Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42541 |
|
Vulnerability in github.com/kubewarden/kubewarden-controller (CVE-2026-42541)
vulnerability in github.com/kubewarden/kubewarden-controller (CVE-2026-42541). Risk of unauthorized operations or information disclosure. Exploitable via ``can_i``. Mitigation: upgrade to `1.35.0` or later.
|
| CVE-2026-8407 |
|
Vulnerability in devolutions (CVE-2026-8407)
vulnerability in devolutions (CVE-2026-8407). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25431 |
|
Vulnerability in CVE-2026-25431 (CVE-2026-25431)
vulnerability in CVE-2026-25431 (CVE-2026-25431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45210 |
|
Vulnerability in CVE-2026-45210 (CVE-2026-45210)
vulnerability in CVE-2026-45210 (CVE-2026-45210). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45212 |
|
Vulnerability in c (CVE-2026-45212)
vulnerability in c (CVE-2026-45212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1934 |
|
Vulnerability in wordpress (CVE-2026-1934)
vulnerability in wordpress (CVE-2026-1934). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6708 |
|
Vulnerability in wordpress (CVE-2026-6708)
vulnerability in wordpress (CVE-2026-6708). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6663 |
|
Vulnerability in wordpress (CVE-2026-6663)
vulnerability in wordpress (CVE-2026-6663). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7050 |
|
Vulnerability in wordpress (CVE-2026-7050)
vulnerability in wordpress (CVE-2026-7050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6709 |
|
Vulnerability in wordpress (CVE-2026-6709)
vulnerability in wordpress (CVE-2026-6709). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4663 |
|
Vulnerability in wordpress (CVE-2026-4663)
vulnerability in wordpress (CVE-2026-4663). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4301 |
|
Vulnerability in wordpress (CVE-2026-4301)
vulnerability in wordpress (CVE-2026-4301). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5693 |
|
Vulnerability in wordpress (CVE-2026-5693)
vulnerability in wordpress (CVE-2026-5693). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39432 |
|
Vulnerability in CVE-2026-39432 (CVE-2026-39432)
vulnerability in CVE-2026-39432 (CVE-2026-39432). Confidential information can be exposed externally.
|
| CVE-2026-40132 |
|
Vulnerability in CVE-2026-40132 (CVE-2026-40132)
vulnerability in CVE-2026-40132 (CVE-2026-40132). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40133 |
|
Vulnerability in CVE-2026-40133 (CVE-2026-40133)
vulnerability in CVE-2026-40133 (CVE-2026-40133). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40134 |
|
Vulnerability in CVE-2026-40134 (CVE-2026-40134)
vulnerability in CVE-2026-40134 (CVE-2026-40134). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43885 |
|
Information Disclosure in wwbn/avideo (CVE-2026-43885)
vulnerability in wwbn/avideo (CVE-2026-43885). Risk of unauthorized operations or information disclosure. Exploitable via ``APISecret``.
|
| CVE-2026-20696 |
|
Vulnerability in apple (CVE-2026-20696)
vulnerability in apple (CVE-2026-20696). Confidential information can be exposed externally.
|
| CVE-2026-42071 |
|
Vulnerability in mantisbt/mantisbt (CVE-2026-42071)
vulnerability in mantisbt/mantisbt (CVE-2026-42071). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/rest/issues/{id}/files`. Mitigation: upgrade to `2.28.2` or later.
|
| CVE-2026-45001 |
|
Vulnerability in ssrf (CVE-2026-45001)
vulnerability in ssrf (CVE-2026-45001). Data can be tampered with by attackers.
|
| CVE-2026-43639 |
|
Vulnerability in bitwarden (CVE-2026-43639)
vulnerability in bitwarden (CVE-2026-43639). Successful exploitation can lead to full system takeover. Exploitable via `POST /providers/{providerId}/clients/existing`.
|
| CVE-2026-44994 |
|
Vulnerability in openclaw (CVE-2026-44994)
vulnerability in openclaw (CVE-2026-44994). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43638 |
|
Vulnerability in bitwarden (CVE-2026-43638)
vulnerability in bitwarden (CVE-2026-43638). Risk of unauthorized operations or information disclosure. Exploitable via `POST /ciphers/import-organization`.
|
| CVE-2026-33359 |
|
Vulnerability in CVE-2026-33359 (CVE-2026-33359)
vulnerability in CVE-2026-33359 (CVE-2026-33359). Confidential information can be exposed externally.
|
| CVE-2026-33357 |
|
Vulnerability in CVE-2026-33357 (CVE-2026-33357)
vulnerability in CVE-2026-33357 (CVE-2026-33357). Confidential information can be exposed externally. Exploitable via `GET /openapi/device/status`.
|
| CVE-2026-42613 |
|
Vulnerability in getgrav/grav (CVE-2026-42613)
vulnerability in getgrav/grav (CVE-2026-42613). Confidential information can be exposed externally. Exploitable via ``groups``. Mitigation: upgrade to `2.0.0-beta.2` or later.
|
| CVE-2026-44571 |
|
Vulnerability in open-webui (CVE-2026-44571)
vulnerability in open-webui (CVE-2026-44571). Data can be tampered with by attackers. Exploitable via `POST /api/v1/channels/{channel_id}/messages/{message_id}/update`. Mitigation: upgrade to `0.8.6` or later.
|
| CVE-2026-44569 |
|
Vulnerability in open-webui (CVE-2026-44569)
vulnerability in open-webui (CVE-2026-44569). Data can be tampered with by attackers. Exploitable via ``message_id``. Mitigation: upgrade to `0.6.19` or later.
|
| CVE-2026-32658 |
|
Vulnerability in dell (CVE-2026-32658)
vulnerability in dell (CVE-2026-32658). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47932 |
|
Vulnerability in wordpress (CVE-2021-47932)
vulnerability in wordpress (CVE-2021-47932). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8194 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-8194 (CVE-2026-8194)
vulnerability in CVE-2026-8194 (CVE-2026-8194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42569 |
|
Vulnerability in nabeel/phpvms (CVE-2026-42569)
vulnerability in nabeel/phpvms (CVE-2026-42569). Data can be tampered with by attackers. Mitigation: upgrade to `7.0.6` or later.
|
| CVE-2026-20155 |
|
Vulnerability in Cisco evolved-programmable-network-manager (CVE-2026-20155)
vulnerability in Cisco evolved-programmable-network-manager (CVE-2026-20155). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20193 |
|
Vulnerability in Cisco identity-services-engine (CVE-2026-20193)
vulnerability in Cisco identity-services-engine (CVE-2026-20193). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20189 |
|
Vulnerability in Cisco prime-infrastructure (CVE-2026-20189)
vulnerability in Cisco prime-infrastructure (CVE-2026-20189). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15634 |
|
Vulnerability in hcltech (CVE-2025-15634)
vulnerability in hcltech (CVE-2025-15634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42461 |
|
Vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-42461)
vulnerability in github.com/getarcaneapp/arcane/backend (CVE-2026-42461). Confidential information can be exposed externally. Exploitable via `GET /api/templates`. Mitigation: upgrade to `1.18.0` or later.
|
| CVE-2026-42297 |
|
Vulnerability in argo-workflows (CVE-2026-42297)
vulnerability in argo-workflows (CVE-2026-42297). Data can be tampered with by attackers. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-42174 |
|
Vulnerability in getkirby/cms (CVE-2026-42174)
vulnerability in getkirby/cms (CVE-2026-42174). Risk of unauthorized operations or information disclosure. Exploitable via ``user.update``. Mitigation: upgrade to `5.4.0` or later.
|
| CVE-2026-42051 |
|
Vulnerability in getkirby/cms (CVE-2026-42051)
vulnerability in getkirby/cms (CVE-2026-42051). Risk of unauthorized operations or information disclosure. Exploitable via ``access.system``. Mitigation: upgrade to `5.4.0` or later.
|
| CVE-2026-42069 |
|
Vulnerability in getkirby/cms (CVE-2026-42069)
vulnerability in getkirby/cms (CVE-2026-42069). Confidential information can be exposed externally. Exploitable via ``options``. Mitigation: upgrade to `5.4.0` or later.
|
| CVE-2026-42137 |
|
Vulnerability in getkirby (CVE-2026-42137)
vulnerability in getkirby (CVE-2026-42137). Confidential information can be exposed externally.
|
| CVE-2026-6667 |
|
Vulnerability in pgbouncer (CVE-2026-6667)
vulnerability in pgbouncer (CVE-2026-6667). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2026-44329 |
|
Vulnerability in github.com/free5gc/smf (CVE-2026-44329)
vulnerability in github.com/free5gc/smf (CVE-2026-44329). Data can be tampered with by attackers. Exploitable via `GET /upi/v1/upNodesLinks`. Mitigation: upgrade to `1.4.3` or later.
|
| CVE-2026-44328 |
|
Vulnerability in github.com/free5gc/smf (CVE-2026-44328)
vulnerability in github.com/free5gc/smf (CVE-2026-44328). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /upi/v1/upNodesLinks/{upNodeRef}`. Mitigation: upgrade to `1.4.3` or later.
|
| CVE-2026-44327 |
|
Vulnerability in github.com/free5gc/nef (CVE-2026-44327)
vulnerability in github.com/free5gc/nef (CVE-2026-44327). Data can be tampered with by attackers.
|
| CVE-2026-44326 |
|
Vulnerability in github.com/free5gc/nef (CVE-2026-44326)
vulnerability in github.com/free5gc/nef (CVE-2026-44326). Data can be tampered with by attackers. Exploitable via ``Authorization``.
|
| CVE-2026-44321 |
|
Vulnerability in github.com/free5gc/smf (CVE-2026-44321)
vulnerability in github.com/free5gc/smf (CVE-2026-44321). Risk of unauthorized operations or information disclosure. Exploitable via `POST /upi/v1/upNodesLinks`.
|
| CVE-2026-44320 |
|
Vulnerability in github.com/free5gc/nef (CVE-2026-44320)
vulnerability in github.com/free5gc/nef (CVE-2026-44320). Risk of unauthorized operations or information disclosure. Exploitable via ``NotifId``.
|