Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2025-68851 Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
CVE-2026-23970 Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.
CVE-2026-27333 Unsafe Deserialization in deserialization (CVE-2026-27333)
vulnerability in deserialization (CVE-2026-27333). Successful exploitation can lead to full system takeover.
CVE-2026-24637 Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
CVE-2026-34898 Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
CVE-2026-34886 Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
CVE-2026-34891 Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
CVE-2026-27407 Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
CVE-2026-39435 Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
CVE-2026-39434 Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
CVE-2026-34900 Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
CVE-2026-34902 Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.
CVE-2025-59133 Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
CVE-2026-48708 Vulnerability in github.com/OliveTin/OliveTin (CVE-2026-48708)
vulnerability in github.com/OliveTin/OliveTin (CVE-2026-48708). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.0-20260521225117-d74da9314005` or later.
CVE-2026-54283 Vulnerability in starlette (CVE-2026-54283)
vulnerability in starlette (CVE-2026-54283). Risk of unauthorized operations or information disclosure. Exploitable via ``max_fields``. Mitigation: upgrade to `1.3.1` or later.
CVE-2026-53539 Vulnerability in python-multipart (CVE-2026-53539)
vulnerability in python-multipart (CVE-2026-53539). Risk of unauthorized operations or information disclosure. Exploitable via ``QuerystringParser``. Mitigation: upgrade to `0.0.30` or later.
CVE-2026-49853 Information Disclosure in tornado (CVE-2026-49853)
vulnerability in tornado (CVE-2026-49853). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `6.5.6` or later.
CVE-2026-49855 Vulnerability in tornado (CVE-2026-49855)
vulnerability in tornado (CVE-2026-49855). Risk of unauthorized operations or information disclosure. Exploitable via ``HTTPServer``. Mitigation: upgrade to `6.5.6` or later.
CVE-2026-53703 Out-of-Bounds Read in CVE-2026-53703 (CVE-2026-53703)
vulnerability in CVE-2026-53703 (CVE-2026-53703). Risk of unauthorized operations or information disclosure.
CVE-2026-53705 Vulnerability in CVE-2026-53705 (CVE-2026-53705)
vulnerability in CVE-2026-53705 (CVE-2026-53705). Risk of unauthorized operations or information disclosure.
CVE-2026-53704 Out-of-Bounds Read in CVE-2026-53704 (CVE-2026-53704)
vulnerability in CVE-2026-53704 (CVE-2026-53704). Risk of unauthorized operations or information disclosure.
CVE-2026-52722 Vulnerability in CVE-2026-52722 (CVE-2026-52722)
vulnerability in CVE-2026-52722 (CVE-2026-52722). Risk of unauthorized operations or information disclosure.
CVE-2026-52720 Vulnerability in CVE-2026-52720 (CVE-2026-52720)
vulnerability in CVE-2026-52720 (CVE-2026-52720). Successful exploitation can lead to full system takeover.
CVE-2026-52719 Out-of-Bounds Read in CVE-2026-52719 (CVE-2026-52719)
vulnerability in CVE-2026-52719 (CVE-2026-52719). Risk of unauthorized operations or information disclosure.
CVE-2026-50891 Vulnerability in github.com/mickael-kerjean/filestash (CVE-2026-50891)
vulnerability in github.com/mickael-kerjean/filestash (CVE-2026-50891). Confidential information can be exposed externally.
CVE-2026-50889 Vulnerability in dos (CVE-2026-50889)
vulnerability in dos (CVE-2026-50889). Risk of unauthorized operations or information disclosure.
CVE-2026-50885 Vulnerability in CVE-2026-50885 (CVE-2026-50885)
vulnerability in CVE-2026-50885 (CVE-2026-50885). Confidential information can be exposed externally.
CVE-2026-50882 Vulnerability in dos (CVE-2026-50882)
vulnerability in dos (CVE-2026-50882). Risk of unauthorized operations or information disclosure.
CVE-2026-50881 Vulnerability in CVE-2026-50881 (CVE-2026-50881)
vulnerability in CVE-2026-50881 (CVE-2026-50881). Confidential information can be exposed externally.
CVE-2026-50884 Vulnerability in github.com/statping-ng/statping-ng (CVE-2026-50884)
vulnerability in github.com/statping-ng/statping-ng (CVE-2026-50884). Successful exploitation can lead to full system takeover.
CVE-2026-50888 SSRF (Server-Side Request Forgery) in koillection/koillection (CVE-2026-50888)
SSRF in koillection/koillection (CVE-2026-50888). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.4` or later.
CVE-2026-50878 Vulnerability in dos (CVE-2026-50878)
vulnerability in dos (CVE-2026-50878). Risk of unauthorized operations or information disclosure.
CVE-2026-50877 Path Traversal in path-traversal (CVE-2026-50877)
path traversal in path-traversal (CVE-2026-50877). Confidential information can be exposed externally.
CVE-2026-48818 SSRF (Server-Side Request Forgery) in starlette (CVE-2026-48818)
SSRF in starlette (CVE-2026-48818). Confidential information can be exposed externally. Exploitable via ``StaticFiles``. Mitigation: upgrade to `1.1.0` or later.
CVE-2026-50875 Vulnerability in CVE-2026-50875 (CVE-2026-50875)
vulnerability in CVE-2026-50875 (CVE-2026-50875). Data can be tampered with by attackers.
CVE-2026-50874 OS Command Injection in CVE-2026-50874 (CVE-2026-50874)
OS command injection in CVE-2026-50874 (CVE-2026-50874). Confidential information can be exposed externally.
CVE-2026-50879 Vulnerability in github.com/andreimarcu/linx-server (CVE-2026-50879)
vulnerability in github.com/andreimarcu/linx-server (CVE-2026-50879). Risk of unauthorized operations or information disclosure.
CVE-2026-50870 Information Disclosure in CVE-2026-50870 (CVE-2026-50870)
vulnerability in CVE-2026-50870 (CVE-2026-50870). Confidential information can be exposed externally.
CVE-2026-49954 Vulnerability in path-traversal (CVE-2026-49954)
vulnerability in path-traversal (CVE-2026-49954). Successful exploitation can lead to full system takeover.
CVE-2026-47835 Vulnerability in CVE-2026-47835 (CVE-2026-47835)
vulnerability in CVE-2026-47835 (CVE-2026-47835). Confidential information can be exposed externally.
CVE-2026-39007 Information Disclosure in CVE-2026-39007 (CVE-2026-39007)
vulnerability in CVE-2026-39007 (CVE-2026-39007). Confidential information can be exposed externally.
CVE-2026-41708 Vulnerability in dos (CVE-2026-41708)
vulnerability in dos (CVE-2026-41708). Risk of unauthorized operations or information disclosure.
CVE-2026-39118 Privilege Escalation in CVE-2026-39118 (CVE-2026-39118)
vulnerability in CVE-2026-39118 (CVE-2026-39118). Successful exploitation can lead to full system takeover.
CVE-2026-36670 SQL Injection in sqli (CVE-2026-36670)
SQL injection in sqli (CVE-2026-36670). Successful exploitation can lead to full system takeover.
CVE-2026-36213 Privilege Escalation in CVE-2026-36213 (CVE-2026-36213)
vulnerability in CVE-2026-36213 (CVE-2026-36213). Successful exploitation can lead to full system takeover.
CVE-2025-68713 Vulnerability in CVE-2025-68713 (CVE-2025-68713)
vulnerability in CVE-2025-68713 (CVE-2025-68713). Successful exploitation can lead to full system takeover.
CVE-2025-56814 Command Injection in CVE-2025-56814 (CVE-2025-56814)
command injection in CVE-2025-56814 (CVE-2025-56814). Successful exploitation can lead to full system takeover.
CVE-2026-54271 Code Injection in protobufjs-cli (CVE-2026-54271)
code injection in protobufjs-cli (CVE-2026-54271). Confidential information can be exposed externally. Exploitable via ``pbjs``. Mitigation: upgrade to `2.5.0` or later.
CVE-2026-54274 Vulnerability in aiohttp (CVE-2026-54274)
vulnerability in aiohttp (CVE-2026-54274). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.1` or later.
CVE-2026-54275 Vulnerability in aiohttp (CVE-2026-54275)
vulnerability in aiohttp (CVE-2026-54275). Risk of unauthorized operations or information disclosure. Exploitable via ``server_hostname``. Mitigation: upgrade to `3.14.1` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →