Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-44510 |
|
Out-of-Bounds Read in CVE-2026-44510 (CVE-2026-44510)
vulnerability in CVE-2026-44510 (CVE-2026-44510). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16324 |
|
Vulnerability in CVE-2026-16324 (CVE-2026-16324)
vulnerability in CVE-2026-16324 (CVE-2026-16324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12900 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12900)
cross-site scripting in wordpress (CVE-2026-12900). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-51316 |
|
Vulnerability in dos (CVE-2024-51316)
vulnerability in dos (CVE-2024-51316). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-51315 |
|
Vulnerability in CVE-2024-51315 (CVE-2024-51315)
vulnerability in CVE-2024-51315 (CVE-2024-51315). Successful exploitation can lead to full system takeover.
|
| CVE-2024-51314 |
|
Vulnerability in CVE-2024-51314 (CVE-2024-51314)
vulnerability in CVE-2024-51314 (CVE-2024-51314). Successful exploitation can lead to full system takeover.
|
| CVE-2024-51312 |
|
Vulnerability in CVE-2024-51312 (CVE-2024-51312)
vulnerability in CVE-2024-51312 (CVE-2024-51312). Successful exploitation can lead to full system takeover.
|
| GHSA-94pj-82f3-465w |
|
Information Disclosure in guzzlehttp/guzzle (GHSA-94pj-82f3-465w)
vulnerability in guzzlehttp/guzzle (GHSA-94pj-82f3-465w). Risk of unauthorized operations or information disclosure. Exploitable via ``CurlHandler``. Mitigation: upgrade to `7.14.2` or later.
|
| CVE-2026-64651 |
|
Authorization Flaw in CVE-2026-64651 (CVE-2026-64651)
vulnerability in CVE-2026-64651 (CVE-2026-64651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64650 |
|
Authorization Flaw in CVE-2026-64650 (CVE-2026-64650)
vulnerability in CVE-2026-64650 (CVE-2026-64650). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58624 |
|
Vulnerability in apache (CVE-2026-58624)
vulnerability in apache (CVE-2026-58624). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56624 |
|
Vulnerability in apache (CVE-2026-56624)
vulnerability in apache (CVE-2026-56624). Confidential information can be exposed externally.
|
| CVE-2026-56623 |
|
Path Traversal in apache (CVE-2026-56623)
path traversal in apache (CVE-2026-56623). Confidential information can be exposed externally.
|
| CVE-2026-56452 |
|
Path Traversal in c (CVE-2026-56452)
path traversal in c (CVE-2026-56452). Data can be tampered with by attackers.
|
| CVE-2026-53596 |
|
Vulnerability in laravel (CVE-2026-53596)
vulnerability in laravel (CVE-2026-53596). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53595 |
|
Vulnerability in laravel (CVE-2026-53595)
vulnerability in laravel (CVE-2026-53595). Confidential information can be exposed externally. Exploitable via `POST /user-setup/{hash}/{invite_sent_at}`.
|
| CVE-2026-53594 |
|
Path Traversal in laravel (CVE-2026-53594)
path traversal in laravel (CVE-2026-53594). Confidential information can be exposed externally.
|
| CVE-2026-47130 |
|
Vulnerability in CVE-2026-47130 (CVE-2026-47130)
vulnerability in CVE-2026-47130 (CVE-2026-47130). Data can be tampered with by attackers. Exploitable via ``member``.
|
| CVE-2026-47129 |
|
Vulnerability in CVE-2026-47129 (CVE-2026-47129)
vulnerability in CVE-2026-47129 (CVE-2026-47129). Data can be tampered with by attackers. Exploitable via ``activateUser``.
|
| CVE-2026-44509 |
|
Vulnerability in CVE-2026-44509 (CVE-2026-44509)
vulnerability in CVE-2026-44509 (CVE-2026-44509). Confidential information can be exposed externally.
|
| CVE-2026-44508 |
|
Vulnerability in CVE-2026-44508 (CVE-2026-44508)
vulnerability in CVE-2026-44508 (CVE-2026-44508). Confidential information can be exposed externally.
|
| CVE-2026-44507 |
|
Authorization Flaw in CVE-2026-44507 (CVE-2026-44507)
vulnerability in CVE-2026-44507 (CVE-2026-44507). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13381 |
|
Vulnerability in vsee (CVE-2026-13381)
vulnerability in vsee (CVE-2026-13381). Confidential information can be exposed externally.
|
| CVE-2026-13380 |
|
Vulnerability in vsee (CVE-2026-13380)
vulnerability in vsee (CVE-2026-13380). Confidential information can be exposed externally.
|
| CVE-2024-51313 |
|
Vulnerability in CVE-2024-51313 (CVE-2024-51313)
vulnerability in CVE-2024-51313 (CVE-2024-51313). Successful exploitation can lead to full system takeover.
|
| CVE-2024-51311 |
|
Vulnerability in CVE-2024-51311 (CVE-2024-51311)
vulnerability in CVE-2024-51311 (CVE-2024-51311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73422 |
|
Cross-Site Scripting (XSS) in astro (CVE-2026-73422)
cross-site scripting in astro (CVE-2026-73422). Risk of unauthorized operations or information disclosure. Exploitable via ``duration``. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-63767 |
|
Unsafe Deserialization in deserialization (CVE-2026-63767)
vulnerability in deserialization (CVE-2026-63767). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63766 |
|
OS Command Injection in CVE-2026-63766 (CVE-2026-63766)
OS command injection in CVE-2026-63766 (CVE-2026-63766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53593 |
|
Unrestricted File Upload in laravel (CVE-2026-53593)
vulnerability in laravel (CVE-2026-53593). Successful exploitation can lead to full system takeover. Exploitable via `POST /uploads/upload`.
|
| CVE-2026-53592 |
|
Vulnerability in laravel (CVE-2026-53592)
vulnerability in laravel (CVE-2026-53592). Risk of unauthorized operations or information disclosure. Exploitable via ``getQueryParam``.
|
| CVE-2026-53591 |
|
Authentication Bypass in laravel (CVE-2026-53591)
authentication bypass in laravel (CVE-2026-53591). Data can be tampered with by attackers. Exploitable via ``last_reply_from``.
|
| CVE-2026-44231 |
|
Information Disclosure in privilege-escalation (CVE-2026-44231)
vulnerability in privilege-escalation (CVE-2026-44231). Confidential information can be exposed externally.
|
| CVE-2026-44230 |
|
Cross-Site Scripting (XSS) in bestpractical (CVE-2026-44230)
cross-site scripting in bestpractical (CVE-2026-44230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44229 |
|
Cross-Site Scripting (XSS) in bestpractical (CVE-2026-44229)
cross-site scripting in bestpractical (CVE-2026-44229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16337 |
|
Privilege Escalation in CVE-2026-16337 (CVE-2026-16337)
vulnerability in CVE-2026-16337 (CVE-2026-16337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15788 |
|
Vulnerability in mobyproject (CVE-2026-15788)
vulnerability in mobyproject (CVE-2026-15788). Confidential information can be exposed externally.
|
| CVE-2026-64619 |
|
Vulnerability in CVE-2026-64619 (CVE-2026-64619)
vulnerability in CVE-2026-64619 (CVE-2026-64619). Confidential information can be exposed externally.
|
| CVE-2026-64194 |
|
Vulnerability in c (CVE-2026-64194)
vulnerability in c (CVE-2026-64194). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64193 |
|
Vulnerability in CVE-2026-64193 (CVE-2026-64193)
vulnerability in CVE-2026-64193 (CVE-2026-64193). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63771 |
|
Vulnerability in CVE-2026-63771 (CVE-2026-63771)
vulnerability in CVE-2026-63771 (CVE-2026-63771). Confidential information can be exposed externally.
|
| CVE-2026-63770 |
|
Vulnerability in CVE-2026-63770 (CVE-2026-63770)
vulnerability in CVE-2026-63770 (CVE-2026-63770). Confidential information can be exposed externally.
|
| CVE-2026-63769 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-63769)
SSRF in c (CVE-2026-63769). Confidential information can be exposed externally.
|
| CVE-2026-63768 |
|
Open Redirect in CVE-2026-63768 (CVE-2026-63768)
vulnerability in CVE-2026-63768 (CVE-2026-63768). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63731 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63731 (CVE-2026-63731)
SSRF in CVE-2026-63731 (CVE-2026-63731). Confidential information can be exposed externally.
|
| CVE-2026-63730 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63730 (CVE-2026-63730)
SSRF in CVE-2026-63730 (CVE-2026-63730). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63108 |
|
Vulnerability in CVE-2026-63108 (CVE-2026-63108)
vulnerability in CVE-2026-63108 (CVE-2026-63108). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63107 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63107 (CVE-2026-63107)
SSRF in CVE-2026-63107 (CVE-2026-63107). Confidential information can be exposed externally. Exploitable via `Host header`.
|
| CVE-2026-62414 |
|
Vulnerability in CVE-2026-62414 (CVE-2026-62414)
vulnerability in CVE-2026-62414 (CVE-2026-62414). Confidential information can be exposed externally.
|
| CVE-2026-61901 |
|
The Joomla extension Hikashop is vulnerable to an open redirect.
The Joomla extension Hikashop is vulnerable to an open redirect.
|