Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72811 |
|
SQL Injection in sqli (CVE-2026-72811)
SQL injection in sqli (CVE-2026-72811). Confidential information can be exposed externally. Mitigation: upgrade to `3.7.4` or later.
|
| CVE-2026-72813 |
|
Vulnerability in dos (CVE-2026-72813)
vulnerability in dos (CVE-2026-72813). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19812 |
|
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the...
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the...
|
| CVE-2026-19813 |
|
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts...
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts...
|
| CVE-2026-19794 |
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
| CVE-2026-19811 |
|
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted...
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted...
|
| CVE-2026-16810 |
|
SQL Injection in wordpress (CVE-2026-16810)
SQL injection in wordpress (CVE-2026-16810). Confidential information can be exposed externally.
|
| CVE-2026-12743 |
|
SQL Injection in wordpress (CVE-2026-12743)
SQL injection in wordpress (CVE-2026-12743). Confidential information can be exposed externally.
|
| CVE-2026-15205 |
|
SQL Injection in wordpress (CVE-2026-15205)
SQL injection in wordpress (CVE-2026-15205). Confidential information can be exposed externally.
|
| CVE-2026-12949 |
|
Vulnerability in wordpress (CVE-2026-12949)
vulnerability in wordpress (CVE-2026-12949). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19617 |
|
Vulnerability in dos (CVE-2026-19617)
vulnerability in dos (CVE-2026-19617). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19787 |
|
Vulnerability in sqli (CVE-2026-19787)
vulnerability in sqli (CVE-2026-19787). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19785 |
|
Vulnerability in sqli (CVE-2026-19785)
vulnerability in sqli (CVE-2026-19785). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18109 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18109)
cross-site scripting in wordpress (CVE-2026-18109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19771 |
|
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown...
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown...
|
| CVE-2026-19767 |
|
Vulnerability in sqli (CVE-2026-19767)
vulnerability in sqli (CVE-2026-19767). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19764 |
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
| CVE-2026-19763 |
|
Path Traversal in path-traversal (CVE-2026-19763)
path traversal in path-traversal (CVE-2026-19763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19762 |
|
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
|
| CVE-2026-19761 |
|
Path Traversal in path-traversal (CVE-2026-19761)
path traversal in path-traversal (CVE-2026-19761). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19758 |
|
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
|
| CVE-2026-19757 |
|
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
|
| CVE-2026-19756 |
|
Path Traversal in path-traversal (CVE-2026-19756)
path traversal in path-traversal (CVE-2026-19756). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72851 |
|
SQL Injection in sqli (CVE-2026-72851)
SQL injection in sqli (CVE-2026-72851). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72853 |
|
SQL Injection in sqli (CVE-2026-72853)
SQL injection in sqli (CVE-2026-72853). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72856 |
|
Vulnerability in CVE-2026-72856 (CVE-2026-72856)
vulnerability in CVE-2026-72856 (CVE-2026-72856). Confidential information can be exposed externally. Exploitable via `PUT /api/global/users/tenant/owner`.
|
| CVE-2026-72776 |
|
Vulnerability in CVE-2026-72776 (CVE-2026-72776)
vulnerability in CVE-2026-72776 (CVE-2026-72776). Successful exploitation can lead to full system takeover. Exploitable via `POST /query`.
|
| CVE-2026-72842 |
|
Vulnerability in path-traversal (CVE-2026-72842)
vulnerability in path-traversal (CVE-2026-72842). Successful exploitation can lead to full system takeover. Exploitable via ``lxc_name``.
|
| CVE-2026-72841 |
|
Vulnerability in path-traversal (CVE-2026-72841)
vulnerability in path-traversal (CVE-2026-72841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56858 |
|
Cross-Site Scripting (XSS) in CVE-2026-56858 (CVE-2026-56858)
cross-site scripting in CVE-2026-56858 (CVE-2026-56858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18741 |
|
Cross-Site Scripting (XSS) in CVE-2026-18741 (CVE-2026-18741)
cross-site scripting in CVE-2026-18741 (CVE-2026-18741). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18509 |
|
Vulnerability in privilege-escalation (CVE-2026-18509)
vulnerability in privilege-escalation (CVE-2026-18509). Confidential information can be exposed externally.
|
| CVE-2026-8715 |
|
Vulnerability in privilege-escalation (CVE-2026-8715)
vulnerability in privilege-escalation (CVE-2026-8715). Confidential information can be exposed externally.
|
| CVE-2026-18086 |
|
Out-of-Bounds Write in dos (CVE-2026-18086)
out-of-bounds write in dos (CVE-2026-18086). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18671 |
|
Vulnerability in dos (CVE-2026-18671)
vulnerability in dos (CVE-2026-18671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17476 |
|
Out-of-Bounds Write in dos (CVE-2026-17476)
out-of-bounds write in dos (CVE-2026-17476). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18077 |
|
Out-of-Bounds Write in dos (CVE-2026-18077)
out-of-bounds write in dos (CVE-2026-18077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18020 |
|
Out-of-Bounds Read in dos (CVE-2026-18020)
vulnerability in dos (CVE-2026-18020). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17502 |
|
Out-of-Bounds Write in dos (CVE-2026-17502)
out-of-bounds write in dos (CVE-2026-17502). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17216 |
|
Vulnerability in dos (CVE-2026-17216)
vulnerability in dos (CVE-2026-17216). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17226 |
|
Out-of-Bounds Read in dos (CVE-2026-17226)
vulnerability in dos (CVE-2026-17226). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17272 |
|
Out-of-Bounds Write in dos (CVE-2026-17272)
out-of-bounds write in dos (CVE-2026-17272). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17078 |
|
Vulnerability in dos (CVE-2026-17078)
vulnerability in dos (CVE-2026-17078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17076 |
|
Vulnerability in dos (CVE-2026-17076)
vulnerability in dos (CVE-2026-17076). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17212 |
|
Out-of-Bounds Read in dos (CVE-2026-17212)
vulnerability in dos (CVE-2026-17212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17077 |
|
Vulnerability in dos (CVE-2026-17077)
vulnerability in dos (CVE-2026-17077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17071 |
|
Path Traversal in path-traversal (CVE-2026-17071)
path traversal in path-traversal (CVE-2026-17071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17088 |
|
Path Traversal in path-traversal (CVE-2026-17088)
path traversal in path-traversal (CVE-2026-17088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73654 |
|
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
|
| CVE-2026-73531 |
|
Cross-Site Scripting (XSS) in django (CVE-2026-73531)
cross-site scripting in django (CVE-2026-73531). Risk of unauthorized operations or information disclosure.
|