Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10523 |
|
Vulnerability in ivanti (CVE-2026-10523)
vulnerability in ivanti (CVE-2026-10523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10520 KEV |
|
[KEV] OS Command Injection in Ivanti standalone-sentry (CVE-2026-10520)
OS command injection in Ivanti standalone-sentry (CVE-2026-10520). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-9279 |
|
OS Command Injection in CVE-2026-9279 (CVE-2026-9279)
OS command injection in CVE-2026-9279 (CVE-2026-9279). Risk of unauthorized operations or information disclosure. Exploitable via ``git``.
|
| CVE-2026-7486 |
|
SQL Injection in sqli (CVE-2026-7486)
SQL injection in sqli (CVE-2026-7486). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49762 |
|
Vulnerability in dos (CVE-2026-49762)
vulnerability in dos (CVE-2026-49762). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47899 |
|
Vulnerability in CVE-2026-47899 (CVE-2026-47899)
vulnerability in CVE-2026-47899 (CVE-2026-47899). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47900 |
|
Cross-Site Scripting (XSS) in CVE-2026-47900 (CVE-2026-47900)
cross-site scripting in CVE-2026-47900 (CVE-2026-47900). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11790 |
|
Vulnerability in dos (CVE-2026-11790)
vulnerability in dos (CVE-2026-11790). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11793 |
|
Vulnerability in c (CVE-2026-11793)
vulnerability in c (CVE-2026-11793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46319 |
|
Use-After-Free in csharp (CVE-2026-46319)
vulnerability in csharp (CVE-2026-46319). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20244 |
|
SQL Injection in wordpress (CVE-2017-20244)
SQL injection in wordpress (CVE-2017-20244). Confidential information can be exposed externally.
|
| CVE-2017-20245 |
|
SQL Injection in wordpress (CVE-2017-20245)
SQL injection in wordpress (CVE-2017-20245). Confidential information can be exposed externally.
|
| CVE-2017-20246 |
|
SQL Injection in wordpress (CVE-2017-20246)
SQL injection in wordpress (CVE-2017-20246). Confidential information can be exposed externally.
|
| CVE-2017-20247 |
|
SQL Injection in wordpress (CVE-2017-20247)
SQL injection in wordpress (CVE-2017-20247). Confidential information can be exposed externally.
|
| CVE-2017-20249 |
|
SQL Injection in sqli (CVE-2017-20249)
SQL injection in sqli (CVE-2017-20249). Confidential information can be exposed externally.
|
| CVE-2017-20248 |
|
Path Traversal in path-traversal (CVE-2017-20248)
path traversal in path-traversal (CVE-2017-20248). Confidential information can be exposed externally.
|
| CVE-2017-20250 |
|
Path Traversal in wordpress (CVE-2017-20250)
path traversal in wordpress (CVE-2017-20250). Confidential information can be exposed externally.
|
| CVE-2016-20063 |
|
SQL Injection in sqli (CVE-2016-20063)
SQL injection in sqli (CVE-2016-20063). Confidential information can be exposed externally.
|
| CVE-2016-20065 |
|
SQL Injection in wordpress (CVE-2016-20065)
SQL injection in wordpress (CVE-2016-20065). Confidential information can be exposed externally.
|
| CVE-2017-20243 |
|
SQL Injection in wordpress (CVE-2017-20243)
SQL injection in wordpress (CVE-2017-20243). Confidential information can be exposed externally.
|
| CVE-2016-20064 |
|
Vulnerability in path-traversal (CVE-2016-20064)
vulnerability in path-traversal (CVE-2016-20064). Confidential information can be exposed externally.
|
| CVE-2016-20062 |
|
SQL Injection in wordpress (CVE-2016-20062)
SQL injection in wordpress (CVE-2016-20062). Confidential information can be exposed externally.
|
| CVE-2026-49740 |
|
Unsafe Deserialization in typo3/cms-core (CVE-2026-49740)
vulnerability in typo3/cms-core (CVE-2026-49740). Risk of unauthorized operations or information disclosure. Exploitable via ``VariableFrontend``. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-49741 |
|
SQL Injection in typo3/cms-core (CVE-2026-49741)
SQL injection in typo3/cms-core (CVE-2026-49741). Risk of unauthorized operations or information disclosure. Exploitable via ``form_definition``. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47348 |
|
Cross-Site Scripting (XSS) in typo3/cms-core (CVE-2026-47348)
cross-site scripting in typo3/cms-core (CVE-2026-47348). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-46747 |
|
Vulnerability in path-traversal (CVE-2026-46747)
vulnerability in path-traversal (CVE-2026-46747). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/sftp/uploadFiles`.
|
| CVE-2026-52902 |
|
Path Traversal in awxkit (CVE-2026-52902)
path traversal in awxkit (CVE-2026-52902). Confidential information can be exposed externally.
|
| CVE-2026-41031 |
|
Cross-Site Scripting (XSS) in CVE-2026-41031 (CVE-2026-41031)
cross-site scripting in CVE-2026-41031 (CVE-2026-41031). Confidential information can be exposed externally.
|
| CVE-2026-10731 |
|
SQL Injection in sqli (CVE-2026-10731)
SQL injection in sqli (CVE-2026-10731). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-40808 |
|
Unrestricted File Upload in dos (CVE-2025-40808)
vulnerability in dos (CVE-2025-40808). Data can be tampered with by attackers.
|
| CVE-2026-11616 |
|
Privilege Escalation in wordpress (CVE-2026-11616)
vulnerability in wordpress (CVE-2026-11616). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8365 |
|
Unsafe Deserialization in wordpress (CVE-2026-8365)
vulnerability in wordpress (CVE-2026-8365). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34033 |
|
Cross-Site Scripting (XSS) in github.com/apache/incubator-answer (CVE-2026-34033)
cross-site scripting in github.com/apache/incubator-answer (CVE-2026-34033). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.2-0.20260509080709-d1a4092c61cc` or later.
|
| CVE-2026-8677 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8677)
cross-site scripting in wordpress (CVE-2026-8677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25688 |
|
Vulnerability in github.com/apache/incubator-answer (CVE-2026-25688)
vulnerability in github.com/apache/incubator-answer (CVE-2026-25688). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.2-0.20260525024654-2746bf5b455f` or later.
|
| CVE-2026-8599 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8599)
cross-site scripting in wordpress (CVE-2026-8599). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41983 |
|
Vulnerability in dos (CVE-2026-41983)
vulnerability in dos (CVE-2026-41983). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41977 |
|
Vulnerability in dos (CVE-2026-41977)
vulnerability in dos (CVE-2026-41977). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41972 |
|
Path Traversal in path-traversal (CVE-2026-41972)
path traversal in path-traversal (CVE-2026-41972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41539 |
|
Cross-Site Scripting (XSS) in qnap (CVE-2026-41539)
cross-site scripting in qnap (CVE-2026-41539). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5067 |
|
Vulnerability in dos (CVE-2026-5067)
vulnerability in dos (CVE-2026-5067). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8977 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8977)
cross-site scripting in wordpress (CVE-2026-8977). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9662 |
|
Vulnerability in wordpress (CVE-2026-9662)
vulnerability in wordpress (CVE-2026-9662). Successful exploitation can lead to full system takeover. Exploitable via ``tpf``.
|
| CVE-2026-8895 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8895)
cross-site scripting in wordpress (CVE-2026-8895). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7662 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7662)
cross-site scripting in wordpress (CVE-2026-7662). Risk of unauthorized operations or information disclosure. Exploitable via ``epaperflip_embed``.
|
| CVE-2026-8841 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8841)
cross-site scripting in wordpress (CVE-2026-8841). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8880 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8880)
cross-site scripting in wordpress (CVE-2026-8880). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8882 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8882)
cross-site scripting in wordpress (CVE-2026-8882). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8883 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8883)
cross-site scripting in wordpress (CVE-2026-8883). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41854 |
|
SSRF (Server-Side Request Forgery) in org.springframework:spring-web (CVE-2026-41854)
SSRF in org.springframework:spring-web (CVE-2026-41854). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.19` or later.
|