Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-56037 |
|
Unsafe Deserialization in deserialization (CVE-2026-56037)
vulnerability in deserialization (CVE-2026-56037). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69094 |
|
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
|
| CVE-2025-69152 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-69152)
cross-site scripting in wordpress (CVE-2025-69152). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14449 |
|
Cross-Site Scripting (XSS) in CVE-2026-14449 (CVE-2026-14449)
cross-site scripting in CVE-2026-14449 (CVE-2026-14449). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69153 |
|
Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
|
| CVE-2025-69154 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-69154)
cross-site scripting in wordpress (CVE-2025-69154). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69155 |
|
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
|
| CVE-2025-69156 |
|
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
|
| CVE-2026-9834 |
|
Command Injection in wordpress (CVE-2026-9834)
command injection in wordpress (CVE-2026-9834). Successful exploitation can lead to full system takeover. Exploitable via ``wp_db_exclude_table``.
|
| CVE-2026-14029 |
|
SQL Injection in wordpress (CVE-2026-14029)
SQL injection in wordpress (CVE-2026-14029). Confidential information can be exposed externally.
|
| CVE-2026-8441 |
|
SQL Injection in wordpress (CVE-2026-8441)
SQL injection in wordpress (CVE-2026-8441). Confidential information can be exposed externally.
|
| CVE-2026-13252 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13252)
cross-site scripting in wordpress (CVE-2026-13252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13251 |
|
Path Traversal in wordpress (CVE-2026-13251)
path traversal in wordpress (CVE-2026-13251). Confidential information can be exposed externally.
|
| CVE-2026-10104 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10104)
cross-site scripting in wordpress (CVE-2026-10104). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9563 |
|
Vulnerability in dos (CVE-2026-9563)
vulnerability in dos (CVE-2026-9563). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5821 |
|
Vulnerability in wordpress (CVE-2026-5821)
vulnerability in wordpress (CVE-2026-5821). Data can be tampered with by attackers.
|
| CVE-2026-13357 |
|
SQL Injection in wordpress (CVE-2026-13357)
SQL injection in wordpress (CVE-2026-13357). Confidential information can be exposed externally.
|
| CVE-2026-13704 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13704)
cross-site scripting in wordpress (CVE-2026-13704). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10077 |
|
Vulnerability in wordpress (CVE-2026-10077)
vulnerability in wordpress (CVE-2026-10077). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10089 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10089)
cross-site scripting in wordpress (CVE-2026-10089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57277 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-57278 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-57274 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-57276 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-57275 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-57271 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-57272 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-57273 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-13125 |
|
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud)...
|
| CVE-2026-14439 |
|
Path Traversal in path-traversal (CVE-2026-14439)
path traversal in path-traversal (CVE-2026-14439). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.1.1` or later.
|
| CVE-2026-52186 |
|
SQL Injection in sqli (CVE-2026-52186)
SQL injection in sqli (CVE-2026-52186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-36909 |
|
Vulnerability in dos (CVE-2026-36909)
vulnerability in dos (CVE-2026-36909). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52190 |
|
Vulnerability in dos (CVE-2026-52190)
vulnerability in dos (CVE-2026-52190). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36912 |
|
Vulnerability in dos (CVE-2026-36912)
vulnerability in dos (CVE-2026-36912). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36910 |
|
Buffer Overflow in dos (CVE-2026-36910)
vulnerability in dos (CVE-2026-36910). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-36911 |
|
Vulnerability in dos (CVE-2026-36911)
vulnerability in dos (CVE-2026-36911). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38891 |
|
Vulnerability in cpp (CVE-2026-38891)
vulnerability in cpp (CVE-2026-38891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55794 |
|
Code Injection in craftcms/cms (CVE-2026-55794)
code injection in craftcms/cms (CVE-2026-55794). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.10.0` or later.
|
| CVE-2026-54712 |
|
Vulnerability in io.opentelemetry.javaagent:opentelemetry-javaagent (CVE-2026-54712)
vulnerability in io.opentelemetry.javaagent:opentelemetry-javaagent (CVE-2026-54712). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.27.0` or later.
|
| CVE-2026-54263 |
|
Cross-Site Scripting (XSS) in wagtail (CVE-2026-54263)
cross-site scripting in wagtail (CVE-2026-54263). Confidential information can be exposed externally. Mitigation: upgrade to `7.4.2` or later.
|
| CVE-2026-14363 |
|
SQL Injection in sqli (CVE-2026-14363)
SQL injection in sqli (CVE-2026-14363). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58451 |
|
Path Traversal in csrf (CVE-2026-58451)
path traversal in csrf (CVE-2026-58451). Confidential information can be exposed externally.
|
| CVE-2026-58517 |
|
Vulnerability in mediawiki (CVE-2026-58517)
vulnerability in mediawiki (CVE-2026-58517). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49119 |
|
Path Traversal in gradio (CVE-2026-49119)
path traversal in gradio (CVE-2026-49119). Confidential information can be exposed externally. Mitigation: upgrade to `6.16.0` or later.
|
| CVE-2026-14358 |
|
Cross-Site Scripting (XSS) in mediawiki (CVE-2026-14358)
cross-site scripting in mediawiki (CVE-2026-14358). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58263 |
|
Cross-Site Scripting (XSS) in jodit (CVE-2026-58263)
cross-site scripting in jodit (CVE-2026-58263). Risk of unauthorized operations or information disclosure. Exploitable via ``onerror``. Mitigation: upgrade to `4.12.28` or later.
|
| CVE-2026-54720 |
|
Cross-Site Scripting (XSS) in silverstripe/framework (CVE-2026-54720)
cross-site scripting in silverstripe/framework (CVE-2026-54720). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.2.2` or later.
|
| CVE-2026-55153 |
|
Vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153)
vulnerability in com.mchange:mchange-commons-java (CVE-2026-55153). Successful exploitation can lead to full system takeover. Exploitable via ``ObjectFactory``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-48978 |
|
Vulnerability in oras.land/oras-go/v2 (CVE-2026-48978)
vulnerability in oras.land/oras-go/v2 (CVE-2026-48978). Risk of unauthorized operations or information disclosure. Exploitable via ``auth.Client``. Mitigation: upgrade to `2.6.1` or later.
|
| CVE-2026-48824 |
|
Vulnerability in github.com/axllent/mailpit (CVE-2026-48824)
vulnerability in github.com/axllent/mailpit (CVE-2026-48824). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/send`. Mitigation: upgrade to `1.30.1` or later.
|