Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-61807 |
|
Cross-Site Scripting (XSS) in snipe/snipe-it (CVE-2026-61807)
cross-site scripting in snipe/snipe-it (CVE-2026-61807). Risk of unauthorized operations or information disclosure. Exploitable via ``b224cc636c6780386e3f73f03d1171f52ab4c37a``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55703 |
|
Vulnerability in snipe/snipe-it (CVE-2026-55703)
vulnerability in snipe/snipe-it (CVE-2026-55703). Risk of unauthorized operations or information disclosure. Exploitable via `GET /maintenances/5`. Mitigation: upgrade to `8.6.3` or later.
|
| CVE-2026-55694 |
|
Vulnerability in snipe/snipe-it (CVE-2026-55694)
vulnerability in snipe/snipe-it (CVE-2026-55694). Risk of unauthorized operations or information disclosure. Exploitable via `GET /stored-eula-file/{filename}`. Mitigation: upgrade to `8.6.3` or later.
|
| CVE-2026-19875 |
|
Vulnerability in langflow (CVE-2026-19875)
vulnerability in langflow (CVE-2026-19875). Data can be tampered with by attackers.
|
| CVE-2026-64852 |
|
Vulnerability in CVE-2026-64852 (CVE-2026-64852)
vulnerability in CVE-2026-64852 (CVE-2026-64852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64851 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-64851)
cross-site scripting in wordpress (CVE-2026-64851). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64850 |
|
Code Injection in CVE-2026-64850 (CVE-2026-64850)
code injection in CVE-2026-64850 (CVE-2026-64850). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63408 |
|
Vulnerability in apache (CVE-2026-63408)
vulnerability in apache (CVE-2026-63408). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-62673 |
|
Vulnerability in getgrav/grav (CVE-2026-62673)
vulnerability in getgrav/grav (CVE-2026-62673). Risk of unauthorized operations or information disclosure. Exploitable via `GET /user/plugins/my-plugin/my-plugin.YAML`. Mitigation: upgrade to `2.0.4` or later.
|
| CVE-2026-62672 |
|
Vulnerability in CVE-2026-62672 (CVE-2026-62672)
vulnerability in CVE-2026-62672 (CVE-2026-62672). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62668 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-62668 (CVE-2026-62668)
SSRF in CVE-2026-62668 (CVE-2026-62668). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62670 |
|
Vulnerability in CVE-2026-62670 (CVE-2026-62670)
vulnerability in CVE-2026-62670 (CVE-2026-62670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61690 |
|
Vulnerability in CVE-2026-61690 (CVE-2026-61690)
vulnerability in CVE-2026-61690 (CVE-2026-61690). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75956 |
|
Vulnerability in dos (CVE-2026-75956)
vulnerability in dos (CVE-2026-75956). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76210 |
|
Vulnerability in CVE-2026-76210 (CVE-2026-76210)
vulnerability in CVE-2026-76210 (CVE-2026-76210). Confidential information can be exposed externally.
|
| CVE-2026-76212 |
|
Vulnerability in sqli (CVE-2026-76212)
vulnerability in sqli (CVE-2026-76212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73389 |
|
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
|
| CVE-2026-73364 |
|
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
|
| CVE-2026-67364 |
|
Code Injection in c (CVE-2026-67364)
code injection in c (CVE-2026-67364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75981 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-75981)
cross-site scripting in wordpress (CVE-2026-75981). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18937 |
|
Code Injection in wordpress (CVE-2026-18937)
code injection in wordpress (CVE-2026-18937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18051 |
|
Path Traversal in wordpress (CVE-2026-18051)
path traversal in wordpress (CVE-2026-18051). Data can be tampered with by attackers.
|
| CVE-2026-11565 |
|
Vulnerability in wordpress (CVE-2026-11565)
vulnerability in wordpress (CVE-2026-11565). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19942 |
|
Path Traversal in wordpress (CVE-2026-19942)
path traversal in wordpress (CVE-2026-19942). Data can be tampered with by attackers.
|
| CVE-2026-76050 |
|
Vulnerability in sqli (CVE-2026-76050)
vulnerability in sqli (CVE-2026-76050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76049 |
|
Vulnerability in sqli (CVE-2026-76049)
vulnerability in sqli (CVE-2026-76049). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76048 |
|
Vulnerability in sqli (CVE-2026-76048)
vulnerability in sqli (CVE-2026-76048). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75986 |
|
Vulnerability in sqli (CVE-2026-75986)
vulnerability in sqli (CVE-2026-75986). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76046 |
|
Vulnerability in c (CVE-2026-76046)
vulnerability in c (CVE-2026-76046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76043 |
|
Vulnerability in google (CVE-2026-76043)
vulnerability in google (CVE-2026-76043). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76045 |
|
Use-After-Free in google (CVE-2026-76045)
vulnerability in google (CVE-2026-76045). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76044 |
|
Vulnerability in google (CVE-2026-76044)
vulnerability in google (CVE-2026-76044). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76042 |
|
Vulnerability in google (CVE-2026-76042)
vulnerability in google (CVE-2026-76042). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76040 |
|
Use-After-Free in google (CVE-2026-76040)
vulnerability in google (CVE-2026-76040). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76041 |
|
Information Disclosure in google (CVE-2026-76041)
vulnerability in google (CVE-2026-76041). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76047 |
|
Vulnerability in google (CVE-2026-76047)
vulnerability in google (CVE-2026-76047). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76038 |
|
Vulnerability in google (CVE-2026-76038)
vulnerability in google (CVE-2026-76038). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76033 |
|
Vulnerability in Google chrome (CVE-2026-76033)
vulnerability in Google chrome (CVE-2026-76033). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76035 |
|
Vulnerability in google (CVE-2026-76035)
vulnerability in google (CVE-2026-76035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76037 |
|
Vulnerability in google (CVE-2026-76037)
vulnerability in google (CVE-2026-76037). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76039 |
|
Vulnerability in google (CVE-2026-76039)
vulnerability in google (CVE-2026-76039). Confidential information can be exposed externally.
|
| CVE-2026-76036 |
|
Vulnerability in google (CVE-2026-76036)
vulnerability in google (CVE-2026-76036). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70845 |
|
Vulnerability in c (CVE-2026-70845)
vulnerability in c (CVE-2026-70845). Data can be tampered with by attackers.
|
| CVE-2026-70844 |
|
Vulnerability in c (CVE-2026-70844)
vulnerability in c (CVE-2026-70844). Confidential information can be exposed externally.
|
| CVE-2026-70814 |
|
Vulnerability in c (CVE-2026-70814)
vulnerability in c (CVE-2026-70814). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70807 |
|
Vulnerability in c (CVE-2026-70807)
vulnerability in c (CVE-2026-70807). Confidential information can be exposed externally.
|
| CVE-2026-70813 |
|
Vulnerability in c (CVE-2026-70813)
vulnerability in c (CVE-2026-70813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70812 |
|
Vulnerability in c (CVE-2026-70812)
vulnerability in c (CVE-2026-70812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70778 |
|
Vulnerability in c (CVE-2026-70778)
vulnerability in c (CVE-2026-70778). Confidential information can be exposed externally.
|
| CVE-2026-70761 |
|
Vulnerability in c (CVE-2026-70761)
vulnerability in c (CVE-2026-70761). Successful exploitation can lead to full system takeover.
|