Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82424 |
|
A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this...
A weakness has been identified in PHPGurukul Student Information System 1.0. Affected by this...
|
| CVE-2026-82422 |
|
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is...
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Impacted is...
|
| CVE-2026-15369 |
|
Privilege Escalation in wordpress (CVE-2026-15369)
vulnerability in wordpress (CVE-2026-15369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82421 |
|
Vulnerability in sqli (CVE-2026-82421)
vulnerability in sqli (CVE-2026-82421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75807 |
|
Authentication Bypass in wordpress (CVE-2026-75807)
authentication bypass in wordpress (CVE-2026-75807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82476 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82476)
SSRF in ssrf (CVE-2026-82476). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82475 |
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
| CVE-2026-82468 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-82468)
vulnerability in csrf (CVE-2026-82468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82473 |
|
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
|
| CVE-2026-82470 |
|
Vulnerability in CVE-2026-82470 (CVE-2026-82470)
vulnerability in CVE-2026-82470 (CVE-2026-82470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82474 |
|
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
|
| CVE-2026-82467 |
|
Open Redirect in CVE-2026-82467 (CVE-2026-82467)
vulnerability in CVE-2026-82467 (CVE-2026-82467). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82472 |
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
| CVE-2026-82460 |
|
Path Traversal in path-traversal (CVE-2026-82460)
path traversal in path-traversal (CVE-2026-82460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82464 |
|
Open Redirect in CVE-2026-82464 (CVE-2026-82464)
vulnerability in CVE-2026-82464 (CVE-2026-82464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82463 |
|
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-82461 |
|
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
|
| CVE-2026-82477 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82477)
SSRF in ssrf (CVE-2026-82477). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82455 |
|
Vulnerability in CVE-2026-82455 (CVE-2026-82455)
vulnerability in CVE-2026-82455 (CVE-2026-82455). Data can be tampered with by attackers.
|
| CVE-2026-82452 |
|
Vulnerability in c (CVE-2026-82452)
vulnerability in c (CVE-2026-82452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82451 |
|
Cross-Site Scripting (XSS) in CVE-2026-82451 (CVE-2026-82451)
cross-site scripting in CVE-2026-82451 (CVE-2026-82451). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2026-82454 |
|
Vulnerability in CVE-2026-82454 (CVE-2026-82454)
vulnerability in CVE-2026-82454 (CVE-2026-82454). Confidential information can be exposed externally.
|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82449 |
|
Vulnerability in CVE-2026-82449 (CVE-2026-82449)
vulnerability in CVE-2026-82449 (CVE-2026-82449). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82447 |
|
Vulnerability in CVE-2026-82447 (CVE-2026-82447)
vulnerability in CVE-2026-82447 (CVE-2026-82447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82448 |
|
Vulnerability in CVE-2026-82448 (CVE-2026-82448)
vulnerability in CVE-2026-82448 (CVE-2026-82448). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14494 |
|
Unrestricted File Upload in wordpress (CVE-2026-14494)
vulnerability in wordpress (CVE-2026-14494). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80192 |
|
Authentication Bypass in CVE-2026-80192 (CVE-2026-80192)
authentication bypass in CVE-2026-80192 (CVE-2026-80192). Confidential information can be exposed externally.
|
| CVE-2026-82364 |
|
Vulnerability in CVE-2026-82364 (CVE-2026-82364)
vulnerability in CVE-2026-82364 (CVE-2026-82364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41012 |
|
Vulnerability in CVE-2026-41012 (CVE-2026-41012)
vulnerability in CVE-2026-41012 (CVE-2026-41012). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55855 |
|
SQL Injection in mariadb (CVE-2026-55855)
SQL injection in mariadb (CVE-2026-55855). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-55860 |
|
Vulnerability in org.mariadb:r2dbc-mariadb (CVE-2026-55860)
vulnerability in org.mariadb:r2dbc-mariadb (CVE-2026-55860). Confidential information can be exposed externally. Mitigation: upgrade to `1.4.1` or later.
|
| CVE-2026-55859 |
|
Vulnerability in org.mariadb:r2dbc-mariadb (CVE-2026-55859)
vulnerability in org.mariadb:r2dbc-mariadb (CVE-2026-55859). Data can be tampered with by attackers. Mitigation: upgrade to `1.4.1` or later.
|
| CVE-2026-55857 |
|
Vulnerability in org.mariadb.jdbc:mariadb-java-client (CVE-2026-55857)
vulnerability in org.mariadb.jdbc:mariadb-java-client (CVE-2026-55857). Confidential information can be exposed externally. Mitigation: upgrade to `2.7.14` or later.
|
| CVE-2026-55856 |
|
Vulnerability in org.mariadb.jdbc:mariadb-java-client (CVE-2026-55856)
vulnerability in org.mariadb.jdbc:mariadb-java-client (CVE-2026-55856). Confidential information can be exposed externally. Mitigation: upgrade to `2.7.14` or later.
|
| CVE-2026-55848 |
|
XXE (XML External Entity) in org.mapfish.print:print-lib (CVE-2026-55848)
vulnerability in org.mapfish.print:print-lib (CVE-2026-55848). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-55785 |
|
Vulnerability in github.com/free5gc/ausf (CVE-2026-55785)
vulnerability in github.com/free5gc/ausf (CVE-2026-55785). Risk of unauthorized operations or information disclosure. Exploitable via ``AT_MAC``. Mitigation: upgrade to `1.4.5` or later.
|
| CVE-2026-55784 |
|
Vulnerability in github.com/free5gc/ausf (CVE-2026-55784)
vulnerability in github.com/free5gc/ausf (CVE-2026-55784). Risk of unauthorized operations or information disclosure. Exploitable via `POST /nausf-auth/v1/ue-authentications`.
|
| CVE-2026-55779 |
|
Cross-Site Scripting (XSS) in silverstripe/versioned (CVE-2026-55779)
cross-site scripting in silverstripe/versioned (CVE-2026-55779). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-82333 |
|
Vulnerability in dos (CVE-2026-82333)
vulnerability in dos (CVE-2026-82333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81533 |
|
Vulnerability in CVE-2026-81533 (CVE-2026-81533)
vulnerability in CVE-2026-81533 (CVE-2026-81533). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81532 |
|
Vulnerability in CVE-2026-81532 (CVE-2026-81532)
vulnerability in CVE-2026-81532 (CVE-2026-81532). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81490 |
|
Vulnerability in CVE-2026-81490 (CVE-2026-81490)
vulnerability in CVE-2026-81490 (CVE-2026-81490). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81518 |
|
Vulnerability in CVE-2026-81518 (CVE-2026-81518)
vulnerability in CVE-2026-81518 (CVE-2026-81518). Confidential information can be exposed externally.
|
| CVE-2026-76649 |
|
Vulnerability in CVE-2026-76649 (CVE-2026-76649)
vulnerability in CVE-2026-76649 (CVE-2026-76649). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76651 |
|
Vulnerability in CVE-2026-76651 (CVE-2026-76651)
vulnerability in CVE-2026-76651 (CVE-2026-76651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77063 |
|
Vulnerability in CVE-2026-77063 (CVE-2026-77063)
vulnerability in CVE-2026-77063 (CVE-2026-77063). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77037 |
|
Vulnerability in dos (CVE-2026-77037)
vulnerability in dos (CVE-2026-77037). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76650 |
|
Vulnerability in CVE-2026-76650 (CVE-2026-76650)
vulnerability in CVE-2026-76650 (CVE-2026-76650). Risk of unauthorized operations or information disclosure.
|