Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2016-20059 Vulnerability in privilege-escalation (CVE-2016-20059)
vulnerability in privilege-escalation (CVE-2016-20059). Successful exploitation can lead to full system takeover.
CVE-2016-20055 Vulnerability in privilege-escalation (CVE-2016-20055)
vulnerability in privilege-escalation (CVE-2016-20055). Successful exploitation can lead to full system takeover.
CVE-2016-20052 Unrestricted File Upload in snewscms (CVE-2016-20052)
vulnerability in snewscms (CVE-2016-20052). Successful exploitation can lead to full system takeover.
CVE-2016-20050 Out-of-Bounds Write in dos (CVE-2016-20050)
out-of-bounds write in dos (CVE-2016-20050). Risk of unauthorized operations or information disclosure.
CVE-2026-2936 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2936)
cross-site scripting in wordpress (CVE-2026-2936). Risk of unauthorized operations or information disclosure.
CVE-2026-3666 Path Traversal in wordpress (CVE-2026-3666)
path traversal in wordpress (CVE-2026-3666). Successful exploitation can lead to full system takeover.
CVE-2026-0626 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0626)
cross-site scripting in wordpress (CVE-2026-0626). Risk of unauthorized operations or information disclosure.
CVE-2026-1233 The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing...
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL database credentials for the vendor's external telemetry server in the `Mementor_TT...
CVE-2026-3445 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass i...
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the...
CVE-2026-5425 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5425)
cross-site scripting in wordpress (CVE-2026-5425). Risk of unauthorized operations or information disclosure.
CVE-2026-2437 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2437)
cross-site scripting in wordpress (CVE-2026-2437). Risk of unauthorized operations or information disclosure.
CVE-2026-0737 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0737)
cross-site scripting in wordpress (CVE-2026-0737). Risk of unauthorized operations or information disclosure.
CVE-2026-0738 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0738)
cross-site scripting in wordpress (CVE-2026-0738). Risk of unauthorized operations or information disclosure.
CVE-2026-2600 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2600)
cross-site scripting in wordpress (CVE-2026-2600). Risk of unauthorized operations or information disclosure.
CVE-2026-4896 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu...
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`,...
CVE-2025-15064 Cross-Site Scripting (XSS) in wordpress (CVE-2025-15064)
cross-site scripting in wordpress (CVE-2025-15064). Risk of unauthorized operations or information disclosure.
CVE-2026-0552 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0552)
cross-site scripting in wordpress (CVE-2026-0552). Risk of unauthorized operations or information disclosure.
CVE-2026-0664 Cross-Site Scripting (XSS) in wordpress (CVE-2026-0664)
cross-site scripting in wordpress (CVE-2026-0664). Risk of unauthorized operations or information disclosure.
CVE-2025-13368 Cross-Site Scripting (XSS) in wordpress (CVE-2025-13368)
cross-site scripting in wordpress (CVE-2025-13368). Risk of unauthorized operations or information disclosure.
CVE-2026-2949 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2949)
cross-site scripting in wordpress (CVE-2026-2949). Risk of unauthorized operations or information disclosure.
CVE-2026-2924 Cross-Site Scripting (XSS) in wordpress (CVE-2026-2924)
cross-site scripting in wordpress (CVE-2026-2924). Risk of unauthorized operations or information disclosure.
CVE-2026-34780 Vulnerability in electronjs (CVE-2026-34780)
vulnerability in electronjs (CVE-2026-34780). Successful exploitation can lead to full system takeover.
CVE-2026-34788 SQL Injection in sqli (CVE-2026-34788)
SQL injection in sqli (CVE-2026-34788). Confidential information can be exposed externally.
CVE-2026-34824 Out-of-Bounds Read in mesop (CVE-2026-34824)
vulnerability in mesop (CVE-2026-34824). Risk of unauthorized operations or information disclosure. Exploitable via ``handle_websocket``. Mitigation: upgrade to `1.2.5` or later.
CVE-2026-34607 Path Traversal in path-traversal (CVE-2026-34607)
path traversal in path-traversal (CVE-2026-34607). Successful exploitation can lead to full system takeover.
CVE-2026-34612 SQL Injection in sqli (CVE-2026-34612)
SQL injection in sqli (CVE-2026-34612). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v1/main/flows/search`.
CVE-2026-34229 Cross-Site Scripting (XSS) in emlog (CVE-2026-34229)
cross-site scripting in emlog (CVE-2026-34229). Risk of unauthorized operations or information disclosure.
CVE-2026-34228 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34228)
vulnerability in csrf (CVE-2026-34228). Data can be tampered with by attackers.
CVE-2026-34787 Vulnerability in csrf (CVE-2026-34787)
vulnerability in csrf (CVE-2026-34787). Confidential information can be exposed externally.
CVE-2026-34052 Vulnerability in jupyterhub-ltiauthenticator (CVE-2026-34052)
vulnerability in jupyterhub-ltiauthenticator (CVE-2026-34052). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.3` or later.
CVE-2017-20234 Vulnerability in CVE-2017-20234 (CVE-2017-20234)
vulnerability in CVE-2017-20234 (CVE-2017-20234). Successful exploitation can lead to full system takeover.
CVE-2017-20235 Authentication Bypass in prosoft-technology (CVE-2017-20235)
authentication bypass in prosoft-technology (CVE-2017-20235). Confidential information can be exposed externally.
CVE-2018-25236 Authentication Bypass in CVE-2018-25236 (CVE-2018-25236)
authentication bypass in CVE-2018-25236 (CVE-2018-25236). Successful exploitation can lead to full system takeover.
CVE-2026-33175 Authentication Bypass in oauthenticator (CVE-2026-33175)
authentication bypass in oauthenticator (CVE-2026-33175). Successful exploitation can lead to full system takeover. Exploitable via ``oauthenticator``. Mitigation: upgrade to `17.4.0` or later.
CVE-2026-27834 SQL Injection in sqli (CVE-2026-27834)
SQL injection in sqli (CVE-2026-27834). Successful exploitation can lead to full system takeover.
CVE-2026-27885 SQL Injection in sqli (CVE-2026-27885)
SQL injection in sqli (CVE-2026-27885). Successful exploitation can lead to full system takeover.
CVE-2026-34978 Path Traversal in path-traversal (CVE-2026-34978)
path traversal in path-traversal (CVE-2026-34978). Risk of unauthorized operations or information disclosure.
CVE-2018-25237 Vulnerability in dos (CVE-2018-25237)
vulnerability in dos (CVE-2018-25237). Successful exploitation can lead to full system takeover.
CVE-2026-35562 Vulnerability in dos (CVE-2026-35562)
vulnerability in dos (CVE-2026-35562). Risk of unauthorized operations or information disclosure.
CVE-2026-26058 Path Traversal in path-traversal (CVE-2026-26058)
path traversal in path-traversal (CVE-2026-26058). Confidential information can be exposed externally.
CVE-2026-22661 Path Traversal in path-traversal (CVE-2026-22661)
path traversal in path-traversal (CVE-2026-22661). Confidential information can be exposed externally.
CVE-2020-37216 Vulnerability in dos (CVE-2020-37216)
vulnerability in dos (CVE-2020-37216). Risk of unauthorized operations or information disclosure.
CVE-2017-20237 Authentication Bypass in CVE-2017-20237 (CVE-2017-20237)
authentication bypass in CVE-2017-20237 (CVE-2017-20237). Successful exploitation can lead to full system takeover.
CVE-2026-25726 Vulnerability in github.com/cloudreve/Cloudreve (CVE-2026-25726)
vulnerability in github.com/cloudreve/Cloudreve (CVE-2026-25726). Successful exploitation can lead to full system takeover. Exploitable via ``secret_key``. Mitigation: upgrade to `4.0.0-20260205113604-ec9fdd33bc54` or later.
CVE-2026-2625 Vulnerability in dos (CVE-2026-2625)
vulnerability in dos (CVE-2026-2625). Risk of unauthorized operations or information disclosure.
CVE-2026-32186 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-32186)
SSRF in ssrf (CVE-2026-32186). Successful exploitation can lead to full system takeover.
CVE-2026-0545 Vulnerability in mlflow (CVE-2026-0545)
vulnerability in mlflow (CVE-2026-0545). Confidential information can be exposed externally.
CVE-2026-5473 Vulnerability in deserialization (CVE-2026-5473)
vulnerability in deserialization (CVE-2026-5473). Risk of unauthorized operations or information disclosure.
CVE-2026-28373 Path Traversal in path-traversal (CVE-2026-28373)
path traversal in path-traversal (CVE-2026-28373). Successful exploitation can lead to full system takeover.
CVE-2026-35216 OS Command Injection in budibase (CVE-2026-35216)
OS command injection in budibase (CVE-2026-35216). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →