Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13521 |
|
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php....
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php....
|
| CVE-2026-13520 |
|
Vulnerability in sqli (CVE-2026-13520)
vulnerability in sqli (CVE-2026-13520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13504 |
|
Cross-Site Scripting (XSS) in CVE-2026-13504 (CVE-2026-13504)
cross-site scripting in CVE-2026-13504 (CVE-2026-13504). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13499 |
|
Cross-Site Scripting (XSS) in CVE-2026-13499 (CVE-2026-13499)
cross-site scripting in CVE-2026-13499 (CVE-2026-13499). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13498 |
|
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an...
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an...
|
| CVE-2026-13497 |
|
Vulnerability in sqli (CVE-2026-13497)
vulnerability in sqli (CVE-2026-13497). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13496 |
|
Vulnerability in sqli (CVE-2026-13496)
vulnerability in sqli (CVE-2026-13496). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13495 |
|
Vulnerability in sqli (CVE-2026-13495)
vulnerability in sqli (CVE-2026-13495). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13487 |
|
Vulnerability in sqli (CVE-2026-13487)
vulnerability in sqli (CVE-2026-13487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13490 |
|
Vulnerability in CVE-2026-13490 (CVE-2026-13490)
vulnerability in CVE-2026-13490 (CVE-2026-13490). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13488 |
|
Vulnerability in sqli (CVE-2026-13488)
vulnerability in sqli (CVE-2026-13488). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13486 |
|
Vulnerability in sqli (CVE-2026-13486)
vulnerability in sqli (CVE-2026-13486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13485 |
|
Vulnerability in sqli (CVE-2026-13485)
vulnerability in sqli (CVE-2026-13485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58054 |
|
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
|
| CVE-2026-58052 |
|
Vulnerability in 7-zip (CVE-2026-58052)
vulnerability in 7-zip (CVE-2026-58052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8095 |
|
Vulnerability in wordpress (CVE-2026-8095)
vulnerability in wordpress (CVE-2026-8095). Data can be tampered with by attackers.
|
| CVE-2026-54244 |
|
Authorization Flaw in statamic/cms (CVE-2026-54244)
vulnerability in statamic/cms (CVE-2026-54244). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.0` or later.
|
| CVE-2026-54243 |
|
Vulnerability in statamic/cms (CVE-2026-54243)
vulnerability in statamic/cms (CVE-2026-54243). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.73.24` or later.
|
| CVE-2026-54242 |
|
Vulnerability in statamic/cms (CVE-2026-54242)
vulnerability in statamic/cms (CVE-2026-54242). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.73.24` or later.
|
| CVE-2026-48770 |
|
Out-of-Bounds Read in notepad-plus-plus (CVE-2026-48770)
vulnerability in notepad-plus-plus (CVE-2026-48770). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.9.6.1` or later.
|
| CVE-2026-48778 |
|
OS Command Injection in cpp (CVE-2026-48778)
OS command injection in cpp (CVE-2026-48778). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.9.6.1` or later.
|
| CVE-2026-48800 |
|
OS Command Injection in cpp (CVE-2026-48800)
OS command injection in cpp (CVE-2026-48800). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.9.6.1` or later.
|
| CVE-2026-52884 |
|
Vulnerability in cpp (CVE-2026-52884)
vulnerability in cpp (CVE-2026-52884). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.9.6.2` or later.
|
| CVE-2026-52885 |
|
Vulnerability in cpp (CVE-2026-52885)
vulnerability in cpp (CVE-2026-52885). Data can be tampered with by attackers. Mitigation: upgrade to `8.9.6.4` or later.
|
| CVE-2026-46710 |
|
Vulnerability in privilege-escalation (CVE-2026-46710)
vulnerability in privilege-escalation (CVE-2026-46710). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `8.9.6` or later.
|
| CVE-2026-57518 |
|
Vulnerability in privilege-escalation (CVE-2026-57518)
vulnerability in privilege-escalation (CVE-2026-57518). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56057 |
|
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
|
| CVE-2026-56031 |
|
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
|
| CVE-2026-56055 |
|
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions.
|
| CVE-2026-56032 |
|
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
|
| CVE-2026-57940 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57940)
SSRF in ssrf (CVE-2026-57940). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57915 |
|
Vulnerability in apache (CVE-2026-57915)
vulnerability in apache (CVE-2026-57915). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-64152 |
|
Path Traversal in apache (CVE-2025-64152)
path traversal in apache (CVE-2025-64152). Confidential information can be exposed externally.
|
| CVE-2025-55017 |
|
Path Traversal in apache (CVE-2025-55017)
path traversal in apache (CVE-2025-55017). Confidential information can be exposed externally.
|
| CVE-2026-57914 |
|
Vulnerability in apache (CVE-2026-57914)
vulnerability in apache (CVE-2026-57914). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49486 |
|
Vulnerability in apache-airflow-providers-ftp (CVE-2026-49486)
vulnerability in apache-airflow-providers-ftp (CVE-2026-49486). Confidential information can be exposed externally. Exploitable via ``ftplib.FTP_TLS``. Mitigation: upgrade to `3.15.1` or later.
|
| CVE-2026-13281 |
|
Vulnerability in Google chrome (CVE-2026-13281)
vulnerability in Google chrome (CVE-2026-13281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50739 |
|
Vulnerability in revive-adserver (CVE-2026-50739)
vulnerability in revive-adserver (CVE-2026-50739). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50740 |
|
Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50740)
cross-site scripting in revive-adserver (CVE-2026-50740). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50745 |
|
Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50745)
cross-site scripting in revive-adserver (CVE-2026-50745). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50742 |
|
Cross-Site Scripting (XSS) in revive-adserver (CVE-2026-50742)
cross-site scripting in revive-adserver (CVE-2026-50742). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13283 |
|
Use-After-Free in google (CVE-2026-13283)
vulnerability in google (CVE-2026-13283). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13282 |
|
Use-After-Free in google (CVE-2026-13282)
vulnerability in google (CVE-2026-13282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40084 |
|
Path Traversal in path-traversal (CVE-2026-40084)
path traversal in path-traversal (CVE-2026-40084). Confidential information can be exposed externally.
|
| CVE-2026-40941 |
|
Vulnerability in cacti (CVE-2026-40941)
vulnerability in cacti (CVE-2026-40941). Data can be tampered with by attackers.
|
| CVE-2026-40083 |
|
SQL Injection in sqli (CVE-2026-40083)
SQL injection in sqli (CVE-2026-40083). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40082 |
|
Vulnerability in cacti (CVE-2026-40082)
vulnerability in cacti (CVE-2026-40082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40080 |
|
Open Redirect in cacti (CVE-2026-40080)
vulnerability in cacti (CVE-2026-40080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37149 |
|
SQL Injection in sqli (CVE-2026-37149)
SQL injection in sqli (CVE-2026-37149). Confidential information can be exposed externally.
|
| CVE-2026-45233 |
|
Path Traversal in path-traversal (CVE-2026-45233)
path traversal in path-traversal (CVE-2026-45233). Data can be tampered with by attackers.
|