Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-37227 |
|
Unrestricted File Upload in CVE-2020-37227 (CVE-2020-37227)
vulnerability in CVE-2020-37227 (CVE-2020-37227). Successful exploitation can lead to full system takeover.
|
| CVE-2025-4202 |
|
Vulnerability in wordpress (CVE-2025-4202)
vulnerability in wordpress (CVE-2025-4202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8681 |
|
Vulnerability in wordpress (CVE-2026-8681)
vulnerability in wordpress (CVE-2026-8681). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-67031 |
|
Code Injection in CVE-2025-67031 (CVE-2025-67031)
code injection in CVE-2025-67031 (CVE-2025-67031). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46367 |
|
Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
|
| CVE-2026-46408 |
|
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter t...
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter the payment flow without verifying cart ownership. A logged-in attacker can therefore reuse another u...
|
| CVE-2026-46359 |
|
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
|
| CVE-2026-46361 |
|
Cross-Site Scripting (XSS) in thorsten/phpmyfaq (CVE-2026-46361)
cross-site scripting in thorsten/phpmyfaq (CVE-2026-46361). Confidential information can be exposed externally. Exploitable via ``search.twig``. Mitigation: upgrade to `4.1.2` or later.
|
| CVE-2026-46366 |
|
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
|
| CVE-2026-45007 |
|
Vulnerability in thorsten/phpmyfaq (CVE-2026-45007)
vulnerability in thorsten/phpmyfaq (CVE-2026-45007). Risk of unauthorized operations or information disclosure. Exploitable via ``ConfigurationTabController.php``. Mitigation: upgrade to `4.1.2` or later.
|
| CVE-2021-47964 |
|
Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated...
Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated...
|
| CVE-2021-47966 |
|
PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in...
PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in...
|
| CVE-2021-47967 |
|
Cross-Site Scripting (XSS) in c (CVE-2021-47967)
cross-site scripting in c (CVE-2021-47967). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47965 |
|
Unrestricted File Upload in wordpress (CVE-2021-47965)
vulnerability in wordpress (CVE-2021-47965). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47959 |
|
WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows...
WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows...
|
| CVE-2021-47958 |
|
SSRF (Server-Side Request Forgery) in CVE-2021-47958 (CVE-2021-47958)
SSRF in CVE-2021-47958 (CVE-2021-47958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45619 |
|
Vulnerability in WWBN/AVideo (CVE-2026-45619)
vulnerability in WWBN/AVideo (CVE-2026-45619). Confidential information can be exposed externally. Exploitable via ``EpgParser.php``.
|
| CVE-2026-45610 |
|
Vulnerability in WWBN/AVideo (CVE-2026-45610)
vulnerability in WWBN/AVideo (CVE-2026-45610). Data can be tampered with by attackers. Exploitable via ``SameSite``.
|
| CVE-2026-45580 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-45580)
cross-site scripting in WWBN/AVideo (CVE-2026-45580). Risk of unauthorized operations or information disclosure. Exploitable via ``echo``.
|
| CVE-2026-45578 |
|
OS Command Injection in WWBN/AVideo (CVE-2026-45578)
OS command injection in WWBN/AVideo (CVE-2026-45578). Successful exploitation can lead to full system takeover. Exploitable via ``on_publish.php``.
|
| CVE-2026-45575 |
|
Vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-45575)
vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-45575). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.2` or later.
|
| CVE-2026-45574 |
|
Vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-45574)
vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-45574). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.2` or later.
|
| CVE-2026-46491 |
|
Path Traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491)
path traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491). Data can be tampered with by attackers. Exploitable via ``ticket``. Mitigation: upgrade to `7.0.3` or later.
|
| CVE-2026-44692 |
|
Vulnerability in code16/sharp (CVE-2026-44692)
vulnerability in code16/sharp (CVE-2026-44692). Confidential information can be exposed externally. Exploitable via `GET /sharp/{globalFilter}/download/{entityKey}/{instanceId`. Mitigation: upgrade to `9.22.0` or later.
|
| CVE-2026-42155 |
|
Vulnerability in openmage/magento-lts (CVE-2026-42155)
vulnerability in openmage/magento-lts (CVE-2026-42155). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/xmlrpc/`. Mitigation: upgrade to `20.18.0` or later.
|
| CVE-2026-41258 |
|
Code Injection in org.openmrs.api:openmrs-api (CVE-2026-41258)
code injection in org.openmrs.api:openmrs-api (CVE-2026-41258). Successful exploitation can lead to full system takeover. Exploitable via ``VelocityEngine``. Mitigation: upgrade to `2.8.6` or later.
|
| CVE-2026-45062 |
|
Vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062)
vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062). Successful exploitation can lead to full system takeover. Exploitable via ``cgi.go``. Mitigation: upgrade to `1.12.3` or later.
|
| CVE-2026-35194 |
|
Code Injection in flink (CVE-2026-35194)
code injection in flink (CVE-2026-35194). Confidential information can be exposed externally. Mitigation: upgrade to `1.20.4, 2.0.2, 2.1.1, 2.2.1` or later.
|
| CVE-2026-46333 |
|
Privilege Escalation in cisa (CVE-2026-46333)
vulnerability in cisa (CVE-2026-46333). Confidential information can be exposed externally.
|
| CVE-2026-8503 |
|
Vulnerability in apache (CVE-2026-8503)
vulnerability in apache (CVE-2026-8503). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8398 KEV |
|
[KEV] Vulnerability in Daemon disc-soft (CVE-2026-8398)
vulnerability in Daemon disc-soft (CVE-2026-8398). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-6228 |
|
Privilege Escalation in wordpress (CVE-2026-6228)
vulnerability in wordpress (CVE-2026-6228). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7046 |
|
SQL Injection in wordpress (CVE-2026-7046)
SQL injection in wordpress (CVE-2026-7046). Confidential information can be exposed externally.
|
| CVE-2026-4683 |
|
Vulnerability in wordpress (CVE-2026-4683)
vulnerability in wordpress (CVE-2026-4683). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6415 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6415)
cross-site scripting in wordpress (CVE-2026-6415). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5229 |
|
Authentication Bypass in wordpress (CVE-2026-5229)
authentication bypass in wordpress (CVE-2026-5229). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7563 |
|
Vulnerability in wordpress (CVE-2026-7563)
vulnerability in wordpress (CVE-2026-7563). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6403 |
|
Path Traversal in wordpress (CVE-2026-6403)
path traversal in wordpress (CVE-2026-6403). Confidential information can be exposed externally.
|
| CVE-2026-8425 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-8425)
vulnerability in wordpress (CVE-2026-8425). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4094 |
|
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
|
| CVE-2026-6646 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6646)
cross-site scripting in wordpress (CVE-2026-6646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41702 |
|
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
|
| CVE-2026-43490 |
|
Out-of-Bounds Write in linux (CVE-2026-43490)
out-of-bounds write in linux (CVE-2026-43490). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6811 |
|
Vulnerability in CVE-2026-6811 (CVE-2026-6811)
vulnerability in CVE-2026-6811 (CVE-2026-6811). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8583 |
|
Vulnerability in google (CVE-2026-8583)
vulnerability in google (CVE-2026-8583). Confidential information can be exposed externally.
|
| CVE-2026-8585 |
|
Vulnerability in c (CVE-2026-8585)
vulnerability in c (CVE-2026-8585). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8582 |
|
Vulnerability in google (CVE-2026-8582)
vulnerability in google (CVE-2026-8582). Confidential information can be exposed externally.
|
| CVE-2026-8584 |
|
Vulnerability in google (CVE-2026-8584)
vulnerability in google (CVE-2026-8584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8587 |
|
Use-After-Free in google (CVE-2026-8587)
vulnerability in google (CVE-2026-8587). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8581 |
|
Use-After-Free in google (CVE-2026-8581)
vulnerability in google (CVE-2026-8581). Successful exploitation can lead to full system takeover.
|