Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19286 |
|
Code Injection in CVE-2026-19286 (CVE-2026-19286)
code injection in CVE-2026-19286 (CVE-2026-19286). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18729 |
|
Code Injection in CVE-2026-18729 (CVE-2026-18729)
code injection in CVE-2026-18729 (CVE-2026-18729). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-77939 |
|
Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
|
| CVE-2026-55634 |
|
SQL Injection in pimcore/pimcore (CVE-2026-55634)
SQL injection in pimcore/pimcore (CVE-2026-55634). Successful exploitation can lead to full system takeover. Exploitable via ``objects``. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-55565 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55565)
code injection in org.yamcs:yamcs-core (CVE-2026-55565). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55559 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55559)
code injection in org.yamcs:yamcs-core (CVE-2026-55559). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/instances`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-55511 |
|
Code Injection in org.yamcs:yamcs-core (CVE-2026-55511)
code injection in org.yamcs:yamcs-core (CVE-2026-55511). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
|
| CVE-2026-82244 |
|
Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81835 |
|
Vulnerability in CVE-2026-81835 (CVE-2026-81835)
vulnerability in CVE-2026-81835 (CVE-2026-81835). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81834 |
|
Vulnerability in CVE-2026-81834 (CVE-2026-81834)
vulnerability in CVE-2026-81834 (CVE-2026-81834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81833 |
|
Vulnerability in CVE-2026-81833 (CVE-2026-81833)
vulnerability in CVE-2026-81833 (CVE-2026-81833). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6876 |
|
Code Injection in CVE-2026-6876 (CVE-2026-6876)
code injection in CVE-2026-6876 (CVE-2026-6876). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53579 |
|
Cross-Site Scripting (XSS) in CVE-2026-53579 (CVE-2026-53579)
cross-site scripting in CVE-2026-53579 (CVE-2026-53579). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53578 |
|
Cross-Site Scripting (XSS) in CVE-2026-53578 (CVE-2026-53578)
cross-site scripting in CVE-2026-53578 (CVE-2026-53578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48996 |
|
Cross-Site Scripting (XSS) in CVE-2026-48996 (CVE-2026-48996)
cross-site scripting in CVE-2026-48996 (CVE-2026-48996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47727 |
|
Code Injection in CVE-2026-47727 (CVE-2026-47727)
code injection in CVE-2026-47727 (CVE-2026-47727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18885 |
|
Code Injection in CVE-2026-18885 (CVE-2026-18885)
code injection in CVE-2026-18885 (CVE-2026-18885). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81719 |
|
Code Injection in CVE-2026-81719 (CVE-2026-81719)
code injection in CVE-2026-81719 (CVE-2026-81719). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.4.9` or later.
|
| CVE-2026-81096 |
|
Code Injection in CVE-2026-81096 (CVE-2026-81096)
code injection in CVE-2026-81096 (CVE-2026-81096). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54721 |
|
Code Injection in silverstripe/userforms (CVE-2026-54721)
code injection in silverstripe/userforms (CVE-2026-54721). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.1.1` or later.
|
| CVE-2026-81743 |
|
Path Traversal in CVE-2026-81743 (CVE-2026-81743)
path traversal in CVE-2026-81743 (CVE-2026-81743). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81662 |
|
Vulnerability in CVE-2026-81662 (CVE-2026-81662)
vulnerability in CVE-2026-81662 (CVE-2026-81662). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19225 |
|
Code Injection in wordpress (CVE-2026-19225)
code injection in wordpress (CVE-2026-19225). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19223 |
|
Code Injection in wordpress (CVE-2026-19223)
code injection in wordpress (CVE-2026-19223). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47852 |
|
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
|
| CVE-2026-58474 |
|
Code Injection in CVE-2026-58474 (CVE-2026-58474)
code injection in CVE-2026-58474 (CVE-2026-58474). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74851 |
|
Code Injection in wordpress (CVE-2026-74851)
code injection in wordpress (CVE-2026-74851). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80201 |
|
Code Injection in CVE-2026-80201 (CVE-2026-80201)
code injection in CVE-2026-80201 (CVE-2026-80201). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76148 |
|
Code Injection in CVE-2026-76148 (CVE-2026-76148)
code injection in CVE-2026-76148 (CVE-2026-76148). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57170 |
|
Code Injection in CVE-2026-57170 (CVE-2026-57170)
code injection in CVE-2026-57170 (CVE-2026-57170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54757 |
|
Code Injection in compliance-trestle (CVE-2026-54757)
code injection in compliance-trestle (CVE-2026-54757). Successful exploitation can lead to full system takeover. Exploitable via ``SandboxedEnvironment``. Mitigation: upgrade to `4.1.0` or later.
|
| CVE-2026-79793 |
|
Cross-Site Scripting (XSS) in CVE-2026-79793 (CVE-2026-79793)
cross-site scripting in CVE-2026-79793 (CVE-2026-79793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79249 |
|
Code Injection in google (CVE-2026-79249)
code injection in google (CVE-2026-79249). Confidential information can be exposed externally.
|
| CVE-2026-65082 |
|
Code Injection in dos (CVE-2026-65082)
code injection in dos (CVE-2026-65082). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55585 |
|
Code Injection in qwed (CVE-2026-55585)
code injection in qwed (CVE-2026-55585). Successful exploitation can lead to full system takeover. Exploitable via `POST /verify/math`. Mitigation: upgrade to `5.1.2` or later.
|
| CVE-2026-55546 |
|
Code Injection in qwed-mcp (CVE-2026-55546)
code injection in qwed-mcp (CVE-2026-55546). Successful exploitation can lead to full system takeover. Exploitable via ``global_dict``. Mitigation: upgrade to `0.2.1` or later.
|
| CVE-2026-57909 |
|
Code Injection in path-traversal (CVE-2026-57909)
code injection in path-traversal (CVE-2026-57909). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49845 |
|
Code Injection in apache (CVE-2026-49845)
code injection in apache (CVE-2026-49845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78654 |
|
Code Injection in CVE-2026-78654 (CVE-2026-78654)
code injection in CVE-2026-78654 (CVE-2026-78654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56703 |
|
Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60004 KEV |
|
[KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-52490 |
|
Code Injection in c (CVE-2026-52490)
code injection in c (CVE-2026-52490). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39975 |
|
Code Injection in CVE-2026-39975 (CVE-2026-39975)
code injection in CVE-2026-39975 (CVE-2026-39975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2025-26238 |
|
Code Injection in CVE-2025-26238 (CVE-2025-26238)
code injection in CVE-2025-26238 (CVE-2025-26238). Confidential information can be exposed externally.
|
| CVE-2026-76836 |
|
Code Injection in CVE-2026-76836 (CVE-2026-76836)
code injection in CVE-2026-76836 (CVE-2026-76836). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/station/{station_id}/profile/edit`.
|
| CVE-2026-78367 |
|
Code Injection in CVE-2026-78367 (CVE-2026-78367)
code injection in CVE-2026-78367 (CVE-2026-78367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76841 |
|
Code Injection in CVE-2026-76841 (CVE-2026-76841)
code injection in CVE-2026-76841 (CVE-2026-76841). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78187 |
|
Cross-Site Scripting (XSS) in CVE-2026-78187 (CVE-2026-78187)
cross-site scripting in CVE-2026-78187 (CVE-2026-78187). Risk of unauthorized operations or information disclosure.
|