🌐

Web Application

slug: web-application

🛡 Vulnérabilités associées 283

ID Titre
CVE-2026-78161 A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
CVE-2026-9769 Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
CVE-2026-4671 justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
CVE-2026-30819 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
CVE-2026-30866 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
CVE-2026-27490 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
CVE-2026-27462 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lead...
CVE-2026-54682 DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Format...
CVE-2026-73197 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
CVE-2026-19905 A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
CVE-2026-14279 The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
CVE-2026-73680 Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
CVE-2026-19825 A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
CVE-2026-19826 A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
CVE-2026-19794 The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
CVE-2026-19762 A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
CVE-2026-19764 A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
CVE-2026-19758 A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
CVE-2026-19757 A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
CVE-2026-73654 Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
CVE-2026-72777 Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
CVE-2026-18146 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
CVE-2026-73031 telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
CVE-2026-73222 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
CVE-2026-15426 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
CVE-2026-67620 Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
CVE-2026-48026 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...

🍪 À propos des cookies

Nous utilisons des cookies pour conserver votre session, mémoriser la langue et améliorer le service.

En savoir plus →