Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-200 Clear
ID Title
CVE-2026-71293 Information Disclosure in CVE-2026-71293 (CVE-2026-71293)
vulnerability in CVE-2026-71293 (CVE-2026-71293). Confidential information can be exposed externally. Exploitable via ``two_factor_recovery_codes``.
CVE-2026-61891 Path Traversal in eclipse (CVE-2026-61891)
path traversal in eclipse (CVE-2026-61891). Confidential information can be exposed externally. Exploitable via `GET /file`.
CVE-2026-17515 Information Disclosure in wordpress (CVE-2026-17515)
vulnerability in wordpress (CVE-2026-17515). Risk of unauthorized operations or information disclosure.
CVE-2026-16993 Information Disclosure in wordpress (CVE-2026-16993)
vulnerability in wordpress (CVE-2026-16993). Risk of unauthorized operations or information disclosure.
CVE-2026-16968 Information Disclosure in wordpress (CVE-2026-16968)
vulnerability in wordpress (CVE-2026-16968). Confidential information can be exposed externally.
CVE-2026-16603 Information Disclosure in wordpress (CVE-2026-16603)
vulnerability in wordpress (CVE-2026-16603). Confidential information can be exposed externally.
CVE-2026-16604 Information Disclosure in wordpress (CVE-2026-16604)
vulnerability in wordpress (CVE-2026-16604). Confidential information can be exposed externally.
CVE-2026-16602 Information Disclosure in wordpress (CVE-2026-16602)
vulnerability in wordpress (CVE-2026-16602). Confidential information can be exposed externally.
CVE-2026-70590 Information Disclosure in ghost (CVE-2026-70590)
vulnerability in ghost (CVE-2026-70590). Data can be tampered with by attackers. Mitigation: upgrade to `6.54.1` or later.
CVE-2026-70491 Information Disclosure in open-webui (CVE-2026-70491)
vulnerability in open-webui (CVE-2026-70491). Confidential information can be exposed externally. Exploitable via `GET /api/v1/tools/`. Mitigation: upgrade to `0.11.0` or later.
CVE-2026-70478 Information Disclosure in flowise (CVE-2026-70478)
vulnerability in flowise (CVE-2026-70478). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/refresh/`. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-70473 Information Disclosure in flowise (CVE-2026-70473)
vulnerability in flowise (CVE-2026-70473). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/upsert-history`. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-18809 Information Disclosure in CVE-2026-18809 (CVE-2026-18809)
vulnerability in CVE-2026-18809 (CVE-2026-18809). Confidential information can be exposed externally.
CVE-2026-67972 Information Disclosure in CVE-2026-67972 (CVE-2026-67972)
vulnerability in CVE-2026-67972 (CVE-2026-67972). Confidential information can be exposed externally.
CVE-2026-69153 Path Traversal in postcss (CVE-2026-69153)
path traversal in postcss (CVE-2026-69153). Risk of unauthorized operations or information disclosure. Exploitable via ``sourceMappingURL``. Mitigation: upgrade to `8.5.23` or later.
CVE-2026-67357 Information Disclosure in CVE-2026-67357 (CVE-2026-67357)
vulnerability in CVE-2026-67357 (CVE-2026-67357). Successful exploitation can lead to full system takeover.
CVE-2026-15236 Information Disclosure in wordpress (CVE-2026-15236)
vulnerability in wordpress (CVE-2026-15236). Confidential information can be exposed externally.
CVE-2026-67343 Information Disclosure in CVE-2026-67343 (CVE-2026-67343)
vulnerability in CVE-2026-67343 (CVE-2026-67343). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/server`.
CVE-2026-67339 Information Disclosure in guzzlehttp/guzzle (CVE-2026-67339)
vulnerability in guzzlehttp/guzzle (CVE-2026-67339). Risk of unauthorized operations or information disclosure. Exploitable via ``CurlHandler``. Mitigation: upgrade to `7.14.2` or later.
CVE-2026-67320 Information Disclosure in CVE-2026-67320 (CVE-2026-67320)
vulnerability in CVE-2026-67320 (CVE-2026-67320). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `0.33.0` or later.
CVE-2026-67322 Information Disclosure in CVE-2026-67322 (CVE-2026-67322)
vulnerability in CVE-2026-67322 (CVE-2026-67322). Confidential information can be exposed externally.
CVE-2026-18059 Information Disclosure in wordpress (CVE-2026-18059)
vulnerability in wordpress (CVE-2026-18059). Risk of unauthorized operations or information disclosure.
CVE-2026-2916 Information Disclosure in wordpress (CVE-2026-2916)
vulnerability in wordpress (CVE-2026-2916). Risk of unauthorized operations or information disclosure. Exploitable via ``JkitDashboardOption``.
CVE-2026-14839 Information Disclosure in wordpress (CVE-2026-14839)
vulnerability in wordpress (CVE-2026-14839). Confidential information can be exposed externally.
CVE-2026-54785 Path Traversal in gemini-bridge (CVE-2026-54785)
path traversal in gemini-bridge (CVE-2026-54785). Confidential information can be exposed externally. Exploitable via ``consult_gemini_with_files``. Mitigation: upgrade to `1.3.1` or later.
CVE-2026-55824 Information Disclosure in contao/contao (CVE-2026-55824)
vulnerability in contao/contao (CVE-2026-55824). Risk of unauthorized operations or information disclosure. Exploitable via ``Cookie``. Mitigation: upgrade to `5.7.7` or later.
CVE-2026-52855 Information Disclosure in github.com/pterodactyl/wings (CVE-2026-52855)
vulnerability in github.com/pterodactyl/wings (CVE-2026-52855). Successful exploitation can lead to full system takeover. Exploitable via ``startup.update``. Mitigation: upgrade to `1.12.3` or later.
CVE-2026-14928 Information Disclosure in wordpress (CVE-2026-14928)
vulnerability in wordpress (CVE-2026-14928). Confidential information can be exposed externally.
CVE-2026-14931 Information Disclosure in wordpress (CVE-2026-14931)
vulnerability in wordpress (CVE-2026-14931). Confidential information can be exposed externally.
CVE-2026-15048 Information Disclosure in wordpress (CVE-2026-15048)
vulnerability in wordpress (CVE-2026-15048). Confidential information can be exposed externally.
CVE-2026-14319 Information Disclosure in wordpress (CVE-2026-14319)
vulnerability in wordpress (CVE-2026-14319). Confidential information can be exposed externally.
CVE-2026-10569 Information Disclosure in ibm (CVE-2026-10569)
vulnerability in ibm (CVE-2026-10569). Risk of unauthorized operations or information disclosure.
CVE-2026-67529 Information Disclosure in CVE-2026-67529 (CVE-2026-67529)
vulnerability in CVE-2026-67529 (CVE-2026-67529). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v3/time_entries`. Mitigation: upgrade to `17.6.0` or later.
CVE-2026-48499 Information Disclosure in CVE-2026-48499 (CVE-2026-48499)
vulnerability in CVE-2026-48499 (CVE-2026-48499). Risk of unauthorized operations or information disclosure.
CVE-2026-41186 Information Disclosure in tigera (CVE-2026-41186)
vulnerability in tigera (CVE-2026-41186). Confidential information can be exposed externally.
CVE-2026-14188 Information Disclosure in wordpress (CVE-2026-14188)
vulnerability in wordpress (CVE-2026-14188). Risk of unauthorized operations or information disclosure.
CVE-2026-14231 Information Disclosure in wordpress (CVE-2026-14231)
vulnerability in wordpress (CVE-2026-14231). Risk of unauthorized operations or information disclosure.
CVE-2026-15235 Information Disclosure in wordpress (CVE-2026-15235)
vulnerability in wordpress (CVE-2026-15235). Risk of unauthorized operations or information disclosure.
CVE-2026-14226 Information Disclosure in wordpress (CVE-2026-14226)
vulnerability in wordpress (CVE-2026-14226). Risk of unauthorized operations or information disclosure.
CVE-2026-18005 Information Disclosure in google (CVE-2026-18005)
vulnerability in google (CVE-2026-18005). Confidential information can be exposed externally.
CVE-2026-18011 Information Disclosure in google (CVE-2026-18011)
vulnerability in google (CVE-2026-18011). Risk of unauthorized operations or information disclosure.
CVE-2026-18001 Information Disclosure in google (CVE-2026-18001)
vulnerability in google (CVE-2026-18001). Confidential information can be exposed externally.
CVE-2026-17975 Information Disclosure in c (CVE-2026-17975)
vulnerability in c (CVE-2026-17975). Confidential information can be exposed externally.
CVE-2026-17966 Information Disclosure in google (CVE-2026-17966)
vulnerability in google (CVE-2026-17966). Confidential information can be exposed externally.
CVE-2026-17973 Information Disclosure in google (CVE-2026-17973)
vulnerability in google (CVE-2026-17973). Confidential information can be exposed externally.
CVE-2026-17928 Information Disclosure in google (CVE-2026-17928)
vulnerability in google (CVE-2026-17928). Risk of unauthorized operations or information disclosure.
CVE-2026-17902 Information Disclosure in google (CVE-2026-17902)
vulnerability in google (CVE-2026-17902). Risk of unauthorized operations or information disclosure.
CVE-2026-17892 Information Disclosure in google (CVE-2026-17892)
vulnerability in google (CVE-2026-17892). Confidential information can be exposed externally.
CVE-2026-17683 Information Disclosure in google (CVE-2026-17683)
vulnerability in google (CVE-2026-17683). Confidential information can be exposed externally.
CVE-2026-67435 Information Disclosure in linuxfabrik-lib (CVE-2026-67435)
vulnerability in linuxfabrik-lib (CVE-2026-67435). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `6.0.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →