Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-52610 |
|
Path Traversal in path-traversal (CVE-2026-52610)
path traversal in path-traversal (CVE-2026-52610). Confidential information can be exposed externally.
|
| CVE-2026-66780 |
|
Vulnerability in CVE-2026-66780 (CVE-2026-66780)
vulnerability in CVE-2026-66780 (CVE-2026-66780). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52608 |
|
Vulnerability in CVE-2026-52608 (CVE-2026-52608)
vulnerability in CVE-2026-52608 (CVE-2026-52608). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43716 |
|
Vulnerability in CVE-2021-43716 (CVE-2021-43716)
vulnerability in CVE-2021-43716 (CVE-2021-43716). Successful exploitation can lead to full system takeover.
|
| CVE-2021-43717 |
|
Vulnerability in CVE-2021-43717 (CVE-2021-43717)
vulnerability in CVE-2021-43717 (CVE-2021-43717). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67271 |
|
Out-of-Bounds Write in dos (CVE-2026-67271)
out-of-bounds write in dos (CVE-2026-67271). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52723 |
|
Vulnerability in CVE-2026-52723 (CVE-2026-52723)
vulnerability in CVE-2026-52723 (CVE-2026-52723). Confidential information can be exposed externally.
|
| CVE-2026-75913 |
|
Vulnerability in CVE-2026-75913 (CVE-2026-75913)
vulnerability in CVE-2026-75913 (CVE-2026-75913). Data can be tampered with by attackers. Mitigation: upgrade to `0.8.64` or later.
|
| CVE-2026-45117 |
|
Code Injection in CVE-2026-45117 (CVE-2026-45117)
code injection in CVE-2026-45117 (CVE-2026-45117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12564 |
|
SSRF (Server-Side Request Forgery) in django (CVE-2026-12564)
SSRF in django (CVE-2026-12564). Confidential information can be exposed externally.
|
| CVE-2026-73397 |
|
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
|
| CVE-2026-73381 |
|
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
|
| CVE-2026-73996 |
|
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
|
| CVE-2026-75784 |
|
Buffer Overflow in nginx (CVE-2026-75784)
vulnerability in nginx (CVE-2026-75784). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74015 |
|
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
|
| CVE-2026-73392 |
|
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
|
| CVE-2026-73376 |
|
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
|
| CVE-2026-73380 |
|
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
|
| CVE-2026-73366 |
|
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
|
| CVE-2026-73341 |
|
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
|
| CVE-2026-73365 |
|
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
|
| CVE-2026-73355 |
|
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
|
| CVE-2026-73339 |
|
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
|
| CVE-2026-73187 |
|
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
|
| CVE-2026-73343 |
|
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
|
| CVE-2026-66627 |
|
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
|
| CVE-2026-32470 |
|
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
|
| CVE-2026-32474 |
|
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
|
| CVE-2026-32463 |
|
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
|
| CVE-2026-28192 |
|
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
|
| CVE-2026-75783 |
|
Buffer Overflow in CVE-2026-75783 (CVE-2026-75783)
vulnerability in CVE-2026-75783 (CVE-2026-75783). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75874 |
|
Vulnerability in mozilla (CVE-2026-75874)
vulnerability in mozilla (CVE-2026-75874). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32444 |
|
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
|
| CVE-2026-74986 |
|
Information Disclosure in mozilla (CVE-2026-74986)
vulnerability in mozilla (CVE-2026-74986). Confidential information can be exposed externally.
|
| CVE-2026-74990 |
|
Buffer Overflow in mozilla (CVE-2026-74990)
vulnerability in mozilla (CVE-2026-74990). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74987 |
|
Buffer Overflow in mozilla (CVE-2026-74987)
vulnerability in mozilla (CVE-2026-74987). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74989 |
|
Buffer Overflow in mozilla (CVE-2026-74989)
vulnerability in mozilla (CVE-2026-74989). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74985 |
|
Privilege Escalation in privilege-escalation (CVE-2026-74985)
vulnerability in privilege-escalation (CVE-2026-74985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74988 |
|
Buffer Overflow in mozilla (CVE-2026-74988)
vulnerability in mozilla (CVE-2026-74988). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74979 |
|
Vulnerability in mozilla (CVE-2026-74979)
vulnerability in mozilla (CVE-2026-74979). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74964 |
|
Vulnerability in mozilla (CVE-2026-74964)
vulnerability in mozilla (CVE-2026-74964). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74956 |
|
Vulnerability in mozilla (CVE-2026-74956)
vulnerability in mozilla (CVE-2026-74956). Confidential information can be exposed externally.
|
| CVE-2026-74961 |
|
Vulnerability in mozilla (CVE-2026-74961)
vulnerability in mozilla (CVE-2026-74961). Confidential information can be exposed externally.
|
| CVE-2026-74959 |
|
Vulnerability in mozilla (CVE-2026-74959)
vulnerability in mozilla (CVE-2026-74959). Confidential information can be exposed externally.
|
| CVE-2026-74943 |
|
Use-After-Free in mozilla (CVE-2026-74943)
vulnerability in mozilla (CVE-2026-74943). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74940 |
|
Use-After-Free in mozilla (CVE-2026-74940)
vulnerability in mozilla (CVE-2026-74940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74944 |
|
Use-After-Free in mozilla (CVE-2026-74944)
vulnerability in mozilla (CVE-2026-74944). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74938 |
|
Vulnerability in mozilla (CVE-2026-74938)
vulnerability in mozilla (CVE-2026-74938). Confidential information can be exposed externally.
|
| CVE-2026-74936 |
|
Use-After-Free in mozilla (CVE-2026-74936)
vulnerability in mozilla (CVE-2026-74936). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75852 |
|
Vulnerability in c (CVE-2026-75852)
vulnerability in c (CVE-2026-75852). Successful exploitation can lead to full system takeover.
|