Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Clear
ID Title
CVE-2026-11471 Vulnerability in sqli (CVE-2026-11471)
vulnerability in sqli (CVE-2026-11471). Risk of unauthorized operations or information disclosure.
CVE-2026-11472 Vulnerability in sqli (CVE-2026-11472)
vulnerability in sqli (CVE-2026-11472). Risk of unauthorized operations or information disclosure.
CVE-2026-11470 Path Traversal in org.hswebframework.web:hsweb-system-file (CVE-2026-11470)
path traversal in org.hswebframework.web:hsweb-system-file (CVE-2026-11470). Risk of unauthorized operations or information disclosure.
CVE-2026-11473 Vulnerability in sqli (CVE-2026-11473)
vulnerability in sqli (CVE-2026-11473). Risk of unauthorized operations or information disclosure.
CVE-2026-11467 Path Traversal in path-traversal (CVE-2026-11467)
path traversal in path-traversal (CVE-2026-11467). Risk of unauthorized operations or information disclosure.
CVE-2026-11469 SSRF (Server-Side Request Forgery) in CVE-2026-11469 (CVE-2026-11469)
SSRF in CVE-2026-11469 (CVE-2026-11469). Risk of unauthorized operations or information disclosure.
CVE-2026-11462 A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This...
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This...
CVE-2026-11464 Information Disclosure in CVE-2026-11464 (CVE-2026-11464)
vulnerability in CVE-2026-11464 (CVE-2026-11464). Risk of unauthorized operations or information disclosure.
CVE-2026-11463 A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
CVE-2026-11456 Vulnerability in sqli (CVE-2026-11456)
vulnerability in sqli (CVE-2026-11456). Risk of unauthorized operations or information disclosure.
CVE-2026-11457 Vulnerability in c (CVE-2026-11457)
vulnerability in c (CVE-2026-11457). Risk of unauthorized operations or information disclosure.
CVE-2026-11408 Command Injection in CVE-2026-11408 (CVE-2026-11408)
command injection in CVE-2026-11408 (CVE-2026-11408). Risk of unauthorized operations or information disclosure.
CVE-2026-9016 Vulnerability in wordpress (CVE-2026-9016)
vulnerability in wordpress (CVE-2026-9016). Risk of unauthorized operations or information disclosure. Exploitable via ``wp_ajax_nopriv_log_js_errors``.
CVE-2026-9280 Cross-Site Scripting (XSS) in wordpress (CVE-2026-9280)
cross-site scripting in wordpress (CVE-2026-9280). Risk of unauthorized operations or information disclosure.
CVE-2026-7795 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7795)
cross-site scripting in wordpress (CVE-2026-7795). Risk of unauthorized operations or information disclosure.
CVE-2026-7566 Unsafe Deserialization in wordpress (CVE-2026-7566)
vulnerability in wordpress (CVE-2026-7566). Successful exploitation can lead to full system takeover.
CVE-2026-2500 Path Traversal in csharp (CVE-2026-2500)
path traversal in csharp (CVE-2026-2500). Confidential information can be exposed externally. Exploitable via ``filename``.
CVE-2026-9281 Cross-Site Scripting (XSS) in wordpress (CVE-2026-9281)
cross-site scripting in wordpress (CVE-2026-9281). Risk of unauthorized operations or information disclosure.
CVE-2026-8438 Cross-Site Scripting (XSS) in wordpress (CVE-2026-8438)
cross-site scripting in wordpress (CVE-2026-8438). Risk of unauthorized operations or information disclosure.
CVE-2026-9290 Path Traversal in wordpress (CVE-2026-9290)
path traversal in wordpress (CVE-2026-9290). Confidential information can be exposed externally.
CVE-2026-7654 Unsafe Deserialization in wordpress (CVE-2026-7654)
vulnerability in wordpress (CVE-2026-7654). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``.
CVE-2026-47732 Authorization Flaw in twig/twig (CVE-2026-47732)
vulnerability in twig/twig (CVE-2026-47732). Confidential information can be exposed externally. Exploitable via ``SandboxNodeVisitor``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-47730 Cross-Site Scripting (XSS) in twig/twig (CVE-2026-47730)
cross-site scripting in twig/twig (CVE-2026-47730). Risk of unauthorized operations or information disclosure. Exploitable via ``ArrayLoader``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-11422 Vulnerability in CVE-2026-11422 (CVE-2026-11422)
vulnerability in CVE-2026-11422 (CVE-2026-11422). Confidential information can be exposed externally.
CVE-2026-11400 AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-46400 Unrestricted File Upload in CVE-2026-46400 (CVE-2026-46400)
vulnerability in CVE-2026-46400 (CVE-2026-46400). Risk of unauthorized operations or information disclosure.
CVE-2026-46401 Vulnerability in CVE-2026-46401 (CVE-2026-46401)
vulnerability in CVE-2026-46401 (CVE-2026-46401). Risk of unauthorized operations or information disclosure.
CVE-2026-46493 Vulnerability in CVE-2026-46493 (CVE-2026-46493)
vulnerability in CVE-2026-46493 (CVE-2026-46493). Confidential information can be exposed externally. Exploitable via ``uniqid``.
CVE-2026-46397 Path Traversal in CVE-2026-46397 (CVE-2026-46397)
path traversal in CVE-2026-46397 (CVE-2026-46397). Confidential information can be exposed externally.
CVE-2026-46398 Vulnerability in CVE-2026-46398 (CVE-2026-46398)
vulnerability in CVE-2026-46398 (CVE-2026-46398). Risk of unauthorized operations or information disclosure.
CVE-2026-45778 Cross-Site Scripting (XSS) in buffalo (CVE-2026-45778)
cross-site scripting in buffalo (CVE-2026-45778). Risk of unauthorized operations or information disclosure.
CVE-2026-11401 AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-5415 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-5411 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-46392 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filen...
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...
CVE-2026-46394 OS Command Injection in CVE-2026-46394 (CVE-2026-46394)
OS command injection in CVE-2026-46394 (CVE-2026-46394). Risk of unauthorized operations or information disclosure.
CVE-2026-46399 Vulnerability in CVE-2026-46399 (CVE-2026-46399)
vulnerability in CVE-2026-46399 (CVE-2026-46399). Risk of unauthorized operations or information disclosure.
CVE-2026-46390 Vulnerability in CVE-2026-46390 (CVE-2026-46390)
vulnerability in CVE-2026-46390 (CVE-2026-46390). Risk of unauthorized operations or information disclosure.
CVE-2026-50733 Vulnerability in CVE-2026-50733 (CVE-2026-50733)
vulnerability in CVE-2026-50733 (CVE-2026-50733). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
CVE-2026-11342 Vulnerability in sqli (CVE-2026-11342)
vulnerability in sqli (CVE-2026-11342). Risk of unauthorized operations or information disclosure.
CVE-2026-11344 Vulnerability in CVE-2026-11344 (CVE-2026-11344)
vulnerability in CVE-2026-11344 (CVE-2026-11344). Risk of unauthorized operations or information disclosure.
CVE-2026-47731 Path Traversal in ait-core (CVE-2026-47731)
path traversal in ait-core (CVE-2026-47731). Data can be tampered with by attackers. Exploitable via ``python_poc.py``. Mitigation: upgrade to `2.6.1` or later.
CVE-2026-48103 Out-of-Bounds Read in cpp (CVE-2026-48103)
vulnerability in cpp (CVE-2026-48103). Risk of unauthorized operations or information disclosure.
CVE-2026-48111 Out-of-Bounds Read in cpp (CVE-2026-48111)
vulnerability in cpp (CVE-2026-48111). Risk of unauthorized operations or information disclosure.
CVE-2026-11339 Vulnerability in c (CVE-2026-11339)
vulnerability in c (CVE-2026-11339). Risk of unauthorized operations or information disclosure.
CVE-2026-11337 Cross-Site Scripting (XSS) in CVE-2026-11337 (CVE-2026-11337)
cross-site scripting in CVE-2026-11337 (CVE-2026-11337). Risk of unauthorized operations or information disclosure.
CVE-2026-48017 Code Injection in dbgate-api (CVE-2026-48017)
code injection in dbgate-api (CVE-2026-48017). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/load-reader`. Mitigation: upgrade to `7.1.9` or later.
CVE-2026-47669 Path Traversal in dbgate (CVE-2026-47669)
path traversal in dbgate (CVE-2026-47669). Risk of unauthorized operations or information disclosure. Exploitable via `POST /auth/login`. Mitigation: upgrade to `7.1.9` or later.
CVE-2026-47668 Vulnerability in dbgate-serve (CVE-2026-47668)
vulnerability in dbgate-serve (CVE-2026-47668). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/start`. Mitigation: upgrade to `7.1.9` or later.
CVE-2026-47387 Cross-Site Scripting (XSS) in nocodb (CVE-2026-47387)
cross-site scripting in nocodb (CVE-2026-47387). Risk of unauthorized operations or information disclosure. Exploitable via ``redirect_url``. Mitigation: upgrade to `2026.05.1` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →