Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: rce Clear
ID Title
CVE-2026-77138 Unsafe Deserialization in CVE-2026-77138 (CVE-2026-77138)
vulnerability in CVE-2026-77138 (CVE-2026-77138). Risk of unauthorized operations or information disclosure.
CVE-2026-77136 Vulnerability in CVE-2026-77136 (CVE-2026-77136)
vulnerability in CVE-2026-77136 (CVE-2026-77136). Risk of unauthorized operations or information disclosure.
CVE-2026-16601 The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
CVE-2026-69665 SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
CVE-2026-68062 SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
CVE-2026-13214 Out-of-Bounds Write in c (CVE-2026-13214)
out-of-bounds write in c (CVE-2026-13214). Successful exploitation can lead to full system takeover.
CVE-2026-78685 Vulnerability in CVE-2026-78685 (CVE-2026-78685)
vulnerability in CVE-2026-78685 (CVE-2026-78685). Successful exploitation can lead to full system takeover.
CVE-2026-78680 NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
CVE-2026-75574 The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
CVE-2026-72696 Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
CVE-2026-56705 Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
CVE-2026-56703 Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
CVE-2026-56702 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
CVE-2026-60004 KEV [KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-71506 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
CVE-2026-71505 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
CVE-2026-40877 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
CVE-2026-78416 Vulnerability in CVE-2026-78416 (CVE-2026-78416)
vulnerability in CVE-2026-78416 (CVE-2026-78416). Risk of unauthorized operations or information disclosure.
CVE-2026-76071 Vulnerability in CVE-2026-76071 (CVE-2026-76071)
vulnerability in CVE-2026-76071 (CVE-2026-76071). Successful exploitation can lead to full system takeover.
CVE-2026-71364 Path Traversal in path-traversal (CVE-2026-71364)
path traversal in path-traversal (CVE-2026-71364). Successful exploitation can lead to full system takeover.
CVE-2026-76070 Vulnerability in CVE-2026-76070 (CVE-2026-76070)
vulnerability in CVE-2026-76070 (CVE-2026-76070). Successful exploitation can lead to full system takeover.
CVE-2026-76841 Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
CVE-2026-59568 Vulnerability in CVE-2026-59568 (CVE-2026-59568)
vulnerability in CVE-2026-59568 (CVE-2026-59568). Confidential information can be exposed externally.
CVE-2026-78317 SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78316 SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78315 SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78314 SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
CVE-2026-78209 exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
CVE-2026-78157 A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the...
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the...
CVE-2026-10053 Path Traversal in path-traversal (CVE-2026-10053)
path traversal in path-traversal (CVE-2026-10053). Successful exploitation can lead to full system takeover.
CVE-2026-78136 chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
CVE-2026-76605 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
CVE-2026-76604 Code Injection in CVE-2026-76604 (CVE-2026-76604)
code injection in CVE-2026-76604 (CVE-2026-76604). Risk of unauthorized operations or information disclosure.
CVE-2026-71513 Unsafe Deserialization in CVE-2026-71513 (CVE-2026-71513)
vulnerability in CVE-2026-71513 (CVE-2026-71513). Successful exploitation can lead to full system takeover.
CVE-2026-49849 Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
CVE-2026-27462 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lead...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
CVE-2026-41449 OS Command Injection in CVE-2026-41449 (CVE-2026-41449)
OS command injection in CVE-2026-41449 (CVE-2026-41449). Successful exploitation can lead to full system takeover.
CVE-2026-39909 Use-After-Free in cpp (CVE-2026-39909)
vulnerability in cpp (CVE-2026-39909). Successful exploitation can lead to full system takeover.
CVE-2026-50112 OS Command Injection in apache (CVE-2026-50112)
OS command injection in apache (CVE-2026-50112). Successful exploitation can lead to full system takeover.
CVE-2026-77645 Vulnerability in deserialization (CVE-2026-77645)
vulnerability in deserialization (CVE-2026-77645). Risk of unauthorized operations or information disclosure.
CVE-2026-69242 Vulnerability in c (CVE-2026-69242)
vulnerability in c (CVE-2026-69242). Risk of unauthorized operations or information disclosure.
CVE-2026-54245 SQL Injection in github.com/fleetdm/fleet (CVE-2026-54245)
SQL injection in github.com/fleetdm/fleet (CVE-2026-54245). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.86.2` or later.
CVE-2026-2334 Unrestricted File Upload in CVE-2026-2334 (CVE-2026-2334)
vulnerability in CVE-2026-2334 (CVE-2026-2334). Risk of unauthorized operations or information disclosure.
CVE-2026-18306 Vulnerability in CVE-2026-18306 (CVE-2026-18306)
vulnerability in CVE-2026-18306 (CVE-2026-18306). Successful exploitation can lead to full system takeover.
CVE-2026-18301 Vulnerability in CVE-2026-18301 (CVE-2026-18301)
vulnerability in CVE-2026-18301 (CVE-2026-18301). Successful exploitation can lead to full system takeover.
CVE-2026-18304 Vulnerability in CVE-2026-18304 (CVE-2026-18304)
vulnerability in CVE-2026-18304 (CVE-2026-18304). Successful exploitation can lead to full system takeover.
CVE-2026-18302 Vulnerability in CVE-2026-18302 (CVE-2026-18302)
vulnerability in CVE-2026-18302 (CVE-2026-18302). Successful exploitation can lead to full system takeover.
CVE-2026-18307 Vulnerability in CVE-2026-18307 (CVE-2026-18307)
vulnerability in CVE-2026-18307 (CVE-2026-18307). Successful exploitation can lead to full system takeover.
CVE-2026-18303 Vulnerability in CVE-2026-18303 (CVE-2026-18303)
vulnerability in CVE-2026-18303 (CVE-2026-18303). Successful exploitation can lead to full system takeover.
CVE-2026-18305 Vulnerability in CVE-2026-18305 (CVE-2026-18305)
vulnerability in CVE-2026-18305 (CVE-2026-18305). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →