Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-hpwp-xm8p-h5hc |
|
MINI-hpwp-xm8p-h5hc |
| MINI-frfm-q83f-rhww |
|
MINI-frfm-q83f-rhww |
| MINI-v4vv-5688-rvgf |
|
MINI-v4vv-5688-rvgf |
| MINI-xhvv-hmcj-fhxq |
|
MINI-xhvv-hmcj-fhxq |
| MINI-2fjm-f3cg-v7vj |
|
MINI-2fjm-f3cg-v7vj |
| MINI-wjfj-c76f-c93j |
|
MINI-wjfj-c76f-c93j |
| MINI-29g3-85mr-6j22 |
|
MINI-29g3-85mr-6j22 |
| openSUSE-SU-2026:20915-1 |
|
Vulnerability in openSUSE-SU-2026:20915-1 (openSUSE-SU-2026:20915-1)
vulnerability in openSUSE-SU-2026:20915-1 (openSUSE-SU-2026:20915-1). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36785 |
|
Vulnerability in dos (CVE-2026-36785)
vulnerability in dos (CVE-2026-36785). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11422 |
|
Vulnerability in CVE-2026-11422 (CVE-2026-11422)
vulnerability in CVE-2026-11422 (CVE-2026-11422). Confidential information can be exposed externally.
|
| CVE-2026-11423 |
|
Path Traversal in path-traversal (CVE-2026-11423)
path traversal in path-traversal (CVE-2026-11423). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-47321 |
|
DEBIAN-CVE-2026-47321 |
| CVE-2026-47743 |
|
Cross-Site Scripting (XSS) in shopper/framework (CVE-2026-47743)
cross-site scripting in shopper/framework (CVE-2026-47743). Confidential information can be exposed externally. Exploitable via ``Hidden``. Mitigation: upgrade to `2.8.0` or later.
|
| CVE-2026-11400 |
|
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
|
| CVE-2026-46493 |
|
Vulnerability in CVE-2026-46493 (CVE-2026-46493)
vulnerability in CVE-2026-46493 (CVE-2026-46493). Confidential information can be exposed externally. Exploitable via ``uniqid``.
|
| CVE-2026-46401 |
|
Vulnerability in CVE-2026-46401 (CVE-2026-46401)
vulnerability in CVE-2026-46401 (CVE-2026-46401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46400 |
|
Unrestricted File Upload in CVE-2026-46400 (CVE-2026-46400)
vulnerability in CVE-2026-46400 (CVE-2026-46400). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46398 |
|
Vulnerability in CVE-2026-46398 (CVE-2026-46398)
vulnerability in CVE-2026-46398 (CVE-2026-46398). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46397 |
|
Path Traversal in CVE-2026-46397 (CVE-2026-46397)
path traversal in CVE-2026-46397 (CVE-2026-46397). Confidential information can be exposed externally.
|
| CVE-2026-45779 |
|
SQL Injection in sqli (CVE-2026-45779)
SQL injection in sqli (CVE-2026-45779). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45778 |
|
Cross-Site Scripting (XSS) in buffalo (CVE-2026-45778)
cross-site scripting in buffalo (CVE-2026-45778). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45777 |
|
OS Command Injection in buffalo (CVE-2026-45777)
OS command injection in buffalo (CVE-2026-45777). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45776 |
|
Vulnerability in buffalo (CVE-2026-45776)
vulnerability in buffalo (CVE-2026-45776). Risk of unauthorized operations or information disclosure.
|
| DEBIAN-CVE-2026-45300 |
|
Vulnerability in async-http-client (DEBIAN-CVE-2026-45300)
vulnerability in async-http-client (DEBIAN-CVE-2026-45300). Confidential information can be exposed externally. Exploitable via ``Cookie``.
|
| CVE-2026-25624 |
|
Cross-Site Scripting (XSS) in arista (CVE-2026-25624)
cross-site scripting in arista (CVE-2026-25624). Confidential information can be exposed externally.
|
| CVE-2026-25623 |
|
OS Command Injection in arista (CVE-2026-25623)
OS command injection in arista (CVE-2026-25623). Confidential information can be exposed externally.
|
| CVE-2026-25622 |
|
OS Command Injection in arista (CVE-2026-25622)
OS command injection in arista (CVE-2026-25622). Confidential information can be exposed externally.
|
| CVE-2026-25621 |
|
OS Command Injection in arista (CVE-2026-25621)
OS command injection in arista (CVE-2026-25621). Confidential information can be exposed externally.
|
| CVE-2026-25620 |
|
OS Command Injection in arista (CVE-2026-25620)
OS command injection in arista (CVE-2026-25620). Confidential information can be exposed externally.
|
| CVE-2026-11420 |
|
Path Traversal in path-traversal (CVE-2026-11420)
path traversal in path-traversal (CVE-2026-11420). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11419 |
|
Path Traversal in path-traversal (CVE-2026-11419)
path traversal in path-traversal (CVE-2026-11419). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11414 |
|
Path Traversal in path-traversal (CVE-2026-11414)
path traversal in path-traversal (CVE-2026-11414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11401 |
|
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
|
| GHSA-wx3m-whqv-xv47 |
|
Path Traversal in skillctl (GHSA-wx3m-whqv-xv47)
path traversal in skillctl (GHSA-wx3m-whqv-xv47). Risk of unauthorized operations or information disclosure. Exploitable via ``skillctl``. Mitigation: upgrade to `0.1.2` or later.
|
| CVE-2026-5415 |
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
|
| CVE-2026-5411 |
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
|
| CVE-2026-46399 |
|
Vulnerability in CVE-2026-46399 (CVE-2026-46399)
vulnerability in CVE-2026-46399 (CVE-2026-46399). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46394 |
|
OS Command Injection in CVE-2026-46394 (CVE-2026-46394)
OS command injection in CVE-2026-46394 (CVE-2026-46394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46392 |
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filen...
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...
|
| CVE-2026-46390 |
|
Vulnerability in CVE-2026-46390 (CVE-2026-46390)
vulnerability in CVE-2026-46390 (CVE-2026-46390). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46389 |
|
Authentication Bypass in defenseunicorns (CVE-2026-46389)
authentication bypass in defenseunicorns (CVE-2026-46389). Successful exploitation can lead to full system takeover. Exploitable via ``client_secret``.
|
| CVE-2026-10580 |
|
Vulnerability in wordpress (CVE-2026-10580)
vulnerability in wordpress (CVE-2026-10580). Successful exploitation can lead to full system takeover.
|
| MAL-2026-5272 |
|
Vulnerability in goodoltoulas (MAL-2026-5272)
vulnerability in goodoltoulas (MAL-2026-5272). Risk of unauthorized operations or information disclosure. Exploitable via ``requests``.
|
| openSUSE-SU-2026:20912-1 |
|
Vulnerability in openSUSE-SU-2026:20912-1 (openSUSE-SU-2026:20912-1)
vulnerability in openSUSE-SU-2026:20912-1 (openSUSE-SU-2026:20912-1). Risk of unauthorized operations or information disclosure.
|
| CGA-4f2m-9q3j-j5mc |
|
CGA-4f2m-9q3j-j5mc |
| CVE-2026-50733 |
|
Vulnerability in CVE-2026-50733 (CVE-2026-50733)
vulnerability in CVE-2026-50733 (CVE-2026-50733). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
|
| CVE-2026-49493 |
|
Code Injection in CVE-2026-49493 (CVE-2026-49493)
code injection in CVE-2026-49493 (CVE-2026-49493). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
|
| CVE-2026-49492 |
|
OS Command Injection in CVE-2026-49492 (CVE-2026-49492)
OS command injection in CVE-2026-49492 (CVE-2026-49492). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
|
| CVE-2026-45750 |
|
OS Command Injection in termix (CVE-2026-45750)
OS command injection in termix (CVE-2026-45750). Successful exploitation can lead to full system takeover. Exploitable via `GET /ssh/file_manager/ssh/resolvePath`.
|
| CVE-2026-45749 |
|
Vulnerability in termix (CVE-2026-45749)
vulnerability in termix (CVE-2026-45749). Confidential information can be exposed externally. Exploitable via `POST /users/totp/disable`.
|