Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Clear
ID Title
CVE-2026-71283 Path Traversal in CVE-2026-71283 (CVE-2026-71283)
path traversal in CVE-2026-71283 (CVE-2026-71283). Data can be tampered with by attackers.
CVE-2026-71277 Authentication Bypass in CVE-2026-71277 (CVE-2026-71277)
authentication bypass in CVE-2026-71277 (CVE-2026-71277). Confidential information can be exposed externally. Exploitable via `Authorization header`.
CVE-2026-71282 SQL Injection in CVE-2026-71282 (CVE-2026-71282)
SQL injection in CVE-2026-71282 (CVE-2026-71282). Confidential information can be exposed externally.
CVE-2026-71269 Path Traversal in CVE-2026-71269 (CVE-2026-71269)
path traversal in CVE-2026-71269 (CVE-2026-71269). Successful exploitation can lead to full system takeover. Exploitable via `POST /library/`.
CVE-2026-71275 Cross-Site Scripting (XSS) in c (CVE-2026-71275)
cross-site scripting in c (CVE-2026-71275). Risk of unauthorized operations or information disclosure. Exploitable via ``host``.
CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
CVE-2026-71271 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
CVE-2026-71272 Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
CVE-2026-71273 Cross-Site Request Forgery (CSRF) in c (CVE-2026-71273)
vulnerability in c (CVE-2026-71273). Data can be tampered with by attackers. Exploitable via ``web_admin_password_enabled``.
CVE-2026-71274 Cross-Site Scripting (XSS) in c (CVE-2026-71274)
cross-site scripting in c (CVE-2026-71274). Confidential information can be exposed externally.
CVE-2026-71263 Out-of-Bounds Write in c (CVE-2026-71263)
out-of-bounds write in c (CVE-2026-71263). Data can be tampered with by attackers.
CVE-2026-71266 Vulnerability in c (CVE-2026-71266)
vulnerability in c (CVE-2026-71266). Successful exploitation can lead to full system takeover. Exploitable via ``linebuf``.
CVE-2026-71267 Vulnerability in c (CVE-2026-71267)
vulnerability in c (CVE-2026-71267). Successful exploitation can lead to full system takeover. Exploitable via ``name``.
CVE-2026-71260 Vulnerability in cpp (CVE-2026-71260)
vulnerability in cpp (CVE-2026-71260). Confidential information can be exposed externally. Exploitable via `GET /text/`.
CVE-2026-71264 Vulnerability in cpp (CVE-2026-71264)
vulnerability in cpp (CVE-2026-71264). Data can be tampered with by attackers. Exploitable via `GET /json/cfg`.
CVE-2026-71265 Vulnerability in cpp (CVE-2026-71265)
vulnerability in cpp (CVE-2026-71265). Successful exploitation can lead to full system takeover.
CVE-2026-71259 ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
CVE-2026-71251 Vulnerability in CVE-2026-71251 (CVE-2026-71251)
vulnerability in CVE-2026-71251 (CVE-2026-71251). Confidential information can be exposed externally.
CVE-2026-71252 Vulnerability in CVE-2026-71252 (CVE-2026-71252)
vulnerability in CVE-2026-71252 (CVE-2026-71252). Data can be tampered with by attackers.
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
CVE-2026-71254 Out-of-Bounds Write in c (CVE-2026-71254)
out-of-bounds write in c (CVE-2026-71254). Successful exploitation can lead to full system takeover.
CVE-2026-71255 Out-of-Bounds Write in c (CVE-2026-71255)
out-of-bounds write in c (CVE-2026-71255). Risk of unauthorized operations or information disclosure.
CVE-2026-71256 Out-of-Bounds Read in c (CVE-2026-71256)
vulnerability in c (CVE-2026-71256). Successful exploitation can lead to full system takeover.
CVE-2026-71250 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71250)
SSRF in ssrf (CVE-2026-71250). Risk of unauthorized operations or information disclosure.
CVE-2026-71249 Cross-Site Scripting (XSS) in CVE-2026-71249 (CVE-2026-71249)
cross-site scripting in CVE-2026-71249 (CVE-2026-71249). Risk of unauthorized operations or information disclosure.
CVE-2026-71248 SQL Injection in sqli (CVE-2026-71248)
SQL injection in sqli (CVE-2026-71248). Successful exploitation can lead to full system takeover.
CVE-2026-71245 SQL Injection in CVE-2026-71245 (CVE-2026-71245)
SQL injection in CVE-2026-71245 (CVE-2026-71245). Confidential information can be exposed externally.
CVE-2026-71237 SQL Injection in sqli (CVE-2026-71237)
SQL injection in sqli (CVE-2026-71237). Successful exploitation can lead to full system takeover. Exploitable via `POST /userlogin`.
CVE-2026-71236 Cross-Site Scripting (XSS) in CVE-2026-71236 (CVE-2026-71236)
cross-site scripting in CVE-2026-71236 (CVE-2026-71236). Confidential information can be exposed externally.
CVE-2026-71233 Cross-Site Scripting (XSS) in laravel (CVE-2026-71233)
cross-site scripting in laravel (CVE-2026-71233). Confidential information can be exposed externally. Exploitable via `PUT /api/v1/invoices/{id}`.
CVE-2026-71235 Code Injection in ssrf (CVE-2026-71235)
code injection in ssrf (CVE-2026-71235). Successful exploitation can lead to full system takeover.
CVE-2026-71231 SQL Injection in sqli (CVE-2026-71231)
SQL injection in sqli (CVE-2026-71231). Successful exploitation can lead to full system takeover.
CVE-2026-71232 Code Injection in CVE-2026-71232 (CVE-2026-71232)
code injection in CVE-2026-71232 (CVE-2026-71232). Successful exploitation can lead to full system takeover.
CVE-2026-7693 Command Injection in wordpress (CVE-2026-7693)
command injection in wordpress (CVE-2026-7693). Successful exploitation can lead to full system takeover. Exploitable via ``file``.
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
CVE-2026-71215 art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
CVE-2026-71207 SQL Injection in CVE-2026-71207 (CVE-2026-71207)
SQL injection in CVE-2026-71207 (CVE-2026-71207). Successful exploitation can lead to full system takeover.
CVE-2026-71206 Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
CVE-2026-71202 Vulnerability in CVE-2026-71202 (CVE-2026-71202)
vulnerability in CVE-2026-71202 (CVE-2026-71202). Risk of unauthorized operations or information disclosure.
CVE-2026-70376 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
CVE-2026-6639 Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-70378 Vulnerability in CVE-2026-70378 (CVE-2026-70378)
vulnerability in CVE-2026-70378 (CVE-2026-70378). Risk of unauthorized operations or information disclosure. Exploitable via ``scale``.
CVE-2026-6020 Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
CVE-2026-64580 Vulnerability in c (CVE-2026-64580)
vulnerability in c (CVE-2026-64580). Successful exploitation can lead to full system takeover.
CVE-2026-64581 Vulnerability in c (CVE-2026-64581)
vulnerability in c (CVE-2026-64581). Successful exploitation can lead to full system takeover.
CVE-2026-64573 Vulnerability in c (CVE-2026-64573)
vulnerability in c (CVE-2026-64573). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →