Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-52610 |
|
Path Traversal in path-traversal (CVE-2026-52610)
path traversal in path-traversal (CVE-2026-52610). Confidential information can be exposed externally.
|
| CVE-2026-52607 |
|
Path Traversal in path-traversal (CVE-2026-52607)
path traversal in path-traversal (CVE-2026-52607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67921 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-67921)
vulnerability in csrf (CVE-2026-67921). Confidential information can be exposed externally.
|
| CVE-2026-52609 |
|
Cross-Site Scripting (XSS) in CVE-2026-52609 (CVE-2026-52609)
cross-site scripting in CVE-2026-52609 (CVE-2026-52609). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52608 |
|
Vulnerability in CVE-2026-52608 (CVE-2026-52608)
vulnerability in CVE-2026-52608 (CVE-2026-52608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74046 |
|
Vulnerability in dos (CVE-2026-74046)
vulnerability in dos (CVE-2026-74046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74039 |
|
Vulnerability in dos (CVE-2026-74039)
vulnerability in dos (CVE-2026-74039). Risk of unauthorized operations or information disclosure. Exploitable via `POST /security/user/authenticate/run_as`.
|
| CVE-2026-74044 |
|
Path Traversal in path-traversal (CVE-2026-74044)
path traversal in path-traversal (CVE-2026-74044). Data can be tampered with by attackers.
|
| CVE-2026-74038 |
|
Path Traversal in path-traversal (CVE-2026-74038)
path traversal in path-traversal (CVE-2026-74038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61696 |
|
Vulnerability in csrf (CVE-2026-61696)
vulnerability in csrf (CVE-2026-61696). Confidential information can be exposed externally.
|
| CVE-2026-50161 |
|
Vulnerability in c (CVE-2026-50161)
vulnerability in c (CVE-2026-50161). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68923 |
|
Cross-Site Request Forgery (CSRF) in mobsf (CVE-2026-68923)
vulnerability in mobsf (CVE-2026-68923). Data can be tampered with by attackers. Exploitable via ``CsrfViewMiddleware``. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-63643 |
|
Vulnerability in magicmirror (CVE-2026-63643)
vulnerability in magicmirror (CVE-2026-63643). Risk of unauthorized operations or information disclosure. Exploitable via ``ADD_CALENDAR``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-75897 |
|
Vulnerability in Amazon dos (CVE-2026-75897)
vulnerability in Amazon dos (CVE-2026-75897). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75924 |
|
Privilege Escalation in privilege-escalation (CVE-2026-75924)
vulnerability in privilege-escalation (CVE-2026-75924). Confidential information can be exposed externally.
|
| CVE-2026-73336 |
|
Cross-Site Scripting (XSS) in CVE-2026-73336 (CVE-2026-73336)
cross-site scripting in CVE-2026-73336 (CVE-2026-73336). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70415 |
|
Vulnerability in dos (CVE-2026-70415)
vulnerability in dos (CVE-2026-70415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67271 |
|
Out-of-Bounds Write in dos (CVE-2026-67271)
out-of-bounds write in dos (CVE-2026-67271). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52606 |
|
Cross-Site Scripting (XSS) in CVE-2026-52606 (CVE-2026-52606)
cross-site scripting in CVE-2026-52606 (CVE-2026-52606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30250 |
|
Cross-Site Scripting (XSS) in CVE-2026-30250 (CVE-2026-30250)
cross-site scripting in CVE-2026-30250 (CVE-2026-30250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61634 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-61634)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-61634). Risk of unauthorized operations or information disclosure. Exploitable via ``frame_max``. Mitigation: upgrade to `5.33.0` or later.
|
| CVE-2026-63335 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-63335)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-63335). Risk of unauthorized operations or information disclosure. Exploitable via ``UnsupportedOperationException``. Mitigation: upgrade to `5.31.0` or later.
|
| CVE-2026-69219 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-69219)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-69219). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `5.33.1` or later.
|
| CVE-2026-69220 |
|
Vulnerability in com.rabbitmq:amqp-client (CVE-2026-69220)
vulnerability in com.rabbitmq:amqp-client (CVE-2026-69220). Risk of unauthorized operations or information disclosure. Exploitable via ``connection.start``. Mitigation: upgrade to `5.33.1` or later.
|
| CVE-2026-55839 |
|
Cross-Site Scripting (XSS) in io.kestra:kestra (CVE-2026-55839)
cross-site scripting in io.kestra:kestra (CVE-2026-55839). Confidential information can be exposed externally. Exploitable via ``onclick``. Mitigation: upgrade to `1.3.24` or later.
|
| CVE-2026-75914 |
|
Path Traversal in path-traversal (CVE-2026-75914)
path traversal in path-traversal (CVE-2026-75914). Confidential information can be exposed externally.
|
| CVE-2026-75856 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75856)
SSRF in ssrf (CVE-2026-75856). Confidential information can be exposed externally.
|
| CVE-2026-75858 |
|
Code Injection in CVE-2026-75858 (CVE-2026-75858)
code injection in CVE-2026-75858 (CVE-2026-75858). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.64` or later.
|
| CVE-2026-71365 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71365)
SSRF in ssrf (CVE-2026-71365). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-73337 |
|
Authentication Bypass in CVE-2026-73337 (CVE-2026-73337)
authentication bypass in CVE-2026-73337 (CVE-2026-73337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45126 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-45126)
vulnerability in csrf (CVE-2026-45126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45117 |
|
Code Injection in CVE-2026-45117 (CVE-2026-45117)
code injection in CVE-2026-45117 (CVE-2026-45117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73382 |
|
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
|
| CVE-2026-73393 |
|
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
|
| CVE-2026-73392 |
|
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
|
| CVE-2026-74015 |
|
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
|
| CVE-2026-74012 |
|
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
|
| CVE-2026-73397 |
|
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
|
| CVE-2026-75032 |
|
Out-of-Bounds Read in dos (CVE-2026-75032)
vulnerability in dos (CVE-2026-75032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73997 |
|
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
|
| CVE-2026-73190 |
|
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
|
| CVE-2026-73342 |
|
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
|
| CVE-2026-73358 |
|
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
|
| CVE-2026-73338 |
|
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
|
| CVE-2026-73359 |
|
Cross-Site Scripting (XSS) in CVE-2026-73359 (CVE-2026-73359)
cross-site scripting in CVE-2026-73359 (CVE-2026-73359). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73361 |
|
Cross-Site Scripting (XSS) in CVE-2026-73361 (CVE-2026-73361)
cross-site scripting in CVE-2026-73361 (CVE-2026-73361). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73351 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-73351)
cross-site scripting in wordpress (CVE-2026-73351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73360 |
|
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
|
| CVE-2026-73375 |
|
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
|
| CVE-2026-73362 |
|
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
|