Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73617 |
|
Vulnerability in CVE-2026-73617 (CVE-2026-73617)
vulnerability in CVE-2026-73617 (CVE-2026-73617). Confidential information can be exposed externally.
|
| CVE-2026-73628 |
|
Cross-Site Scripting (XSS) in CVE-2026-73628 (CVE-2026-73628)
cross-site scripting in CVE-2026-73628 (CVE-2026-73628). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2026-73602 |
|
Vulnerability in path-traversal (CVE-2026-73602)
vulnerability in path-traversal (CVE-2026-73602). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73483 |
|
OS Command Injection in CVE-2026-73483 (CVE-2026-73483)
OS command injection in CVE-2026-73483 (CVE-2026-73483). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-19484 |
|
Vulnerability in CVE-2026-19484 (CVE-2026-19484)
vulnerability in CVE-2026-19484 (CVE-2026-19484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19481 |
|
Vulnerability in dos (CVE-2026-19481)
vulnerability in dos (CVE-2026-19481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73492 |
|
Cross-Site Scripting (XSS) in CVE-2026-73492 (CVE-2026-73492)
cross-site scripting in CVE-2026-73492 (CVE-2026-73492). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73329 |
|
Cross-Site Scripting (XSS) in CVE-2026-73329 (CVE-2026-73329)
cross-site scripting in CVE-2026-73329 (CVE-2026-73329). Confidential information can be exposed externally.
|
| CVE-2026-72787 |
|
Cross-Site Scripting (XSS) in CVE-2026-72787 (CVE-2026-72787)
cross-site scripting in CVE-2026-72787 (CVE-2026-72787). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49466 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-49466)
cross-site scripting in wordpress (CVE-2026-49466). Risk of unauthorized operations or information disclosure. Exploitable via ``template``.
|
| CVE-2026-19657 |
|
Cross-Site Scripting (XSS) in scada-lts (CVE-2026-19657)
cross-site scripting in scada-lts (CVE-2026-19657). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48552 |
|
Cross-Site Scripting (XSS) in CVE-2026-48552 (CVE-2026-48552)
cross-site scripting in CVE-2026-48552 (CVE-2026-48552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48550 |
|
Cross-Site Scripting (XSS) in CVE-2026-48550 (CVE-2026-48550)
cross-site scripting in CVE-2026-48550 (CVE-2026-48550). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16694 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2026-16694)
cross-site scripting in ibm (CVE-2026-16694). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73299 |
|
Code Injection in CVE-2026-73299 (CVE-2026-73299)
code injection in CVE-2026-73299 (CVE-2026-73299). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49467 |
|
Vulnerability in CVE-2026-49467 (CVE-2026-49467)
vulnerability in CVE-2026-49467 (CVE-2026-49467). Successful exploitation can lead to full system takeover. Exploitable via ``await``.
|
| CVE-2026-73295 |
|
Cross-Site Scripting (XSS) in CVE-2026-73295 (CVE-2026-73295)
cross-site scripting in CVE-2026-73295 (CVE-2026-73295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73374 |
|
Cross-Site Scripting (XSS) in CVE-2026-73374 (CVE-2026-73374)
cross-site scripting in CVE-2026-73374 (CVE-2026-73374). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73291 |
|
Path Traversal in CVE-2026-73291 (CVE-2026-73291)
path traversal in CVE-2026-73291 (CVE-2026-73291). Data can be tampered with by attackers. Exploitable via `GET /avatarproxy/`.
|
| CVE-2026-73262 |
|
Cross-Site Scripting (XSS) in CVE-2026-73262 (CVE-2026-73262)
cross-site scripting in CVE-2026-73262 (CVE-2026-73262). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45694 |
|
Cross-Site Scripting (XSS) in librenms/librenms (CVE-2026-45694)
cross-site scripting in librenms/librenms (CVE-2026-45694). Risk of unauthorized operations or information disclosure. Exploitable via ``document.title``. Mitigation: upgrade to `26.5.0` or later.
|
| CVE-2026-57858 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-57858)
cross-site scripting in csrf (CVE-2026-57858). Confidential information can be exposed externally.
|
| CVE-2026-9318 |
|
Cross-Site Scripting (XSS) in tablib (CVE-2026-9318)
cross-site scripting in tablib (CVE-2026-9318). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-66832 |
|
Vulnerability in CVE-2026-66832 (CVE-2026-66832)
vulnerability in CVE-2026-66832 (CVE-2026-66832). Confidential information can be exposed externally. Exploitable via `User-Agent header`.
|
| CVE-2026-73231 |
|
Vulnerability in CVE-2026-73231 (CVE-2026-73231)
vulnerability in CVE-2026-73231 (CVE-2026-73231). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73031 |
|
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
|
| CVE-2026-73032 |
|
Code Injection in CVE-2026-73032 (CVE-2026-73032)
code injection in CVE-2026-73032 (CVE-2026-73032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66146 |
|
Cross-Site Scripting (XSS) in CVE-2026-66146 (CVE-2026-66146)
cross-site scripting in CVE-2026-66146 (CVE-2026-66146). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73224 |
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user do...
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder and invokes Properties and Calculate Size because calcLocal in src/client/c...
|
| CVE-2026-73227 |
|
Path Traversal in CVE-2026-73227 (CVE-2026-73227)
path traversal in CVE-2026-73227 (CVE-2026-73227). Data can be tampered with by attackers.
|
| CVE-2026-73226 |
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions t...
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values in upgrade-func in src/app/server/dispatch-center.js and handle...
|
| CVE-2026-73222 |
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
| CVE-2026-18708 |
|
Code Injection in dos (CVE-2026-18708)
code injection in dos (CVE-2026-18708). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21269 |
|
Cross-Site Scripting (XSS) in adobe (CVE-2026-21269)
cross-site scripting in adobe (CVE-2026-21269). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48413 |
|
Cross-Site Scripting (XSS) in CVE-2026-48413 (CVE-2026-48413)
cross-site scripting in CVE-2026-48413 (CVE-2026-48413). Confidential information can be exposed externally.
|
| CVE-2026-48414 |
|
Cross-Site Scripting (XSS) in CVE-2026-48414 (CVE-2026-48414)
cross-site scripting in CVE-2026-48414 (CVE-2026-48414). Confidential information can be exposed externally.
|
| CVE-2026-73089 |
|
Vulnerability in CVE-2026-73089 (CVE-2026-73089)
vulnerability in CVE-2026-73089 (CVE-2026-73089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73083 |
|
Vulnerability in CVE-2026-73083 (CVE-2026-73083)
vulnerability in CVE-2026-73083 (CVE-2026-73083). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73086 |
|
Vulnerability in csrf (CVE-2026-73086)
vulnerability in csrf (CVE-2026-73086). Confidential information can be exposed externally.
|
| CVE-2026-73085 |
|
Authentication Bypass in CVE-2026-73085 (CVE-2026-73085)
authentication bypass in CVE-2026-73085 (CVE-2026-73085). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73084 |
|
Cross-Site Scripting (XSS) in CVE-2026-73084 (CVE-2026-73084)
cross-site scripting in CVE-2026-73084 (CVE-2026-73084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73088 |
|
Vulnerability in CVE-2026-73088 (CVE-2026-73088)
vulnerability in CVE-2026-73088 (CVE-2026-73088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72925 |
|
Cross-Site Scripting (XSS) in CVE-2026-72925 (CVE-2026-72925)
cross-site scripting in CVE-2026-72925 (CVE-2026-72925). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19434 |
|
Cross-Site Scripting (XSS) in CVE-2026-19434 (CVE-2026-19434)
cross-site scripting in CVE-2026-19434 (CVE-2026-19434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72764 |
|
Vulnerability in CVE-2026-72764 (CVE-2026-72764)
vulnerability in CVE-2026-72764 (CVE-2026-72764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72749 |
|
Vulnerability in dos (CVE-2026-72749)
vulnerability in dos (CVE-2026-72749). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72747 |
|
Cross-Site Scripting (XSS) in CVE-2026-72747 (CVE-2026-72747)
cross-site scripting in CVE-2026-72747 (CVE-2026-72747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72559 |
|
Cross-Site Scripting (XSS) in CVE-2026-72559 (CVE-2026-72559)
cross-site scripting in CVE-2026-72559 (CVE-2026-72559). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72553 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2026-72553)
cross-site scripting in privilege-escalation (CVE-2026-72553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19418 |
|
Vulnerability in CVE-2026-19418 (CVE-2026-19418)
vulnerability in CVE-2026-19418 (CVE-2026-19418). Risk of unauthorized operations or information disclosure.
|