Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48900 |
|
Vulnerability in joomla (CVE-2026-48900)
vulnerability in joomla (CVE-2026-48900). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-48901 |
|
Vulnerability in joomla (CVE-2026-48901)
vulnerability in joomla (CVE-2026-48901). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-48902 |
|
Vulnerability in joomla (CVE-2026-48902)
vulnerability in joomla (CVE-2026-48902). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-40383 |
|
Joomla! Core - [20260509] - LFI in HTMLView layout parameter
Joomla! Core - [20260509] - LFI in HTMLView layout parameter
|
| CVE-2026-40384 |
|
Path Traversal in joomla (CVE-2026-40384)
path traversal in joomla (CVE-2026-40384). Confidential information can be exposed externally. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-35223 |
|
Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints
|
| CVE-2026-35220 |
|
Cross-Site Request Forgery (CSRF) in joomla (CVE-2026-35220)
vulnerability in joomla (CVE-2026-35220). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.1` or later.
|
| CVE-2026-35221 |
|
SQL Injection in joomla (CVE-2026-35221)
SQL injection in joomla (CVE-2026-35221). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.4.6, 6.1.1` or later.
|
| CVE-2026-35222 |
|
Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
|
| CVE-2026-30895 |
|
Joomla! Core - [20260504] - XSS in readmore links
Joomla! Core - [20260504] - XSS in readmore links
|
| CVE-2026-25900 |
|
Joomla! Core - [20260501] - XSS in feed modules
Joomla! Core - [20260501] - XSS in feed modules
|
| CVE-2026-25901 |
|
Joomla! Core - [20260502] - XSS in com_associations
Joomla! Core - [20260502] - XSS in com_associations
|
| CVE-2026-30894 |
|
Joomla! Core - [20260503] - XSS in com_contenthistory
Joomla! Core - [20260503] - XSS in com_contenthistory
|
| CVE-2026-40564 |
|
Vulnerability in apache (CVE-2026-40564)
vulnerability in apache (CVE-2026-40564). Confidential information can be exposed externally.
|
| CVE-2026-8174 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-8174)
vulnerability in wordpress (CVE-2026-8174). Data can be tampered with by attackers.
|
| CVE-2026-43828 |
|
Vulnerability in org.apache.shiro:shiro-web (CVE-2026-43828)
vulnerability in org.apache.shiro:shiro-web (CVE-2026-43828). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-44598 |
|
Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-43827 |
|
Vulnerability in org.apache.shiro:shiro-core (CVE-2026-43827)
vulnerability in org.apache.shiro:shiro-core (CVE-2026-43827). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-48589 |
|
Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-48589)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-48589). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-42782 |
|
Vulnerability in org.apache.syncope.core:syncope-core-spring (CVE-2026-42782)
vulnerability in org.apache.syncope.core:syncope-core-spring (CVE-2026-42782). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-42797 |
|
Vulnerability in org.apache.syncope.core:syncope-core-provisioning-api (CVE-2026-42797)
vulnerability in org.apache.syncope.core:syncope-core-provisioning-api (CVE-2026-42797). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-46745 |
|
Vulnerability in apache-airflow-providers-fab (CVE-2026-46745)
vulnerability in apache-airflow-providers-fab (CVE-2026-46745). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.4` or later.
|
| CVE-2026-45361 |
|
Vulnerability in apache-airflow-providers-google (CVE-2026-45361)
vulnerability in apache-airflow-providers-google (CVE-2026-45361). Successful exploitation can lead to full system takeover. Exploitable via ``ComputeEngineSSHHook``. Mitigation: upgrade to `22.0.0` or later.
|
| CVE-2026-45249 |
|
Cross-Site Scripting (XSS) in echarts (CVE-2026-45249)
cross-site scripting in echarts (CVE-2026-45249). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.0` or later.
|
| CVE-2026-9374 |
|
Vulnerability in vue (CVE-2026-9374)
vulnerability in vue (CVE-2026-9374). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9349 |
|
Information Disclosure in react (CVE-2026-9349)
vulnerability in react (CVE-2026-9349). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25347 |
|
SQL Injection in wordpress (CVE-2018-25347)
SQL injection in wordpress (CVE-2018-25347). Confidential information can be exposed externally.
|
| CVE-2018-25352 |
|
SQL Injection in wordpress (CVE-2018-25352)
SQL injection in wordpress (CVE-2018-25352). Confidential information can be exposed externally.
|
| CVE-2018-25346 |
|
SQL Injection in wordpress (CVE-2018-25346)
SQL injection in wordpress (CVE-2018-25346). Confidential information can be exposed externally.
|
| CVE-2026-6898 |
|
Privilege Escalation in wordpress (CVE-2026-6898)
vulnerability in wordpress (CVE-2026-6898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9284 |
|
Vulnerability in wordpress (CVE-2026-9284)
vulnerability in wordpress (CVE-2026-9284). Confidential information can be exposed externally.
|
| CVE-2026-6419 |
|
Privilege Escalation in wordpress (CVE-2026-6419)
vulnerability in wordpress (CVE-2026-6419). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6895 |
|
Privilege Escalation in wordpress (CVE-2026-6895)
vulnerability in wordpress (CVE-2026-6895). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6897 |
|
Privilege Escalation in wordpress (CVE-2026-6897)
vulnerability in wordpress (CVE-2026-6897). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8347 |
|
Vulnerability in concrete5/concrete5 (CVE-2026-8347)
vulnerability in concrete5/concrete5 (CVE-2026-8347). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-9256 |
|
Vulnerability in nginx (CVE-2026-9256)
vulnerability in nginx (CVE-2026-9256). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.24.0, 1.30.2, 1.31.1` or later.
|
| CVE-2026-44930 |
|
Vulnerability in org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (CVE-2026-44930)
vulnerability in org.apache.cxf.services.xkms:cxf-services-xkms-x509-repo-ldap (CVE-2026-44930). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.11` or later.
|
| CVE-2026-44618 |
|
XXE (XML External Entity) in org.apache.cxf:cxf-rt-ws-transfer (CVE-2026-44618)
vulnerability in org.apache.cxf:cxf-rt-ws-transfer (CVE-2026-44618). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.11` or later.
|
| CVE-2026-44417 |
|
Vulnerability in org.apache.cxf:cxf-rt-transports-jms (CVE-2026-44417)
vulnerability in org.apache.cxf:cxf-rt-transports-jms (CVE-2026-44417). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.11` or later.
|
| CVE-2026-46715 |
|
Authentication Bypass in Flask-Security-Too (CVE-2026-46715)
authentication bypass in Flask-Security-Too (CVE-2026-46715). Risk of unauthorized operations or information disclosure. Exploitable via `POST /change-username`. Mitigation: upgrade to `5.8.1` or later.
|
| CVE-2026-7615 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-7615)
vulnerability in wordpress (CVE-2026-7615). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7636 |
|
Information Disclosure in wordpress (CVE-2026-7636)
vulnerability in wordpress (CVE-2026-7636). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8679 |
|
Vulnerability in wordpress (CVE-2026-8679)
vulnerability in wordpress (CVE-2026-8679). Confidential information can be exposed externally.
|
| CVE-2026-7798 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-7798)
SSRF in wordpress (CVE-2026-7798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8684 |
|
Vulnerability in wordpress (CVE-2026-8684)
vulnerability in wordpress (CVE-2026-8684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8692 |
|
Vulnerability in wordpress (CVE-2026-8692)
vulnerability in wordpress (CVE-2026-8692). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9011 |
|
Vulnerability in wordpress (CVE-2026-9011)
vulnerability in wordpress (CVE-2026-9011). Confidential information can be exposed externally.
|
| CVE-2026-9018 |
|
Privilege Escalation in wordpress (CVE-2026-9018)
vulnerability in wordpress (CVE-2026-9018). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_eel_register``.
|
| CVE-2026-9104 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9104)
cross-site scripting in wordpress (CVE-2026-9104). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4070 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-4070)
vulnerability in wordpress (CVE-2026-4070). Risk of unauthorized operations or information disclosure.
|