Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-67986 |
|
Code Injection in CVE-2026-67986 (CVE-2026-67986)
code injection in CVE-2026-67986 (CVE-2026-67986). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67990 |
|
Cross-Site Request Forgery (CSRF) in rails (CVE-2026-67990)
vulnerability in rails (CVE-2026-67990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67991 |
|
Vulnerability in dos (CVE-2026-67991)
vulnerability in dos (CVE-2026-67991). Confidential information can be exposed externally.
|
| CVE-2026-28176 |
|
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
|
| CVE-2026-28149 |
|
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
|
| CVE-2026-19716 |
|
Cross-Site Scripting (XSS) in CVE-2026-19716 (CVE-2026-19716)
cross-site scripting in CVE-2026-19716 (CVE-2026-19716). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27380 |
|
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
|
| CVE-2025-62318 |
|
Cross-Site Request Forgery (CSRF) in CVE-2025-62318 (CVE-2025-62318)
vulnerability in CVE-2025-62318 (CVE-2025-62318). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55087 |
|
Cross-Site Scripting (XSS) in ep_etherpad-lite (CVE-2026-55087)
cross-site scripting in ep_etherpad-lite (CVE-2026-55087). Risk of unauthorized operations or information disclosure. Exploitable via ``String.prototype.replaceAll``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49827 |
|
Vulnerability in CVE-2026-49827 (CVE-2026-49827)
vulnerability in CVE-2026-49827 (CVE-2026-49827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73617 |
|
Vulnerability in CVE-2026-73617 (CVE-2026-73617)
vulnerability in CVE-2026-73617 (CVE-2026-73617). Confidential information can be exposed externally.
|
| CVE-2026-73628 |
|
Cross-Site Scripting (XSS) in CVE-2026-73628 (CVE-2026-73628)
cross-site scripting in CVE-2026-73628 (CVE-2026-73628). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2026-73602 |
|
Vulnerability in path-traversal (CVE-2026-73602)
vulnerability in path-traversal (CVE-2026-73602). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73483 |
|
OS Command Injection in CVE-2026-73483 (CVE-2026-73483)
OS command injection in CVE-2026-73483 (CVE-2026-73483). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-73486 |
|
Code Injection in CVE-2026-73486 (CVE-2026-73486)
code injection in CVE-2026-73486 (CVE-2026-73486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73485 |
|
Code Injection in CVE-2026-73485 (CVE-2026-73485)
code injection in CVE-2026-73485 (CVE-2026-73485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73487 |
|
Code Injection in ssrf (CVE-2026-73487)
code injection in ssrf (CVE-2026-73487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18368 |
|
Vulnerability in c (CVE-2026-18368)
vulnerability in c (CVE-2026-18368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19484 |
|
Vulnerability in CVE-2026-19484 (CVE-2026-19484)
vulnerability in CVE-2026-19484 (CVE-2026-19484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19481 |
|
Vulnerability in dos (CVE-2026-19481)
vulnerability in dos (CVE-2026-19481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18146 |
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
| CVE-2026-19135 |
|
Vulnerability in CVE-2026-19135 (CVE-2026-19135)
vulnerability in CVE-2026-19135 (CVE-2026-19135). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46382 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-46382 (CVE-2026-46382)
SSRF in CVE-2026-46382 (CVE-2026-46382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46688 |
|
Open Redirect in CVE-2026-46688 (CVE-2026-46688)
vulnerability in CVE-2026-46688 (CVE-2026-46688). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49819 |
|
OS Command Injection in c (CVE-2026-49819)
OS command injection in c (CVE-2026-49819). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/upsnap/init-superuser`.
|
| CVE-2026-50544 |
|
Vulnerability in c (CVE-2026-50544)
vulnerability in c (CVE-2026-50544). Successful exploitation can lead to full system takeover. Exploitable via ``SYSTEM``.
|
| CVE-2026-49481 |
|
OS Command Injection in c (CVE-2026-49481)
OS command injection in c (CVE-2026-49481). Confidential information can be exposed externally.
|
| CVE-2026-73492 |
|
Cross-Site Scripting (XSS) in CVE-2026-73492 (CVE-2026-73492)
cross-site scripting in CVE-2026-73492 (CVE-2026-73492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19642 |
|
Out-of-Bounds Write in Amazon aws (CVE-2026-19642)
out-of-bounds write in Amazon aws (CVE-2026-19642). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73332 |
|
SQL Injection in c (CVE-2026-73332)
SQL injection in c (CVE-2026-73332). Confidential information can be exposed externally.
|
| CVE-2026-73329 |
|
Cross-Site Scripting (XSS) in CVE-2026-73329 (CVE-2026-73329)
cross-site scripting in CVE-2026-73329 (CVE-2026-73329). Confidential information can be exposed externally.
|
| CVE-2026-73330 |
|
Vulnerability in rails (CVE-2026-73330)
vulnerability in rails (CVE-2026-73330). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72802 |
|
Vulnerability in c (CVE-2026-72802)
vulnerability in c (CVE-2026-72802). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72787 |
|
Cross-Site Scripting (XSS) in CVE-2026-72787 (CVE-2026-72787)
cross-site scripting in CVE-2026-72787 (CVE-2026-72787). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49466 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-49466)
cross-site scripting in wordpress (CVE-2026-49466). Risk of unauthorized operations or information disclosure. Exploitable via ``template``.
|
| CVE-2026-19657 |
|
Cross-Site Scripting (XSS) in scada-lts (CVE-2026-19657)
cross-site scripting in scada-lts (CVE-2026-19657). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19643 |
|
Out-of-Bounds Read in cpp (CVE-2026-19643)
vulnerability in cpp (CVE-2026-19643). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18676 |
|
Vulnerability in c (CVE-2026-18676)
vulnerability in c (CVE-2026-18676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73327 |
|
Path Traversal in path-traversal (CVE-2026-73327)
path traversal in path-traversal (CVE-2026-73327). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48550 |
|
Cross-Site Scripting (XSS) in CVE-2026-48550 (CVE-2026-48550)
cross-site scripting in CVE-2026-48550 (CVE-2026-48550). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48552 |
|
Cross-Site Scripting (XSS) in CVE-2026-48552 (CVE-2026-48552)
cross-site scripting in CVE-2026-48552 (CVE-2026-48552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16694 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2026-16694)
cross-site scripting in ibm (CVE-2026-16694). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73299 |
|
Code Injection in CVE-2026-73299 (CVE-2026-73299)
code injection in CVE-2026-73299 (CVE-2026-73299). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49467 |
|
Vulnerability in CVE-2026-49467 (CVE-2026-49467)
vulnerability in CVE-2026-49467 (CVE-2026-49467). Successful exploitation can lead to full system takeover. Exploitable via ``await``.
|
| CVE-2026-73295 |
|
Cross-Site Scripting (XSS) in CVE-2026-73295 (CVE-2026-73295)
cross-site scripting in CVE-2026-73295 (CVE-2026-73295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73325 |
|
Unsafe Deserialization in deserialization (CVE-2026-73325)
vulnerability in deserialization (CVE-2026-73325). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19548 |
|
Use-After-Free in c (CVE-2026-19548)
vulnerability in c (CVE-2026-19548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73374 |
|
Cross-Site Scripting (XSS) in CVE-2026-73374 (CVE-2026-73374)
cross-site scripting in CVE-2026-73374 (CVE-2026-73374). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48798 |
|
Path Traversal in SSH.NET (CVE-2026-48798)
path traversal in SSH.NET (CVE-2026-48798). Data can be tampered with by attackers. Exploitable via ``ScpException``. Mitigation: upgrade to `2026.0.0` or later.
|
| CVE-2026-73291 |
|
Path Traversal in CVE-2026-73291 (CVE-2026-73291)
path traversal in CVE-2026-73291 (CVE-2026-73291). Data can be tampered with by attackers. Exploitable via `GET /avatarproxy/`.
|