Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10899 |
|
Use-After-Free in c (CVE-2026-10899)
vulnerability in c (CVE-2026-10899). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10896 |
|
Use-After-Free in google (CVE-2026-10896)
vulnerability in google (CVE-2026-10896). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10895 |
|
Use-After-Free in google (CVE-2026-10895)
vulnerability in google (CVE-2026-10895). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10897 |
|
Out-of-Bounds Write in google (CVE-2026-10897)
out-of-bounds write in google (CVE-2026-10897). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10898 |
|
Vulnerability in google (CVE-2026-10898)
vulnerability in google (CVE-2026-10898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10902 |
|
Use-After-Free in google (CVE-2026-10902)
vulnerability in google (CVE-2026-10902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10887 |
|
Use-After-Free in google (CVE-2026-10887)
vulnerability in google (CVE-2026-10887). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10894 |
|
Use-After-Free in google (CVE-2026-10894)
vulnerability in google (CVE-2026-10894). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10892 |
|
Out-of-Bounds Write in google (CVE-2026-10892)
out-of-bounds write in google (CVE-2026-10892). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10891 |
|
Use-After-Free in google (CVE-2026-10891)
vulnerability in google (CVE-2026-10891). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10886 |
|
Use-After-Free in google (CVE-2026-10886)
vulnerability in google (CVE-2026-10886). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10888 |
|
Use-After-Free in google (CVE-2026-10888)
vulnerability in google (CVE-2026-10888). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10889 |
|
Out-of-Bounds Read in google (CVE-2026-10889)
vulnerability in google (CVE-2026-10889). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10890 |
|
Use-After-Free in google (CVE-2026-10890)
vulnerability in google (CVE-2026-10890). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10893 |
|
Use-After-Free in google (CVE-2026-10893)
vulnerability in google (CVE-2026-10893). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10874 |
|
Vulnerability in sqli (CVE-2026-10874)
vulnerability in sqli (CVE-2026-10874). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10885 |
|
Use-After-Free in google (CVE-2026-10885)
vulnerability in google (CVE-2026-10885). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10882 |
|
Use-After-Free in google (CVE-2026-10882)
vulnerability in google (CVE-2026-10882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10883 |
|
Out-of-Bounds Write in google (CVE-2026-10883)
out-of-bounds write in google (CVE-2026-10883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10884 |
|
Use-After-Free in google (CVE-2026-10884)
vulnerability in google (CVE-2026-10884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10881 |
|
Out-of-Bounds Read in Google chrome (CVE-2026-10881)
vulnerability in Google chrome (CVE-2026-10881). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48016 |
|
Vulnerability in shopware/platform (CVE-2026-48016)
vulnerability in shopware/platform (CVE-2026-48016). Risk of unauthorized operations or information disclosure. Exploitable via ``orderId``. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48014 |
|
Vulnerability in shopware/platform (CVE-2026-48014)
vulnerability in shopware/platform (CVE-2026-48014). Data can be tampered with by attackers. Exploitable via ``orderId``. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48010 |
|
Privilege Escalation in shopware/platform (CVE-2026-48010)
vulnerability in shopware/platform (CVE-2026-48010). Confidential information can be exposed externally. Exploitable via ``SYSTEM_SCOPE``. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48009 |
|
Information Disclosure in shopware/platform (CVE-2026-48009)
vulnerability in shopware/platform (CVE-2026-48009). Confidential information can be exposed externally. Exploitable via `POST /api/search/user-recovery`. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48008 |
|
Vulnerability in shopware/platform (CVE-2026-48008)
vulnerability in shopware/platform (CVE-2026-48008). Confidential information can be exposed externally. Exploitable via `POST /api/_action/sync`. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-54458 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-54458)
cross-site scripting in WWBN/AVideo (CVE-2026-54458). Confidential information can be exposed externally. Exploitable via ``page_title``.
|
| CVE-2026-50182 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-50182)
cross-site scripting in WWBN/AVideo (CVE-2026-50182). Risk of unauthorized operations or information disclosure. Exploitable via ``href``.
|
| CVE-2026-49279 |
|
Cross-Site Scripting (XSS) in wwbn/avideo (CVE-2026-49279)
cross-site scripting in wwbn/avideo (CVE-2026-49279). Risk of unauthorized operations or information disclosure. Exploitable via ``autoEvalCodeOnHTML``.
|
| CVE-2026-47671 |
|
Vulnerability in github.com/nhost/nhost (CVE-2026-47671)
vulnerability in github.com/nhost/nhost (CVE-2026-47671). Risk of unauthorized operations or information disclosure. Exploitable via ``configserver``. Mitigation: upgrade to `0.0.0-20260518172022-e407511627d2` or later.
|
| CVE-2026-50076 |
|
Unsafe Deserialization in org.apache.fory:fory-core (CVE-2026-50076)
vulnerability in org.apache.fory:fory-core (CVE-2026-50076). Confidential information can be exposed externally. Mitigation: upgrade to `1.1.0` or later.
|
| CVE-2026-10815 |
|
Vulnerability in CVE-2026-10815 (CVE-2026-10815)
vulnerability in CVE-2026-10815 (CVE-2026-10815). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10811 |
|
Vulnerability in sqli (CVE-2026-10811)
vulnerability in sqli (CVE-2026-10811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10863 |
|
Vulnerability in sqli (CVE-2026-10863)
vulnerability in sqli (CVE-2026-10863). Confidential information can be exposed externally.
|
| CVE-2026-28318 KEV |
|
[KEV] Vulnerability in Solarwinds serv-u (CVE-2026-28318)
vulnerability in Solarwinds serv-u (CVE-2026-28318). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-10810 |
|
Cross-Site Scripting (XSS) in CVE-2026-10810 (CVE-2026-10810)
cross-site scripting in CVE-2026-10810 (CVE-2026-10810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10806 |
|
Vulnerability in CVE-2026-10806 (CVE-2026-10806)
vulnerability in CVE-2026-10806 (CVE-2026-10806). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10808 |
|
Vulnerability in sqli (CVE-2026-10808)
vulnerability in sqli (CVE-2026-10808). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10807 |
|
Vulnerability in CVE-2026-10807 (CVE-2026-10807)
vulnerability in CVE-2026-10807 (CVE-2026-10807). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10809 |
|
Vulnerability in sqli (CVE-2026-10809)
vulnerability in sqli (CVE-2026-10809). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25734 |
|
Path Traversal in csrf (CVE-2019-25734)
path traversal in csrf (CVE-2019-25734). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25744 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25744)
cross-site scripting in wordpress (CVE-2019-25744). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25738 |
|
Vulnerability in wordpress (CVE-2019-25738)
vulnerability in wordpress (CVE-2019-25738). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25730 |
|
SQL Injection in sqli (CVE-2019-25730)
SQL injection in sqli (CVE-2019-25730). Confidential information can be exposed externally.
|
| CVE-2019-25732 |
|
SQL Injection in sqli (CVE-2019-25732)
SQL injection in sqli (CVE-2019-25732). Confidential information can be exposed externally.
|
| CVE-2019-25729 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2019-25729)
vulnerability in csrf (CVE-2019-25729). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25728 |
|
SQL Injection in sqli (CVE-2019-25728)
SQL injection in sqli (CVE-2019-25728). Confidential information can be exposed externally.
|
| CVE-2019-25727 |
|
Path Traversal in wordpress (CVE-2019-25727)
path traversal in wordpress (CVE-2019-25727). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43926 |
|
Vulnerability in nginx (CVE-2026-43926)
vulnerability in nginx (CVE-2026-43926). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10737 |
|
Vulnerability in wordpress (CVE-2026-10737)
vulnerability in wordpress (CVE-2026-10737). Confidential information can be exposed externally.
|