Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-33386 |
|
Cross-Site Scripting (XSS) in CVE-2026-33386 (CVE-2026-33386)
cross-site scripting in CVE-2026-33386 (CVE-2026-33386). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25384 |
|
Cross-Site Scripting (XSS) in CVE-2018-25384 (CVE-2018-25384)
cross-site scripting in CVE-2018-25384 (CVE-2018-25384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44495 |
|
Code Injection in axios (CVE-2026-44495)
code injection in axios (CVE-2026-44495). Confidential information can be exposed externally. Exploitable via ``Object.prototype.transformResponse``. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-44494 |
|
Vulnerability in axios (CVE-2026-44494)
vulnerability in axios (CVE-2026-44494). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `1.15.0` or later.
|
| CVE-2026-44492 |
|
SSRF (Server-Side Request Forgery) in axios (CVE-2026-44492)
SSRF in axios (CVE-2026-44492). Confidential information can be exposed externally. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-44490 |
|
Vulnerability in axios (CVE-2026-44490)
vulnerability in axios (CVE-2026-44490). Risk of unauthorized operations or information disclosure. Exploitable via ``Object.prototype``. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-44489 |
|
Vulnerability in axios (CVE-2026-44489)
vulnerability in axios (CVE-2026-44489). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-47694 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-47694)
cross-site scripting in WWBN/AVideo (CVE-2026-47694). Risk of unauthorized operations or information disclosure. Exploitable via ``category_description``.
|
| CVE-2026-44698 |
|
Code Injection in CVE-2026-44698 (CVE-2026-44698)
code injection in CVE-2026-44698 (CVE-2026-44698). Successful exploitation can lead to full system takeover. Exploitable via ``window.externalApp``. Mitigation: upgrade to `2026.4.1` or later.
|
| CVE-2026-48527 |
|
Cross-Site Scripting (XSS) in @haxtheweb/haxcms-nodejs (CVE-2026-48527)
cross-site scripting in @haxtheweb/haxcms-nodejs (CVE-2026-48527). Confidential information can be exposed externally. Exploitable via `POST /system/api/saveNode`. Mitigation: upgrade to `26.0.1` or later.
|
| CVE-2026-45551 |
|
Cross-Site Scripting (XSS) in CVE-2026-45551 (CVE-2026-45551)
cross-site scripting in CVE-2026-45551 (CVE-2026-45551). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `26.0.25` or later.
|
| CVE-2026-10058 |
|
Cross-Site Scripting (XSS) in CVE-2026-10058 (CVE-2026-10058)
cross-site scripting in CVE-2026-10058 (CVE-2026-10058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10057 |
|
Cross-Site Scripting (XSS) in CVE-2026-10057 (CVE-2026-10057)
cross-site scripting in CVE-2026-10057 (CVE-2026-10057). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6275 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6275)
cross-site scripting in wordpress (CVE-2026-6275). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8732 |
|
Vulnerability in wordpress (CVE-2026-8732)
vulnerability in wordpress (CVE-2026-8732). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7430 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7430)
cross-site scripting in wordpress (CVE-2026-7430). Risk of unauthorized operations or information disclosure. Exploitable via ``WPEditor.php``.
|
| CVE-2026-45343 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-45343)
cross-site scripting in csrf (CVE-2026-45343). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.6` or later.
|
| CVE-2026-9645 |
|
OS Command Injection in scadabr (CVE-2026-9645)
OS command injection in scadabr (CVE-2026-9645). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45323 |
|
Cross-Site Scripting (XSS) in jpettitt (CVE-2026-45323)
cross-site scripting in jpettitt (CVE-2026-45323). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.3.3` or later.
|
| CVE-2026-47673 |
|
Vulnerability in hono (CVE-2026-47673)
vulnerability in hono (CVE-2026-47673). Risk of unauthorized operations or information disclosure. Exploitable via ``jwt``. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-47674 |
|
Vulnerability in hono (CVE-2026-47674)
vulnerability in hono (CVE-2026-47674). Risk of unauthorized operations or information disclosure. Exploitable via ``getIP``. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-47675 |
|
Vulnerability in hono (CVE-2026-47675)
vulnerability in hono (CVE-2026-47675). Risk of unauthorized operations or information disclosure. Exploitable via ``domain``. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-47676 |
|
Vulnerability in hono (CVE-2026-47676)
vulnerability in hono (CVE-2026-47676). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-45753 |
|
Cross-Site Scripting (XSS) in symfony/html-sanitizer (CVE-2026-45753)
cross-site scripting in symfony/html-sanitizer (CVE-2026-45753). Risk of unauthorized operations or information disclosure. Exploitable via ``UrlAttributeSanitizer``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-47760 |
|
Cross-Site Scripting (XSS) in tinymce (CVE-2026-47760)
cross-site scripting in tinymce (CVE-2026-47760). Confidential information can be exposed externally. Mitigation: upgrade to `7.1.0` or later.
|
| CVE-2026-44358 |
|
Vulnerability in CVE-2026-44358 (CVE-2026-44358)
vulnerability in CVE-2026-44358 (CVE-2026-44358). Data can be tampered with by attackers. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-9806 |
|
Cross-Site Scripting (XSS) in CVE-2026-9806 (CVE-2026-9806)
cross-site scripting in CVE-2026-9806 (CVE-2026-9806). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7797 |
|
SQL Injection in wordpress (CVE-2026-7797)
SQL injection in wordpress (CVE-2026-7797). Confidential information can be exposed externally.
|
| CVE-2026-5737 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-5737)
SSRF in wordpress (CVE-2026-5737). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46562 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-46562)
code injection in org.yamcs:yamcs-core (CVE-2026-46562). Successful exploitation can lead to full system takeover. Exploitable via `PATCH /api/mdb/{instance}/{processor}/algorithms/{name`. Mitigation: upgrade to `5.12.7` or later.
|
| CVE-2026-45102 |
|
Vulnerability in CVE-2026-45102 (CVE-2026-45102)
vulnerability in CVE-2026-45102 (CVE-2026-45102). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `10.0.98` or later.
|
| CVE-2026-42197 |
|
Cross-Site Scripting (XSS) in django (CVE-2026-42197)
cross-site scripting in django (CVE-2026-42197). Confidential information can be exposed externally. Exploitable via ``ParticipationAdmin``.
|
| CVE-2026-42877 |
|
Cross-Site Scripting (XSS) in facturascripts/facturascripts (CVE-2026-42877)
cross-site scripting in facturascripts/facturascripts (CVE-2026-42877). Risk of unauthorized operations or information disclosure. Exploitable via ``referencia``.
|
| CVE-2026-44726 |
|
Vulnerability in deno (CVE-2026-44726)
vulnerability in deno (CVE-2026-44726). Confidential information can be exposed externally. Exploitable via `POST /v1/charge`. Mitigation: upgrade to `2.7.8` or later.
|
| CVE-2026-45617 |
|
Vulnerability in liquidjs (CVE-2026-45617)
vulnerability in liquidjs (CVE-2026-45617). Risk of unauthorized operations or information disclosure. Exploitable via ``strip_html``. Mitigation: upgrade to `10.26.0` or later.
|
| CVE-2026-45368 |
|
Cross-Site Scripting (XSS) in getkirby/cms (CVE-2026-45368)
cross-site scripting in getkirby/cms (CVE-2026-45368). Risk of unauthorized operations or information disclosure. Exploitable via ``image``. Mitigation: upgrade to `5.4.1` or later.
|
| CVE-2026-45357 |
|
Vulnerability in liquidjs (CVE-2026-45357)
vulnerability in liquidjs (CVE-2026-45357). Risk of unauthorized operations or information disclosure. Exploitable via ``date``.
|
| CVE-2026-36044 |
|
OS Command Injection in CVE-2026-36044 (CVE-2026-36044)
OS command injection in CVE-2026-36044 (CVE-2026-36044). Successful exploitation can lead to full system takeover.
|
| CVE-2025-3633 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2025-3633)
cross-site scripting in ibm (CVE-2025-3633). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47119 |
|
Cross-Site Scripting (XSS) in CVE-2026-47119 (CVE-2026-47119)
cross-site scripting in CVE-2026-47119 (CVE-2026-47119). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42280 |
|
Authorization Flaw in auth0-js (CVE-2026-42280)
vulnerability in auth0-js (CVE-2026-42280). Confidential information can be exposed externally. Mitigation: upgrade to `10.0.0` or later.
|
| CVE-2026-3375 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3375)
cross-site scripting in wordpress (CVE-2026-3375). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48999 |
|
Cross-Site Scripting (XSS) in CVE-2026-48999 (CVE-2026-48999)
cross-site scripting in CVE-2026-48999 (CVE-2026-48999). Data can be tampered with by attackers.
|
| CVE-2026-44705 |
|
Path Traversal in tmp (CVE-2026-44705)
path traversal in tmp (CVE-2026-44705). Data can be tampered with by attackers. Exploitable via ``prefix``. Mitigation: upgrade to `0.2.6` or later.
|
| CVE-2026-44646 |
|
Vulnerability in liquidjs (CVE-2026-44646)
vulnerability in liquidjs (CVE-2026-44646). Risk of unauthorized operations or information disclosure. Exploitable via ``Context``.
|
| CVE-2026-44645 |
|
Vulnerability in liquidjs (CVE-2026-44645)
vulnerability in liquidjs (CVE-2026-44645). Risk of unauthorized operations or information disclosure. Exploitable via ``renderLimit``.
|
| CVE-2026-44644 |
|
Cross-Site Scripting (XSS) in liquidjs (CVE-2026-44644)
cross-site scripting in liquidjs (CVE-2026-44644). Risk of unauthorized operations or information disclosure. Exploitable via ``strip_html``.
|
| CVE-2026-44587 |
|
Cross-Site Scripting (XSS) in carrierwave (CVE-2026-44587)
cross-site scripting in carrierwave (CVE-2026-44587). Risk of unauthorized operations or information disclosure. Exploitable via ``Regexp.quote``. Mitigation: upgrade to `2.2.7` or later.
|
| CVE-2026-34986 |
|
Vulnerability in github.com/go-jose/go-jose/v3 (CVE-2026-34986)
vulnerability in github.com/go-jose/go-jose/v3 (CVE-2026-34986). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.5` or later.
|
| CVE-2025-68709 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2025-68709)
cross-site scripting in privilege-escalation (CVE-2025-68709). Risk of unauthorized operations or information disclosure.
|