Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-70383 |
|
Path Traversal in path-traversal (CVE-2026-70383)
path traversal in path-traversal (CVE-2026-70383). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76633 |
|
Vulnerability in CVE-2026-76633 (CVE-2026-76633)
vulnerability in CVE-2026-76633 (CVE-2026-76633). Confidential information can be exposed externally.
|
| CVE-2026-76635 |
|
SQL Injection in sqli (CVE-2026-76635)
SQL injection in sqli (CVE-2026-76635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64972 |
|
Cross-Site Scripting (XSS) in CVE-2026-64972 (CVE-2026-64972)
cross-site scripting in CVE-2026-64972 (CVE-2026-64972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64970 |
|
Cross-Site Scripting (XSS) in CVE-2026-64970 (CVE-2026-64970)
cross-site scripting in CVE-2026-64970 (CVE-2026-64970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64971 |
|
Cross-Site Scripting (XSS) in CVE-2026-64971 (CVE-2026-64971)
cross-site scripting in CVE-2026-64971 (CVE-2026-64971). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64968 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-64968 (CVE-2026-64968)
SSRF in CVE-2026-64968 (CVE-2026-64968). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64963 |
|
Path Traversal in path-traversal (CVE-2026-64963)
path traversal in path-traversal (CVE-2026-64963). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64966 |
|
Path Traversal in path-traversal (CVE-2026-64966)
path traversal in path-traversal (CVE-2026-64966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64967 |
|
Path Traversal in path-traversal (CVE-2026-64967)
path traversal in path-traversal (CVE-2026-64967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64965 |
|
Vulnerability in CVE-2026-64965 (CVE-2026-64965)
vulnerability in CVE-2026-64965 (CVE-2026-64965). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15706 |
|
Vulnerability in CVE-2026-15706 (CVE-2026-15706)
vulnerability in CVE-2026-15706 (CVE-2026-15706). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64960 |
|
Unrestricted File Upload in CVE-2026-64960 (CVE-2026-64960)
vulnerability in CVE-2026-64960 (CVE-2026-64960). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64962 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-64962)
vulnerability in csrf (CVE-2026-64962). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73220 |
|
Vulnerability in CVE-2026-73220 (CVE-2026-73220)
vulnerability in CVE-2026-73220 (CVE-2026-73220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63490 |
|
Path Traversal in CVE-2026-63490 (CVE-2026-63490)
path traversal in CVE-2026-63490 (CVE-2026-63490). Confidential information can be exposed externally.
|
| CVE-2026-55558 |
|
Vulnerability in aiosmtplib (CVE-2026-55558)
vulnerability in aiosmtplib (CVE-2026-55558). Data can be tampered with by attackers. Mitigation: upgrade to `5.1.2` or later.
|
| CVE-2026-77118 |
|
Out-of-Bounds Write in c (CVE-2026-77118)
out-of-bounds write in c (CVE-2026-77118). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7485 |
|
Authorization Flaw in CVE-2026-7485 (CVE-2026-7485)
vulnerability in CVE-2026-7485 (CVE-2026-7485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76988 |
|
Buffer Overflow in CVE-2026-76988 (CVE-2026-76988)
vulnerability in CVE-2026-76988 (CVE-2026-76988). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76989 |
|
Buffer Overflow in CVE-2026-76989 (CVE-2026-76989)
vulnerability in CVE-2026-76989 (CVE-2026-76989). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76987 |
|
Buffer Overflow in CVE-2026-76987 (CVE-2026-76987)
vulnerability in CVE-2026-76987 (CVE-2026-76987). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74011 |
|
SQL Injection in sqli (CVE-2026-74011)
SQL injection in sqli (CVE-2026-74011). Confidential information can be exposed externally.
|
| CVE-2026-28163 |
|
Vulnerability in CVE-2026-28163 (CVE-2026-28163)
vulnerability in CVE-2026-28163 (CVE-2026-28163). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28164 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-28164)
vulnerability in csrf (CVE-2026-28164). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21784 |
|
Information Disclosure in CVE-2026-21784 (CVE-2026-21784)
vulnerability in CVE-2026-21784 (CVE-2026-21784). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18482 |
|
OS Command Injection in CVE-2026-18482 (CVE-2026-18482)
OS command injection in CVE-2026-18482 (CVE-2026-18482). Successful exploitation can lead to full system takeover.
|
| CVE-2025-62300 |
|
Vulnerability in CVE-2025-62300 (CVE-2025-62300)
vulnerability in CVE-2025-62300 (CVE-2025-62300). Data can be tampered with by attackers.
|
| CVE-2026-77084 |
|
OS Command Injection in CVE-2026-77084 (CVE-2026-77084)
OS command injection in CVE-2026-77084 (CVE-2026-77084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77080 |
|
OS Command Injection in CVE-2026-77080 (CVE-2026-77080)
OS command injection in CVE-2026-77080 (CVE-2026-77080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73992 |
|
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
|
| CVE-2026-77074 |
|
Code Injection in CVE-2026-77074 (CVE-2026-77074)
code injection in CVE-2026-77074 (CVE-2026-77074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77077 |
|
Code Injection in CVE-2026-77077 (CVE-2026-77077)
code injection in CVE-2026-77077 (CVE-2026-77077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77075 |
|
Code Injection in CVE-2026-77075 (CVE-2026-77075)
code injection in CVE-2026-77075 (CVE-2026-77075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77083 |
|
Vulnerability in CVE-2026-77083 (CVE-2026-77083)
vulnerability in CVE-2026-77083 (CVE-2026-77083). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74001 |
|
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
|
| CVE-2026-74018 |
|
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
|
| CVE-2026-74016 |
|
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
|
| CVE-2026-74014 |
|
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
|
| CVE-2026-73998 |
|
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
|
| CVE-2026-74013 |
|
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
|
| CVE-2026-77071 |
|
SQL Injection in CVE-2026-77071 (CVE-2026-77071)
SQL injection in CVE-2026-77071 (CVE-2026-77071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68566 |
|
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
|
| CVE-2026-66680 |
|
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
|
| CVE-2026-77072 |
|
Cross-Site Scripting (XSS) in CVE-2026-77072 (CVE-2026-77072)
cross-site scripting in CVE-2026-77072 (CVE-2026-77072). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73402 |
|
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
|
| CVE-2026-68564 |
|
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
|
| CVE-2026-77076 |
|
Vulnerability in CVE-2026-77076 (CVE-2026-77076)
vulnerability in CVE-2026-77076 (CVE-2026-77076). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77085 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-77085)
SSRF in ssrf (CVE-2026-77085). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77069 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-77069)
SSRF in ssrf (CVE-2026-77069). Risk of unauthorized operations or information disclosure.
|