Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-59549 Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59550 Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
CVE-2026-59551 Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59537 SQL Injection in sqli (CVE-2026-59537)
SQL injection in sqli (CVE-2026-59537). Confidential information can be exposed externally.
CVE-2026-59533 Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
CVE-2026-59538 Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
CVE-2025-59181 Vulnerability in path-traversal (CVE-2025-59181)
vulnerability in path-traversal (CVE-2025-59181). Risk of unauthorized operations or information disclosure.
CVE-2026-59527 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-10819 Vulnerability in dos (CVE-2026-10819)
vulnerability in dos (CVE-2026-10819). Risk of unauthorized operations or information disclosure.
CVE-2026-15003 Out-of-Bounds Read in c (CVE-2026-15003)
vulnerability in c (CVE-2026-15003). Risk of unauthorized operations or information disclosure.
CVE-2026-17514 Path Traversal in path-traversal (CVE-2026-17514)
path traversal in path-traversal (CVE-2026-17514). Risk of unauthorized operations or information disclosure.
CVE-2026-65877 SQL Injection in sqli (CVE-2026-65877)
SQL injection in sqli (CVE-2026-65877). Risk of unauthorized operations or information disclosure.
CVE-2026-65766 SQL Injection in sqli (CVE-2026-65766)
SQL injection in sqli (CVE-2026-65766). Risk of unauthorized operations or information disclosure.
CVE-2026-65876 SQL Injection in sqli (CVE-2026-65876)
SQL injection in sqli (CVE-2026-65876). Risk of unauthorized operations or information disclosure.
CVE-2026-57917 XXE (XML External Entity) in ssrf (CVE-2026-57917)
vulnerability in ssrf (CVE-2026-57917). Risk of unauthorized operations or information disclosure.
CVE-2026-14856 Cross-Site Scripting (XSS) in csrf (CVE-2026-14856)
cross-site scripting in csrf (CVE-2026-14856). Risk of unauthorized operations or information disclosure.
CVE-2026-12495 Vulnerability in dos (CVE-2026-12495)
vulnerability in dos (CVE-2026-12495). Risk of unauthorized operations or information disclosure.
CVE-2026-17534 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-17534)
SSRF in ssrf (CVE-2026-17534). Confidential information can be exposed externally.
CVE-2026-17523 Vulnerability in privilege-escalation (CVE-2026-17523)
vulnerability in privilege-escalation (CVE-2026-17523). Successful exploitation can lead to full system takeover.
CVE-2026-65764 Cross-Site Scripting (XSS) in CVE-2026-65764 (CVE-2026-65764)
cross-site scripting in CVE-2026-65764 (CVE-2026-65764). Risk of unauthorized operations or information disclosure.
CVE-2026-65765 Path Traversal in path-traversal (CVE-2026-65765)
path traversal in path-traversal (CVE-2026-65765). Risk of unauthorized operations or information disclosure.
CVE-2026-16554 Vulnerability in c (CVE-2026-16554)
vulnerability in c (CVE-2026-16554). Risk of unauthorized operations or information disclosure.
CVE-2026-13400 Cross-Site Scripting (XSS) in wordpress (CVE-2026-13400)
cross-site scripting in wordpress (CVE-2026-13400). Risk of unauthorized operations or information disclosure.
CVE-2026-13726 Cross-Site Scripting (XSS) in wordpress (CVE-2026-13726)
cross-site scripting in wordpress (CVE-2026-13726). Risk of unauthorized operations or information disclosure.
CVE-2026-13714 Unrestricted File Upload in wordpress (CVE-2026-13714)
vulnerability in wordpress (CVE-2026-13714). Successful exploitation can lead to full system takeover.
CVE-2026-14289 Code Injection in wordpress (CVE-2026-14289)
code injection in wordpress (CVE-2026-14289). Successful exploitation can lead to full system takeover.
CVE-2026-14189 SQL Injection in wordpress (CVE-2026-14189)
SQL injection in wordpress (CVE-2026-14189). Risk of unauthorized operations or information disclosure.
CVE-2026-12982 Cross-Site Scripting (XSS) in wordpress (CVE-2026-12982)
cross-site scripting in wordpress (CVE-2026-12982). Risk of unauthorized operations or information disclosure.
CVE-2026-15928 Cross-Site Scripting (XSS) in c (CVE-2026-15928)
cross-site scripting in c (CVE-2026-15928). Risk of unauthorized operations or information disclosure.
CVE-2026-17496 Cross-Site Scripting (XSS) in notegen (CVE-2026-17496)
cross-site scripting in notegen (CVE-2026-17496). Confidential information can be exposed externally.
CVE-2026-17497 OS Command Injection in notegen (CVE-2026-17497)
OS command injection in notegen (CVE-2026-17497). Successful exploitation can lead to full system takeover.
CVE-2026-63720 Code Injection in CVE-2026-63720 (CVE-2026-63720)
code injection in CVE-2026-63720 (CVE-2026-63720). Successful exploitation can lead to full system takeover.
CVE-2026-15962 Unsafe Deserialization in wordpress (CVE-2026-15962)
vulnerability in wordpress (CVE-2026-15962). Successful exploitation can lead to full system takeover.
CVE-2026-66013 Vulnerability in CVE-2026-66013 (CVE-2026-66013)
vulnerability in CVE-2026-66013 (CVE-2026-66013). Risk of unauthorized operations or information disclosure.
CVE-2026-64400 Vulnerability in path-traversal (CVE-2026-64400)
vulnerability in path-traversal (CVE-2026-64400). Risk of unauthorized operations or information disclosure.
CVE-2026-16766 OS Command Injection in CVE-2026-16766 (CVE-2026-16766)
OS command injection in CVE-2026-16766 (CVE-2026-16766). Successful exploitation can lead to full system takeover.
CVE-2026-15425 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15425)
cross-site scripting in wordpress (CVE-2026-15425). Risk of unauthorized operations or information disclosure.
CVE-2026-14955 Path Traversal in wordpress (CVE-2026-14955)
path traversal in wordpress (CVE-2026-14955). Confidential information can be exposed externally.
CVE-2026-10818 Unrestricted File Upload in wordpress (CVE-2026-10818)
vulnerability in wordpress (CVE-2026-10818). Successful exploitation can lead to full system takeover.
CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
CVE-2026-66374 Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
CVE-2026-73502 Vulnerability in github.com/getkin/kin-openapi (CVE-2026-73502)
vulnerability in github.com/getkin/kin-openapi (CVE-2026-73502). Risk of unauthorized operations or information disclosure. Exploitable via ``HEAD``. Mitigation: upgrade to `0.144.0` or later.
CVE-2026-73647 Vulnerability in quasar (CVE-2026-73647)
vulnerability in quasar (CVE-2026-73647). Risk of unauthorized operations or information disclosure. Exploitable via ``__proto__``. Mitigation: upgrade to `2.22.0` or later.
CVE-2026-73413 Vulnerability in shescape (CVE-2026-73413)
vulnerability in shescape (CVE-2026-73413). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.0.1` or later.
CVE-2026-73493 Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `1.0.0-M42` or later.
CVE-2026-66040 FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
CVE-2026-66036 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
CVE-2026-57531 Cross-Site Scripting (XSS) in CVE-2026-57531 (CVE-2026-57531)
cross-site scripting in CVE-2026-57531 (CVE-2026-57531). Risk of unauthorized operations or information disclosure.
CVE-2026-57530 Cross-Site Scripting (XSS) in CVE-2026-57530 (CVE-2026-57530)
cross-site scripting in CVE-2026-57530 (CVE-2026-57530). Risk of unauthorized operations or information disclosure.
CVE-2026-65707 SQL Injection in sqli (CVE-2026-65707)
SQL injection in sqli (CVE-2026-65707). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →