Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13213 |
|
Vulnerability in c (CVE-2026-13213)
vulnerability in c (CVE-2026-13213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76071 |
|
Vulnerability in CVE-2026-76071 (CVE-2026-76071)
vulnerability in CVE-2026-76071 (CVE-2026-76071). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76070 |
|
Vulnerability in CVE-2026-76070 (CVE-2026-76070)
vulnerability in CVE-2026-76070 (CVE-2026-76070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71366 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71366)
SSRF in ssrf (CVE-2026-71366). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-71364 |
|
Path Traversal in path-traversal (CVE-2026-71364)
path traversal in path-traversal (CVE-2026-71364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67204 |
|
Authorization Flaw in CVE-2026-67204 (CVE-2026-67204)
vulnerability in CVE-2026-67204 (CVE-2026-67204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13343 |
|
Information Disclosure in c (CVE-2026-13343)
vulnerability in c (CVE-2026-13343). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-68825 |
|
Vulnerability in CVE-2025-68825 (CVE-2025-68825)
vulnerability in CVE-2025-68825 (CVE-2025-68825). Confidential information can be exposed externally.
|
| CVE-2026-78414 |
|
Cross-Site Scripting (XSS) in CVE-2026-78414 (CVE-2026-78414)
cross-site scripting in CVE-2026-78414 (CVE-2026-78414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78391 |
|
Cross-Site Scripting (XSS) in CVE-2026-78391 (CVE-2026-78391)
cross-site scripting in CVE-2026-78391 (CVE-2026-78391). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78387 |
|
Vulnerability in CVE-2026-78387 (CVE-2026-78387)
vulnerability in CVE-2026-78387 (CVE-2026-78387). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39914 |
|
Vulnerability in CVE-2026-39914 (CVE-2026-39914)
vulnerability in CVE-2026-39914 (CVE-2026-39914). Confidential information can be exposed externally.
|
| CVE-2026-65053 |
|
Cross-Site Scripting (XSS) in CVE-2026-65053 (CVE-2026-65053)
cross-site scripting in CVE-2026-65053 (CVE-2026-65053). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76055 |
|
OS Command Injection in c (CVE-2026-76055)
OS command injection in c (CVE-2026-76055). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78376 |
|
Use-After-Free in CVE-2026-78376 (CVE-2026-78376)
vulnerability in CVE-2026-78376 (CVE-2026-78376). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19874 |
|
Vulnerability in CVE-2026-19874 (CVE-2026-19874)
vulnerability in CVE-2026-19874 (CVE-2026-19874). Data can be tampered with by attackers.
|
| CVE-2026-78386 |
|
Information Disclosure in CVE-2026-78386 (CVE-2026-78386)
vulnerability in CVE-2026-78386 (CVE-2026-78386). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78378 |
|
Information Disclosure in CVE-2026-78378 (CVE-2026-78378)
vulnerability in CVE-2026-78378 (CVE-2026-78378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78385 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-78385)
SSRF in ssrf (CVE-2026-78385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78381 |
|
Path Traversal in path-traversal (CVE-2026-78381)
path traversal in path-traversal (CVE-2026-78381). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78380 |
|
Vulnerability in CVE-2026-78380 (CVE-2026-78380)
vulnerability in CVE-2026-78380 (CVE-2026-78380). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78372 |
|
Vulnerability in CVE-2026-78372 (CVE-2026-78372)
vulnerability in CVE-2026-78372 (CVE-2026-78372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78370 |
|
Vulnerability in CVE-2026-78370 (CVE-2026-78370)
vulnerability in CVE-2026-78370 (CVE-2026-78370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78250 |
|
Vulnerability in CVE-2026-78250 (CVE-2026-78250)
vulnerability in CVE-2026-78250 (CVE-2026-78250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78369 |
|
Vulnerability in CVE-2026-78369 (CVE-2026-78369)
vulnerability in CVE-2026-78369 (CVE-2026-78369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78248 |
|
Vulnerability in sqli (CVE-2026-78248)
vulnerability in sqli (CVE-2026-78248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78367 |
|
Code Injection in CVE-2026-78367 (CVE-2026-78367)
code injection in CVE-2026-78367 (CVE-2026-78367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76841 |
|
Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59568 |
|
Vulnerability in CVE-2026-59568 (CVE-2026-59568)
vulnerability in CVE-2026-59568 (CVE-2026-59568). Confidential information can be exposed externally.
|
| CVE-2026-76840 |
|
Vulnerability in c (CVE-2026-76840)
vulnerability in c (CVE-2026-76840). Data can be tampered with by attackers.
|
| CVE-2026-76848 |
|
SQL Injection in CVE-2026-76848 (CVE-2026-76848)
SQL injection in CVE-2026-76848 (CVE-2026-76848). Confidential information can be exposed externally.
|
| CVE-2026-78247 |
|
Vulnerability in sqli (CVE-2026-78247)
vulnerability in sqli (CVE-2026-78247). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17033 |
|
Cross-Site Scripting (XSS) in CVE-2026-17033 (CVE-2026-17033)
cross-site scripting in CVE-2026-17033 (CVE-2026-17033). Confidential information can be exposed externally.
|
| CVE-2026-76843 |
|
Unsafe Deserialization in CVE-2026-76843 (CVE-2026-76843)
vulnerability in CVE-2026-76843 (CVE-2026-76843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76844 |
|
Path Traversal in CVE-2026-76844 (CVE-2026-76844)
path traversal in CVE-2026-76844 (CVE-2026-76844). Confidential information can be exposed externally. Exploitable via `GET /assets../.env`.
|
| CVE-2026-76842 |
|
Path Traversal in CVE-2026-76842 (CVE-2026-76842)
path traversal in CVE-2026-76842 (CVE-2026-76842). Confidential information can be exposed externally.
|
| CVE-2026-76847 |
|
Vulnerability in CVE-2026-76847 (CVE-2026-76847)
vulnerability in CVE-2026-76847 (CVE-2026-76847). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78365 |
|
Vulnerability in CVE-2026-78365 (CVE-2026-78365)
vulnerability in CVE-2026-78365 (CVE-2026-78365). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76845 |
|
Vulnerability in CVE-2026-76845 (CVE-2026-76845)
vulnerability in CVE-2026-76845 (CVE-2026-76845). Data can be tampered with by attackers.
|
| CVE-2026-30512 |
|
Vulnerability in privilege-escalation (CVE-2026-30512)
vulnerability in privilege-escalation (CVE-2026-30512). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59567 |
|
Vulnerability in privilege-escalation (CVE-2026-59567)
vulnerability in privilege-escalation (CVE-2026-59567). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67602 |
|
Vulnerability in CVE-2026-67602 (CVE-2026-67602)
vulnerability in CVE-2026-67602 (CVE-2026-67602). Confidential information can be exposed externally.
|
| CVE-2026-9728 |
|
Vulnerability in c (CVE-2026-9728)
vulnerability in c (CVE-2026-9728). Confidential information can be exposed externally.
|
| CVE-2026-78277 |
|
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
|
| CVE-2026-78323 |
|
Vulnerability in CVE-2026-78323 (CVE-2026-78323)
vulnerability in CVE-2026-78323 (CVE-2026-78323). Confidential information can be exposed externally.
|
| CVE-2026-78291 |
|
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
|
| CVE-2026-78272 |
|
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.
|
| CVE-2026-78270 |
|
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
|
| CVE-2026-78290 |
|
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
|
| CVE-2026-78279 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.
|