Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-94 Clear
ID Title
CVE-2026-19286 Code Injection in CVE-2026-19286 (CVE-2026-19286)
code injection in CVE-2026-19286 (CVE-2026-19286). Successful exploitation can lead to full system takeover.
CVE-2026-18729 Code Injection in CVE-2026-18729 (CVE-2026-18729)
code injection in CVE-2026-18729 (CVE-2026-18729). Successful exploitation can lead to full system takeover.
CVE-2026-82278 Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
CVE-2026-77939 Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
CVE-2026-55634 SQL Injection in pimcore/pimcore (CVE-2026-55634)
SQL injection in pimcore/pimcore (CVE-2026-55634). Successful exploitation can lead to full system takeover. Exploitable via ``objects``. Mitigation: upgrade to `2026.1.6` or later.
CVE-2026-55565 Code Injection in org.yamcs:yamcs-core (CVE-2026-55565)
code injection in org.yamcs:yamcs-core (CVE-2026-55565). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
CVE-2026-55559 Code Injection in org.yamcs:yamcs-core (CVE-2026-55559)
code injection in org.yamcs:yamcs-core (CVE-2026-55559). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/instances`. Mitigation: upgrade to `5.12.8` or later.
CVE-2026-55511 Code Injection in org.yamcs:yamcs-core (CVE-2026-55511)
code injection in org.yamcs:yamcs-core (CVE-2026-55511). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
CVE-2026-82244 Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
CVE-2026-81835 Vulnerability in CVE-2026-81835 (CVE-2026-81835)
vulnerability in CVE-2026-81835 (CVE-2026-81835). Risk of unauthorized operations or information disclosure.
CVE-2026-81834 Vulnerability in CVE-2026-81834 (CVE-2026-81834)
vulnerability in CVE-2026-81834 (CVE-2026-81834). Risk of unauthorized operations or information disclosure.
CVE-2026-81833 Vulnerability in CVE-2026-81833 (CVE-2026-81833)
vulnerability in CVE-2026-81833 (CVE-2026-81833). Risk of unauthorized operations or information disclosure.
CVE-2026-6876 Code Injection in CVE-2026-6876 (CVE-2026-6876)
code injection in CVE-2026-6876 (CVE-2026-6876). Risk of unauthorized operations or information disclosure.
CVE-2026-53579 Cross-Site Scripting (XSS) in CVE-2026-53579 (CVE-2026-53579)
cross-site scripting in CVE-2026-53579 (CVE-2026-53579). Risk of unauthorized operations or information disclosure.
CVE-2026-53578 Cross-Site Scripting (XSS) in CVE-2026-53578 (CVE-2026-53578)
cross-site scripting in CVE-2026-53578 (CVE-2026-53578). Risk of unauthorized operations or information disclosure.
CVE-2026-48996 Cross-Site Scripting (XSS) in CVE-2026-48996 (CVE-2026-48996)
cross-site scripting in CVE-2026-48996 (CVE-2026-48996). Risk of unauthorized operations or information disclosure.
CVE-2026-47727 Code Injection in CVE-2026-47727 (CVE-2026-47727)
code injection in CVE-2026-47727 (CVE-2026-47727). Risk of unauthorized operations or information disclosure.
CVE-2026-18885 Code Injection in CVE-2026-18885 (CVE-2026-18885)
code injection in CVE-2026-18885 (CVE-2026-18885). Risk of unauthorized operations or information disclosure.
CVE-2026-81719 Code Injection in CVE-2026-81719 (CVE-2026-81719)
code injection in CVE-2026-81719 (CVE-2026-81719). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.4.9` or later.
CVE-2026-81096 Code Injection in CVE-2026-81096 (CVE-2026-81096)
code injection in CVE-2026-81096 (CVE-2026-81096). Successful exploitation can lead to full system takeover.
CVE-2026-54721 Code Injection in silverstripe/userforms (CVE-2026-54721)
code injection in silverstripe/userforms (CVE-2026-54721). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.1` or later.
CVE-2026-81743 Path Traversal in CVE-2026-81743 (CVE-2026-81743)
path traversal in CVE-2026-81743 (CVE-2026-81743). Risk of unauthorized operations or information disclosure.
CVE-2026-81662 Vulnerability in CVE-2026-81662 (CVE-2026-81662)
vulnerability in CVE-2026-81662 (CVE-2026-81662). Risk of unauthorized operations or information disclosure.
CVE-2026-19225 Code Injection in wordpress (CVE-2026-19225)
code injection in wordpress (CVE-2026-19225). Successful exploitation can lead to full system takeover.
CVE-2026-19223 Code Injection in wordpress (CVE-2026-19223)
code injection in wordpress (CVE-2026-19223). Successful exploitation can lead to full system takeover.
CVE-2026-47852 A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
CVE-2026-58474 Code Injection in CVE-2026-58474 (CVE-2026-58474)
code injection in CVE-2026-58474 (CVE-2026-58474). Successful exploitation can lead to full system takeover.
CVE-2026-74851 Code Injection in wordpress (CVE-2026-74851)
code injection in wordpress (CVE-2026-74851). Successful exploitation can lead to full system takeover.
CVE-2026-80201 Code Injection in CVE-2026-80201 (CVE-2026-80201)
code injection in CVE-2026-80201 (CVE-2026-80201). Risk of unauthorized operations or information disclosure.
CVE-2026-76148 Code Injection in CVE-2026-76148 (CVE-2026-76148)
code injection in CVE-2026-76148 (CVE-2026-76148). Successful exploitation can lead to full system takeover.
CVE-2026-57170 Code Injection in CVE-2026-57170 (CVE-2026-57170)
code injection in CVE-2026-57170 (CVE-2026-57170). Successful exploitation can lead to full system takeover.
CVE-2026-54757 Code Injection in compliance-trestle (CVE-2026-54757)
code injection in compliance-trestle (CVE-2026-54757). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxedEnvironment``. Mitigation: upgrade to `4.1.0` or later.
CVE-2026-79793 Cross-Site Scripting (XSS) in CVE-2026-79793 (CVE-2026-79793)
cross-site scripting in CVE-2026-79793 (CVE-2026-79793). Risk of unauthorized operations or information disclosure.
CVE-2026-79249 Code Injection in google (CVE-2026-79249)
code injection in google (CVE-2026-79249). Confidential information can be exposed externally.
CVE-2026-65082 Code Injection in dos (CVE-2026-65082)
code injection in dos (CVE-2026-65082). Successful exploitation can lead to full system takeover.
CVE-2026-55585 Code Injection in qwed (CVE-2026-55585)
code injection in qwed (CVE-2026-55585). Successful exploitation can lead to full system takeover. Exploitable via `POST /verify/math`. Mitigation: upgrade to `5.1.2` or later.
CVE-2026-55546 Code Injection in qwed-mcp (CVE-2026-55546)
code injection in qwed-mcp (CVE-2026-55546). Successful exploitation can lead to full system takeover. Exploitable via ``global_dict``. Mitigation: upgrade to `0.2.1` or later.
CVE-2026-57909 Code Injection in path-traversal (CVE-2026-57909)
code injection in path-traversal (CVE-2026-57909). Risk of unauthorized operations or information disclosure.
CVE-2026-49845 Code Injection in apache (CVE-2026-49845)
code injection in apache (CVE-2026-49845). Successful exploitation can lead to full system takeover.
CVE-2026-78654 Code Injection in CVE-2026-78654 (CVE-2026-78654)
code injection in CVE-2026-78654 (CVE-2026-78654). Risk of unauthorized operations or information disclosure.
CVE-2026-56703 Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
CVE-2026-60004 KEV [KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-52490 Code Injection in c (CVE-2026-52490)
code injection in c (CVE-2026-52490). Successful exploitation can lead to full system takeover.
CVE-2026-39975 Code Injection in CVE-2026-39975 (CVE-2026-39975)
code injection in CVE-2026-39975 (CVE-2026-39975). Risk of unauthorized operations or information disclosure.
CVE-2026-40877 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
CVE-2025-26238 Code Injection in CVE-2025-26238 (CVE-2025-26238)
code injection in CVE-2025-26238 (CVE-2025-26238). Confidential information can be exposed externally.
CVE-2026-76836 Code Injection in CVE-2026-76836 (CVE-2026-76836)
code injection in CVE-2026-76836 (CVE-2026-76836). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/station/{station_id}/profile/edit`.
CVE-2026-78367 Code Injection in CVE-2026-78367 (CVE-2026-78367)
code injection in CVE-2026-78367 (CVE-2026-78367). Successful exploitation can lead to full system takeover.
CVE-2026-76841 Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
CVE-2026-78187 Cross-Site Scripting (XSS) in CVE-2026-78187 (CVE-2026-78187)
cross-site scripting in CVE-2026-78187 (CVE-2026-78187). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →