Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-94 Clear
ID Title
CVE-2026-18874 Code Injection in CVE-2026-18874 (CVE-2026-18874)
code injection in CVE-2026-18874 (CVE-2026-18874). Data can be tampered with by attackers.
CVE-2026-72530 KEV [KEV] Code Injection in trueconf (CVE-2026-72530)
code injection in trueconf (CVE-2026-72530). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-64850 Code Injection in CVE-2026-64850 (CVE-2026-64850)
code injection in CVE-2026-64850 (CVE-2026-64850). Risk of unauthorized operations or information disclosure.
CVE-2026-53451 Path Traversal in path-traversal (CVE-2026-53451)
path traversal in path-traversal (CVE-2026-53451). Successful exploitation can lead to full system takeover.
CVE-2026-45272 Code Injection in CVE-2026-45272 (CVE-2026-45272)
code injection in CVE-2026-45272 (CVE-2026-45272). Risk of unauthorized operations or information disclosure.
CVE-2026-76224 Code Injection in CVE-2026-76224 (CVE-2026-76224)
code injection in CVE-2026-76224 (CVE-2026-76224). Successful exploitation can lead to full system takeover.
CVE-2026-43961 Code Injection in CVE-2026-43961 (CVE-2026-43961)
code injection in CVE-2026-43961 (CVE-2026-43961). Successful exploitation can lead to full system takeover.
CVE-2026-67364 Code Injection in c (CVE-2026-67364)
code injection in c (CVE-2026-67364). Risk of unauthorized operations or information disclosure.
CVE-2026-18937 Code Injection in wordpress (CVE-2026-18937)
code injection in wordpress (CVE-2026-18937). Successful exploitation can lead to full system takeover.
CVE-2026-75911 Code Injection in CVE-2026-75911 (CVE-2026-75911)
code injection in CVE-2026-75911 (CVE-2026-75911). Successful exploitation can lead to full system takeover.
CVE-2026-75858 Code Injection in CVE-2026-75858 (CVE-2026-75858)
code injection in CVE-2026-75858 (CVE-2026-75858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.64` or later.
CVE-2026-73073 Code Injection in c (CVE-2026-73073)
code injection in c (CVE-2026-73073). Risk of unauthorized operations or information disclosure.
CVE-2026-45117 Code Injection in CVE-2026-45117 (CVE-2026-45117)
code injection in CVE-2026-45117 (CVE-2026-45117). Successful exploitation can lead to full system takeover.
CVE-2026-73343 Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
CVE-2026-32444 Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVE-2026-50187 Code Injection in CVE-2026-50187 (CVE-2026-50187)
code injection in CVE-2026-50187 (CVE-2026-50187). Successful exploitation can lead to full system takeover.
CVE-2026-75827 Code Injection in CVE-2026-75827 (CVE-2026-75827)
code injection in CVE-2026-75827 (CVE-2026-75827). Successful exploitation can lead to full system takeover.
CVE-2025-62593 KEV [KEV] Cross-Site Request Forgery (CSRF) in Ray-project ray (CVE-2025-62593)
vulnerability in Ray-project ray (CVE-2025-62593). Successful exploitation can lead to full system takeover. Exploitable via ``fetch``. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `2.52.0` or later.
CVE-2026-67961 Code Injection in CVE-2026-67961 (CVE-2026-67961)
code injection in CVE-2026-67961 (CVE-2026-67961). Successful exploitation can lead to full system takeover.
CVE-2026-67919 Code Injection in CVE-2026-67919 (CVE-2026-67919)
code injection in CVE-2026-67919 (CVE-2026-67919). Successful exploitation can lead to full system takeover.
CVE-2026-75078 Cross-Site Scripting (XSS) in CVE-2026-75078 (CVE-2026-75078)
cross-site scripting in CVE-2026-75078 (CVE-2026-75078). Risk of unauthorized operations or information disclosure.
CVE-2026-38165 Code Injection in CVE-2026-38165 (CVE-2026-38165)
code injection in CVE-2026-38165 (CVE-2026-38165). Successful exploitation can lead to full system takeover.
CVE-2026-67960 Code Injection in CVE-2026-67960 (CVE-2026-67960)
code injection in CVE-2026-67960 (CVE-2026-67960). Successful exploitation can lead to full system takeover.
CVE-2026-75077 Cross-Site Scripting (XSS) in c (CVE-2026-75077)
cross-site scripting in c (CVE-2026-75077). Risk of unauthorized operations or information disclosure.
CVE-2026-67926 Code Injection in CVE-2026-67926 (CVE-2026-67926)
code injection in CVE-2026-67926 (CVE-2026-67926). Successful exploitation can lead to full system takeover.
CVE-2026-34789 Code Injection in cpp (CVE-2026-34789)
code injection in cpp (CVE-2026-34789). Successful exploitation can lead to full system takeover.
CVE-2026-19478 Code Injection in CVE-2026-19478 (CVE-2026-19478)
code injection in CVE-2026-19478 (CVE-2026-19478). Data can be tampered with by attackers.
CVE-2026-74253 Code Injection in CVE-2026-74253 (CVE-2026-74253)
code injection in CVE-2026-74253 (CVE-2026-74253). Risk of unauthorized operations or information disclosure.
CVE-2026-50772 Code Injection in CVE-2026-50772 (CVE-2026-50772)
code injection in CVE-2026-50772 (CVE-2026-50772). Successful exploitation can lead to full system takeover.
CVE-2026-59894 Code Injection in sqlparse (CVE-2026-59894)
code injection in sqlparse (CVE-2026-59894). Risk of unauthorized operations or information disclosure. Exploitable via ``EVOHUNT_OUTPUT_FORMAT_INJECTION_VERIFIED``. Mitigation: upgrade to `0.6.0` or later.
CVE-2026-19998 Cross-Site Scripting (XSS) in CVE-2026-19998 (CVE-2026-19998)
cross-site scripting in CVE-2026-19998 (CVE-2026-19998). Risk of unauthorized operations or information disclosure.
CVE-2026-19995 Cross-Site Scripting (XSS) in CVE-2026-19995 (CVE-2026-19995)
cross-site scripting in CVE-2026-19995 (CVE-2026-19995). Risk of unauthorized operations or information disclosure.
CVE-2026-19980 Vulnerability in CVE-2026-19980 (CVE-2026-19980)
vulnerability in CVE-2026-19980 (CVE-2026-19980). Risk of unauthorized operations or information disclosure.
CVE-2026-19964 Vulnerability in CVE-2026-19964 (CVE-2026-19964)
vulnerability in CVE-2026-19964 (CVE-2026-19964). Risk of unauthorized operations or information disclosure.
CVE-2026-19958 Vulnerability in CVE-2026-19958 (CVE-2026-19958)
vulnerability in CVE-2026-19958 (CVE-2026-19958). Risk of unauthorized operations or information disclosure.
CVE-2026-19932 Vulnerability in CVE-2026-19932 (CVE-2026-19932)
vulnerability in CVE-2026-19932 (CVE-2026-19932). Risk of unauthorized operations or information disclosure.
CVE-2026-18385 Code Injection in wordpress (CVE-2026-18385)
code injection in wordpress (CVE-2026-18385). Risk of unauthorized operations or information disclosure.
CVE-2026-17581 Code Injection in wordpress (CVE-2026-17581)
code injection in wordpress (CVE-2026-17581). Successful exploitation can lead to full system takeover.
CVE-2026-19922 Cross-Site Scripting (XSS) in CVE-2026-19922 (CVE-2026-19922)
cross-site scripting in CVE-2026-19922 (CVE-2026-19922). Risk of unauthorized operations or information disclosure.
CVE-2026-19916 Cross-Site Scripting (XSS) in CVE-2026-19916 (CVE-2026-19916)
cross-site scripting in CVE-2026-19916 (CVE-2026-19916). Risk of unauthorized operations or information disclosure.
CVE-2026-19904 Cross-Site Scripting (XSS) in CVE-2026-19904 (CVE-2026-19904)
cross-site scripting in CVE-2026-19904 (CVE-2026-19904). Risk of unauthorized operations or information disclosure.
CVE-2026-73679 Code Injection in CVE-2026-73679 (CVE-2026-73679)
code injection in CVE-2026-73679 (CVE-2026-73679). Successful exploitation can lead to full system takeover.
CVE-2026-73678 Code Injection in c (CVE-2026-73678)
code injection in c (CVE-2026-73678). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/responses/`.
CVE-2026-19768 Code Injection in CVE-2026-19768 (CVE-2026-19768)
code injection in CVE-2026-19768 (CVE-2026-19768). Confidential information can be exposed externally.
CVE-2026-72819 Code Injection in c (CVE-2026-72819)
code injection in c (CVE-2026-72819). Successful exploitation can lead to full system takeover.
CVE-2026-72676 Code Injection in CVE-2026-72676 (CVE-2026-72676)
code injection in CVE-2026-72676 (CVE-2026-72676). Confidential information can be exposed externally.
CVE-2026-67986 Code Injection in CVE-2026-67986 (CVE-2026-67986)
code injection in CVE-2026-67986 (CVE-2026-67986). Successful exploitation can lead to full system takeover.
CVE-2026-61962 Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
CVE-2026-27544 Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
CVE-2026-73487 Code Injection in ssrf (CVE-2026-73487)
code injection in ssrf (CVE-2026-73487). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →