Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-71832 |
|
Vulnerability in dos (CVE-2026-71832)
vulnerability in dos (CVE-2026-71832). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71509 |
|
Vulnerability in CVE-2026-71509 (CVE-2026-71509)
vulnerability in CVE-2026-71509 (CVE-2026-71509). Data can be tampered with by attackers.
|
| CVE-2026-71508 |
|
Vulnerability in CVE-2026-71508 (CVE-2026-71508)
vulnerability in CVE-2026-71508 (CVE-2026-71508). Data can be tampered with by attackers.
|
| CVE-2026-71507 |
|
Vulnerability in CVE-2026-71507 (CVE-2026-71507)
vulnerability in CVE-2026-71507 (CVE-2026-71507). Data can be tampered with by attackers.
|
| CVE-2026-71506 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
| CVE-2026-71505 |
|
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
|
| CVE-2026-71504 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
| CVE-2026-71503 |
|
Cross-Site Scripting (XSS) in CVE-2026-71503 (CVE-2026-71503)
cross-site scripting in CVE-2026-71503 (CVE-2026-71503). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-39975 |
|
Code Injection in CVE-2026-39975 (CVE-2026-39975)
code injection in CVE-2026-39975 (CVE-2026-39975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30864 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
| CVE-2026-13081 |
|
Vulnerability in CVE-2026-13081 (CVE-2026-13081)
vulnerability in CVE-2026-13081 (CVE-2026-13081). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13047 |
|
Vulnerability in CVE-2026-13047 (CVE-2026-13047)
vulnerability in CVE-2026-13047 (CVE-2026-13047). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-26238 |
|
Code Injection in CVE-2025-26238 (CVE-2025-26238)
code injection in CVE-2025-26238 (CVE-2025-26238). Confidential information can be exposed externally.
|
| CVE-2025-26237 |
|
Command Injection in CVE-2025-26237 (CVE-2025-26237)
command injection in CVE-2025-26237 (CVE-2025-26237). Confidential information can be exposed externally.
|
| CVE-2026-9254 |
|
OS Command Injection in CVE-2026-9254 (CVE-2026-9254)
OS command injection in CVE-2026-9254 (CVE-2026-9254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76838 |
|
SSRF (Server-Side Request Forgery) in laravel (CVE-2026-76838)
SSRF in laravel (CVE-2026-76838). Confidential information can be exposed externally.
|
| CVE-2026-76837 |
|
Cross-Site Scripting (XSS) in CVE-2026-76837 (CVE-2026-76837)
cross-site scripting in CVE-2026-76837 (CVE-2026-76837). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/user/account/`.
|
| CVE-2026-78475 |
|
Out-of-Bounds Read in dos (CVE-2026-78475)
vulnerability in dos (CVE-2026-78475). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71942 |
|
Vulnerability in dos (CVE-2026-71942)
vulnerability in dos (CVE-2026-71942). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76835 |
|
Vulnerability in CVE-2026-76835 (CVE-2026-76835)
vulnerability in CVE-2026-76835 (CVE-2026-76835). Confidential information can be exposed externally.
|
| CVE-2026-76072 |
|
Vulnerability in CVE-2026-76072 (CVE-2026-76072)
vulnerability in CVE-2026-76072 (CVE-2026-76072). Data can be tampered with by attackers.
|
| CVE-2026-76836 |
|
Code Injection in CVE-2026-76836 (CVE-2026-76836)
code injection in CVE-2026-76836 (CVE-2026-76836). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/station/{station_id}/profile/edit`.
|
| CVE-2026-71943 |
|
OS Command Injection in CVE-2026-71943 (CVE-2026-71943)
OS command injection in CVE-2026-71943 (CVE-2026-71943). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76073 |
|
Vulnerability in CVE-2026-76073 (CVE-2026-76073)
vulnerability in CVE-2026-76073 (CVE-2026-76073). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71982 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-71941 |
|
Vulnerability in dos (CVE-2026-71941)
vulnerability in dos (CVE-2026-71941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71937 |
|
Vulnerability in dos (CVE-2026-71937)
vulnerability in dos (CVE-2026-71937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71940 |
|
Vulnerability in dos (CVE-2026-71940)
vulnerability in dos (CVE-2026-71940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71935 |
|
Vulnerability in dos (CVE-2026-71935)
vulnerability in dos (CVE-2026-71935). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71939 |
|
Vulnerability in dos (CVE-2026-71939)
vulnerability in dos (CVE-2026-71939). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71938 |
|
Vulnerability in dos (CVE-2026-71938)
vulnerability in dos (CVE-2026-71938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71936 |
|
Vulnerability in dos (CVE-2026-71936)
vulnerability in dos (CVE-2026-71936). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71934 |
|
Vulnerability in dos (CVE-2026-71934)
vulnerability in dos (CVE-2026-71934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71933 |
|
Vulnerability in CVE-2026-71933 (CVE-2026-71933)
vulnerability in CVE-2026-71933 (CVE-2026-71933). Data can be tampered with by attackers.
|
| CVE-2026-71932 |
|
Path Traversal in path-traversal (CVE-2026-71932)
path traversal in path-traversal (CVE-2026-71932). Confidential information can be exposed externally.
|
| CVE-2026-71931 |
|
OS Command Injection in CVE-2026-71931 (CVE-2026-71931)
OS command injection in CVE-2026-71931 (CVE-2026-71931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71922 |
|
Vulnerability in dos (CVE-2026-71922)
vulnerability in dos (CVE-2026-71922). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71928 |
|
OS Command Injection in CVE-2026-71928 (CVE-2026-71928)
OS command injection in CVE-2026-71928 (CVE-2026-71928). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71926 |
|
OS Command Injection in CVE-2026-71926 (CVE-2026-71926)
OS command injection in CVE-2026-71926 (CVE-2026-71926). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71927 |
|
OS Command Injection in CVE-2026-71927 (CVE-2026-71927)
OS command injection in CVE-2026-71927 (CVE-2026-71927). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71930 |
|
OS Command Injection in CVE-2026-71930 (CVE-2026-71930)
OS command injection in CVE-2026-71930 (CVE-2026-71930). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71929 |
|
OS Command Injection in CVE-2026-71929 (CVE-2026-71929)
OS command injection in CVE-2026-71929 (CVE-2026-71929). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71925 |
|
OS Command Injection in CVE-2026-71925 (CVE-2026-71925)
OS command injection in CVE-2026-71925 (CVE-2026-71925). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71921 |
|
OS Command Injection in CVE-2026-71921 (CVE-2026-71921)
OS command injection in CVE-2026-71921 (CVE-2026-71921). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71917 |
|
OS Command Injection in CVE-2026-71917 (CVE-2026-71917)
OS command injection in CVE-2026-71917 (CVE-2026-71917). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71915 |
|
OS Command Injection in CVE-2026-71915 (CVE-2026-71915)
OS command injection in CVE-2026-71915 (CVE-2026-71915). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71914 |
|
OS Command Injection in CVE-2026-71914 (CVE-2026-71914)
OS command injection in CVE-2026-71914 (CVE-2026-71914). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71919 |
|
OS Command Injection in CVE-2026-71919 (CVE-2026-71919)
OS command injection in CVE-2026-71919 (CVE-2026-71919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71920 |
|
Vulnerability in dos (CVE-2026-71920)
vulnerability in dos (CVE-2026-71920). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`.
|