Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73486 |
|
Code Injection in CVE-2026-73486 (CVE-2026-73486)
code injection in CVE-2026-73486 (CVE-2026-73486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0298 |
|
Code Injection in CVE-2026-0298 (CVE-2026-0298)
code injection in CVE-2026-0298 (CVE-2026-0298). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13094 |
|
Code Injection in ibm (CVE-2026-13094)
code injection in ibm (CVE-2026-13094). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73268 |
|
Code Injection in privilege-escalation (CVE-2026-73268)
code injection in privilege-escalation (CVE-2026-73268). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73299 |
|
Code Injection in CVE-2026-73299 (CVE-2026-73299)
code injection in CVE-2026-73299 (CVE-2026-73299). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65941 |
|
Vulnerability in CVE-2026-65941 (CVE-2026-65941)
vulnerability in CVE-2026-65941 (CVE-2026-65941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73291 |
|
Path Traversal in CVE-2026-73291 (CVE-2026-73291)
path traversal in CVE-2026-73291 (CVE-2026-73291). Data can be tampered with by attackers. Exploitable via `GET /avatarproxy/`.
|
| CVE-2026-67282 |
|
Code Injection in CVE-2026-67282 (CVE-2026-67282)
code injection in CVE-2026-67282 (CVE-2026-67282). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16051 |
|
Code Injection in wordpress (CVE-2026-16051)
code injection in wordpress (CVE-2026-16051). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73248 |
|
Code Injection in CVE-2026-73248 (CVE-2026-73248)
code injection in CVE-2026-73248 (CVE-2026-73248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66150 |
|
Code Injection in CVE-2026-66150 (CVE-2026-66150)
code injection in CVE-2026-66150 (CVE-2026-66150). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66148 |
|
Code Injection in CVE-2026-66148 (CVE-2026-66148)
code injection in CVE-2026-66148 (CVE-2026-66148). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66147 |
|
Code Injection in CVE-2026-66147 (CVE-2026-66147)
code injection in CVE-2026-66147 (CVE-2026-66147). Data can be tampered with by attackers.
|
| CVE-2026-66149 |
|
Code Injection in CVE-2026-66149 (CVE-2026-66149)
code injection in CVE-2026-66149 (CVE-2026-66149). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73233 |
|
Code Injection in cpp (CVE-2026-73233)
code injection in cpp (CVE-2026-73233). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73032 |
|
Code Injection in CVE-2026-73032 (CVE-2026-73032)
code injection in CVE-2026-73032 (CVE-2026-73032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66145 |
|
Code Injection in CVE-2026-66145 (CVE-2026-66145)
code injection in CVE-2026-66145 (CVE-2026-66145). Confidential information can be exposed externally.
|
| CVE-2026-18708 |
|
Code Injection in dos (CVE-2026-18708)
code injection in dos (CVE-2026-18708). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73084 |
|
Cross-Site Scripting (XSS) in CVE-2026-73084 (CVE-2026-73084)
cross-site scripting in CVE-2026-73084 (CVE-2026-73084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70338 |
|
Code Injection in microsoft (CVE-2026-70338)
code injection in microsoft (CVE-2026-70338). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70336 |
|
Code Injection in microsoft (CVE-2026-70336)
code injection in microsoft (CVE-2026-70336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65660 |
|
Code Injection in microsoft (CVE-2026-65660)
code injection in microsoft (CVE-2026-65660). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73076 |
|
Code Injection in CVE-2026-73076 (CVE-2026-73076)
code injection in CVE-2026-73076 (CVE-2026-73076). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19546 |
|
Code Injection in CVE-2026-19546 (CVE-2026-19546)
code injection in CVE-2026-19546 (CVE-2026-19546). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72765 |
|
Code Injection in CVE-2026-72765 (CVE-2026-72765)
code injection in CVE-2026-72765 (CVE-2026-72765). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58231 |
|
Code Injection in CVE-2026-58231 (CVE-2026-58231)
code injection in CVE-2026-58231 (CVE-2026-58231). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44758 |
|
Code Injection in CVE-2026-44758 (CVE-2026-44758)
code injection in CVE-2026-44758 (CVE-2026-44758). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18942 |
|
Code Injection in CVE-2026-18942 (CVE-2026-18942)
code injection in CVE-2026-18942 (CVE-2026-18942). Confidential information can be exposed externally.
|
| CVE-2026-72904 |
|
Command Injection in ssrf (CVE-2026-72904)
command injection in ssrf (CVE-2026-72904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72718 |
|
Code Injection in CVE-2026-72718 (CVE-2026-72718)
code injection in CVE-2026-72718 (CVE-2026-72718). Risk of unauthorized operations or information disclosure. Exploitable via ``git``.
|
| CVE-2026-66738 |
|
Code Injection in CVE-2026-66738 (CVE-2026-66738)
code injection in CVE-2026-66738 (CVE-2026-66738). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55799 |
|
Code Injection in apache (CVE-2026-55799)
code injection in apache (CVE-2026-55799). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42537 |
|
Vulnerability in apache (CVE-2026-42537)
vulnerability in apache (CVE-2026-42537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44416 |
|
Code Injection in apache (CVE-2026-44416)
code injection in apache (CVE-2026-44416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66915 |
|
Code Injection in CVE-2026-66915 (CVE-2026-66915)
code injection in CVE-2026-66915 (CVE-2026-66915). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19378 |
|
Cross-Site Scripting (XSS) in CVE-2026-19378 (CVE-2026-19378)
cross-site scripting in CVE-2026-19378 (CVE-2026-19378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46409 |
|
Code Injection in CVE-2026-46409 (CVE-2026-46409)
code injection in CVE-2026-46409 (CVE-2026-46409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19230 |
|
Cross-Site Scripting (XSS) in CVE-2026-19230 (CVE-2026-19230)
cross-site scripting in CVE-2026-19230 (CVE-2026-19230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17603 |
|
Code Injection in CVE-2026-17603 (CVE-2026-17603)
code injection in CVE-2026-17603 (CVE-2026-17603). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19209 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-19209)
cross-site scripting in c (CVE-2026-19209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19207 |
|
Cross-Site Scripting (XSS) in CVE-2026-19207 (CVE-2026-19207)
cross-site scripting in CVE-2026-19207 (CVE-2026-19207). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19110 |
|
Cross-Site Scripting (XSS) in CVE-2026-19110 (CVE-2026-19110)
cross-site scripting in CVE-2026-19110 (CVE-2026-19110). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19060 |
|
Vulnerability in CVE-2026-19060 (CVE-2026-19060)
vulnerability in CVE-2026-19060 (CVE-2026-19060). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19058 |
|
Vulnerability in CVE-2026-19058 (CVE-2026-19058)
vulnerability in CVE-2026-19058 (CVE-2026-19058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50159 |
|
Code Injection in mermaid (CVE-2026-50159)
code injection in mermaid (CVE-2026-50159). Risk of unauthorized operations or information disclosure. Exploitable via ``secure``. Mitigation: upgrade to `10.9.8` or later.
|
| CVE-2026-66709 |
|
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
|
| CVE-2026-65553 |
|
Code Injection in CVE-2026-65553 (CVE-2026-65553)
code injection in CVE-2026-65553 (CVE-2026-65553). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65548 |
|
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
|
| CVE-2026-15991 |
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
| CVE-2026-18968 |
|
Cross-Site Scripting (XSS) in CVE-2026-18968 (CVE-2026-18968)
cross-site scripting in CVE-2026-18968 (CVE-2026-18968). Risk of unauthorized operations or information disclosure.
|