Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-46961 |
|
Privilege Escalation in c (CVE-2026-46961)
vulnerability in c (CVE-2026-46961). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46952 |
|
Privilege Escalation in c (CVE-2026-46952)
vulnerability in c (CVE-2026-46952). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46951 |
|
Privilege Escalation in c (CVE-2026-46951)
vulnerability in c (CVE-2026-46951). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46937 |
|
Privilege Escalation in c (CVE-2026-46937)
vulnerability in c (CVE-2026-46937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46929 |
|
Privilege Escalation in c (CVE-2026-46929)
vulnerability in c (CVE-2026-46929). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46942 |
|
Privilege Escalation in c (CVE-2026-46942)
vulnerability in c (CVE-2026-46942). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46940 |
|
Privilege Escalation in c (CVE-2026-46940)
vulnerability in c (CVE-2026-46940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46916 |
|
Privilege Escalation in c (CVE-2026-46916)
vulnerability in c (CVE-2026-46916). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46919 |
|
Vulnerability in c (CVE-2026-46919)
vulnerability in c (CVE-2026-46919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46921 |
|
Privilege Escalation in c (CVE-2026-46921)
vulnerability in c (CVE-2026-46921). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46928 |
|
Privilege Escalation in c (CVE-2026-46928)
vulnerability in c (CVE-2026-46928). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46903 |
|
Privilege Escalation in c (CVE-2026-46903)
vulnerability in c (CVE-2026-46903). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46890 |
|
Vulnerability in c (CVE-2026-46890)
vulnerability in c (CVE-2026-46890). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46859 |
|
Authentication Bypass in c (CVE-2026-46859)
authentication bypass in c (CVE-2026-46859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35261 |
|
Authentication Bypass in c (CVE-2026-35261)
authentication bypass in c (CVE-2026-35261). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48117 |
|
Authentication Bypass in CVE-2026-48117 (CVE-2026-48117)
authentication bypass in CVE-2026-48117 (CVE-2026-48117). Confidential information can be exposed externally.
|
| CVE-2026-52845 |
|
Authentication Bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845)
authentication bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845). Confidential information can be exposed externally. Exploitable via `GET /index.php`. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-48780 |
|
Authentication Bypass in CVE-2026-48780 (CVE-2026-48780)
authentication bypass in CVE-2026-48780 (CVE-2026-48780). Confidential information can be exposed externally. Exploitable via ``a2ab6d4``.
|
| CVE-2026-48114 |
|
SQL Injection in sqli (CVE-2026-48114)
SQL injection in sqli (CVE-2026-48114). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12183 |
|
Authentication Bypass in CVE-2026-12183 (CVE-2026-12183)
authentication bypass in CVE-2026-12183 (CVE-2026-12183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50623 |
|
Authentication Bypass in org.apache.cxf:cxf-rt-rs-security-oauth2 (CVE-2026-50623)
authentication bypass in org.apache.cxf:cxf-rt-rs-security-oauth2 (CVE-2026-50623). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.1.7` or later.
|
| CVE-2026-48611 |
|
Authentication Bypass in CVE-2026-48611 (CVE-2026-48611)
authentication bypass in CVE-2026-48611 (CVE-2026-48611). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48039 |
|
Authentication Bypass in meta-ads-mcp (CVE-2026-48039)
authentication bypass in meta-ads-mcp (CVE-2026-48039). Confidential information can be exposed externally. Exploitable via `POST /mcp`. Mitigation: upgrade to `1.0.109` or later.
|
| CVE-2026-40995 |
|
Authentication Bypass in org.springframework.ws:spring-ws-security (CVE-2026-40995)
authentication bypass in org.springframework.ws:spring-ws-security (CVE-2026-40995). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-48575 |
|
Authentication Bypass in apple (CVE-2022-48575)
authentication bypass in apple (CVE-2022-48575). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45567 |
|
Authentication Bypass in nginx (CVE-2026-45567)
authentication bypass in nginx (CVE-2026-45567). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47838 |
|
Authentication Bypass in org.springframework.security:spring-security-web (CVE-2026-47838)
authentication bypass in org.springframework.security:spring-security-web (CVE-2026-47838). Confidential information can be exposed externally. Exploitable via ``SubjectDnX509PrincipalExtractor``.
|
| CVE-2026-36727 |
|
Authentication Bypass in CVE-2026-36727 (CVE-2026-36727)
authentication bypass in CVE-2026-36727 (CVE-2026-36727). Confidential information can be exposed externally.
|
| CVE-2026-44810 |
|
Authentication Bypass in microsoft (CVE-2026-44810)
authentication bypass in microsoft (CVE-2026-44810). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49848 |
|
Authentication Bypass in freeswitch (CVE-2026-49848)
authentication bypass in freeswitch (CVE-2026-49848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49843 |
|
Authentication Bypass in freeswitch (CVE-2026-49843)
authentication bypass in freeswitch (CVE-2026-49843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41720 |
|
Authentication Bypass in org.springframework.ldap:spring-ldap-core (CVE-2026-41720)
authentication bypass in org.springframework.ldap:spring-ldap-core (CVE-2026-41720). Confidential information can be exposed externally.
|
| CVE-2026-11618 |
|
Authentication Bypass in CVE-2026-11618 (CVE-2026-11618)
authentication bypass in CVE-2026-11618 (CVE-2026-11618). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50751 KEV |
|
[KEV] Authentication Bypass in Check point checkpoint (CVE-2026-50751)
authentication bypass in Check point checkpoint (CVE-2026-50751). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-34123 |
|
Authentication Bypass in CVE-2026-34123 (CVE-2026-34123)
authentication bypass in CVE-2026-34123 (CVE-2026-34123). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46389 |
|
Authentication Bypass in defenseunicorns (CVE-2026-46389)
authentication bypass in defenseunicorns (CVE-2026-46389). Successful exploitation can lead to full system takeover. Exploitable via ``client_secret``.
|
| CVE-2026-11345 |
|
Authentication Bypass in CVE-2026-11345 (CVE-2026-11345)
authentication bypass in CVE-2026-11345 (CVE-2026-11345). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6274 |
|
Authentication Bypass in CVE-2026-6274 (CVE-2026-6274)
authentication bypass in CVE-2026-6274 (CVE-2026-6274). Successful exploitation can lead to full system takeover.
|
| CVE-2023-5502 |
|
Authentication Bypass in CVE-2023-5502 (CVE-2023-5502)
authentication bypass in CVE-2023-5502 (CVE-2023-5502). Data can be tampered with by attackers.
|
| CVE-2026-44476 |
|
Authentication Bypass in doorkeeper-openid_connect (CVE-2026-44476)
authentication bypass in doorkeeper-openid_connect (CVE-2026-44476). Risk of unauthorized operations or information disclosure. Exploitable via `POST /oauth/registration`. Mitigation: upgrade to `1.10.0` or later.
|
| CVE-2026-49191 |
|
Authentication Bypass in acer (CVE-2026-49191)
authentication bypass in acer (CVE-2026-49191). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49194 |
|
Authentication Bypass in acer (CVE-2026-49194)
authentication bypass in acer (CVE-2026-49194). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49202 |
|
Authentication Bypass in acer (CVE-2026-49202)
authentication bypass in acer (CVE-2026-49202). Confidential information can be exposed externally.
|
| CVE-2026-49203 |
|
Authentication Bypass in acer (CVE-2026-49203)
authentication bypass in acer (CVE-2026-49203). Data can be tampered with by attackers.
|
| CVE-2026-49186 |
|
Authentication Bypass in acer (CVE-2026-49186)
authentication bypass in acer (CVE-2026-49186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10777 |
|
A vulnerability was identified in ealpha072 Student-Management-System up to...
A vulnerability was identified in ealpha072 Student-Management-System up to...
|
| CVE-2026-52793 |
|
Authentication Bypass in froxlor/froxlor (CVE-2026-52793)
authentication bypass in froxlor/froxlor (CVE-2026-52793). Confidential information can be exposed externally. Exploitable via `POST /index.php`. Mitigation: upgrade to `2.3.7` or later.
|
| CVE-2026-10619 |
|
Authentication Bypass in CVE-2026-10619 (CVE-2026-10619)
authentication bypass in CVE-2026-10619 (CVE-2026-10619). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49443 |
|
Authentication Bypass in authentik (CVE-2026-49443)
authentication bypass in authentik (CVE-2026-49443). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2025.12.6, 2026.2.4, 2026.5.1` or later.
|
| CVE-2026-49448 |
|
Authentication Bypass in authentik (CVE-2026-49448)
authentication bypass in authentik (CVE-2026-49448). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2025.12.6, 2026.2.4, 2026.5.1` or later.
|