Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19895 |
|
Vulnerability in CVE-2026-19895 (CVE-2026-19895)
vulnerability in CVE-2026-19895 (CVE-2026-19895). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19894 |
|
Vulnerability in sqli (CVE-2026-19894)
vulnerability in sqli (CVE-2026-19894). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73634 |
|
Vulnerability in apache (CVE-2026-73634)
vulnerability in apache (CVE-2026-73634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73635 |
|
Vulnerability in apache (CVE-2026-73635)
vulnerability in apache (CVE-2026-73635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73632 |
|
Vulnerability in apache (CVE-2026-73632)
vulnerability in apache (CVE-2026-73632). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73631 |
|
Vulnerability in apache (CVE-2026-73631)
vulnerability in apache (CVE-2026-73631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14279 |
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
| CVE-2026-16145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15162 |
|
SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
|
| CVE-2026-14484 |
|
Path Traversal in wordpress (CVE-2026-14484)
path traversal in wordpress (CVE-2026-14484). Data can be tampered with by attackers.
|
| CVE-2026-73683 |
|
Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69414 |
|
Vulnerability in microsoft (CVE-2026-69414)
vulnerability in microsoft (CVE-2026-69414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73680 |
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
| CVE-2026-73679 |
|
Code Injection in CVE-2026-73679 (CVE-2026-73679)
code injection in CVE-2026-73679 (CVE-2026-73679). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19839 |
|
Vulnerability in CVE-2026-19839 (CVE-2026-19839)
vulnerability in CVE-2026-19839 (CVE-2026-19839). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73850 |
|
SQL Injection in sqli (CVE-2026-73850)
SQL injection in sqli (CVE-2026-73850). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73847 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73847)
vulnerability in csrf (CVE-2026-73847). Confidential information can be exposed externally.
|
| CVE-2026-73849 |
|
Vulnerability in CVE-2026-73849 (CVE-2026-73849)
vulnerability in CVE-2026-73849 (CVE-2026-73849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48528 |
|
SQL Injection in tomcat (CVE-2026-48528)
SQL injection in tomcat (CVE-2026-48528). Successful exploitation can lead to full system takeover. Exploitable via ``nodeId``.
|
| CVE-2026-58224 |
|
Vulnerability in dos (CVE-2026-58224)
vulnerability in dos (CVE-2026-58224). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73633 |
|
Vulnerability in apache (CVE-2026-73633)
vulnerability in apache (CVE-2026-73633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19825 |
|
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
|
| CVE-2026-72832 |
|
Cross-Site Scripting (XSS) in CVE-2026-72832 (CVE-2026-72832)
cross-site scripting in CVE-2026-72832 (CVE-2026-72832). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.13` or later.
|
| CVE-2026-72819 |
|
Code Injection in c (CVE-2026-72819)
code injection in c (CVE-2026-72819). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19794 |
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
| CVE-2026-19787 |
|
Vulnerability in sqli (CVE-2026-19787)
vulnerability in sqli (CVE-2026-19787). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19785 |
|
Vulnerability in sqli (CVE-2026-19785)
vulnerability in sqli (CVE-2026-19785). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19784 |
|
Vulnerability in CVE-2026-19784 (CVE-2026-19784)
vulnerability in CVE-2026-19784 (CVE-2026-19784). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19786 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-19786 (CVE-2026-19786)
vulnerability in CVE-2026-19786 (CVE-2026-19786). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19767 |
|
Vulnerability in sqli (CVE-2026-19767)
vulnerability in sqli (CVE-2026-19767). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19764 |
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
| CVE-2026-73664 |
|
Privilege Escalation in CVE-2026-73664 (CVE-2026-73664)
vulnerability in CVE-2026-73664 (CVE-2026-73664). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73661 |
|
Vulnerability in CVE-2026-73661 (CVE-2026-73661)
vulnerability in CVE-2026-73661 (CVE-2026-73661). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73663 |
|
SQL Injection in CVE-2026-73663 (CVE-2026-73663)
SQL injection in CVE-2026-73663 (CVE-2026-73663). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73662 |
|
OS Command Injection in CVE-2026-73662 (CVE-2026-73662)
OS command injection in CVE-2026-73662 (CVE-2026-73662). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19297 |
|
Vulnerability in langflow (CVE-2026-19297)
vulnerability in langflow (CVE-2026-19297). Confidential information can be exposed externally.
|
| CVE-2026-72642 |
|
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models...
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models...
|
| CVE-2026-14525 |
|
Vulnerability in ibm (CVE-2026-14525)
vulnerability in ibm (CVE-2026-14525). Confidential information can be exposed externally.
|
| CVE-2026-10571 |
|
Unsafe Deserialization in dos (CVE-2026-10571)
vulnerability in dos (CVE-2026-10571). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73482 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73482)
vulnerability in csrf (CVE-2026-73482). Data can be tampered with by attackers.
|
| CVE-2026-73481 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73481)
vulnerability in csrf (CVE-2026-73481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18428 |
|
Vulnerability in Amazon aws (CVE-2026-18428)
vulnerability in Amazon aws (CVE-2026-18428). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73671 |
|
Open Redirect in CVE-2026-73671 (CVE-2026-73671)
vulnerability in CVE-2026-73671 (CVE-2026-73671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73670 |
|
SQL Injection in sqli (CVE-2026-73670)
SQL injection in sqli (CVE-2026-73670). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73574 |
|
Vulnerability in synacor (CVE-2026-73574)
vulnerability in synacor (CVE-2026-73574). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73573 |
|
Vulnerability in path-traversal (CVE-2026-73573)
vulnerability in path-traversal (CVE-2026-73573). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73572 |
|
Cross-Site Scripting (XSS) in synacor (CVE-2026-73572)
cross-site scripting in synacor (CVE-2026-73572). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73570 KEV |
|
[KEV] OS Command Injection in Synacor zimbra-collaboration-suite (CVE-2026-73570)
OS command injection in Synacor zimbra-collaboration-suite (CVE-2026-73570). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-73571 |
|
Authorization Flaw in c (CVE-2026-73571)
vulnerability in c (CVE-2026-73571). Risk of unauthorized operations or information disclosure.
|