Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44548 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-44548 (CVE-2026-44548)
vulnerability in CVE-2026-44548 (CVE-2026-44548). Data can be tampered with by attackers. Mitigation: upgrade to `7.3.2` or later.
|
| CVE-2026-42289 |
|
Privilege Escalation in csrf (CVE-2026-42289)
vulnerability in csrf (CVE-2026-42289). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.3.2` or later.
|
| CVE-2026-40902 |
|
Vulnerability in phpoffice/phpspreadsheet (CVE-2026-40902)
vulnerability in phpoffice/phpspreadsheet (CVE-2026-40902). Risk of unauthorized operations or information disclosure. Exploitable via ``cachedHighestRow``. Mitigation: upgrade to `1.30.4` or later.
|
| CVE-2026-40863 |
|
Vulnerability in phpoffice/phpspreadsheet (CVE-2026-40863)
vulnerability in phpoffice/phpspreadsheet (CVE-2026-40863). Risk of unauthorized operations or information disclosure. Exploitable via ``cachedHighestRow``. Mitigation: upgrade to `1.30.4` or later.
|
| CVE-2026-34687 |
|
Vulnerability in adobe (CVE-2026-34687)
vulnerability in adobe (CVE-2026-34687). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34661 |
|
Out-of-Bounds Write in adobe (CVE-2026-34661)
out-of-bounds write in adobe (CVE-2026-34661). Successful exploitation can lead to full system takeover.
|
| CVE-2025-46311 |
|
Vulnerability in apple (CVE-2025-46311)
vulnerability in apple (CVE-2025-46311). Confidential information can be exposed externally.
|
| CVE-2026-7432 |
|
Vulnerability in ivanti (CVE-2026-7432)
vulnerability in ivanti (CVE-2026-7432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-43884 |
|
SSRF (Server-Side Request Forgery) in wwbn/avideo (CVE-2026-43884)
SSRF in wwbn/avideo (CVE-2026-43884). Confidential information can be exposed externally. Exploitable via `POST /plugin/AI/receiveAsync.json.php`.
|
| CVE-2026-43873 |
|
Vulnerability in wwbn/avideo (CVE-2026-43873)
vulnerability in wwbn/avideo (CVE-2026-43873). Confidential information can be exposed externally. Exploitable via ``cloneSiteURL``.
|
| CVE-2026-43660 |
|
Vulnerability in apple (CVE-2026-43660)
vulnerability in apple (CVE-2026-43660). Confidential information can be exposed externally.
|
| CVE-2026-43661 |
|
Vulnerability in apple (CVE-2026-43661)
vulnerability in apple (CVE-2026-43661). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39871 |
|
Vulnerability in apple (CVE-2026-39871)
vulnerability in apple (CVE-2026-39871). Confidential information can be exposed externally.
|
| CVE-2026-28995 |
|
Privilege Escalation in apple (CVE-2026-28995)
vulnerability in apple (CVE-2026-28995). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28986 |
|
Vulnerability in apple (CVE-2026-28986)
vulnerability in apple (CVE-2026-28986). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28965 |
|
Vulnerability in apple (CVE-2026-28965)
vulnerability in apple (CVE-2026-28965). Confidential information can be exposed externally.
|
| CVE-2026-28964 |
|
Vulnerability in apple (CVE-2026-28964)
vulnerability in apple (CVE-2026-28964). Confidential information can be exposed externally.
|
| CVE-2026-28990 |
|
Buffer Overflow in apple (CVE-2026-28990)
vulnerability in apple (CVE-2026-28990). Confidential information can be exposed externally.
|
| CVE-2026-28969 |
|
Use-After-Free in apple (CVE-2026-28969)
vulnerability in apple (CVE-2026-28969). Confidential information can be exposed externally.
|
| CVE-2026-28962 |
|
Information Disclosure in apple (CVE-2026-28962)
vulnerability in apple (CVE-2026-28962). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28987 |
|
Vulnerability in apple (CVE-2026-28987)
vulnerability in apple (CVE-2026-28987). Confidential information can be exposed externally.
|
| CVE-2026-28974 |
|
Vulnerability in apple (CVE-2026-28974)
vulnerability in apple (CVE-2026-28974). Confidential information can be exposed externally.
|
| CVE-2026-28951 |
|
Authorization Flaw in apple (CVE-2026-28951)
vulnerability in apple (CVE-2026-28951). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28954 |
|
Vulnerability in apple (CVE-2026-28954)
vulnerability in apple (CVE-2026-28954). Confidential information can be exposed externally.
|
| CVE-2026-28925 |
|
Vulnerability in apple (CVE-2026-28925)
vulnerability in apple (CVE-2026-28925). Confidential information can be exposed externally.
|
| CVE-2026-28923 |
|
Vulnerability in apple (CVE-2026-28923)
vulnerability in apple (CVE-2026-28923). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28924 |
|
Vulnerability in apple (CVE-2026-28924)
vulnerability in apple (CVE-2026-28924). Confidential information can be exposed externally.
|
| CVE-2026-28944 |
|
Buffer Overflow in apple (CVE-2026-28944)
vulnerability in apple (CVE-2026-28944). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28953 |
|
Buffer Overflow in apple (CVE-2026-28953)
vulnerability in apple (CVE-2026-28953). Confidential information can be exposed externally.
|
| CVE-2026-28929 |
|
Vulnerability in apple (CVE-2026-28929)
vulnerability in apple (CVE-2026-28929). Confidential information can be exposed externally.
|
| CVE-2026-28919 |
|
Privilege Escalation in apple (CVE-2026-28919)
vulnerability in apple (CVE-2026-28919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28883 |
|
Use-After-Free in apple (CVE-2026-28883)
vulnerability in apple (CVE-2026-28883). Confidential information can be exposed externally.
|
| CVE-2026-28908 |
|
Vulnerability in dos (CVE-2026-28908)
vulnerability in dos (CVE-2026-28908). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28904 |
|
Buffer Overflow in apple (CVE-2026-28904)
vulnerability in apple (CVE-2026-28904). Confidential information can be exposed externally.
|
| CVE-2026-28848 |
|
Vulnerability in apple (CVE-2026-28848)
vulnerability in apple (CVE-2026-28848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28860 |
|
Vulnerability in apple (CVE-2026-28860)
vulnerability in apple (CVE-2026-28860). Confidential information can be exposed externally.
|
| CVE-2026-28840 |
|
Privilege Escalation in apple (CVE-2026-28840)
vulnerability in apple (CVE-2026-28840). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28913 |
|
Buffer Overflow in apple (CVE-2026-28913)
vulnerability in apple (CVE-2026-28913). Confidential information can be exposed externally.
|
| CVE-2026-28905 |
|
Buffer Overflow in apple (CVE-2026-28905)
vulnerability in apple (CVE-2026-28905). Confidential information can be exposed externally.
|
| CVE-2026-43874 |
|
Code Injection in wwbn/avideo (CVE-2026-43874)
code injection in wwbn/avideo (CVE-2026-43874). Risk of unauthorized operations or information disclosure. Exploitable via ``autoEvalCodeOnHTML``.
|
| CVE-2026-44413 |
|
Vulnerability in jetbrains (CVE-2026-44413)
vulnerability in jetbrains (CVE-2026-44413). Confidential information can be exposed externally.
|
| CVE-2026-36962 |
|
SQL Injection in sqli (CVE-2026-36962)
SQL injection in sqli (CVE-2026-36962). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61311 |
|
Cross-Site Scripting (XSS) in CVE-2025-61311 (CVE-2025-61311)
cross-site scripting in CVE-2025-61311 (CVE-2025-61311). Confidential information can be exposed externally.
|
| CVE-2025-61312 |
|
Cross-Site Scripting (XSS) in CVE-2025-61312 (CVE-2025-61312)
cross-site scripting in CVE-2025-61312 (CVE-2025-61312). Confidential information can be exposed externally.
|
| CVE-2025-61313 |
|
Cross-Site Scripting (XSS) in CVE-2025-61313 (CVE-2025-61313)
cross-site scripting in CVE-2025-61313 (CVE-2025-61313). Confidential information can be exposed externally.
|
| CVE-2025-61314 |
|
Cross-Site Scripting (XSS) in CVE-2025-61314 (CVE-2025-61314)
cross-site scripting in CVE-2025-61314 (CVE-2025-61314). Confidential information can be exposed externally.
|
| CVE-2026-6433 |
|
Vulnerability in wordpress (CVE-2026-6433)
vulnerability in wordpress (CVE-2026-6433). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-50944 |
|
Code Injection in CVE-2022-50944 (CVE-2022-50944)
code injection in CVE-2022-50944 (CVE-2022-50944). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47943 |
|
Unrestricted File Upload in CVE-2021-47943 (CVE-2021-47943)
vulnerability in CVE-2021-47943 (CVE-2021-47943). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47938 |
|
Code Injection in CVE-2021-47938 (CVE-2021-47938)
code injection in CVE-2021-47938 (CVE-2021-47938). Successful exploitation can lead to full system takeover.
|