Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10895 |
|
Use-After-Free in google (CVE-2026-10895)
vulnerability in google (CVE-2026-10895). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10896 |
|
Use-After-Free in google (CVE-2026-10896)
vulnerability in google (CVE-2026-10896). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10899 |
|
Use-After-Free in c (CVE-2026-10899)
vulnerability in c (CVE-2026-10899). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10900 |
|
Use-After-Free in google (CVE-2026-10900)
vulnerability in google (CVE-2026-10900). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10901 |
|
Use-After-Free in google (CVE-2026-10901)
vulnerability in google (CVE-2026-10901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10902 |
|
Use-After-Free in google (CVE-2026-10902)
vulnerability in google (CVE-2026-10902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10897 |
|
Out-of-Bounds Write in google (CVE-2026-10897)
out-of-bounds write in google (CVE-2026-10897). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10889 |
|
Out-of-Bounds Read in google (CVE-2026-10889)
vulnerability in google (CVE-2026-10889). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10886 |
|
Use-After-Free in google (CVE-2026-10886)
vulnerability in google (CVE-2026-10886). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10887 |
|
Use-After-Free in google (CVE-2026-10887)
vulnerability in google (CVE-2026-10887). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10888 |
|
Use-After-Free in google (CVE-2026-10888)
vulnerability in google (CVE-2026-10888). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10890 |
|
Use-After-Free in google (CVE-2026-10890)
vulnerability in google (CVE-2026-10890). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10891 |
|
Use-After-Free in google (CVE-2026-10891)
vulnerability in google (CVE-2026-10891). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10893 |
|
Use-After-Free in google (CVE-2026-10893)
vulnerability in google (CVE-2026-10893). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10894 |
|
Use-After-Free in google (CVE-2026-10894)
vulnerability in google (CVE-2026-10894). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10892 |
|
Out-of-Bounds Write in google (CVE-2026-10892)
out-of-bounds write in google (CVE-2026-10892). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10882 |
|
Use-After-Free in google (CVE-2026-10882)
vulnerability in google (CVE-2026-10882). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10884 |
|
Use-After-Free in google (CVE-2026-10884)
vulnerability in google (CVE-2026-10884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10885 |
|
Use-After-Free in google (CVE-2026-10885)
vulnerability in google (CVE-2026-10885). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10883 |
|
Out-of-Bounds Write in google (CVE-2026-10883)
out-of-bounds write in google (CVE-2026-10883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10874 |
|
Vulnerability in sqli (CVE-2026-10874)
vulnerability in sqli (CVE-2026-10874). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10875 |
|
Vulnerability in sqli (CVE-2026-10875)
vulnerability in sqli (CVE-2026-10875). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10872 |
|
Command Injection in CVE-2026-10872 (CVE-2026-10872)
command injection in CVE-2026-10872 (CVE-2026-10872). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10873 |
|
Command Injection in CVE-2026-10873 (CVE-2026-10873)
command injection in CVE-2026-10873 (CVE-2026-10873). Successful exploitation can lead to full system takeover.
|
| CVE-2024-27892 |
|
Vulnerability in CVE-2024-27892 (CVE-2024-27892)
vulnerability in CVE-2024-27892 (CVE-2024-27892). Data can be tampered with by attackers.
|
| CVE-2024-27890 |
|
Vulnerability in CVE-2024-27890 (CVE-2024-27890)
vulnerability in CVE-2024-27890 (CVE-2024-27890). Data can be tampered with by attackers.
|
| CVE-2023-5502 |
|
Authentication Bypass in CVE-2023-5502 (CVE-2023-5502)
authentication bypass in CVE-2023-5502 (CVE-2023-5502). Data can be tampered with by attackers.
|
| CVE-2024-27891 |
|
Vulnerability in CVE-2024-27891 (CVE-2024-27891)
vulnerability in CVE-2024-27891 (CVE-2024-27891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10881 |
|
Out-of-Bounds Read in Google chrome (CVE-2026-10881)
vulnerability in Google chrome (CVE-2026-10881). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42547 |
|
Authorization Flaw in CVE-2026-42547 (CVE-2026-42547)
vulnerability in CVE-2026-42547 (CVE-2026-42547). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10871 |
|
Command Injection in CVE-2026-10871 (CVE-2026-10871)
command injection in CVE-2026-10871 (CVE-2026-10871). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11322 |
|
Vulnerability in path-traversal (CVE-2026-11322)
vulnerability in path-traversal (CVE-2026-11322). Confidential information can be exposed externally.
|
| CVE-2024-6858 |
|
Vulnerability in CVE-2024-6858 (CVE-2024-6858)
vulnerability in CVE-2024-6858 (CVE-2024-6858). Data can be tampered with by attackers.
|
| CVE-2026-10870 |
|
Command Injection in CVE-2026-10870 (CVE-2026-10870)
command injection in CVE-2026-10870 (CVE-2026-10870). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5066 |
|
Out-of-Bounds Write in c (CVE-2026-5066)
out-of-bounds write in c (CVE-2026-5066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42538 |
|
Unrestricted File Upload in CVE-2026-42538 (CVE-2026-42538)
vulnerability in CVE-2026-42538 (CVE-2026-42538). Confidential information can be exposed externally.
|
| CVE-2026-47708 |
|
Command Injection in stata-mcp (CVE-2026-47708)
command injection in stata-mcp (CVE-2026-47708). Risk of unauthorized operations or information disclosure. Exploitable via ``log_file_name``. Mitigation: upgrade to `1.17.3` or later.
|
| CVE-2026-41522 |
|
Vulnerability in flask (CVE-2026-41522)
vulnerability in flask (CVE-2026-41522). Risk of unauthorized operations or information disclosure. Exploitable via ``case.iocs``. Mitigation: upgrade to `2.4.28` or later.
|
| CVE-2026-5589 |
|
Out-of-Bounds Write in c (CVE-2026-5589)
out-of-bounds write in c (CVE-2026-5589). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41518 |
|
Cross-Site Scripting (XSS) in CVE-2026-41518 (CVE-2026-41518)
cross-site scripting in CVE-2026-41518 (CVE-2026-41518). Confidential information can be exposed externally. Exploitable via ``ChartDatasetConfig.legend``.
|
| CVE-2026-47703 |
|
Vulnerability in github.com/AdguardTeam/AdGuardHome (CVE-2026-47703)
vulnerability in github.com/AdguardTeam/AdGuardHome (CVE-2026-47703). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.107.75` or later.
|
| CVE-2026-48013 |
|
SSRF (Server-Side Request Forgery) in shopware/core (CVE-2026-48013)
SSRF in shopware/core (CVE-2026-48013). Risk of unauthorized operations or information disclosure. Exploitable via ``uploadFromURL``. Mitigation: upgrade to `6.7.10.1` or later.
|
| CVE-2026-48015 |
|
Cross-Site Scripting (XSS) in shopware/core (CVE-2026-48015)
cross-site scripting in shopware/core (CVE-2026-48015). Confidential information can be exposed externally. Exploitable via ``allowed_extensions``. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48014 |
|
Vulnerability in shopware/platform (CVE-2026-48014)
vulnerability in shopware/platform (CVE-2026-48014). Data can be tampered with by attackers. Exploitable via ``orderId``. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48012 |
|
Open Redirect in shopware/core (CVE-2026-48012)
vulnerability in shopware/core (CVE-2026-48012). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/oauth/sso/auth`. Mitigation: upgrade to `6.7.10.1` or later.
|
| CVE-2026-48011 |
|
Vulnerability in shopware/platform (CVE-2026-48011)
vulnerability in shopware/platform (CVE-2026-48011). Risk of unauthorized operations or information disclosure. Exploitable via ``password_verify``. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48010 |
|
Privilege Escalation in shopware/platform (CVE-2026-48010)
vulnerability in shopware/platform (CVE-2026-48010). Confidential information can be exposed externally. Exploitable via ``SYSTEM_SCOPE``. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48009 |
|
Information Disclosure in shopware/platform (CVE-2026-48009)
vulnerability in shopware/platform (CVE-2026-48009). Confidential information can be exposed externally. Exploitable via `POST /api/search/user-recovery`. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-48008 |
|
Vulnerability in shopware/platform (CVE-2026-48008)
vulnerability in shopware/platform (CVE-2026-48008). Confidential information can be exposed externally. Exploitable via `POST /api/_action/sync`. Mitigation: upgrade to `6.6.10.18` or later.
|
| CVE-2026-36499 |
|
Vulnerability in dos (CVE-2026-36499)
vulnerability in dos (CVE-2026-36499). Risk of unauthorized operations or information disclosure.
|