Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Tag: rce Clear
ID Title
CVE-2026-82472 Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
CVE-2026-82473 KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
CVE-2026-82461 pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
CVE-2026-82450 Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
CVE-2026-14494 Unrestricted File Upload in wordpress (CVE-2026-14494)
vulnerability in wordpress (CVE-2026-14494). Successful exploitation can lead to full system takeover.
CVE-2026-82278 Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
CVE-2026-77939 Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
CVE-2026-81757 Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
CVE-2026-82244 Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
CVE-2026-40013 Vulnerability in dos (CVE-2026-40013)
vulnerability in dos (CVE-2026-40013). Risk of unauthorized operations or information disclosure.
CVE-2026-14558 Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
CVE-2026-18983 Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
CVE-2026-16759 Vulnerability in wordpress (CVE-2026-16759)
vulnerability in wordpress (CVE-2026-16759). Risk of unauthorized operations or information disclosure.
CVE-2026-61800 Path Traversal in CVE-2026-61800 (CVE-2026-61800)
path traversal in CVE-2026-61800 (CVE-2026-61800). Successful exploitation can lead to full system takeover.
CVE-2026-38821 Vulnerability in c (CVE-2026-38821)
vulnerability in c (CVE-2026-38821). Confidential information can be exposed externally.
CVE-2026-61802 Information Disclosure in CVE-2026-61802 (CVE-2026-61802)
vulnerability in CVE-2026-61802 (CVE-2026-61802). Confidential information can be exposed externally. Exploitable via `GET /cluster/local/config.`.
CVE-2026-5706 Vulnerability in CVE-2026-5706 (CVE-2026-5706)
vulnerability in CVE-2026-5706 (CVE-2026-5706). Risk of unauthorized operations or information disclosure.
CVE-2026-76639 Path Traversal in path-traversal (CVE-2026-76639)
path traversal in path-traversal (CVE-2026-76639). Successful exploitation can lead to full system takeover.
CVE-2026-53579 Cross-Site Scripting (XSS) in CVE-2026-53579 (CVE-2026-53579)
cross-site scripting in CVE-2026-53579 (CVE-2026-53579). Risk of unauthorized operations or information disclosure.
CVE-2026-53578 Cross-Site Scripting (XSS) in CVE-2026-53578 (CVE-2026-53578)
cross-site scripting in CVE-2026-53578 (CVE-2026-53578). Risk of unauthorized operations or information disclosure.
CVE-2026-48996 Cross-Site Scripting (XSS) in CVE-2026-48996 (CVE-2026-48996)
cross-site scripting in CVE-2026-48996 (CVE-2026-48996). Risk of unauthorized operations or information disclosure.
CVE-2026-47727 Code Injection in CVE-2026-47727 (CVE-2026-47727)
code injection in CVE-2026-47727 (CVE-2026-47727). Risk of unauthorized operations or information disclosure.
CVE-2026-79988 Vulnerability in CVE-2026-79988 (CVE-2026-79988)
vulnerability in CVE-2026-79988 (CVE-2026-79988). Risk of unauthorized operations or information disclosure.
CVE-2026-79720 Cross-Site Scripting (XSS) in CVE-2026-79720 (CVE-2026-79720)
cross-site scripting in CVE-2026-79720 (CVE-2026-79720). Risk of unauthorized operations or information disclosure.
CVE-2026-79718 Cross-Site Scripting (XSS) in CVE-2026-79718 (CVE-2026-79718)
cross-site scripting in CVE-2026-79718 (CVE-2026-79718). Risk of unauthorized operations or information disclosure.
CVE-2026-79719 Cross-Site Scripting (XSS) in CVE-2026-79719 (CVE-2026-79719)
cross-site scripting in CVE-2026-79719 (CVE-2026-79719). Risk of unauthorized operations or information disclosure.
CVE-2026-81581 Buffer Overflow in privilege-escalation (CVE-2026-81581)
vulnerability in privilege-escalation (CVE-2026-81581). Successful exploitation can lead to full system takeover.
CVE-2026-77991 Unrestricted File Upload in csharp (CVE-2026-77991)
vulnerability in csharp (CVE-2026-77991). Risk of unauthorized operations or information disclosure.
CVE-2026-77018 Unrestricted File Upload in wordpress (CVE-2026-77018)
vulnerability in wordpress (CVE-2026-77018). Successful exploitation can lead to full system takeover.
CVE-2026-47884 Path Traversal in spring (CVE-2026-47884)
path traversal in spring (CVE-2026-47884). Successful exploitation can lead to full system takeover.
CVE-2026-47875 Unsafe Deserialization in deserialization (CVE-2026-47875)
vulnerability in deserialization (CVE-2026-47875). Risk of unauthorized operations or information disclosure.
CVE-2026-47852 A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
CVE-2026-71171 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
CVE-2026-54569 Vulnerability in senaite.core (CVE-2026-54569)
vulnerability in senaite.core (CVE-2026-54569). Successful exploitation can lead to full system takeover. Exploitable via `GET /senaite/bika_setup/`.
CVE-2026-12717 Vulnerability in CVE-2026-12717 (CVE-2026-12717)
vulnerability in CVE-2026-12717 (CVE-2026-12717). Risk of unauthorized operations or information disclosure.
CVE-2026-77532 Vulnerability in CVE-2026-77532 (CVE-2026-77532)
vulnerability in CVE-2026-77532 (CVE-2026-77532). Successful exploitation can lead to full system takeover.
CVE-2026-18080 Unrestricted File Upload in wordpress (CVE-2026-18080)
vulnerability in wordpress (CVE-2026-18080). Successful exploitation can lead to full system takeover.
CVE-2026-18431 Vulnerability in wordpress (CVE-2026-18431)
vulnerability in wordpress (CVE-2026-18431). Successful exploitation can lead to full system takeover.
CVE-2021-23758 KEV Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CVE-2026-54757 Code Injection in compliance-trestle (CVE-2026-54757)
code injection in compliance-trestle (CVE-2026-54757). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxedEnvironment``. Mitigation: upgrade to `4.1.0` or later.
CVE-2026-75496 Unrestricted File Upload in CVE-2026-75496 (CVE-2026-75496)
vulnerability in CVE-2026-75496 (CVE-2026-75496). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `153ec1c` or later.
CVE-2026-79774 Vulnerability in CVE-2026-79774 (CVE-2026-79774)
vulnerability in CVE-2026-79774 (CVE-2026-79774). Successful exploitation can lead to full system takeover.
CVE-2026-18798 Vulnerability in dos (CVE-2026-18798)
vulnerability in dos (CVE-2026-18798). Risk of unauthorized operations or information disclosure.
CVE-2026-57863 Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
CVE-2026-63073 Vulnerability in dos (CVE-2026-63073)
vulnerability in dos (CVE-2026-63073). Risk of unauthorized operations or information disclosure.
CVE-2026-79657 Unsafe Deserialization in CVE-2026-79657 (CVE-2026-79657)
vulnerability in CVE-2026-79657 (CVE-2026-79657). Successful exploitation can lead to full system takeover.
CVE-2026-19949 SQL Injection in wordpress (CVE-2026-19949)
SQL injection in wordpress (CVE-2026-19949). Successful exploitation can lead to full system takeover.
CVE-2026-77136 Vulnerability in CVE-2026-77136 (CVE-2026-77136)
vulnerability in CVE-2026-77136 (CVE-2026-77136). Risk of unauthorized operations or information disclosure.
CVE-2026-77138 Unsafe Deserialization in CVE-2026-77138 (CVE-2026-77138)
vulnerability in CVE-2026-77138 (CVE-2026-77138). Risk of unauthorized operations or information disclosure.
CVE-2026-16601 The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →