Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9273 |
|
Vulnerability in wordpress (CVE-2026-9273)
vulnerability in wordpress (CVE-2026-9273). Confidential information can be exposed externally.
|
| CVE-2026-62517 |
|
Vulnerability in c (CVE-2026-62517)
vulnerability in c (CVE-2026-62517). Confidential information can be exposed externally.
|
| CVE-2026-62486 |
|
Vulnerability in c (CVE-2026-62486)
vulnerability in c (CVE-2026-62486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61181 |
|
Vulnerability in c (CVE-2026-61181)
vulnerability in c (CVE-2026-61181). Confidential information can be exposed externally.
|
| CVE-2026-61143 |
|
Vulnerability in c (CVE-2026-61143)
vulnerability in c (CVE-2026-61143). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61049 |
|
Vulnerability in c (CVE-2026-61049)
vulnerability in c (CVE-2026-61049). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60658 |
|
Cross-Site Request Forgery (CSRF) in c (CVE-2026-60658)
vulnerability in c (CVE-2026-60658). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60650 |
|
Vulnerability in c (CVE-2026-60650)
vulnerability in c (CVE-2026-60650). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60648 |
|
Vulnerability in c (CVE-2026-60648)
vulnerability in c (CVE-2026-60648). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60646 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-60646)
cross-site scripting in c (CVE-2026-60646). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53595 |
|
Vulnerability in laravel (CVE-2026-53595)
vulnerability in laravel (CVE-2026-53595). Confidential information can be exposed externally. Exploitable via `POST /user-setup/{hash}/{invite_sent_at}`.
|
| CVE-2026-37106 |
|
Vulnerability in CVE-2026-37106 (CVE-2026-37106)
vulnerability in CVE-2026-37106 (CVE-2026-37106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12417 |
|
Vulnerability in wordpress (CVE-2026-12417)
vulnerability in wordpress (CVE-2026-12417). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_pravel_change_password``.
|
| CVE-2026-46894 |
|
Cross-Site Request Forgery (CSRF) in c (CVE-2026-46894)
vulnerability in c (CVE-2026-46894). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12066 |
|
Vulnerability in CVE-2026-12066 (CVE-2026-12066)
vulnerability in CVE-2026-12066 (CVE-2026-12066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10169 |
|
Vulnerability in CVE-2026-10169 (CVE-2026-10169)
vulnerability in CVE-2026-10169 (CVE-2026-10169). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9609 |
|
Vulnerability in CVE-2026-9609 (CVE-2026-9609)
vulnerability in CVE-2026-9609 (CVE-2026-9609). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35676 |
|
Vulnerability in thorsten/phpmyfaq (CVE-2026-35676)
vulnerability in thorsten/phpmyfaq (CVE-2026-35676). Data can be tampered with by attackers. Exploitable via `PUT /api/index.php/user/password/update`. Mitigation: upgrade to `4.1.3` or later.
|
| CVE-2026-45013 |
|
Vulnerability in apostrophe (CVE-2026-45013)
vulnerability in apostrophe (CVE-2026-45013). Confidential information can be exposed externally. Exploitable via `POST /api/v1/login/reset-request`.
|
| CVE-2018-16988 |
|
Vulnerability in buffalo (CVE-2018-16988)
vulnerability in buffalo (CVE-2018-16988). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8295 |
|
Vulnerability in wordpress (CVE-2017-8295)
vulnerability in wordpress (CVE-2017-8295). Data can be tampered with by attackers. Exploitable via `Host header`.
|
| CVE-2017-7615 |
|
Vulnerability in mantisbt (CVE-2017-7615)
vulnerability in mantisbt (CVE-2017-7615). Successful exploitation can lead to full system takeover.
|