Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-57944 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-57944 (CVE-2026-57944)
vulnerability in CVE-2026-57944 (CVE-2026-57944). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59256 |
|
Information Disclosure in CVE-2026-59256 (CVE-2026-59256)
vulnerability in CVE-2026-59256 (CVE-2026-59256). Confidential information can be exposed externally.
|
| CVE-2026-58001 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-58001 (CVE-2026-58001)
vulnerability in CVE-2026-58001 (CVE-2026-58001). Data can be tampered with by attackers.
|
| CVE-2026-58002 |
|
Vulnerability in CVE-2026-58002 (CVE-2026-58002)
vulnerability in CVE-2026-58002 (CVE-2026-58002). Data can be tampered with by attackers.
|
| CVE-2026-58003 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-58003 (CVE-2026-58003)
vulnerability in CVE-2026-58003 (CVE-2026-58003). Confidential information can be exposed externally.
|
| CVE-2026-56380 |
|
Information Disclosure in CVE-2026-56380 (CVE-2026-56380)
vulnerability in CVE-2026-56380 (CVE-2026-56380). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76074 |
|
Vulnerability in wordpress (CVE-2026-76074)
vulnerability in wordpress (CVE-2026-76074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49849 |
|
Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34836 |
|
Vulnerability in CVE-2026-34836 (CVE-2026-34836)
vulnerability in CVE-2026-34836 (CVE-2026-34836). Confidential information can be exposed externally.
|
| CVE-2026-34741 |
|
Vulnerability in CVE-2026-34741 (CVE-2026-34741)
vulnerability in CVE-2026-34741 (CVE-2026-34741). Data can be tampered with by attackers.
|
| CVE-2026-31803 |
|
Cross-Site Scripting (XSS) in CVE-2026-31803 (CVE-2026-31803)
cross-site scripting in CVE-2026-31803 (CVE-2026-31803). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63135 |
|
Cross-Site Scripting (XSS) in yourls/yourls (CVE-2026-63135)
cross-site scripting in yourls/yourls (CVE-2026-63135). Data can be tampered with by attackers. Exploitable via `Referer header`. Mitigation: upgrade to `1.10.4` or later.
|
| CVE-2026-59989 |
|
Code Injection in phalcon/cphalcon (CVE-2026-59989)
code injection in phalcon/cphalcon (CVE-2026-59989). Risk of unauthorized operations or information disclosure. Exploitable via ``join``. Mitigation: upgrade to `5.16.0` or later.
|
| CVE-2026-74252 |
|
Cross-Site Scripting (XSS) in CVE-2026-74252 (CVE-2026-74252)
cross-site scripting in CVE-2026-74252 (CVE-2026-74252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62960 |
|
Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_interna...
Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-...
|
| CVE-2026-30819 |
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
|
| CVE-2026-54789 |
|
Out-of-Bounds Read in apache (CVE-2026-54789)
vulnerability in apache (CVE-2026-54789). Risk of unauthorized operations or information disclosure. Exploitable via ``mod_auth_openidc``.
|
| CVE-2026-59654 |
|
Vulnerability in apache (CVE-2026-59654)
vulnerability in apache (CVE-2026-59654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77686 |
|
Vulnerability in CVE-2026-77686 (CVE-2026-77686)
vulnerability in CVE-2026-77686 (CVE-2026-77686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77681 |
|
Vulnerability in CVE-2026-77681 (CVE-2026-77681)
vulnerability in CVE-2026-77681 (CVE-2026-77681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68745 |
|
Vulnerability in apache (CVE-2026-68745)
vulnerability in apache (CVE-2026-68745). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66722 |
|
Vulnerability in apache (CVE-2026-66722)
vulnerability in apache (CVE-2026-66722). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66797 |
|
Vulnerability in apache (CVE-2026-66797)
vulnerability in apache (CVE-2026-66797). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61397 |
|
Information Disclosure in apache (CVE-2026-61397)
vulnerability in apache (CVE-2026-61397). Confidential information can be exposed externally.
|
| CVE-2026-61399 |
|
Vulnerability in apache (CVE-2026-61399)
vulnerability in apache (CVE-2026-61399). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59780 |
|
Information Disclosure in apache (CVE-2026-59780)
vulnerability in apache (CVE-2026-59780). Confidential information can be exposed externally.
|
| CVE-2026-59657 |
|
Vulnerability in apache (CVE-2026-59657)
vulnerability in apache (CVE-2026-59657). Confidential information can be exposed externally.
|
| CVE-2026-61398 |
|
Vulnerability in apache (CVE-2026-61398)
vulnerability in apache (CVE-2026-61398). Confidential information can be exposed externally.
|
| CVE-2026-59655 |
|
Information Disclosure in apache (CVE-2026-59655)
vulnerability in apache (CVE-2026-59655). Confidential information can be exposed externally.
|
| CVE-2026-50222 |
|
Information Disclosure in apache (CVE-2026-50222)
vulnerability in apache (CVE-2026-50222). Confidential information can be exposed externally.
|
| CVE-2026-65613 |
|
Information Disclosure in apache (CVE-2026-65613)
vulnerability in apache (CVE-2026-65613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66721 |
|
Vulnerability in apache (CVE-2026-66721)
vulnerability in apache (CVE-2026-66721). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59799 |
|
Privilege Escalation in apache (CVE-2026-59799)
vulnerability in apache (CVE-2026-59799). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59085 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-59085)
SSRF in apache (CVE-2026-59085). Confidential information can be exposed externally.
|
| CVE-2026-63046 |
|
Vulnerability in apache (CVE-2026-63046)
vulnerability in apache (CVE-2026-63046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62440 |
|
Vulnerability in apache (CVE-2026-62440)
vulnerability in apache (CVE-2026-62440). Confidential information can be exposed externally.
|
| CVE-2026-61422 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-61422)
SSRF in apache (CVE-2026-61422). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61400 |
|
Command Injection in apache (CVE-2026-61400)
command injection in apache (CVE-2026-61400). Successful exploitation can lead to full system takeover. Exploitable via ``getDiagnosticsData``.
|
| CVE-2026-50112 |
|
OS Command Injection in apache (CVE-2026-50112)
OS command injection in apache (CVE-2026-50112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47359 |
|
OS Command Injection in apache (CVE-2026-47359)
OS command injection in apache (CVE-2026-47359). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77392 |
|
Vulnerability in sqli (CVE-2026-77392)
vulnerability in sqli (CVE-2026-77392). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77391 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-77391 (CVE-2026-77391)
vulnerability in CVE-2026-77391 (CVE-2026-77391). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43679 |
|
Vulnerability in apple (CVE-2026-43679)
vulnerability in apple (CVE-2026-43679). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20679 |
|
Out-of-Bounds Read in apple (CVE-2026-20679)
vulnerability in apple (CVE-2026-20679). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77647 |
|
Code Injection in CVE-2026-77647 (CVE-2026-77647)
code injection in CVE-2026-77647 (CVE-2026-77647). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69558 |
|
Vulnerability in microsoft (CVE-2026-69558)
vulnerability in microsoft (CVE-2026-69558). Confidential information can be exposed externally.
|
| CVE-2026-65770 |
|
Vulnerability in apache (CVE-2026-65770)
vulnerability in apache (CVE-2026-65770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76018 |
|
Vulnerability in google (CVE-2026-76018)
vulnerability in google (CVE-2026-76018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76019 |
|
Authorization Flaw in google (CVE-2026-76019)
vulnerability in google (CVE-2026-76019). Confidential information can be exposed externally.
|
| CVE-2026-76020 |
|
Vulnerability in google (CVE-2026-76020)
vulnerability in google (CVE-2026-76020). Successful exploitation can lead to full system takeover.
|