Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-70332 |
|
Cross-Site Scripting (XSS) in ssrf (CVE-2026-70332)
cross-site scripting in ssrf (CVE-2026-70332). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65667 |
|
Vulnerability in microsoft (CVE-2026-65667)
vulnerability in microsoft (CVE-2026-65667). Confidential information can be exposed externally.
|
| CVE-2026-63508 |
|
Vulnerability in microsoft (CVE-2026-63508)
vulnerability in microsoft (CVE-2026-63508). Confidential information can be exposed externally.
|
| CVE-2026-62896 |
|
Authentication Bypass in microsoft (CVE-2026-62896)
authentication bypass in microsoft (CVE-2026-62896). Confidential information can be exposed externally.
|
| CVE-2026-62873 |
|
Vulnerability in microsoft (CVE-2026-62873)
vulnerability in microsoft (CVE-2026-62873). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56161 |
|
Vulnerability in microsoft (CVE-2026-56161)
vulnerability in microsoft (CVE-2026-56161). Confidential information can be exposed externally.
|
| CVE-2026-59115 |
|
Vulnerability in microsoft (CVE-2026-59115)
vulnerability in microsoft (CVE-2026-59115). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50515 |
|
Unsafe Deserialization in deserialization (CVE-2026-50515)
vulnerability in deserialization (CVE-2026-50515). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50481 |
|
Vulnerability in microsoft (CVE-2026-50481)
vulnerability in microsoft (CVE-2026-50481). Confidential information can be exposed externally.
|
| CVE-2026-59118 |
|
Vulnerability in microsoft (CVE-2026-59118)
vulnerability in microsoft (CVE-2026-59118). Confidential information can be exposed externally.
|
| CVE-2026-62830 |
|
Vulnerability in microsoft (CVE-2026-62830)
vulnerability in microsoft (CVE-2026-62830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56162 |
|
Authentication Bypass in microsoft (CVE-2026-56162)
authentication bypass in microsoft (CVE-2026-56162). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70558 |
|
Unrestricted File Upload in CVE-2026-70558 (CVE-2026-70558)
vulnerability in CVE-2026-70558 (CVE-2026-70558). Successful exploitation can lead to full system takeover. Exploitable via `POST /download/uploadFromRsByLocal`.
|
| CVE-2026-67689 |
|
SQL Injection in sqli (CVE-2026-67689)
SQL injection in sqli (CVE-2026-67689). Successful exploitation can lead to full system takeover. Exploitable via ``field``.
|
| CVE-2026-67688 |
|
Unrestricted File Upload in CVE-2026-67688 (CVE-2026-67688)
vulnerability in CVE-2026-67688 (CVE-2026-67688). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67622 |
|
Vulnerability in CVE-2026-67622 (CVE-2026-67622)
vulnerability in CVE-2026-67622 (CVE-2026-67622). Confidential information can be exposed externally.
|
| CVE-2026-65400 KEV |
|
[KEV] Authentication Bypass in Apple macos (CVE-2026-65400)
authentication bypass in Apple macos (CVE-2026-65400). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-53984 |
|
Vulnerability in CVE-2026-53984 (CVE-2026-53984)
vulnerability in CVE-2026-53984 (CVE-2026-53984). Data can be tampered with by attackers.
|
| CVE-2026-48088 |
|
Vulnerability in CVE-2026-48088 (CVE-2026-48088)
vulnerability in CVE-2026-48088 (CVE-2026-48088). Confidential information can be exposed externally. Exploitable via `POST /api/tenants/{tenantId}/staff/{staffId}/crypto`.
|
| CVE-2026-48087 |
|
Authentication Bypass in CVE-2026-48087 (CVE-2026-48087)
authentication bypass in CVE-2026-48087 (CVE-2026-48087). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/auth/register/{userId}`.
|
| CVE-2026-48086 |
|
Privilege Escalation in privilege-escalation (CVE-2026-48086)
vulnerability in privilege-escalation (CVE-2026-48086). Successful exploitation can lead to full system takeover. Exploitable via ``GLOBAL_ADMIN``.
|
| CVE-2026-48085 |
|
Vulnerability in csrf (CVE-2026-48085)
vulnerability in csrf (CVE-2026-48085). Successful exploitation can lead to full system takeover. Exploitable via ``default``.
|
| CVE-2026-3418 |
|
Unrestricted File Upload in CVE-2026-3418 (CVE-2026-3418)
vulnerability in CVE-2026-3418 (CVE-2026-3418). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19175 |
|
Use-After-Free in google (CVE-2026-19175)
vulnerability in google (CVE-2026-19175). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19171 |
|
Use-After-Free in google (CVE-2026-19171)
vulnerability in google (CVE-2026-19171). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19170 |
|
Use-After-Free in google (CVE-2026-19170)
vulnerability in google (CVE-2026-19170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19166 |
|
Use-After-Free in google (CVE-2026-19166)
vulnerability in google (CVE-2026-19166). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19164 |
|
Vulnerability in google (CVE-2026-19164)
vulnerability in google (CVE-2026-19164). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19157 |
|
Out-of-Bounds Write in google (CVE-2026-19157)
out-of-bounds write in google (CVE-2026-19157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19149 |
|
Use-After-Free in google (CVE-2026-19149)
vulnerability in google (CVE-2026-19149). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18367 |
|
Vulnerability in privilege-escalation (CVE-2026-18367)
vulnerability in privilege-escalation (CVE-2026-18367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17032 |
|
Vulnerability in CVE-2026-17032 (CVE-2026-17032)
vulnerability in CVE-2026-17032 (CVE-2026-17032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15734 |
|
Vulnerability in CVE-2026-15734 (CVE-2026-15734)
vulnerability in CVE-2026-15734 (CVE-2026-15734). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15733 |
|
OS Command Injection in CVE-2026-15733 (CVE-2026-15733)
OS command injection in CVE-2026-15733 (CVE-2026-15733). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15732 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-15732 (CVE-2026-15732)
SSRF in CVE-2026-15732 (CVE-2026-15732). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14812 |
|
Vulnerability in wordpress (CVE-2026-14812)
vulnerability in wordpress (CVE-2026-14812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11976 |
|
Vulnerability in CVE-2026-11976 (CVE-2026-11976)
vulnerability in CVE-2026-11976 (CVE-2026-11976). Successful exploitation can lead to full system takeover.
|
| CVE-2025-14561 |
|
Vulnerability in CVE-2025-14561 (CVE-2025-14561)
vulnerability in CVE-2025-14561 (CVE-2025-14561). Confidential information can be exposed externally.
|
| CVE-2026-67261 |
|
OS Command Injection in dell (CVE-2026-67261)
OS command injection in dell (CVE-2026-67261). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66709 |
|
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
|
| CVE-2026-66665 |
|
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
|
| CVE-2026-66662 |
|
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
|
| CVE-2026-66447 |
|
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
|
| CVE-2026-65581 |
|
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
|
| CVE-2026-65579 |
|
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
|
| CVE-2026-65578 |
|
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
|
| CVE-2026-65577 |
|
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
|
| CVE-2026-65576 |
|
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
|
| CVE-2026-65575 |
|
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
|
| CVE-2026-65574 |
|
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
|