Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72573 |
|
OS Command Injection in CVE-2026-72573 (CVE-2026-72573)
OS command injection in CVE-2026-72573 (CVE-2026-72573). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72576 |
|
Cross-Site Scripting (XSS) in CVE-2026-72576 (CVE-2026-72576)
cross-site scripting in CVE-2026-72576 (CVE-2026-72576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72570 |
|
Cross-Site Scripting (XSS) in CVE-2026-72570 (CVE-2026-72570)
cross-site scripting in CVE-2026-72570 (CVE-2026-72570). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72571 |
|
Path Traversal in path-traversal (CVE-2026-72571)
path traversal in path-traversal (CVE-2026-72571). Confidential information can be exposed externally.
|
| CVE-2026-72572 |
|
Path Traversal in path-traversal (CVE-2026-72572)
path traversal in path-traversal (CVE-2026-72572). Confidential information can be exposed externally.
|
| CVE-2026-71391 |
|
Vulnerability in c (CVE-2026-71391)
vulnerability in c (CVE-2026-71391). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71392 |
|
Vulnerability in c (CVE-2026-71392)
vulnerability in c (CVE-2026-71392). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71393 |
|
Vulnerability in c (CVE-2026-71393)
vulnerability in c (CVE-2026-71393). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71394 |
|
Vulnerability in c (CVE-2026-71394)
vulnerability in c (CVE-2026-71394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66485 |
|
Vulnerability in c (CVE-2026-66485)
vulnerability in c (CVE-2026-66485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19075 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19075 (CVE-2026-19075)
SSRF in CVE-2026-19075 (CVE-2026-19075). Risk of unauthorized operations or information disclosure. Exploitable via ``aiovg_videos``.
|
| CVE-2026-17019 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17019)
cross-site scripting in wordpress (CVE-2026-17019). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16985 |
|
Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14293 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14293)
cross-site scripting in wordpress (CVE-2026-14293). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15047 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15047)
cross-site scripting in wordpress (CVE-2026-15047). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13170 |
|
Path Traversal in wordpress (CVE-2026-13170)
path traversal in wordpress (CVE-2026-13170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19384 |
|
Vulnerability in sqli (CVE-2026-19384)
vulnerability in sqli (CVE-2026-19384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19378 |
|
Cross-Site Scripting (XSS) in CVE-2026-19378 (CVE-2026-19378)
cross-site scripting in CVE-2026-19378 (CVE-2026-19378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19376 |
|
Vulnerability in CVE-2026-19376 (CVE-2026-19376)
vulnerability in CVE-2026-19376 (CVE-2026-19376). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12372 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-12372)
SSRF in ssrf (CVE-2026-12372). Risk of unauthorized operations or information disclosure. Exploitable via ``ipaddress``.
|
| CVE-2026-19364 |
|
Vulnerability in sqli (CVE-2026-19364)
vulnerability in sqli (CVE-2026-19364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19353 |
|
Vulnerability in CVE-2026-19353 (CVE-2026-19353)
vulnerability in CVE-2026-19353 (CVE-2026-19353). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19351 |
|
Vulnerability in sqli (CVE-2026-19351)
vulnerability in sqli (CVE-2026-19351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19350 |
|
Vulnerability in CVE-2026-19350 (CVE-2026-19350)
vulnerability in CVE-2026-19350 (CVE-2026-19350). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19347 |
|
Vulnerability in sqli (CVE-2026-19347)
vulnerability in sqli (CVE-2026-19347). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19345 |
|
Vulnerability in CVE-2026-19345 (CVE-2026-19345)
vulnerability in CVE-2026-19345 (CVE-2026-19345). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19344 |
|
Vulnerability in sqli (CVE-2026-19344)
vulnerability in sqli (CVE-2026-19344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19342 |
|
Authentication Bypass in CVE-2026-19342 (CVE-2026-19342)
authentication bypass in CVE-2026-19342 (CVE-2026-19342). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19343 |
|
Vulnerability in sqli (CVE-2026-19343)
vulnerability in sqli (CVE-2026-19343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19340 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19340 (CVE-2026-19340)
SSRF in CVE-2026-19340 (CVE-2026-19340). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18465 |
|
Path Traversal in wordpress (CVE-2026-18465)
path traversal in wordpress (CVE-2026-18465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10595 |
|
Vulnerability in path-traversal (CVE-2026-10595)
vulnerability in path-traversal (CVE-2026-10595). Confidential information can be exposed externally. Exploitable via ``pathlib``.
|
| CVE-2026-71991 |
|
OS Command Injection in c (CVE-2026-71991)
OS command injection in c (CVE-2026-71991). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71502 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-71502)
cross-site scripting in vue (CVE-2026-71502). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71949 |
|
OS Command Injection in c (CVE-2026-71949)
OS command injection in c (CVE-2026-71949). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71950 |
|
OS Command Injection in c (CVE-2026-71950)
OS command injection in c (CVE-2026-71950). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71951 |
|
OS Command Injection in c (CVE-2026-71951)
OS command injection in c (CVE-2026-71951). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19282 |
|
Vulnerability in c (CVE-2026-19282)
vulnerability in c (CVE-2026-19282). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68082 |
|
Vulnerability in c (CVE-2026-68082)
vulnerability in c (CVE-2026-68082). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19259 |
|
Buffer Overflow in c (CVE-2026-19259)
vulnerability in c (CVE-2026-19259). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19263 |
|
Vulnerability in CVE-2026-19263 (CVE-2026-19263)
vulnerability in CVE-2026-19263 (CVE-2026-19263). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16558 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16558)
cross-site scripting in wordpress (CVE-2026-16558). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16559 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16559)
cross-site scripting in wordpress (CVE-2026-16559). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16267 |
|
Unsafe Deserialization in wordpress (CVE-2026-16267)
vulnerability in wordpress (CVE-2026-16267). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14526 |
|
Privilege Escalation in wordpress (CVE-2026-14526)
vulnerability in wordpress (CVE-2026-14526). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13505 |
|
Vulnerability in CVE-2026-13505 (CVE-2026-13505)
vulnerability in CVE-2026-13505 (CVE-2026-13505). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8798 |
|
Vulnerability in CVE-2026-8798 (CVE-2026-8798)
vulnerability in CVE-2026-8798 (CVE-2026-8798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48122 |
|
OS Command Injection in CVE-2026-48122 (CVE-2026-48122)
OS command injection in CVE-2026-48122 (CVE-2026-48122). Risk of unauthorized operations or information disclosure. Exploitable via ``Gemfile``.
|
| CVE-2026-48026 |
|
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
|
| CVE-2026-11742 |
|
Use-After-Free in c (CVE-2026-11742)
vulnerability in c (CVE-2026-11742). Risk of unauthorized operations or information disclosure.
|