Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2018-25386 |
|
SQL Injection in sqli (CVE-2018-25386)
SQL injection in sqli (CVE-2018-25386). Confidential information can be exposed externally.
|
| CVE-2018-25388 |
|
Unrestricted File Upload in CVE-2018-25388 (CVE-2018-25388)
vulnerability in CVE-2018-25388 (CVE-2018-25388). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44495 |
|
Code Injection in axios (CVE-2026-44495)
code injection in axios (CVE-2026-44495). Confidential information can be exposed externally. Exploitable via ``Object.prototype.transformResponse``. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-44494 |
|
Vulnerability in axios (CVE-2026-44494)
vulnerability in axios (CVE-2026-44494). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-44492 |
|
SSRF (Server-Side Request Forgery) in axios (CVE-2026-44492)
SSRF in axios (CVE-2026-44492). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-41236 |
|
Vulnerability in froxlor/froxlor (CVE-2026-41236)
vulnerability in froxlor/froxlor (CVE-2026-41236). Successful exploitation can lead to full system takeover. Exploitable via `POST /customer_ftp.php`. Mitigation: upgrade to `2.3.7` or later.
|
| CVE-2026-39292 |
|
Unrestricted File Upload in CVE-2026-39292 (CVE-2026-39292)
vulnerability in CVE-2026-39292 (CVE-2026-39292). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10062 |
|
Buffer Overflow in trendnet (CVE-2026-10062)
vulnerability in trendnet (CVE-2026-10062). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10063 |
|
Buffer Overflow in trendnet (CVE-2026-10063)
vulnerability in trendnet (CVE-2026-10063). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48501 |
|
Authorization Flaw in github.com/cli/cli/v2 (CVE-2026-48501)
vulnerability in github.com/cli/cli/v2 (CVE-2026-48501). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `2.93.0` or later.
|
| CVE-2026-45555 |
|
Code Injection in csharp (CVE-2026-45555)
code injection in csharp (CVE-2026-45555). Successful exploitation can lead to full system takeover. Exploitable via ``get_diagnostics``. Mitigation: upgrade to `1.17.0` or later.
|
| CVE-2026-45615 |
|
Vulnerability in c (CVE-2026-45615)
vulnerability in c (CVE-2026-45615). Risk of unauthorized operations or information disclosure. Exploitable via ``INTEGER_decode_oer``.
|
| CVE-2026-44698 |
|
Code Injection in CVE-2026-44698 (CVE-2026-44698)
code injection in CVE-2026-44698 (CVE-2026-44698). Successful exploitation can lead to full system takeover. Exploitable via ``window.externalApp``. Mitigation: upgrade to `2026.4.1` or later.
|
| CVE-2026-44237 |
|
Vulnerability in sangoma (CVE-2026-44237)
vulnerability in sangoma (CVE-2026-44237). Confidential information can be exposed externally. Mitigation: upgrade to `17.0.8` or later.
|
| CVE-2026-44238 |
|
SQL Injection in sqli (CVE-2026-44238)
SQL injection in sqli (CVE-2026-44238). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `16.0.50` or later.
|
| CVE-2026-44239 |
|
Vulnerability in path-traversal (CVE-2026-44239)
vulnerability in path-traversal (CVE-2026-44239). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `16.0.22` or later.
|
| CVE-2026-10072 |
|
Unrestricted File Upload in CVE-2026-10072 (CVE-2026-10072)
vulnerability in CVE-2026-10072 (CVE-2026-10072). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10073 |
|
Vulnerability in path-traversal (CVE-2026-10073)
vulnerability in path-traversal (CVE-2026-10073). Confidential information can be exposed externally.
|
| CVE-2026-48527 |
|
Cross-Site Scripting (XSS) in @haxtheweb/haxcms-nodejs (CVE-2026-48527)
cross-site scripting in @haxtheweb/haxcms-nodejs (CVE-2026-48527). Confidential information can be exposed externally. Exploitable via `POST /system/api/saveNode`. Mitigation: upgrade to `26.0.1` or later.
|
| CVE-2025-41281 |
|
OS Command Injection in waterfall-security (CVE-2025-41281)
OS command injection in waterfall-security (CVE-2025-41281). Successful exploitation can lead to full system takeover.
|
| CVE-2025-41278 |
|
Out-of-Bounds Read in waterfall-security (CVE-2025-41278)
vulnerability in waterfall-security (CVE-2025-41278). Successful exploitation can lead to full system takeover.
|
| CVE-2025-41279 |
|
OS Command Injection in waterfall-security (CVE-2025-41279)
OS command injection in waterfall-security (CVE-2025-41279). Successful exploitation can lead to full system takeover.
|
| CVE-2025-41280 |
|
Vulnerability in path-traversal (CVE-2025-41280)
vulnerability in path-traversal (CVE-2025-41280). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42965 |
|
SSRF (Server-Side Request Forgery) in redhat (CVE-2026-42965)
SSRF in redhat (CVE-2026-42965). Confidential information can be exposed externally.
|
| CVE-2026-46579 |
|
Authentication Bypass in redhat (CVE-2026-46579)
authentication bypass in redhat (CVE-2026-46579). Confidential information can be exposed externally. Exploitable via ``insecureEdgeTerminationPolicy``.
|
| CVE-2025-41265 |
|
OS Command Injection in waterfall-security (CVE-2025-41265)
OS command injection in waterfall-security (CVE-2025-41265). Successful exploitation can lead to full system takeover.
|
| CVE-2025-41266 |
|
OS Command Injection in waterfall-security (CVE-2025-41266)
OS command injection in waterfall-security (CVE-2025-41266). Successful exploitation can lead to full system takeover.
|
| CVE-2025-41267 |
|
OS Command Injection in waterfall-security (CVE-2025-41267)
OS command injection in waterfall-security (CVE-2025-41267). Successful exploitation can lead to full system takeover.
|
| CVE-2025-41271 |
|
Vulnerability in path-traversal (CVE-2025-41271)
vulnerability in path-traversal (CVE-2025-41271). Confidential information can be exposed externally.
|
| CVE-2026-9808 |
|
Authorization Flaw in mautic/core (CVE-2026-9808)
vulnerability in mautic/core (CVE-2026-9808). Confidential information can be exposed externally. Exploitable via ``viewown``. Mitigation: upgrade to `7.1.2` or later.
|
| CVE-2026-9809 |
|
Cross-Site Scripting (XSS) in mautic/core (CVE-2026-9809)
cross-site scripting in mautic/core (CVE-2026-9809). Data can be tampered with by attackers. Mitigation: upgrade to `7.1.2` or later.
|
| CVE-2026-52834 |
|
Vulnerability in jxl-grid (CVE-2026-52834)
vulnerability in jxl-grid (CVE-2026-52834). Risk of unauthorized operations or information disclosure. Exploitable via ``usize``. Mitigation: upgrade to `0.6.2` or later.
|
| CVE-2026-6075 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-6075)
vulnerability in wordpress (CVE-2026-6075). Data can be tampered with by attackers.
|
| CVE-2026-10056 |
|
Vulnerability in CVE-2026-10056 (CVE-2026-10056)
vulnerability in CVE-2026-10056 (CVE-2026-10056). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /rest/v2/system/settings`.
|
| CVE-2026-49196 |
|
Command Injection in acer (CVE-2026-49196)
command injection in acer (CVE-2026-49196). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49195 |
|
Vulnerability in acer (CVE-2026-49195)
vulnerability in acer (CVE-2026-49195). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4776 |
|
Mautic has SQL Injection in API Contact Filtering
Mautic has SQL Injection in API Contact Filtering
|
| CVE-2025-11262 |
|
The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
|
| CVE-2025-11993 |
|
Unsafe Deserialization in wordpress (CVE-2025-11993)
vulnerability in wordpress (CVE-2025-11993). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9938 |
|
Code Injection in google (CVE-2026-9938)
code injection in google (CVE-2026-9938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9934 |
|
Use-After-Free in Google chrome (CVE-2026-9934)
vulnerability in Google chrome (CVE-2026-9934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9937 |
|
Use-After-Free in google (CVE-2026-9937)
vulnerability in google (CVE-2026-9937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9948 |
|
Use-After-Free in google (CVE-2026-9948)
vulnerability in google (CVE-2026-9948). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9946 |
|
Use-After-Free in google (CVE-2026-9946)
vulnerability in google (CVE-2026-9946). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9947 |
|
Use-After-Free in google (CVE-2026-9947)
vulnerability in google (CVE-2026-9947). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9951 |
|
Use-After-Free in google (CVE-2026-9951)
vulnerability in google (CVE-2026-9951). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9952 |
|
Use-After-Free in google (CVE-2026-9952)
vulnerability in google (CVE-2026-9952). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9905 |
|
Use-After-Free in google (CVE-2026-9905)
vulnerability in google (CVE-2026-9905). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9909 |
|
Vulnerability in google (CVE-2026-9909)
vulnerability in google (CVE-2026-9909). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9904 |
|
Use-After-Free in google (CVE-2026-9904)
vulnerability in google (CVE-2026-9904). Successful exploitation can lead to full system takeover.
|