Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Clear
ID Title
CVE-2026-64102 Out-of-Bounds Read in c (CVE-2026-64102)
vulnerability in c (CVE-2026-64102). Successful exploitation can lead to full system takeover.
CVE-2026-63993 Vulnerability in c (CVE-2026-63993)
vulnerability in c (CVE-2026-63993). Successful exploitation can lead to full system takeover.
CVE-2026-63984 Vulnerability in c (CVE-2026-63984)
vulnerability in c (CVE-2026-63984). Successful exploitation can lead to full system takeover.
CVE-2026-52348 cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
CVE-2026-8635 Code Injection in c (CVE-2026-8635)
code injection in c (CVE-2026-8635). Successful exploitation can lead to full system takeover.
CVE-2026-8481 Code Injection in c (CVE-2026-8481)
code injection in c (CVE-2026-8481). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/validate/code`.
CVE-2026-8476 Unsafe Deserialization in langflow (CVE-2026-8476)
vulnerability in langflow (CVE-2026-8476). Successful exploitation can lead to full system takeover.
CVE-2026-63030 KEV WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
CVE-2026-36669 Unrestricted File Upload in CVE-2026-36669 (CVE-2026-36669)
vulnerability in CVE-2026-36669 (CVE-2026-36669). Successful exploitation can lead to full system takeover.
CVE-2026-9135 Code Injection in langflow (CVE-2026-9135)
code injection in langflow (CVE-2026-9135). Successful exploitation can lead to full system takeover.
CVE-2026-15982 Privilege Escalation in wordpress (CVE-2026-15982)
vulnerability in wordpress (CVE-2026-15982). Successful exploitation can lead to full system takeover.
CVE-2026-55579 Vulnerability in pheditor/pheditor (CVE-2026-55579)
vulnerability in pheditor/pheditor (CVE-2026-55579). Successful exploitation can lead to full system takeover. Exploitable via ``admin``. Mitigation: upgrade to `2.0.6` or later.
CVE-2026-46512 Code Injection in CVE-2026-46512 (CVE-2026-46512)
code injection in CVE-2026-46512 (CVE-2026-46512). Successful exploitation can lead to full system takeover.
CVE-2026-11386 Vulnerability in CVE-2026-11386 (CVE-2026-11386)
vulnerability in CVE-2026-11386 (CVE-2026-11386). Successful exploitation can lead to full system takeover.
CVE-2026-55652 Authentication Bypass in CVE-2026-55652 (CVE-2026-55652)
authentication bypass in CVE-2026-55652 (CVE-2026-55652). Successful exploitation can lead to full system takeover.
CVE-2026-52891 OS Command Injection in CVE-2026-52891 (CVE-2026-52891)
OS command injection in CVE-2026-52891 (CVE-2026-52891). Successful exploitation can lead to full system takeover.
CVE-2026-30623 Command Injection in c (CVE-2026-30623)
command injection in c (CVE-2026-30623). Successful exploitation can lead to full system takeover.
CVE-2026-62948 Cross-Site Scripting (XSS) in c (CVE-2026-62948)
cross-site scripting in c (CVE-2026-62948). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `25.12.5` or later.
CVE-2026-51808 Vulnerability in cpp (CVE-2026-51808)
vulnerability in cpp (CVE-2026-51808). Successful exploitation can lead to full system takeover.
CVE-2026-51807 Vulnerability in cpp (CVE-2026-51807)
vulnerability in cpp (CVE-2026-51807). Successful exploitation can lead to full system takeover.
CVE-2026-48259 SSRF (Server-Side Request Forgery) in c (CVE-2026-48259)
SSRF in c (CVE-2026-48259). Confidential information can be exposed externally.
CVE-2026-59891 Vulnerability in @sigstore/oci (CVE-2026-59891)
vulnerability in @sigstore/oci (CVE-2026-59891). Successful exploitation can lead to full system takeover. Exploitable via ``cr.io``. Mitigation: upgrade to `0.7.1` or later.
CVE-2026-54058 Out-of-Bounds Read in pillow (CVE-2026-54058)
vulnerability in pillow (CVE-2026-54058). Confidential information can be exposed externally. Exploitable via ``raw``. Mitigation: upgrade to `12.3.0` or later.
CVE-2026-15265 Path Traversal in c (CVE-2026-15265)
path traversal in c (CVE-2026-15265). Successful exploitation can lead to full system takeover.
CVE-2026-57898 Path Traversal in CVE-2026-57898 (CVE-2026-57898)
path traversal in CVE-2026-57898 (CVE-2026-57898). Successful exploitation can lead to full system takeover.
CVE-2026-11563 Vulnerability in wordpress (CVE-2026-11563)
vulnerability in wordpress (CVE-2026-11563). Data can be tampered with by attackers.
CVE-2026-62327 Vulnerability in CVE-2026-62327 (CVE-2026-62327)
vulnerability in CVE-2026-62327 (CVE-2026-62327). Confidential information can be exposed externally.
CVE-2026-59801 Vulnerability in dos (CVE-2026-59801)
vulnerability in dos (CVE-2026-59801). Successful exploitation can lead to full system takeover.
CVE-2026-58409 Unrestricted File Upload in CVE-2026-58409 (CVE-2026-58409)
vulnerability in CVE-2026-58409 (CVE-2026-58409). Successful exploitation can lead to full system takeover. Exploitable via ``php``.
CVE-2026-13221 Vulnerability in perl (CVE-2026-13221)
vulnerability in perl (CVE-2026-13221). Data can be tampered with by attackers.
CVE-2026-60121 OS Command Injection in vitec (CVE-2026-60121)
OS command injection in vitec (CVE-2026-60121). Successful exploitation can lead to full system takeover.
CVE-2026-61498 OS Command Injection in vitec (CVE-2026-61498)
OS command injection in vitec (CVE-2026-61498). Successful exploitation can lead to full system takeover.
CVE-2026-40469 Vulnerability in c (CVE-2026-40469)
vulnerability in c (CVE-2026-40469). Data can be tampered with by attackers.
CVE-2026-40468 Vulnerability in c (CVE-2026-40468)
vulnerability in c (CVE-2026-40468). Data can be tampered with by attackers.
CVE-2026-61447 Code Injection in CVE-2026-61447 (CVE-2026-61447)
code injection in CVE-2026-61447 (CVE-2026-61447). Successful exploitation can lead to full system takeover.
CVE-2026-54159 Vulnerability in prestashop/ps_facetedsearch (CVE-2026-54159)
vulnerability in prestashop/ps_facetedsearch (CVE-2026-54159). Successful exploitation can lead to full system takeover. Exploitable via ``ps_facetedsearch``. Mitigation: upgrade to `4.0.4` or later.
CVE-2026-57158 Out-of-Bounds Read in c (CVE-2026-57158)
vulnerability in c (CVE-2026-57158). Confidential information can be exposed externally.
CVE-2026-57156 Vulnerability in c (CVE-2026-57156)
vulnerability in c (CVE-2026-57156). Successful exploitation can lead to full system takeover.
CVE-2026-61444 Code Injection in CVE-2026-61444 (CVE-2026-61444)
code injection in CVE-2026-61444 (CVE-2026-61444). Successful exploitation can lead to full system takeover.
CVE-2026-40008 Vulnerability in c (CVE-2026-40008)
vulnerability in c (CVE-2026-40008). Successful exploitation can lead to full system takeover.
CVE-2026-15300 SQL Injection in wordpress (CVE-2026-15300)
SQL injection in wordpress (CVE-2026-15300). Data can be tampered with by attackers. Mitigation: upgrade to `4.5.5` or later.
CVE-2026-13461 Vulnerability in CVE-2026-13461 (CVE-2026-13461)
vulnerability in CVE-2026-13461 (CVE-2026-13461). Successful exploitation can lead to full system takeover.
CVE-2026-59826 Code Injection in metabase (CVE-2026-59826)
code injection in metabase (CVE-2026-59826). Successful exploitation can lead to full system takeover.
CVE-2026-59827 Unsafe Deserialization in metabase (CVE-2026-59827)
vulnerability in metabase (CVE-2026-59827). Successful exploitation can lead to full system takeover.
CVE-2026-14480 Vulnerability in cisa (CVE-2026-14480)
vulnerability in cisa (CVE-2026-14480). Successful exploitation can lead to full system takeover.
CVE-2026-12116 Vulnerability in CVE-2026-12116 (CVE-2026-12116)
vulnerability in CVE-2026-12116 (CVE-2026-12116). Successful exploitation can lead to full system takeover.
CVE-2026-15158 Unrestricted File Upload in wordpress (CVE-2026-15158)
vulnerability in wordpress (CVE-2026-15158). Successful exploitation can lead to full system takeover.
CVE-2026-14245 Vulnerability in wordpress (CVE-2026-14245)
vulnerability in wordpress (CVE-2026-14245). Successful exploitation can lead to full system takeover. Exploitable via ``form_nonce``.
CVE-2026-15062 SQL Injection in sqli (CVE-2026-15062)
SQL injection in sqli (CVE-2026-15062). Confidential information can be exposed externally.
CVE-2026-58480 Unrestricted File Upload in wordpress (CVE-2026-58480)
vulnerability in wordpress (CVE-2026-58480). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →