Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-52838 |
|
Cross-Site Scripting (XSS) in alextselegidis/easyappointments (CVE-2026-52838)
cross-site scripting in alextselegidis/easyappointments (CVE-2026-52838). Risk of unauthorized operations or information disclosure. Exploitable via `POST /index.php/booking_settings/save`.
|
| CVE-2026-23573 |
|
Cross-Site Scripting (XSS) in fortinet (CVE-2026-23573)
cross-site scripting in fortinet (CVE-2026-23573). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11944 |
|
Path Traversal in path-traversal (CVE-2026-11944)
path traversal in path-traversal (CVE-2026-11944). Confidential information can be exposed externally.
|
| CVE-2026-11917 |
|
Path Traversal in path-traversal (CVE-2026-11917)
path traversal in path-traversal (CVE-2026-11917). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60114 |
|
Path Traversal in path-traversal (CVE-2026-60114)
path traversal in path-traversal (CVE-2026-60114). Data can be tampered with by attackers.
|
| CVE-2026-58478 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-58478)
SSRF in ssrf (CVE-2026-58478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58475 |
|
Cross-Site Scripting (XSS) in dan-in-ca (CVE-2026-58475)
cross-site scripting in dan-in-ca (CVE-2026-58475). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58476 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-58476)
vulnerability in csrf (CVE-2026-58476). Data can be tampered with by attackers.
|
| CVE-2026-51105 |
|
Vulnerability in dos (CVE-2026-51105)
vulnerability in dos (CVE-2026-51105). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15736 |
|
Vulnerability in sqli (CVE-2026-15736)
vulnerability in sqli (CVE-2026-15736). Confidential information can be exposed externally.
|
| CVE-2026-15265 |
|
Path Traversal in c (CVE-2026-15265)
path traversal in c (CVE-2026-15265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14903 |
|
Path Traversal in path-traversal (CVE-2026-14903)
path traversal in path-traversal (CVE-2026-14903). Confidential information can be exposed externally.
|
| CVE-2026-10669 |
|
Out-of-Bounds Write in c (CVE-2026-10669)
out-of-bounds write in c (CVE-2026-10669). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10670 |
|
Vulnerability in c (CVE-2026-10670)
vulnerability in c (CVE-2026-10670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10672 |
|
Out-of-Bounds Read in c (CVE-2026-10672)
vulnerability in c (CVE-2026-10672). Confidential information can be exposed externally.
|
| CVE-2026-62390 |
|
SQL Injection in apache (CVE-2026-62390)
SQL injection in apache (CVE-2026-62390). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49488 |
|
Path Traversal in apache (CVE-2026-49488)
path traversal in apache (CVE-2026-49488). Confidential information can be exposed externally.
|
| CVE-2026-12588 |
|
Vulnerability in dos (CVE-2026-12588)
vulnerability in dos (CVE-2026-12588). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62422 |
|
Vulnerability in jetbrains (CVE-2026-62422)
vulnerability in jetbrains (CVE-2026-62422). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58319 |
|
Vulnerability in apache (CVE-2026-58319)
vulnerability in apache (CVE-2026-58319). Data can be tampered with by attackers.
|
| CVE-2026-14852 |
|
OS Command Injection in privilege-escalation (CVE-2026-14852)
OS command injection in privilege-escalation (CVE-2026-14852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9561 |
|
Vulnerability in dos (CVE-2026-9561)
vulnerability in dos (CVE-2026-9561). Data can be tampered with by attackers.
|
| CVE-2026-57898 |
|
Path Traversal in CVE-2026-57898 (CVE-2026-57898)
path traversal in CVE-2026-57898 (CVE-2026-57898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15183 |
|
SQL Injection in privilege-escalation (CVE-2026-15183)
SQL injection in privilege-escalation (CVE-2026-15183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58229 |
|
Vulnerability in ssrf (CVE-2026-58229)
vulnerability in ssrf (CVE-2026-58229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59246 |
|
Vulnerability in ssrf (CVE-2026-59246)
vulnerability in ssrf (CVE-2026-59246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15416 |
|
Vulnerability in CVE-2026-15416 (CVE-2026-15416)
vulnerability in CVE-2026-15416 (CVE-2026-15416). Confidential information can be exposed externally.
|
| CVE-2026-15678 |
|
Cross-Site Scripting (XSS) in CVE-2026-15678 (CVE-2026-15678)
cross-site scripting in CVE-2026-15678 (CVE-2026-15678). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11563 |
|
Vulnerability in wordpress (CVE-2026-11563)
vulnerability in wordpress (CVE-2026-11563). Data can be tampered with by attackers.
|
| CVE-2026-15672 |
|
Vulnerability in sqli (CVE-2026-15672)
vulnerability in sqli (CVE-2026-15672). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15676 |
|
Vulnerability in sqli (CVE-2026-15676)
vulnerability in sqli (CVE-2026-15676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15675 |
|
Vulnerability in sqli (CVE-2026-15675)
vulnerability in sqli (CVE-2026-15675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12511 |
|
Vulnerability in wordpress (CVE-2026-12511)
vulnerability in wordpress (CVE-2026-12511). Confidential information can be exposed externally.
|
| CVE-2026-12482 |
|
Path Traversal in keras (CVE-2026-12482)
path traversal in keras (CVE-2026-12482). Risk of unauthorized operations or information disclosure. Exploitable via ``filter_safe_tarinfos``. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-12583 |
|
Unsafe Deserialization in wordpress (CVE-2026-12583)
vulnerability in wordpress (CVE-2026-12583). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15626 |
|
Path Traversal in path-traversal (CVE-2026-15626)
path traversal in path-traversal (CVE-2026-15626). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11390 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11390)
cross-site scripting in wordpress (CVE-2026-11390). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7640 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7640)
cross-site scripting in wordpress (CVE-2026-7640). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58233 |
|
Unsafe Deserialization in deserialization (CVE-2026-58233)
vulnerability in deserialization (CVE-2026-58233). Confidential information can be exposed externally.
|
| CVE-2026-44760 |
|
Cross-Site Scripting (XSS) in CVE-2026-44760 (CVE-2026-44760)
cross-site scripting in CVE-2026-44760 (CVE-2026-44760). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15409 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in Sonicwall ssrf (CVE-2026-15409)
SSRF in Sonicwall ssrf (CVE-2026-15409). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-58101 |
|
Vulnerability in dos (CVE-2026-58101)
vulnerability in dos (CVE-2026-58101). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58486 |
|
Vulnerability in dos (CVE-2026-58486)
vulnerability in dos (CVE-2026-58486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57856 |
|
Path Traversal in path-traversal (CVE-2026-57856)
path traversal in path-traversal (CVE-2026-57856). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62194 |
|
Vulnerability in privilege-escalation (CVE-2026-62194)
vulnerability in privilege-escalation (CVE-2026-62194). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62185 |
|
Vulnerability in CVE-2026-62185 (CVE-2026-62185)
vulnerability in CVE-2026-62185 (CVE-2026-62185). Confidential information can be exposed externally.
|
| CVE-2026-58411 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2026-58411)
cross-site scripting in privilege-escalation (CVE-2026-58411). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56877 |
|
Vulnerability in dos (CVE-2026-56877)
vulnerability in dos (CVE-2026-56877). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59801 |
|
Vulnerability in dos (CVE-2026-59801)
vulnerability in dos (CVE-2026-59801). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51539 |
|
Vulnerability in dos (CVE-2026-51539)
vulnerability in dos (CVE-2026-51539). Risk of unauthorized operations or information disclosure.
|