Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-11400 AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-46400 Unrestricted File Upload in CVE-2026-46400 (CVE-2026-46400)
vulnerability in CVE-2026-46400 (CVE-2026-46400). Risk of unauthorized operations or information disclosure.
CVE-2026-45779 SQL Injection in sqli (CVE-2026-45779)
SQL injection in sqli (CVE-2026-45779). Successful exploitation can lead to full system takeover.
CVE-2026-25624 Cross-Site Scripting (XSS) in arista (CVE-2026-25624)
cross-site scripting in arista (CVE-2026-25624). Confidential information can be exposed externally.
CVE-2026-11419 Path Traversal in path-traversal (CVE-2026-11419)
path traversal in path-traversal (CVE-2026-11419). Successful exploitation can lead to full system takeover.
CVE-2026-11420 Path Traversal in path-traversal (CVE-2026-11420)
path traversal in path-traversal (CVE-2026-11420). Successful exploitation can lead to full system takeover.
CVE-2026-11414 Path Traversal in path-traversal (CVE-2026-11414)
path traversal in path-traversal (CVE-2026-11414). Successful exploitation can lead to full system takeover.
CVE-2026-11401 AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-5415 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-5411 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-46392 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filen...
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...
CVE-2026-46394 OS Command Injection in CVE-2026-46394 (CVE-2026-46394)
OS command injection in CVE-2026-46394 (CVE-2026-46394). Risk of unauthorized operations or information disclosure.
CVE-2026-10580 Vulnerability in wordpress (CVE-2026-10580)
vulnerability in wordpress (CVE-2026-10580). Successful exploitation can lead to full system takeover.
CVE-2026-45746 Vulnerability in termix (CVE-2026-45746)
vulnerability in termix (CVE-2026-45746). Successful exploitation can lead to full system takeover.
CVE-2026-36500 Path Traversal in path-traversal (CVE-2026-36500)
path traversal in path-traversal (CVE-2026-36500). Confidential information can be exposed externally.
CVE-2026-36501 Vulnerability in dos (CVE-2026-36501)
vulnerability in dos (CVE-2026-36501). Risk of unauthorized operations or information disclosure.
CVE-2026-11342 Vulnerability in sqli (CVE-2026-11342)
vulnerability in sqli (CVE-2026-11342). Risk of unauthorized operations or information disclosure.
CVE-2026-47731 Path Traversal in ait-core (CVE-2026-47731)
path traversal in ait-core (CVE-2026-47731). Data can be tampered with by attackers. Exploitable via ``python_poc.py``. Mitigation: upgrade to `2.6.1` or later.
CVE-2026-48103 Out-of-Bounds Read in cpp (CVE-2026-48103)
vulnerability in cpp (CVE-2026-48103). Risk of unauthorized operations or information disclosure.
CVE-2026-48104 Out-of-Bounds Read in dos (CVE-2026-48104)
vulnerability in dos (CVE-2026-48104). Risk of unauthorized operations or information disclosure.
CVE-2026-48111 Out-of-Bounds Read in cpp (CVE-2026-48111)
vulnerability in cpp (CVE-2026-48111). Risk of unauthorized operations or information disclosure.
CVE-2026-11338 Cross-Site Scripting (XSS) in CVE-2026-11338 (CVE-2026-11338)
cross-site scripting in CVE-2026-11338 (CVE-2026-11338). Risk of unauthorized operations or information disclosure.
CVE-2026-11337 Cross-Site Scripting (XSS) in CVE-2026-11337 (CVE-2026-11337)
cross-site scripting in CVE-2026-11337 (CVE-2026-11337). Risk of unauthorized operations or information disclosure.
CVE-2025-5089 Vulnerability in dos (CVE-2025-5089)
vulnerability in dos (CVE-2025-5089). Risk of unauthorized operations or information disclosure.
CVE-2025-5090 Vulnerability in dos (CVE-2025-5090)
vulnerability in dos (CVE-2025-5090). Risk of unauthorized operations or information disclosure.
CVE-2026-52880 Vulnerability in github.com/klever-io/klever-go (CVE-2026-52880)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52880). Risk of unauthorized operations or information disclosure. Exploitable via ``Engine.Run``. Mitigation: upgrade to `1.7.18` or later.
CVE-2026-52879 Vulnerability in github.com/klever-io/klever-go (CVE-2026-52879)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52879). Risk of unauthorized operations or information disclosure. Exploitable via ``networkMessenger.directMessageHandler``. Mitigation: upgrade to `1.7.18` or later.
CVE-2026-47684 SSRF (Server-Side Request Forgery) in @sync-in/server (CVE-2026-47684)
SSRF in @sync-in/server (CVE-2026-47684). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.0` or later.
CVE-2026-47670 Command Injection in dbgate-api (CVE-2026-47670)
command injection in dbgate-api (CVE-2026-47670). Risk of unauthorized operations or information disclosure. Exploitable via ``functionName``. Mitigation: upgrade to `7.1.9` or later.
CVE-2026-47668 Vulnerability in dbgate-serve (CVE-2026-47668)
vulnerability in dbgate-serve (CVE-2026-47668). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/start`. Mitigation: upgrade to `7.1.9` or later.
CVE-2026-48102 Out-of-Bounds Read in cpp (CVE-2026-48102)
vulnerability in cpp (CVE-2026-48102). Risk of unauthorized operations or information disclosure.
CVE-2026-47250 Vulnerability in mcp-server-kubernetes (CVE-2026-47250)
vulnerability in mcp-server-kubernetes (CVE-2026-47250). Confidential information can be exposed externally. Exploitable via ``kubectl_generic``. Mitigation: upgrade to `3.7.0` or later.
CVE-2026-11334 Vulnerability in sqli (CVE-2026-11334)
vulnerability in sqli (CVE-2026-11334). Risk of unauthorized operations or information disclosure.
CVE-2026-38579 Cross-Site Scripting (XSS) in CVE-2026-38579 (CVE-2026-38579)
cross-site scripting in CVE-2026-38579 (CVE-2026-38579). Risk of unauthorized operations or information disclosure.
CVE-2026-48095 Vulnerability in dos (CVE-2026-48095)
vulnerability in dos (CVE-2026-48095). Successful exploitation can lead to full system takeover.
CVE-2026-50230 Cross-Site Scripting (XSS) in CVE-2026-50230 (CVE-2026-50230)
cross-site scripting in CVE-2026-50230 (CVE-2026-50230). Risk of unauthorized operations or information disclosure.
CVE-2026-50231 Cross-Site Scripting (XSS) in CVE-2026-50231 (CVE-2026-50231)
cross-site scripting in CVE-2026-50231 (CVE-2026-50231). Risk of unauthorized operations or information disclosure. Exploitable via `User-Agent header`.
CVE-2026-50232 Cross-Site Scripting (XSS) in CVE-2026-50232 (CVE-2026-50232)
cross-site scripting in CVE-2026-50232 (CVE-2026-50232). Risk of unauthorized operations or information disclosure.
CVE-2026-50235 Cross-Site Scripting (XSS) in CVE-2026-50235 (CVE-2026-50235)
cross-site scripting in CVE-2026-50235 (CVE-2026-50235). Risk of unauthorized operations or information disclosure.
CVE-2026-50234 Path Traversal in c (CVE-2026-50234)
path traversal in c (CVE-2026-50234). Confidential information can be exposed externally.
CVE-2026-50264 Out-of-Bounds Write in privilege-escalation (CVE-2026-50264)
out-of-bounds write in privilege-escalation (CVE-2026-50264). Successful exploitation can lead to full system takeover.
CVE-2026-50258 Vulnerability in privilege-escalation (CVE-2026-50258)
vulnerability in privilege-escalation (CVE-2026-50258). Successful exploitation can lead to full system takeover.
CVE-2026-50259 Vulnerability in privilege-escalation (CVE-2026-50259)
vulnerability in privilege-escalation (CVE-2026-50259). Successful exploitation can lead to full system takeover.
CVE-2026-50260 Use-After-Free in privilege-escalation (CVE-2026-50260)
vulnerability in privilege-escalation (CVE-2026-50260). Successful exploitation can lead to full system takeover.
CVE-2026-50261 Use-After-Free in privilege-escalation (CVE-2026-50261)
vulnerability in privilege-escalation (CVE-2026-50261). Successful exploitation can lead to full system takeover.
CVE-2026-50256 Vulnerability in privilege-escalation (CVE-2026-50256)
vulnerability in privilege-escalation (CVE-2026-50256). Successful exploitation can lead to full system takeover.
CVE-2026-50257 Use-After-Free in privilege-escalation (CVE-2026-50257)
vulnerability in privilege-escalation (CVE-2026-50257). Successful exploitation can lead to full system takeover.
CVE-2026-11346 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-11346)
SSRF in ssrf (CVE-2026-11346). Risk of unauthorized operations or information disclosure.
CVE-2026-10732 Path Traversal in decompress (CVE-2026-10732)
path traversal in decompress (CVE-2026-10732). Data can be tampered with by attackers.
CVE-2026-21825 Cross-Site Scripting (XSS) in hcltech (CVE-2026-21825)
cross-site scripting in hcltech (CVE-2026-21825). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →