Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64967 |
|
Path Traversal in path-traversal (CVE-2026-64967)
path traversal in path-traversal (CVE-2026-64967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64963 |
|
Path Traversal in path-traversal (CVE-2026-64963)
path traversal in path-traversal (CVE-2026-64963). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64966 |
|
Path Traversal in path-traversal (CVE-2026-64966)
path traversal in path-traversal (CVE-2026-64966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64960 |
|
Unrestricted File Upload in CVE-2026-64960 (CVE-2026-64960)
vulnerability in CVE-2026-64960 (CVE-2026-64960). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15706 |
|
Vulnerability in CVE-2026-15706 (CVE-2026-15706)
vulnerability in CVE-2026-15706 (CVE-2026-15706). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64961 |
|
Vulnerability in c (CVE-2026-64961)
vulnerability in c (CVE-2026-64961). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74011 |
|
SQL Injection in sqli (CVE-2026-74011)
SQL injection in sqli (CVE-2026-74011). Confidential information can be exposed externally.
|
| CVE-2026-28164 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-28164)
vulnerability in csrf (CVE-2026-28164). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68564 |
|
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
|
| CVE-2026-73402 |
|
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
|
| CVE-2026-77072 |
|
Cross-Site Scripting (XSS) in CVE-2026-77072 (CVE-2026-77072)
cross-site scripting in CVE-2026-77072 (CVE-2026-77072). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77069 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-77069)
SSRF in ssrf (CVE-2026-77069). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77085 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-77085)
SSRF in ssrf (CVE-2026-77085). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73998 |
|
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
|
| CVE-2026-74013 |
|
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
|
| CVE-2026-68566 |
|
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
|
| CVE-2026-66680 |
|
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
|
| CVE-2026-77068 |
|
Path Traversal in path-traversal (CVE-2026-77068)
path traversal in path-traversal (CVE-2026-77068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73992 |
|
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
|
| CVE-2026-66682 |
|
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
|
| CVE-2026-77082 |
|
Vulnerability in dos (CVE-2026-77082)
vulnerability in dos (CVE-2026-77082). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66598 |
|
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
|
| CVE-2026-66597 |
|
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
|
| CVE-2026-66601 |
|
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.
|
| CVE-2026-66606 |
|
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
|
| CVE-2026-66604 |
|
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
|
| CVE-2026-66607 |
|
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
|
| CVE-2026-66615 |
|
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
|
| CVE-2026-66611 |
|
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
|
| CVE-2026-66616 |
|
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
|
| CVE-2026-66612 |
|
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
|
| CVE-2026-66614 |
|
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
|
| CVE-2026-66673 |
|
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
|
| CVE-2026-66605 |
|
Cross-Site Scripting (XSS) in CVE-2026-66605 (CVE-2026-66605)
cross-site scripting in CVE-2026-66605 (CVE-2026-66605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66609 |
|
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
|
| CVE-2026-66649 |
|
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
|
| CVE-2026-66593 |
|
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
|
| CVE-2026-66594 |
|
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
|
| CVE-2026-66590 |
|
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
|
| CVE-2026-66581 |
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
|
| CVE-2026-66582 |
|
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
|
| CVE-2026-66592 |
|
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
|
| CVE-2025-15688 |
|
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
|
| CVE-2025-15689 |
|
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
|
| CVE-2026-73196 |
|
Vulnerability in dos (CVE-2026-73196)
vulnerability in dos (CVE-2026-73196). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73197 |
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
|
| CVE-2026-73198 |
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in...
|
| CVE-2026-73199 |
|
Vulnerability in dos (CVE-2026-73199)
vulnerability in dos (CVE-2026-73199). Risk of unauthorized operations or information disclosure. Exploitable via ``JOIN_OID``.
|
| CVE-2026-13097 |
|
Vulnerability in privilege-escalation (CVE-2026-13097)
vulnerability in privilege-escalation (CVE-2026-13097). Confidential information can be exposed externally.
|
| CVE-2026-18917 |
|
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow...
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow...
|