Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Clear
ID Title
CVE-2026-72573 OS Command Injection in CVE-2026-72573 (CVE-2026-72573)
OS command injection in CVE-2026-72573 (CVE-2026-72573). Successful exploitation can lead to full system takeover.
CVE-2026-72576 Cross-Site Scripting (XSS) in CVE-2026-72576 (CVE-2026-72576)
cross-site scripting in CVE-2026-72576 (CVE-2026-72576). Risk of unauthorized operations or information disclosure.
CVE-2026-72570 Cross-Site Scripting (XSS) in CVE-2026-72570 (CVE-2026-72570)
cross-site scripting in CVE-2026-72570 (CVE-2026-72570). Risk of unauthorized operations or information disclosure.
CVE-2026-72571 Path Traversal in path-traversal (CVE-2026-72571)
path traversal in path-traversal (CVE-2026-72571). Confidential information can be exposed externally.
CVE-2026-72572 Path Traversal in path-traversal (CVE-2026-72572)
path traversal in path-traversal (CVE-2026-72572). Confidential information can be exposed externally.
CVE-2026-71391 Vulnerability in c (CVE-2026-71391)
vulnerability in c (CVE-2026-71391). Risk of unauthorized operations or information disclosure.
CVE-2026-71392 Vulnerability in c (CVE-2026-71392)
vulnerability in c (CVE-2026-71392). Risk of unauthorized operations or information disclosure.
CVE-2026-71393 Vulnerability in c (CVE-2026-71393)
vulnerability in c (CVE-2026-71393). Risk of unauthorized operations or information disclosure.
CVE-2026-71394 Vulnerability in c (CVE-2026-71394)
vulnerability in c (CVE-2026-71394). Risk of unauthorized operations or information disclosure.
CVE-2026-66485 Vulnerability in c (CVE-2026-66485)
vulnerability in c (CVE-2026-66485). Risk of unauthorized operations or information disclosure.
CVE-2026-19075 SSRF (Server-Side Request Forgery) in CVE-2026-19075 (CVE-2026-19075)
SSRF in CVE-2026-19075 (CVE-2026-19075). Risk of unauthorized operations or information disclosure. Exploitable via ``aiovg_videos``.
CVE-2026-17019 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17019)
cross-site scripting in wordpress (CVE-2026-17019). Risk of unauthorized operations or information disclosure.
CVE-2026-16985 Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
CVE-2026-14293 Cross-Site Scripting (XSS) in wordpress (CVE-2026-14293)
cross-site scripting in wordpress (CVE-2026-14293). Successful exploitation can lead to full system takeover.
CVE-2026-15047 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15047)
cross-site scripting in wordpress (CVE-2026-15047). Successful exploitation can lead to full system takeover.
CVE-2026-13170 Path Traversal in wordpress (CVE-2026-13170)
path traversal in wordpress (CVE-2026-13170). Successful exploitation can lead to full system takeover.
CVE-2026-19384 Vulnerability in sqli (CVE-2026-19384)
vulnerability in sqli (CVE-2026-19384). Risk of unauthorized operations or information disclosure.
CVE-2026-19378 Cross-Site Scripting (XSS) in CVE-2026-19378 (CVE-2026-19378)
cross-site scripting in CVE-2026-19378 (CVE-2026-19378). Risk of unauthorized operations or information disclosure.
CVE-2026-19376 Vulnerability in CVE-2026-19376 (CVE-2026-19376)
vulnerability in CVE-2026-19376 (CVE-2026-19376). Risk of unauthorized operations or information disclosure.
CVE-2026-12372 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12372)
SSRF in ssrf (CVE-2026-12372). Risk of unauthorized operations or information disclosure. Exploitable via ``ipaddress``.
CVE-2026-19364 Vulnerability in sqli (CVE-2026-19364)
vulnerability in sqli (CVE-2026-19364). Risk of unauthorized operations or information disclosure.
CVE-2026-19353 Vulnerability in CVE-2026-19353 (CVE-2026-19353)
vulnerability in CVE-2026-19353 (CVE-2026-19353). Risk of unauthorized operations or information disclosure.
CVE-2026-19351 Vulnerability in sqli (CVE-2026-19351)
vulnerability in sqli (CVE-2026-19351). Risk of unauthorized operations or information disclosure.
CVE-2026-19350 Vulnerability in CVE-2026-19350 (CVE-2026-19350)
vulnerability in CVE-2026-19350 (CVE-2026-19350). Risk of unauthorized operations or information disclosure.
CVE-2026-19347 Vulnerability in sqli (CVE-2026-19347)
vulnerability in sqli (CVE-2026-19347). Risk of unauthorized operations or information disclosure.
CVE-2026-19345 Vulnerability in CVE-2026-19345 (CVE-2026-19345)
vulnerability in CVE-2026-19345 (CVE-2026-19345). Risk of unauthorized operations or information disclosure.
CVE-2026-19344 Vulnerability in sqli (CVE-2026-19344)
vulnerability in sqli (CVE-2026-19344). Risk of unauthorized operations or information disclosure.
CVE-2026-19342 Authentication Bypass in CVE-2026-19342 (CVE-2026-19342)
authentication bypass in CVE-2026-19342 (CVE-2026-19342). Risk of unauthorized operations or information disclosure.
CVE-2026-19343 Vulnerability in sqli (CVE-2026-19343)
vulnerability in sqli (CVE-2026-19343). Risk of unauthorized operations or information disclosure.
CVE-2026-19340 SSRF (Server-Side Request Forgery) in CVE-2026-19340 (CVE-2026-19340)
SSRF in CVE-2026-19340 (CVE-2026-19340). Risk of unauthorized operations or information disclosure.
CVE-2026-18465 Path Traversal in wordpress (CVE-2026-18465)
path traversal in wordpress (CVE-2026-18465). Risk of unauthorized operations or information disclosure.
CVE-2026-10595 Vulnerability in path-traversal (CVE-2026-10595)
vulnerability in path-traversal (CVE-2026-10595). Confidential information can be exposed externally. Exploitable via ``pathlib``.
CVE-2026-71991 OS Command Injection in c (CVE-2026-71991)
OS command injection in c (CVE-2026-71991). Successful exploitation can lead to full system takeover.
CVE-2026-71502 Cross-Site Scripting (XSS) in vue (CVE-2026-71502)
cross-site scripting in vue (CVE-2026-71502). Risk of unauthorized operations or information disclosure.
CVE-2026-71949 OS Command Injection in c (CVE-2026-71949)
OS command injection in c (CVE-2026-71949). Successful exploitation can lead to full system takeover.
CVE-2026-71950 OS Command Injection in c (CVE-2026-71950)
OS command injection in c (CVE-2026-71950). Successful exploitation can lead to full system takeover.
CVE-2026-71951 OS Command Injection in c (CVE-2026-71951)
OS command injection in c (CVE-2026-71951). Successful exploitation can lead to full system takeover.
CVE-2026-19282 Vulnerability in c (CVE-2026-19282)
vulnerability in c (CVE-2026-19282). Risk of unauthorized operations or information disclosure.
CVE-2026-68082 Vulnerability in c (CVE-2026-68082)
vulnerability in c (CVE-2026-68082). Successful exploitation can lead to full system takeover.
CVE-2026-19259 Buffer Overflow in c (CVE-2026-19259)
vulnerability in c (CVE-2026-19259). Risk of unauthorized operations or information disclosure.
CVE-2026-19263 Vulnerability in CVE-2026-19263 (CVE-2026-19263)
vulnerability in CVE-2026-19263 (CVE-2026-19263). Risk of unauthorized operations or information disclosure.
CVE-2026-16558 Cross-Site Scripting (XSS) in wordpress (CVE-2026-16558)
cross-site scripting in wordpress (CVE-2026-16558). Risk of unauthorized operations or information disclosure.
CVE-2026-16559 Cross-Site Scripting (XSS) in wordpress (CVE-2026-16559)
cross-site scripting in wordpress (CVE-2026-16559). Successful exploitation can lead to full system takeover.
CVE-2026-16267 Unsafe Deserialization in wordpress (CVE-2026-16267)
vulnerability in wordpress (CVE-2026-16267). Successful exploitation can lead to full system takeover.
CVE-2026-14526 Privilege Escalation in wordpress (CVE-2026-14526)
vulnerability in wordpress (CVE-2026-14526). Successful exploitation can lead to full system takeover.
CVE-2026-13505 Vulnerability in CVE-2026-13505 (CVE-2026-13505)
vulnerability in CVE-2026-13505 (CVE-2026-13505). Risk of unauthorized operations or information disclosure.
CVE-2026-8798 Vulnerability in CVE-2026-8798 (CVE-2026-8798)
vulnerability in CVE-2026-8798 (CVE-2026-8798). Risk of unauthorized operations or information disclosure.
CVE-2026-48122 OS Command Injection in CVE-2026-48122 (CVE-2026-48122)
OS command injection in CVE-2026-48122 (CVE-2026-48122). Risk of unauthorized operations or information disclosure. Exploitable via ``Gemfile``.
CVE-2026-48026 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
CVE-2026-11742 Use-After-Free in c (CVE-2026-11742)
vulnerability in c (CVE-2026-11742). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →