Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55855 |
|
SQL Injection in mariadb (CVE-2026-55855)
SQL injection in mariadb (CVE-2026-55855). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-55779 |
|
Cross-Site Scripting (XSS) in silverstripe/versioned (CVE-2026-55779)
cross-site scripting in silverstripe/versioned (CVE-2026-55779). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-82333 |
|
Vulnerability in dos (CVE-2026-82333)
vulnerability in dos (CVE-2026-82333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77037 |
|
Vulnerability in dos (CVE-2026-77037)
vulnerability in dos (CVE-2026-77037). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77078 |
|
Vulnerability in dos (CVE-2026-77078)
vulnerability in dos (CVE-2026-77078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77063 |
|
Vulnerability in CVE-2026-77063 (CVE-2026-77063)
vulnerability in CVE-2026-77063 (CVE-2026-77063). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55854 |
|
Vulnerability in mariadb (CVE-2026-55854)
vulnerability in mariadb (CVE-2026-55854). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-55891 |
|
Vulnerability in privatebin/privatebin (CVE-2026-55891)
vulnerability in privatebin/privatebin (CVE-2026-55891). Risk of unauthorized operations or information disclosure. Exploitable via ``FILTER_SANITIZE_URL``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-55696 |
|
Cross-Site Scripting (XSS) in privatebin/privatebin (CVE-2026-55696)
cross-site scripting in privatebin/privatebin (CVE-2026-55696). Risk of unauthorized operations or information disclosure. Exploitable via ``lang``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-55378 |
|
OS Command Injection in CVE-2026-55378 (CVE-2026-55378)
OS command injection in CVE-2026-55378 (CVE-2026-55378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50980 |
|
Vulnerability in CVE-2026-50980 (CVE-2026-50980)
vulnerability in CVE-2026-50980 (CVE-2026-50980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55215 |
|
Vulnerability in mariadb (CVE-2026-55215)
vulnerability in mariadb (CVE-2026-55215). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-55248 |
|
Vulnerability in plone.app.portlets (CVE-2026-55248)
vulnerability in plone.app.portlets (CVE-2026-55248). Risk of unauthorized operations or information disclosure. Exploitable via ``plone.app.portlets``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-55566 |
|
Cross-Site Scripting (XSS) in org.yamcs:yamcs-core (CVE-2026-55566)
cross-site scripting in org.yamcs:yamcs-core (CVE-2026-55566). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55549 |
|
Cross-Site Scripting (XSS) in org.yamcs:yamcs-core (CVE-2026-55549)
cross-site scripting in org.yamcs:yamcs-core (CVE-2026-55549). Confidential information can be exposed externally. Exploitable via ``fetch``. Mitigation: upgrade to `5.9.4` or later.
|
| CVE-2026-55834 |
|
Open Redirect in github.com/pocket-id/pocket-id/backend (CVE-2026-55834)
vulnerability in github.com/pocket-id/pocket-id/backend (CVE-2026-55834). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.9.0` or later.
|
| CVE-2026-38725 |
|
Cross-Site Scripting (XSS) in CVE-2026-38725 (CVE-2026-38725)
cross-site scripting in CVE-2026-38725 (CVE-2026-38725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15603 |
|
Vulnerability in CVE-2026-15603 (CVE-2026-15603)
vulnerability in CVE-2026-15603 (CVE-2026-15603). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82244 |
|
Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6286 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82090 |
|
Cross-Site Scripting (XSS) in CVE-2026-82090 (CVE-2026-82090)
cross-site scripting in CVE-2026-82090 (CVE-2026-82090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78616 |
|
Cross-Site Scripting (XSS) in CVE-2026-78616 (CVE-2026-78616)
cross-site scripting in CVE-2026-78616 (CVE-2026-78616). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78615 |
|
Cross-Site Scripting (XSS) in CVE-2026-78615 (CVE-2026-78615)
cross-site scripting in CVE-2026-78615 (CVE-2026-78615). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78195 |
|
Cross-Site Scripting (XSS) in CVE-2026-78195 (CVE-2026-78195)
cross-site scripting in CVE-2026-78195 (CVE-2026-78195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78047 |
|
Cross-Site Scripting (XSS) in CVE-2026-78047 (CVE-2026-78047)
cross-site scripting in CVE-2026-78047 (CVE-2026-78047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81931 |
|
Unrestricted File Upload in CVE-2026-81931 (CVE-2026-81931)
vulnerability in CVE-2026-81931 (CVE-2026-81931). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81731 |
|
Cross-Site Scripting (XSS) in CVE-2026-81731 (CVE-2026-81731)
cross-site scripting in CVE-2026-81731 (CVE-2026-81731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59281 |
|
Cross-Site Scripting (XSS) in spring (CVE-2026-59281)
cross-site scripting in spring (CVE-2026-59281). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59286 |
|
Vulnerability in CVE-2026-59286 (CVE-2026-59286)
vulnerability in CVE-2026-59286 (CVE-2026-59286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53579 |
|
Cross-Site Scripting (XSS) in CVE-2026-53579 (CVE-2026-53579)
cross-site scripting in CVE-2026-53579 (CVE-2026-53579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53578 |
|
Cross-Site Scripting (XSS) in CVE-2026-53578 (CVE-2026-53578)
cross-site scripting in CVE-2026-53578 (CVE-2026-53578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48996 |
|
Cross-Site Scripting (XSS) in CVE-2026-48996 (CVE-2026-48996)
cross-site scripting in CVE-2026-48996 (CVE-2026-48996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47727 |
|
Code Injection in CVE-2026-47727 (CVE-2026-47727)
code injection in CVE-2026-47727 (CVE-2026-47727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36102 |
|
Vulnerability in CVE-2026-36102 (CVE-2026-36102)
vulnerability in CVE-2026-36102 (CVE-2026-36102). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54732 |
|
Path Traversal in libreoffice-convert (CVE-2026-54732)
path traversal in libreoffice-convert (CVE-2026-54732). Data can be tampered with by attackers. Exploitable via ``path.basename``. Mitigation: upgrade to `1.8.2` or later.
|
| CVE-2026-75357 |
|
Vulnerability in CVE-2026-75357 (CVE-2026-75357)
vulnerability in CVE-2026-75357 (CVE-2026-75357). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81753 |
|
Cross-Site Scripting (XSS) in CVE-2026-81753 (CVE-2026-81753)
cross-site scripting in CVE-2026-81753 (CVE-2026-81753). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47666 |
|
Cross-Site Scripting (XSS) in CVE-2026-47666 (CVE-2026-47666)
cross-site scripting in CVE-2026-47666 (CVE-2026-47666). Confidential information can be exposed externally.
|
| CVE-2026-75331 |
|
Unrestricted File Upload in CVE-2026-75331 (CVE-2026-75331)
vulnerability in CVE-2026-75331 (CVE-2026-75331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16809 |
|
Cross-Site Scripting (XSS) in CVE-2026-16809 (CVE-2026-16809)
cross-site scripting in CVE-2026-16809 (CVE-2026-16809). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39275 |
|
Cross-Site Scripting (XSS) in CVE-2026-39275 (CVE-2026-39275)
cross-site scripting in CVE-2026-39275 (CVE-2026-39275). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66003 |
|
Authorization Flaw in CVE-2026-66003 (CVE-2026-66003)
vulnerability in CVE-2026-66003 (CVE-2026-66003). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80348 |
|
Vulnerability in CVE-2026-80348 (CVE-2026-80348)
vulnerability in CVE-2026-80348 (CVE-2026-80348). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81033 |
|
Vulnerability in CVE-2026-81033 (CVE-2026-81033)
vulnerability in CVE-2026-81033 (CVE-2026-81033). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81031 |
|
Vulnerability in CVE-2026-81031 (CVE-2026-81031)
vulnerability in CVE-2026-81031 (CVE-2026-81031). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54606 |
|
Cross-Site Scripting (XSS) in suneditor (CVE-2026-54606)
cross-site scripting in suneditor (CVE-2026-54606). Risk of unauthorized operations or information disclosure. Exploitable via `GET /poc.js`. Mitigation: upgrade to `3.1.4` or later.
|
| CVE-2026-18331 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18331)
cross-site scripting in wordpress (CVE-2026-18331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19760 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19760)
cross-site scripting in wordpress (CVE-2026-19760). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-73335 |
|
Vulnerability in CVE-2026-73335 (CVE-2026-73335)
vulnerability in CVE-2026-73335 (CVE-2026-73335). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16645 |
|
Vulnerability in drupal (CVE-2026-16645)
vulnerability in drupal (CVE-2026-16645). Confidential information can be exposed externally.
|