Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-48132 |
|
Out-of-Bounds Read in dos (CVE-2026-48132)
vulnerability in dos (CVE-2026-48132). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8047 |
|
Vulnerability in dos (CVE-2026-8047)
vulnerability in dos (CVE-2026-8047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39642 |
|
Vulnerability in CVE-2026-39642 (CVE-2026-39642)
vulnerability in CVE-2026-39642 (CVE-2026-39642). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27427 |
|
Cross-Site Scripting (XSS) in CVE-2026-27427 (CVE-2026-27427)
cross-site scripting in CVE-2026-27427 (CVE-2026-27427). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44469 |
|
Vulnerability in privilege-escalation (CVE-2026-44469)
vulnerability in privilege-escalation (CVE-2026-44469). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44468 |
|
Vulnerability in privilege-escalation (CVE-2026-44468)
vulnerability in privilege-escalation (CVE-2026-44468). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9496 |
|
Vulnerability in pacote (CVE-2026-9496)
vulnerability in pacote (CVE-2026-9496). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `21.5.1` or later.
|
| CVE-2026-9526 |
|
Vulnerability in sqli (CVE-2026-9526)
vulnerability in sqli (CVE-2026-9526). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9528 |
|
Vulnerability in sqli (CVE-2026-9528)
vulnerability in sqli (CVE-2026-9528). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9525 |
|
Vulnerability in sqli (CVE-2026-9525)
vulnerability in sqli (CVE-2026-9525). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9524 |
|
Vulnerability in sqli (CVE-2026-9524)
vulnerability in sqli (CVE-2026-9524). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9523 |
|
Vulnerability in sqli (CVE-2026-9523)
vulnerability in sqli (CVE-2026-9523). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9519 |
|
Cross-Site Scripting (XSS) in CVE-2026-9519 (CVE-2026-9519)
cross-site scripting in CVE-2026-9519 (CVE-2026-9519). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9518 |
|
Cross-Site Scripting (XSS) in CVE-2026-9518 (CVE-2026-9518)
cross-site scripting in CVE-2026-9518 (CVE-2026-9518). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71310 |
|
Vulnerability in CVE-2025-71310 (CVE-2025-71310)
vulnerability in CVE-2025-71310 (CVE-2025-71310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9527 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-9527)
cross-site scripting in c (CVE-2026-9527). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9520 |
|
Cross-Site Scripting (XSS) in blitz (CVE-2026-9520)
cross-site scripting in blitz (CVE-2026-9520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48837 |
|
SQL Injection in sqli (CVE-2026-48837)
SQL injection in sqli (CVE-2026-48837). Confidential information can be exposed externally.
|
| CVE-2026-42774 |
|
SQL Injection in sqli (CVE-2026-42774)
SQL injection in sqli (CVE-2026-42774). Confidential information can be exposed externally.
|
| CVE-2026-42773 |
|
SQL Injection in sqli (CVE-2026-42773)
SQL injection in sqli (CVE-2026-42773). Confidential information can be exposed externally.
|
| CVE-2026-45435 |
|
Cross-Site Scripting (XSS) in CVE-2026-45435 (CVE-2026-45435)
cross-site scripting in CVE-2026-45435 (CVE-2026-45435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39436 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39436)
vulnerability in csrf (CVE-2026-39436). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45217 |
|
Vulnerability in CVE-2026-45217 (CVE-2026-45217)
vulnerability in CVE-2026-45217 (CVE-2026-45217). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45216 |
|
Vulnerability in privilege-escalation (CVE-2026-45216)
vulnerability in privilege-escalation (CVE-2026-45216). Successful exploitation can lead to full system takeover.
|
| CVE-2025-62745 |
|
Cross-Site Scripting (XSS) in CVE-2025-62745 (CVE-2025-62745)
cross-site scripting in CVE-2025-62745 (CVE-2025-62745). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24554 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-24554)
vulnerability in csrf (CVE-2026-24554). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9485 |
|
Cross-Site Scripting (XSS) in CVE-2026-9485 (CVE-2026-9485)
cross-site scripting in CVE-2026-9485 (CVE-2026-9485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44598 |
|
Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-24597 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-24597)
vulnerability in csrf (CVE-2026-24597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24574 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-24574)
vulnerability in csrf (CVE-2026-24574). Data can be tampered with by attackers.
|
| CVE-2026-9497 |
|
Vulnerability in org.mengyun:tcc-transaction (CVE-2026-9497)
vulnerability in org.mengyun:tcc-transaction (CVE-2026-9497). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48845 |
|
Vulnerability in privilege-escalation (CVE-2026-48845)
vulnerability in privilege-escalation (CVE-2026-48845). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48842 |
|
SQL Injection in sqli (CVE-2026-48842)
SQL injection in sqli (CVE-2026-48842). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48849 |
|
Cross-Site Scripting (XSS) in CVE-2026-48849 (CVE-2026-48849)
cross-site scripting in CVE-2026-48849 (CVE-2026-48849). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48843 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48843)
SSRF in ssrf (CVE-2026-48843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9474 |
|
Vulnerability in sqli (CVE-2026-9474)
vulnerability in sqli (CVE-2026-9474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9472 |
|
Path Traversal in path-traversal (CVE-2026-9472)
path traversal in path-traversal (CVE-2026-9472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9473 |
|
Path Traversal in c (CVE-2026-9473)
path traversal in c (CVE-2026-9473). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9470 |
|
Vulnerability in sqli (CVE-2026-9470)
vulnerability in sqli (CVE-2026-9470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9469 |
|
Vulnerability in sqli (CVE-2026-9469)
vulnerability in sqli (CVE-2026-9469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27768 |
|
SQL Injection affecting the Access Manager role.
SQL Injection affecting the Access Manager role.
|
| CVE-2026-9471 |
|
Cross-Site Scripting (XSS) in CVE-2026-9471 (CVE-2026-9471)
cross-site scripting in CVE-2026-9471 (CVE-2026-9471). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9467 |
|
Path Traversal in path-traversal (CVE-2026-9467)
path traversal in path-traversal (CVE-2026-9467). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9468 |
|
Path Traversal in path-traversal (CVE-2026-9468)
path traversal in path-traversal (CVE-2026-9468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9465 |
|
Vulnerability in sqli (CVE-2026-9465)
vulnerability in sqli (CVE-2026-9465). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25380 |
|
SQL Injection in sqli (CVE-2018-25380)
SQL injection in sqli (CVE-2018-25380). Confidential information can be exposed externally.
|
| CVE-2018-25381 |
|
SQL Injection in sqli (CVE-2018-25381)
SQL injection in sqli (CVE-2018-25381). Confidential information can be exposed externally.
|
| CVE-2018-25379 |
|
SQL Injection in sqli (CVE-2018-25379)
SQL injection in sqli (CVE-2018-25379). Confidential information can be exposed externally.
|
| CVE-2018-25378 |
|
Vulnerability in dos (CVE-2018-25378)
vulnerability in dos (CVE-2018-25378). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25368 |
|
Vulnerability in dos (CVE-2018-25368)
vulnerability in dos (CVE-2018-25368). Confidential information can be exposed externally.
|