Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-46319 |
|
Use-After-Free in csharp (CVE-2026-46319)
vulnerability in csharp (CVE-2026-46319). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20250 |
|
Path Traversal in wordpress (CVE-2017-20250)
path traversal in wordpress (CVE-2017-20250). Confidential information can be exposed externally.
|
| CVE-2017-20248 |
|
Path Traversal in path-traversal (CVE-2017-20248)
path traversal in path-traversal (CVE-2017-20248). Confidential information can be exposed externally.
|
| CVE-2017-20246 |
|
SQL Injection in wordpress (CVE-2017-20246)
SQL injection in wordpress (CVE-2017-20246). Confidential information can be exposed externally.
|
| CVE-2017-20245 |
|
SQL Injection in wordpress (CVE-2017-20245)
SQL injection in wordpress (CVE-2017-20245). Confidential information can be exposed externally.
|
| CVE-2017-20244 |
|
SQL Injection in wordpress (CVE-2017-20244)
SQL injection in wordpress (CVE-2017-20244). Confidential information can be exposed externally.
|
| CVE-2016-20065 |
|
SQL Injection in wordpress (CVE-2016-20065)
SQL injection in wordpress (CVE-2016-20065). Confidential information can be exposed externally.
|
| CVE-2016-20062 |
|
SQL Injection in wordpress (CVE-2016-20062)
SQL injection in wordpress (CVE-2016-20062). Confidential information can be exposed externally.
|
| CVE-2026-41031 |
|
Cross-Site Scripting (XSS) in CVE-2026-41031 (CVE-2026-41031)
cross-site scripting in CVE-2026-41031 (CVE-2026-41031). Confidential information can be exposed externally.
|
| CVE-2026-8365 |
|
Unsafe Deserialization in wordpress (CVE-2026-8365)
vulnerability in wordpress (CVE-2026-8365). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5068 |
|
Out-of-Bounds Write in c (CVE-2026-5068)
out-of-bounds write in c (CVE-2026-5068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9662 |
|
Vulnerability in wordpress (CVE-2026-9662)
vulnerability in wordpress (CVE-2026-9662). Successful exploitation can lead to full system takeover. Exploitable via ``tpf``.
|
| CVE-2026-41845 |
|
Cross-Site Scripting (XSS) in org.springframework:spring-webmvc (CVE-2026-41845)
cross-site scripting in org.springframework:spring-webmvc (CVE-2026-41845). Confidential information can be exposed externally.
|
| CVE-2026-11618 |
|
Authentication Bypass in CVE-2026-11618 (CVE-2026-11618)
authentication bypass in CVE-2026-11618 (CVE-2026-11618). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11693 |
|
Vulnerability in c (CVE-2026-11693)
vulnerability in c (CVE-2026-11693). Confidential information can be exposed externally.
|
| CVE-2026-47737 |
|
Vulnerability in puma (CVE-2026-47737)
vulnerability in puma (CVE-2026-47737). Data can be tampered with by attackers. Exploitable via ``REMOTE_ADDR``. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-47736 |
|
Vulnerability in puma (CVE-2026-47736)
vulnerability in puma (CVE-2026-47736). Risk of unauthorized operations or information disclosure. Exploitable via ``set_remote_address``. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-47719 |
|
SSRF (Server-Side Request Forgery) in fuxa-server (CVE-2026-47719)
SSRF in fuxa-server (CVE-2026-47719). Confidential information can be exposed externally. Exploitable via ``property.address``.
|
| CVE-2026-40519 |
|
OS Command Injection in nginx (CVE-2026-40519)
OS command injection in nginx (CVE-2026-40519). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11582 |
|
Vulnerability in sqli (CVE-2026-11582)
vulnerability in sqli (CVE-2026-11582). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44892 |
|
Vulnerability in io.netty:netty-codec-http3 (CVE-2026-44892)
vulnerability in io.netty:netty-codec-http3 (CVE-2026-44892). Risk of unauthorized operations or information disclosure. Exploitable via ``Http3ConnectionHandler``. Mitigation: upgrade to `4.2.15.Final` or later.
|
| CVE-2026-46307 |
|
Out-of-Bounds Read in c (CVE-2026-46307)
vulnerability in c (CVE-2026-46307). Confidential information can be exposed externally.
|
| CVE-2026-46303 |
|
Vulnerability in c (CVE-2026-46303)
vulnerability in c (CVE-2026-46303). Confidential information can be exposed externally.
|
| CVE-2026-25856 |
|
Code Injection in c (CVE-2026-25856)
code injection in c (CVE-2026-25856). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11531 |
|
Vulnerability in sqli (CVE-2026-11531)
vulnerability in sqli (CVE-2026-11531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49233 |
|
Path Traversal in routinator (CVE-2026-49233)
path traversal in routinator (CVE-2026-49233). Confidential information can be exposed externally. Mitigation: upgrade to `0.15.2` or later.
|
| CVE-2026-11501 |
|
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System...
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System...
|
| CVE-2026-11490 |
|
Vulnerability in sqli (CVE-2026-11490)
vulnerability in sqli (CVE-2026-11490). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11488 |
|
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This...
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This...
|
| CVE-2026-11489 |
|
A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects...
A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects...
|
| CVE-2026-11485 |
|
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1...
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1...
|
| CVE-2026-11483 |
|
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This...
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This...
|
| CVE-2026-11486 |
|
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by...
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by...
|
| CVE-2026-11484 |
|
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This...
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This...
|
| CVE-2026-11482 |
|
Vulnerability in sqli (CVE-2026-11482)
vulnerability in sqli (CVE-2026-11482). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-54350 |
|
Vulnerability in c (CVE-2023-54350)
vulnerability in c (CVE-2023-54350). Confidential information can be exposed externally.
|
| CVE-2023-54351 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2023-54351)
cross-site scripting in wordpress (CVE-2023-54351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11474 |
|
Vulnerability in CVE-2026-11474 (CVE-2026-11474)
vulnerability in CVE-2026-11474 (CVE-2026-11474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11472 |
|
Vulnerability in sqli (CVE-2026-11472)
vulnerability in sqli (CVE-2026-11472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11471 |
|
Vulnerability in sqli (CVE-2026-11471)
vulnerability in sqli (CVE-2026-11471). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11462 |
|
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This...
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This...
|
| CVE-2026-11463 |
|
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of...
|
| CVE-2026-11456 |
|
Vulnerability in sqli (CVE-2026-11456)
vulnerability in sqli (CVE-2026-11456). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11457 |
|
Vulnerability in c (CVE-2026-11457)
vulnerability in c (CVE-2026-11457). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8438 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8438)
cross-site scripting in wordpress (CVE-2026-8438). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9290 |
|
Path Traversal in wordpress (CVE-2026-9290)
path traversal in wordpress (CVE-2026-9290). Confidential information can be exposed externally.
|
| CVE-2026-7654 |
|
Unsafe Deserialization in wordpress (CVE-2026-7654)
vulnerability in wordpress (CVE-2026-7654). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``.
|
| CVE-2026-11422 |
|
Vulnerability in CVE-2026-11422 (CVE-2026-11422)
vulnerability in CVE-2026-11422 (CVE-2026-11422). Confidential information can be exposed externally.
|
| CVE-2026-11400 |
|
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
|
| CVE-2026-46493 |
|
Vulnerability in CVE-2026-46493 (CVE-2026-46493)
vulnerability in CVE-2026-46493 (CVE-2026-46493). Confidential information can be exposed externally. Exploitable via ``uniqid``.
|