-2026-45754)
authentication bypass in symfony/lox24-notifier (CVE-2026-45754). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-48526 |
|
Authentication Bypass in pyjwt (CVE-2026-48526)
authentication bypass in pyjwt (CVE-2026-48526). Confidential information can be exposed externally. Mitigation: upgrade to `2.13.0` or later.
|
| CVE-2026-8979 |
|
Authentication Bypass in CVE-2026-8979 (CVE-2026-8979)
authentication bypass in CVE-2026-8979 (CVE-2026-8979). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44711 |
|
Vulnerability in CVE-2026-44711 (CVE-2026-44711)
vulnerability in CVE-2026-44711 (CVE-2026-44711). Data can be tampered with by attackers. Mitigation: upgrade to `0.8.7` or later.
|
| CVE-2026-47272 |
|
Authentication Bypass in c (CVE-2026-47272)
authentication bypass in c (CVE-2026-47272). Confidential information can be exposed externally. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-44460 |
|
Information Disclosure in CVE-2026-44460 (CVE-2026-44460)
vulnerability in CVE-2026-44460 (CVE-2026-44460). Confidential information can be exposed externally. Mitigation: upgrade to `3.12.0` or later.
|
| CVE-2025-68712 |
|
Vulnerability in c (CVE-2025-68712)
vulnerability in c (CVE-2025-68712). Confidential information can be exposed externally.
|
| CVE-2026-7876 |
|
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
|
| CVE-2026-8994 |
|
Authentication Bypass in wordpress (CVE-2026-8994)
authentication bypass in wordpress (CVE-2026-8994). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv``.
|
| CVE-2026-44847 |
|
Authentication Bypass in django (CVE-2026-44847)
authentication bypass in django (CVE-2026-44847). Data can be tampered with by attackers. Mitigation: upgrade to `2.9.0` or later.
|
| CVE-2026-47202 |
|
Authentication Bypass in CVE-2026-47202 (CVE-2026-47202)
authentication bypass in CVE-2026-47202 (CVE-2026-47202). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.9.0.2` or later.
|
| CVE-2026-44707 |
|
Vulnerability in CVE-2026-44707 (CVE-2026-44707)
vulnerability in CVE-2026-44707 (CVE-2026-44707). Confidential information can be exposed externally. Mitigation: upgrade to `4.13.0` or later.
|
| CVE-2026-48896 |
|
Joomla! Core - [20260511] - MFA Authentication Bypass
Joomla! Core - [20260511] - MFA Authentication Bypass
|
| CVE-2026-48897 |
|
Joomla! Core - [20260512] - MFA Authentication Bypass
Joomla! Core - [20260512] - MFA Authentication Bypass
|
| CVE-2026-9398 |
|
Authentication Bypass in CVE-2026-9398 (CVE-2026-9398)
authentication bypass in CVE-2026-9398 (CVE-2026-9398). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9371 |
|
Authentication Bypass in CVE-2026-9371 (CVE-2026-9371)
authentication bypass in CVE-2026-9371 (CVE-2026-9371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9373 |
|
Authentication Bypass in CVE-2026-9373 (CVE-2026-9373)
authentication bypass in CVE-2026-9373 (CVE-2026-9373). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47280 |
|
Authentication Bypass in microsoft (CVE-2026-47280)
authentication bypass in microsoft (CVE-2026-47280). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41076 |
|
Authentication Bypass in CVE-2026-41076 (CVE-2026-41076)
authentication bypass in CVE-2026-41076 (CVE-2026-41076). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39969 |
|
Authentication Bypass in CVE-2026-39969 (CVE-2026-39969)
authentication bypass in CVE-2026-39969 (CVE-2026-39969). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook`.
|
| CVE-2026-46715 |
|
Authentication Bypass in Flask-Security-Too (CVE-2026-46715)
authentication bypass in Flask-Security-Too (CVE-2026-46715). Risk of unauthorized operations or information disclosure. Exploitable via `POST /change-username`. Mitigation: upgrade to `5.8.1` or later.
|
| CVE-2026-32253 |
|
Authentication Bypass in cpp (CVE-2026-32253)
authentication bypass in cpp (CVE-2026-32253). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47166 |
|
Out-of-Bounds Read in Magick.NET-Q16-AnyCPU (CVE-2026-47166)
vulnerability in Magick.NET-Q16-AnyCPU (CVE-2026-47166). Confidential information can be exposed externally. Mitigation: upgrade to `14.12.0` or later.
|