Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-7186 |
|
Cross-Site Scripting (XSS) in checkmk (CVE-2026-7186)
cross-site scripting in checkmk (CVE-2026-7186). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11569 |
|
Cross-Site Scripting (XSS) in CVE-2026-11569 (CVE-2026-11569)
cross-site scripting in CVE-2026-11569 (CVE-2026-11569). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47983 |
|
Cross-Site Scripting (XSS) in c (CVE-2021-47983)
cross-site scripting in c (CVE-2021-47983). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47984 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2021-47984)
cross-site scripting in wordpress (CVE-2021-47984). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-54351 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2023-54351)
cross-site scripting in wordpress (CVE-2023-54351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11408 |
|
Command Injection in CVE-2026-11408 (CVE-2026-11408)
command injection in CVE-2026-11408 (CVE-2026-11408). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9016 |
|
Vulnerability in wordpress (CVE-2026-9016)
vulnerability in wordpress (CVE-2026-9016). Risk of unauthorized operations or information disclosure. Exploitable via ``wp_ajax_nopriv_log_js_errors``.
|
| CVE-2026-9280 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9280)
cross-site scripting in wordpress (CVE-2026-9280). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7795 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7795)
cross-site scripting in wordpress (CVE-2026-7795). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9281 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9281)
cross-site scripting in wordpress (CVE-2026-9281). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8438 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8438)
cross-site scripting in wordpress (CVE-2026-8438). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11422 |
|
Vulnerability in CVE-2026-11422 (CVE-2026-11422)
vulnerability in CVE-2026-11422 (CVE-2026-11422). Confidential information can be exposed externally.
|
| CVE-2026-46493 |
|
Vulnerability in CVE-2026-46493 (CVE-2026-46493)
vulnerability in CVE-2026-46493 (CVE-2026-46493). Confidential information can be exposed externally. Exploitable via ``uniqid``.
|
| CVE-2026-46401 |
|
Vulnerability in CVE-2026-46401 (CVE-2026-46401)
vulnerability in CVE-2026-46401 (CVE-2026-46401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46400 |
|
Unrestricted File Upload in CVE-2026-46400 (CVE-2026-46400)
vulnerability in CVE-2026-46400 (CVE-2026-46400). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46398 |
|
Vulnerability in CVE-2026-46398 (CVE-2026-46398)
vulnerability in CVE-2026-46398 (CVE-2026-46398). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46397 |
|
Path Traversal in CVE-2026-46397 (CVE-2026-46397)
path traversal in CVE-2026-46397 (CVE-2026-46397). Confidential information can be exposed externally.
|
| CVE-2026-45778 |
|
Cross-Site Scripting (XSS) in buffalo (CVE-2026-45778)
cross-site scripting in buffalo (CVE-2026-45778). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46399 |
|
Vulnerability in CVE-2026-46399 (CVE-2026-46399)
vulnerability in CVE-2026-46399 (CVE-2026-46399). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46394 |
|
OS Command Injection in CVE-2026-46394 (CVE-2026-46394)
OS command injection in CVE-2026-46394 (CVE-2026-46394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46392 |
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filen...
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...
|
| CVE-2026-46390 |
|
Vulnerability in CVE-2026-46390 (CVE-2026-46390)
vulnerability in CVE-2026-46390 (CVE-2026-46390). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50733 |
|
Vulnerability in CVE-2026-50733 (CVE-2026-50733)
vulnerability in CVE-2026-50733 (CVE-2026-50733). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
|
| CVE-2026-47731 |
|
Path Traversal in ait-core (CVE-2026-47731)
path traversal in ait-core (CVE-2026-47731). Data can be tampered with by attackers. Exploitable via ``python_poc.py``. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2026-48017 |
|
Code Injection in dbgate-api (CVE-2026-48017)
code injection in dbgate-api (CVE-2026-48017). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/load-reader`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47669 |
|
Path Traversal in dbgate (CVE-2026-47669)
path traversal in dbgate (CVE-2026-47669). Risk of unauthorized operations or information disclosure. Exploitable via `POST /auth/login`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47668 |
|
Vulnerability in dbgate-serve (CVE-2026-47668)
vulnerability in dbgate-serve (CVE-2026-47668). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/start`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47387 |
|
Cross-Site Scripting (XSS) in nocodb (CVE-2026-47387)
cross-site scripting in nocodb (CVE-2026-47387). Risk of unauthorized operations or information disclosure. Exploitable via ``redirect_url``. Mitigation: upgrade to `2026.05.1` or later.
|
| CVE-2026-47376 |
|
Cross-Site Scripting (XSS) in nocodb (CVE-2026-47376)
cross-site scripting in nocodb (CVE-2026-47376). Risk of unauthorized operations or information disclosure. Exploitable via ``dataset.token``. Mitigation: upgrade to `2026.04.1` or later.
|
| CVE-2026-38579 |
|
Cross-Site Scripting (XSS) in CVE-2026-38579 (CVE-2026-38579)
cross-site scripting in CVE-2026-38579 (CVE-2026-38579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50235 |
|
Cross-Site Scripting (XSS) in CVE-2026-50235 (CVE-2026-50235)
cross-site scripting in CVE-2026-50235 (CVE-2026-50235). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50233 |
|
Vulnerability in CVE-2026-50233 (CVE-2026-50233)
vulnerability in CVE-2026-50233 (CVE-2026-50233). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50230 |
|
Cross-Site Scripting (XSS) in CVE-2026-50230 (CVE-2026-50230)
cross-site scripting in CVE-2026-50230 (CVE-2026-50230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11345 |
|
Authentication Bypass in CVE-2026-11345 (CVE-2026-11345)
authentication bypass in CVE-2026-11345 (CVE-2026-11345). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21825 |
|
Cross-Site Scripting (XSS) in hcltech (CVE-2026-21825)
cross-site scripting in hcltech (CVE-2026-21825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10732 |
|
Path Traversal in decompress (CVE-2026-10732)
path traversal in decompress (CVE-2026-10732). Data can be tampered with by attackers.
|
| CVE-2026-41518 |
|
Cross-Site Scripting (XSS) in CVE-2026-41518 (CVE-2026-41518)
cross-site scripting in CVE-2026-41518 (CVE-2026-41518). Confidential information can be exposed externally. Exploitable via ``ChartDatasetConfig.legend``.
|
| CVE-2026-48015 |
|
Cross-Site Scripting (XSS) in shopware/core (CVE-2026-48015)
cross-site scripting in shopware/core (CVE-2026-48015). Confidential information can be exposed externally. Exploitable via ``allowed_extensions``. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48012 |
|
Open Redirect in shopware/core (CVE-2026-48012)
vulnerability in shopware/core (CVE-2026-48012). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/oauth/sso/auth`. Mitigation: upgrade to `6.7.10.1` or later.
|
| CVE-2025-65640 |
|
Cross-Site Scripting (XSS) in CVE-2025-65640 (CVE-2025-65640)
cross-site scripting in CVE-2025-65640 (CVE-2025-65640). Confidential information can be exposed externally.
|
| CVE-2026-54458 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-54458)
cross-site scripting in WWBN/AVideo (CVE-2026-54458). Confidential information can be exposed externally. Exploitable via ``page_title``.
|
| CVE-2026-50183 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-50183)
cross-site scripting in WWBN/AVideo (CVE-2026-50183). Risk of unauthorized operations or information disclosure. Exploitable via ``snippet.title``.
|
| CVE-2026-50182 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-50182)
cross-site scripting in WWBN/AVideo (CVE-2026-50182). Risk of unauthorized operations or information disclosure. Exploitable via ``href``.
|
| CVE-2026-49279 |
|
Cross-Site Scripting (XSS) in wwbn/avideo (CVE-2026-49279)
cross-site scripting in wwbn/avideo (CVE-2026-49279). Risk of unauthorized operations or information disclosure. Exploitable via ``autoEvalCodeOnHTML``.
|
| CVE-2026-10796 |
|
OS Command Injection in openjsf (CVE-2026-10796)
OS command injection in openjsf (CVE-2026-10796). Successful exploitation can lead to full system takeover. Exploitable via ``eval``.
|
| CVE-2026-43984 |
|
Cross-Site Scripting (XSS) in CVE-2026-43984 (CVE-2026-43984)
cross-site scripting in CVE-2026-43984 (CVE-2026-43984). Confidential information can be exposed externally. Exploitable via ``log_js_errors``.
|
| CVE-2019-25742 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2019-25742)
cross-site scripting in wordpress (CVE-2019-25742). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25739 |
|
Cross-Site Scripting (XSS) in CVE-2019-25739 (CVE-2019-25739)
cross-site scripting in CVE-2019-25739 (CVE-2019-25739). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25731 |
|
Cross-Site Scripting (XSS) in CVE-2019-25731 (CVE-2019-25731)
cross-site scripting in CVE-2019-25731 (CVE-2019-25731). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44496 |
|
Vulnerability in axios (CVE-2026-44496)
vulnerability in axios (CVE-2026-44496). Risk of unauthorized operations or information disclosure. Exploitable via ``document.cookie``. Mitigation: upgrade to `0.32.0` or later.
|