Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-46333 |
|
Privilege Escalation in cisa (CVE-2026-46333)
vulnerability in cisa (CVE-2026-46333). Confidential information can be exposed externally.
|
| CVE-2026-6228 |
|
Privilege Escalation in wordpress (CVE-2026-6228)
vulnerability in wordpress (CVE-2026-6228). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45675 |
|
Privilege Escalation in open-webui (CVE-2026-45675)
vulnerability in open-webui (CVE-2026-45675). Successful exploitation can lead to full system takeover. Exploitable via ``signup_handler``. Mitigation: upgrade to `0.9.0` or later.
|
| CVE-2026-45395 |
|
Privilege Escalation in open-webui (CVE-2026-45395)
vulnerability in open-webui (CVE-2026-45395). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/tools/id/{id}/update`. Mitigation: upgrade to `0.9.5` or later.
|
| CVE-2026-43978 |
|
Privilege Escalation in wger (CVE-2026-43978)
vulnerability in wger (CVE-2026-43978). Confidential information can be exposed externally. Exploitable via ``trainer.identity``.
|
| CVE-2025-62625 |
|
Privilege Escalation in CVE-2025-62625 (CVE-2025-62625)
vulnerability in CVE-2025-62625 (CVE-2025-62625). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5193 |
|
Privilege Escalation in wordpress (CVE-2026-5193)
vulnerability in wordpress (CVE-2026-5193). Data can be tampered with by attackers.
|
| CVE-2026-44470 |
|
Vulnerability in privilege-escalation (CVE-2026-44470)
vulnerability in privilege-escalation (CVE-2026-44470). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.3834.0` or later.
|
| CVE-2026-42289 |
|
Privilege Escalation in csrf (CVE-2026-42289)
vulnerability in csrf (CVE-2026-42289). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.3.2` or later.
|
| CVE-2026-42844 |
|
Privilege Escalation in getgrav/grav (CVE-2026-42844)
vulnerability in getgrav/grav (CVE-2026-42844). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/auth/token`. Mitigation: upgrade to `2.0.0-beta.4` or later.
|
| CVE-2026-44224 |
|
Privilege Escalation in requarks (CVE-2026-44224)
vulnerability in requarks (CVE-2026-44224). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.5.313` or later.
|
| CVE-2026-44218 |
|
Privilege Escalation in ciguard (CVE-2026-44218)
vulnerability in ciguard (CVE-2026-44218). Risk of unauthorized operations or information disclosure. Exploitable via ``Dockerfile``. Mitigation: upgrade to `0.8.2` or later.
|
| CVE-2026-33821 |
|
Privilege Escalation in microsoft (CVE-2026-33821)
vulnerability in microsoft (CVE-2026-33821). Data can be tampered with by attackers.
|
| CVE-2026-43886 |
|
Privilege Escalation in CVE-2026-43886 (CVE-2026-43886)
vulnerability in CVE-2026-43886 (CVE-2026-43886). Data can be tampered with by attackers. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2026-28976 |
|
Information Disclosure in apple (CVE-2026-28976)
vulnerability in apple (CVE-2026-28976). Confidential information can be exposed externally.
|
| CVE-2026-28995 |
|
Privilege Escalation in apple (CVE-2026-28995)
vulnerability in apple (CVE-2026-28995). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28919 |
|
Privilege Escalation in apple (CVE-2026-28919)
vulnerability in apple (CVE-2026-28919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28840 |
|
Privilege Escalation in apple (CVE-2026-28840)
vulnerability in apple (CVE-2026-28840). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41489 |
|
Vulnerability in privilege-escalation (CVE-2026-41489)
vulnerability in privilege-escalation (CVE-2026-41489). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42609 |
|
Privilege Escalation in getgrav/grav (CVE-2026-42609)
vulnerability in getgrav/grav (CVE-2026-42609). Data can be tampered with by attackers. Exploitable via ``d904efc33``. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-44543 |
|
Vulnerability in github.com/rancher/local-path-provisioner (CVE-2026-44543)
vulnerability in github.com/rancher/local-path-provisioner (CVE-2026-44543). Confidential information can be exposed externally. Exploitable via ``helperPod.yaml``. Mitigation: upgrade to `0.0.36` or later.
|
| CVE-2026-26946 |
|
Privilege Escalation in dell (CVE-2026-26946)
vulnerability in dell (CVE-2026-26946). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42562 |
|
Privilege Escalation in CVE-2026-42562 (CVE-2026-42562)
vulnerability in CVE-2026-42562 (CVE-2026-42562). Confidential information can be exposed externally. Exploitable via `PUT /api.php/v1/users/{id}.`.
|
| CVE-2026-41163 |
|
Privilege Escalation in CVE-2026-41163 (CVE-2026-41163)
vulnerability in CVE-2026-41163 (CVE-2026-41163). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44987 |
|
Privilege Escalation in django (CVE-2026-44987)
vulnerability in django (CVE-2026-44987). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42185 |
|
Privilege Escalation in CVE-2026-42185 (CVE-2026-42185)
vulnerability in CVE-2026-42185 (CVE-2026-42185). Data can be tampered with by attackers.
|
| CVE-2026-8069 |
|
Path Traversal in privilege-escalation (CVE-2026-8069)
path traversal in privilege-escalation (CVE-2026-8069). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37525 |
|
Privilege Escalation in c (CVE-2026-37525)
vulnerability in c (CVE-2026-37525). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5141 |
|
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment...
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment...
|
| CVE-2026-3621 |
|
Privilege Escalation in ibm (CVE-2026-3621)
vulnerability in ibm (CVE-2026-3621). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1726 |
|
Privilege Escalation in privilege-escalation (CVE-2026-1726)
vulnerability in privilege-escalation (CVE-2026-1726). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6750 |
|
Privilege Escalation in privilege-escalation (CVE-2026-6750)
vulnerability in privilege-escalation (CVE-2026-6750). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31368 |
|
Privilege Escalation in CVE-2026-31368 (CVE-2026-31368)
vulnerability in CVE-2026-31368 (CVE-2026-31368). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35154 |
|
Privilege Escalation in dell (CVE-2026-35154)
vulnerability in dell (CVE-2026-35154). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40002 |
|
Privilege Escalation in zte (CVE-2026-40002)
vulnerability in zte (CVE-2026-40002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40291 |
|
Privilege Escalation in chamilo (CVE-2026-40291)
vulnerability in chamilo (CVE-2026-40291). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/users/{id}`.
|
| CVE-2026-32181 |
|
Privilege Escalation in microsoft (CVE-2026-32181)
vulnerability in microsoft (CVE-2026-32181). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39961 |
|
Privilege Escalation in github.com/aiven/aiven-operator (CVE-2026-39961)
vulnerability in github.com/aiven/aiven-operator (CVE-2026-39961). Confidential information can be exposed externally. Mitigation: upgrade to `0.37.0` or later.
|
| CVE-2026-27456 |
|
Vulnerability in kernel (CVE-2026-27456)
vulnerability in kernel (CVE-2026-27456). Confidential information can be exposed externally.
|
| CVE-2023-7343 |
|
Privilege Escalation in privilege-escalation (CVE-2023-7343)
vulnerability in privilege-escalation (CVE-2023-7343). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44250 |
|
Privilege Escalation in apple (CVE-2024-44250)
vulnerability in apple (CVE-2024-44250). Successful exploitation can lead to full system takeover.
|
| CVE-2023-7342 |
|
Privilege Escalation in privilege-escalation (CVE-2023-7342)
vulnerability in privilege-escalation (CVE-2023-7342). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33074 |
|
Privilege Escalation in discourse (CVE-2026-33074)
vulnerability in discourse (CVE-2026-33074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34218 |
|
Privilege Escalation in craigjbass (CVE-2026-34218)
vulnerability in craigjbass (CVE-2026-34218). Confidential information can be exposed externally.
|
| CVE-2026-2640 |
|
Privilege Escalation in lenovo (CVE-2026-2640)
vulnerability in lenovo (CVE-2026-2640). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30902 |
|
Privilege Escalation in zoom (CVE-2026-30902)
vulnerability in zoom (CVE-2026-30902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2777 |
|
Privilege Escalation in privilege-escalation (CVE-2026-2777)
vulnerability in privilege-escalation (CVE-2026-2777). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26725 |
|
Privilege Escalation in edubusinesssolutions (CVE-2026-26725)
vulnerability in edubusinesssolutions (CVE-2026-26725). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `19.76` or later.
|
| CVE-2026-26369 |
|
Privilege Escalation in privilege-escalation (CVE-2026-26369)
vulnerability in privilege-escalation (CVE-2026-26369). Successful exploitation can lead to full system takeover.
|
| CVE-2025-46310 |
|
Privilege Escalation in apple (CVE-2025-46310)
vulnerability in apple (CVE-2025-46310). Data can be tampered with by attackers.
|