Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12722 |
|
Vulnerability in CVE-2026-12722 (CVE-2026-12722)
vulnerability in CVE-2026-12722 (CVE-2026-12722). Confidential information can be exposed externally.
|
| CVE-2026-54367 |
|
Vulnerability in CVE-2026-54367 (CVE-2026-54367)
vulnerability in CVE-2026-54367 (CVE-2026-54367). Data can be tampered with by attackers.
|
| CVE-2026-59309 |
|
Vulnerability in vmware (CVE-2026-59309)
vulnerability in vmware (CVE-2026-59309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54365 |
|
Vulnerability in deserialization (CVE-2026-54365)
vulnerability in deserialization (CVE-2026-54365). Data can be tampered with by attackers.
|
| CVE-2026-41703 |
|
Out-of-Bounds Read in dos (CVE-2026-41703)
vulnerability in dos (CVE-2026-41703). Confidential information can be exposed externally.
|
| CVE-2026-53431 |
|
Vulnerability in CVE-2026-53431 (CVE-2026-53431)
vulnerability in CVE-2026-53431 (CVE-2026-53431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57859 |
|
Unsafe Deserialization in deserialization (CVE-2026-57859)
vulnerability in deserialization (CVE-2026-57859). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18369 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-18369)
SSRF in ssrf (CVE-2026-18369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17543 |
|
SQL Injection in sqli (CVE-2026-17543)
SQL injection in sqli (CVE-2026-17543). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18360 |
|
Cross-Site Scripting (XSS) in CVE-2026-18360 (CVE-2026-18360)
cross-site scripting in CVE-2026-18360 (CVE-2026-18360). Confidential information can be exposed externally.
|
| CVE-2026-18361 |
|
Cross-Site Scripting (XSS) in CVE-2026-18361 (CVE-2026-18361)
cross-site scripting in CVE-2026-18361 (CVE-2026-18361). Confidential information can be exposed externally.
|
| CVE-2026-16969 |
|
Cross-Site Scripting (XSS) in CVE-2026-16969 (CVE-2026-16969)
cross-site scripting in CVE-2026-16969 (CVE-2026-16969). Confidential information can be exposed externally.
|
| CVE-2026-44106 |
|
A privilege escalation vulnerability in the init-script for user-applications allows a low...
A privilege escalation vulnerability in the init-script for user-applications allows a low...
|
| CVE-2026-44107 |
|
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
A reboot of the charging controller can be triggered via Modbus TCP without authentication....
|
| CVE-2026-44099 |
|
A privilege escalation vulnerability in the system configuration allows a low-privileged local...
A privilege escalation vulnerability in the system configuration allows a low-privileged local...
|
| CVE-2026-44094 |
|
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition...
|
| CVE-2026-44098 |
|
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
|
| CVE-2026-44093 |
|
A local privilege escalation vulnerability in the init-script for user-applications allows a low...
A local privilege escalation vulnerability in the init-script for user-applications allows a low...
|
| CVE-2026-44095 |
|
A privilege escalation vulnerability in a script used for network configuration allows a low...
A privilege escalation vulnerability in a script used for network configuration allows a low...
|
| CVE-2026-44096 |
|
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute...
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute...
|
| CVE-2026-44097 |
|
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
|
| CVE-2026-13584 |
|
Vulnerability in dos (CVE-2026-13584)
vulnerability in dos (CVE-2026-13584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16529 |
|
Vulnerability in dos (CVE-2026-16529)
vulnerability in dos (CVE-2026-16529). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16530 |
|
Out-of-Bounds Read in dos (CVE-2026-16530)
vulnerability in dos (CVE-2026-16530). Risk of unauthorized operations or information disclosure. Exploitable via ``pmproxy``.
|
| CVE-2026-47858 |
|
Vulnerability in spring (CVE-2026-47858)
vulnerability in spring (CVE-2026-47858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59327 |
|
Vulnerability in spring (CVE-2026-59327)
vulnerability in spring (CVE-2026-59327). Confidential information can be exposed externally.
|
| CVE-2026-58046 |
|
SQL Injection in sqli (CVE-2026-58046)
SQL injection in sqli (CVE-2026-58046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16531 |
|
Path Traversal in path-traversal (CVE-2026-16531)
path traversal in path-traversal (CVE-2026-16531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14602 |
|
Code Injection in wordpress (CVE-2026-14602)
code injection in wordpress (CVE-2026-14602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13395 |
|
SQL Injection in wordpress (CVE-2026-13395)
SQL injection in wordpress (CVE-2026-13395). Confidential information can be exposed externally.
|
| CVE-2026-15153 |
|
SQL Injection in wordpress (CVE-2026-15153)
SQL injection in wordpress (CVE-2026-15153). Confidential information can be exposed externally.
|
| CVE-2026-14239 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14239)
cross-site scripting in wordpress (CVE-2026-14239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13330 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13330)
cross-site scripting in wordpress (CVE-2026-13330). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11881 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11881)
cross-site scripting in wordpress (CVE-2026-11881). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13344 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13344)
cross-site scripting in wordpress (CVE-2026-13344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67247 |
|
Path Traversal in path-traversal (CVE-2026-67247)
path traversal in path-traversal (CVE-2026-67247). Confidential information can be exposed externally.
|
| CVE-2026-12687 |
|
Privilege Escalation in wordpress (CVE-2026-12687)
vulnerability in wordpress (CVE-2026-12687). Confidential information can be exposed externally.
|
| CVE-2026-67248 |
|
Vulnerability in dos (CVE-2026-67248)
vulnerability in dos (CVE-2026-67248). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1360 |
|
Unsafe Deserialization in wordpress (CVE-2026-1360)
vulnerability in wordpress (CVE-2026-1360). Successful exploitation can lead to full system takeover. Exploitable via ``allowed_classes``.
|
| CVE-2026-16610 |
|
Unrestricted File Upload in wordpress (CVE-2026-16610)
vulnerability in wordpress (CVE-2026-16610). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67246 |
|
Path Traversal in path-traversal (CVE-2026-67246)
path traversal in path-traversal (CVE-2026-67246). Confidential information can be exposed externally.
|
| CVE-2026-67245 |
|
Path Traversal in path-traversal (CVE-2026-67245)
path traversal in path-traversal (CVE-2026-67245). Data can be tampered with by attackers.
|
| CVE-2026-16092 |
|
SQL Injection in wordpress (CVE-2026-16092)
SQL injection in wordpress (CVE-2026-16092). Confidential information can be exposed externally.
|
| CVE-2026-48448 |
|
SQL Injection in sqli (CVE-2026-48448)
SQL injection in sqli (CVE-2026-48448). Confidential information can be exposed externally.
|
| CVE-2026-67244 |
|
Vulnerability in dos (CVE-2026-67244)
vulnerability in dos (CVE-2026-67244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18188 |
|
Vulnerability in dos (CVE-2026-18188)
vulnerability in dos (CVE-2026-18188). Confidential information can be exposed externally.
|
| CVE-2026-18186 |
|
Vulnerability in dos (CVE-2026-18186)
vulnerability in dos (CVE-2026-18186). Confidential information can be exposed externally.
|
| CVE-2026-18187 |
|
Vulnerability in dos (CVE-2026-18187)
vulnerability in dos (CVE-2026-18187). Confidential information can be exposed externally.
|
| CVE-2026-15929 |
|
SQL Injection in sqli (CVE-2026-15929)
SQL injection in sqli (CVE-2026-15929). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17993 |
|
Vulnerability in privilege-escalation (CVE-2026-17993)
vulnerability in privilege-escalation (CVE-2026-17993). Successful exploitation can lead to full system takeover.
|