Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16080 |
|
SQL Injection in wordpress (CVE-2026-16080)
SQL injection in wordpress (CVE-2026-16080). Confidential information can be exposed externally.
|
| CVE-2026-15162 |
|
SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
|
| CVE-2026-14433 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14433)
cross-site scripting in wordpress (CVE-2026-14433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12128 |
|
Vulnerability in wordpress (CVE-2026-12128)
vulnerability in wordpress (CVE-2026-12128). Risk of unauthorized operations or information disclosure. Exploitable via ``cart_data``.
|
| CVE-2026-14484 |
|
Path Traversal in wordpress (CVE-2026-14484)
path traversal in wordpress (CVE-2026-14484). Data can be tampered with by attackers.
|
| CVE-2026-74247 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-74247)
SSRF in ssrf (CVE-2026-74247). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74245 |
|
Vulnerability in redhat (CVE-2026-74245)
vulnerability in redhat (CVE-2026-74245). Confidential information can be exposed externally.
|
| CVE-2026-74243 |
|
Vulnerability in path-traversal (CVE-2026-74243)
vulnerability in path-traversal (CVE-2026-74243). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74244 |
|
Vulnerability in redhat (CVE-2026-74244)
vulnerability in redhat (CVE-2026-74244). Data can be tampered with by attackers.
|
| CVE-2026-63650 |
|
Vulnerability in CVE-2026-63650 (CVE-2026-63650)
vulnerability in CVE-2026-63650 (CVE-2026-63650). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74240 |
|
Authentication Bypass in redhat (CVE-2026-74240)
authentication bypass in redhat (CVE-2026-74240). Risk of unauthorized operations or information disclosure. Exploitable via ``azp``.
|
| CVE-2026-73683 |
|
Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69414 |
|
Vulnerability in microsoft (CVE-2026-69414)
vulnerability in microsoft (CVE-2026-69414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71570 |
|
Vulnerability in CVE-2026-71570 (CVE-2026-71570)
vulnerability in CVE-2026-71570 (CVE-2026-71570). Risk of unauthorized operations or information disclosure. Exploitable via ``com_icagenda``.
|
| CVE-2026-74248 |
|
Authorization Flaw in CVE-2026-74248 (CVE-2026-74248)
vulnerability in CVE-2026-74248 (CVE-2026-74248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67366 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-67366)
vulnerability in csrf (CVE-2026-67366). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50523 |
|
Command Injection in microsoft (CVE-2026-50523)
command injection in microsoft (CVE-2026-50523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73682 |
|
Vulnerability in CVE-2026-73682 (CVE-2026-73682)
vulnerability in CVE-2026-73682 (CVE-2026-73682). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73680 |
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
| CVE-2026-71571 |
|
SQL Injection in sqli (CVE-2026-71571)
SQL injection in sqli (CVE-2026-71571). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67365 |
|
SQL Injection in sqli (CVE-2026-67365)
SQL injection in sqli (CVE-2026-67365). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64887 |
|
Vulnerability in CVE-2026-64887 (CVE-2026-64887)
vulnerability in CVE-2026-64887 (CVE-2026-64887). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19909 |
|
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This...
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This...
|
| CVE-2026-34492 |
|
Vulnerability in CVE-2026-34492 (CVE-2026-34492)
vulnerability in CVE-2026-34492 (CVE-2026-34492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19908 |
|
Vulnerability in CVE-2026-19908 (CVE-2026-19908)
vulnerability in CVE-2026-19908 (CVE-2026-19908). Confidential information can be exposed externally.
|
| CVE-2026-19910 |
|
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution...
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution...
|
| CVE-2026-17184 |
|
Vulnerability in ibm (CVE-2026-17184)
vulnerability in ibm (CVE-2026-17184). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17186 |
|
OS Command Injection in ibm (CVE-2026-17186)
OS command injection in ibm (CVE-2026-17186). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18554 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
|
| CVE-2026-18178 |
|
Path Traversal in path-traversal (CVE-2026-18178)
path traversal in path-traversal (CVE-2026-18178). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17209 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2026-17209)
cross-site scripting in ibm (CVE-2026-17209). Data can be tampered with by attackers.
|
| CVE-2026-17227 |
|
SQL Injection in ibm (CVE-2026-17227)
SQL injection in ibm (CVE-2026-17227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17079 |
|
Vulnerability in ibm (CVE-2026-17079)
vulnerability in ibm (CVE-2026-17079). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17179 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
|
| CVE-2026-17175 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
|
| CVE-2026-17182 |
|
Authentication Bypass in ibm (CVE-2026-17182)
authentication bypass in ibm (CVE-2026-17182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17181 |
|
Path Traversal in path-traversal (CVE-2026-17181)
path traversal in path-traversal (CVE-2026-17181). Data can be tampered with by attackers.
|
| CVE-2026-17173 |
|
Path Traversal in ibm (CVE-2026-17173)
path traversal in ibm (CVE-2026-17173). Confidential information can be exposed externally.
|
| CVE-2026-17081 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
|
| CVE-2026-16905 |
|
Authentication Bypass in ibm (CVE-2026-16905)
authentication bypass in ibm (CVE-2026-16905). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16915 |
|
Path Traversal in ibm (CVE-2026-16915)
path traversal in ibm (CVE-2026-16915). Confidential information can be exposed externally.
|
| CVE-2026-16879 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
|
| CVE-2026-35219 |
|
SSRF (Server-Side Request Forgery) in @budibase/server (CVE-2026-35219)
SSRF in @budibase/server (CVE-2026-35219). Risk of unauthorized operations or information disclosure. Exploitable via ``BLACKLIST_IPS``. Mitigation: upgrade to `3.41.3` or later.
|
| CVE-2026-73679 |
|
Code Injection in CVE-2026-73679 (CVE-2026-73679)
code injection in CVE-2026-73679 (CVE-2026-73679). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73678 |
|
Code Injection in c (CVE-2026-73678)
code injection in c (CVE-2026-73678). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/responses/`.
|
| CVE-2026-45699 |
|
Vulnerability in CVE-2026-45699 (CVE-2026-45699)
vulnerability in CVE-2026-45699 (CVE-2026-45699). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18403 |
|
SQL Injection in sqli (CVE-2026-18403)
SQL injection in sqli (CVE-2026-18403). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63361 |
|
Cross-Site Scripting (XSS) in CVE-2026-63361 (CVE-2026-63361)
cross-site scripting in CVE-2026-63361 (CVE-2026-63361). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19682 |
|
OS Command Injection in tenable (CVE-2026-19682)
OS command injection in tenable (CVE-2026-19682). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19847 |
|
Buffer Overflow in CVE-2026-19847 (CVE-2026-19847)
vulnerability in CVE-2026-19847 (CVE-2026-19847). Successful exploitation can lead to full system takeover.
|