Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39885 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-39885)
SSRF in ssrf (CVE-2026-39885). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.0` or later.
|
| CVE-2026-39416 |
|
Cross-Site Scripting (XSS) in circl (CVE-2026-39416)
cross-site scripting in circl (CVE-2026-39416). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.8` or later.
|
| CVE-2026-39415 |
|
Vulnerability in privilege-escalation (CVE-2026-39415)
vulnerability in privilege-escalation (CVE-2026-39415). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.46.0` or later.
|
| CVE-2026-39863 |
|
Buffer Overflow in dos (CVE-2026-39863)
vulnerability in dos (CVE-2026-39863). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.1.1` or later.
|
| CVE-2026-39864 |
|
Out-of-Bounds Read in dos (CVE-2026-39864)
vulnerability in dos (CVE-2026-39864). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.5` or later.
|
| CVE-2026-39862 |
|
OS Command Injection in c (CVE-2026-39862)
OS command injection in c (CVE-2026-39862). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.5.1` or later.
|
| CVE-2026-23869 |
|
Vulnerability in react (CVE-2026-23869)
vulnerability in react (CVE-2026-23869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35455 |
|
Cross-Site Scripting (XSS) in futo (CVE-2026-35455)
cross-site scripting in futo (CVE-2026-35455). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.7.0` or later.
|
| CVE-2026-35169 |
|
Cross-Site Scripting (XSS) in mcgill (CVE-2026-35169)
cross-site scripting in mcgill (CVE-2026-35169). Confidential information can be exposed externally. Mitigation: upgrade to `27.0.3` or later.
|
| CVE-2026-35403 |
|
Cross-Site Scripting (XSS) in mcgill (CVE-2026-35403)
cross-site scripting in mcgill (CVE-2026-35403). Confidential information can be exposed externally. Mitigation: upgrade to `27.0.3` or later.
|
| CVE-2026-34724 |
|
Code Injection in zammad (CVE-2026-34724)
code injection in zammad (CVE-2026-34724). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.1` or later.
|
| CVE-2026-34721 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34721)
vulnerability in csrf (CVE-2026-34721). Confidential information can be exposed externally. Mitigation: upgrade to `7.0.1` or later.
|
| CVE-2026-33350 |
|
SQL Injection in sqli (CVE-2026-33350)
SQL injection in sqli (CVE-2026-33350). Confidential information can be exposed externally. Mitigation: upgrade to `27.0.3` or later.
|
| CVE-2026-34166 |
|
Vulnerability in dos (CVE-2026-34166)
vulnerability in dos (CVE-2026-34166). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.25.3` or later.
|
| CVE-2026-2942 |
|
Unrestricted File Upload in wordpress (CVE-2026-2942)
vulnerability in wordpress (CVE-2026-2942). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39890 |
|
Unsafe Deserialization in praisonai (CVE-2026-39890)
vulnerability in praisonai (CVE-2026-39890). Successful exploitation can lead to full system takeover. Exploitable via ``AgentService.loadAgentFromFile``. Mitigation: upgrade to `4.5.115` or later.
|
| CVE-2026-33466 |
|
Path Traversal in path-traversal (CVE-2026-33466)
path traversal in path-traversal (CVE-2026-33466). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33459 |
|
Vulnerability in dos (CVE-2026-33459)
vulnerability in dos (CVE-2026-33459). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-52222 |
|
Vulnerability in dos (CVE-2025-52222)
vulnerability in dos (CVE-2025-52222). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-45057 |
|
Vulnerability in dos (CVE-2025-45057)
vulnerability in dos (CVE-2025-45057). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-45058 |
|
Vulnerability in dos (CVE-2025-45058)
vulnerability in dos (CVE-2025-45058). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-45059 |
|
Vulnerability in dos (CVE-2025-45059)
vulnerability in dos (CVE-2025-45059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4837 |
|
Vulnerability in rapid7 (CVE-2026-4837)
vulnerability in rapid7 (CVE-2026-4837). Successful exploitation can lead to full system takeover.
|
| CVE-2026-31017 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-31017)
SSRF in ssrf (CVE-2026-31017). Confidential information can be exposed externally.
|
| CVE-2026-30075 |
|
Vulnerability in dos (CVE-2026-30075)
vulnerability in dos (CVE-2026-30075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2377 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-2377)
SSRF in ssrf (CVE-2026-2377). Confidential information can be exposed externally.
|
| CVE-2023-46945 |
|
QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
QD 20230821 is vulnerable to Server-side request forgery (SSRF) via a crafted request
|
| CVE-2025-57847 |
|
Vulnerability in privilege-escalation (CVE-2025-57847)
vulnerability in privilege-escalation (CVE-2025-57847). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39394 |
|
Vulnerability in csrf (CVE-2026-39394)
vulnerability in csrf (CVE-2026-39394). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.31.4.0` or later.
|
| CVE-2026-39408 |
|
Path Traversal in path-traversal (CVE-2026-39408)
path traversal in path-traversal (CVE-2026-39408). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-5795 |
|
Vulnerability in privilege-escalation (CVE-2026-5795)
vulnerability in privilege-escalation (CVE-2026-5795). Confidential information can be exposed externally.
|
| CVE-2026-2509 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2509)
cross-site scripting in wordpress (CVE-2026-2509). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-57853 |
|
Vulnerability in c (CVE-2025-57853)
vulnerability in c (CVE-2025-57853). Successful exploitation can lead to full system takeover.
|
| CVE-2025-57854 |
|
Vulnerability in privilege-escalation (CVE-2025-57854)
vulnerability in privilege-escalation (CVE-2025-57854). Successful exploitation can lead to full system takeover.
|
| CVE-2025-58713 |
|
Vulnerability in privilege-escalation (CVE-2025-58713)
vulnerability in privilege-escalation (CVE-2025-58713). Successful exploitation can lead to full system takeover.
|
| CVE-2025-57851 |
|
Vulnerability in privilege-escalation (CVE-2025-57851)
vulnerability in privilege-escalation (CVE-2025-57851). Successful exploitation can lead to full system takeover.
|
| CVE-2025-14815 |
|
Vulnerability in dos (CVE-2025-14815)
vulnerability in dos (CVE-2025-14815). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-14816 |
|
Vulnerability in dos (CVE-2025-14816)
vulnerability in dos (CVE-2025-14816). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5301 |
|
Cross-Site Scripting (XSS) in coolercontrol (CVE-2026-5301)
cross-site scripting in coolercontrol (CVE-2026-5301). Data can be tampered with by attackers.
|
| CVE-2026-3243 |
|
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1....
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
|
| CVE-2026-3396 |
|
SQL Injection in sqli (CVE-2026-3396)
SQL injection in sqli (CVE-2026-3396). Confidential information can be exposed externally.
|
| CVE-2026-2481 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2481)
cross-site scripting in wordpress (CVE-2026-2481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1865 |
|
SQL Injection in wordpress (CVE-2026-1865)
SQL injection in wordpress (CVE-2026-1865). Confidential information can be exposed externally.
|
| CVE-2026-4303 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4303)
cross-site scripting in wordpress (CVE-2026-4303). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4073 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4073)
cross-site scripting in wordpress (CVE-2026-4073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4300 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4300)
cross-site scripting in wordpress (CVE-2026-4300). Risk of unauthorized operations or information disclosure. Exploitable via ``rbs_gallery_LoadingWord``.
|
| CVE-2026-4025 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4025)
cross-site scripting in wordpress (CVE-2026-4025). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39712 |
|
Vulnerability in CVE-2026-39712 (CVE-2026-39712)
vulnerability in CVE-2026-39712 (CVE-2026-39712). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39708 |
|
Cross-Site Scripting (XSS) in CVE-2026-39708 (CVE-2026-39708)
cross-site scripting in CVE-2026-39708 (CVE-2026-39708). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39710 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39710)
vulnerability in csrf (CVE-2026-39710). Risk of unauthorized operations or information disclosure.
|