Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Tag: rce Clear
ID Title
CVE-2026-82450 Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
CVE-2026-82278 Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
CVE-2026-77939 Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
CVE-2026-82244 Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
CVE-2026-14558 Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
CVE-2026-18983 Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
CVE-2026-16759 Vulnerability in wordpress (CVE-2026-16759)
vulnerability in wordpress (CVE-2026-16759). Risk of unauthorized operations or information disclosure.
CVE-2026-38821 Vulnerability in c (CVE-2026-38821)
vulnerability in c (CVE-2026-38821). Confidential information can be exposed externally.
CVE-2026-53579 Cross-Site Scripting (XSS) in CVE-2026-53579 (CVE-2026-53579)
cross-site scripting in CVE-2026-53579 (CVE-2026-53579). Risk of unauthorized operations or information disclosure.
CVE-2026-53578 Cross-Site Scripting (XSS) in CVE-2026-53578 (CVE-2026-53578)
cross-site scripting in CVE-2026-53578 (CVE-2026-53578). Risk of unauthorized operations or information disclosure.
CVE-2026-48996 Cross-Site Scripting (XSS) in CVE-2026-48996 (CVE-2026-48996)
cross-site scripting in CVE-2026-48996 (CVE-2026-48996). Risk of unauthorized operations or information disclosure.
CVE-2026-47727 Code Injection in CVE-2026-47727 (CVE-2026-47727)
code injection in CVE-2026-47727 (CVE-2026-47727). Risk of unauthorized operations or information disclosure.
CVE-2026-77991 Unrestricted File Upload in csharp (CVE-2026-77991)
vulnerability in csharp (CVE-2026-77991). Risk of unauthorized operations or information disclosure.
CVE-2026-54569 Vulnerability in senaite.core (CVE-2026-54569)
vulnerability in senaite.core (CVE-2026-54569). Successful exploitation can lead to full system takeover. Exploitable via `GET /senaite/bika_setup/`.
CVE-2026-18080 Unrestricted File Upload in wordpress (CVE-2026-18080)
vulnerability in wordpress (CVE-2026-18080). Successful exploitation can lead to full system takeover.
CVE-2026-18431 Vulnerability in wordpress (CVE-2026-18431)
vulnerability in wordpress (CVE-2026-18431). Successful exploitation can lead to full system takeover.
CVE-2021-23758 KEV Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CVE-2026-54757 Code Injection in compliance-trestle (CVE-2026-54757)
code injection in compliance-trestle (CVE-2026-54757). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxedEnvironment``. Mitigation: upgrade to `4.1.0` or later.
CVE-2026-19912 Vulnerability in deserialization (CVE-2026-19912)
vulnerability in deserialization (CVE-2026-19912). Risk of unauthorized operations or information disclosure.
CVE-2026-79774 Vulnerability in CVE-2026-79774 (CVE-2026-79774)
vulnerability in CVE-2026-79774 (CVE-2026-79774). Successful exploitation can lead to full system takeover.
CVE-2026-57863 Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
CVE-2026-77138 Unsafe Deserialization in CVE-2026-77138 (CVE-2026-77138)
vulnerability in CVE-2026-77138 (CVE-2026-77138). Risk of unauthorized operations or information disclosure.
CVE-2026-16601 The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
CVE-2026-13214 Out-of-Bounds Write in c (CVE-2026-13214)
out-of-bounds write in c (CVE-2026-13214). Successful exploitation can lead to full system takeover.
CVE-2026-78680 NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
CVE-2026-75574 The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
CVE-2026-56703 Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
CVE-2026-56705 Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
CVE-2026-56702 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
CVE-2026-40877 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
CVE-2026-78416 Vulnerability in CVE-2026-78416 (CVE-2026-78416)
vulnerability in CVE-2026-78416 (CVE-2026-78416). Risk of unauthorized operations or information disclosure.
CVE-2026-76841 Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
CVE-2026-78209 exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
CVE-2026-78157 A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the...
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the...
CVE-2026-78136 chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
CVE-2026-76604 Code Injection in CVE-2026-76604 (CVE-2026-76604)
code injection in CVE-2026-76604 (CVE-2026-76604). Risk of unauthorized operations or information disclosure.
CVE-2026-49849 Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
CVE-2026-39909 Use-After-Free in cpp (CVE-2026-39909)
vulnerability in cpp (CVE-2026-39909). Successful exploitation can lead to full system takeover.
CVE-2026-69242 Vulnerability in c (CVE-2026-69242)
vulnerability in c (CVE-2026-69242). Risk of unauthorized operations or information disclosure.
CVE-2026-18286 Code Injection in CVE-2026-18286 (CVE-2026-18286)
code injection in CVE-2026-18286 (CVE-2026-18286). Successful exploitation can lead to full system takeover.
CVE-2026-18287 Code Injection in CVE-2026-18287 (CVE-2026-18287)
code injection in CVE-2026-18287 (CVE-2026-18287). Successful exploitation can lead to full system takeover.
CVE-2026-15049 Unrestricted File Upload in wordpress (CVE-2026-15049)
vulnerability in wordpress (CVE-2026-15049). Successful exploitation can lead to full system takeover.
CVE-2026-49392 Vulnerability in cpp (CVE-2026-49392)
vulnerability in cpp (CVE-2026-49392). Risk of unauthorized operations or information disclosure.
CVE-2026-76224 Code Injection in CVE-2026-76224 (CVE-2026-76224)
code injection in CVE-2026-76224 (CVE-2026-76224). Successful exploitation can lead to full system takeover.
CVE-2026-19942 Path Traversal in wordpress (CVE-2026-19942)
path traversal in wordpress (CVE-2026-19942). Data can be tampered with by attackers.
CVE-2026-52608 Vulnerability in CVE-2026-52608 (CVE-2026-52608)
vulnerability in CVE-2026-52608 (CVE-2026-52608). Successful exploitation can lead to full system takeover.
CVE-2026-75858 Code Injection in CVE-2026-75858 (CVE-2026-75858)
code injection in CVE-2026-75858 (CVE-2026-75858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.64` or later.
CVE-2026-45117 Code Injection in CVE-2026-45117 (CVE-2026-45117)
code injection in CVE-2026-45117 (CVE-2026-45117). Successful exploitation can lead to full system takeover.
CVE-2026-75827 Code Injection in CVE-2026-75827 (CVE-2026-75827)
code injection in CVE-2026-75827 (CVE-2026-75827). Successful exploitation can lead to full system takeover.
CVE-2026-16099 Unsafe Deserialization in wordpress (CVE-2026-16099)
vulnerability in wordpress (CVE-2026-16099). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →