Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-68959 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-69665 |
|
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
|
| CVE-2026-68062 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-12561 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12561)
cross-site scripting in wordpress (CVE-2026-12561). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78470 |
|
SQL Injection in wordpress (CVE-2026-78470)
SQL injection in wordpress (CVE-2026-78470). Confidential information can be exposed externally.
|
| CVE-2026-78638 |
|
Path Traversal in path-traversal (CVE-2026-78638)
path traversal in path-traversal (CVE-2026-78638). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78477 |
|
Vulnerability in wordpress (CVE-2026-78477)
vulnerability in wordpress (CVE-2026-78477). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13215 |
|
Out-of-Bounds Write in c (CVE-2026-13215)
out-of-bounds write in c (CVE-2026-13215). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13214 |
|
Out-of-Bounds Write in c (CVE-2026-13214)
out-of-bounds write in c (CVE-2026-13214). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76063 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76063)
cross-site scripting in wordpress (CVE-2026-76063). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19943 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19943)
cross-site scripting in wordpress (CVE-2026-19943). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19892 |
|
Vulnerability in wordpress (CVE-2026-19892)
vulnerability in wordpress (CVE-2026-19892). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17089 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17089)
cross-site scripting in wordpress (CVE-2026-17089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75019 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-75019)
cross-site scripting in wordpress (CVE-2026-75019). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-9878 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-9878)
cross-site scripting in wordpress (CVE-2025-9878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78685 |
|
Vulnerability in CVE-2026-78685 (CVE-2026-78685)
vulnerability in CVE-2026-78685 (CVE-2026-78685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78683 |
|
Unsafe Deserialization in deserialization (CVE-2026-78683)
vulnerability in deserialization (CVE-2026-78683). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-78681 |
|
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
|
| CVE-2026-78677 |
|
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
|
| CVE-2026-78680 |
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
| CVE-2026-78675 |
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
| CVE-2026-75574 |
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
| CVE-2026-76839 |
|
Vulnerability in CVE-2026-76839 (CVE-2026-76839)
vulnerability in CVE-2026-76839 (CVE-2026-76839). Confidential information can be exposed externally.
|
| CVE-2026-72697 |
|
Path Traversal in path-traversal (CVE-2026-72697)
path traversal in path-traversal (CVE-2026-72697). Confidential information can be exposed externally.
|
| CVE-2026-72695 |
|
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
|
| CVE-2026-72701 |
|
Vulnerability in csrf (CVE-2026-72701)
vulnerability in csrf (CVE-2026-72701). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72696 |
|
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
|
| CVE-2026-56706 |
|
Vulnerability in csrf (CVE-2026-56706)
vulnerability in csrf (CVE-2026-56706). Data can be tampered with by attackers.
|
| CVE-2026-56703 |
|
Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56705 |
|
Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56707 |
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
| CVE-2026-56702 |
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
| CVE-2026-34959 |
|
Vulnerability in CVE-2026-34959 (CVE-2026-34959)
vulnerability in CVE-2026-34959 (CVE-2026-34959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34967 |
|
Vulnerability in path-traversal (CVE-2026-34967)
vulnerability in path-traversal (CVE-2026-34967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34968 |
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
| CVE-2026-15023 |
|
SQL Injection in wordpress (CVE-2026-15023)
SQL injection in wordpress (CVE-2026-15023). Confidential information can be exposed externally.
|
| CVE-2026-66766 |
|
Vulnerability in dos (CVE-2026-66766)
vulnerability in dos (CVE-2026-66766). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54920 |
|
Vulnerability in dos (CVE-2026-54920)
vulnerability in dos (CVE-2026-54920). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55371 |
|
Vulnerability in c (CVE-2026-55371)
vulnerability in c (CVE-2026-55371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60004 KEV |
|
[KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-53532 |
|
Vulnerability in dos (CVE-2026-53532)
vulnerability in dos (CVE-2026-53532). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78435 |
|
Path Traversal in path-traversal (CVE-2026-78435)
path traversal in path-traversal (CVE-2026-78435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78282 |
|
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
|
| CVE-2026-78264 |
|
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
|
| CVE-2026-78263 |
|
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
|
| CVE-2026-78267 |
|
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
|
| CVE-2026-77337 |
|
Vulnerability in CVE-2026-77337 (CVE-2026-77337)
vulnerability in CVE-2026-77337 (CVE-2026-77337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68516 |
|
Vulnerability in dos (CVE-2026-68516)
vulnerability in dos (CVE-2026-68516). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77384 |
|
Vulnerability in dos (CVE-2026-77384)
vulnerability in dos (CVE-2026-77384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32561 |
|
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
|