Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16961 |
|
SQL Injection in sqli (CVE-2026-16961)
SQL injection in sqli (CVE-2026-16961). Confidential information can be exposed externally.
|
| CVE-2026-16887 |
|
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
|
| CVE-2026-16908 |
|
Path Traversal in path-traversal (CVE-2026-16908)
path traversal in path-traversal (CVE-2026-16908). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16815 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and...
|
| CVE-2026-16868 |
|
Vulnerability in dos (CVE-2026-16868)
vulnerability in dos (CVE-2026-16868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16722 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized...
|
| CVE-2026-16674 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
|
| CVE-2026-73482 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73482)
vulnerability in csrf (CVE-2026-73482). Data can be tampered with by attackers.
|
| CVE-2026-72777 |
|
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
|
| CVE-2026-17220 |
|
Vulnerability in dos (CVE-2026-17220)
vulnerability in dos (CVE-2026-17220). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58374 |
|
SQL Injection in sqli (CVE-2024-58374)
SQL injection in sqli (CVE-2024-58374). Confidential information can be exposed externally.
|
| CVE-2019-25765 |
|
SQL Injection in sqli (CVE-2019-25765)
SQL injection in sqli (CVE-2019-25765). Confidential information can be exposed externally.
|
| CVE-2026-59109 |
|
Vulnerability in sqli (CVE-2026-59109)
vulnerability in sqli (CVE-2026-59109). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7639 |
|
Unsafe Deserialization in cisa (CVE-2025-7639)
vulnerability in cisa (CVE-2025-7639). Data can be tampered with by attackers.
|
| CVE-2026-73670 |
|
SQL Injection in sqli (CVE-2026-73670)
SQL injection in sqli (CVE-2026-73670). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73570 KEV |
|
[KEV] OS Command Injection in Synacor zimbra-collaboration-suite (CVE-2026-73570)
OS command injection in Synacor zimbra-collaboration-suite (CVE-2026-73570). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-73515 |
|
Out-of-Bounds Read in dos (CVE-2026-73515)
vulnerability in dos (CVE-2026-73515). Confidential information can be exposed externally.
|
| CVE-2026-19710 |
|
Vulnerability in sqli (CVE-2026-19710)
vulnerability in sqli (CVE-2026-19710). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66256 |
|
Unsafe Deserialization in apache (CVE-2026-66256)
vulnerability in apache (CVE-2026-66256). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6387 |
|
Vulnerability in CVE-2026-6387 (CVE-2026-6387)
vulnerability in CVE-2026-6387 (CVE-2026-6387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14456 |
|
Vulnerability in dos (CVE-2026-14456)
vulnerability in dos (CVE-2026-14456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28154 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-28154)
cross-site scripting in wordpress (CVE-2026-28154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70464 |
|
Vulnerability in dos (CVE-2026-70464)
vulnerability in dos (CVE-2026-70464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70455 |
|
Vulnerability in dos (CVE-2026-70455)
vulnerability in dos (CVE-2026-70455). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70460 |
|
Path Traversal in path-traversal (CVE-2026-70460)
path traversal in path-traversal (CVE-2026-70460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70453 |
|
Vulnerability in dos (CVE-2026-70453)
vulnerability in dos (CVE-2026-70453). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53803 |
|
Vulnerability in privilege-escalation (CVE-2026-53803)
vulnerability in privilege-escalation (CVE-2026-53803). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53785 |
|
Vulnerability in path-traversal (CVE-2026-53785)
vulnerability in path-traversal (CVE-2026-53785). Data can be tampered with by attackers.
|
| CVE-2026-53784 |
|
Vulnerability in path-traversal (CVE-2026-53784)
vulnerability in path-traversal (CVE-2026-53784). Confidential information can be exposed externally.
|
| CVE-2026-73346 |
|
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
|
| CVE-2026-67991 |
|
Vulnerability in dos (CVE-2026-67991)
vulnerability in dos (CVE-2026-67991). Confidential information can be exposed externally.
|
| CVE-2026-66704 |
|
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
|
| CVE-2026-66697 |
|
Cross-Site Scripting (XSS) in CVE-2026-66697 (CVE-2026-66697)
cross-site scripting in CVE-2026-66697 (CVE-2026-66697). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66698 |
|
Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
|
| CVE-2026-66700 |
|
Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
|
| CVE-2026-66661 |
|
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
|
| CVE-2026-66655 |
|
Cross-Site Scripting (XSS) in CVE-2026-66655 (CVE-2026-66655)
cross-site scripting in CVE-2026-66655 (CVE-2026-66655). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66658 |
|
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
|
| CVE-2026-66468 |
|
Cross-Site Scripting (XSS) in CVE-2026-66468 (CVE-2026-66468)
cross-site scripting in CVE-2026-66468 (CVE-2026-66468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66449 |
|
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.18 versions.
|
| CVE-2026-66426 |
|
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
|
| CVE-2026-66430 |
|
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
|
| CVE-2026-65580 |
|
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions.
|
| CVE-2026-66429 |
|
Cross-Site Scripting (XSS) in CVE-2026-66429 (CVE-2026-66429)
cross-site scripting in CVE-2026-66429 (CVE-2026-66429). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61974 |
|
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions.
|
| CVE-2026-61979 |
|
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
|
| CVE-2026-61960 |
|
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions.
|
| CVE-2026-61965 |
|
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
Unauthenticated Cross Site Scripting (XSS) in GeekyBot <= 1.2.6 versions.
|
| CVE-2026-28187 |
|
Cross-Site Scripting (XSS) in CVE-2026-28187 (CVE-2026-28187)
cross-site scripting in CVE-2026-28187 (CVE-2026-28187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28184 |
|
Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.
Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.
|