Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10811 |
|
Vulnerability in sqli (CVE-2026-10811)
vulnerability in sqli (CVE-2026-10811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10863 |
|
Vulnerability in sqli (CVE-2026-10863)
vulnerability in sqli (CVE-2026-10863). Confidential information can be exposed externally.
|
| CVE-2026-8037 KEV |
|
[KEV] Command Injection in Progress connection-manager-for-objectscale (CVE-2026-8037)
command injection in Progress connection-manager-for-objectscale (CVE-2026-8037). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-10808 |
|
Vulnerability in sqli (CVE-2026-10808)
vulnerability in sqli (CVE-2026-10808). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10809 |
|
Vulnerability in sqli (CVE-2026-10809)
vulnerability in sqli (CVE-2026-10809). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10810 |
|
Cross-Site Scripting (XSS) in CVE-2026-10810 (CVE-2026-10810)
cross-site scripting in CVE-2026-10810 (CVE-2026-10810). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25745 |
|
SQL Injection in wordpress (CVE-2019-25745)
SQL injection in wordpress (CVE-2019-25745). Confidential information can be exposed externally.
|
| CVE-2019-25742 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25742)
cross-site scripting in wordpress (CVE-2019-25742). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25744 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25744)
cross-site scripting in wordpress (CVE-2019-25744). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25737 |
|
Cross-Site Scripting (XSS) in CVE-2019-25737 (CVE-2019-25737)
cross-site scripting in CVE-2019-25737 (CVE-2019-25737). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25739 |
|
Cross-Site Scripting (XSS) in CVE-2019-25739 (CVE-2019-25739)
cross-site scripting in CVE-2019-25739 (CVE-2019-25739). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25743 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25743)
cross-site scripting in wordpress (CVE-2019-25743). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25734 |
|
Path Traversal in csrf (CVE-2019-25734)
path traversal in csrf (CVE-2019-25734). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25740 |
|
Path Traversal in path-traversal (CVE-2019-25740)
path traversal in path-traversal (CVE-2019-25740). Confidential information can be exposed externally.
|
| CVE-2025-46638 |
|
Vulnerability in dos (CVE-2025-46638)
vulnerability in dos (CVE-2025-46638). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25730 |
|
SQL Injection in sqli (CVE-2019-25730)
SQL injection in sqli (CVE-2019-25730). Confidential information can be exposed externally.
|
| CVE-2019-25732 |
|
SQL Injection in sqli (CVE-2019-25732)
SQL injection in sqli (CVE-2019-25732). Confidential information can be exposed externally.
|
| CVE-2019-25731 |
|
Cross-Site Scripting (XSS) in CVE-2019-25731 (CVE-2019-25731)
cross-site scripting in CVE-2019-25731 (CVE-2019-25731). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25728 |
|
SQL Injection in sqli (CVE-2019-25728)
SQL injection in sqli (CVE-2019-25728). Confidential information can be exposed externally.
|
| CVE-2019-25726 |
|
SQL Injection in sqli (CVE-2019-25726)
SQL injection in sqli (CVE-2019-25726). Confidential information can be exposed externally.
|
| CVE-2019-25729 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2019-25729)
vulnerability in csrf (CVE-2019-25729). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41065 |
|
Vulnerability in CVE-2026-41065 (CVE-2026-41065)
vulnerability in CVE-2026-41065 (CVE-2026-41065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47707 |
|
Vulnerability in strawberry-graphql (CVE-2026-47707)
vulnerability in strawberry-graphql (CVE-2026-47707). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.315.7` or later.
|
| CVE-2026-47706 |
|
Vulnerability in strawberry-graphql (CVE-2026-47706)
vulnerability in strawberry-graphql (CVE-2026-47706). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.315.7` or later.
|
| CVE-2026-40605 |
|
Path Traversal in path-traversal (CVE-2026-40605)
path traversal in path-traversal (CVE-2026-40605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45431 |
|
OS Command Injection in CVE-2026-45431 (CVE-2026-45431)
OS command injection in CVE-2026-45431 (CVE-2026-45431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4104 |
|
SQL Injection in sqli (CVE-2026-4104)
SQL injection in sqli (CVE-2026-4104). Successful exploitation can lead to full system takeover.
|
| CVE-2025-52612 |
|
Vulnerability in hcltech (CVE-2025-52612)
vulnerability in hcltech (CVE-2025-52612). Successful exploitation can lead to full system takeover.
|
| CVE-2025-52609 |
|
Vulnerability in hcltech (CVE-2025-52609)
vulnerability in hcltech (CVE-2025-52609). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-12694 |
|
Vulnerability in privilege-escalation (CVE-2025-12694)
vulnerability in privilege-escalation (CVE-2025-12694). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49771 |
|
SQL Injection in sqli (CVE-2026-49771)
SQL injection in sqli (CVE-2026-49771). Confidential information can be exposed externally.
|
| CVE-2026-50212 |
|
Vulnerability in dos (CVE-2026-50212)
vulnerability in dos (CVE-2026-50212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10805 |
|
OS Command Injection in privilege-escalation (CVE-2026-10805)
OS command injection in privilege-escalation (CVE-2026-10805). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48681 |
|
Vulnerability in ironic (CVE-2026-48681)
vulnerability in ironic (CVE-2026-48681). Confidential information can be exposed externally. Mitigation: upgrade to `35.0.2` or later.
|
| CVE-2026-41283 |
|
Authorization Flaw in mistral (CVE-2026-41283)
vulnerability in mistral (CVE-2026-41283). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8653 |
|
SQL Injection in wordpress (CVE-2026-8653)
SQL injection in wordpress (CVE-2026-8653). Confidential information can be exposed externally.
|
| CVE-2026-7764 |
|
Out-of-Bounds Read in dos (CVE-2026-7764)
vulnerability in dos (CVE-2026-7764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10775 |
|
Vulnerability in sglang (CVE-2026-10775)
vulnerability in sglang (CVE-2026-10775). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10777 |
|
A vulnerability was identified in ealpha072 Student-Management-System up to...
A vulnerability was identified in ealpha072 Student-Management-System up to...
|
| CVE-2026-10771 |
|
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate...
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate...
|
| CVE-2026-44023 |
|
Path Traversal in docling-core (CVE-2026-44023)
path traversal in docling-core (CVE-2026-44023). Confidential information can be exposed externally. Mitigation: upgrade to `2.74.1` or later.
|
| CVE-2026-44022 |
|
Path Traversal in docling (CVE-2026-44022)
path traversal in docling (CVE-2026-44022). Confidential information can be exposed externally. Mitigation: upgrade to `2.91.0` or later.
|
| CVE-2026-44020 |
|
XXE (XML External Entity) in docling (CVE-2026-44020)
vulnerability in docling (CVE-2026-44020). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.74.0` or later.
|
| CVE-2026-44016 |
|
Code Injection in docling (CVE-2026-44016)
code injection in docling (CVE-2026-44016). Confidential information can be exposed externally. Mitigation: upgrade to `2.91.0` or later.
|
| CVE-2026-40898 |
|
Vulnerability in github.com/quic-go/quic-go (CVE-2026-40898)
vulnerability in github.com/quic-go/quic-go (CVE-2026-40898). Risk of unauthorized operations or information disclosure. Exploitable via ``http.Header``. Mitigation: upgrade to `0.59.1` or later.
|
| CVE-2026-44609 |
|
Vulnerability in privilege-escalation (CVE-2026-44609)
vulnerability in privilege-escalation (CVE-2026-44609). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44682 |
|
Vulnerability in privilege-escalation (CVE-2026-44682)
vulnerability in privilege-escalation (CVE-2026-44682). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50033 |
|
Vulnerability in privilege-escalation (CVE-2026-50033)
vulnerability in privilege-escalation (CVE-2026-50033). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42061 |
|
Vulnerability in privilege-escalation (CVE-2026-42061)
vulnerability in privilege-escalation (CVE-2026-42061). Successful exploitation can lead to full system takeover.
|
| CVE-2026-37700 |
|
Cross-Site Scripting (XSS) in CVE-2026-37700 (CVE-2026-37700)
cross-site scripting in CVE-2026-37700 (CVE-2026-37700). Risk of unauthorized operations or information disclosure.
|