Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-32258 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32258)
cross-site scripting in winter/wn-backend-module (CVE-2026-32258). Confidential information can be exposed externally. Exploitable via ``backend.manage_editor``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32257 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32257)
cross-site scripting in winter/wn-backend-module (CVE-2026-32257). Confidential information can be exposed externally. Exploitable via ``backend.manage_branding``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-67285 |
|
Path Traversal in CVE-2026-67285 (CVE-2026-67285)
path traversal in CVE-2026-67285 (CVE-2026-67285). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68868 |
|
Vulnerability in apache (CVE-2026-68868)
vulnerability in apache (CVE-2026-68868). Confidential information can be exposed externally. Exploitable via ``team_name``.
|
| CVE-2026-18391 |
|
Unrestricted File Upload in wordpress (CVE-2026-18391)
vulnerability in wordpress (CVE-2026-18391). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15039 |
|
Unrestricted File Upload in wordpress (CVE-2026-15039)
vulnerability in wordpress (CVE-2026-15039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19557 |
|
Use-After-Free in google (CVE-2026-19557)
vulnerability in google (CVE-2026-19557). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19560 |
|
Use-After-Free in google (CVE-2026-19560)
vulnerability in google (CVE-2026-19560). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19559 |
|
Use-After-Free in google (CVE-2026-19559)
vulnerability in google (CVE-2026-19559). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19558 |
|
Use-After-Free in google (CVE-2026-19558)
vulnerability in google (CVE-2026-19558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19556 |
|
Use-After-Free in Google chrome (CVE-2026-19556)
vulnerability in Google chrome (CVE-2026-19556). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71290 |
|
Vulnerability in apache (CVE-2026-71290)
vulnerability in apache (CVE-2026-71290). Confidential information can be exposed externally.
|
| CVE-2026-55676 |
|
Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
|
| CVE-2026-19091 |
|
Path Traversal in wordpress (CVE-2026-19091)
path traversal in wordpress (CVE-2026-19091). Data can be tampered with by attackers.
|
| CVE-2026-13457 |
|
Unrestricted File Upload in wordpress (CVE-2026-13457)
vulnerability in wordpress (CVE-2026-13457). Confidential information can be exposed externally.
|
| CVE-2026-15426 |
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
| CVE-2026-58639 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-58639)
SSRF in ssrf (CVE-2026-58639). Confidential information can be exposed externally.
|
| CVE-2026-58641 |
|
Vulnerability in csharp (CVE-2026-58641)
vulnerability in csharp (CVE-2026-58641). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57105 |
|
Cross-Site Scripting (XSS) in microsoft (CVE-2026-57105)
cross-site scripting in microsoft (CVE-2026-57105). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48440 |
|
Vulnerability in adobe (CVE-2026-48440)
vulnerability in adobe (CVE-2026-48440). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48375 |
|
Authorization Flaw in adobe (CVE-2026-48375)
vulnerability in adobe (CVE-2026-48375). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34635 |
|
Vulnerability in adobe (CVE-2026-34635)
vulnerability in adobe (CVE-2026-34635). Confidential information can be exposed externally.
|
| CVE-2026-48376 |
|
Vulnerability in adobe (CVE-2026-48376)
vulnerability in adobe (CVE-2026-48376). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48386 |
|
Vulnerability in adobe (CVE-2026-48386)
vulnerability in adobe (CVE-2026-48386). Confidential information can be exposed externally.
|
| CVE-2026-48384 |
|
Vulnerability in adobe (CVE-2026-48384)
vulnerability in adobe (CVE-2026-48384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48362 |
|
OS Command Injection in adobe (CVE-2026-48362)
OS command injection in adobe (CVE-2026-48362). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48385 |
|
OS Command Injection in adobe (CVE-2026-48385)
OS command injection in adobe (CVE-2026-48385). Data can be tampered with by attackers.
|
| CVE-2026-25652 |
|
Authorization Flaw in privilege-escalation (CVE-2026-25652)
vulnerability in privilege-escalation (CVE-2026-25652). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21279 |
|
Vulnerability in adobe (CVE-2026-21279)
vulnerability in adobe (CVE-2026-21279). Confidential information can be exposed externally.
|
| CVE-2026-21273 |
|
Vulnerability in privilege-escalation (CVE-2026-21273)
vulnerability in privilege-escalation (CVE-2026-21273). Confidential information can be exposed externally.
|
| CVE-2026-21269 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-21269)
cross-site scripting in adobe (CVE-2026-21269). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48447 |
|
Authorization Flaw in adobe (CVE-2026-48447)
vulnerability in adobe (CVE-2026-48447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48441 |
|
Path Traversal in path-traversal (CVE-2026-48441)
path traversal in path-traversal (CVE-2026-48441). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48409 |
|
Out-of-Bounds Write in adobe (CVE-2026-48409)
out-of-bounds write in adobe (CVE-2026-48409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48410 |
|
Out-of-Bounds Write in adobe (CVE-2026-48410)
out-of-bounds write in adobe (CVE-2026-48410). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48408 |
|
Out-of-Bounds Write in adobe (CVE-2026-48408)
out-of-bounds write in adobe (CVE-2026-48408). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48407 |
|
Out-of-Bounds Write in adobe (CVE-2026-48407)
out-of-bounds write in adobe (CVE-2026-48407). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48406 |
|
Out-of-Bounds Write in adobe (CVE-2026-48406)
out-of-bounds write in adobe (CVE-2026-48406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48397 |
|
Unsafe Deserialization in deserialization (CVE-2026-48397)
vulnerability in deserialization (CVE-2026-48397). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48404 |
|
Out-of-Bounds Write in adobe (CVE-2026-48404)
out-of-bounds write in adobe (CVE-2026-48404). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48405 |
|
Out-of-Bounds Write in adobe (CVE-2026-48405)
out-of-bounds write in adobe (CVE-2026-48405). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47940 |
|
Vulnerability in adobe (CVE-2026-47940)
vulnerability in adobe (CVE-2026-47940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71386 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-71386)
cross-site scripting in adobe (CVE-2026-71386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71383 |
|
Authorization Flaw in adobe (CVE-2026-71383)
vulnerability in adobe (CVE-2026-71383). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71387 |
|
Authorization Flaw in adobe (CVE-2026-71387)
vulnerability in adobe (CVE-2026-71387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71384 |
|
Authorization Flaw in adobe (CVE-2026-71384)
vulnerability in adobe (CVE-2026-71384). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70355 |
|
Cross-Site Scripting (XSS) in microsoft (CVE-2026-70355)
cross-site scripting in microsoft (CVE-2026-70355). Confidential information can be exposed externally.
|
| CVE-2026-70354 |
|
Out-of-Bounds Write in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-70354)
out-of-bounds write in Microsoft.WindowsDesktop.App.Runtime.win-arm64 (CVE-2026-70354). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-70324 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-70324)
SSRF in ssrf (CVE-2026-70324). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70326 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-70326)
SSRF in ssrf (CVE-2026-70326). Successful exploitation can lead to full system takeover.
|