Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42746 |
|
Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for...
Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for...
|
| CVE-2026-42735 |
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare...
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare...
|
| CVE-2026-42737 |
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
|
| CVE-2026-42745 |
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online...
Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online...
|
| CVE-2026-42730 |
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
|
| CVE-2026-3012 |
|
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate...
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate...
|
| CVE-2026-40829 |
|
SQL Injection in sqli (CVE-2026-40829)
SQL injection in sqli (CVE-2026-40829). Confidential information can be exposed externally.
|
| CVE-2026-40830 |
|
SQL Injection in sqli (CVE-2026-40830)
SQL injection in sqli (CVE-2026-40830). Confidential information can be exposed externally.
|
| CVE-2026-40834 |
|
SQL Injection in sqli (CVE-2026-40834)
SQL injection in sqli (CVE-2026-40834). Confidential information can be exposed externally.
|
| CVE-2026-40833 |
|
SQL Injection in sqli (CVE-2026-40833)
SQL injection in sqli (CVE-2026-40833). Confidential information can be exposed externally.
|
| CVE-2026-40816 |
|
SQL Injection in sqli (CVE-2026-40816)
SQL injection in sqli (CVE-2026-40816). Confidential information can be exposed externally.
|
| CVE-2026-40814 |
|
SQL Injection in sqli (CVE-2026-40814)
SQL injection in sqli (CVE-2026-40814). Confidential information can be exposed externally.
|
| CVE-2026-8832 |
|
Code Injection in wordpress (CVE-2026-8832)
code injection in wordpress (CVE-2026-8832). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6169 |
|
Code Injection in wordpress (CVE-2026-6169)
code injection in wordpress (CVE-2026-6169). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3001 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3001)
cross-site scripting in wordpress (CVE-2026-3001). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9200 |
|
Vulnerability in wordpress (CVE-2026-9200)
vulnerability in wordpress (CVE-2026-9200). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8939 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-8939)
vulnerability in wordpress (CVE-2026-8939). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8868 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-8868)
cross-site scripting in wordpress (CVE-2026-8868). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7493 |
|
Vulnerability in wordpress (CVE-2026-7493)
vulnerability in wordpress (CVE-2026-7493). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9609 |
|
Vulnerability in CVE-2026-9609 (CVE-2026-9609)
vulnerability in CVE-2026-9609 (CVE-2026-9609). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7899504660052 |
|
Vulnerability in Google chrome (CVE-2026-7899504660052)
vulnerability in Google chrome (CVE-2026-7899504660052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44974 |
|
Vulnerability in @hapi/content (CVE-2026-44974)
vulnerability in @hapi/content (CVE-2026-44974). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.0.2` or later.
|
| CVE-2026-44739 |
|
SQL Injection in pimcore/pimcore (CVE-2026-44739)
SQL injection in pimcore/pimcore (CVE-2026-44739). Confidential information can be exposed externally. Exploitable via `POST /admin/bundle/customreports/custom-report/column-config`. Mitigation: upgrade to `12.3.6` or later.
|
| CVE-2026-9607 |
|
Vulnerability in sqli (CVE-2026-9607)
vulnerability in sqli (CVE-2026-9607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9606 |
|
Vulnerability in sqli (CVE-2026-9606)
vulnerability in sqli (CVE-2026-9606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44177 |
|
Path Traversal in getkirby/cms (CVE-2026-44177)
path traversal in getkirby/cms (CVE-2026-44177). Risk of unauthorized operations or information disclosure. Exploitable via ``Users``. Mitigation: upgrade to `5.4.1` or later.
|
| CVE-2026-9584 |
|
A security vulnerability has been detected in code-projects Project Management System 1.0....
A security vulnerability has been detected in code-projects Project Management System 1.0....
|
| CVE-2026-9603 |
|
Vulnerability in CVE-2026-9603 (CVE-2026-9603)
vulnerability in CVE-2026-9603 (CVE-2026-9603). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-43451 |
|
Vulnerability in apple (CVE-2025-43451)
vulnerability in apple (CVE-2025-43451). Confidential information can be exposed externally.
|
| CVE-2025-46280 |
|
Out-of-Bounds Read in apple (CVE-2025-46280)
vulnerability in apple (CVE-2025-46280). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-46284 |
|
Vulnerability in apple (CVE-2025-46284)
vulnerability in apple (CVE-2025-46284). Successful exploitation can lead to full system takeover.
|
| CVE-2025-46307 |
|
Vulnerability in apple (CVE-2025-46307)
vulnerability in apple (CVE-2025-46307). Confidential information can be exposed externally.
|
| CVE-2025-43289 |
|
Vulnerability in apple (CVE-2025-43289)
vulnerability in apple (CVE-2025-43289). Confidential information can be exposed externally.
|
| CVE-2025-43290 |
|
Vulnerability in apple (CVE-2025-43290)
vulnerability in apple (CVE-2025-43290). Data can be tampered with by attackers.
|
| CVE-2025-43306 |
|
Privilege Escalation in apple (CVE-2025-43306)
vulnerability in apple (CVE-2025-43306). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9583 |
|
Information Disclosure in CVE-2026-9583 (CVE-2026-9583)
vulnerability in CVE-2026-9583 (CVE-2026-9583). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9573 |
|
Vulnerability in sqli (CVE-2026-9573)
vulnerability in sqli (CVE-2026-9573). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9574 |
|
Vulnerability in sqli (CVE-2026-9574)
vulnerability in sqli (CVE-2026-9574). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9575 |
|
Vulnerability in sqli (CVE-2026-9575)
vulnerability in sqli (CVE-2026-9575). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8835 |
|
Vulnerability in dos (CVE-2026-8835)
vulnerability in dos (CVE-2026-8835). Confidential information can be exposed externally.
|
| CVE-2026-8856 |
|
Vulnerability in dos (CVE-2026-8856)
vulnerability in dos (CVE-2026-8856). Data can be tampered with by attackers.
|
| CVE-2026-8834 |
|
Vulnerability in dos (CVE-2026-8834)
vulnerability in dos (CVE-2026-8834). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8854 |
|
Vulnerability in dos (CVE-2026-8854)
vulnerability in dos (CVE-2026-8854). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8855 |
|
Code Injection in dos (CVE-2026-8855)
code injection in dos (CVE-2026-8855). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9170 |
|
Code Injection in dos (CVE-2026-9170)
code injection in dos (CVE-2026-9170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48695 |
|
OS Command Injection in pavel-odintsov (CVE-2026-48695)
OS command injection in pavel-odintsov (CVE-2026-48695). Confidential information can be exposed externally. Exploitable via ``date``.
|
| CVE-2026-48694 |
|
Command Injection in pavel-odintsov (CVE-2026-48694)
command injection in pavel-odintsov (CVE-2026-48694). Confidential information can be exposed externally.
|
| CVE-2026-8850 |
|
Vulnerability in dos (CVE-2026-8850)
vulnerability in dos (CVE-2026-8850). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8852 |
|
Vulnerability in dos (CVE-2026-8852)
vulnerability in dos (CVE-2026-8852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48905 |
|
Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code.
Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code.
|