Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Clear
ID Title
CVE-2026-48950 Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
CVE-2026-48951 Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48952 Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-48953 Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2026-48947 Vulnerability in joomla (CVE-2026-48947)
vulnerability in joomla (CVE-2026-48947). Data can be tampered with by attackers.
CVE-2026-48948 Vulnerability in joomla (CVE-2026-48948)
vulnerability in joomla (CVE-2026-48948). Successful exploitation can lead to full system takeover.
CVE-2026-23698 Unrestricted File Upload in apache (CVE-2026-23698)
vulnerability in apache (CVE-2026-23698). Successful exploitation can lead to full system takeover.
CVE-2026-23697 Unrestricted File Upload in apache (CVE-2026-23697)
vulnerability in apache (CVE-2026-23697). Successful exploitation can lead to full system takeover.
CVE-2026-13019 Vulnerability in esri (CVE-2026-13019)
vulnerability in esri (CVE-2026-13019). Successful exploitation can lead to full system takeover.
CVE-2026-13020 Vulnerability in esri (CVE-2026-13020)
vulnerability in esri (CVE-2026-13020). Successful exploitation can lead to full system takeover.
CVE-2026-6101 Vulnerability in wordpress (CVE-2026-6101)
vulnerability in wordpress (CVE-2026-6101). Successful exploitation can lead to full system takeover.
CVE-2026-53479 OS Command Injection in dell (CVE-2026-53479)
OS command injection in dell (CVE-2026-53479). Successful exploitation can lead to full system takeover.
CVE-2026-53481 Path Traversal in path-traversal (CVE-2026-53481)
path traversal in path-traversal (CVE-2026-53481). Successful exploitation can lead to full system takeover.
CVE-2026-53483 Authentication Bypass in dell (CVE-2026-53483)
authentication bypass in dell (CVE-2026-53483). Successful exploitation can lead to full system takeover.
CVE-2026-40187 OS Command Injection in egroupware/egroupware (CVE-2026-40187)
OS command injection in egroupware/egroupware (CVE-2026-40187). Risk of unauthorized operations or information disclosure. Exploitable via ``chgrp``. Mitigation: upgrade to `23.1.20260601` or later.
CVE-2026-48828 Information Disclosure in apache (CVE-2026-48828)
vulnerability in apache (CVE-2026-48828). Confidential information can be exposed externally. Exploitable via ``should_hide_value_for_key``.
CVE-2026-48891 Information Disclosure in apache (CVE-2026-48891)
vulnerability in apache (CVE-2026-48891). Risk of unauthorized operations or information disclosure. Exploitable via ``dep.source``.
CVE-2026-48892 Information Disclosure in apache (CVE-2026-48892)
vulnerability in apache (CVE-2026-48892). Confidential information can be exposed externally. Exploitable via ``sensitive_config_values``.
CVE-2026-49296 Vulnerability in apache-airflow (CVE-2026-49296)
vulnerability in apache-airflow (CVE-2026-49296). Confidential information can be exposed externally. Exploitable via `GET /api/v2/dagSources/{dag_id}`. Mitigation: upgrade to `3.3.0` or later.
CVE-2026-49487 Information Disclosure in apache (CVE-2026-49487)
vulnerability in apache (CVE-2026-49487). Confidential information can be exposed externally.
CVE-2026-33264 Unsafe Deserialization in apache (CVE-2026-33264)
vulnerability in apache (CVE-2026-33264). Successful exploitation can lead to full system takeover.
CVE-2026-14345 Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
CVE-2026-12277 Vulnerability in wordpress (CVE-2026-12277)
vulnerability in wordpress (CVE-2026-12277). Data can be tampered with by attackers.
CVE-2026-10834 Vulnerability in wordpress (CVE-2026-10834)
vulnerability in wordpress (CVE-2026-10834). Risk of unauthorized operations or information disclosure.
CVE-2026-4375 Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
CVE-2026-12375 Vulnerability in wordpress (CVE-2026-12375)
vulnerability in wordpress (CVE-2026-12375). Successful exploitation can lead to full system takeover.
CVE-2026-42200 Path Traversal in CVE-2026-42200 (CVE-2026-42200)
path traversal in CVE-2026-42200 (CVE-2026-42200). Successful exploitation can lead to full system takeover.
CVE-2026-42145 Unrestricted File Upload in CVE-2026-42145 (CVE-2026-42145)
vulnerability in CVE-2026-42145 (CVE-2026-42145). Risk of unauthorized operations or information disclosure.
CVE-2026-34037 Vulnerability in CVE-2026-34037 (CVE-2026-34037)
vulnerability in CVE-2026-34037 (CVE-2026-34037). Confidential information can be exposed externally.
CVE-2026-34057 OS Command Injection in CVE-2026-34057 (CVE-2026-34057)
OS command injection in CVE-2026-34057 (CVE-2026-34057). Successful exploitation can lead to full system takeover.
CVE-2026-11328 Cross-Site Scripting (XSS) in wordpress (CVE-2026-11328)
cross-site scripting in wordpress (CVE-2026-11328). Risk of unauthorized operations or information disclosure.
CVE-2026-13356 Vulnerability in mozilla (CVE-2026-13356)
vulnerability in mozilla (CVE-2026-13356). Risk of unauthorized operations or information disclosure.
CVE-2024-56141 Vulnerability in CVE-2024-56141 (CVE-2024-56141)
vulnerability in CVE-2024-56141 (CVE-2024-56141). Risk of unauthorized operations or information disclosure.
CVE-2026-53646 Vulnerability in nginx (CVE-2026-53646)
vulnerability in nginx (CVE-2026-53646). Risk of unauthorized operations or information disclosure. Exploitable via ``ClientPasswordReset``.
CVE-2026-42148 OS Command Injection in CVE-2026-42148 (CVE-2026-42148)
OS command injection in CVE-2026-42148 (CVE-2026-42148). Risk of unauthorized operations or information disclosure.
CVE-2026-43918 Vulnerability in CVE-2026-43918 (CVE-2026-43918)
vulnerability in CVE-2026-43918 (CVE-2026-43918). Risk of unauthorized operations or information disclosure.
CVE-2026-43921 Code Injection in CVE-2026-43921 (CVE-2026-43921)
code injection in CVE-2026-43921 (CVE-2026-43921). Risk of unauthorized operations or information disclosure. Exploitable via ``config.php``.
CVE-2026-21384 Out-of-Bounds Write in qualcomm (CVE-2026-21384)
out-of-bounds write in qualcomm (CVE-2026-21384). Risk of unauthorized operations or information disclosure.
CVE-2026-21370 Out-of-Bounds Write in qualcomm (CVE-2026-21370)
out-of-bounds write in qualcomm (CVE-2026-21370). Risk of unauthorized operations or information disclosure.
CVE-2026-21379 Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-21383 Vulnerability in qualcomm (CVE-2026-21383)
vulnerability in qualcomm (CVE-2026-21383). Confidential information can be exposed externally.
CVE-2026-25271 Vulnerability in qualcomm (CVE-2026-25271)
vulnerability in qualcomm (CVE-2026-25271). Successful exploitation can lead to full system takeover.
CVE-2026-21369 Out-of-Bounds Write in qualcomm (CVE-2026-21369)
out-of-bounds write in qualcomm (CVE-2026-21369). Risk of unauthorized operations or information disclosure.
CVE-2026-21368 Out-of-Bounds Write in qualcomm (CVE-2026-21368)
out-of-bounds write in qualcomm (CVE-2026-21368). Risk of unauthorized operations or information disclosure.
CVE-2026-25268 Vulnerability in qualcomm (CVE-2026-25268)
vulnerability in qualcomm (CVE-2026-25268). Successful exploitation can lead to full system takeover.
CVE-2026-48267 Vulnerability in adobe (CVE-2026-48267)
vulnerability in adobe (CVE-2026-48267). Risk of unauthorized operations or information disclosure.
CVE-2025-59616 Use-After-Free in qualcomm (CVE-2025-59616)
vulnerability in qualcomm (CVE-2025-59616). Data can be tampered with by attackers.
CVE-2025-59615 Use-After-Free in qualcomm (CVE-2025-59615)
vulnerability in qualcomm (CVE-2025-59615). Data can be tampered with by attackers.
CVE-2025-59617 Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
CVE-2026-42341 Vulnerability in CVE-2026-42341 (CVE-2026-42341)
vulnerability in CVE-2026-42341 (CVE-2026-42341). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →