Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82447 |
|
Vulnerability in CVE-2026-82447 (CVE-2026-82447)
vulnerability in CVE-2026-82447 (CVE-2026-82447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77939 |
|
Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
|
| CVE-2026-55559 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55559)
code injection in org.yamcs:yamcs-core (CVE-2026-55559). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/instances`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-47727 |
|
Code Injection in CVE-2026-47727 (CVE-2026-47727)
code injection in CVE-2026-47727 (CVE-2026-47727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54718 |
|
Vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718)
vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-57170 |
|
Code Injection in CVE-2026-57170 (CVE-2026-57170)
code injection in CVE-2026-57170 (CVE-2026-57170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77136 |
|
Vulnerability in CVE-2026-77136 (CVE-2026-77136)
vulnerability in CVE-2026-77136 (CVE-2026-77136). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77129 |
|
Vulnerability in CVE-2026-77129 (CVE-2026-77129)
vulnerability in CVE-2026-77129 (CVE-2026-77129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75574 |
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
| CVE-2026-78140 |
|
Vulnerability in CVE-2026-78140 (CVE-2026-78140)
vulnerability in CVE-2026-78140 (CVE-2026-78140). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59989 |
|
Code Injection in phalcon/cphalcon (CVE-2026-59989)
code injection in phalcon/cphalcon (CVE-2026-59989). Risk of unauthorized operations or information disclosure. Exploitable via ``join``. Mitigation: upgrade to `5.16.0` or later.
|
| CVE-2026-72717 |
|
Code Injection in CVE-2026-72717 (CVE-2026-72717)
code injection in CVE-2026-72717 (CVE-2026-72717). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72716 |
|
Vulnerability in CVE-2026-72716 (CVE-2026-72716)
vulnerability in CVE-2026-72716 (CVE-2026-72716). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71871 |
|
Code Injection in CVE-2026-71871 (CVE-2026-71871)
code injection in CVE-2026-71871 (CVE-2026-71871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71869 |
|
Code Injection in CVE-2026-71869 (CVE-2026-71869)
code injection in CVE-2026-71869 (CVE-2026-71869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71868 |
|
Code Injection in CVE-2026-71868 (CVE-2026-71868)
code injection in CVE-2026-71868 (CVE-2026-71868). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62682 |
|
Code Injection in CVE-2026-62682 (CVE-2026-62682)
code injection in CVE-2026-62682 (CVE-2026-62682). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62681 |
|
Code Injection in react (CVE-2026-62681)
code injection in react (CVE-2026-62681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66613 |
|
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
|
| CVE-2026-75979 |
|
Vulnerability in CVE-2026-75979 (CVE-2026-75979)
vulnerability in CVE-2026-75979 (CVE-2026-75979). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71880 |
|
Vulnerability in CVE-2026-71880 (CVE-2026-71880)
vulnerability in CVE-2026-71880 (CVE-2026-71880). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75829 |
|
Vulnerability in CVE-2026-75829 (CVE-2026-75829)
vulnerability in CVE-2026-75829 (CVE-2026-75829). Confidential information can be exposed externally.
|
| CVE-2026-65974 |
|
Vulnerability in CVE-2026-65974 (CVE-2026-65974)
vulnerability in CVE-2026-65974 (CVE-2026-65974). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44845 |
|
Vulnerability in CVE-2026-44845 (CVE-2026-44845)
vulnerability in CVE-2026-44845 (CVE-2026-44845). Confidential information can be exposed externally.
|
| CVE-2026-19929 |
|
Vulnerability in CVE-2026-19929 (CVE-2026-19929)
vulnerability in CVE-2026-19929 (CVE-2026-19929). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72827 |
|
Vulnerability in CVE-2026-72827 (CVE-2026-72827)
vulnerability in CVE-2026-72827 (CVE-2026-72827). Successful exploitation can lead to full system takeover.
|
| CVE-2022-4993 |
|
Vulnerability in CVE-2022-4993 (CVE-2022-4993)
vulnerability in CVE-2022-4993 (CVE-2022-4993). Confidential information can be exposed externally. Exploitable via ``_AUTO``.
|
| CVE-2026-13051 |
|
Vulnerability in CVE-2026-13051 (CVE-2026-13051)
vulnerability in CVE-2026-13051 (CVE-2026-13051). Confidential information can be exposed externally. Exploitable via ``_AUTO``.
|
| CVE-2026-73330 |
|
Vulnerability in rails (CVE-2026-73330)
vulnerability in rails (CVE-2026-73330). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73299 |
|
Code Injection in CVE-2026-73299 (CVE-2026-73299)
code injection in CVE-2026-73299 (CVE-2026-73299). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72911 |
|
Vulnerability in CVE-2026-72911 (CVE-2026-72911)
vulnerability in CVE-2026-72911 (CVE-2026-72911). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69118 |
|
Authorization Flaw in CVE-2026-69118 (CVE-2026-69118)
vulnerability in CVE-2026-69118 (CVE-2026-69118). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71502 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-71502)
cross-site scripting in vue (CVE-2026-71502). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5336 |
|
Information Disclosure in wordpress (CVE-2026-5336)
vulnerability in wordpress (CVE-2026-5336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15734 |
|
Vulnerability in CVE-2026-15734 (CVE-2026-15734)
vulnerability in CVE-2026-15734 (CVE-2026-15734). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71291 |
|
Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
|
| CVE-2026-71286 |
|
Vulnerability in CVE-2026-71286 (CVE-2026-71286)
vulnerability in CVE-2026-71286 (CVE-2026-71286). Risk of unauthorized operations or information disclosure. Exploitable via ``templateString``.
|
| CVE-2026-71239 |
|
Vulnerability in django (CVE-2026-71239)
vulnerability in django (CVE-2026-71239). Confidential information can be exposed externally.
|
| CVE-2026-48323 |
|
Vulnerability in c (CVE-2026-48323)
vulnerability in c (CVE-2026-48323). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18632 |
|
Vulnerability in CVE-2026-18632 (CVE-2026-18632)
vulnerability in CVE-2026-18632 (CVE-2026-18632). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54666 |
|
Vulnerability in swagger-typescript-api (CVE-2026-54666)
vulnerability in swagger-typescript-api (CVE-2026-54666). Successful exploitation can lead to full system takeover. Exploitable via ``paths``. Mitigation: upgrade to `13.12.2` or later.
|
| CVE-2026-54664 |
|
Vulnerability in swagger-typescript-api (CVE-2026-54664)
vulnerability in swagger-typescript-api (CVE-2026-54664). Successful exploitation can lead to full system takeover. Exploitable via ``enum``. Mitigation: upgrade to `13.12.2` or later.
|
| CVE-2026-54661 |
|
Vulnerability in swagger-typescript-api (CVE-2026-54661)
vulnerability in swagger-typescript-api (CVE-2026-54661). Successful exploitation can lead to full system takeover. Exploitable via ``HttpClient``. Mitigation: upgrade to `13.12.2` or later.
|
| CVE-2026-54662 |
|
Vulnerability in swagger-typescript-api (CVE-2026-54662)
vulnerability in swagger-typescript-api (CVE-2026-54662). Successful exploitation can lead to full system takeover. Exploitable via ``HttpClient``. Mitigation: upgrade to `13.12.2` or later.
|
| CVE-2026-9177 |
|
Vulnerability in CVE-2026-9177 (CVE-2026-9177)
vulnerability in CVE-2026-9177 (CVE-2026-9177). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54654 |
|
Code Injection in datamodel-code-generator (CVE-2026-54654)
code injection in datamodel-code-generator (CVE-2026-54654). Successful exploitation can lead to full system takeover. Exploitable via ``comment``. Mitigation: upgrade to `0.60.2` or later.
|
| CVE-2026-54653 |
|
Code Injection in datamodel-code-generator (CVE-2026-54653)
code injection in datamodel-code-generator (CVE-2026-54653). Successful exploitation can lead to full system takeover. Exploitable via ``import``. Mitigation: upgrade to `0.60.2` or later.
|
| CVE-2026-54621 |
|
Code Injection in datamodel-code-generator (CVE-2026-54621)
code injection in datamodel-code-generator (CVE-2026-54621). Successful exploitation can lead to full system takeover. Exploitable via ``import``. Mitigation: upgrade to `0.60.1` or later.
|
| CVE-2026-73505 |
|
Code Injection in github.com/jandedobbeleer/oh-my-posh (CVE-2026-73505)
code injection in github.com/jandedobbeleer/oh-my-posh (CVE-2026-73505). Successful exploitation can lead to full system takeover. Exploitable via ``cmd``. Mitigation: upgrade to `29.35.1` or later.
|
| CVE-2026-47752 |
|
Vulnerability in CVE-2026-47752 (CVE-2026-47752)
vulnerability in CVE-2026-47752 (CVE-2026-47752). Successful exploitation can lead to full system takeover. Exploitable via ``title_template``.
|