Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-68872 |
|
Vulnerability in apache (CVE-2026-68872)
vulnerability in apache (CVE-2026-68872). Confidential information can be exposed externally.
|
| CVE-2026-72898 KEV |
|
[KEV] SQL Injection in metabase (CVE-2026-72898)
SQL injection in metabase (CVE-2026-72898). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-66738 |
|
Code Injection in CVE-2026-66738 (CVE-2026-66738)
code injection in CVE-2026-66738 (CVE-2026-66738). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47754 |
|
Path Traversal in tomcat (CVE-2026-47754)
path traversal in tomcat (CVE-2026-47754). Confidential information can be exposed externally. Exploitable via ``archiveEntryName``.
|
| CVE-2026-18412 |
|
Vulnerability in path-traversal (CVE-2026-18412)
vulnerability in path-traversal (CVE-2026-18412). Confidential information can be exposed externally.
|
| CVE-2026-63106 |
|
SQL Injection in sqli (CVE-2026-63106)
SQL injection in sqli (CVE-2026-63106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72592 |
|
Unrestricted File Upload in CVE-2026-72592 (CVE-2026-72592)
vulnerability in CVE-2026-72592 (CVE-2026-72592). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72574 |
|
Vulnerability in CVE-2026-72574 (CVE-2026-72574)
vulnerability in CVE-2026-72574 (CVE-2026-72574). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-61899 |
|
Information Disclosure in apache (CVE-2026-61899)
vulnerability in apache (CVE-2026-61899). Confidential information can be exposed externally.
|
| CVE-2026-65948 |
|
Vulnerability in apache (CVE-2026-65948)
vulnerability in apache (CVE-2026-65948). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65945 |
|
Vulnerability in apache (CVE-2026-65945)
vulnerability in apache (CVE-2026-65945). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65942 |
|
Vulnerability in apache (CVE-2026-65942)
vulnerability in apache (CVE-2026-65942). Confidential information can be exposed externally.
|
| CVE-2026-55799 |
|
Code Injection in apache (CVE-2026-55799)
code injection in apache (CVE-2026-55799). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55814 |
|
Vulnerability in apache (CVE-2026-55814)
vulnerability in apache (CVE-2026-55814). Confidential information can be exposed externally.
|
| CVE-2026-32227 |
|
SQL Injection in apache (CVE-2026-32227)
SQL injection in apache (CVE-2026-32227). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40920 |
|
Vulnerability in apache (CVE-2026-40920)
vulnerability in apache (CVE-2026-40920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42537 |
|
Vulnerability in apache (CVE-2026-42537)
vulnerability in apache (CVE-2026-42537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44416 |
|
Code Injection in apache (CVE-2026-44416)
code injection in apache (CVE-2026-44416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28672 |
|
Command Injection in apache (CVE-2026-28672)
command injection in apache (CVE-2026-28672). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44630 |
|
Vulnerability in apache (CVE-2026-44630)
vulnerability in apache (CVE-2026-44630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19075 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19075 (CVE-2026-19075)
SSRF in CVE-2026-19075 (CVE-2026-19075). Risk of unauthorized operations or information disclosure. Exploitable via ``aiovg_videos``.
|
| CVE-2026-16985 |
|
Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13170 |
|
Path Traversal in wordpress (CVE-2026-13170)
path traversal in wordpress (CVE-2026-13170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19384 |
|
Vulnerability in sqli (CVE-2026-19384)
vulnerability in sqli (CVE-2026-19384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19378 |
|
Cross-Site Scripting (XSS) in CVE-2026-19378 (CVE-2026-19378)
cross-site scripting in CVE-2026-19378 (CVE-2026-19378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19376 |
|
Vulnerability in CVE-2026-19376 (CVE-2026-19376)
vulnerability in CVE-2026-19376 (CVE-2026-19376). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19364 |
|
Vulnerability in sqli (CVE-2026-19364)
vulnerability in sqli (CVE-2026-19364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19353 |
|
Vulnerability in CVE-2026-19353 (CVE-2026-19353)
vulnerability in CVE-2026-19353 (CVE-2026-19353). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19350 |
|
Vulnerability in CVE-2026-19350 (CVE-2026-19350)
vulnerability in CVE-2026-19350 (CVE-2026-19350). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19347 |
|
Vulnerability in sqli (CVE-2026-19347)
vulnerability in sqli (CVE-2026-19347). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19345 |
|
Vulnerability in CVE-2026-19345 (CVE-2026-19345)
vulnerability in CVE-2026-19345 (CVE-2026-19345). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19344 |
|
Vulnerability in sqli (CVE-2026-19344)
vulnerability in sqli (CVE-2026-19344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19342 |
|
Authentication Bypass in CVE-2026-19342 (CVE-2026-19342)
authentication bypass in CVE-2026-19342 (CVE-2026-19342). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19343 |
|
Vulnerability in sqli (CVE-2026-19343)
vulnerability in sqli (CVE-2026-19343). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18465 |
|
Path Traversal in wordpress (CVE-2026-18465)
path traversal in wordpress (CVE-2026-18465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16267 |
|
Unsafe Deserialization in wordpress (CVE-2026-16267)
vulnerability in wordpress (CVE-2026-16267). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69127 |
|
Vulnerability in CVE-2026-69127 (CVE-2026-69127)
vulnerability in CVE-2026-69127 (CVE-2026-69127). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70561 |
|
Vulnerability in CVE-2026-70561 (CVE-2026-70561)
vulnerability in CVE-2026-70561 (CVE-2026-70561). Confidential information can be exposed externally.
|
| CVE-2026-19230 |
|
Cross-Site Scripting (XSS) in CVE-2026-19230 (CVE-2026-19230)
cross-site scripting in CVE-2026-19230 (CVE-2026-19230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19231 |
|
Vulnerability in sqli (CVE-2026-19231)
vulnerability in sqli (CVE-2026-19231). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19211 |
|
Vulnerability in sqli (CVE-2026-19211)
vulnerability in sqli (CVE-2026-19211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19210 |
|
Vulnerability in CVE-2026-19210 (CVE-2026-19210)
vulnerability in CVE-2026-19210 (CVE-2026-19210). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19209 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-19209)
cross-site scripting in c (CVE-2026-19209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19207 |
|
Cross-Site Scripting (XSS) in CVE-2026-19207 (CVE-2026-19207)
cross-site scripting in CVE-2026-19207 (CVE-2026-19207). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62996 |
|
Path Traversal in smarty/smarty (CVE-2026-62996)
path traversal in smarty/smarty (CVE-2026-62996). Risk of unauthorized operations or information disclosure. Exploitable via ``stream``. Mitigation: upgrade to `5.8.4` or later.
|
| CVE-2026-62992 |
|
Path Traversal in smarty/smarty (CVE-2026-62992)
path traversal in smarty/smarty (CVE-2026-62992). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.8.2` or later.
|
| CVE-2026-71559 |
|
Unsafe Deserialization in apache (CVE-2026-71559)
vulnerability in apache (CVE-2026-71559). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71558 |
|
Unsafe Deserialization in c (CVE-2026-71558)
vulnerability in c (CVE-2026-71558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71560 |
|
Out-of-Bounds Read in c (CVE-2026-71560)
vulnerability in c (CVE-2026-71560). Data can be tampered with by attackers.
|
| CVE-2026-19196 |
|
Vulnerability in sqli (CVE-2026-19196)
vulnerability in sqli (CVE-2026-19196). Risk of unauthorized operations or information disclosure.
|