Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-76098 |
|
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens fr...
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee...
|
| CVE-2026-75369 |
|
Out-of-Bounds Read in dos (CVE-2026-75369)
vulnerability in dos (CVE-2026-75369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75368 |
|
Vulnerability in dos (CVE-2026-75368)
vulnerability in dos (CVE-2026-75368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61419 |
|
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
|
| CVE-2026-75371 |
|
Vulnerability in dos (CVE-2026-75371)
vulnerability in dos (CVE-2026-75371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71505 |
|
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
|
| CVE-2026-71506 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-30864 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
| CVE-2026-71942 |
|
Vulnerability in dos (CVE-2026-71942)
vulnerability in dos (CVE-2026-71942). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71939 |
|
Vulnerability in dos (CVE-2026-71939)
vulnerability in dos (CVE-2026-71939). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71938 |
|
Vulnerability in dos (CVE-2026-71938)
vulnerability in dos (CVE-2026-71938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71936 |
|
Vulnerability in dos (CVE-2026-71936)
vulnerability in dos (CVE-2026-71936). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71934 |
|
Vulnerability in dos (CVE-2026-71934)
vulnerability in dos (CVE-2026-71934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71935 |
|
Vulnerability in dos (CVE-2026-71935)
vulnerability in dos (CVE-2026-71935). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71940 |
|
Vulnerability in dos (CVE-2026-71940)
vulnerability in dos (CVE-2026-71940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71937 |
|
Vulnerability in dos (CVE-2026-71937)
vulnerability in dos (CVE-2026-71937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71941 |
|
Vulnerability in dos (CVE-2026-71941)
vulnerability in dos (CVE-2026-71941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71922 |
|
Vulnerability in dos (CVE-2026-71922)
vulnerability in dos (CVE-2026-71922). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71912 |
|
Vulnerability in dos (CVE-2026-71912)
vulnerability in dos (CVE-2026-71912). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71911 |
|
Vulnerability in dos (CVE-2026-71911)
vulnerability in dos (CVE-2026-71911). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78465 |
|
Vulnerability in dos (CVE-2026-78465)
vulnerability in dos (CVE-2026-78465). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66907 |
|
Vulnerability in org.apache.camel:camel-google-storage (CVE-2026-66907)
vulnerability in org.apache.camel:camel-google-storage (CVE-2026-66907). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2025-36940 |
|
Use-After-Free in privilege-escalation (CVE-2025-36940)
vulnerability in privilege-escalation (CVE-2025-36940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71366 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71366)
SSRF in ssrf (CVE-2026-71366). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-71364 |
|
Path Traversal in path-traversal (CVE-2026-71364)
path traversal in path-traversal (CVE-2026-71364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78414 |
|
Cross-Site Scripting (XSS) in CVE-2026-78414 (CVE-2026-78414)
cross-site scripting in CVE-2026-78414 (CVE-2026-78414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78248 |
|
Vulnerability in sqli (CVE-2026-78248)
vulnerability in sqli (CVE-2026-78248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78247 |
|
Vulnerability in sqli (CVE-2026-78247)
vulnerability in sqli (CVE-2026-78247). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76841 |
|
Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59567 |
|
Vulnerability in privilege-escalation (CVE-2026-59567)
vulnerability in privilege-escalation (CVE-2026-59567). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30512 |
|
Vulnerability in privilege-escalation (CVE-2026-30512)
vulnerability in privilege-escalation (CVE-2026-30512). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78270 |
|
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
|
| CVE-2026-66599 |
|
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
|
| CVE-2026-66623 |
|
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
|
| CVE-2026-66610 |
|
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
|
| CVE-2026-32476 |
|
Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
|
| CVE-2026-32471 |
|
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
|
| CVE-2026-28166 |
|
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
|
| CVE-2026-66584 |
|
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
|
| CVE-2026-28162 |
|
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
|
| CVE-2026-32478 |
|
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
|
| CVE-2026-78246 |
|
Vulnerability in sqli (CVE-2026-78246)
vulnerability in sqli (CVE-2026-78246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78244 |
|
Vulnerability in sqli (CVE-2026-78244)
vulnerability in sqli (CVE-2026-78244). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78317 |
|
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
|
| CVE-2026-78315 |
|
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
|
| CVE-2026-78314 |
|
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
|
| CVE-2026-78316 |
|
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
|
| CVE-2026-78198 |
|
Vulnerability in sqli (CVE-2026-78198)
vulnerability in sqli (CVE-2026-78198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78197 |
|
Vulnerability in sqli (CVE-2026-78197)
vulnerability in sqli (CVE-2026-78197). Risk of unauthorized operations or information disclosure.
|