Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-45327 |
|
Vulnerability in github.com/DatanoiseTV/tinyice (CVE-2026-45327)
vulnerability in github.com/DatanoiseTV/tinyice (CVE-2026-45327). Data can be tampered with by attackers. Exploitable via `POST /webrtc/source-offer`. Mitigation: upgrade to `2.5.0` or later.
|
| CVE-2026-41085 |
|
Privilege Escalation in privilege-escalation (CVE-2026-41085)
vulnerability in privilege-escalation (CVE-2026-41085). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45270 |
|
Cross-Site Scripting (XSS) in ci4-cms-erp/ci4ms (CVE-2026-45270)
cross-site scripting in ci4-cms-erp/ci4ms (CVE-2026-45270). Confidential information can be exposed externally. Exploitable via ``Pages``. Mitigation: upgrade to `0.31.9.0` or later.
|
| CVE-2025-56352 |
|
Vulnerability in dos (CVE-2025-56352)
vulnerability in dos (CVE-2025-56352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26462 |
|
Vulnerability in CVE-2026-26462 (CVE-2026-26462)
vulnerability in CVE-2026-26462 (CVE-2026-26462). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45135 |
|
Vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-45135)
vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-45135). Successful exploitation can lead to full system takeover. Exploitable via ``search.IgnoreCase``. Mitigation: upgrade to `2.11.3` or later.
|
| CVE-2026-45609 |
|
SSRF (Server-Side Request Forgery) in org.springaicommunity:mcp-client-security (CVE-2026-45609)
SSRF in org.springaicommunity:mcp-client-security (CVE-2026-45609). Risk of unauthorized operations or information disclosure. Exploitable via ``McpOAuth2ClientManager``. Mitigation: upgrade to `0.1.9` or later.
|
| CVE-2026-42009 |
|
Vulnerability in dos (CVE-2026-42009)
vulnerability in dos (CVE-2026-42009). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7498 |
|
Cross-Site Scripting (XSS) in CVE-2026-7498 (CVE-2026-7498)
cross-site scripting in CVE-2026-7498 (CVE-2026-7498). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6379 |
|
SQL Injection in wordpress (CVE-2026-6379)
SQL injection in wordpress (CVE-2026-6379). Confidential information can be exposed externally.
|
| CVE-2026-6495 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6495)
cross-site scripting in wordpress (CVE-2026-6495). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3220 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3220)
cross-site scripting in wordpress (CVE-2026-3220). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8785 |
|
Vulnerability in sqli (CVE-2026-8785)
vulnerability in sqli (CVE-2026-8785). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8771 |
|
Vulnerability in org.linlinjava:litemall-wx-api (CVE-2026-8771)
vulnerability in org.linlinjava:litemall-wx-api (CVE-2026-8771). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8757 |
|
Path Traversal in path-traversal (CVE-2026-8757)
path traversal in path-traversal (CVE-2026-8757). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8756 |
|
Path Traversal in path-traversal (CVE-2026-8756)
path traversal in path-traversal (CVE-2026-8756). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8755 |
|
Path Traversal in path-traversal (CVE-2026-8755)
path traversal in path-traversal (CVE-2026-8755). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25339 |
|
SQL Injection in sqli (CVE-2018-25339)
SQL injection in sqli (CVE-2018-25339). Confidential information can be exposed externally.
|
| CVE-2018-25338 |
|
SQL Injection in sqli (CVE-2018-25338)
SQL injection in sqli (CVE-2018-25338). Confidential information can be exposed externally.
|
| CVE-2018-25333 |
|
SQL Injection in sqli (CVE-2018-25333)
SQL injection in sqli (CVE-2018-25333). Confidential information can be exposed externally.
|
| CVE-2018-25330 |
|
SQL Injection in sqli (CVE-2018-25330)
SQL injection in sqli (CVE-2018-25330). Confidential information can be exposed externally.
|
| CVE-2018-25326 |
|
Path Traversal in wordpress (CVE-2018-25326)
path traversal in wordpress (CVE-2018-25326). Confidential information can be exposed externally.
|
| CVE-2018-25319 |
|
SQL Injection in sqli (CVE-2018-25319)
SQL injection in sqli (CVE-2018-25319). Confidential information can be exposed externally.
|
| CVE-2018-25325 |
|
Path Traversal in wordpress (CVE-2018-25325)
path traversal in wordpress (CVE-2018-25325). Confidential information can be exposed externally.
|
| CVE-2026-8751 |
|
Vulnerability in deserialization (CVE-2026-8751)
vulnerability in deserialization (CVE-2026-8751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8734 |
|
Vulnerability in sqli (CVE-2026-8734)
vulnerability in sqli (CVE-2026-8734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8719 |
|
Privilege Escalation in wordpress (CVE-2026-8719)
vulnerability in wordpress (CVE-2026-8719). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47976 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2021-47976)
vulnerability in csrf (CVE-2021-47976). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47980 |
|
SQL Injection in sqli (CVE-2021-47980)
SQL injection in sqli (CVE-2021-47980). Confidential information can be exposed externally.
|
| CVE-2021-47977 |
|
Path Traversal in wordpress (CVE-2021-47977)
path traversal in wordpress (CVE-2021-47977). Confidential information can be exposed externally.
|
| CVE-2021-47973 |
|
Vulnerability in dos (CVE-2021-47973)
vulnerability in dos (CVE-2021-47973). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47972 |
|
Vulnerability in dos (CVE-2021-47972)
vulnerability in dos (CVE-2021-47972). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47971 |
|
Vulnerability in dos (CVE-2021-47971)
vulnerability in dos (CVE-2021-47971). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47970 |
|
Vulnerability in dos (CVE-2021-47970)
vulnerability in dos (CVE-2021-47970). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47969 |
|
Vulnerability in dos (CVE-2021-47969)
vulnerability in dos (CVE-2021-47969). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47975 |
|
Cross-Site Scripting (XSS) in CVE-2021-47975 (CVE-2021-47975)
cross-site scripting in CVE-2021-47975 (CVE-2021-47975). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47954 |
|
SQL Injection in sqli (CVE-2021-47954)
SQL injection in sqli (CVE-2021-47954). Confidential information can be exposed externally.
|
| CVE-2021-47956 |
|
SQL Injection in sqli (CVE-2021-47956)
SQL injection in sqli (CVE-2021-47956). Confidential information can be exposed externally.
|
| CVE-2021-47942 |
|
Path Traversal in path-traversal (CVE-2021-47942)
path traversal in path-traversal (CVE-2021-47942). Confidential information can be exposed externally.
|
| CVE-2020-37242 |
|
SQL Injection in sqli (CVE-2020-37242)
SQL injection in sqli (CVE-2020-37242). Confidential information can be exposed externally.
|
| CVE-2020-37243 |
|
SQL Injection in sqli (CVE-2020-37243)
SQL injection in sqli (CVE-2020-37243). Confidential information can be exposed externally.
|
| CVE-2020-37244 |
|
SQL Injection in sqli (CVE-2020-37244)
SQL injection in sqli (CVE-2020-37244). Confidential information can be exposed externally.
|
| CVE-2020-37245 |
|
Cross-Site Scripting (XSS) in path-traversal (CVE-2020-37245)
cross-site scripting in path-traversal (CVE-2020-37245). Confidential information can be exposed externally.
|
| CVE-2020-37227 |
|
Unrestricted File Upload in CVE-2020-37227 (CVE-2020-37227)
vulnerability in CVE-2020-37227 (CVE-2020-37227). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8696 |
|
Use-After-Free in dos (CVE-2026-8696)
vulnerability in dos (CVE-2026-8696). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8686 |
|
Out-of-Bounds Read in Amazon aws (CVE-2026-8686)
vulnerability in Amazon aws (CVE-2026-8686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46407 |
|
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator to...
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the backend admin/auth-token endpoint allows an authenticated administrator to load another administrator's REST API token list by supplying that user's admin_id. This can disclo...
|
| CVE-2026-46367 |
|
Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
|
| CVE-2026-46359 |
|
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
|
| CVE-2026-46366 |
|
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
|