Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39519 |
|
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
|
| CVE-2026-39441 |
|
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
|
| CVE-2026-27053 |
|
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
|
| CVE-2026-34901 |
|
Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
|
| CVE-2026-50890 |
|
SQL Injection in sqli (CVE-2026-50890)
SQL injection in sqli (CVE-2026-50890). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50886 |
|
Vulnerability in grumpydictator/firefly-iii (CVE-2026-50886)
vulnerability in grumpydictator/firefly-iii (CVE-2026-50886). Confidential information can be exposed externally.
|
| CVE-2026-50883 |
|
Cross-Site Scripting (XSS) in CVE-2026-50883 (CVE-2026-50883)
cross-site scripting in CVE-2026-50883 (CVE-2026-50883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50887 |
|
SSRF (Server-Side Request Forgery) in shlinkio/shlink (CVE-2026-50887)
SSRF in shlinkio/shlink (CVE-2026-50887). Confidential information can be exposed externally.
|
| CVE-2026-50880 |
|
Code Injection in youtransfer (CVE-2026-50880)
code injection in youtransfer (CVE-2026-50880). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50873 |
|
Unrestricted File Upload in CVE-2026-50873 (CVE-2026-50873)
vulnerability in CVE-2026-50873 (CVE-2026-50873). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49952 |
|
Vulnerability in CVE-2026-49952 (CVE-2026-49952)
vulnerability in CVE-2026-49952 (CVE-2026-49952). Confidential information can be exposed externally.
|
| CVE-2026-50871 |
|
Code Injection in CVE-2026-50871 (CVE-2026-50871)
code injection in CVE-2026-50871 (CVE-2026-50871). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50869 |
|
Path Traversal in path-traversal (CVE-2026-50869)
path traversal in path-traversal (CVE-2026-50869). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50872 |
|
Code Injection in CVE-2026-50872 (CVE-2026-50872)
code injection in CVE-2026-50872 (CVE-2026-50872). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48114 |
|
SQL Injection in sqli (CVE-2026-48114)
SQL injection in sqli (CVE-2026-48114). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38329 |
|
Vulnerability in CVE-2026-38329 (CVE-2026-38329)
vulnerability in CVE-2026-38329 (CVE-2026-38329). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/files/{key}`.
|
| CVE-2026-39196 |
|
SQL Injection in sqli (CVE-2026-39196)
SQL injection in sqli (CVE-2026-39196). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39006 |
|
Vulnerability in org.snmp4j:snmp4j-agent (CVE-2026-39006)
vulnerability in org.snmp4j:snmp4j-agent (CVE-2026-39006). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38812 |
|
SQL Injection in sqli (CVE-2026-38812)
SQL injection in sqli (CVE-2026-38812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38063 |
|
OS Command Injection in CVE-2026-38063 (CVE-2026-38063)
OS command injection in CVE-2026-38063 (CVE-2026-38063). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38062 |
|
OS Command Injection in CVE-2026-38062 (CVE-2026-38062)
OS command injection in CVE-2026-38062 (CVE-2026-38062). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38061 |
|
OS Command Injection in CVE-2026-38061 (CVE-2026-38061)
OS command injection in CVE-2026-38061 (CVE-2026-38061). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38060 |
|
OS Command Injection in CVE-2026-38060 (CVE-2026-38060)
OS command injection in CVE-2026-38060 (CVE-2026-38060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38065 |
|
OS Command Injection in CVE-2026-38065 (CVE-2026-38065)
OS command injection in CVE-2026-38065 (CVE-2026-38065). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38064 |
|
OS Command Injection in CVE-2026-38064 (CVE-2026-38064)
OS command injection in CVE-2026-38064 (CVE-2026-38064). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30120 |
|
Code Injection in remotion (CVE-2026-30120)
code injection in remotion (CVE-2026-30120). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.0.410` or later.
|
| CVE-2026-30121 |
|
Remotion: arbitrary file write vulnerability
Remotion: arbitrary file write vulnerability
|
| CVE-2026-36537 |
|
Vulnerability in CVE-2026-36537 (CVE-2026-36537)
vulnerability in CVE-2026-36537 (CVE-2026-36537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53633 |
|
Vulnerability in @vitest/browser (CVE-2026-53633)
vulnerability in @vitest/browser (CVE-2026-53633). Successful exploitation can lead to full system takeover. Exploitable via ``browser.api.allowWrite``. Mitigation: upgrade to `3.2.5` or later.
|
| CVE-2026-9862 |
|
OS Command Injection in forta (CVE-2026-9862)
OS command injection in forta (CVE-2026-9862). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52704 |
|
Code Injection in CVE-2026-52704 (CVE-2026-52704)
code injection in CVE-2026-52704 (CVE-2026-52704). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25436 |
|
Unrestricted File Upload in wordpress (CVE-2018-25436)
vulnerability in wordpress (CVE-2018-25436). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8935 |
|
Vulnerability in wordpress (CVE-2026-8935)
vulnerability in wordpress (CVE-2026-8935). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11526 |
|
Vulnerability in CVE-2026-11526 (CVE-2026-11526)
vulnerability in CVE-2026-11526 (CVE-2026-11526). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12183 |
|
Authentication Bypass in CVE-2026-12183 (CVE-2026-12183)
authentication bypass in CVE-2026-12183 (CVE-2026-12183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53838 |
|
Vulnerability in openclaw (CVE-2026-53838)
vulnerability in openclaw (CVE-2026-53838). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.5.27` or later.
|
| CVE-2026-53609 |
|
Vulnerability in apostrophe (CVE-2026-53609)
vulnerability in apostrophe (CVE-2026-53609). Confidential information can be exposed externally. Exploitable via ``__proto__``. Mitigation: upgrade to `4.31.0` or later.
|
| CVE-2026-53519 |
|
Path Traversal in github.com/nezhahq/nezha (CVE-2026-53519)
path traversal in github.com/nezhahq/nezha (CVE-2026-53519). Confidential information can be exposed externally. Exploitable via `GET /dashboard../data/config.yaml`. Mitigation: upgrade to `2.0.13` or later.
|
| CVE-2026-41157 |
|
Out-of-Bounds Write in Google chrome (CVE-2026-41157)
out-of-bounds write in Google chrome (CVE-2026-41157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28742 |
|
Vulnerability in CVE-2026-28742 (CVE-2026-28742)
vulnerability in CVE-2026-28742 (CVE-2026-28742). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48558 KEV |
|
[KEV] Vulnerability in Simplehelp simple-help (CVE-2026-48558)
vulnerability in Simplehelp simple-help (CVE-2026-48558). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-44172 |
|
SQL Injection in mariadb (CVE-2026-44172)
SQL injection in mariadb (CVE-2026-44172). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44170 |
|
OS Command Injection in mariadb (CVE-2026-44170)
OS command injection in mariadb (CVE-2026-44170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50091 |
|
Vulnerability in c (CVE-2026-50091)
vulnerability in c (CVE-2026-50091). Confidential information can be exposed externally.
|
| CVE-2026-50090 |
|
Vulnerability in c (CVE-2026-50090)
vulnerability in c (CVE-2026-50090). Confidential information can be exposed externally.
|
| CVE-2026-50086 |
|
Vulnerability in c (CVE-2026-50086)
vulnerability in c (CVE-2026-50086). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50084 |
|
Vulnerability in c (CVE-2026-50084)
vulnerability in c (CVE-2026-50084). Confidential information can be exposed externally.
|
| CVE-2026-50083 |
|
Vulnerability in c (CVE-2026-50083)
vulnerability in c (CVE-2026-50083). Confidential information can be exposed externally.
|
| CVE-2026-6853 |
|
Vulnerability in CVE-2026-6853 (CVE-2026-6853)
vulnerability in CVE-2026-6853 (CVE-2026-6853). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53787 |
|
Unrestricted File Upload in path-traversal (CVE-2026-53787)
vulnerability in path-traversal (CVE-2026-53787). Successful exploitation can lead to full system takeover.
|