Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-45609 |
|
SSRF (Server-Side Request Forgery) in org.springaicommunity:mcp-client-security (CVE-2026-45609)
SSRF in org.springaicommunity:mcp-client-security (CVE-2026-45609). Risk of unauthorized operations or information disclosure. Exploitable via ``McpOAuth2ClientManager``. Mitigation: upgrade to `0.1.9` or later.
|
| CVE-2026-46510 |
|
Vulnerability in form-data-objectizer (CVE-2026-46510)
vulnerability in form-data-objectizer (CVE-2026-46510). Data can be tampered with by attackers. Exploitable via ``__proto__``. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-42009 |
|
Vulnerability in dos (CVE-2026-42009)
vulnerability in dos (CVE-2026-42009). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8788 |
|
Vulnerability in CVE-2026-8788 (CVE-2026-8788)
vulnerability in CVE-2026-8788 (CVE-2026-8788). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6346 |
|
Information Disclosure in github.com/mattermost/mattermost/server/v8 (CVE-2026-6346)
vulnerability in github.com/mattermost/mattermost/server/v8 (CVE-2026-6346). Confidential information can be exposed externally. Mitigation: upgrade to `8.0.0-20260326202606-fac92f4a71f3` or later.
|
| CVE-2026-7498 |
|
Cross-Site Scripting (XSS) in CVE-2026-7498 (CVE-2026-7498)
cross-site scripting in CVE-2026-7498 (CVE-2026-7498). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6347 |
|
Information Disclosure in github.com/mattermost/mattermost-server (CVE-2026-6347)
vulnerability in github.com/mattermost/mattermost-server (CVE-2026-6347). Confidential information can be exposed externally. Mitigation: upgrade to `11.4.4` or later.
|
| CVE-2026-3220 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3220)
cross-site scripting in wordpress (CVE-2026-3220). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6379 |
|
SQL Injection in wordpress (CVE-2026-6379)
SQL injection in wordpress (CVE-2026-6379). Confidential information can be exposed externally.
|
| CVE-2026-6381 |
|
Path Traversal in wordpress (CVE-2026-6381)
path traversal in wordpress (CVE-2026-6381). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6495 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6495)
cross-site scripting in wordpress (CVE-2026-6495). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8785 |
|
Vulnerability in sqli (CVE-2026-8785)
vulnerability in sqli (CVE-2026-8785). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8776 |
|
Buffer Overflow in CVE-2026-8776 (CVE-2026-8776)
vulnerability in CVE-2026-8776 (CVE-2026-8776). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8775 |
|
Buffer Overflow in CVE-2026-8775 (CVE-2026-8775)
vulnerability in CVE-2026-8775 (CVE-2026-8775). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8771 |
|
Vulnerability in org.linlinjava:litemall-wx-api (CVE-2026-8771)
vulnerability in org.linlinjava:litemall-wx-api (CVE-2026-8771). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8768 |
|
SSRF (Server-Side Request Forgery) in vercel (CVE-2026-8768)
SSRF in vercel (CVE-2026-8768). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8764 |
|
Buffer Overflow in CVE-2026-8764 (CVE-2026-8764)
vulnerability in CVE-2026-8764 (CVE-2026-8764). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46720 |
|
Vulnerability in CVE-2026-46720 (CVE-2026-46720)
vulnerability in CVE-2026-46720 (CVE-2026-46720). Data can be tampered with by attackers.
|
| CVE-2026-8759 |
|
Vulnerability in com.ibeetl:beetl-spring-classic (CVE-2026-8759)
vulnerability in com.ibeetl:beetl-spring-classic (CVE-2026-8759). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8758 |
|
Vulnerability in CVE-2026-8758 (CVE-2026-8758)
vulnerability in CVE-2026-8758 (CVE-2026-8758). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8757 |
|
Path Traversal in path-traversal (CVE-2026-8757)
path traversal in path-traversal (CVE-2026-8757). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8755 |
|
Path Traversal in path-traversal (CVE-2026-8755)
path traversal in path-traversal (CVE-2026-8755). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8756 |
|
Path Traversal in path-traversal (CVE-2026-8756)
path traversal in path-traversal (CVE-2026-8756). Risk of unauthorized operations or information disclosure.
|
| CVE-2018-25338 |
|
SQL Injection in sqli (CVE-2018-25338)
SQL injection in sqli (CVE-2018-25338). Confidential information can be exposed externally.
|
| CVE-2018-25339 |
|
SQL Injection in sqli (CVE-2018-25339)
SQL injection in sqli (CVE-2018-25339). Confidential information can be exposed externally.
|
| CVE-2018-25326 |
|
Path Traversal in wordpress (CVE-2018-25326)
path traversal in wordpress (CVE-2018-25326). Confidential information can be exposed externally.
|
| CVE-2018-25328 |
|
Vulnerability in CVE-2018-25328 (CVE-2018-25328)
vulnerability in CVE-2018-25328 (CVE-2018-25328). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25329 |
|
Vulnerability in wordpress (CVE-2018-25329)
vulnerability in wordpress (CVE-2018-25329). Confidential information can be exposed externally.
|
| CVE-2018-25330 |
|
SQL Injection in sqli (CVE-2018-25330)
SQL injection in sqli (CVE-2018-25330). Confidential information can be exposed externally.
|
| CVE-2018-25333 |
|
SQL Injection in sqli (CVE-2018-25333)
SQL injection in sqli (CVE-2018-25333). Confidential information can be exposed externally.
|
| CVE-2018-25319 |
|
SQL Injection in sqli (CVE-2018-25319)
SQL injection in sqli (CVE-2018-25319). Confidential information can be exposed externally.
|
| CVE-2018-25322 |
|
Vulnerability in CVE-2018-25322 (CVE-2018-25322)
vulnerability in CVE-2018-25322 (CVE-2018-25322). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25323 |
|
Vulnerability in CVE-2018-25323 (CVE-2018-25323)
vulnerability in CVE-2018-25323 (CVE-2018-25323). Successful exploitation can lead to full system takeover.
|
| CVE-2018-25325 |
|
Path Traversal in wordpress (CVE-2018-25325)
path traversal in wordpress (CVE-2018-25325). Confidential information can be exposed externally.
|
| CVE-2026-8751 |
|
Vulnerability in deserialization (CVE-2026-8751)
vulnerability in deserialization (CVE-2026-8751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8734 |
|
Vulnerability in sqli (CVE-2026-8734)
vulnerability in sqli (CVE-2026-8734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8719 |
|
Privilege Escalation in wordpress (CVE-2026-8719)
vulnerability in wordpress (CVE-2026-8719). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8725 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-8725 (CVE-2026-8725)
SSRF in CVE-2026-8725 (CVE-2026-8725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46728 |
|
Vulnerability in denx (CVE-2026-46728)
vulnerability in denx (CVE-2026-46728). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47976 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2021-47976)
vulnerability in csrf (CVE-2021-47976). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47977 |
|
Path Traversal in wordpress (CVE-2021-47977)
path traversal in wordpress (CVE-2021-47977). Confidential information can be exposed externally.
|
| CVE-2021-47979 |
|
Path Traversal in c (CVE-2021-47979)
path traversal in c (CVE-2021-47979). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47980 |
|
SQL Injection in sqli (CVE-2021-47980)
SQL injection in sqli (CVE-2021-47980). Confidential information can be exposed externally.
|
| CVE-2021-47969 |
|
Vulnerability in dos (CVE-2021-47969)
vulnerability in dos (CVE-2021-47969). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47970 |
|
Vulnerability in dos (CVE-2021-47970)
vulnerability in dos (CVE-2021-47970). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47971 |
|
Vulnerability in dos (CVE-2021-47971)
vulnerability in dos (CVE-2021-47971). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47972 |
|
Vulnerability in dos (CVE-2021-47972)
vulnerability in dos (CVE-2021-47972). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47973 |
|
Vulnerability in dos (CVE-2021-47973)
vulnerability in dos (CVE-2021-47973). Risk of unauthorized operations or information disclosure.
|
| CVE-2021-47974 |
|
Vulnerability in c (CVE-2021-47974)
vulnerability in c (CVE-2021-47974). Successful exploitation can lead to full system takeover.
|
| CVE-2021-47975 |
|
Cross-Site Scripting (XSS) in CVE-2021-47975 (CVE-2021-47975)
cross-site scripting in CVE-2021-47975 (CVE-2021-47975). Risk of unauthorized operations or information disclosure.
|