Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-77138 |
|
Unsafe Deserialization in CVE-2026-77138 (CVE-2026-77138)
vulnerability in CVE-2026-77138 (CVE-2026-77138). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77136 |
|
Vulnerability in CVE-2026-77136 (CVE-2026-77136)
vulnerability in CVE-2026-77136 (CVE-2026-77136). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16601 |
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
| CVE-2026-69665 |
|
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
|
| CVE-2026-68062 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-13214 |
|
Out-of-Bounds Write in c (CVE-2026-13214)
out-of-bounds write in c (CVE-2026-13214). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78685 |
|
Vulnerability in CVE-2026-78685 (CVE-2026-78685)
vulnerability in CVE-2026-78685 (CVE-2026-78685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78680 |
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
| CVE-2026-75574 |
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
| CVE-2026-72696 |
|
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
|
| CVE-2026-56705 |
|
Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56703 |
|
Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56702 |
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
| CVE-2026-60004 KEV |
|
[KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-71506 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
| CVE-2026-71505 |
|
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-78416 |
|
Vulnerability in CVE-2026-78416 (CVE-2026-78416)
vulnerability in CVE-2026-78416 (CVE-2026-78416). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76071 |
|
Vulnerability in CVE-2026-76071 (CVE-2026-76071)
vulnerability in CVE-2026-76071 (CVE-2026-76071). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71364 |
|
Path Traversal in path-traversal (CVE-2026-71364)
path traversal in path-traversal (CVE-2026-71364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76070 |
|
Vulnerability in CVE-2026-76070 (CVE-2026-76070)
vulnerability in CVE-2026-76070 (CVE-2026-76070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76841 |
|
Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59568 |
|
Vulnerability in CVE-2026-59568 (CVE-2026-59568)
vulnerability in CVE-2026-59568 (CVE-2026-59568). Confidential information can be exposed externally.
|
| CVE-2026-78317 |
|
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
|
| CVE-2026-78316 |
|
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
|
| CVE-2026-78315 |
|
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
|
| CVE-2026-78314 |
|
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.
|
| CVE-2026-78209 |
|
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
|
| CVE-2026-78157 |
|
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the...
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the...
|
| CVE-2026-10053 |
|
Path Traversal in path-traversal (CVE-2026-10053)
path traversal in path-traversal (CVE-2026-10053). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78136 |
|
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in...
|
| CVE-2026-76605 |
|
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
|
| CVE-2026-76604 |
|
Code Injection in CVE-2026-76604 (CVE-2026-76604)
code injection in CVE-2026-76604 (CVE-2026-76604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71513 |
|
Unsafe Deserialization in CVE-2026-71513 (CVE-2026-71513)
vulnerability in CVE-2026-71513 (CVE-2026-71513). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49849 |
|
Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27462 |
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, lead...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on multiple factors in the reset password mechanism, leading to user enumeration. This issue has been fixed in version 3.2.3.
|
| CVE-2026-41449 |
|
OS Command Injection in CVE-2026-41449 (CVE-2026-41449)
OS command injection in CVE-2026-41449 (CVE-2026-41449). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39909 |
|
Use-After-Free in cpp (CVE-2026-39909)
vulnerability in cpp (CVE-2026-39909). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50112 |
|
OS Command Injection in apache (CVE-2026-50112)
OS command injection in apache (CVE-2026-50112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77645 |
|
Vulnerability in deserialization (CVE-2026-77645)
vulnerability in deserialization (CVE-2026-77645). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69242 |
|
Vulnerability in c (CVE-2026-69242)
vulnerability in c (CVE-2026-69242). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54245 |
|
SQL Injection in github.com/fleetdm/fleet (CVE-2026-54245)
SQL injection in github.com/fleetdm/fleet (CVE-2026-54245). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.86.2` or later.
|
| CVE-2026-2334 |
|
Unrestricted File Upload in CVE-2026-2334 (CVE-2026-2334)
vulnerability in CVE-2026-2334 (CVE-2026-2334). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18306 |
|
Vulnerability in CVE-2026-18306 (CVE-2026-18306)
vulnerability in CVE-2026-18306 (CVE-2026-18306). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18301 |
|
Vulnerability in CVE-2026-18301 (CVE-2026-18301)
vulnerability in CVE-2026-18301 (CVE-2026-18301). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18304 |
|
Vulnerability in CVE-2026-18304 (CVE-2026-18304)
vulnerability in CVE-2026-18304 (CVE-2026-18304). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18302 |
|
Vulnerability in CVE-2026-18302 (CVE-2026-18302)
vulnerability in CVE-2026-18302 (CVE-2026-18302). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18307 |
|
Vulnerability in CVE-2026-18307 (CVE-2026-18307)
vulnerability in CVE-2026-18307 (CVE-2026-18307). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18303 |
|
Vulnerability in CVE-2026-18303 (CVE-2026-18303)
vulnerability in CVE-2026-18303 (CVE-2026-18303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18305 |
|
Vulnerability in CVE-2026-18305 (CVE-2026-18305)
vulnerability in CVE-2026-18305 (CVE-2026-18305). Successful exploitation can lead to full system takeover.
|