Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82333 |
|
Vulnerability in dos (CVE-2026-82333)
vulnerability in dos (CVE-2026-82333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77078 |
|
Vulnerability in dos (CVE-2026-77078)
vulnerability in dos (CVE-2026-77078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77037 |
|
Vulnerability in dos (CVE-2026-77037)
vulnerability in dos (CVE-2026-77037). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55215 |
|
Vulnerability in mariadb (CVE-2026-55215)
vulnerability in mariadb (CVE-2026-55215). Confidential information can be exposed externally. Mitigation: upgrade to `3.2.4` or later.
|
| CVE-2026-6286 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47666 |
|
Cross-Site Scripting (XSS) in CVE-2026-47666 (CVE-2026-47666)
cross-site scripting in CVE-2026-47666 (CVE-2026-47666). Confidential information can be exposed externally.
|
| CVE-2026-80348 |
|
Vulnerability in CVE-2026-80348 (CVE-2026-80348)
vulnerability in CVE-2026-80348 (CVE-2026-80348). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81031 |
|
Vulnerability in CVE-2026-81031 (CVE-2026-81031)
vulnerability in CVE-2026-81031 (CVE-2026-81031). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18331 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18331)
cross-site scripting in wordpress (CVE-2026-18331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19760 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19760)
cross-site scripting in wordpress (CVE-2026-19760). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-74932 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-74932)
cross-site scripting in wordpress (CVE-2026-74932). Successful exploitation can lead to full system takeover. Exploitable via `Host header`.
|
| CVE-2026-55609 |
|
Vulnerability in consciousness-explorer (CVE-2026-55609)
vulnerability in consciousness-explorer (CVE-2026-55609). Data can be tampered with by attackers. Exploitable via ``export_state``. Mitigation: upgrade to `1.1.2` or later.
|
| CVE-2026-55553 |
|
Information Disclosure in urllib (CVE-2026-55553)
vulnerability in urllib (CVE-2026-55553). Confidential information can be exposed externally. Exploitable via `Cookie header`. Mitigation: upgrade to `2.44.1` or later.
|
| CVE-2026-16231 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-16231)
cross-site scripting in express (CVE-2026-16231). Confidential information can be exposed externally. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2026-16601 |
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
| CVE-2026-78637 |
|
Vulnerability in CVE-2026-78637 (CVE-2026-78637)
vulnerability in CVE-2026-78637 (CVE-2026-78637). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77384 |
|
Vulnerability in dos (CVE-2026-77384)
vulnerability in dos (CVE-2026-77384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78414 |
|
Cross-Site Scripting (XSS) in CVE-2026-78414 (CVE-2026-78414)
cross-site scripting in CVE-2026-78414 (CVE-2026-78414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39915 |
|
Vulnerability in CVE-2026-39915 (CVE-2026-39915)
vulnerability in CVE-2026-39915 (CVE-2026-39915). Confidential information can be exposed externally.
|
| CVE-2026-76842 |
|
Path Traversal in CVE-2026-76842 (CVE-2026-76842)
path traversal in CVE-2026-76842 (CVE-2026-76842). Confidential information can be exposed externally.
|
| CVE-2026-76172 |
|
Vulnerability in CVE-2026-76172 (CVE-2026-76172)
vulnerability in CVE-2026-76172 (CVE-2026-76172). Data can be tampered with by attackers. Mitigation: upgrade to `2.4.5` or later.
|
| CVE-2026-75931 |
|
Vulnerability in CVE-2026-75931 (CVE-2026-75931)
vulnerability in CVE-2026-75931 (CVE-2026-75931). Data can be tampered with by attackers. Mitigation: upgrade to `2.4.5` or later.
|
| CVE-2026-75975 |
|
Vulnerability in CVE-2026-75975 (CVE-2026-75975)
vulnerability in CVE-2026-75975 (CVE-2026-75975). Data can be tampered with by attackers. Mitigation: upgrade to `2.4.5` or later.
|
| CVE-2026-75899 |
|
Vulnerability in CVE-2026-75899 (CVE-2026-75899)
vulnerability in CVE-2026-75899 (CVE-2026-75899). Data can be tampered with by attackers. Mitigation: upgrade to `2.4.5` or later.
|
| CVE-2026-78213 |
|
Cross-Site Scripting (XSS) in CVE-2026-78213 (CVE-2026-78213)
cross-site scripting in CVE-2026-78213 (CVE-2026-78213). Confidential information can be exposed externally.
|
| CVE-2026-78178 |
|
Code Injection in CVE-2026-78178 (CVE-2026-78178)
code injection in CVE-2026-78178 (CVE-2026-78178). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78208 |
|
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
|
| CVE-2026-78209 |
|
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
|
| CVE-2026-78206 |
|
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory...
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory...
|
| CVE-2026-4671 |
|
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
|
| CVE-2026-76789 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76789)
cross-site scripting in wordpress (CVE-2026-76789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77811 |
|
Cross-Site Scripting (XSS) in Amazon aws (CVE-2026-77811)
cross-site scripting in Amazon aws (CVE-2026-77811). Confidential information can be exposed externally.
|
| CVE-2026-63135 |
|
Cross-Site Scripting (XSS) in yourls/yourls (CVE-2026-63135)
cross-site scripting in yourls/yourls (CVE-2026-63135). Data can be tampered with by attackers. Exploitable via `Referer header`. Mitigation: upgrade to `1.10.4` or later.
|
| CVE-2026-63421 |
|
Vulnerability in @keystone-6/core (CVE-2026-63421)
vulnerability in @keystone-6/core (CVE-2026-63421). Risk of unauthorized operations or information disclosure. Exploitable via ``graphql.maxTake``. Mitigation: upgrade to `6.5.3` or later.
|
| CVE-2026-61824 |
|
Cross-Site Scripting (XSS) in defuddle (CVE-2026-61824)
cross-site scripting in defuddle (CVE-2026-61824). Confidential information can be exposed externally. Mitigation: upgrade to `0.19.1` or later.
|
| CVE-2026-75933 |
|
Cross-Site Scripting (XSS) in CVE-2026-75933 (CVE-2026-75933)
cross-site scripting in CVE-2026-75933 (CVE-2026-75933). Confidential information can be exposed externally.
|
| CVE-2026-18409 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18409)
cross-site scripting in wordpress (CVE-2026-18409). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72860 |
|
Vulnerability in CVE-2026-72860 (CVE-2026-72860)
vulnerability in CVE-2026-72860 (CVE-2026-72860). Confidential information can be exposed externally. Exploitable via `POST /api/provider-nodes/validate`.
|
| CVE-2026-49436 |
|
Cross-Site Scripting (XSS) in CVE-2026-49436 (CVE-2026-49436)
cross-site scripting in CVE-2026-49436 (CVE-2026-49436). Confidential information can be exposed externally. Exploitable via `POST /api/v2/bulk/links`.
|
| CVE-2026-61704 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61704)
SSRF in ssrf (CVE-2026-61704). Confidential information can be exposed externally.
|
| CVE-2026-76833 |
|
Vulnerability in CVE-2026-76833 (CVE-2026-76833)
vulnerability in CVE-2026-76833 (CVE-2026-76833). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76333 |
|
Cross-Site Scripting (XSS) in splunk (CVE-2026-76333)
cross-site scripting in splunk (CVE-2026-76333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76325 |
|
Cross-Site Scripting (XSS) in splunk (CVE-2026-76325)
cross-site scripting in splunk (CVE-2026-76325). Confidential information can be exposed externally.
|
| CVE-2026-69222 |
|
Vulnerability in CVE-2026-69222 (CVE-2026-69222)
vulnerability in CVE-2026-69222 (CVE-2026-69222). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68899 |
|
Unrestricted File Upload in CVE-2026-68899 (CVE-2026-68899)
vulnerability in CVE-2026-68899 (CVE-2026-68899). Confidential information can be exposed externally.
|
| CVE-2026-68900 |
|
Cross-Site Scripting (XSS) in CVE-2026-68900 (CVE-2026-68900)
cross-site scripting in CVE-2026-68900 (CVE-2026-68900). Confidential information can be exposed externally.
|
| CVE-2026-68561 |
|
Privilege Escalation in CVE-2026-68561 (CVE-2026-68561)
vulnerability in CVE-2026-68561 (CVE-2026-68561). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68558 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-68558 (CVE-2026-68558)
SSRF in CVE-2026-68558 (CVE-2026-68558). Confidential information can be exposed externally.
|
| CVE-2026-62680 |
|
Path Traversal in CVE-2026-62680 (CVE-2026-62680)
path traversal in CVE-2026-62680 (CVE-2026-62680). Confidential information can be exposed externally.
|
| CVE-2026-63407 |
|
Vulnerability in CVE-2026-63407 (CVE-2026-63407)
vulnerability in CVE-2026-63407 (CVE-2026-63407). Confidential information can be exposed externally.
|