Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-47781 |
|
Code Injection in pdm (CVE-2026-47781)
code injection in pdm (CVE-2026-47781). Risk of unauthorized operations or information disclosure. Exploitable via ``Core``. Mitigation: upgrade to `2.27.0` or later.
|
| CVE-2026-50223 |
|
Code Injection in apache (CVE-2026-50223)
code injection in apache (CVE-2026-50223). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45558 |
|
Vulnerability in c (CVE-2026-45558)
vulnerability in c (CVE-2026-45558). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/service/haproxy/`.
|
| CVE-2026-47906 |
|
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third...
|
| CVE-2026-45583 |
|
Code Injection in microsoft (CVE-2026-45583)
code injection in microsoft (CVE-2026-45583). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0414 |
|
Code Injection in netgear (CVE-2026-0414)
code injection in netgear (CVE-2026-0414). Data can be tampered with by attackers.
|
| CVE-2026-47292 |
|
Code Injection in microsoft (CVE-2026-47292)
code injection in microsoft (CVE-2026-47292). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20251 |
|
Code Injection in wordpress (CVE-2017-20251)
code injection in wordpress (CVE-2017-20251). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8795 |
|
Vulnerability in CVE-2026-8795 (CVE-2026-8795)
vulnerability in CVE-2026-8795 (CVE-2026-8795). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11688 |
|
Code Injection in google (CVE-2026-11688)
code injection in google (CVE-2026-11688). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47722 |
|
Code Injection in github.com/juev/nebula-mesh (CVE-2026-47722)
code injection in github.com/juev/nebula-mesh (CVE-2026-47722). Risk of unauthorized operations or information disclosure. Exploitable via ``ListenHost``. Mitigation: upgrade to `0.3.2` or later.
|
| CVE-2026-11393 |
|
Code Injection in Amazon @aws/agentcore (CVE-2026-11393)
code injection in Amazon @aws/agentcore (CVE-2026-11393). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.0.0-preview.9` or later.
|
| CVE-2026-52778 |
|
Code Injection in yeswiki/yeswiki (CVE-2026-52778)
code injection in yeswiki/yeswiki (CVE-2026-52778). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.6.6` or later.
|
| CVE-2026-42890 |
|
Code Injection in actual (CVE-2026-42890)
code injection in actual (CVE-2026-42890). Risk of unauthorized operations or information disclosure. Exploitable via ``actual``. Mitigation: upgrade to `26.5.0` or later.
|
| CVE-2026-25856 |
|
Code Injection in c (CVE-2026-25856)
code injection in c (CVE-2026-25856). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11534 |
|
Cross-Site Scripting (XSS) in CVE-2026-11534 (CVE-2026-11534)
cross-site scripting in CVE-2026-11534 (CVE-2026-11534). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11518 |
|
Cross-Site Scripting (XSS) in CVE-2026-11518 (CVE-2026-11518)
cross-site scripting in CVE-2026-11518 (CVE-2026-11518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11520 |
|
Cross-Site Scripting (XSS) in CVE-2026-11520 (CVE-2026-11520)
cross-site scripting in CVE-2026-11520 (CVE-2026-11520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11512 |
|
Cross-Site Scripting (XSS) in CVE-2026-11512 (CVE-2026-11512)
cross-site scripting in CVE-2026-11512 (CVE-2026-11512). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11491 |
|
Cross-Site Scripting (XSS) in CVE-2026-11491 (CVE-2026-11491)
cross-site scripting in CVE-2026-11491 (CVE-2026-11491). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11468 |
|
Cross-Site Scripting (XSS) in CVE-2026-11468 (CVE-2026-11468)
cross-site scripting in CVE-2026-11468 (CVE-2026-11468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11436 |
|
Cross-Site Scripting (XSS) in CVE-2026-11436 (CVE-2026-11436)
cross-site scripting in CVE-2026-11436 (CVE-2026-11436). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11434 |
|
Cross-Site Scripting (XSS) in CVE-2026-11434 (CVE-2026-11434)
cross-site scripting in CVE-2026-11434 (CVE-2026-11434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11429 |
|
Path Traversal in path-traversal (CVE-2026-11429)
path traversal in path-traversal (CVE-2026-11429). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
|
| CVE-2026-49493 |
|
Code Injection in CVE-2026-49493 (CVE-2026-49493)
code injection in CVE-2026-49493 (CVE-2026-49493). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.28` or later.
|
| CVE-2026-11338 |
|
Cross-Site Scripting (XSS) in CVE-2026-11338 (CVE-2026-11338)
cross-site scripting in CVE-2026-11338 (CVE-2026-11338). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11337 |
|
Cross-Site Scripting (XSS) in CVE-2026-11337 (CVE-2026-11337)
cross-site scripting in CVE-2026-11337 (CVE-2026-11337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48017 |
|
Code Injection in dbgate-api (CVE-2026-48017)
code injection in dbgate-api (CVE-2026-48017). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/load-reader`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-47668 |
|
Vulnerability in dbgate-serve (CVE-2026-47668)
vulnerability in dbgate-serve (CVE-2026-47668). Successful exploitation can lead to full system takeover. Exploitable via `POST /runners/start`. Mitigation: upgrade to `7.1.9` or later.
|
| CVE-2026-11231 |
|
Code Injection in google (CVE-2026-11231)
code injection in google (CVE-2026-11231). Confidential information can be exposed externally.
|
| CVE-2026-11218 |
|
Vulnerability in google (CVE-2026-11218)
vulnerability in google (CVE-2026-11218). Confidential information can be exposed externally.
|
| CVE-2026-11157 |
|
Code Injection in google (CVE-2026-11157)
code injection in google (CVE-2026-11157). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10928 |
|
Code Injection in google (CVE-2026-10928)
code injection in google (CVE-2026-10928). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10904 |
|
Vulnerability in google (CVE-2026-10904)
vulnerability in google (CVE-2026-10904). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10810 |
|
Cross-Site Scripting (XSS) in CVE-2026-10810 (CVE-2026-10810)
cross-site scripting in CVE-2026-10810 (CVE-2026-10810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44016 |
|
Code Injection in docling (CVE-2026-44016)
code injection in docling (CVE-2026-44016). Confidential information can be exposed externally. Exploitable via ``enable_remote_fetch``. Mitigation: upgrade to `2.91.0` or later.
|
| CVE-2026-10688 |
|
Vulnerability in CVE-2026-10688 (CVE-2026-10688)
vulnerability in CVE-2026-10688 (CVE-2026-10688). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49143 |
|
Code Injection in browserstack-runner (CVE-2026-49143)
code injection in browserstack-runner (CVE-2026-49143). Successful exploitation can lead to full system takeover. Exploitable via ``context``.
|
| CVE-2026-1829 |
|
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code...
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code...
|
| CVE-2026-47117 |
|
Code Injection in openmed (CVE-2026-47117)
code injection in openmed (CVE-2026-47117). Successful exploitation can lead to full system takeover. Exploitable via ``model_name``. Mitigation: upgrade to `1.5.2` or later.
|
| CVE-2026-39552 |
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
|
| CVE-2026-10567 |
|
Cross-Site Scripting (XSS) in CVE-2026-10567 (CVE-2026-10567)
cross-site scripting in CVE-2026-10567 (CVE-2026-10567). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10529 |
|
Cross-Site Scripting (XSS) in CVE-2026-10529 (CVE-2026-10529)
cross-site scripting in CVE-2026-10529 (CVE-2026-10529). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10514 |
|
Cross-Site Scripting (XSS) in CVE-2026-10514 (CVE-2026-10514)
cross-site scripting in CVE-2026-10514 (CVE-2026-10514). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10301 |
|
Cross-Site Scripting (XSS) in CVE-2026-10301 (CVE-2026-10301)
cross-site scripting in CVE-2026-10301 (CVE-2026-10301). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10289 |
|
Cross-Site Scripting (XSS) in CVE-2026-10289 (CVE-2026-10289)
cross-site scripting in CVE-2026-10289 (CVE-2026-10289). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9311 |
|
Code Injection in ibm (CVE-2026-9311)
code injection in ibm (CVE-2026-9311). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45132 |
|
Code Injection in CVE-2026-45132 (CVE-2026-45132)
code injection in CVE-2026-45132 (CVE-2026-45132). Confidential information can be exposed externally.
|
| CVE-2026-45131 |
|
Code Injection in CVE-2026-45131 (CVE-2026-45131)
code injection in CVE-2026-45131 (CVE-2026-45131). Confidential information can be exposed externally.
|
| CVE-2026-8931 |
|
Code Injection in CVE-2026-8931 (CVE-2026-8931)
code injection in CVE-2026-8931 (CVE-2026-8931). Risk of unauthorized operations or information disclosure.
|