Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-78263 |
|
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
|
| CVE-2026-78267 |
|
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
|
| CVE-2026-77337 |
|
Vulnerability in CVE-2026-77337 (CVE-2026-77337)
vulnerability in CVE-2026-77337 (CVE-2026-77337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68516 |
|
Vulnerability in dos (CVE-2026-68516)
vulnerability in dos (CVE-2026-68516). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77384 |
|
Vulnerability in dos (CVE-2026-77384)
vulnerability in dos (CVE-2026-77384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32561 |
|
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
|
| CVE-2026-32555 |
|
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
|
| CVE-2026-32554 |
|
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
|
| CVE-2026-32556 |
|
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
|
| CVE-2022-30983 |
|
Cross-Site Scripting (XSS) in CVE-2022-30983 (CVE-2022-30983)
cross-site scripting in CVE-2022-30983 (CVE-2022-30983). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77635 |
|
SQL Injection in sqli (CVE-2026-77635)
SQL injection in sqli (CVE-2026-77635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78551 |
|
Vulnerability in dos (CVE-2026-78551)
vulnerability in dos (CVE-2026-78551). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77310 |
|
SSRF (Server-Side Request Forgery) in csharp (CVE-2026-77310)
SSRF in csharp (CVE-2026-77310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75369 |
|
Out-of-Bounds Read in dos (CVE-2026-75369)
vulnerability in dos (CVE-2026-75369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76098 |
|
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens fr...
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee...
|
| CVE-2026-75368 |
|
Vulnerability in dos (CVE-2026-75368)
vulnerability in dos (CVE-2026-75368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71510 |
|
Authorization Flaw in sqli (CVE-2026-71510)
vulnerability in sqli (CVE-2026-71510). Confidential information can be exposed externally.
|
| CVE-2026-61419 |
|
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
|
| CVE-2026-75370 |
|
Out-of-Bounds Read in dos (CVE-2026-75370)
vulnerability in dos (CVE-2026-75370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75371 |
|
Vulnerability in dos (CVE-2026-75371)
vulnerability in dos (CVE-2026-75371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71832 |
|
Vulnerability in dos (CVE-2026-71832)
vulnerability in dos (CVE-2026-71832). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71503 |
|
Cross-Site Scripting (XSS) in CVE-2026-71503 (CVE-2026-71503)
cross-site scripting in CVE-2026-71503 (CVE-2026-71503). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71506 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
| CVE-2026-71505 |
|
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-30864 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
| CVE-2026-78475 |
|
Out-of-Bounds Read in dos (CVE-2026-78475)
vulnerability in dos (CVE-2026-78475). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71942 |
|
Vulnerability in dos (CVE-2026-71942)
vulnerability in dos (CVE-2026-71942). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71934 |
|
Vulnerability in dos (CVE-2026-71934)
vulnerability in dos (CVE-2026-71934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71936 |
|
Vulnerability in dos (CVE-2026-71936)
vulnerability in dos (CVE-2026-71936). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71938 |
|
Vulnerability in dos (CVE-2026-71938)
vulnerability in dos (CVE-2026-71938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71939 |
|
Vulnerability in dos (CVE-2026-71939)
vulnerability in dos (CVE-2026-71939). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71935 |
|
Vulnerability in dos (CVE-2026-71935)
vulnerability in dos (CVE-2026-71935). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71940 |
|
Vulnerability in dos (CVE-2026-71940)
vulnerability in dos (CVE-2026-71940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71937 |
|
Vulnerability in dos (CVE-2026-71937)
vulnerability in dos (CVE-2026-71937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71941 |
|
Vulnerability in dos (CVE-2026-71941)
vulnerability in dos (CVE-2026-71941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71922 |
|
Vulnerability in dos (CVE-2026-71922)
vulnerability in dos (CVE-2026-71922). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71932 |
|
Path Traversal in path-traversal (CVE-2026-71932)
path traversal in path-traversal (CVE-2026-71932). Confidential information can be exposed externally.
|
| CVE-2026-71911 |
|
Vulnerability in dos (CVE-2026-71911)
vulnerability in dos (CVE-2026-71911). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71912 |
|
Vulnerability in dos (CVE-2026-71912)
vulnerability in dos (CVE-2026-71912). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71920 |
|
Vulnerability in dos (CVE-2026-71920)
vulnerability in dos (CVE-2026-71920). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`.
|
| CVE-2026-78465 |
|
Vulnerability in dos (CVE-2026-78465)
vulnerability in dos (CVE-2026-78465). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77915 |
|
Vulnerability in CVE-2026-77915 (CVE-2026-77915)
vulnerability in CVE-2026-77915 (CVE-2026-77915). Successful exploitation can lead to full system takeover. Exploitable via `POST /register`.
|
| CVE-2026-77914 |
|
Path Traversal in path-traversal (CVE-2026-77914)
path traversal in path-traversal (CVE-2026-77914). Confidential information can be exposed externally.
|
| CVE-2026-60093 |
|
Vulnerability in org.apache.camel:camel-azure-storage-datalake (CVE-2026-60093)
vulnerability in org.apache.camel:camel-azure-storage-datalake (CVE-2026-60093). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-66907 |
|
Vulnerability in org.apache.camel:camel-google-storage (CVE-2026-66907)
vulnerability in org.apache.camel:camel-google-storage (CVE-2026-66907). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-66906 |
|
Vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906)
vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-63621 |
|
Vulnerability in org.apache.camel:camel-knative (CVE-2026-63621)
vulnerability in org.apache.camel:camel-knative (CVE-2026-63621). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2025-36939 |
|
Vulnerability in dos (CVE-2025-36939)
vulnerability in dos (CVE-2025-36939). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-36940 |
|
Use-After-Free in privilege-escalation (CVE-2025-36940)
vulnerability in privilege-escalation (CVE-2025-36940). Successful exploitation can lead to full system takeover.
|