Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-30056 |
|
Vulnerability in dos (CVE-2026-30056)
vulnerability in dos (CVE-2026-30056). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30057 |
|
Vulnerability in dos (CVE-2026-30057)
vulnerability in dos (CVE-2026-30057). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11747 |
|
Cross-Site Scripting (XSS) in CVE-2026-11747 (CVE-2026-11747)
cross-site scripting in CVE-2026-11747 (CVE-2026-11747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81677 |
|
SQL Injection in sqli (CVE-2026-81677)
SQL injection in sqli (CVE-2026-81677). Risk of unauthorized operations or information disclosure. Exploitable via ``id_ambito``.
|
| CVE-2026-81676 |
|
SQL Injection in sqli (CVE-2026-81676)
SQL injection in sqli (CVE-2026-81676). Risk of unauthorized operations or information disclosure. Exploitable via ``limit_videos``.
|
| CVE-2026-81675 |
|
SQL Injection in sqli (CVE-2026-81675)
SQL injection in sqli (CVE-2026-81675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81674 |
|
SQL Injection in sqli (CVE-2026-81674)
SQL injection in sqli (CVE-2026-81674). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81673 |
|
SQL Injection in sqli (CVE-2026-81673)
SQL injection in sqli (CVE-2026-81673). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81672 |
|
SQL Injection in sqli (CVE-2026-81672)
SQL injection in sqli (CVE-2026-81672). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81560 |
|
Path Traversal in path-traversal (CVE-2026-81560)
path traversal in path-traversal (CVE-2026-81560). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5218 |
|
Vulnerability in CVE-2026-5218 (CVE-2026-5218)
vulnerability in CVE-2026-5218 (CVE-2026-5218). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81581 |
|
Buffer Overflow in privilege-escalation (CVE-2026-81581)
vulnerability in privilege-escalation (CVE-2026-81581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81579 |
|
Vulnerability in privilege-escalation (CVE-2026-81579)
vulnerability in privilege-escalation (CVE-2026-81579). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81572 |
|
Vulnerability in c (CVE-2026-81572)
vulnerability in c (CVE-2026-81572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81273 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
|
| CVE-2026-81277 |
|
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
|
| CVE-2026-78293 |
|
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
|
| CVE-2026-78289 |
|
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
|
| CVE-2026-78288 |
|
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
|
| CVE-2026-78285 |
|
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
|
| CVE-2026-81271 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
|
| CVE-2026-78283 |
|
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
|
| CVE-2026-78281 |
|
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
|
| CVE-2026-78273 |
|
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
|
| CVE-2026-78261 |
|
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
|
| CVE-2026-78271 |
|
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
|
| CVE-2026-59354 |
|
Vulnerability in ssrf (CVE-2026-59354)
vulnerability in ssrf (CVE-2026-59354). Confidential information can be exposed externally.
|
| CVE-2026-78260 |
|
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
|
| CVE-2026-32564 |
|
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
|
| CVE-2026-32550 |
|
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
|
| CVE-2026-32479 |
|
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
|
| CVE-2026-32566 |
|
Vulnerability in wordpress (CVE-2026-32566)
vulnerability in wordpress (CVE-2026-32566). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78333 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-78333)
cross-site scripting in wordpress (CVE-2026-78333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77989 |
|
Cross-Site Scripting (XSS) in csharp (CVE-2026-77989)
cross-site scripting in csharp (CVE-2026-77989). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77991 |
|
Unrestricted File Upload in csharp (CVE-2026-77991)
vulnerability in csharp (CVE-2026-77991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77018 |
|
Unrestricted File Upload in wordpress (CVE-2026-77018)
vulnerability in wordpress (CVE-2026-77018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76549 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-76549)
vulnerability in wordpress (CVE-2026-76549). Data can be tampered with by attackers.
|
| CVE-2026-47875 |
|
Unsafe Deserialization in deserialization (CVE-2026-47875)
vulnerability in deserialization (CVE-2026-47875). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47884 |
|
Path Traversal in spring (CVE-2026-47884)
path traversal in spring (CVE-2026-47884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47886 |
|
Vulnerability in spring (CVE-2026-47886)
vulnerability in spring (CVE-2026-47886). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47864 |
|
Unsafe Deserialization in deserialization (CVE-2026-47864)
vulnerability in deserialization (CVE-2026-47864). Confidential information can be exposed externally.
|
| CVE-2026-13415 |
|
Privilege Escalation in wordpress (CVE-2026-13415)
vulnerability in wordpress (CVE-2026-13415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81491 |
|
Path Traversal in path-traversal (CVE-2026-81491)
path traversal in path-traversal (CVE-2026-81491). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81486 |
|
Path Traversal in path-traversal (CVE-2026-81486)
path traversal in path-traversal (CVE-2026-81486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81485 |
|
Path Traversal in path-traversal (CVE-2026-81485)
path traversal in path-traversal (CVE-2026-81485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81421 |
|
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
|
| CVE-2026-47863 |
|
Vulnerability in dos (CVE-2026-47863)
vulnerability in dos (CVE-2026-47863). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47857 |
|
Vulnerability in dos (CVE-2026-47857)
vulnerability in dos (CVE-2026-47857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47856 |
|
Unsafe Deserialization in deserialization (CVE-2026-47856)
vulnerability in deserialization (CVE-2026-47856). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47852 |
|
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
|