Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-71279 Path Traversal in CVE-2026-71279 (CVE-2026-71279)
path traversal in CVE-2026-71279 (CVE-2026-71279). Successful exploitation can lead to full system takeover. Exploitable via ``name``.
CVE-2026-71281 Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
CVE-2026-71276 SQL Injection in sqli (CVE-2026-71276)
SQL injection in sqli (CVE-2026-71276). Confidential information can be exposed externally. Exploitable via ``format``.
CVE-2026-71280 go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
CVE-2026-71268 Path Traversal in CVE-2026-71268 (CVE-2026-71268)
path traversal in CVE-2026-71268 (CVE-2026-71268). Successful exploitation can lead to full system takeover.
CVE-2026-71269 Path Traversal in CVE-2026-71269 (CVE-2026-71269)
path traversal in CVE-2026-71269 (CVE-2026-71269). Successful exploitation can lead to full system takeover. Exploitable via `POST /library/`.
CVE-2026-71271 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
CVE-2026-71273 Cross-Site Request Forgery (CSRF) in c (CVE-2026-71273)
vulnerability in c (CVE-2026-71273). Data can be tampered with by attackers. Exploitable via ``web_admin_password_enabled``.
CVE-2026-71272 Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
CVE-2026-71262 Vulnerability in path-traversal (CVE-2026-71262)
vulnerability in path-traversal (CVE-2026-71262). Successful exploitation can lead to full system takeover.
CVE-2026-71259 ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
CVE-2026-71227 Vulnerability in dos (CVE-2026-71227)
vulnerability in dos (CVE-2026-71227). Risk of unauthorized operations or information disclosure.
CVE-2026-71254 Out-of-Bounds Write in c (CVE-2026-71254)
out-of-bounds write in c (CVE-2026-71254). Successful exploitation can lead to full system takeover.
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
CVE-2026-71239 Vulnerability in django (CVE-2026-71239)
vulnerability in django (CVE-2026-71239). Confidential information can be exposed externally.
CVE-2026-71238 Vulnerability in django (CVE-2026-71238)
vulnerability in django (CVE-2026-71238). Confidential information can be exposed externally.
CVE-2026-71248 SQL Injection in sqli (CVE-2026-71248)
SQL injection in sqli (CVE-2026-71248). Successful exploitation can lead to full system takeover.
CVE-2026-71250 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71250)
SSRF in ssrf (CVE-2026-71250). Risk of unauthorized operations or information disclosure.
CVE-2026-71246 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71246)
SSRF in ssrf (CVE-2026-71246). Risk of unauthorized operations or information disclosure.
CVE-2026-71249 Cross-Site Scripting (XSS) in CVE-2026-71249 (CVE-2026-71249)
cross-site scripting in CVE-2026-71249 (CVE-2026-71249). Risk of unauthorized operations or information disclosure.
CVE-2026-71237 SQL Injection in sqli (CVE-2026-71237)
SQL injection in sqli (CVE-2026-71237). Successful exploitation can lead to full system takeover. Exploitable via `POST /userlogin`.
CVE-2026-71235 Code Injection in ssrf (CVE-2026-71235)
code injection in ssrf (CVE-2026-71235). Successful exploitation can lead to full system takeover.
CVE-2026-71236 Cross-Site Scripting (XSS) in CVE-2026-71236 (CVE-2026-71236)
cross-site scripting in CVE-2026-71236 (CVE-2026-71236). Confidential information can be exposed externally.
CVE-2026-71233 Cross-Site Scripting (XSS) in laravel (CVE-2026-71233)
cross-site scripting in laravel (CVE-2026-71233). Confidential information can be exposed externally. Exploitable via `PUT /api/v1/invoices/{id}`.
CVE-2026-60009 Path Traversal in eclipse (CVE-2026-60009)
path traversal in eclipse (CVE-2026-60009). Successful exploitation can lead to full system takeover. Exploitable via `POST /file-upload`.
CVE-2026-71232 Code Injection in CVE-2026-71232 (CVE-2026-71232)
code injection in CVE-2026-71232 (CVE-2026-71232). Successful exploitation can lead to full system takeover.
CVE-2026-66747 Vulnerability in CVE-2026-66747 (CVE-2026-66747)
vulnerability in CVE-2026-66747 (CVE-2026-66747). Successful exploitation can lead to full system takeover.
CVE-2026-71231 SQL Injection in sqli (CVE-2026-71231)
SQL injection in sqli (CVE-2026-71231). Successful exploitation can lead to full system takeover.
CVE-2026-15452 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15452)
cross-site scripting in wordpress (CVE-2026-15452). Risk of unauthorized operations or information disclosure.
CVE-2026-44945 Vulnerability in privilege-escalation (CVE-2026-44945)
vulnerability in privilege-escalation (CVE-2026-44945). Successful exploitation can lead to full system takeover.
CVE-2026-10090 Vulnerability in privilege-escalation (CVE-2026-10090)
vulnerability in privilege-escalation (CVE-2026-10090). Confidential information can be exposed externally.
CVE-2026-10059 Vulnerability in privilege-escalation (CVE-2026-10059)
vulnerability in privilege-escalation (CVE-2026-10059). Successful exploitation can lead to full system takeover.
CVE-2026-8029 SQL Injection in sqli (CVE-2026-8029)
SQL injection in sqli (CVE-2026-8029). Confidential information can be exposed externally.
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-7441 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7441)
cross-site scripting in wordpress (CVE-2026-7441). Risk of unauthorized operations or information disclosure. Exploitable via ``posttype``.
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-71215 art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
CVE-2026-71211 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71211)
SSRF in ssrf (CVE-2026-71211). Confidential information can be exposed externally.
CVE-2026-71210 Vulnerability in ssrf (CVE-2026-71210)
vulnerability in ssrf (CVE-2026-71210). Confidential information can be exposed externally.
CVE-2026-71206 Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-70376 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
CVE-2026-6972 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6972)
cross-site scripting in wordpress (CVE-2026-6972). Risk of unauthorized operations or information disclosure. Exploitable via ``chart_size``.
CVE-2026-5581 Vulnerability in wordpress (CVE-2026-5581)
vulnerability in wordpress (CVE-2026-5581). Data can be tampered with by attackers. Exploitable via ``wp_ajax_nopriv_gfmu_delete_file``.
CVE-2026-5651 SQL Injection in wordpress (CVE-2026-5651)
SQL injection in wordpress (CVE-2026-5651). Confidential information can be exposed externally.
CVE-2026-61484 Unsafe Deserialization in apache (CVE-2026-61484)
vulnerability in apache (CVE-2026-61484). Successful exploitation can lead to full system takeover.
CVE-2026-55997 Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →