Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-94 Clear
ID Title
CVE-2026-73486 Code Injection in CVE-2026-73486 (CVE-2026-73486)
code injection in CVE-2026-73486 (CVE-2026-73486). Risk of unauthorized operations or information disclosure.
CVE-2026-0298 Code Injection in CVE-2026-0298 (CVE-2026-0298)
code injection in CVE-2026-0298 (CVE-2026-0298). Risk of unauthorized operations or information disclosure.
CVE-2026-13094 Code Injection in ibm (CVE-2026-13094)
code injection in ibm (CVE-2026-13094). Successful exploitation can lead to full system takeover.
CVE-2026-73268 Code Injection in privilege-escalation (CVE-2026-73268)
code injection in privilege-escalation (CVE-2026-73268). Successful exploitation can lead to full system takeover.
CVE-2026-73299 Code Injection in CVE-2026-73299 (CVE-2026-73299)
code injection in CVE-2026-73299 (CVE-2026-73299). Successful exploitation can lead to full system takeover.
CVE-2026-65941 Vulnerability in CVE-2026-65941 (CVE-2026-65941)
vulnerability in CVE-2026-65941 (CVE-2026-65941). Successful exploitation can lead to full system takeover.
CVE-2026-73291 Path Traversal in CVE-2026-73291 (CVE-2026-73291)
path traversal in CVE-2026-73291 (CVE-2026-73291). Data can be tampered with by attackers. Exploitable via `GET /avatarproxy/`.
CVE-2026-67282 Code Injection in CVE-2026-67282 (CVE-2026-67282)
code injection in CVE-2026-67282 (CVE-2026-67282). Risk of unauthorized operations or information disclosure.
CVE-2026-16051 Code Injection in wordpress (CVE-2026-16051)
code injection in wordpress (CVE-2026-16051). Successful exploitation can lead to full system takeover.
CVE-2026-73248 Code Injection in CVE-2026-73248 (CVE-2026-73248)
code injection in CVE-2026-73248 (CVE-2026-73248). Risk of unauthorized operations or information disclosure.
CVE-2026-66150 Code Injection in CVE-2026-66150 (CVE-2026-66150)
code injection in CVE-2026-66150 (CVE-2026-66150). Successful exploitation can lead to full system takeover.
CVE-2026-66148 Code Injection in CVE-2026-66148 (CVE-2026-66148)
code injection in CVE-2026-66148 (CVE-2026-66148). Risk of unauthorized operations or information disclosure.
CVE-2026-66147 Code Injection in CVE-2026-66147 (CVE-2026-66147)
code injection in CVE-2026-66147 (CVE-2026-66147). Data can be tampered with by attackers.
CVE-2026-66149 Code Injection in CVE-2026-66149 (CVE-2026-66149)
code injection in CVE-2026-66149 (CVE-2026-66149). Successful exploitation can lead to full system takeover.
CVE-2026-73233 Code Injection in cpp (CVE-2026-73233)
code injection in cpp (CVE-2026-73233). Risk of unauthorized operations or information disclosure.
CVE-2026-73032 Code Injection in CVE-2026-73032 (CVE-2026-73032)
code injection in CVE-2026-73032 (CVE-2026-73032). Successful exploitation can lead to full system takeover.
CVE-2026-66145 Code Injection in CVE-2026-66145 (CVE-2026-66145)
code injection in CVE-2026-66145 (CVE-2026-66145). Confidential information can be exposed externally.
CVE-2026-18708 Code Injection in dos (CVE-2026-18708)
code injection in dos (CVE-2026-18708). Risk of unauthorized operations or information disclosure.
CVE-2026-73084 Cross-Site Scripting (XSS) in CVE-2026-73084 (CVE-2026-73084)
cross-site scripting in CVE-2026-73084 (CVE-2026-73084). Risk of unauthorized operations or information disclosure.
CVE-2026-70338 Code Injection in microsoft (CVE-2026-70338)
code injection in microsoft (CVE-2026-70338). Successful exploitation can lead to full system takeover.
CVE-2026-70336 Code Injection in microsoft (CVE-2026-70336)
code injection in microsoft (CVE-2026-70336). Successful exploitation can lead to full system takeover.
CVE-2026-65660 Code Injection in microsoft (CVE-2026-65660)
code injection in microsoft (CVE-2026-65660). Successful exploitation can lead to full system takeover.
CVE-2026-73076 Code Injection in CVE-2026-73076 (CVE-2026-73076)
code injection in CVE-2026-73076 (CVE-2026-73076). Risk of unauthorized operations or information disclosure.
CVE-2026-19546 Code Injection in CVE-2026-19546 (CVE-2026-19546)
code injection in CVE-2026-19546 (CVE-2026-19546). Successful exploitation can lead to full system takeover.
CVE-2026-72765 Code Injection in CVE-2026-72765 (CVE-2026-72765)
code injection in CVE-2026-72765 (CVE-2026-72765). Risk of unauthorized operations or information disclosure.
CVE-2026-58231 Code Injection in CVE-2026-58231 (CVE-2026-58231)
code injection in CVE-2026-58231 (CVE-2026-58231). Successful exploitation can lead to full system takeover.
CVE-2026-44758 Code Injection in CVE-2026-44758 (CVE-2026-44758)
code injection in CVE-2026-44758 (CVE-2026-44758). Successful exploitation can lead to full system takeover.
CVE-2026-18942 Code Injection in CVE-2026-18942 (CVE-2026-18942)
code injection in CVE-2026-18942 (CVE-2026-18942). Confidential information can be exposed externally.
CVE-2026-72904 Command Injection in ssrf (CVE-2026-72904)
command injection in ssrf (CVE-2026-72904). Risk of unauthorized operations or information disclosure.
CVE-2026-72718 Code Injection in CVE-2026-72718 (CVE-2026-72718)
code injection in CVE-2026-72718 (CVE-2026-72718). Risk of unauthorized operations or information disclosure. Exploitable via ``git``.
CVE-2026-66738 Code Injection in CVE-2026-66738 (CVE-2026-66738)
code injection in CVE-2026-66738 (CVE-2026-66738). Successful exploitation can lead to full system takeover.
CVE-2026-55799 Code Injection in apache (CVE-2026-55799)
code injection in apache (CVE-2026-55799). Successful exploitation can lead to full system takeover.
CVE-2026-42537 Vulnerability in apache (CVE-2026-42537)
vulnerability in apache (CVE-2026-42537). Successful exploitation can lead to full system takeover.
CVE-2026-44416 Code Injection in apache (CVE-2026-44416)
code injection in apache (CVE-2026-44416). Successful exploitation can lead to full system takeover.
CVE-2026-66915 Code Injection in CVE-2026-66915 (CVE-2026-66915)
code injection in CVE-2026-66915 (CVE-2026-66915). Risk of unauthorized operations or information disclosure.
CVE-2026-19378 Cross-Site Scripting (XSS) in CVE-2026-19378 (CVE-2026-19378)
cross-site scripting in CVE-2026-19378 (CVE-2026-19378). Risk of unauthorized operations or information disclosure.
CVE-2026-46409 Code Injection in CVE-2026-46409 (CVE-2026-46409)
code injection in CVE-2026-46409 (CVE-2026-46409). Successful exploitation can lead to full system takeover.
CVE-2026-19230 Cross-Site Scripting (XSS) in CVE-2026-19230 (CVE-2026-19230)
cross-site scripting in CVE-2026-19230 (CVE-2026-19230). Risk of unauthorized operations or information disclosure.
CVE-2026-17603 Code Injection in CVE-2026-17603 (CVE-2026-17603)
code injection in CVE-2026-17603 (CVE-2026-17603). Risk of unauthorized operations or information disclosure.
CVE-2026-19209 Cross-Site Scripting (XSS) in c (CVE-2026-19209)
cross-site scripting in c (CVE-2026-19209). Risk of unauthorized operations or information disclosure.
CVE-2026-19207 Cross-Site Scripting (XSS) in CVE-2026-19207 (CVE-2026-19207)
cross-site scripting in CVE-2026-19207 (CVE-2026-19207). Risk of unauthorized operations or information disclosure.
CVE-2026-19110 Cross-Site Scripting (XSS) in CVE-2026-19110 (CVE-2026-19110)
cross-site scripting in CVE-2026-19110 (CVE-2026-19110). Risk of unauthorized operations or information disclosure.
CVE-2026-19060 Vulnerability in CVE-2026-19060 (CVE-2026-19060)
vulnerability in CVE-2026-19060 (CVE-2026-19060). Risk of unauthorized operations or information disclosure.
CVE-2026-19058 Vulnerability in CVE-2026-19058 (CVE-2026-19058)
vulnerability in CVE-2026-19058 (CVE-2026-19058). Risk of unauthorized operations or information disclosure.
CVE-2026-50159 Code Injection in mermaid (CVE-2026-50159)
code injection in mermaid (CVE-2026-50159). Risk of unauthorized operations or information disclosure. Exploitable via ``secure``. Mitigation: upgrade to `10.9.8` or later.
CVE-2026-66709 Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-65553 Code Injection in CVE-2026-65553 (CVE-2026-65553)
code injection in CVE-2026-65553 (CVE-2026-65553). Successful exploitation can lead to full system takeover.
CVE-2026-65548 Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
CVE-2026-18968 Cross-Site Scripting (XSS) in CVE-2026-18968 (CVE-2026-18968)
cross-site scripting in CVE-2026-18968 (CVE-2026-18968). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →