Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-58460 |
|
Path Traversal in react (CVE-2026-58460)
path traversal in react (CVE-2026-58460). Data can be tampered with by attackers.
|
| CVE-2026-52191 |
|
Vulnerability in dos (CVE-2026-52191)
vulnerability in dos (CVE-2026-52191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52188 |
|
Buffer Overflow in dos (CVE-2026-52188)
vulnerability in dos (CVE-2026-52188). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52189 |
|
Vulnerability in dos (CVE-2026-52189)
vulnerability in dos (CVE-2026-52189). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52192 |
|
Vulnerability in dos (CVE-2026-52192)
vulnerability in dos (CVE-2026-52192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59101 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59101)
SSRF in ssrf (CVE-2026-59101). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/setup/test-downloader`.
|
| CVE-2026-59102 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-59102)
cross-site scripting in vue (CVE-2026-59102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59095 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59095)
SSRF in ssrf (CVE-2026-59095). Confidential information can be exposed externally.
|
| CVE-2026-59092 |
|
Vulnerability in dos (CVE-2026-59092)
vulnerability in dos (CVE-2026-59092). Confidential information can be exposed externally.
|
| CVE-2026-58578 |
|
Vulnerability in dos (CVE-2026-58578)
vulnerability in dos (CVE-2026-58578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58381 |
|
Vulnerability in dos (CVE-2026-58381)
vulnerability in dos (CVE-2026-58381). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58467 |
|
Path Traversal in nginx (CVE-2026-58467)
path traversal in nginx (CVE-2026-58467). Confidential information can be exposed externally.
|
| CVE-2025-71385 |
|
Cross-Site Scripting (XSS) in netdata (CVE-2025-71385)
cross-site scripting in netdata (CVE-2025-71385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52187 |
|
Vulnerability in dos (CVE-2026-52187)
vulnerability in dos (CVE-2026-52187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49360 |
|
Vulnerability in recce (CVE-2026-49360)
vulnerability in recce (CVE-2026-49360). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.50.0` or later.
|
| CVE-2026-52746 |
|
Vulnerability in jsonata (CVE-2026-52746)
vulnerability in jsonata (CVE-2026-52746). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.8.9` or later.
|
| CVE-2026-49255 |
|
OS Command Injection in electerm (CVE-2026-49255)
OS command injection in electerm (CVE-2026-49255). Successful exploitation can lead to full system takeover. Exploitable via ``rmrf``. Mitigation: upgrade to `3.11.11` or later.
|
| CVE-2026-7311 |
|
Path Traversal in wordpress (CVE-2026-7311)
path traversal in wordpress (CVE-2026-7311). Data can be tampered with by attackers.
|
| CVE-2026-58465 |
|
Vulnerability in c (CVE-2026-58465)
vulnerability in c (CVE-2026-58465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50181 |
|
Path Traversal in langroid (CVE-2026-50181)
path traversal in langroid (CVE-2026-50181). Confidential information can be exposed externally. Exploitable via ``ReadFileTool``. Mitigation: upgrade to `0.64.0` or later.
|
| CVE-2026-8699 |
|
Cross-Site Scripting (XSS) in CVE-2026-8699 (CVE-2026-8699)
cross-site scripting in CVE-2026-8699 (CVE-2026-8699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54886 |
|
Vulnerability in dos (CVE-2026-54886)
vulnerability in dos (CVE-2026-54886). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55950 |
|
Vulnerability in dos (CVE-2026-55950)
vulnerability in dos (CVE-2026-55950). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-14037 |
|
Unrestricted File Upload in CVE-2024-14037 (CVE-2024-14037)
vulnerability in CVE-2024-14037 (CVE-2024-14037). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58352 |
|
Vulnerability in CVE-2024-58352 (CVE-2024-58352)
vulnerability in CVE-2024-58352 (CVE-2024-58352). Confidential information can be exposed externally.
|
| CVE-2022-50973 |
|
Unrestricted File Upload in CVE-2022-50973 (CVE-2022-50973)
vulnerability in CVE-2022-50973 (CVE-2022-50973). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44941 |
|
Vulnerability in path-traversal (CVE-2026-44941)
vulnerability in path-traversal (CVE-2026-44941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56841 |
|
SQL Injection in sqli (CVE-2026-56841)
SQL injection in sqli (CVE-2026-56841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55117 |
|
Path Traversal in path-traversal (CVE-2026-55117)
path traversal in path-traversal (CVE-2026-55117). Confidential information can be exposed externally.
|
| CVE-2026-55115 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55115)
SSRF in ssrf (CVE-2026-55115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55113 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-55113)
SSRF in ssrf (CVE-2026-55113). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55111 |
|
Path Traversal in path-traversal (CVE-2026-55111)
path traversal in path-traversal (CVE-2026-55111). Confidential information can be exposed externally.
|
| CVE-2026-54401 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-54401)
SSRF in ssrf (CVE-2026-54401). Confidential information can be exposed externally.
|
| CVE-2026-5524 |
|
Unrestricted File Upload in wordpress (CVE-2026-5524)
vulnerability in wordpress (CVE-2026-5524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54404 |
|
SQL Injection in sqli (CVE-2026-54404)
SQL injection in sqli (CVE-2026-54404). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50747 |
|
SQL Injection in sqli (CVE-2026-50747)
SQL injection in sqli (CVE-2026-50747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54406 |
|
Path Traversal in path-traversal (CVE-2026-54406)
path traversal in path-traversal (CVE-2026-54406). Data can be tampered with by attackers.
|
| CVE-2026-54403 |
|
Path Traversal in path-traversal (CVE-2026-54403)
path traversal in path-traversal (CVE-2026-54403). Confidential information can be exposed externally.
|
| CVE-2026-4770 |
|
Cross-Site Scripting (XSS) in CVE-2026-4770 (CVE-2026-4770)
cross-site scripting in CVE-2026-4770 (CVE-2026-4770). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4772 |
|
Cross-Site Scripting (XSS) in CVE-2026-4772 (CVE-2026-4772)
cross-site scripting in CVE-2026-4772 (CVE-2026-4772). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12166 |
|
Vulnerability in dos (CVE-2026-12166)
vulnerability in dos (CVE-2026-12166). Risk of unauthorized operations or information disclosure. Exploitable via ``GFAC_Sys_x64.sys``.
|
| CVE-2026-54405 |
|
Vulnerability in dos (CVE-2026-54405)
vulnerability in dos (CVE-2026-54405). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57765 |
|
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
|
| CVE-2026-57766 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-57766)
vulnerability in csrf (CVE-2026-57766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57764 |
|
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
|
| CVE-2026-57762 |
|
Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
|
| CVE-2026-57763 |
|
Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
|
| CVE-2026-57756 |
|
Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
|
| CVE-2026-57687 |
|
Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
|
| CVE-2026-57683 |
|
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.
|