Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-36789 Vulnerability in dos (CVE-2026-36789)
vulnerability in dos (CVE-2026-36789). Risk of unauthorized operations or information disclosure.
CVE-2026-11577 Authorization Flaw in privilege-escalation (CVE-2026-11577)
vulnerability in privilege-escalation (CVE-2026-11577). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/realms/{realm}/partialImport`.
CVE-2026-11501 A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System...
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System...
CVE-2026-11503 A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is...
A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is...
CVE-2026-41723 Cross-Site Scripting (XSS) in vmware (CVE-2026-41723)
cross-site scripting in vmware (CVE-2026-41723). Successful exploitation can lead to full system takeover.
CVE-2026-41724 Cross-Site Scripting (XSS) in vmware (CVE-2026-41724)
cross-site scripting in vmware (CVE-2026-41724). Successful exploitation can lead to full system takeover.
CVE-2026-41722 Cross-Site Scripting (XSS) in vmware (CVE-2026-41722)
cross-site scripting in vmware (CVE-2026-41722). Successful exploitation can lead to full system takeover.
CVE-2026-11490 Vulnerability in sqli (CVE-2026-11490)
vulnerability in sqli (CVE-2026-11490). Risk of unauthorized operations or information disclosure.
CVE-2026-11488 A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This...
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This...
CVE-2026-11489 A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects...
A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects...
CVE-2026-11485 A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1...
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1...
CVE-2026-11486 A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by...
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by...
CVE-2026-11484 A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This...
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This...
CVE-2026-11483 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This...
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This...
CVE-2026-11482 Vulnerability in sqli (CVE-2026-11482)
vulnerability in sqli (CVE-2026-11482). Risk of unauthorized operations or information disclosure.
CVE-2023-54351 Cross-Site Scripting (XSS) in wordpress (CVE-2023-54351)
cross-site scripting in wordpress (CVE-2023-54351). Risk of unauthorized operations or information disclosure.
CVE-2023-54350 Vulnerability in c (CVE-2023-54350)
vulnerability in c (CVE-2023-54350). Confidential information can be exposed externally.
CVE-2026-11472 Vulnerability in sqli (CVE-2026-11472)
vulnerability in sqli (CVE-2026-11472). Risk of unauthorized operations or information disclosure.
CVE-2026-11471 Vulnerability in sqli (CVE-2026-11471)
vulnerability in sqli (CVE-2026-11471). Risk of unauthorized operations or information disclosure.
CVE-2026-11463 A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
CVE-2026-11462 A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This...
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This...
CVE-2026-11456 Vulnerability in sqli (CVE-2026-11456)
vulnerability in sqli (CVE-2026-11456). Risk of unauthorized operations or information disclosure.
CVE-2026-26422 Vulnerability in privilege-escalation (CVE-2026-26422)
vulnerability in privilege-escalation (CVE-2026-26422). Successful exploitation can lead to full system takeover.
CVE-2026-11435 Vulnerability in sqli (CVE-2026-11435)
vulnerability in sqli (CVE-2026-11435). Risk of unauthorized operations or information disclosure.
CVE-2026-9851 Vulnerability in wordpress (CVE-2026-9851)
vulnerability in wordpress (CVE-2026-9851). Successful exploitation can lead to full system takeover.
CVE-2025-2414 Vulnerability in CVE-2025-2414 (CVE-2025-2414)
vulnerability in CVE-2025-2414 (CVE-2025-2414). Confidential information can be exposed externally.
CVE-2025-2415 Vulnerability in CVE-2025-2415 (CVE-2025-2415)
vulnerability in CVE-2025-2415 (CVE-2025-2415). Confidential information can be exposed externally.
CVE-2026-7537 Unrestricted File Upload in wordpress (CVE-2026-7537)
vulnerability in wordpress (CVE-2026-7537). Successful exploitation can lead to full system takeover.
CVE-2026-8901 Cross-Site Scripting (XSS) in wordpress (CVE-2026-8901)
cross-site scripting in wordpress (CVE-2026-8901). Risk of unauthorized operations or information disclosure.
CVE-2026-8438 Cross-Site Scripting (XSS) in wordpress (CVE-2026-8438)
cross-site scripting in wordpress (CVE-2026-8438). Risk of unauthorized operations or information disclosure.
CVE-2026-7654 Unsafe Deserialization in wordpress (CVE-2026-7654)
vulnerability in wordpress (CVE-2026-7654). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``.
CVE-2026-11416 Path Traversal in path-traversal (CVE-2026-11416)
path traversal in path-traversal (CVE-2026-11416). Data can be tampered with by attackers.
CVE-2026-36785 Vulnerability in dos (CVE-2026-36785)
vulnerability in dos (CVE-2026-36785). Risk of unauthorized operations or information disclosure.
CVE-2026-47743 Cross-Site Scripting (XSS) in shopper/framework (CVE-2026-47743)
cross-site scripting in shopper/framework (CVE-2026-47743). Confidential information can be exposed externally. Exploitable via ``Hidden``. Mitigation: upgrade to `2.8.0` or later.
CVE-2026-11400 AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-11419 Path Traversal in path-traversal (CVE-2026-11419)
path traversal in path-traversal (CVE-2026-11419). Successful exploitation can lead to full system takeover.
CVE-2026-11401 AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-5415 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-5411 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-46392 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filen...
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...
CVE-2026-36501 Vulnerability in dos (CVE-2026-36501)
vulnerability in dos (CVE-2026-36501). Risk of unauthorized operations or information disclosure.
CVE-2026-11342 Vulnerability in sqli (CVE-2026-11342)
vulnerability in sqli (CVE-2026-11342). Risk of unauthorized operations or information disclosure.
CVE-2026-52880 Vulnerability in github.com/klever-io/klever-go (CVE-2026-52880)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52880). Risk of unauthorized operations or information disclosure. Exploitable via ``Engine.Run``. Mitigation: upgrade to `1.7.18` or later.
CVE-2026-52879 Vulnerability in github.com/klever-io/klever-go (CVE-2026-52879)
vulnerability in github.com/klever-io/klever-go (CVE-2026-52879). Risk of unauthorized operations or information disclosure. Exploitable via ``networkMessenger.directMessageHandler``. Mitigation: upgrade to `1.7.18` or later.
CVE-2026-47684 SSRF (Server-Side Request Forgery) in @sync-in/server (CVE-2026-47684)
SSRF in @sync-in/server (CVE-2026-47684). Confidential information can be exposed externally. Mitigation: upgrade to `2.3.0` or later.
CVE-2026-11334 Vulnerability in sqli (CVE-2026-11334)
vulnerability in sqli (CVE-2026-11334). Risk of unauthorized operations or information disclosure.
CVE-2026-48095 Vulnerability in dos (CVE-2026-48095)
vulnerability in dos (CVE-2026-48095). Successful exploitation can lead to full system takeover.
CVE-2026-50234 Path Traversal in c (CVE-2026-50234)
path traversal in c (CVE-2026-50234). Confidential information can be exposed externally.
CVE-2026-50231 Cross-Site Scripting (XSS) in CVE-2026-50231 (CVE-2026-50231)
cross-site scripting in CVE-2026-50231 (CVE-2026-50231). Risk of unauthorized operations or information disclosure. Exploitable via `User-Agent header`.
CVE-2026-50232 Cross-Site Scripting (XSS) in CVE-2026-50232 (CVE-2026-50232)
cross-site scripting in CVE-2026-50232 (CVE-2026-50232). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →