Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Clear
ID Title
CVE-2026-11431 Path Traversal in path-traversal (CVE-2026-11431)
path traversal in path-traversal (CVE-2026-11431). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
CVE-2026-11429 Path Traversal in path-traversal (CVE-2026-11429)
path traversal in path-traversal (CVE-2026-11429). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
CVE-2026-47732 Authorization Flaw in twig/twig (CVE-2026-47732)
vulnerability in twig/twig (CVE-2026-47732). Confidential information can be exposed externally. Exploitable via ``SandboxNodeVisitor``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-47730 Cross-Site Scripting (XSS) in twig/twig (CVE-2026-47730)
cross-site scripting in twig/twig (CVE-2026-47730). Risk of unauthorized operations or information disclosure. Exploitable via ``ArrayLoader``. Mitigation: upgrade to `3.26.0` or later.
CVE-2026-11423 Path Traversal in path-traversal (CVE-2026-11423)
path traversal in path-traversal (CVE-2026-11423). Risk of unauthorized operations or information disclosure.
CVE-2026-11422 Vulnerability in CVE-2026-11422 (CVE-2026-11422)
vulnerability in CVE-2026-11422 (CVE-2026-11422). Confidential information can be exposed externally.
CVE-2026-36785 Vulnerability in dos (CVE-2026-36785)
vulnerability in dos (CVE-2026-36785). Risk of unauthorized operations or information disclosure.
CVE-2026-47743 Cross-Site Scripting (XSS) in shopper/framework (CVE-2026-47743)
cross-site scripting in shopper/framework (CVE-2026-47743). Confidential information can be exposed externally. Exploitable via ``Hidden``. Mitigation: upgrade to `2.8.0` or later.
CVE-2026-11400 AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-46400 Unrestricted File Upload in CVE-2026-46400 (CVE-2026-46400)
vulnerability in CVE-2026-46400 (CVE-2026-46400). Risk of unauthorized operations or information disclosure.
CVE-2026-46397 Path Traversal in CVE-2026-46397 (CVE-2026-46397)
path traversal in CVE-2026-46397 (CVE-2026-46397). Confidential information can be exposed externally.
CVE-2026-45779 SQL Injection in sqli (CVE-2026-45779)
SQL injection in sqli (CVE-2026-45779). Successful exploitation can lead to full system takeover.
CVE-2026-45778 Cross-Site Scripting (XSS) in buffalo (CVE-2026-45778)
cross-site scripting in buffalo (CVE-2026-45778). Risk of unauthorized operations or information disclosure.
CVE-2026-45777 OS Command Injection in buffalo (CVE-2026-45777)
OS command injection in buffalo (CVE-2026-45777). Successful exploitation can lead to full system takeover.
CVE-2026-45776 Vulnerability in buffalo (CVE-2026-45776)
vulnerability in buffalo (CVE-2026-45776). Risk of unauthorized operations or information disclosure.
CVE-2026-25624 Cross-Site Scripting (XSS) in arista (CVE-2026-25624)
cross-site scripting in arista (CVE-2026-25624). Confidential information can be exposed externally.
CVE-2026-25620 OS Command Injection in arista (CVE-2026-25620)
OS command injection in arista (CVE-2026-25620). Confidential information can be exposed externally.
CVE-2026-25621 OS Command Injection in arista (CVE-2026-25621)
OS command injection in arista (CVE-2026-25621). Confidential information can be exposed externally.
CVE-2026-25622 OS Command Injection in arista (CVE-2026-25622)
OS command injection in arista (CVE-2026-25622). Confidential information can be exposed externally.
CVE-2026-25623 OS Command Injection in arista (CVE-2026-25623)
OS command injection in arista (CVE-2026-25623). Confidential information can be exposed externally.
CVE-2026-11414 Path Traversal in path-traversal (CVE-2026-11414)
path traversal in path-traversal (CVE-2026-11414). Successful exploitation can lead to full system takeover.
CVE-2026-11419 Path Traversal in path-traversal (CVE-2026-11419)
path traversal in path-traversal (CVE-2026-11419). Successful exploitation can lead to full system takeover.
CVE-2026-11420 Path Traversal in path-traversal (CVE-2026-11420)
path traversal in path-traversal (CVE-2026-11420). Successful exploitation can lead to full system takeover.
CVE-2026-11401 AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-5415 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-5411 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the...
CVE-2026-46392 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filen...
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML...
CVE-2026-46394 OS Command Injection in CVE-2026-46394 (CVE-2026-46394)
OS command injection in CVE-2026-46394 (CVE-2026-46394). Risk of unauthorized operations or information disclosure.
CVE-2026-46399 Vulnerability in CVE-2026-46399 (CVE-2026-46399)
vulnerability in CVE-2026-46399 (CVE-2026-46399). Risk of unauthorized operations or information disclosure.
CVE-2026-46389 Authentication Bypass in defenseunicorns (CVE-2026-46389)
authentication bypass in defenseunicorns (CVE-2026-46389). Successful exploitation can lead to full system takeover. Exploitable via ``client_secret``.
CVE-2026-10580 Vulnerability in wordpress (CVE-2026-10580)
vulnerability in wordpress (CVE-2026-10580). Successful exploitation can lead to full system takeover.
CVE-2026-50733 Vulnerability in CVE-2026-50733 (CVE-2026-50733)
vulnerability in CVE-2026-50733 (CVE-2026-50733). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
CVE-2026-49492 OS Command Injection in CVE-2026-49492 (CVE-2026-49492)
OS command injection in CVE-2026-49492 (CVE-2026-49492). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
CVE-2026-49493 Code Injection in CVE-2026-49493 (CVE-2026-49493)
code injection in CVE-2026-49493 (CVE-2026-49493). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
CVE-2026-45750 OS Command Injection in termix (CVE-2026-45750)
OS command injection in termix (CVE-2026-45750). Successful exploitation can lead to full system takeover. Exploitable via `GET /ssh/file_manager/ssh/resolvePath`.
CVE-2026-45748 OS Command Injection in termix (CVE-2026-45748)
OS command injection in termix (CVE-2026-45748). Successful exploitation can lead to full system takeover. Exploitable via `POST /ssh/tunnel/connect`.
CVE-2026-45746 Vulnerability in termix (CVE-2026-45746)
vulnerability in termix (CVE-2026-45746). Successful exploitation can lead to full system takeover.
CVE-2026-45745 Vulnerability in termix (CVE-2026-45745)
vulnerability in termix (CVE-2026-45745). Confidential information can be exposed externally.
CVE-2026-45744 OS Command Injection in termix (CVE-2026-45744)
OS command injection in termix (CVE-2026-45744). Successful exploitation can lead to full system takeover. Exploitable via `GET /ssh/file_manager/ssh/resolvePath`.
CVE-2026-45290 Vulnerability in CVE-2026-45290 (CVE-2026-45290)
vulnerability in CVE-2026-45290 (CVE-2026-45290). Risk of unauthorized operations or information disclosure.
CVE-2026-45291 Vulnerability in CVE-2026-45291 (CVE-2026-45291)
vulnerability in CVE-2026-45291 (CVE-2026-45291). Risk of unauthorized operations or information disclosure.
CVE-2026-36501 Vulnerability in dos (CVE-2026-36501)
vulnerability in dos (CVE-2026-36501). Risk of unauthorized operations or information disclosure.
CVE-2026-36500 Path Traversal in path-traversal (CVE-2026-36500)
path traversal in path-traversal (CVE-2026-36500). Confidential information can be exposed externally.
CVE-2026-11344 Vulnerability in CVE-2026-11344 (CVE-2026-11344)
vulnerability in CVE-2026-11344 (CVE-2026-11344). Risk of unauthorized operations or information disclosure.
CVE-2026-11342 Vulnerability in sqli (CVE-2026-11342)
vulnerability in sqli (CVE-2026-11342). Risk of unauthorized operations or information disclosure.
CVE-2026-11341 Command Injection in CVE-2026-11341 (CVE-2026-11341)
command injection in CVE-2026-11341 (CVE-2026-11341). Risk of unauthorized operations or information disclosure.
CVE-2025-71318 Vulnerability in CVE-2025-71318 (CVE-2025-71318)
vulnerability in CVE-2025-71318 (CVE-2025-71318). Successful exploitation can lead to full system takeover.
CVE-2025-71317 Vulnerability in CVE-2025-71317 (CVE-2025-71317)
vulnerability in CVE-2025-71317 (CVE-2025-71317). Successful exploitation can lead to full system takeover.
CVE-2026-47731 Path Traversal in ait-core (CVE-2026-47731)
path traversal in ait-core (CVE-2026-47731). Data can be tampered with by attackers. Exploitable via ``python_poc.py``. Mitigation: upgrade to `2.6.1` or later.
CVE-2026-8714 Vulnerability in tp-link (CVE-2026-8714)
vulnerability in tp-link (CVE-2026-8714). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →