Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2018-25405 |
|
SQL Injection in sqli (CVE-2018-25405)
SQL injection in sqli (CVE-2018-25405). Confidential information can be exposed externally.
|
| CVE-2026-10110 |
|
Vulnerability in sqli (CVE-2026-10110)
vulnerability in sqli (CVE-2026-10110). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47231 |
|
Vulnerability in admidio/admidio (CVE-2026-47231)
vulnerability in admidio/admidio (CVE-2026-47231). Confidential information can be exposed externally. Exploitable via `GET /modules/documents-files.php`. Mitigation: upgrade to `5.0.10` or later.
|
| CVE-2026-48557 |
|
Spatie Laravel Media Library contains a file upload restriction bypass
Spatie Laravel Media Library contains a file upload restriction bypass
|
| CVE-2026-46527 |
|
Vulnerability in c (CVE-2026-46527)
vulnerability in c (CVE-2026-46527). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.44.0` or later.
|
| CVE-2026-48555 |
|
SSRF (Server-Side Request Forgery) in spatie/laravel-medialibrary (CVE-2026-48555)
SSRF in spatie/laravel-medialibrary (CVE-2026-48555). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `11.23.0` or later.
|
| CVE-2026-47123 |
|
Vulnerability in laravel (CVE-2026-47123)
vulnerability in laravel (CVE-2026-47123). Data can be tampered with by attackers. Mitigation: upgrade to `1.8.220` or later.
|
| CVE-2026-46702 |
|
Vulnerability in russh (CVE-2026-46702)
vulnerability in russh (CVE-2026-46702). Risk of unauthorized operations or information disclosure. Exploitable via ``russh``. Mitigation: upgrade to `0.61.1` or later.
|
| CVE-2026-47139 |
|
Vulnerability in vm2 (CVE-2026-47139)
vulnerability in vm2 (CVE-2026-47139). Confidential information can be exposed externally. Exploitable via ``NodeVM``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47209 |
|
Vulnerability in vm2 (CVE-2026-47209)
vulnerability in vm2 (CVE-2026-47209). Data can be tampered with by attackers. Exploitable via ``BaseHandler.set``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-47135 |
|
Vulnerability in vm2 (CVE-2026-47135)
vulnerability in vm2 (CVE-2026-47135). Confidential information can be exposed externally. Exploitable via ``Symbol.for``. Mitigation: upgrade to `3.11.4` or later.
|
| CVE-2026-39276 |
|
Path Traversal in path-traversal (CVE-2026-39276)
path traversal in path-traversal (CVE-2026-39276). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25404 |
|
SQL Injection in sqli (CVE-2018-25404)
SQL injection in sqli (CVE-2018-25404). Confidential information can be exposed externally.
|
| CVE-2018-25403 |
|
SQL Injection in sqli (CVE-2018-25403)
SQL injection in sqli (CVE-2018-25403). Confidential information can be exposed externally.
|
| CVE-2018-25402 |
|
SQL Injection in sqli (CVE-2018-25402)
SQL injection in sqli (CVE-2018-25402). Confidential information can be exposed externally.
|
| CVE-2018-25401 |
|
SQL Injection in sqli (CVE-2018-25401)
SQL injection in sqli (CVE-2018-25401). Confidential information can be exposed externally.
|
| CVE-2018-25400 |
|
SQL Injection in sqli (CVE-2018-25400)
SQL injection in sqli (CVE-2018-25400). Confidential information can be exposed externally.
|
| CVE-2018-25399 |
|
SQL Injection in sqli (CVE-2018-25399)
SQL injection in sqli (CVE-2018-25399). Confidential information can be exposed externally.
|
| CVE-2018-25398 |
|
SQL Injection in sqli (CVE-2018-25398)
SQL injection in sqli (CVE-2018-25398). Confidential information can be exposed externally.
|
| CVE-2018-25389 |
|
SQL Injection in sqli (CVE-2018-25389)
SQL injection in sqli (CVE-2018-25389). Confidential information can be exposed externally.
|
| CVE-2018-25390 |
|
SQL Injection in sqli (CVE-2018-25390)
SQL injection in sqli (CVE-2018-25390). Confidential information can be exposed externally.
|
| CVE-2018-25395 |
|
SQL Injection in sqli (CVE-2018-25395)
SQL injection in sqli (CVE-2018-25395). Confidential information can be exposed externally.
|
| CVE-2018-25394 |
|
SQL Injection in sqli (CVE-2018-25394)
SQL injection in sqli (CVE-2018-25394). Confidential information can be exposed externally.
|
| CVE-2018-25392 |
|
SQL Injection in sqli (CVE-2018-25392)
SQL injection in sqli (CVE-2018-25392). Confidential information can be exposed externally.
|
| CVE-2018-25391 |
|
Vulnerability in CVE-2018-25391 (CVE-2018-25391)
vulnerability in CVE-2018-25391 (CVE-2018-25391). Data can be tampered with by attackers.
|
| CVE-2018-25385 |
|
SQL Injection in sqli (CVE-2018-25385)
SQL injection in sqli (CVE-2018-25385). Confidential information can be exposed externally.
|
| CVE-2018-25382 |
|
SQL Injection in sqli (CVE-2018-25382)
SQL injection in sqli (CVE-2018-25382). Confidential information can be exposed externally.
|
| CVE-2018-25386 |
|
SQL Injection in sqli (CVE-2018-25386)
SQL injection in sqli (CVE-2018-25386). Confidential information can be exposed externally.
|
| CVE-2018-25388 |
|
Unrestricted File Upload in CVE-2018-25388 (CVE-2018-25388)
vulnerability in CVE-2018-25388 (CVE-2018-25388). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44495 |
|
Code Injection in axios (CVE-2026-44495)
code injection in axios (CVE-2026-44495). Confidential information can be exposed externally. Exploitable via ``Object.prototype.transformResponse``. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-44494 |
|
Vulnerability in axios (CVE-2026-44494)
vulnerability in axios (CVE-2026-44494). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-44492 |
|
SSRF (Server-Side Request Forgery) in axios (CVE-2026-44492)
SSRF in axios (CVE-2026-44492). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-45615 |
|
Vulnerability in c (CVE-2026-45615)
vulnerability in c (CVE-2026-45615). Risk of unauthorized operations or information disclosure. Exploitable via ``INTEGER_decode_oer``.
|
| CVE-2026-45555 |
|
Code Injection in csharp (CVE-2026-45555)
code injection in csharp (CVE-2026-45555). Successful exploitation can lead to full system takeover. Exploitable via ``get_diagnostics``. Mitigation: upgrade to `1.17.0` or later.
|
| CVE-2026-44698 |
|
Code Injection in CVE-2026-44698 (CVE-2026-44698)
code injection in CVE-2026-44698 (CVE-2026-44698). Successful exploitation can lead to full system takeover. Exploitable via ``window.externalApp``. Mitigation: upgrade to `2026.4.1` or later.
|
| CVE-2026-44239 |
|
Vulnerability in path-traversal (CVE-2026-44239)
vulnerability in path-traversal (CVE-2026-44239). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `16.0.22` or later.
|
| CVE-2026-44237 |
|
Vulnerability in sangoma (CVE-2026-44237)
vulnerability in sangoma (CVE-2026-44237). Confidential information can be exposed externally. Mitigation: upgrade to `17.0.8` or later.
|
| CVE-2026-48527 |
|
Cross-Site Scripting (XSS) in @haxtheweb/haxcms-nodejs (CVE-2026-48527)
cross-site scripting in @haxtheweb/haxcms-nodejs (CVE-2026-48527). Confidential information can be exposed externally. Exploitable via `POST /system/api/saveNode`. Mitigation: upgrade to `26.0.1` or later.
|
| CVE-2026-52834 |
|
Vulnerability in jxl-grid (CVE-2026-52834)
vulnerability in jxl-grid (CVE-2026-52834). Risk of unauthorized operations or information disclosure. Exploitable via ``usize``. Mitigation: upgrade to `0.6.2` or later.
|
| CVE-2025-11262 |
|
The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
|
| CVE-2025-11993 |
|
Unsafe Deserialization in wordpress (CVE-2025-11993)
vulnerability in wordpress (CVE-2025-11993). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9998 |
|
Vulnerability in c (CVE-2026-9998)
vulnerability in c (CVE-2026-9998). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42305 |
|
Path Traversal in dulwich (CVE-2026-42305)
path traversal in dulwich (CVE-2026-42305). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.2.5` or later.
|
| CVE-2026-46823 |
|
Authorization Flaw in c (CVE-2026-46823)
vulnerability in c (CVE-2026-46823). Confidential information can be exposed externally.
|
| CVE-2026-46834 |
|
Vulnerability in c (CVE-2026-46834)
vulnerability in c (CVE-2026-46834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46828 |
|
Vulnerability in c (CVE-2026-46828)
vulnerability in c (CVE-2026-46828). Confidential information can be exposed externally.
|
| CVE-2026-46829 |
|
Vulnerability in c (CVE-2026-46829)
vulnerability in c (CVE-2026-46829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46827 |
|
Privilege Escalation in c (CVE-2026-46827)
vulnerability in c (CVE-2026-46827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46837 |
|
Privilege Escalation in c (CVE-2026-46837)
vulnerability in c (CVE-2026-46837). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46826 |
|
Vulnerability in c (CVE-2026-46826)
vulnerability in c (CVE-2026-46826). Successful exploitation can lead to full system takeover.
|