Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82483 |
|
Cross-Site Scripting (XSS) in CVE-2026-82483 (CVE-2026-82483)
cross-site scripting in CVE-2026-82483 (CVE-2026-82483). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82482 |
|
Cross-Site Scripting (XSS) in CVE-2026-82482 (CVE-2026-82482)
cross-site scripting in CVE-2026-82482 (CVE-2026-82482). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-77939 |
|
Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
|
| CVE-2026-55634 |
|
SQL Injection in pimcore/pimcore (CVE-2026-55634)
SQL injection in pimcore/pimcore (CVE-2026-55634). Successful exploitation can lead to full system takeover. Exploitable via ``objects``. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-55565 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55565)
code injection in org.yamcs:yamcs-core (CVE-2026-55565). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55559 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55559)
code injection in org.yamcs:yamcs-core (CVE-2026-55559). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/instances`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55511 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55511)
code injection in org.yamcs:yamcs-core (CVE-2026-55511). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-82244 |
|
Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53579 |
|
Cross-Site Scripting (XSS) in CVE-2026-53579 (CVE-2026-53579)
cross-site scripting in CVE-2026-53579 (CVE-2026-53579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53578 |
|
Cross-Site Scripting (XSS) in CVE-2026-53578 (CVE-2026-53578)
cross-site scripting in CVE-2026-53578 (CVE-2026-53578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48996 |
|
Cross-Site Scripting (XSS) in CVE-2026-48996 (CVE-2026-48996)
cross-site scripting in CVE-2026-48996 (CVE-2026-48996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47727 |
|
Code Injection in CVE-2026-47727 (CVE-2026-47727)
code injection in CVE-2026-47727 (CVE-2026-47727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81096 |
|
Code Injection in CVE-2026-81096 (CVE-2026-81096)
code injection in CVE-2026-81096 (CVE-2026-81096). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81662 |
|
Vulnerability in CVE-2026-81662 (CVE-2026-81662)
vulnerability in CVE-2026-81662 (CVE-2026-81662). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58474 |
|
Code Injection in CVE-2026-58474 (CVE-2026-58474)
code injection in CVE-2026-58474 (CVE-2026-58474). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57170 |
|
Code Injection in CVE-2026-57170 (CVE-2026-57170)
code injection in CVE-2026-57170 (CVE-2026-57170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54757 |
|
Code Injection in compliance-trestle (CVE-2026-54757)
code injection in compliance-trestle (CVE-2026-54757). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxedEnvironment``. Mitigation: upgrade to `4.1.0` or later.
|
| CVE-2026-79793 |
|
Cross-Site Scripting (XSS) in CVE-2026-79793 (CVE-2026-79793)
cross-site scripting in CVE-2026-79793 (CVE-2026-79793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55585 |
|
Code Injection in qwed (CVE-2026-55585)
code injection in qwed (CVE-2026-55585). Successful exploitation can lead to full system takeover. Exploitable via `POST /verify/math`. Mitigation: upgrade to `5.1.2` or later.
|
| CVE-2026-55546 |
|
Code Injection in qwed-mcp (CVE-2026-55546)
code injection in qwed-mcp (CVE-2026-55546). Successful exploitation can lead to full system takeover. Exploitable via ``global_dict``. Mitigation: upgrade to `0.2.1` or later.
|
| CVE-2026-56703 |
|
Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52490 |
|
Code Injection in c (CVE-2026-52490)
code injection in c (CVE-2026-52490). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-76836 |
|
Code Injection in CVE-2026-76836 (CVE-2026-76836)
code injection in CVE-2026-76836 (CVE-2026-76836). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/station/{station_id}/profile/edit`.
|
| CVE-2026-76841 |
|
Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78179 |
|
Code Injection in CVE-2026-78179 (CVE-2026-78179)
code injection in CVE-2026-78179 (CVE-2026-78179). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78178 |
|
Code Injection in CVE-2026-78178 (CVE-2026-78178)
code injection in CVE-2026-78178 (CVE-2026-78178). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78166 |
|
Vulnerability in CVE-2026-78166 (CVE-2026-78166)
vulnerability in CVE-2026-78166 (CVE-2026-78166). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78060 |
|
Cross-Site Scripting (XSS) in CVE-2026-78060 (CVE-2026-78060)
cross-site scripting in CVE-2026-78060 (CVE-2026-78060). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78059 |
|
Cross-Site Scripting (XSS) in CVE-2026-78059 (CVE-2026-78059)
cross-site scripting in CVE-2026-78059 (CVE-2026-78059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78055 |
|
Cross-Site Scripting (XSS) in CVE-2026-78055 (CVE-2026-78055)
cross-site scripting in CVE-2026-78055 (CVE-2026-78055). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78054 |
|
Cross-Site Scripting (XSS) in CVE-2026-78054 (CVE-2026-78054)
cross-site scripting in CVE-2026-78054 (CVE-2026-78054). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76604 |
|
Code Injection in CVE-2026-76604 (CVE-2026-76604)
code injection in CVE-2026-76604 (CVE-2026-76604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77414 |
|
Code Injection in jsonata (CVE-2026-77414)
code injection in jsonata (CVE-2026-77414). Risk of unauthorized operations or information disclosure. Exploitable via ``hasOwnProperty``. Mitigation: upgrade to `1.8.8` or later.
|
| CVE-2026-68508 |
|
Code Injection in hydra-core (CVE-2026-68508)
code injection in hydra-core (CVE-2026-68508). Successful exploitation can lead to full system takeover. Exploitable via ``_target_``. Mitigation: upgrade to `1.3.4` or later.
|
| CVE-2026-77413 |
|
Code Injection in jsonata (CVE-2026-77413)
code injection in jsonata (CVE-2026-77413). Risk of unauthorized operations or information disclosure. Exploitable via ``hasOwnProperty``. Mitigation: upgrade to `2.2.0` or later.
|
| CVE-2026-59989 |
|
Code Injection in phalcon/cphalcon (CVE-2026-59989)
code injection in phalcon/cphalcon (CVE-2026-59989). Risk of unauthorized operations or information disclosure. Exploitable via ``join``. Mitigation: upgrade to `5.16.0` or later.
|
| CVE-2026-62675 |
|
Code Injection in CVE-2026-62675 (CVE-2026-62675)
code injection in CVE-2026-62675 (CVE-2026-62675). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/sessions`.
|
| CVE-2026-77647 |
|
Code Injection in CVE-2026-77647 (CVE-2026-77647)
code injection in CVE-2026-77647 (CVE-2026-77647). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18286 |
|
Code Injection in CVE-2026-18286 (CVE-2026-18286)
code injection in CVE-2026-18286 (CVE-2026-18286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18287 |
|
Code Injection in CVE-2026-18287 (CVE-2026-18287)
code injection in CVE-2026-18287 (CVE-2026-18287). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76635 |
|
SQL Injection in sqli (CVE-2026-76635)
SQL injection in sqli (CVE-2026-76635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77077 |
|
Code Injection in CVE-2026-77077 (CVE-2026-77077)
code injection in CVE-2026-77077 (CVE-2026-77077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77075 |
|
Code Injection in CVE-2026-77075 (CVE-2026-77075)
code injection in CVE-2026-77075 (CVE-2026-77075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13405 |
|
Code Injection in wordpress (CVE-2026-13405)
code injection in wordpress (CVE-2026-13405). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76760 |
|
Vulnerability in c (CVE-2026-76760)
vulnerability in c (CVE-2026-76760). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72717 |
|
Code Injection in CVE-2026-72717 (CVE-2026-72717)
code injection in CVE-2026-72717 (CVE-2026-72717). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71871 |
|
Code Injection in CVE-2026-71871 (CVE-2026-71871)
code injection in CVE-2026-71871 (CVE-2026-71871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71869 |
|
Code Injection in CVE-2026-71869 (CVE-2026-71869)
code injection in CVE-2026-71869 (CVE-2026-71869). Risk of unauthorized operations or information disclosure.
|