Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-94 Clear
ID Title
CVE-2026-31040 Code Injection in statamcp (CVE-2026-31040)
code injection in statamcp (CVE-2026-31040). Successful exploitation can lead to full system takeover.
CVE-2026-25776 Code Injection in sixapart (CVE-2026-25776)
code injection in sixapart (CVE-2026-25776). Successful exploitation can lead to full system takeover.
CVE-2026-1340 KEV [KEV] Code Injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1340)
code injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1340). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-39846 Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-39846)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-39846). Successful exploitation can lead to full system takeover. Exploitable via ``nodeIntegration``. Mitigation: upgrade to `0.0.0-20260407035653-2f416e5253f1` or later.
CVE-2026-5739 Vulnerability in CVE-2026-5739 (CVE-2026-5739)
vulnerability in CVE-2026-5739 (CVE-2026-5739). Risk of unauthorized operations or information disclosure.
CVE-2025-71058 Code Injection in CVE-2025-71058 (CVE-2025-71058)
code injection in CVE-2025-71058 (CVE-2025-71058). Data can be tampered with by attackers.
CVE-2026-30460 Code Injection in thedaylightstudio (CVE-2026-30460)
code injection in thedaylightstudio (CVE-2026-30460). Successful exploitation can lead to full system takeover.
CVE-2026-22666 Vulnerability in dolibarr (CVE-2026-22666)
vulnerability in dolibarr (CVE-2026-22666). Successful exploitation can lead to full system takeover.
CVE-2026-5705 Cross-Site Scripting (XSS) in CVE-2026-5705 (CVE-2026-5705)
cross-site scripting in CVE-2026-5705 (CVE-2026-5705). Risk of unauthorized operations or information disclosure.
CVE-2026-35197 Code Injection in mattiebee (CVE-2026-35197)
code injection in mattiebee (CVE-2026-35197). Confidential information can be exposed externally. Mitigation: upgrade to `1.1.1` or later.
CVE-2026-35178 Code Injection in forceworkbench (CVE-2026-35178)
code injection in forceworkbench (CVE-2026-35178). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `65.0.0` or later.
CVE-2026-5671 Cross-Site Scripting (XSS) in CVE-2026-5671 (CVE-2026-5671)
cross-site scripting in CVE-2026-5671 (CVE-2026-5671). Risk of unauthorized operations or information disclosure.
CVE-2026-5631 Vulnerability in CVE-2026-5631 (CVE-2026-5631)
vulnerability in CVE-2026-5631 (CVE-2026-5631). Risk of unauthorized operations or information disclosure.
CVE-2026-5630 Cross-Site Scripting (XSS) in CVE-2026-5630 (CVE-2026-5630)
cross-site scripting in CVE-2026-5630 (CVE-2026-5630). Risk of unauthorized operations or information disclosure.
CVE-2026-5625 Cross-Site Scripting (XSS) in CVE-2026-5625 (CVE-2026-5625)
cross-site scripting in CVE-2026-5625 (CVE-2026-5625). Risk of unauthorized operations or information disclosure.
CVE-2026-5615 Cross-Site Scripting (XSS) in CVE-2026-5615 (CVE-2026-5615)
cross-site scripting in CVE-2026-5615 (CVE-2026-5615). Risk of unauthorized operations or information disclosure.
CVE-2026-5594 Vulnerability in CVE-2026-5594 (CVE-2026-5594)
vulnerability in CVE-2026-5594 (CVE-2026-5594). Risk of unauthorized operations or information disclosure.
CVE-2026-5584 Vulnerability in fosowl (CVE-2026-5584)
vulnerability in fosowl (CVE-2026-5584). Risk of unauthorized operations or information disclosure.
CVE-2026-5568 Cross-Site Scripting (XSS) in CVE-2026-5568 (CVE-2026-5568)
cross-site scripting in CVE-2026-5568 (CVE-2026-5568). Risk of unauthorized operations or information disclosure.
CVE-2026-5562 Vulnerability in provectus (CVE-2026-5562)
vulnerability in provectus (CVE-2026-5562). Risk of unauthorized operations or information disclosure.
CVE-2026-5556 Vulnerability in CVE-2026-5556 (CVE-2026-5556)
vulnerability in CVE-2026-5556 (CVE-2026-5556). Risk of unauthorized operations or information disclosure.
CVE-2026-5541 Cross-Site Scripting (XSS) in CVE-2026-5541 (CVE-2026-5541)
cross-site scripting in CVE-2026-5541 (CVE-2026-5541). Risk of unauthorized operations or information disclosure.
CVE-2026-5542 Cross-Site Scripting (XSS) in CVE-2026-5542 (CVE-2026-5542)
cross-site scripting in CVE-2026-5542 (CVE-2026-5542). Risk of unauthorized operations or information disclosure.
CVE-2026-5539 Cross-Site Scripting (XSS) in CVE-2026-5539 (CVE-2026-5539)
cross-site scripting in CVE-2026-5539 (CVE-2026-5539). Risk of unauthorized operations or information disclosure.
CVE-2026-5533 Cross-Site Scripting (XSS) in CVE-2026-5533 (CVE-2026-5533)
cross-site scripting in CVE-2026-5533 (CVE-2026-5533). Risk of unauthorized operations or information disclosure.
CVE-2026-3309 Code Injection in wordpress (CVE-2026-3309)
code injection in wordpress (CVE-2026-3309). Risk of unauthorized operations or information disclosure.
CVE-2026-28797 Vulnerability in infiniflow (CVE-2026-28797)
vulnerability in infiniflow (CVE-2026-28797). Successful exploitation can lead to full system takeover.
CVE-2026-5468 Cross-Site Scripting (XSS) in github.com/casdoor/casdoor (CVE-2026-5468)
cross-site scripting in github.com/casdoor/casdoor (CVE-2026-5468). Risk of unauthorized operations or information disclosure.
CVE-2026-35171 Code Injection in kedro (CVE-2026-35171)
code injection in kedro (CVE-2026-35171). Successful exploitation can lead to full system takeover. Exploitable via ``KEDRO_LOGGING_CONFIG``. Mitigation: upgrade to `1.3.0` or later.
CVE-2026-5370 Cross-Site Scripting (XSS) in laravel (CVE-2026-5370)
cross-site scripting in laravel (CVE-2026-5370). Risk of unauthorized operations or information disclosure.
CVE-2026-34725 Cross-Site Scripting (XSS) in CVE-2026-34725 (CVE-2026-34725)
cross-site scripting in CVE-2026-34725 (CVE-2026-34725). Successful exploitation can lead to full system takeover.
CVE-2026-35093 Code Injection in freedesktop (CVE-2026-35093)
code injection in freedesktop (CVE-2026-35093). Successful exploitation can lead to full system takeover.
CVE-2026-34448 Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448). Successful exploitation can lead to full system takeover. Exploitable via ``mAsse``. Mitigation: upgrade to `3.6.2` or later.
CVE-2026-4800 Code Injection in lodash (CVE-2026-4800)
code injection in lodash (CVE-2026-4800). Successful exploitation can lead to full system takeover.
CVE-2026-5209 Cross-Site Scripting (XSS) in CVE-2026-5209 (CVE-2026-5209)
cross-site scripting in CVE-2026-5209 (CVE-2026-5209). Risk of unauthorized operations or information disclosure.
CVE-2026-34202 Code Injection in deserialization (CVE-2026-34202)
code injection in deserialization (CVE-2026-34202). Risk of unauthorized operations or information disclosure.
CVE-2026-34060 Code Injection in shopify (CVE-2026-34060)
code injection in shopify (CVE-2026-34060). Successful exploitation can lead to full system takeover.
CVE-2026-33940 Code Injection in handlebarsjs (CVE-2026-33940)
code injection in handlebarsjs (CVE-2026-33940). Successful exploitation can lead to full system takeover. Exploitable via ``undefined``.
CVE-2026-33941 Cross-Site Scripting (XSS) in handlebarsjs (CVE-2026-33941)
cross-site scripting in handlebarsjs (CVE-2026-33941). Successful exploitation can lead to full system takeover.
CVE-2026-33943 Code Injection in capricorn86 (CVE-2026-33943)
code injection in capricorn86 (CVE-2026-33943). Successful exploitation can lead to full system takeover. Exploitable via ``ECMAScriptModuleCompiler``.
CVE-2026-33937 Code Injection in handlebarsjs (CVE-2026-33937)
code injection in handlebarsjs (CVE-2026-33937). Successful exploitation can lead to full system takeover. Exploitable via ``value``.
CVE-2026-33938 Code Injection in handlebarsjs (CVE-2026-33938)
code injection in handlebarsjs (CVE-2026-33938). Successful exploitation can lead to full system takeover.
CVE-2026-27876 Code Injection in grafana (CVE-2026-27876)
code injection in grafana (CVE-2026-27876). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
CVE-2026-30457 Code Injection in thedaylightstudio (CVE-2026-30457)
code injection in thedaylightstudio (CVE-2026-30457). Successful exploitation can lead to full system takeover.
CVE-2026-33017 KEV [KEV] Vulnerability in langflow (CVE-2026-33017)
vulnerability in langflow (CVE-2026-33017). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/build_public_tmp/{flow_id}/flow`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.9.0` or later.
CVE-2025-32432 KEV [KEV] Code Injection in Craft cms craft-cms (CVE-2025-32432)
code injection in Craft cms craft-cms (CVE-2025-32432). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-54068 KEV [KEV] Code Injection in Laravel livewire (CVE-2025-54068)
code injection in Laravel livewire (CVE-2025-54068). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-31898 Vulnerability in parall (CVE-2026-31898)
vulnerability in parall (CVE-2026-31898). Confidential information can be exposed externally. Exploitable via ``createAnnotation``.
CVE-2026-21570 Code Injection in atlassian (CVE-2026-21570)
code injection in atlassian (CVE-2026-21570). Successful exploitation can lead to full system takeover.
CVE-2025-50881 Code Injection in CVE-2025-50881 (CVE-2025-50881)
code injection in CVE-2025-50881 (CVE-2025-50881). Successful exploitation can lead to full system takeover. Exploitable via ``action``.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →