Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66766 |
|
Vulnerability in dos (CVE-2026-66766)
vulnerability in dos (CVE-2026-66766). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78284 |
|
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
|
| CVE-2026-78282 |
|
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
|
| CVE-2026-78268 |
|
Vulnerability in CVE-2026-78268 (CVE-2026-78268)
vulnerability in CVE-2026-78268 (CVE-2026-78268). Confidential information can be exposed externally.
|
| CVE-2026-78264 |
|
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
|
| CVE-2026-78263 |
|
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
|
| CVE-2026-78259 |
|
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
|
| CVE-2026-77384 |
|
Vulnerability in dos (CVE-2026-77384)
vulnerability in dos (CVE-2026-77384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32561 |
|
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
|
| CVE-2026-32560 |
|
Vulnerability in wordpress (CVE-2026-32560)
vulnerability in wordpress (CVE-2026-32560). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32556 |
|
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
|
| CVE-2026-7455 |
|
Out-of-Bounds Write in autodesk (CVE-2026-7455)
out-of-bounds write in autodesk (CVE-2026-7455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19568 |
|
Vulnerability in autodesk (CVE-2026-19568)
vulnerability in autodesk (CVE-2026-19568). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75464 |
|
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
|
| CVE-2026-52492 |
|
Vulnerability in CVE-2026-52492 (CVE-2026-52492)
vulnerability in CVE-2026-52492 (CVE-2026-52492). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16783 |
|
Out-of-Bounds Write in autodesk (CVE-2026-16783)
out-of-bounds write in autodesk (CVE-2026-16783). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77567 |
|
Authentication Bypass in laravel (CVE-2026-77567)
authentication bypass in laravel (CVE-2026-77567). Confidential information can be exposed externally.
|
| CVE-2026-56135 |
|
Vulnerability in c (CVE-2026-56135)
vulnerability in c (CVE-2026-56135). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76098 |
|
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens fr...
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can excee...
|
| CVE-2026-75369 |
|
Out-of-Bounds Read in dos (CVE-2026-75369)
vulnerability in dos (CVE-2026-75369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75368 |
|
Vulnerability in dos (CVE-2026-75368)
vulnerability in dos (CVE-2026-75368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61419 |
|
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
|
| CVE-2026-75371 |
|
Vulnerability in dos (CVE-2026-75371)
vulnerability in dos (CVE-2026-75371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71506 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
| CVE-2026-71505 |
|
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
|
| CVE-2026-71504 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-30864 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
| CVE-2025-26238 |
|
Code Injection in CVE-2025-26238 (CVE-2025-26238)
code injection in CVE-2025-26238 (CVE-2025-26238). Confidential information can be exposed externally.
|
| CVE-2025-26237 |
|
Command Injection in CVE-2025-26237 (CVE-2025-26237)
command injection in CVE-2025-26237 (CVE-2025-26237). Confidential information can be exposed externally.
|
| CVE-2026-76838 |
|
SSRF (Server-Side Request Forgery) in laravel (CVE-2026-76838)
SSRF in laravel (CVE-2026-76838). Confidential information can be exposed externally.
|
| CVE-2026-71942 |
|
Vulnerability in dos (CVE-2026-71942)
vulnerability in dos (CVE-2026-71942). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76072 |
|
Vulnerability in CVE-2026-76072 (CVE-2026-76072)
vulnerability in CVE-2026-76072 (CVE-2026-76072). Data can be tampered with by attackers.
|
| CVE-2026-76836 |
|
Code Injection in CVE-2026-76836 (CVE-2026-76836)
code injection in CVE-2026-76836 (CVE-2026-76836). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/station/{station_id}/profile/edit`.
|
| CVE-2026-71943 |
|
OS Command Injection in CVE-2026-71943 (CVE-2026-71943)
OS command injection in CVE-2026-71943 (CVE-2026-71943). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76073 |
|
Vulnerability in CVE-2026-76073 (CVE-2026-76073)
vulnerability in CVE-2026-76073 (CVE-2026-76073). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71941 |
|
Vulnerability in dos (CVE-2026-71941)
vulnerability in dos (CVE-2026-71941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71937 |
|
Vulnerability in dos (CVE-2026-71937)
vulnerability in dos (CVE-2026-71937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71940 |
|
Vulnerability in dos (CVE-2026-71940)
vulnerability in dos (CVE-2026-71940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71935 |
|
Vulnerability in dos (CVE-2026-71935)
vulnerability in dos (CVE-2026-71935). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71939 |
|
Vulnerability in dos (CVE-2026-71939)
vulnerability in dos (CVE-2026-71939). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71938 |
|
Vulnerability in dos (CVE-2026-71938)
vulnerability in dos (CVE-2026-71938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71936 |
|
Vulnerability in dos (CVE-2026-71936)
vulnerability in dos (CVE-2026-71936). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71934 |
|
Vulnerability in dos (CVE-2026-71934)
vulnerability in dos (CVE-2026-71934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71931 |
|
OS Command Injection in CVE-2026-71931 (CVE-2026-71931)
OS command injection in CVE-2026-71931 (CVE-2026-71931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71922 |
|
Vulnerability in dos (CVE-2026-71922)
vulnerability in dos (CVE-2026-71922). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71928 |
|
OS Command Injection in CVE-2026-71928 (CVE-2026-71928)
OS command injection in CVE-2026-71928 (CVE-2026-71928). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71926 |
|
OS Command Injection in CVE-2026-71926 (CVE-2026-71926)
OS command injection in CVE-2026-71926 (CVE-2026-71926). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71927 |
|
OS Command Injection in CVE-2026-71927 (CVE-2026-71927)
OS command injection in CVE-2026-71927 (CVE-2026-71927). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71930 |
|
OS Command Injection in CVE-2026-71930 (CVE-2026-71930)
OS command injection in CVE-2026-71930 (CVE-2026-71930). Successful exploitation can lead to full system takeover.
|