Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-64206 Vulnerability in linux (CVE-2026-64206)
vulnerability in linux (CVE-2026-64206). Successful exploitation can lead to full system takeover.
CVE-2026-64191 Out-of-Bounds Read in c (CVE-2026-64191)
vulnerability in c (CVE-2026-64191). Successful exploitation can lead to full system takeover.
CVE-2026-64189 Vulnerability in c (CVE-2026-64189)
vulnerability in c (CVE-2026-64189). Successful exploitation can lead to full system takeover.
CVE-2026-64188 Use-After-Free in c (CVE-2026-64188)
vulnerability in c (CVE-2026-64188). Successful exploitation can lead to full system takeover.
CVE-2026-58484 Path Traversal in network-ai (CVE-2026-58484)
path traversal in network-ai (CVE-2026-58484). Data can be tampered with by attackers. Exploitable via ``path``. Mitigation: upgrade to `5.12.2` or later.
CVE-2026-54538 Vulnerability in neutrinolabs (CVE-2026-54538)
vulnerability in neutrinolabs (CVE-2026-54538). Risk of unauthorized operations or information disclosure.
CVE-2026-44178 Vulnerability in dos (CVE-2026-44178)
vulnerability in dos (CVE-2026-44178). Successful exploitation can lead to full system takeover.
CVE-2026-46555 Path Traversal in path-traversal (CVE-2026-46555)
path traversal in path-traversal (CVE-2026-46555). Confidential information can be exposed externally. Exploitable via `Host header`.
CVE-2026-41521 Vulnerability in dos (CVE-2026-41521)
vulnerability in dos (CVE-2026-41521). Confidential information can be exposed externally.
CVE-2026-39879 Vulnerability in c (CVE-2026-39879)
vulnerability in c (CVE-2026-39879). Risk of unauthorized operations or information disclosure. Exploitable via ``afsql_dd_run_query``.
CVE-2026-35591 Vulnerability in libvips (CVE-2026-35591)
vulnerability in libvips (CVE-2026-35591). Successful exploitation can lead to full system takeover. Exploitable via ``tiffload``.
CVE-2026-32824 Open Redirect in CVE-2026-32824 (CVE-2026-32824)
vulnerability in CVE-2026-32824 (CVE-2026-32824). Confidential information can be exposed externally. Exploitable via ``forwardToUrl``.
CVE-2026-32825 Vulnerability in rails (CVE-2026-32825)
vulnerability in rails (CVE-2026-32825). Confidential information can be exposed externally.
CVE-2026-33327 Vulnerability in libvips (CVE-2026-33327)
vulnerability in libvips (CVE-2026-33327). Successful exploitation can lead to full system takeover. Exploitable via ``vipsload``.
CVE-2026-32806 Vulnerability in CVE-2026-32806 (CVE-2026-32806)
vulnerability in CVE-2026-32806 (CVE-2026-32806). Confidential information can be exposed externally. Mitigation: upgrade to `26.06.08` or later.
CVE-2026-32821 Vulnerability in CVE-2026-32821 (CVE-2026-32821)
vulnerability in CVE-2026-32821 (CVE-2026-32821). Confidential information can be exposed externally. Exploitable via ``user_email``.
CVE-2026-32820 Path Traversal in rails (CVE-2026-32820)
path traversal in rails (CVE-2026-32820). Confidential information can be exposed externally. Exploitable via ``docs``.
CVE-2026-63429 Vulnerability in CVE-2026-63429 (CVE-2026-63429)
vulnerability in CVE-2026-63429 (CVE-2026-63429). Data can be tampered with by attackers. Exploitable via `POST /api/upload`.
CVE-2026-26197 Out-of-Bounds Read in hdfgroup (CVE-2026-26197)
vulnerability in hdfgroup (CVE-2026-26197). Confidential information can be exposed externally.
CVE-2026-28220 Unsafe Deserialization in wazuh (CVE-2026-28220)
vulnerability in wazuh (CVE-2026-28220). Successful exploitation can lead to full system takeover. Exploitable via ``ALLOWED_CALLABLES_PACKAGES``.
CVE-2026-32807 Vulnerability in CVE-2026-32807 (CVE-2026-32807)
vulnerability in CVE-2026-32807 (CVE-2026-32807). Confidential information can be exposed externally.
CVE-2026-25039 Vulnerability in CVE-2026-25039 (CVE-2026-25039)
vulnerability in CVE-2026-25039 (CVE-2026-25039). Successful exploitation can lead to full system takeover. Exploitable via ``NTLM``.
CVE-2026-21824 Vulnerability in privilege-escalation (CVE-2026-21824)
vulnerability in privilege-escalation (CVE-2026-21824). Successful exploitation can lead to full system takeover.
CVE-2026-63090 Vulnerability in c (CVE-2026-63090)
vulnerability in c (CVE-2026-63090). Successful exploitation can lead to full system takeover.
CVE-2026-62418 SSRF (Server-Side Request Forgery) in apache (CVE-2026-62418)
SSRF in apache (CVE-2026-62418). Confidential information can be exposed externally.
CVE-2026-52349 Path Traversal in path-traversal (CVE-2026-52349)
path traversal in path-traversal (CVE-2026-52349). Successful exploitation can lead to full system takeover.
CVE-2026-16252 Vulnerability in sqli (CVE-2026-16252)
vulnerability in sqli (CVE-2026-16252). Risk of unauthorized operations or information disclosure.
CVE-2026-16248 Buffer Overflow in CVE-2026-16248 (CVE-2026-16248)
vulnerability in CVE-2026-16248 (CVE-2026-16248). Successful exploitation can lead to full system takeover.
CVE-2026-12080 Vulnerability in CVE-2026-12080 (CVE-2026-12080)
vulnerability in CVE-2026-12080 (CVE-2026-12080). Successful exploitation can lead to full system takeover.
CVE-2026-54910 Path Traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910)
path traversal in github.com/gtsteffaniak/filebrowser/backend (CVE-2026-54910). Confidential information can be exposed externally. Exploitable via `GET /api/media/subtitles`. Mitigation: upgrade to `0.0.0-20260608182036-f3f4bbe80cb5` or later.
CVE-2026-63760 Vulnerability in surrealdb (CVE-2026-63760)
vulnerability in surrealdb (CVE-2026-63760). Risk of unauthorized operations or information disclosure.
CVE-2026-64622 Vulnerability in CVE-2026-64622 (CVE-2026-64622)
vulnerability in CVE-2026-64622 (CVE-2026-64622). Confidential information can be exposed externally. Exploitable via `GET /approvals/`.
CVE-2026-63763 Vulnerability in privilege-escalation (CVE-2026-63763)
vulnerability in privilege-escalation (CVE-2026-63763). Successful exploitation can lead to full system takeover.
CVE-2026-64623 Vulnerability in CVE-2026-64623 (CVE-2026-64623)
vulnerability in CVE-2026-64623 (CVE-2026-64623). Data can be tampered with by attackers.
CVE-2026-64621 Vulnerability in c (CVE-2026-64621)
vulnerability in c (CVE-2026-64621). Data can be tampered with by attackers.
CVE-2026-63756 Vulnerability in surrealdb (CVE-2026-63756)
vulnerability in surrealdb (CVE-2026-63756). Successful exploitation can lead to full system takeover.
CVE-2026-63757 Vulnerability in surrealdb (CVE-2026-63757)
vulnerability in surrealdb (CVE-2026-63757). Successful exploitation can lead to full system takeover.
CVE-2026-63747 Vulnerability in dos (CVE-2026-63747)
vulnerability in dos (CVE-2026-63747). Risk of unauthorized operations or information disclosure.
CVE-2026-63735 Vulnerability in surrealdb (CVE-2026-63735)
vulnerability in surrealdb (CVE-2026-63735). Confidential information can be exposed externally.
CVE-2026-14448 OS Command Injection in CVE-2026-14448 (CVE-2026-14448)
OS command injection in CVE-2026-14448 (CVE-2026-14448). Successful exploitation can lead to full system takeover.
CVE-2026-63739 Path Traversal in surrealdb (CVE-2026-63739)
path traversal in surrealdb (CVE-2026-63739). Confidential information can be exposed externally.
CVE-2026-16246 Vulnerability in CVE-2026-16246 (CVE-2026-16246)
vulnerability in CVE-2026-16246 (CVE-2026-16246). Data can be tampered with by attackers.
CVE-2026-16247 Vulnerability in CVE-2026-16247 (CVE-2026-16247)
vulnerability in CVE-2026-16247 (CVE-2026-16247). Confidential information can be exposed externally.
CVE-2026-13577 Vulnerability in CVE-2026-13577 (CVE-2026-13577)
vulnerability in CVE-2026-13577 (CVE-2026-13577). Risk of unauthorized operations or information disclosure.
CVE-2026-6656 Vulnerability in CVE-2026-6656 (CVE-2026-6656)
vulnerability in CVE-2026-6656 (CVE-2026-6656). Confidential information can be exposed externally.
CVE-2026-9833 Cross-Site Scripting (XSS) in wordpress (CVE-2026-9833)
cross-site scripting in wordpress (CVE-2026-9833). Risk of unauthorized operations or information disclosure. Exploitable via ``edit_pages``.
CVE-2026-13142 Privilege Escalation in wordpress (CVE-2026-13142)
vulnerability in wordpress (CVE-2026-13142). Successful exploitation can lead to full system takeover.
CVE-2026-12970 Cross-Site Scripting (XSS) in wordpress (CVE-2026-12970)
cross-site scripting in wordpress (CVE-2026-12970). Risk of unauthorized operations or information disclosure.
CVE-2026-12592 Cross-Site Scripting (XSS) in wordpress (CVE-2026-12592)
cross-site scripting in wordpress (CVE-2026-12592). Successful exploitation can lead to full system takeover.
CVE-2026-11349 SQL Injection in wordpress (CVE-2026-11349)
SQL injection in wordpress (CVE-2026-11349). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →