Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-18165 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-18165)
vulnerability in csrf (CVE-2026-18165). Risk of unauthorized operations or information disclosure.
CVE-2026-74547 Vulnerability in dos (CVE-2026-74547)
vulnerability in dos (CVE-2026-74547). Risk of unauthorized operations or information disclosure.
CVE-2026-74516 Vulnerability in c (CVE-2026-74516)
vulnerability in c (CVE-2026-74516). Successful exploitation can lead to full system takeover.
CVE-2026-74484 Vulnerability in dos (CVE-2026-74484)
vulnerability in dos (CVE-2026-74484). Risk of unauthorized operations or information disclosure.
CVE-2026-19894 Vulnerability in sqli (CVE-2026-19894)
vulnerability in sqli (CVE-2026-19894). Risk of unauthorized operations or information disclosure.
CVE-2026-12248 SQL Injection in wordpress (CVE-2026-12248)
SQL injection in wordpress (CVE-2026-12248). Confidential information can be exposed externally.
CVE-2026-18438 Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
CVE-2026-15142 Privilege Escalation in wordpress (CVE-2026-15142)
vulnerability in wordpress (CVE-2026-15142). Successful exploitation can lead to full system takeover.
CVE-2026-14279 The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
CVE-2026-15826 Vulnerability in wordpress (CVE-2026-15826)
vulnerability in wordpress (CVE-2026-15826). Successful exploitation can lead to full system takeover.
CVE-2026-16007 SQL Injection in sqli (CVE-2026-16007)
SQL injection in sqli (CVE-2026-16007). Risk of unauthorized operations or information disclosure.
CVE-2026-74400 Vulnerability in dos (CVE-2026-74400)
vulnerability in dos (CVE-2026-74400). Risk of unauthorized operations or information disclosure.
CVE-2026-74312 Vulnerability in dos (CVE-2026-74312)
vulnerability in dos (CVE-2026-74312). Successful exploitation can lead to full system takeover.
CVE-2026-18387 SQL Injection in wordpress (CVE-2026-18387)
SQL injection in wordpress (CVE-2026-18387). Confidential information can be exposed externally.
CVE-2026-17090 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17090)
cross-site scripting in wordpress (CVE-2026-17090). Risk of unauthorized operations or information disclosure.
CVE-2026-16145 Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
CVE-2026-16146 SQL Injection in wordpress (CVE-2026-16146)
SQL injection in wordpress (CVE-2026-16146). Confidential information can be exposed externally.
CVE-2026-16586 SQL Injection in wordpress (CVE-2026-16586)
SQL injection in wordpress (CVE-2026-16586). Confidential information can be exposed externally.
CVE-2026-15993 SQL Injection in wordpress (CVE-2026-15993)
SQL injection in wordpress (CVE-2026-15993). Confidential information can be exposed externally.
CVE-2026-16094 SQL Injection in wordpress (CVE-2026-16094)
SQL injection in wordpress (CVE-2026-16094). Confidential information can be exposed externally.
CVE-2026-15948 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15948)
cross-site scripting in wordpress (CVE-2026-15948). Risk of unauthorized operations or information disclosure.
CVE-2026-15453 SQL Injection in wordpress (CVE-2026-15453)
SQL injection in wordpress (CVE-2026-15453). Confidential information can be exposed externally.
CVE-2026-13360 Cross-Site Scripting (XSS) in wordpress (CVE-2026-13360)
cross-site scripting in wordpress (CVE-2026-13360). Risk of unauthorized operations or information disclosure.
CVE-2026-15965 Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
CVE-2026-15162 SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
CVE-2026-16080 SQL Injection in wordpress (CVE-2026-16080)
SQL injection in wordpress (CVE-2026-16080). Confidential information can be exposed externally.
CVE-2026-15001 Privilege Escalation in wordpress (CVE-2026-15001)
vulnerability in wordpress (CVE-2026-15001). Successful exploitation can lead to full system takeover. Exploitable via ``save_bloyal_configuration_data``.
CVE-2026-15312 Privilege Escalation in wordpress (CVE-2026-15312)
vulnerability in wordpress (CVE-2026-15312). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
CVE-2026-15303 Authentication Bypass in wordpress (CVE-2026-15303)
authentication bypass in wordpress (CVE-2026-15303). Successful exploitation can lead to full system takeover.
CVE-2026-15341 Authentication Bypass in wordpress (CVE-2026-15341)
authentication bypass in wordpress (CVE-2026-15341). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
CVE-2026-14433 Cross-Site Scripting (XSS) in wordpress (CVE-2026-14433)
cross-site scripting in wordpress (CVE-2026-14433). Risk of unauthorized operations or information disclosure.
CVE-2026-14484 Path Traversal in wordpress (CVE-2026-14484)
path traversal in wordpress (CVE-2026-14484). Data can be tampered with by attackers.
CVE-2026-74247 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-74247)
SSRF in ssrf (CVE-2026-74247). Risk of unauthorized operations or information disclosure.
CVE-2026-74243 Vulnerability in path-traversal (CVE-2026-74243)
vulnerability in path-traversal (CVE-2026-74243). Risk of unauthorized operations or information disclosure.
CVE-2026-73683 Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
CVE-2026-67366 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-67366)
vulnerability in csrf (CVE-2026-67366). Risk of unauthorized operations or information disclosure.
CVE-2026-73682 Vulnerability in CVE-2026-73682 (CVE-2026-73682)
vulnerability in CVE-2026-73682 (CVE-2026-73682). Successful exploitation can lead to full system takeover.
CVE-2026-73680 Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
CVE-2026-71571 SQL Injection in sqli (CVE-2026-71571)
SQL injection in sqli (CVE-2026-71571). Risk of unauthorized operations or information disclosure.
CVE-2026-67365 SQL Injection in sqli (CVE-2026-67365)
SQL injection in sqli (CVE-2026-67365). Risk of unauthorized operations or information disclosure.
CVE-2026-19909 PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This...
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This...
CVE-2026-19910 PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution...
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution...
CVE-2026-17209 Cross-Site Scripting (XSS) in ibm (CVE-2026-17209)
cross-site scripting in ibm (CVE-2026-17209). Data can be tampered with by attackers.
CVE-2026-18178 Path Traversal in path-traversal (CVE-2026-18178)
path traversal in path-traversal (CVE-2026-18178). Risk of unauthorized operations or information disclosure.
CVE-2026-18554 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
CVE-2026-17081 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
CVE-2026-17181 Path Traversal in path-traversal (CVE-2026-17181)
path traversal in path-traversal (CVE-2026-17181). Data can be tampered with by attackers.
CVE-2026-17175 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
CVE-2026-17177 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
CVE-2026-17179 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →