Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66395 |
|
Cross-Site Scripting (XSS) in CVE-2026-66395 (CVE-2026-66395)
cross-site scripting in CVE-2026-66395 (CVE-2026-66395). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66396 |
|
Cross-Site Scripting (XSS) in CVE-2026-66396 (CVE-2026-66396)
cross-site scripting in CVE-2026-66396 (CVE-2026-66396). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54272 |
|
Vulnerability in ip-address (CVE-2026-54272)
vulnerability in ip-address (CVE-2026-54272). Risk of unauthorized operations or information disclosure. Exploitable via ``Address6``. Mitigation: upgrade to `10.2.1` or later.
|
| CVE-2026-17514 |
|
Path Traversal in path-traversal (CVE-2026-17514)
path traversal in path-traversal (CVE-2026-17514). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14856 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-14856)
cross-site scripting in csrf (CVE-2026-14856). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55968 |
|
Vulnerability in apache (CVE-2026-55968)
vulnerability in apache (CVE-2026-55968). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14827 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14827)
cross-site scripting in wordpress (CVE-2026-14827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14190 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14190)
cross-site scripting in wordpress (CVE-2026-14190). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14203 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14203)
cross-site scripting in wordpress (CVE-2026-14203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17496 |
|
Cross-Site Scripting (XSS) in notegen (CVE-2026-17496)
cross-site scripting in notegen (CVE-2026-17496). Confidential information can be exposed externally.
|
| CVE-2026-17497 |
|
OS Command Injection in notegen (CVE-2026-17497)
OS command injection in notegen (CVE-2026-17497). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73647 |
|
Vulnerability in quasar (CVE-2026-73647)
vulnerability in quasar (CVE-2026-73647). Risk of unauthorized operations or information disclosure. Exploitable via ``__proto__``. Mitigation: upgrade to `2.22.0` or later.
|
| CVE-2026-73413 |
|
Vulnerability in shescape (CVE-2026-73413)
vulnerability in shescape (CVE-2026-73413). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73411 |
|
Vulnerability in shescape (CVE-2026-73411)
vulnerability in shescape (CVE-2026-73411). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73414 |
|
OS Command Injection in shescape (CVE-2026-73414)
OS command injection in shescape (CVE-2026-73414). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73412 |
|
OS Command Injection in shescape (CVE-2026-73412)
OS command injection in shescape (CVE-2026-73412). Risk of unauthorized operations or information disclosure. Exploitable via ``shell``. Mitigation: upgrade to `3.0.1` or later.
|
| CVE-2026-73567 |
|
Vulnerability in sm-crypto (CVE-2026-73567)
vulnerability in sm-crypto (CVE-2026-73567). Confidential information can be exposed externally. Exploitable via ``SecureRandom``. Mitigation: upgrade to `0.5.0` or later.
|
| CVE-2026-73561 |
|
Vulnerability in @anephenix/hub (CVE-2026-73561)
vulnerability in @anephenix/hub (CVE-2026-73561). Risk of unauthorized operations or information disclosure. Exploitable via ``setInterval``. Mitigation: upgrade to `0.2.16` or later.
|
| CVE-2026-57531 |
|
Cross-Site Scripting (XSS) in CVE-2026-57531 (CVE-2026-57531)
cross-site scripting in CVE-2026-57531 (CVE-2026-57531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57530 |
|
Cross-Site Scripting (XSS) in CVE-2026-57530 (CVE-2026-57530)
cross-site scripting in CVE-2026-57530 (CVE-2026-57530). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73643 |
|
Vulnerability in js-yaml (CVE-2026-73643)
vulnerability in js-yaml (CVE-2026-73643). Risk of unauthorized operations or information disclosure. Exploitable via ``maxDepth``. Mitigation: upgrade to `5.2.2` or later.
|
| CVE-2026-73646 |
|
Path Traversal in postcss (CVE-2026-73646)
path traversal in postcss (CVE-2026-73646). Confidential information can be exposed externally. Exploitable via ``loadFile``. Mitigation: upgrade to `8.5.18` or later.
|
| CVE-2026-73649 |
|
Code Injection in velocityjs (CVE-2026-73649)
code injection in velocityjs (CVE-2026-73649). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.7` or later.
|
| CVE-2026-73428 |
|
Cross-Site Scripting (XSS) in trix (CVE-2026-73428)
cross-site scripting in trix (CVE-2026-73428). Risk of unauthorized operations or information disclosure. Exploitable via ``HTMLParser``. Mitigation: upgrade to `2.1.18` or later.
|
| CVE-2026-59940 |
|
Unsafe Deserialization in seroval (CVE-2026-59940)
vulnerability in seroval (CVE-2026-59940). Successful exploitation can lead to full system takeover. Exploitable via ``seroval``. Mitigation: upgrade to `1.5.3` or later.
|
| CVE-2026-55730 |
|
Cross-Site Scripting (XSS) in CVE-2026-55730 (CVE-2026-55730)
cross-site scripting in CVE-2026-55730 (CVE-2026-55730). Risk of unauthorized operations or information disclosure. Exploitable via ``project``.
|
| CVE-2026-12496 |
|
Cross-Site Scripting (XSS) in CVE-2026-12496 (CVE-2026-12496)
cross-site scripting in CVE-2026-12496 (CVE-2026-12496). Risk of unauthorized operations or information disclosure. Exploitable via `POST /da`.
|
| CVE-2026-15810 |
|
Cross-Site Scripting (XSS) in CVE-2026-15810 (CVE-2026-15810)
cross-site scripting in CVE-2026-15810 (CVE-2026-15810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6454 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6454)
cross-site scripting in wordpress (CVE-2026-6454). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15420 |
|
Path Traversal in wordpress (CVE-2026-15420)
path traversal in wordpress (CVE-2026-15420). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15100 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15100)
cross-site scripting in wordpress (CVE-2026-15100). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58353 |
|
Vulnerability in react (CVE-2024-58353)
vulnerability in react (CVE-2024-58353). Confidential information can be exposed externally.
|
| CVE-2024-58355 |
|
Vulnerability in react (CVE-2024-58355)
vulnerability in react (CVE-2024-58355). Confidential information can be exposed externally. Mitigation: upgrade to `4.7.16` or later.
|
| CVE-2025-71389 |
|
Code Injection in react (CVE-2025-71389)
code injection in react (CVE-2025-71389). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16763 |
|
Command Injection in CVE-2026-16763 (CVE-2026-16763)
command injection in CVE-2026-16763 (CVE-2026-16763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65697 |
|
Cross-Site Scripting (XSS) in CVE-2026-65697 (CVE-2026-65697)
cross-site scripting in CVE-2026-65697 (CVE-2026-65697). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16733 |
|
Command Injection in CVE-2026-16733 (CVE-2026-16733)
command injection in CVE-2026-16733 (CVE-2026-16733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16735 |
|
Command Injection in CVE-2026-16735 (CVE-2026-16735)
command injection in CVE-2026-16735 (CVE-2026-16735). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73421 |
|
Vulnerability in next-auth (CVE-2026-73421)
vulnerability in next-auth (CVE-2026-73421). Risk of unauthorized operations or information disclosure. Exploitable via ``auth``. Mitigation: upgrade to `5.0.0-beta.32` or later.
|
| CVE-2026-73418 |
|
Vulnerability in @auth/core (CVE-2026-73418)
vulnerability in @auth/core (CVE-2026-73418). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `0.41.3` or later.
|
| CVE-2026-73420 |
|
Vulnerability in @auth/core (CVE-2026-73420)
vulnerability in @auth/core (CVE-2026-73420). Risk of unauthorized operations or information disclosure. Exploitable via ``normalizeIdentifier``. Mitigation: upgrade to `0.41.3` or later.
|
| CVE-2026-73419 |
|
Vulnerability in @auth/core (CVE-2026-73419)
vulnerability in @auth/core (CVE-2026-73419). Confidential information can be exposed externally. Exploitable via ``state``. Mitigation: upgrade to `0.41.3` or later.
|
| CVE-2026-14257 |
|
Vulnerability in brace-expansion (CVE-2026-14257)
vulnerability in brace-expansion (CVE-2026-14257). Risk of unauthorized operations or information disclosure. Exploitable via ``max``. Mitigation: upgrade to `1.1.17` or later.
|
| CVE-2026-65606 |
|
Cross-Site Scripting (XSS) in CVE-2026-65606 (CVE-2026-65606)
cross-site scripting in CVE-2026-65606 (CVE-2026-65606). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64806 |
|
Vulnerability in jetbrains (CVE-2026-64806)
vulnerability in jetbrains (CVE-2026-64806). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65756 |
|
Shortcut configuration accepted arbitrary inline JavaScript.
Shortcut configuration accepted arbitrary inline JavaScript.
|
| CVE-2026-15404 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15404)
cross-site scripting in wordpress (CVE-2026-15404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9066)
cross-site scripting in wordpress (CVE-2026-9066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16631 |
|
Command Injection in CVE-2026-16631 (CVE-2026-16631)
command injection in CVE-2026-16631 (CVE-2026-16631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16630 |
|
Command Injection in CVE-2026-16630 (CVE-2026-16630)
command injection in CVE-2026-16630 (CVE-2026-16630). Risk of unauthorized operations or information disclosure.
|