Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75077 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-75077)
cross-site scripting in c (CVE-2026-75077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67918 |
|
Path Traversal in path-traversal (CVE-2026-67918)
path traversal in path-traversal (CVE-2026-67918). Confidential information can be exposed externally.
|
| CVE-2026-67854 |
|
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
|
| CVE-2026-75531 |
|
Cross-Site Scripting (XSS) in CVE-2026-75531 (CVE-2026-75531)
cross-site scripting in CVE-2026-75531 (CVE-2026-75531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75529 |
|
Cross-Site Scripting (XSS) in flask (CVE-2026-75529)
cross-site scripting in flask (CVE-2026-75529). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75482 |
|
Path Traversal in path-traversal (CVE-2026-75482)
path traversal in path-traversal (CVE-2026-75482). Confidential information can be exposed externally.
|
| CVE-2026-75479 |
|
Vulnerability in CVE-2026-75479 (CVE-2026-75479)
vulnerability in CVE-2026-75479 (CVE-2026-75479). Confidential information can be exposed externally.
|
| CVE-2026-66795 |
|
Vulnerability in privilege-escalation (CVE-2026-66795)
vulnerability in privilege-escalation (CVE-2026-66795). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67917 |
|
SQL Injection in sqli (CVE-2026-67917)
SQL injection in sqli (CVE-2026-67917). Successful exploitation can lead to full system takeover. Exploitable via ``db.sql``.
|
| CVE-2026-67925 |
|
Cross-Site Scripting (XSS) in CVE-2026-67925 (CVE-2026-67925)
cross-site scripting in CVE-2026-67925 (CVE-2026-67925). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65640 |
|
Unrestricted File Upload in wordpress (CVE-2026-65640)
vulnerability in wordpress (CVE-2026-65640). Successful exploitation can lead to full system takeover. Exploitable via ``upload_files``.
|
| CVE-2026-65974 |
|
Vulnerability in CVE-2026-65974 (CVE-2026-65974)
vulnerability in CVE-2026-65974 (CVE-2026-65974). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40506 |
|
Path Traversal in path-traversal (CVE-2026-40506)
path traversal in path-traversal (CVE-2026-40506). Data can be tampered with by attackers.
|
| CVE-2026-75014 |
|
Vulnerability in sqli (CVE-2026-75014)
vulnerability in sqli (CVE-2026-75014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74234 |
|
Vulnerability in CVE-2026-74234 (CVE-2026-74234)
vulnerability in CVE-2026-74234 (CVE-2026-74234). Confidential information can be exposed externally.
|
| CVE-2026-71553 |
|
Vulnerability in dos (CVE-2026-71553)
vulnerability in dos (CVE-2026-71553). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/v1/article/`.
|
| CVE-2026-68005 |
|
Vulnerability in dos (CVE-2026-68005)
vulnerability in dos (CVE-2026-68005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50775 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-50775)
SSRF in ssrf (CVE-2026-50775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50776 |
|
Path Traversal in path-traversal (CVE-2026-50776)
path traversal in path-traversal (CVE-2026-50776). Confidential information can be exposed externally.
|
| CVE-2026-17639 |
|
Vulnerability in dos (CVE-2026-17639)
vulnerability in dos (CVE-2026-17639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74253 |
|
Code Injection in CVE-2026-74253 (CVE-2026-74253)
code injection in CVE-2026-74253 (CVE-2026-74253). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74254 |
|
SQL Injection in sqli (CVE-2026-74254)
SQL injection in sqli (CVE-2026-74254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51346 |
|
SQL Injection in sqli (CVE-2026-51346)
SQL injection in sqli (CVE-2026-51346). Confidential information can be exposed externally.
|
| CVE-2026-50769 |
|
SQL Injection in sqli (CVE-2026-50769)
SQL injection in sqli (CVE-2026-50769). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50771 |
|
Cross-Site Scripting (XSS) in CVE-2026-50771 (CVE-2026-50771)
cross-site scripting in CVE-2026-50771 (CVE-2026-50771). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73522 |
|
Vulnerability in dos (CVE-2026-73522)
vulnerability in dos (CVE-2026-73522). Data can be tampered with by attackers.
|
| CVE-2026-75054 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75054)
SSRF in ssrf (CVE-2026-75054). Confidential information can be exposed externally.
|
| CVE-2026-75053 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
|
| CVE-2026-75056 |
|
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
|
| CVE-2026-75050 |
|
Vulnerability in dos (CVE-2026-75050)
vulnerability in dos (CVE-2026-75050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75047 |
|
Vulnerability in dos (CVE-2026-75047)
vulnerability in dos (CVE-2026-75047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75048 |
|
Cross-Site Scripting (XSS) in CVE-2026-75048 (CVE-2026-75048)
cross-site scripting in CVE-2026-75048 (CVE-2026-75048). Confidential information can be exposed externally.
|
| CVE-2026-68762 |
|
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible
|
| CVE-2026-33437 |
|
Cross-Site Scripting (XSS) in CVE-2026-33437 (CVE-2026-33437)
cross-site scripting in CVE-2026-33437 (CVE-2026-33437). Confidential information can be exposed externally.
|
| CVE-2026-55090 |
|
Cross-Site Scripting (XSS) in ep_etherpad-lite (CVE-2026-55090)
cross-site scripting in ep_etherpad-lite (CVE-2026-55090). Risk of unauthorized operations or information disclosure. Exploitable via ``getHTMLFromAtext``. Mitigation: upgrade to `3.3.0` or later.
|
| CVE-2026-9771 |
|
Vulnerability in c (CVE-2026-9771)
vulnerability in c (CVE-2026-9771). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12629 |
|
Vulnerability in c (CVE-2026-12629)
vulnerability in c (CVE-2026-12629). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12519 |
|
Out-of-Bounds Write in c (CVE-2026-12519)
out-of-bounds write in c (CVE-2026-12519). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-27770 |
|
Vulnerability in CVE-2025-27770 (CVE-2025-27770)
vulnerability in CVE-2025-27770 (CVE-2025-27770). Risk of unauthorized operations or information disclosure. Exploitable via ``checks``.
|
| CVE-2025-27771 |
|
Vulnerability in CVE-2025-27771 (CVE-2025-27771)
vulnerability in CVE-2025-27771 (CVE-2025-27771). Risk of unauthorized operations or information disclosure. Exploitable via ``checks``.
|
| CVE-2025-27772 |
|
Vulnerability in CVE-2025-27772 (CVE-2025-27772)
vulnerability in CVE-2025-27772 (CVE-2025-27772). Risk of unauthorized operations or information disclosure. Exploitable via ``checks``.
|
| CVE-2026-59909 |
|
Vulnerability in path-traversal (CVE-2026-59909)
vulnerability in path-traversal (CVE-2026-59909). Data can be tampered with by attackers.
|
| CVE-2026-56089 |
|
Vulnerability in path-traversal (CVE-2026-56089)
vulnerability in path-traversal (CVE-2026-56089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75006 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75006)
SSRF in ssrf (CVE-2026-75006). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15218 |
|
Vulnerability in CVE-2026-15218 (CVE-2026-15218)
vulnerability in CVE-2026-15218 (CVE-2026-15218). Confidential information can be exposed externally.
|
| CVE-2026-16139 |
|
Vulnerability in CVE-2026-16139 (CVE-2026-16139)
vulnerability in CVE-2026-16139 (CVE-2026-16139). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16137 |
|
Path Traversal in path-traversal (CVE-2026-16137)
path traversal in path-traversal (CVE-2026-16137). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74999 |
|
Cross-Site Scripting (XSS) in CVE-2026-74999 (CVE-2026-74999)
cross-site scripting in CVE-2026-74999 (CVE-2026-74999). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16138 |
|
Unsafe Deserialization in deserialization (CVE-2026-16138)
vulnerability in deserialization (CVE-2026-16138). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75007 |
|
Command Injection in privilege-escalation (CVE-2026-75007)
command injection in privilege-escalation (CVE-2026-75007). Risk of unauthorized operations or information disclosure.
|