Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-20250 |
|
Path Traversal in wordpress (CVE-2017-20250)
path traversal in wordpress (CVE-2017-20250). Confidential information can be exposed externally.
|
| CVE-2017-20244 |
|
SQL Injection in wordpress (CVE-2017-20244)
SQL injection in wordpress (CVE-2017-20244). Confidential information can be exposed externally.
|
| CVE-2017-20245 |
|
SQL Injection in wordpress (CVE-2017-20245)
SQL injection in wordpress (CVE-2017-20245). Confidential information can be exposed externally.
|
| CVE-2017-20246 |
|
SQL Injection in wordpress (CVE-2017-20246)
SQL injection in wordpress (CVE-2017-20246). Confidential information can be exposed externally.
|
| CVE-2017-20247 |
|
SQL Injection in wordpress (CVE-2017-20247)
SQL injection in wordpress (CVE-2017-20247). Confidential information can be exposed externally.
|
| CVE-2017-20249 |
|
SQL Injection in sqli (CVE-2017-20249)
SQL injection in sqli (CVE-2017-20249). Confidential information can be exposed externally.
|
| CVE-2016-20063 |
|
SQL Injection in sqli (CVE-2016-20063)
SQL injection in sqli (CVE-2016-20063). Confidential information can be exposed externally.
|
| CVE-2016-20065 |
|
SQL Injection in wordpress (CVE-2016-20065)
SQL injection in wordpress (CVE-2016-20065). Confidential information can be exposed externally.
|
| CVE-2017-20243 |
|
SQL Injection in wordpress (CVE-2017-20243)
SQL injection in wordpress (CVE-2017-20243). Confidential information can be exposed externally.
|
| CVE-2016-20064 |
|
Vulnerability in path-traversal (CVE-2016-20064)
vulnerability in path-traversal (CVE-2016-20064). Confidential information can be exposed externally.
|
| CVE-2016-20062 |
|
SQL Injection in wordpress (CVE-2016-20062)
SQL injection in wordpress (CVE-2016-20062). Confidential information can be exposed externally.
|
| CVE-2026-49741 |
|
SQL Injection in typo3/cms-core (CVE-2026-49741)
SQL injection in typo3/cms-core (CVE-2026-49741). Risk of unauthorized operations or information disclosure. Exploitable via ``form_definition``. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47352 |
|
Vulnerability in typo3/cms-core (CVE-2026-47352)
vulnerability in typo3/cms-core (CVE-2026-47352). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-49740 |
|
Unsafe Deserialization in typo3/cms-core (CVE-2026-49740)
vulnerability in typo3/cms-core (CVE-2026-49740). Risk of unauthorized operations or information disclosure. Exploitable via ``VariableFrontend``. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-49738 |
|
Path Traversal in typo3/cms-core (CVE-2026-49738)
path traversal in typo3/cms-core (CVE-2026-49738). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-49742 |
|
Path Traversal in typo3/cms-core (CVE-2026-49742)
path traversal in typo3/cms-core (CVE-2026-49742). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47343 |
|
Vulnerability in typo3/cms-core (CVE-2026-47343)
vulnerability in typo3/cms-core (CVE-2026-47343). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47346 |
|
Vulnerability in typo3/cms-core (CVE-2026-47346)
vulnerability in typo3/cms-core (CVE-2026-47346). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47349 |
|
Vulnerability in typo3/cms-core (CVE-2026-47349)
vulnerability in typo3/cms-core (CVE-2026-47349). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47350 |
|
Vulnerability in typo3/cms-core (CVE-2026-47350)
vulnerability in typo3/cms-core (CVE-2026-47350). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47351 |
|
Information Disclosure in typo3/cms-core (CVE-2026-47351)
vulnerability in typo3/cms-core (CVE-2026-47351). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47348 |
|
Cross-Site Scripting (XSS) in typo3/cms-core (CVE-2026-47348)
cross-site scripting in typo3/cms-core (CVE-2026-47348). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-47347 |
|
Open Redirect in typo3/cms-core (CVE-2026-47347)
vulnerability in typo3/cms-core (CVE-2026-47347). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-11607 |
|
Vulnerability in typo3/cms-core (CVE-2026-11607)
vulnerability in typo3/cms-core (CVE-2026-11607). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `14.3.3` or later.
|
| CVE-2026-4058 |
|
Vulnerability in wordpress (CVE-2026-4058)
vulnerability in wordpress (CVE-2026-4058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52902 |
|
Path Traversal in awxkit (CVE-2026-52902)
path traversal in awxkit (CVE-2026-52902). Confidential information can be exposed externally.
|
| CVE-2026-46748 |
|
Vulnerability in siemens (CVE-2026-46748)
vulnerability in siemens (CVE-2026-46748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46746 |
|
OS Command Injection in siemens (CVE-2026-46746)
OS command injection in siemens (CVE-2026-46746). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41031 |
|
Cross-Site Scripting (XSS) in CVE-2026-41031 (CVE-2026-41031)
cross-site scripting in CVE-2026-41031 (CVE-2026-41031). Confidential information can be exposed externally.
|
| CVE-2026-10731 |
|
SQL Injection in sqli (CVE-2026-10731)
SQL injection in sqli (CVE-2026-10731). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-40808 |
|
Unrestricted File Upload in dos (CVE-2025-40808)
vulnerability in dos (CVE-2025-40808). Data can be tampered with by attackers.
|
| CVE-2025-10263 |
|
Vulnerability in jvn (CVE-2025-10263)
vulnerability in jvn (CVE-2025-10263). Confidential information can be exposed externally.
|
| CVE-2026-34033 |
|
Cross-Site Scripting (XSS) in github.com/apache/incubator-answer (CVE-2026-34033)
cross-site scripting in github.com/apache/incubator-answer (CVE-2026-34033). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.2-0.20260509080709-d1a4092c61cc` or later.
|
| CVE-2026-8677 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8677)
cross-site scripting in wordpress (CVE-2026-8677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8599 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8599)
cross-site scripting in wordpress (CVE-2026-8599). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8365 |
|
Unsafe Deserialization in wordpress (CVE-2026-8365)
vulnerability in wordpress (CVE-2026-8365). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49818 |
|
Path Traversal in apache-airflow-providers-samba (CVE-2026-49818)
path traversal in apache-airflow-providers-samba (CVE-2026-49818). Risk of unauthorized operations or information disclosure. Exploitable via ``GCSToSambaOperator``. Mitigation: upgrade to `4.12.6` or later.
|
| CVE-2026-11616 |
|
Privilege Escalation in wordpress (CVE-2026-11616)
vulnerability in wordpress (CVE-2026-11616). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28262 |
|
Vulnerability in CVE-2026-28262 (CVE-2026-28262)
vulnerability in CVE-2026-28262 (CVE-2026-28262). Data can be tampered with by attackers.
|
| CVE-2026-34905 |
|
Information Disclosure in github.com/apache/incubator-answer (CVE-2026-34905)
vulnerability in github.com/apache/incubator-answer (CVE-2026-34905). Confidential information can be exposed externally. Mitigation: upgrade to `1.7.2-0.20260509071350-11c80384f13a` or later.
|
| CVE-2026-7542 |
|
Information Disclosure in wordpress (CVE-2026-7542)
vulnerability in wordpress (CVE-2026-7542). Confidential information can be exposed externally.
|
| CVE-2026-34031 |
|
Unrestricted File Upload in github.com/apache/incubator-answer (CVE-2026-34031)
vulnerability in github.com/apache/incubator-answer (CVE-2026-34031). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.2-0.20260511040518-11091244f64e` or later.
|
| CVE-2026-33582 |
|
Unrestricted File Upload in github.com/apache/incubator-answer (CVE-2026-33582)
vulnerability in github.com/apache/incubator-answer (CVE-2026-33582). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.2-0.20260325113131-cfc3e54f30cc` or later.
|
| CVE-2026-5068 |
|
Out-of-Bounds Write in c (CVE-2026-5068)
out-of-bounds write in c (CVE-2026-5068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9698 |
|
Out-of-Bounds Write in perl (CVE-2026-9698)
out-of-bounds write in perl (CVE-2026-9698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41982 |
|
Use-After-Free in CVE-2026-41982 (CVE-2026-41982)
vulnerability in CVE-2026-41982 (CVE-2026-41982). Confidential information can be exposed externally.
|
| CVE-2026-41981 |
|
Vulnerability in CVE-2026-41981 (CVE-2026-41981)
vulnerability in CVE-2026-41981 (CVE-2026-41981). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41984 |
|
Vulnerability in CVE-2026-41984 (CVE-2026-41984)
vulnerability in CVE-2026-41984 (CVE-2026-41984). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41985 |
|
Vulnerability in CVE-2026-41985 (CVE-2026-41985)
vulnerability in CVE-2026-41985 (CVE-2026-41985). Data can be tampered with by attackers.
|
| CVE-2026-41983 |
|
Vulnerability in dos (CVE-2026-41983)
vulnerability in dos (CVE-2026-41983). Risk of unauthorized operations or information disclosure.
|