Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55585 |
|
Code Injection in qwed (CVE-2026-55585)
code injection in qwed (CVE-2026-55585). Successful exploitation can lead to full system takeover. Exploitable via `POST /verify/math`. Mitigation: upgrade to `5.1.2` or later.
|
| CVE-2026-55553 |
|
Information Disclosure in urllib (CVE-2026-55553)
vulnerability in urllib (CVE-2026-55553). Confidential information can be exposed externally. Exploitable via `Cookie header`. Mitigation: upgrade to `2.44.1` or later.
|
| CVE-2026-55571 |
|
Vulnerability in djust (CVE-2026-55571)
vulnerability in djust (CVE-2026-55571). Data can be tampered with by attackers. Exploitable via ``LiveViewConsumer``. Mitigation: upgrade to `1.0.4` or later.
|
| CVE-2026-55581 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55581)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55581). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-55582 |
|
OS Command Injection in github.com/sonirico/mcp-shell (CVE-2026-55582)
OS command injection in github.com/sonirico/mcp-shell (CVE-2026-55582). Successful exploitation can lead to full system takeover. Exploitable via ``security.yaml``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-15310 |
|
Vulnerability in CVE-2026-15310 (CVE-2026-15310)
vulnerability in CVE-2026-15310 (CVE-2026-15310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77998 |
|
Vulnerability in CVE-2026-77998 (CVE-2026-77998)
vulnerability in CVE-2026-77998 (CVE-2026-77998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57863 |
|
Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55546 |
|
Code Injection in qwed-mcp (CVE-2026-55546)
code injection in qwed-mcp (CVE-2026-55546). Successful exploitation can lead to full system takeover. Exploitable via ``global_dict``. Mitigation: upgrade to `0.2.1` or later.
|
| CVE-2026-79670 |
|
Unrestricted File Upload in CVE-2026-79670 (CVE-2026-79670)
vulnerability in CVE-2026-79670 (CVE-2026-79670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79663 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-79663)
cross-site scripting in c (CVE-2026-79663). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79658 |
|
Vulnerability in dos (CVE-2026-79658)
vulnerability in dos (CVE-2026-79658). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79660 |
|
Information Disclosure in c (CVE-2026-79660)
vulnerability in c (CVE-2026-79660). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18547 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18547)
cross-site scripting in wordpress (CVE-2026-18547). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78572 |
|
Unsafe Deserialization in wordpress (CVE-2026-78572)
vulnerability in wordpress (CVE-2026-78572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16231 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-16231)
cross-site scripting in express (CVE-2026-16231). Confidential information can be exposed externally. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2026-78562 |
|
Vulnerability in wordpress (CVE-2026-78562)
vulnerability in wordpress (CVE-2026-78562). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78566 |
|
Vulnerability in wordpress (CVE-2026-78566)
vulnerability in wordpress (CVE-2026-78566). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77138 |
|
Unsafe Deserialization in CVE-2026-77138 (CVE-2026-77138)
vulnerability in CVE-2026-77138 (CVE-2026-77138). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56095 |
|
Unsafe Deserialization in CVE-2026-56095 (CVE-2026-56095)
vulnerability in CVE-2026-56095 (CVE-2026-56095). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18100 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18100)
cross-site scripting in wordpress (CVE-2026-18100). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16601 |
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
| CVE-2026-18323 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-18328 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-78656 |
|
Vulnerability in sqli (CVE-2026-78656)
vulnerability in sqli (CVE-2026-78656). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78637 |
|
Vulnerability in CVE-2026-78637 (CVE-2026-78637)
vulnerability in CVE-2026-78637 (CVE-2026-78637). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78638 |
|
Path Traversal in path-traversal (CVE-2026-78638)
path traversal in path-traversal (CVE-2026-78638). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78478 |
|
Vulnerability in wordpress (CVE-2026-78478)
vulnerability in wordpress (CVE-2026-78478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13215 |
|
Out-of-Bounds Write in c (CVE-2026-13215)
out-of-bounds write in c (CVE-2026-13215). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13214 |
|
Out-of-Bounds Write in c (CVE-2026-13214)
out-of-bounds write in c (CVE-2026-13214). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75930 |
|
Vulnerability in wordpress (CVE-2026-75930)
vulnerability in wordpress (CVE-2026-75930). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14280 |
|
Vulnerability in wordpress (CVE-2026-14280)
vulnerability in wordpress (CVE-2026-14280). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78683 |
|
Unsafe Deserialization in deserialization (CVE-2026-78683)
vulnerability in deserialization (CVE-2026-78683). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-78677 |
|
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
|
| CVE-2026-78680 |
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
| CVE-2026-78681 |
|
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
|
| CVE-2026-75574 |
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
| CVE-2026-78675 |
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
| CVE-2026-72699 |
|
Vulnerability in CVE-2026-72699 (CVE-2026-72699)
vulnerability in CVE-2026-72699 (CVE-2026-72699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72700 |
|
Vulnerability in CVE-2026-72700 (CVE-2026-72700)
vulnerability in CVE-2026-72700 (CVE-2026-72700). Confidential information can be exposed externally.
|
| CVE-2026-56704 |
|
Cross-Site Scripting (XSS) in CVE-2026-56704 (CVE-2026-56704)
cross-site scripting in CVE-2026-56704 (CVE-2026-56704). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56703 |
|
Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56705 |
|
Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56706 |
|
Vulnerability in csrf (CVE-2026-56706)
vulnerability in csrf (CVE-2026-56706). Data can be tampered with by attackers.
|
| CVE-2026-56707 |
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
| CVE-2026-56702 |
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
| CVE-2026-16434 |
|
Vulnerability in CVE-2026-16434 (CVE-2026-16434)
vulnerability in CVE-2026-16434 (CVE-2026-16434). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5.1` or later.
|
| CVE-2026-34967 |
|
Vulnerability in path-traversal (CVE-2026-34967)
vulnerability in path-traversal (CVE-2026-34967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34968 |
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
| CVE-2026-55371 |
|
Vulnerability in c (CVE-2026-55371)
vulnerability in c (CVE-2026-55371). Risk of unauthorized operations or information disclosure.
|