Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82472 |
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
| CVE-2026-82473 |
|
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
|
| CVE-2026-82461 |
|
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14494 |
|
Unrestricted File Upload in wordpress (CVE-2026-14494)
vulnerability in wordpress (CVE-2026-14494). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-77939 |
|
Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
|
| CVE-2026-81757 |
|
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
|
| CVE-2026-82244 |
|
Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40013 |
|
Vulnerability in dos (CVE-2026-40013)
vulnerability in dos (CVE-2026-40013). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14558 |
|
Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18983 |
|
Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16759 |
|
Vulnerability in wordpress (CVE-2026-16759)
vulnerability in wordpress (CVE-2026-16759). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38821 |
|
Vulnerability in c (CVE-2026-38821)
vulnerability in c (CVE-2026-38821). Confidential information can be exposed externally.
|
| CVE-2026-61802 |
|
Information Disclosure in CVE-2026-61802 (CVE-2026-61802)
vulnerability in CVE-2026-61802 (CVE-2026-61802). Confidential information can be exposed externally. Exploitable via `GET /cluster/local/config.`.
|
| CVE-2026-61800 |
|
Path Traversal in CVE-2026-61800 (CVE-2026-61800)
path traversal in CVE-2026-61800 (CVE-2026-61800). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5706 |
|
Vulnerability in CVE-2026-5706 (CVE-2026-5706)
vulnerability in CVE-2026-5706 (CVE-2026-5706). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76639 |
|
Path Traversal in path-traversal (CVE-2026-76639)
path traversal in path-traversal (CVE-2026-76639). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53579 |
|
Cross-Site Scripting (XSS) in CVE-2026-53579 (CVE-2026-53579)
cross-site scripting in CVE-2026-53579 (CVE-2026-53579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53578 |
|
Cross-Site Scripting (XSS) in CVE-2026-53578 (CVE-2026-53578)
cross-site scripting in CVE-2026-53578 (CVE-2026-53578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48996 |
|
Cross-Site Scripting (XSS) in CVE-2026-48996 (CVE-2026-48996)
cross-site scripting in CVE-2026-48996 (CVE-2026-48996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47727 |
|
Code Injection in CVE-2026-47727 (CVE-2026-47727)
code injection in CVE-2026-47727 (CVE-2026-47727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37003 |
|
Vulnerability in CVE-2026-37003 (CVE-2026-37003)
vulnerability in CVE-2026-37003 (CVE-2026-37003). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79720 |
|
Cross-Site Scripting (XSS) in CVE-2026-79720 (CVE-2026-79720)
cross-site scripting in CVE-2026-79720 (CVE-2026-79720). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79988 |
|
Vulnerability in CVE-2026-79988 (CVE-2026-79988)
vulnerability in CVE-2026-79988 (CVE-2026-79988). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79719 |
|
Cross-Site Scripting (XSS) in CVE-2026-79719 (CVE-2026-79719)
cross-site scripting in CVE-2026-79719 (CVE-2026-79719). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79718 |
|
Cross-Site Scripting (XSS) in CVE-2026-79718 (CVE-2026-79718)
cross-site scripting in CVE-2026-79718 (CVE-2026-79718). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81581 |
|
Buffer Overflow in privilege-escalation (CVE-2026-81581)
vulnerability in privilege-escalation (CVE-2026-81581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77991 |
|
Unrestricted File Upload in csharp (CVE-2026-77991)
vulnerability in csharp (CVE-2026-77991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77018 |
|
Unrestricted File Upload in wordpress (CVE-2026-77018)
vulnerability in wordpress (CVE-2026-77018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47875 |
|
Unsafe Deserialization in deserialization (CVE-2026-47875)
vulnerability in deserialization (CVE-2026-47875). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47884 |
|
Path Traversal in spring (CVE-2026-47884)
path traversal in spring (CVE-2026-47884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47852 |
|
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
|
| CVE-2026-52103 |
|
Vulnerability in CVE-2026-52103 (CVE-2026-52103)
vulnerability in CVE-2026-52103 (CVE-2026-52103). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71171 |
|
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
|
| CVE-2026-54569 |
|
Vulnerability in senaite.core (CVE-2026-54569)
vulnerability in senaite.core (CVE-2026-54569). Successful exploitation can lead to full system takeover. Exploitable via `GET /senaite/bika_setup/`.
|
| CVE-2026-12717 |
|
Vulnerability in CVE-2026-12717 (CVE-2026-12717)
vulnerability in CVE-2026-12717 (CVE-2026-12717). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77532 |
|
Vulnerability in CVE-2026-77532 (CVE-2026-77532)
vulnerability in CVE-2026-77532 (CVE-2026-77532). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18080 |
|
Unrestricted File Upload in wordpress (CVE-2026-18080)
vulnerability in wordpress (CVE-2026-18080). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18431 |
|
Vulnerability in wordpress (CVE-2026-18431)
vulnerability in wordpress (CVE-2026-18431). Successful exploitation can lead to full system takeover.
|
| CVE-2021-23758 KEV |
|
Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
|
| CVE-2026-54757 |
|
Code Injection in compliance-trestle (CVE-2026-54757)
code injection in compliance-trestle (CVE-2026-54757). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxedEnvironment``. Mitigation: upgrade to `4.1.0` or later.
|
| CVE-2026-75496 |
|
Unrestricted File Upload in CVE-2026-75496 (CVE-2026-75496)
vulnerability in CVE-2026-75496 (CVE-2026-75496). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `153ec1c` or later.
|
| CVE-2026-19912 |
|
Vulnerability in deserialization (CVE-2026-19912)
vulnerability in deserialization (CVE-2026-19912). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79774 |
|
Vulnerability in CVE-2026-79774 (CVE-2026-79774)
vulnerability in CVE-2026-79774 (CVE-2026-79774). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57863 |
|
Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18798 |
|
Vulnerability in dos (CVE-2026-18798)
vulnerability in dos (CVE-2026-18798). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63073 |
|
Vulnerability in dos (CVE-2026-63073)
vulnerability in dos (CVE-2026-63073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79657 |
|
Unsafe Deserialization in CVE-2026-79657 (CVE-2026-79657)
vulnerability in CVE-2026-79657 (CVE-2026-79657). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19949 |
|
SQL Injection in wordpress (CVE-2026-19949)
SQL injection in wordpress (CVE-2026-19949). Successful exploitation can lead to full system takeover.
|