Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72833 |
|
Privilege Escalation in privilege-escalation (CVE-2026-72833)
vulnerability in privilege-escalation (CVE-2026-72833). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.13` or later.
|
| CVE-2026-72829 |
|
Privilege Escalation in CVE-2026-72829 (CVE-2026-72829)
vulnerability in CVE-2026-72829 (CVE-2026-72829). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72830 |
|
Privilege Escalation in symfony (CVE-2026-72830)
vulnerability in symfony (CVE-2026-72830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72826 |
|
Vulnerability in CVE-2026-72826 (CVE-2026-72826)
vulnerability in CVE-2026-72826 (CVE-2026-72826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72827 |
|
Vulnerability in CVE-2026-72827 (CVE-2026-72827)
vulnerability in CVE-2026-72827 (CVE-2026-72827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72828 |
|
Privilege Escalation in privilege-escalation (CVE-2026-72828)
vulnerability in privilege-escalation (CVE-2026-72828). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72825 |
|
Vulnerability in CVE-2026-72825 (CVE-2026-72825)
vulnerability in CVE-2026-72825 (CVE-2026-72825). Data can be tampered with by attackers. Exploitable via `POST /reports/twig-content/allowlist`.
|
| CVE-2026-72824 |
|
Vulnerability in CVE-2026-72824 (CVE-2026-72824)
vulnerability in CVE-2026-72824 (CVE-2026-72824). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72831 |
|
Authorization Flaw in CVE-2026-72831 (CVE-2026-72831)
vulnerability in CVE-2026-72831 (CVE-2026-72831). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72822 |
|
Vulnerability in CVE-2026-72822 (CVE-2026-72822)
vulnerability in CVE-2026-72822 (CVE-2026-72822). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/users/{user}/2fa/disable`.
|
| CVE-2026-72819 |
|
Code Injection in c (CVE-2026-72819)
code injection in c (CVE-2026-72819). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19822 |
|
Buffer Overflow in CVE-2026-19822 (CVE-2026-19822)
vulnerability in CVE-2026-19822 (CVE-2026-19822). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19821 |
|
Buffer Overflow in CVE-2026-19821 (CVE-2026-19821)
vulnerability in CVE-2026-19821 (CVE-2026-19821). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72810 |
|
Vulnerability in CVE-2026-72810 (CVE-2026-72810)
vulnerability in CVE-2026-72810 (CVE-2026-72810). Confidential information can be exposed externally.
|
| CVE-2026-19815 |
|
Buffer Overflow in CVE-2026-19815 (CVE-2026-19815)
vulnerability in CVE-2026-19815 (CVE-2026-19815). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19814 |
|
Buffer Overflow in CVE-2026-19814 (CVE-2026-19814)
vulnerability in CVE-2026-19814 (CVE-2026-19814). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19813 |
|
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts...
A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts...
|
| CVE-2026-19812 |
|
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the...
A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the...
|
| CVE-2026-19794 |
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
| CVE-2026-19811 |
|
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted...
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted...
|
| CVE-2026-18039 |
|
Privilege Escalation in wordpress (CVE-2026-18039)
vulnerability in wordpress (CVE-2026-18039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15205 |
|
SQL Injection in wordpress (CVE-2026-15205)
SQL injection in wordpress (CVE-2026-15205). Confidential information can be exposed externally.
|
| CVE-2026-19791 |
|
Buffer Overflow in CVE-2026-19791 (CVE-2026-19791)
vulnerability in CVE-2026-19791 (CVE-2026-19791). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19792 |
|
Buffer Overflow in CVE-2026-19792 (CVE-2026-19792)
vulnerability in CVE-2026-19792 (CVE-2026-19792). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19790 |
|
Buffer Overflow in CVE-2026-19790 (CVE-2026-19790)
vulnerability in CVE-2026-19790 (CVE-2026-19790). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19789 |
|
Buffer Overflow in CVE-2026-19789 (CVE-2026-19789)
vulnerability in CVE-2026-19789 (CVE-2026-19789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19788 |
|
Buffer Overflow in CVE-2026-19788 (CVE-2026-19788)
vulnerability in CVE-2026-19788 (CVE-2026-19788). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18109 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18109)
cross-site scripting in wordpress (CVE-2026-18109). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19771 |
|
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown...
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown...
|
| CVE-2026-19764 |
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
| CVE-2026-19762 |
|
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
|
| CVE-2026-19758 |
|
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
|
| CVE-2026-19757 |
|
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
|
| CVE-2026-19753 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-19753 (CVE-2026-19753)
SSRF in CVE-2026-19753 (CVE-2026-19753). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73841 |
|
Vulnerability in CVE-2026-73841 (CVE-2026-73841)
vulnerability in CVE-2026-73841 (CVE-2026-73841). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-73667 |
|
OS Command Injection in c (CVE-2026-73667)
OS command injection in c (CVE-2026-73667). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73666 |
|
Vulnerability in CVE-2026-73666 (CVE-2026-73666)
vulnerability in CVE-2026-73666 (CVE-2026-73666). Confidential information can be exposed externally.
|
| CVE-2026-73659 |
|
Path Traversal in CVE-2026-73659 (CVE-2026-73659)
path traversal in CVE-2026-73659 (CVE-2026-73659). Confidential information can be exposed externally.
|
| CVE-2026-73658 |
|
Vulnerability in CVE-2026-73658 (CVE-2026-73658)
vulnerability in CVE-2026-73658 (CVE-2026-73658). Confidential information can be exposed externally.
|
| CVE-2026-73408 |
|
SQL Injection in CVE-2026-73408 (CVE-2026-73408)
SQL injection in CVE-2026-73408 (CVE-2026-73408). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72857 |
|
Vulnerability in CVE-2026-72857 (CVE-2026-72857)
vulnerability in CVE-2026-72857 (CVE-2026-72857). Confidential information can be exposed externally.
|
| CVE-2026-72856 |
|
Vulnerability in CVE-2026-72856 (CVE-2026-72856)
vulnerability in CVE-2026-72856 (CVE-2026-72856). Confidential information can be exposed externally. Exploitable via `PUT /api/global/users/tenant/owner`.
|
| CVE-2026-72855 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-72855 (CVE-2026-72855)
SSRF in CVE-2026-72855 (CVE-2026-72855). Confidential information can be exposed externally.
|
| CVE-2026-72853 |
|
SQL Injection in sqli (CVE-2026-72853)
SQL injection in sqli (CVE-2026-72853). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72849 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-72849 (CVE-2026-72849)
vulnerability in CVE-2026-72849 (CVE-2026-72849). Confidential information can be exposed externally.
|
| CVE-2026-72840 |
|
Vulnerability in CVE-2026-72840 (CVE-2026-72840)
vulnerability in CVE-2026-72840 (CVE-2026-72840). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56865 |
|
Vulnerability in CVE-2026-56865 (CVE-2026-56865)
vulnerability in CVE-2026-56865 (CVE-2026-56865). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56864 |
|
Vulnerability in CVE-2026-56864 (CVE-2026-56864)
vulnerability in CVE-2026-56864 (CVE-2026-56864). Confidential information can be exposed externally.
|
| CVE-2026-56862 |
|
Vulnerability in CVE-2026-56862 (CVE-2026-56862)
vulnerability in CVE-2026-56862 (CVE-2026-56862). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56859 |
|
Vulnerability in CVE-2026-56859 (CVE-2026-56859)
vulnerability in CVE-2026-56859 (CVE-2026-56859). Risk of unauthorized operations or information disclosure.
|