Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-56705 |
|
Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56707 |
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
| CVE-2026-56706 |
|
Vulnerability in csrf (CVE-2026-56706)
vulnerability in csrf (CVE-2026-56706). Data can be tampered with by attackers.
|
| CVE-2026-56703 |
|
Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56702 |
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
| CVE-2026-19801 |
|
Vulnerability in wordpress (CVE-2026-19801)
vulnerability in wordpress (CVE-2026-19801). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34968 |
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
| CVE-2026-16434 |
|
Vulnerability in CVE-2026-16434 (CVE-2026-16434)
vulnerability in CVE-2026-16434 (CVE-2026-16434). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5.1` or later.
|
| CVE-2026-34967 |
|
Vulnerability in path-traversal (CVE-2026-34967)
vulnerability in path-traversal (CVE-2026-34967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15023 |
|
SQL Injection in wordpress (CVE-2026-15023)
SQL injection in wordpress (CVE-2026-15023). Confidential information can be exposed externally.
|
| CVE-2026-10630 |
|
Vulnerability in wordpress (CVE-2026-10630)
vulnerability in wordpress (CVE-2026-10630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78434 |
|
Authentication Bypass in CVE-2026-78434 (CVE-2026-78434)
authentication bypass in CVE-2026-78434 (CVE-2026-78434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78435 |
|
Path Traversal in path-traversal (CVE-2026-78435)
path traversal in path-traversal (CVE-2026-78435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78265 |
|
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
|
| CVE-2026-78262 |
|
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
|
| CVE-2026-32560 |
|
Vulnerability in wordpress (CVE-2026-32560)
vulnerability in wordpress (CVE-2026-32560). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32563 |
|
Unsafe Deserialization in wordpress (CVE-2026-32563)
vulnerability in wordpress (CVE-2026-32563). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77567 |
|
Authentication Bypass in laravel (CVE-2026-77567)
authentication bypass in laravel (CVE-2026-77567). Confidential information can be exposed externally.
|
| CVE-2026-77634 |
|
Vulnerability in CVE-2026-77634 (CVE-2026-77634)
vulnerability in CVE-2026-77634 (CVE-2026-77634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77635 |
|
SQL Injection in sqli (CVE-2026-77635)
SQL injection in sqli (CVE-2026-77635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77923 |
|
Authorization Flaw in CVE-2026-77923 (CVE-2026-77923)
vulnerability in CVE-2026-77923 (CVE-2026-77923). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77310 |
|
SSRF (Server-Side Request Forgery) in csharp (CVE-2026-77310)
SSRF in csharp (CVE-2026-77310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61419 |
|
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
|
| CVE-2026-71504 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-13081 |
|
Vulnerability in CVE-2026-13081 (CVE-2026-13081)
vulnerability in CVE-2026-13081 (CVE-2026-13081). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13047 |
|
Vulnerability in CVE-2026-13047 (CVE-2026-13047)
vulnerability in CVE-2026-13047 (CVE-2026-13047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76838 |
|
SSRF (Server-Side Request Forgery) in laravel (CVE-2026-76838)
SSRF in laravel (CVE-2026-76838). Confidential information can be exposed externally.
|
| CVE-2026-76836 |
|
Code Injection in CVE-2026-76836 (CVE-2026-76836)
code injection in CVE-2026-76836 (CVE-2026-76836). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/station/{station_id}/profile/edit`.
|
| CVE-2026-78329 |
|
Vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329)
vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-77915 |
|
Vulnerability in CVE-2026-77915 (CVE-2026-77915)
vulnerability in CVE-2026-77915 (CVE-2026-77915). Successful exploitation can lead to full system takeover. Exploitable via `POST /register`.
|
| CVE-2026-66906 |
|
Vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906)
vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-66907 |
|
Vulnerability in org.apache.camel:camel-google-storage (CVE-2026-66907)
vulnerability in org.apache.camel:camel-google-storage (CVE-2026-66907). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-66908 |
|
Authentication Bypass in org.apache.camel:camel-platform-http-main (CVE-2026-66908)
authentication bypass in org.apache.camel:camel-platform-http-main (CVE-2026-66908). Data can be tampered with by attackers. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-71300 |
|
Vulnerability in org.apache.camel:camel-atmosphere-websocket (CVE-2026-71300)
vulnerability in org.apache.camel:camel-atmosphere-websocket (CVE-2026-71300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-59230 |
|
Vulnerability in org.apache.camel:camel-mail (CVE-2026-59230)
vulnerability in org.apache.camel:camel-mail (CVE-2026-59230). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-63621 |
|
Vulnerability in org.apache.camel:camel-knative (CVE-2026-63621)
vulnerability in org.apache.camel:camel-knative (CVE-2026-63621). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-60093 |
|
Vulnerability in org.apache.camel:camel-azure-storage-datalake (CVE-2026-60093)
vulnerability in org.apache.camel:camel-azure-storage-datalake (CVE-2026-60093). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-75099 |
|
Information Disclosure in apache (CVE-2026-75099)
vulnerability in apache (CVE-2026-75099). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78416 |
|
Vulnerability in CVE-2026-78416 (CVE-2026-78416)
vulnerability in CVE-2026-78416 (CVE-2026-78416). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65053 |
|
Cross-Site Scripting (XSS) in CVE-2026-65053 (CVE-2026-65053)
cross-site scripting in CVE-2026-65053 (CVE-2026-65053). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78248 |
|
Vulnerability in sqli (CVE-2026-78248)
vulnerability in sqli (CVE-2026-78248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78247 |
|
Vulnerability in sqli (CVE-2026-78247)
vulnerability in sqli (CVE-2026-78247). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78323 |
|
Vulnerability in CVE-2026-78323 (CVE-2026-78323)
vulnerability in CVE-2026-78323 (CVE-2026-78323). Confidential information can be exposed externally.
|
| CVE-2026-28153 |
|
Vulnerability in wordpress (CVE-2026-28153)
vulnerability in wordpress (CVE-2026-28153). Confidential information can be exposed externally.
|
| CVE-2026-32558 |
|
Vulnerability in wordpress (CVE-2026-32558)
vulnerability in wordpress (CVE-2026-32558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78246 |
|
Vulnerability in sqli (CVE-2026-78246)
vulnerability in sqli (CVE-2026-78246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66650 |
|
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
|
| CVE-2026-78244 |
|
Vulnerability in sqli (CVE-2026-78244)
vulnerability in sqli (CVE-2026-78244). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78245 |
|
Vulnerability in CVE-2026-78245 (CVE-2026-78245)
vulnerability in CVE-2026-78245 (CVE-2026-78245). Risk of unauthorized operations or information disclosure.
|