Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-31040 |
|
Code Injection in statamcp (CVE-2026-31040)
code injection in statamcp (CVE-2026-31040). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25776 |
|
Code Injection in sixapart (CVE-2026-25776)
code injection in sixapart (CVE-2026-25776). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1340 KEV |
|
[KEV] Code Injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1340)
code injection in Ivanti endpoint-manager-mobile-epmm (CVE-2026-1340). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-39846 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-39846)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-39846). Successful exploitation can lead to full system takeover. Exploitable via ``nodeIntegration``. Mitigation: upgrade to `0.0.0-20260407035653-2f416e5253f1` or later.
|
| CVE-2026-5739 |
|
Vulnerability in CVE-2026-5739 (CVE-2026-5739)
vulnerability in CVE-2026-5739 (CVE-2026-5739). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71058 |
|
Code Injection in CVE-2025-71058 (CVE-2025-71058)
code injection in CVE-2025-71058 (CVE-2025-71058). Data can be tampered with by attackers.
|
| CVE-2026-30460 |
|
Code Injection in thedaylightstudio (CVE-2026-30460)
code injection in thedaylightstudio (CVE-2026-30460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22666 |
|
Vulnerability in dolibarr (CVE-2026-22666)
vulnerability in dolibarr (CVE-2026-22666). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5705 |
|
Cross-Site Scripting (XSS) in CVE-2026-5705 (CVE-2026-5705)
cross-site scripting in CVE-2026-5705 (CVE-2026-5705). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35197 |
|
Code Injection in mattiebee (CVE-2026-35197)
code injection in mattiebee (CVE-2026-35197). Confidential information can be exposed externally. Mitigation: upgrade to `1.1.1` or later.
|
| CVE-2026-35178 |
|
Code Injection in forceworkbench (CVE-2026-35178)
code injection in forceworkbench (CVE-2026-35178). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `65.0.0` or later.
|
| CVE-2026-5671 |
|
Cross-Site Scripting (XSS) in CVE-2026-5671 (CVE-2026-5671)
cross-site scripting in CVE-2026-5671 (CVE-2026-5671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5631 |
|
Vulnerability in CVE-2026-5631 (CVE-2026-5631)
vulnerability in CVE-2026-5631 (CVE-2026-5631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5630 |
|
Cross-Site Scripting (XSS) in CVE-2026-5630 (CVE-2026-5630)
cross-site scripting in CVE-2026-5630 (CVE-2026-5630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5625 |
|
Cross-Site Scripting (XSS) in CVE-2026-5625 (CVE-2026-5625)
cross-site scripting in CVE-2026-5625 (CVE-2026-5625). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5615 |
|
Cross-Site Scripting (XSS) in CVE-2026-5615 (CVE-2026-5615)
cross-site scripting in CVE-2026-5615 (CVE-2026-5615). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5594 |
|
Vulnerability in CVE-2026-5594 (CVE-2026-5594)
vulnerability in CVE-2026-5594 (CVE-2026-5594). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5584 |
|
Vulnerability in fosowl (CVE-2026-5584)
vulnerability in fosowl (CVE-2026-5584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5568 |
|
Cross-Site Scripting (XSS) in CVE-2026-5568 (CVE-2026-5568)
cross-site scripting in CVE-2026-5568 (CVE-2026-5568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5562 |
|
Vulnerability in provectus (CVE-2026-5562)
vulnerability in provectus (CVE-2026-5562). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5556 |
|
Vulnerability in CVE-2026-5556 (CVE-2026-5556)
vulnerability in CVE-2026-5556 (CVE-2026-5556). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5541 |
|
Cross-Site Scripting (XSS) in CVE-2026-5541 (CVE-2026-5541)
cross-site scripting in CVE-2026-5541 (CVE-2026-5541). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5542 |
|
Cross-Site Scripting (XSS) in CVE-2026-5542 (CVE-2026-5542)
cross-site scripting in CVE-2026-5542 (CVE-2026-5542). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5539 |
|
Cross-Site Scripting (XSS) in CVE-2026-5539 (CVE-2026-5539)
cross-site scripting in CVE-2026-5539 (CVE-2026-5539). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5533 |
|
Cross-Site Scripting (XSS) in CVE-2026-5533 (CVE-2026-5533)
cross-site scripting in CVE-2026-5533 (CVE-2026-5533). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3309 |
|
Code Injection in wordpress (CVE-2026-3309)
code injection in wordpress (CVE-2026-3309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28797 |
|
Vulnerability in infiniflow (CVE-2026-28797)
vulnerability in infiniflow (CVE-2026-28797). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5468 |
|
Cross-Site Scripting (XSS) in github.com/casdoor/casdoor (CVE-2026-5468)
cross-site scripting in github.com/casdoor/casdoor (CVE-2026-5468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35171 |
|
Code Injection in kedro (CVE-2026-35171)
code injection in kedro (CVE-2026-35171). Successful exploitation can lead to full system takeover. Exploitable via ``KEDRO_LOGGING_CONFIG``. Mitigation: upgrade to `1.3.0` or later.
|
| CVE-2026-5370 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-5370)
cross-site scripting in laravel (CVE-2026-5370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34725 |
|
Cross-Site Scripting (XSS) in CVE-2026-34725 (CVE-2026-34725)
cross-site scripting in CVE-2026-34725 (CVE-2026-34725). Successful exploitation can lead to full system takeover.
|
| CVE-2026-35093 |
|
Code Injection in freedesktop (CVE-2026-35093)
code injection in freedesktop (CVE-2026-35093). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34448 |
|
Cross-Site Scripting (XSS) in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448)
cross-site scripting in github.com/siyuan-note/siyuan/kernel (CVE-2026-34448). Successful exploitation can lead to full system takeover. Exploitable via ``mAsse``. Mitigation: upgrade to `3.6.2` or later.
|
| CVE-2026-4800 |
|
Code Injection in lodash (CVE-2026-4800)
code injection in lodash (CVE-2026-4800). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5209 |
|
Cross-Site Scripting (XSS) in CVE-2026-5209 (CVE-2026-5209)
cross-site scripting in CVE-2026-5209 (CVE-2026-5209). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34202 |
|
Code Injection in deserialization (CVE-2026-34202)
code injection in deserialization (CVE-2026-34202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34060 |
|
Code Injection in shopify (CVE-2026-34060)
code injection in shopify (CVE-2026-34060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33940 |
|
Code Injection in handlebarsjs (CVE-2026-33940)
code injection in handlebarsjs (CVE-2026-33940). Successful exploitation can lead to full system takeover. Exploitable via ``undefined``.
|
| CVE-2026-33941 |
|
Cross-Site Scripting (XSS) in handlebarsjs (CVE-2026-33941)
cross-site scripting in handlebarsjs (CVE-2026-33941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33943 |
|
Code Injection in capricorn86 (CVE-2026-33943)
code injection in capricorn86 (CVE-2026-33943). Successful exploitation can lead to full system takeover. Exploitable via ``ECMAScriptModuleCompiler``.
|
| CVE-2026-33937 |
|
Code Injection in handlebarsjs (CVE-2026-33937)
code injection in handlebarsjs (CVE-2026-33937). Successful exploitation can lead to full system takeover. Exploitable via ``value``.
|
| CVE-2026-33938 |
|
Code Injection in handlebarsjs (CVE-2026-33938)
code injection in handlebarsjs (CVE-2026-33938). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27876 |
|
Code Injection in grafana (CVE-2026-27876)
code injection in grafana (CVE-2026-27876). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2` or later.
|
| CVE-2026-30457 |
|
Code Injection in thedaylightstudio (CVE-2026-30457)
code injection in thedaylightstudio (CVE-2026-30457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33017 KEV |
|
[KEV] Vulnerability in langflow (CVE-2026-33017)
vulnerability in langflow (CVE-2026-33017). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/build_public_tmp/{flow_id}/flow`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.9.0` or later.
|
| CVE-2025-32432 KEV |
|
[KEV] Code Injection in Craft cms craft-cms (CVE-2025-32432)
code injection in Craft cms craft-cms (CVE-2025-32432). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-54068 KEV |
|
[KEV] Code Injection in Laravel livewire (CVE-2025-54068)
code injection in Laravel livewire (CVE-2025-54068). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-31898 |
|
Vulnerability in parall (CVE-2026-31898)
vulnerability in parall (CVE-2026-31898). Confidential information can be exposed externally. Exploitable via ``createAnnotation``.
|
| CVE-2026-21570 |
|
Code Injection in atlassian (CVE-2026-21570)
code injection in atlassian (CVE-2026-21570). Successful exploitation can lead to full system takeover.
|
| CVE-2025-50881 |
|
Code Injection in CVE-2025-50881 (CVE-2025-50881)
code injection in CVE-2025-50881 (CVE-2025-50881). Successful exploitation can lead to full system takeover. Exploitable via ``action``.
|