Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9485 |
|
Cross-Site Scripting (XSS) in CVE-2026-9485 (CVE-2026-9485)
cross-site scripting in CVE-2026-9485 (CVE-2026-9485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9484 |
|
Vulnerability in CVE-2026-9484 (CVE-2026-9484)
vulnerability in CVE-2026-9484 (CVE-2026-9484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43828 |
|
Vulnerability in org.apache.shiro:shiro-web (CVE-2026-43828)
vulnerability in org.apache.shiro:shiro-web (CVE-2026-43828). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-44598 |
|
Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-44598). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-43827 |
|
Vulnerability in org.apache.shiro:shiro-core (CVE-2026-43827)
vulnerability in org.apache.shiro:shiro-core (CVE-2026-43827). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-48589 |
|
Open Redirect in org.apache.shiro:shiro-jakarta-ee (CVE-2026-48589)
vulnerability in org.apache.shiro:shiro-jakarta-ee (CVE-2026-48589). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`. Mitigation: upgrade to `3.0.0-alpha-2` or later.
|
| CVE-2026-9483 |
|
Vulnerability in CVE-2026-9483 (CVE-2026-9483)
vulnerability in CVE-2026-9483 (CVE-2026-9483). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9474 |
|
Vulnerability in sqli (CVE-2026-9474)
vulnerability in sqli (CVE-2026-9474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9470 |
|
Vulnerability in sqli (CVE-2026-9470)
vulnerability in sqli (CVE-2026-9470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9469 |
|
Vulnerability in sqli (CVE-2026-9469)
vulnerability in sqli (CVE-2026-9469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9471 |
|
Cross-Site Scripting (XSS) in CVE-2026-9471 (CVE-2026-9471)
cross-site scripting in CVE-2026-9471 (CVE-2026-9471). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9078 |
|
Vulnerability in mozilla (CVE-2026-9078)
vulnerability in mozilla (CVE-2026-9078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42782 |
|
Vulnerability in org.apache.syncope.core:syncope-core-spring (CVE-2026-42782)
vulnerability in org.apache.syncope.core:syncope-core-spring (CVE-2026-42782). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2026-42797 |
|
Vulnerability in org.apache.syncope.core:syncope-core-provisioning-api (CVE-2026-42797)
vulnerability in org.apache.syncope.core:syncope-core-provisioning-api (CVE-2026-42797). Confidential information can be exposed externally. Mitigation: upgrade to `4.1.1` or later.
|
| CVE-2018-25370 |
|
Cross-Site Request Forgery (CSRF) in CVE-2018-25370 (CVE-2018-25370)
vulnerability in CVE-2018-25370 (CVE-2018-25370). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25372 |
|
SQL Injection in sqli (CVE-2018-25372)
SQL injection in sqli (CVE-2018-25372). Confidential information can be exposed externally.
|
| CVE-2018-25374 |
|
Path Traversal in c (CVE-2018-25374)
path traversal in c (CVE-2018-25374). Confidential information can be exposed externally.
|
| CVE-2018-25362 |
|
SQL Injection in sqli (CVE-2018-25362)
SQL injection in sqli (CVE-2018-25362). Confidential information can be exposed externally.
|
| CVE-2018-25363 |
|
Cross-Site Request Forgery (CSRF) in CVE-2018-25363 (CVE-2018-25363)
vulnerability in CVE-2018-25363 (CVE-2018-25363). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25364 |
|
SQL Injection in sqli (CVE-2018-25364)
SQL injection in sqli (CVE-2018-25364). Confidential information can be exposed externally.
|
| CVE-2026-9451 |
|
Vulnerability in sqli (CVE-2026-9451)
vulnerability in sqli (CVE-2026-9451). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9449 |
|
Vulnerability in sqli (CVE-2026-9449)
vulnerability in sqli (CVE-2026-9449). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9450 |
|
Vulnerability in sqli (CVE-2026-9450)
vulnerability in sqli (CVE-2026-9450). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9446 |
|
Vulnerability in sqli (CVE-2026-9446)
vulnerability in sqli (CVE-2026-9446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9444 |
|
Vulnerability in sqli (CVE-2026-9444)
vulnerability in sqli (CVE-2026-9444). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9445 |
|
Vulnerability in CVE-2026-9445 (CVE-2026-9445)
vulnerability in CVE-2026-9445 (CVE-2026-9445). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9447 |
|
Vulnerability in sqli (CVE-2026-9447)
vulnerability in sqli (CVE-2026-9447). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9448 |
|
Cross-Site Scripting (XSS) in CVE-2026-9448 (CVE-2026-9448)
cross-site scripting in CVE-2026-9448 (CVE-2026-9448). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46745 |
|
Vulnerability in apache-airflow-providers-fab (CVE-2026-46745)
vulnerability in apache-airflow-providers-fab (CVE-2026-46745). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.4` or later.
|
| CVE-2026-45361 |
|
Vulnerability in apache-airflow-providers-google (CVE-2026-45361)
vulnerability in apache-airflow-providers-google (CVE-2026-45361). Successful exploitation can lead to full system takeover. Exploitable via ``ComputeEngineSSHHook``. Mitigation: upgrade to `22.0.0` or later.
|
| CVE-2026-45249 |
|
Cross-Site Scripting (XSS) in echarts (CVE-2026-45249)
cross-site scripting in echarts (CVE-2026-45249). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.1.0` or later.
|
| CVE-2026-9438 |
|
Vulnerability in CVE-2026-9438 (CVE-2026-9438)
vulnerability in CVE-2026-9438 (CVE-2026-9438). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41863 |
|
Path Traversal in org.springframework.ai:spring-ai-anthropic (CVE-2026-41863)
path traversal in org.springframework.ai:spring-ai-anthropic (CVE-2026-41863). Data can be tampered with by attackers. Mitigation: upgrade to `1.1.7` or later.
|
| CVE-2026-9418 |
|
Cross-Site Scripting (XSS) in CVE-2026-9418 (CVE-2026-9418)
cross-site scripting in CVE-2026-9418 (CVE-2026-9418). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9421 |
|
Vulnerability in CVE-2026-9421 (CVE-2026-9421)
vulnerability in CVE-2026-9421 (CVE-2026-9421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9419 |
|
Cross-Site Scripting (XSS) in CVE-2026-9419 (CVE-2026-9419)
cross-site scripting in CVE-2026-9419 (CVE-2026-9419). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9417 |
|
Cross-Site Scripting (XSS) in CVE-2026-9417 (CVE-2026-9417)
cross-site scripting in CVE-2026-9417 (CVE-2026-9417). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9416 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-9416)
cross-site scripting in c (CVE-2026-9416). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9411 |
|
Vulnerability in sqli (CVE-2026-9411)
vulnerability in sqli (CVE-2026-9411). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9413 |
|
Cross-Site Scripting (XSS) in CVE-2026-9413 (CVE-2026-9413)
cross-site scripting in CVE-2026-9413 (CVE-2026-9413). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9415 |
|
Cross-Site Scripting (XSS) in CVE-2026-9415 (CVE-2026-9415)
cross-site scripting in CVE-2026-9415 (CVE-2026-9415). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9414 |
|
Cross-Site Scripting (XSS) in CVE-2026-9414 (CVE-2026-9414)
cross-site scripting in CVE-2026-9414 (CVE-2026-9414). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48832 |
|
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
|
| CVE-2026-9383 |
|
Vulnerability in sqli (CVE-2026-9383)
vulnerability in sqli (CVE-2026-9383). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9377 |
|
Cross-Site Scripting (XSS) in CVE-2026-9377 (CVE-2026-9377)
cross-site scripting in CVE-2026-9377 (CVE-2026-9377). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9370 |
|
Vulnerability in com.github.ulisesbocchio:jasypt-spring-boot (CVE-2026-9370)
vulnerability in com.github.ulisesbocchio:jasypt-spring-boot (CVE-2026-9370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9364 |
|
Vulnerability in sqli (CVE-2026-9364)
vulnerability in sqli (CVE-2026-9364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9356 |
|
Vulnerability in sqli (CVE-2026-9356)
vulnerability in sqli (CVE-2026-9356). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9355 |
|
Vulnerability in sqli (CVE-2026-9355)
vulnerability in sqli (CVE-2026-9355). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9342 |
|
Vulnerability in sqli (CVE-2026-9342)
vulnerability in sqli (CVE-2026-9342). Risk of unauthorized operations or information disclosure.
|