Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-70638 |
|
Vulnerability in cpp (CVE-2026-70638)
vulnerability in cpp (CVE-2026-70638). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70639 |
|
Vulnerability in cpp (CVE-2026-70639)
vulnerability in cpp (CVE-2026-70639). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70633 |
|
Out-of-Bounds Read in dos (CVE-2026-70633)
vulnerability in dos (CVE-2026-70633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67689 |
|
SQL Injection in sqli (CVE-2026-67689)
SQL injection in sqli (CVE-2026-67689). Successful exploitation can lead to full system takeover. Exploitable via ``field``.
|
| CVE-2026-67422 |
|
Vulnerability in pymdown-extensions (CVE-2026-67422)
vulnerability in pymdown-extensions (CVE-2026-67422). Risk of unauthorized operations or information disclosure. Exploitable via ``caret``. Mitigation: upgrade to `10.16.1` or later.
|
| CVE-2026-64677 |
|
Path Traversal in path-traversal (CVE-2026-64677)
path traversal in path-traversal (CVE-2026-64677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5857 |
|
Out-of-Bounds Write in c (CVE-2026-5857)
out-of-bounds write in c (CVE-2026-5857). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53983 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-53983)
SSRF in c (CVE-2026-53983). Confidential information can be exposed externally.
|
| CVE-2026-48085 |
|
Vulnerability in csrf (CVE-2026-48085)
vulnerability in csrf (CVE-2026-48085). Successful exploitation can lead to full system takeover. Exploitable via ``default``.
|
| CVE-2026-48088 |
|
Vulnerability in CVE-2026-48088 (CVE-2026-48088)
vulnerability in CVE-2026-48088 (CVE-2026-48088). Confidential information can be exposed externally. Exploitable via `POST /api/tenants/{tenantId}/staff/{staffId}/crypto`.
|
| CVE-2026-48086 |
|
Privilege Escalation in privilege-escalation (CVE-2026-48086)
vulnerability in privilege-escalation (CVE-2026-48086). Successful exploitation can lead to full system takeover. Exploitable via ``GLOBAL_ADMIN``.
|
| CVE-2026-48083 |
|
Vulnerability in dos (CVE-2026-48083)
vulnerability in dos (CVE-2026-48083). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48080 |
|
Information Disclosure in ssrf (CVE-2026-48080)
vulnerability in ssrf (CVE-2026-48080). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/tenants/{id}`.
|
| CVE-2026-48071 |
|
Vulnerability in dos (CVE-2026-48071)
vulnerability in dos (CVE-2026-48071). Risk of unauthorized operations or information disclosure. Exploitable via ``emailHash``.
|
| CVE-2026-43631 |
|
Vulnerability in cpp (CVE-2026-43631)
vulnerability in cpp (CVE-2026-43631). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43628 |
|
Out-of-Bounds Read in cpp (CVE-2026-43628)
vulnerability in cpp (CVE-2026-43628). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41861 |
|
Path Traversal in path-traversal (CVE-2026-41861)
path traversal in path-traversal (CVE-2026-41861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3418 |
|
Unrestricted File Upload in CVE-2026-3418 (CVE-2026-3418)
vulnerability in CVE-2026-3418 (CVE-2026-3418). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19169 |
|
Vulnerability in privilege-escalation (CVE-2026-19169)
vulnerability in privilege-escalation (CVE-2026-19169). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19139 |
|
Vulnerability in privilege-escalation (CVE-2026-19139)
vulnerability in privilege-escalation (CVE-2026-19139). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19110 |
|
Cross-Site Scripting (XSS) in CVE-2026-19110 (CVE-2026-19110)
cross-site scripting in CVE-2026-19110 (CVE-2026-19110). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19071 |
|
Vulnerability in sqli (CVE-2026-19071)
vulnerability in sqli (CVE-2026-19071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19070 |
|
Vulnerability in sqli (CVE-2026-19070)
vulnerability in sqli (CVE-2026-19070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19069 |
|
Vulnerability in sqli (CVE-2026-19069)
vulnerability in sqli (CVE-2026-19069). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19068 |
|
Vulnerability in sqli (CVE-2026-19068)
vulnerability in sqli (CVE-2026-19068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19067 |
|
Vulnerability in sqli (CVE-2026-19067)
vulnerability in sqli (CVE-2026-19067). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19062 |
|
Vulnerability in sqli (CVE-2026-19062)
vulnerability in sqli (CVE-2026-19062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19059 |
|
Path Traversal in path-traversal (CVE-2026-19059)
path traversal in path-traversal (CVE-2026-19059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19054 |
|
Path Traversal in path-traversal (CVE-2026-19054)
path traversal in path-traversal (CVE-2026-19054). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18367 |
|
Vulnerability in privilege-escalation (CVE-2026-18367)
vulnerability in privilege-escalation (CVE-2026-18367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15733 |
|
OS Command Injection in CVE-2026-15733 (CVE-2026-15733)
OS command injection in CVE-2026-15733 (CVE-2026-15733). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14812 |
|
Vulnerability in wordpress (CVE-2026-14812)
vulnerability in wordpress (CVE-2026-14812). Successful exploitation can lead to full system takeover.
|
| CVE-2024-39024 |
|
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
|
| CVE-2026-71497 |
|
Cross-Site Scripting (XSS) in org.jsoup:jsoup (CVE-2026-71497)
cross-site scripting in org.jsoup:jsoup (CVE-2026-71497). Risk of unauthorized operations or information disclosure. Exploitable via ``Safelist``. Mitigation: upgrade to `1.23.1` or later.
|
| CVE-2026-54717 |
|
Cross-Site Scripting (XSS) in silverstripe/cms (CVE-2026-54717)
cross-site scripting in silverstripe/cms (CVE-2026-54717). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.1` or later.
|
| CVE-2026-71476 |
|
Path Traversal in nx (CVE-2026-71476)
path traversal in nx (CVE-2026-71476). Risk of unauthorized operations or information disclosure. Exploitable via ``NX_SELF_HOSTED_REMOTE_CACHE_SERVER``. Mitigation: upgrade to `23.0.2` or later.
|
| CVE-2026-71436 |
|
Vulnerability in mermaid (CVE-2026-71436)
vulnerability in mermaid (CVE-2026-71436). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.16.1` or later.
|
| CVE-2026-66829 |
|
Open Redirect in rrrene (CVE-2026-66829)
vulnerability in rrrene (CVE-2026-66829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66843 |
|
Vulnerability in rrrene (CVE-2026-66843)
vulnerability in rrrene (CVE-2026-66843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53977 |
|
Vulnerability in express (CVE-2026-53977)
vulnerability in express (CVE-2026-53977). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43622 |
|
Vulnerability in c (CVE-2026-43622)
vulnerability in c (CVE-2026-43622). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3430 |
|
SQL Injection in wordpress (CVE-2026-3430)
SQL injection in wordpress (CVE-2026-3430). Confidential information can be exposed externally.
|
| CVE-2026-19046 |
|
Path Traversal in path-traversal (CVE-2026-19046)
path traversal in path-traversal (CVE-2026-19046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70637 |
|
Vulnerability in c (CVE-2026-70637)
vulnerability in c (CVE-2026-70637). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66711 |
|
Cross-Site Scripting (XSS) in CVE-2026-66711 (CVE-2026-66711)
cross-site scripting in CVE-2026-66711 (CVE-2026-66711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66702 |
|
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
|
| CVE-2026-66703 |
|
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
|
| CVE-2026-66705 |
|
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
|
| CVE-2026-66706 |
|
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
|
| CVE-2026-66707 |
|
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
|