Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-69935 |
|
SQL Injection in sqli (CVE-2025-69935)
SQL injection in sqli (CVE-2025-69935). Successful exploitation can lead to full system takeover.
|
| CVE-2025-65341 |
|
Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
|
| CVE-2025-69930 |
|
SQL Injection in sqli (CVE-2025-69930)
SQL injection in sqli (CVE-2025-69930). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69937 |
|
SQL Injection in sqli (CVE-2025-69937)
SQL injection in sqli (CVE-2025-69937). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69931 |
|
SQL Injection in sqli (CVE-2025-69931)
SQL injection in sqli (CVE-2025-69931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67207 |
|
Vulnerability in CVE-2026-67207 (CVE-2026-67207)
vulnerability in CVE-2026-67207 (CVE-2026-67207). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67206 |
|
Unrestricted File Upload in CVE-2026-67206 (CVE-2026-67206)
vulnerability in CVE-2026-67206 (CVE-2026-67206). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69936 |
|
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
|
| CVE-2025-65336 |
|
SQL Injection in sqli (CVE-2025-65336)
SQL injection in sqli (CVE-2025-65336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35847 |
|
Command Injection in CVE-2026-35847 (CVE-2026-35847)
command injection in CVE-2026-35847 (CVE-2026-35847). Successful exploitation can lead to full system takeover.
|
| CVE-2025-51684 |
|
Cross-Site Scripting (XSS) in CVE-2025-51684 (CVE-2025-51684)
cross-site scripting in CVE-2025-51684 (CVE-2025-51684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66416 |
|
Cross-Site Request Forgery (CSRF) in laravel (CVE-2026-66416)
vulnerability in laravel (CVE-2026-66416). Successful exploitation can lead to full system takeover.
|
| CVE-2025-0152 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2025-0152)
cross-site scripting in ibm (CVE-2025-0152). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68499 |
|
Vulnerability in re2 (CVE-2026-68499)
vulnerability in re2 (CVE-2026-68499). Risk of unauthorized operations or information disclosure. Exploitable via ``String.prototype.match``. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2026-61526 |
|
Cross-Site Scripting (XSS) in CVE-2026-61526 (CVE-2026-61526)
cross-site scripting in CVE-2026-61526 (CVE-2026-61526). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67550 |
|
Out-of-Bounds Read in re2 (CVE-2026-67550)
vulnerability in re2 (CVE-2026-67550). Risk of unauthorized operations or information disclosure. Exploitable via ``re2``. Mitigation: upgrade to `1.25.1` or later.
|
| CVE-2026-61536 |
|
Code Injection in CVE-2026-61536 (CVE-2026-61536)
code injection in CVE-2026-61536 (CVE-2026-61536). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.4.2` or later.
|
| CVE-2026-59881 |
|
Vulnerability in aiohttp (CVE-2026-59881)
vulnerability in aiohttp (CVE-2026-59881). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.2` or later.
|
| CVE-2026-51291 |
|
Use-After-Free in c (CVE-2026-51291)
vulnerability in c (CVE-2026-51291). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48910 |
|
Vulnerability in apache (CVE-2026-48910)
vulnerability in apache (CVE-2026-48910). Confidential information can be exposed externally.
|
| CVE-2026-57862 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57862)
SSRF in ssrf (CVE-2026-57862). Confidential information can be exposed externally.
|
| CVE-2026-66066 |
|
Vulnerability in activestorage (CVE-2026-66066)
vulnerability in activestorage (CVE-2026-66066). Risk of unauthorized operations or information disclosure. Exploitable via ``secret_key_base``. Mitigation: upgrade to `8.1.3.1` or later.
|
| CVE-2026-62663 |
|
Path Traversal in path-traversal (CVE-2026-62663)
path traversal in path-traversal (CVE-2026-62663). Confidential information can be exposed externally.
|
| CVE-2026-54522 |
|
Use-After-Free in msgpack (CVE-2026-54522)
vulnerability in msgpack (CVE-2026-54522). Risk of unauthorized operations or information disclosure. Exploitable via ``rmem_last``. Mitigation: upgrade to `1.8.2` or later.
|
| CVE-2026-54722 |
|
Vulnerability in dssrf (CVE-2026-54722)
vulnerability in dssrf (CVE-2026-54722). Risk of unauthorized operations or information disclosure. Exploitable via ``is_url_safe``. Mitigation: upgrade to `1.0.4` or later.
|
| CVE-2025-36431 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2025-36431)
cross-site scripting in ibm (CVE-2025-36431). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-36298 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2025-36298)
cross-site scripting in ibm (CVE-2025-36298). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54364 |
|
Vulnerability in c (CVE-2026-54364)
vulnerability in c (CVE-2026-54364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57859 |
|
Unsafe Deserialization in deserialization (CVE-2026-57859)
vulnerability in deserialization (CVE-2026-57859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7260 |
|
Vulnerability in c (CVE-2026-7260)
vulnerability in c (CVE-2026-7260). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17544 |
|
Out-of-Bounds Write in CVE-2026-17544 (CVE-2026-17544)
out-of-bounds write in CVE-2026-17544 (CVE-2026-17544). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17543 |
|
SQL Injection in sqli (CVE-2026-17543)
SQL injection in sqli (CVE-2026-17543). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18353 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18353 (CVE-2026-18353)
SSRF in CVE-2026-18353 (CVE-2026-18353). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/upload/sbom`.
|
| CVE-2026-58040 |
|
Vulnerability in CVE-2026-58040 (CVE-2026-58040)
vulnerability in CVE-2026-58040 (CVE-2026-58040). Confidential information can be exposed externally.
|
| CVE-2026-58043 |
|
Vulnerability in nodejs (CVE-2026-58043)
vulnerability in nodejs (CVE-2026-58043). Confidential information can be exposed externally.
|
| CVE-2026-56847 |
|
Vulnerability in nodejs (CVE-2026-56847)
vulnerability in nodejs (CVE-2026-56847). Confidential information can be exposed externally.
|
| CVE-2026-56850 |
|
Authentication Bypass in nodejs (CVE-2026-56850)
authentication bypass in nodejs (CVE-2026-56850). Data can be tampered with by attackers.
|
| CVE-2026-59328 |
|
Cross-Site Scripting (XSS) in spring (CVE-2026-59328)
cross-site scripting in spring (CVE-2026-59328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14592 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14592)
cross-site scripting in wordpress (CVE-2026-14592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14207 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14207)
cross-site scripting in wordpress (CVE-2026-14207). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13344 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13344)
cross-site scripting in wordpress (CVE-2026-13344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13330 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13330)
cross-site scripting in wordpress (CVE-2026-13330). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14239 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14239)
cross-site scripting in wordpress (CVE-2026-14239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14602 |
|
Code Injection in wordpress (CVE-2026-14602)
code injection in wordpress (CVE-2026-14602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15240 |
|
Authentication Bypass in c (CVE-2026-15240)
authentication bypass in c (CVE-2026-15240). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1360 |
|
Unsafe Deserialization in wordpress (CVE-2026-1360)
vulnerability in wordpress (CVE-2026-1360). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``.
|
| CVE-2026-17975 |
|
Information Disclosure in c (CVE-2026-17975)
vulnerability in c (CVE-2026-17975). Confidential information can be exposed externally.
|
| CVE-2026-17980 |
|
Vulnerability in c (CVE-2026-17980)
vulnerability in c (CVE-2026-17980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17865 |
|
Vulnerability in c (CVE-2026-17865)
vulnerability in c (CVE-2026-17865). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17860 |
|
Vulnerability in c (CVE-2026-17860)
vulnerability in c (CVE-2026-17860). Risk of unauthorized operations or information disclosure.
|