Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-82268 SSRF (Server-Side Request Forgery) in CVE-2026-82268 (CVE-2026-82268)
SSRF in CVE-2026-82268 (CVE-2026-82268). Confidential information can be exposed externally.
CVE-2026-82021 Vulnerability in CVE-2026-82021 (CVE-2026-82021)
vulnerability in CVE-2026-82021 (CVE-2026-82021). Successful exploitation can lead to full system takeover.
CVE-2026-77586 SQL Injection in CVE-2026-77586 (CVE-2026-77586)
SQL injection in CVE-2026-77586 (CVE-2026-77586). Successful exploitation can lead to full system takeover.
CVE-2026-75486 OS Command Injection in CVE-2026-75486 (CVE-2026-75486)
OS command injection in CVE-2026-75486 (CVE-2026-75486). Successful exploitation can lead to full system takeover.
CVE-2026-75124 Vulnerability in dos (CVE-2026-75124)
vulnerability in dos (CVE-2026-75124). Risk of unauthorized operations or information disclosure.
CVE-2026-75123 OS Command Injection in CVE-2026-75123 (CVE-2026-75123)
OS command injection in CVE-2026-75123 (CVE-2026-75123). Successful exploitation can lead to full system takeover.
CVE-2026-75122 OS Command Injection in CVE-2026-75122 (CVE-2026-75122)
OS command injection in CVE-2026-75122 (CVE-2026-75122). Successful exploitation can lead to full system takeover.
CVE-2026-75121 OS Command Injection in CVE-2026-75121 (CVE-2026-75121)
OS command injection in CVE-2026-75121 (CVE-2026-75121). Successful exploitation can lead to full system takeover.
CVE-2026-72984 Vulnerability in CVE-2026-72984 (CVE-2026-72984)
vulnerability in CVE-2026-72984 (CVE-2026-72984). Successful exploitation can lead to full system takeover.
CVE-2026-56100 Vulnerability in privilege-escalation (CVE-2026-56100)
vulnerability in privilege-escalation (CVE-2026-56100). Confidential information can be exposed externally.
CVE-2026-55484 Vulnerability in github.com/guno1928/alos-http (CVE-2026-55484)
vulnerability in github.com/guno1928/alos-http (CVE-2026-55484). Risk of unauthorized operations or information disclosure. Exploitable via ``sanitizeRequestPath``. Mitigation: upgrade to `0.0.0-20260617230736-314b6783e196` or later.
CVE-2026-55215 Vulnerability in mariadb (CVE-2026-55215)
vulnerability in mariadb (CVE-2026-55215). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
CVE-2026-55584 Vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584)
vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584). Confidential information can be exposed externally. Exploitable via ``PSI_ALLOWED``. Mitigation: upgrade to `3.4.6` or later.
CVE-2026-81849 Vulnerability in Amazon aws (CVE-2026-81849)
vulnerability in Amazon aws (CVE-2026-81849). Successful exploitation can lead to full system takeover.
CVE-2026-55485 Information Disclosure in piccolo-admin (CVE-2026-55485)
vulnerability in piccolo-admin (CVE-2026-55485). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/tables/piccolo_user/2/`. Mitigation: upgrade to `1.14.0` or later.
CVE-2026-55552 Path Traversal in org.yamcs:yamcs-core (CVE-2026-55552)
path traversal in org.yamcs:yamcs-core (CVE-2026-55552). Confidential information can be exposed externally. Mitigation: upgrade to `5.12.0` or later.
CVE-2026-55521 Vulnerability in org.yamcs:yamcs-core (CVE-2026-55521)
vulnerability in org.yamcs:yamcs-core (CVE-2026-55521). Successful exploitation can lead to full system takeover. Exploitable via ``SystemPrivilege``. Mitigation: upgrade to `5.12.8` or later.
CVE-2026-55066 Vulnerability in code.vikunja.io/api (CVE-2026-55066)
vulnerability in code.vikunja.io/api (CVE-2026-55066). Confidential information can be exposed externally. Exploitable via `POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks`. Mitigation: upgrade to `2.4.0` or later.
CVE-2026-55065 Vulnerability in code.vikunja.io/api (CVE-2026-55065)
vulnerability in code.vikunja.io/api (CVE-2026-55065). Data can be tampered with by attackers. Exploitable via `GET /api/v1/projects/`. Mitigation: upgrade to `2.4.0` or later.
CVE-2026-54788 Vulnerability in datadog-opentelemetry (CVE-2026-54788)
vulnerability in datadog-opentelemetry (CVE-2026-54788). Risk of unauthorized operations or information disclosure. Exploitable via ``tracecontext``. Mitigation: upgrade to `0.3.3` or later.
CVE-2026-82227 Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
CVE-2026-81767 Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
CVE-2026-81760 Cross-Site Scripting (XSS) in CVE-2026-81760 (CVE-2026-81760)
cross-site scripting in CVE-2026-81760 (CVE-2026-81760). Risk of unauthorized operations or information disclosure.
CVE-2026-81757 Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
CVE-2026-81285 Vulnerability in dos (CVE-2026-81285)
vulnerability in dos (CVE-2026-81285). Risk of unauthorized operations or information disclosure.
CVE-2026-81020 Vulnerability in CVE-2026-81020 (CVE-2026-81020)
vulnerability in CVE-2026-81020 (CVE-2026-81020). Confidential information can be exposed externally.
CVE-2026-81019 Vulnerability in CVE-2026-81019 (CVE-2026-81019)
vulnerability in CVE-2026-81019 (CVE-2026-81019). Confidential information can be exposed externally.
CVE-2026-6176 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6176)
cross-site scripting in wordpress (CVE-2026-6176). Risk of unauthorized operations or information disclosure.
CVE-2026-5934 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5934)
cross-site scripting in wordpress (CVE-2026-5934). Risk of unauthorized operations or information disclosure.
CVE-2026-56854 Authorization Flaw in CVE-2026-56854 (CVE-2026-56854)
vulnerability in CVE-2026-56854 (CVE-2026-56854). Confidential information can be exposed externally.
CVE-2026-50979 Command Injection in CVE-2026-50979 (CVE-2026-50979)
command injection in CVE-2026-50979 (CVE-2026-50979). Confidential information can be exposed externally.
CVE-2026-38638 Vulnerability in dos (CVE-2026-38638)
vulnerability in dos (CVE-2026-38638). Risk of unauthorized operations or information disclosure.
CVE-2026-38636 Vulnerability in dos (CVE-2026-38636)
vulnerability in dos (CVE-2026-38636). Risk of unauthorized operations or information disclosure.
CVE-2026-37736 Vulnerability in dos (CVE-2026-37736)
vulnerability in dos (CVE-2026-37736). Risk of unauthorized operations or information disclosure.
CVE-2026-37237 Vulnerability in dos (CVE-2026-37237)
vulnerability in dos (CVE-2026-37237). Risk of unauthorized operations or information disclosure.
CVE-2026-55108 Vulnerability in github.com/oam-dev/kubevela (CVE-2026-55108)
vulnerability in github.com/oam-dev/kubevela (CVE-2026-55108). Risk of unauthorized operations or information disclosure. Exploitable via ``ComponentDefinition``. Mitigation: upgrade to `1.11.0-alpha.4` or later.
CVE-2026-82261 Vulnerability in dos (CVE-2026-82261)
vulnerability in dos (CVE-2026-82261). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.52.2` or later.
CVE-2026-82260 Vulnerability in dos (CVE-2026-82260)
vulnerability in dos (CVE-2026-82260). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.52.2` or later.
CVE-2026-82259 Unsafe Deserialization in dos (CVE-2026-82259)
vulnerability in dos (CVE-2026-82259). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.53.3` or later.
CVE-2026-82254 Vulnerability in CVE-2026-82254 (CVE-2026-82254)
vulnerability in CVE-2026-82254 (CVE-2026-82254). Risk of unauthorized operations or information disclosure.
CVE-2026-82251 Path Traversal in path-traversal (CVE-2026-82251)
path traversal in path-traversal (CVE-2026-82251). Confidential information can be exposed externally.
CVE-2026-82252 Vulnerability in CVE-2026-82252 (CVE-2026-82252)
vulnerability in CVE-2026-82252 (CVE-2026-82252). Confidential information can be exposed externally.
CVE-2026-82253 Path Traversal in path-traversal (CVE-2026-82253)
path traversal in path-traversal (CVE-2026-82253). Confidential information can be exposed externally.
CVE-2026-82246 SSRF (Server-Side Request Forgery) in CVE-2026-82246 (CVE-2026-82246)
SSRF in CVE-2026-82246 (CVE-2026-82246). Confidential information can be exposed externally.
CVE-2026-82243 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82243)
SSRF in ssrf (CVE-2026-82243). Confidential information can be exposed externally.
CVE-2026-82242 Vulnerability in CVE-2026-82242 (CVE-2026-82242)
vulnerability in CVE-2026-82242 (CVE-2026-82242). Data can be tampered with by attackers. Exploitable via `POST /api/resources/duplicate`.
CVE-2026-82245 Vulnerability in CVE-2026-82245 (CVE-2026-82245)
vulnerability in CVE-2026-82245 (CVE-2026-82245). Data can be tampered with by attackers.
CVE-2026-82247 Vulnerability in CVE-2026-82247 (CVE-2026-82247)
vulnerability in CVE-2026-82247 (CVE-2026-82247). Confidential information can be exposed externally. Mitigation: upgrade to `0.37.1` or later.
CVE-2026-82241 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82241)
SSRF in ssrf (CVE-2026-82241). Confidential information can be exposed externally. Exploitable via `POST /api/queries/preview`.
CVE-2026-82240 Vulnerability in CVE-2026-82240 (CVE-2026-82240)
vulnerability in CVE-2026-82240 (CVE-2026-82240). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →