Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48528 |
|
SQL Injection in tomcat (CVE-2026-48528)
SQL injection in tomcat (CVE-2026-48528). Successful exploitation can lead to full system takeover. Exploitable via ``nodeId``.
|
| CVE-2026-72811 |
|
SQL Injection in sqli (CVE-2026-72811)
SQL injection in sqli (CVE-2026-72811). Confidential information can be exposed externally. Mitigation: upgrade to `3.7.4` or later.
|
| CVE-2026-73843 |
|
Vulnerability in CVE-2026-73843 (CVE-2026-73843)
vulnerability in CVE-2026-73843 (CVE-2026-73843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73842 |
|
Privilege Escalation in CVE-2026-73842 (CVE-2026-73842)
vulnerability in CVE-2026-73842 (CVE-2026-73842). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72850 |
|
Path Traversal in CVE-2026-72850 (CVE-2026-72850)
path traversal in CVE-2026-72850 (CVE-2026-72850). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72851 |
|
SQL Injection in sqli (CVE-2026-72851)
SQL injection in sqli (CVE-2026-72851). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72842 |
|
Vulnerability in path-traversal (CVE-2026-72842)
vulnerability in path-traversal (CVE-2026-72842). Successful exploitation can lead to full system takeover. Exploitable via ``lxc_name``.
|
| CVE-2026-72841 |
|
Vulnerability in path-traversal (CVE-2026-72841)
vulnerability in path-traversal (CVE-2026-72841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72776 |
|
Vulnerability in CVE-2026-72776 (CVE-2026-72776)
vulnerability in CVE-2026-72776 (CVE-2026-72776). Successful exploitation can lead to full system takeover. Exploitable via `POST /query`.
|
| CVE-2026-8715 |
|
Vulnerability in privilege-escalation (CVE-2026-8715)
vulnerability in privilege-escalation (CVE-2026-8715). Confidential information can be exposed externally.
|
| CVE-2026-17482 |
|
Vulnerability in ibm (CVE-2026-17482)
vulnerability in ibm (CVE-2026-17482). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73656 |
|
Vulnerability in CVE-2026-73656 (CVE-2026-73656)
vulnerability in CVE-2026-73656 (CVE-2026-73656). Data can be tampered with by attackers. Exploitable via `POST /api/v1/deployments/`.
|
| CVE-2026-19747 |
|
Vulnerability in CVE-2026-19747 (CVE-2026-19747)
vulnerability in CVE-2026-19747 (CVE-2026-19747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14525 |
|
Vulnerability in ibm (CVE-2026-14525)
vulnerability in ibm (CVE-2026-14525). Confidential information can be exposed externally.
|
| CVE-2026-67614 |
|
Vulnerability in CVE-2026-67614 (CVE-2026-67614)
vulnerability in CVE-2026-67614 (CVE-2026-67614). Successful exploitation can lead to full system takeover.
|
| CVE-2022-4993 |
|
Vulnerability in CVE-2022-4993 (CVE-2022-4993)
vulnerability in CVE-2022-4993 (CVE-2022-4993). Confidential information can be exposed externally. Exploitable via ``_AUTO``.
|
| CVE-2026-13051 |
|
Vulnerability in CVE-2026-13051 (CVE-2026-13051)
vulnerability in CVE-2026-13051 (CVE-2026-13051). Confidential information can be exposed externally. Exploitable via ``_AUTO``.
|
| CVE-2026-58508 |
|
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
|
| CVE-2026-58433 |
|
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting
|
| CVE-2026-19188 |
|
OS Command Injection in cisa (CVE-2026-19188)
OS command injection in cisa (CVE-2026-19188). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73532 |
|
Vulnerability in CVE-2026-73532 (CVE-2026-73532)
vulnerability in CVE-2026-73532 (CVE-2026-73532). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73533 |
|
Vulnerability in CVE-2026-73533 (CVE-2026-73533)
vulnerability in CVE-2026-73533 (CVE-2026-73533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53791 |
|
Vulnerability in CVE-2026-53791 (CVE-2026-53791)
vulnerability in CVE-2026-53791 (CVE-2026-53791). Confidential information can be exposed externally.
|
| CVE-2026-66472 |
|
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
|
| CVE-2026-66478 |
|
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
|
| CVE-2026-66465 |
|
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
|
| CVE-2026-66453 |
|
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
|
| CVE-2026-66458 |
|
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
|
| CVE-2026-66436 |
|
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
|
| CVE-2026-66446 |
|
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
|
| CVE-2026-61969 |
|
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
|
| CVE-2026-61966 |
|
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
|
| CVE-2026-61962 |
|
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
|
| CVE-2026-28149 |
|
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
|
| CVE-2026-28001 |
|
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
|
| CVE-2026-28148 |
|
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
|
| CVE-2026-28142 |
|
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
|
| CVE-2026-28008 |
|
Vulnerability in CVE-2026-28008 (CVE-2026-28008)
vulnerability in CVE-2026-28008 (CVE-2026-28008). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27544 |
|
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
|
| CVE-2026-49827 |
|
Vulnerability in CVE-2026-49827 (CVE-2026-49827)
vulnerability in CVE-2026-49827 (CVE-2026-49827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59500 |
|
CWE-287: Improper Authentication
CWE-287: Improper Authentication
|
| CVE-2026-59503 |
|
Information Disclosure in CVE-2026-59503 (CVE-2026-59503)
vulnerability in CVE-2026-59503 (CVE-2026-59503). Confidential information can be exposed externally.
|
| CVE-2026-59506 |
|
CWE-306: Missing Authentication for Critical Function
CWE-306: Missing Authentication for Critical Function
|
| CVE-2026-59507 |
|
Vulnerability in CVE-2026-59507 (CVE-2026-59507)
vulnerability in CVE-2026-59507 (CVE-2026-59507). Confidential information can be exposed externally.
|
| CVE-2026-15413 |
|
Vulnerability in wordpress (CVE-2026-15413)
vulnerability in wordpress (CVE-2026-15413). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14182 |
|
Authentication Bypass in wordpress (CVE-2026-14182)
authentication bypass in wordpress (CVE-2026-14182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71193 |
|
Authorization Flaw in dos (CVE-2026-71193)
vulnerability in dos (CVE-2026-71193). Data can be tampered with by attackers.
|
| CVE-2026-16770 |
|
Vulnerability in CVE-2026-16770 (CVE-2026-16770)
vulnerability in CVE-2026-16770 (CVE-2026-16770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49819 |
|
OS Command Injection in c (CVE-2026-49819)
OS command injection in c (CVE-2026-49819). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/upsnap/init-superuser`.
|
| CVE-2026-49481 |
|
OS Command Injection in c (CVE-2026-49481)
OS command injection in c (CVE-2026-49481). Confidential information can be exposed externally.
|