Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15647 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15647)
cross-site scripting in wordpress (CVE-2026-15647). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15794 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15794)
cross-site scripting in wordpress (CVE-2026-15794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15404 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15404)
cross-site scripting in wordpress (CVE-2026-15404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15646 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15646)
cross-site scripting in wordpress (CVE-2026-15646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15448 |
|
SQL Injection in wordpress (CVE-2026-15448)
SQL injection in wordpress (CVE-2026-15448). Confidential information can be exposed externally.
|
| CVE-2026-15761 |
|
SQL Injection in wordpress (CVE-2026-15761)
SQL injection in wordpress (CVE-2026-15761). Confidential information can be exposed externally.
|
| CVE-2026-15906 |
|
SQL Injection in wordpress (CVE-2026-15906)
SQL injection in wordpress (CVE-2026-15906). Confidential information can be exposed externally.
|
| CVE-2026-64871 |
|
Vulnerability in csrf (CVE-2026-64871)
vulnerability in csrf (CVE-2026-64871). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64873 |
|
Custom query URLs could access internal or reserved network services.
Custom query URLs could access internal or reserved network services.
|
| CVE-2026-64799 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-64799)
SSRF in ssrf (CVE-2026-64799). Confidential information can be exposed externally.
|
| CVE-2026-64876 |
|
Vulnerability in csrf (CVE-2026-64876)
vulnerability in csrf (CVE-2026-64876). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14481 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14481)
cross-site scripting in wordpress (CVE-2026-14481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15394 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15394)
cross-site scripting in wordpress (CVE-2026-15394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13119 |
|
SQL Injection in wordpress (CVE-2026-13119)
SQL injection in wordpress (CVE-2026-13119). Confidential information can be exposed externally.
|
| CVE-2026-13009 |
|
SQL Injection in wordpress (CVE-2026-13009)
SQL injection in wordpress (CVE-2026-13009). Confidential information can be exposed externally.
|
| CVE-2026-14282 |
|
Unrestricted File Upload in wordpress (CVE-2026-14282)
vulnerability in wordpress (CVE-2026-14282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15348 |
|
Authentication Bypass in wordpress (CVE-2026-15348)
authentication bypass in wordpress (CVE-2026-15348). Risk of unauthorized operations or information disclosure. Exploitable via ``wpdmppdl``.
|
| CVE-2026-15017 |
|
Privilege Escalation in wordpress (CVE-2026-15017)
vulnerability in wordpress (CVE-2026-15017). Successful exploitation can lead to full system takeover. Exploitable via ``new_role``.
|
| CVE-2026-9729 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9729)
cross-site scripting in wordpress (CVE-2026-9729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9713 |
|
SQL Injection in wordpress (CVE-2026-9713)
SQL injection in wordpress (CVE-2026-9713). Confidential information can be exposed externally.
|
| CVE-2026-16723 |
|
Vulnerability in com.alibaba:fastjson (CVE-2026-16723)
vulnerability in com.alibaba:fastjson (CVE-2026-16723). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9577 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9577)
cross-site scripting in wordpress (CVE-2026-9577). Risk of unauthorized operations or information disclosure. Exploitable via ``mod``.
|
| CVE-2026-12421 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12421)
cross-site scripting in wordpress (CVE-2026-12421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9635 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9635)
cross-site scripting in wordpress (CVE-2026-9635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9066)
cross-site scripting in wordpress (CVE-2026-9066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7534 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7534)
cross-site scripting in wordpress (CVE-2026-7534). Risk of unauthorized operations or information disclosure. Exploitable via ``user_has_cap``.
|
| CVE-2026-7232 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7232)
cross-site scripting in wordpress (CVE-2026-7232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6390 |
|
Vulnerability in dos (CVE-2026-6390)
vulnerability in dos (CVE-2026-6390). Data can be tampered with by attackers.
|
| CVE-2026-15074 |
|
@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
|
| CVE-2026-16653 |
|
Path Traversal in c (CVE-2026-16653)
path traversal in c (CVE-2026-16653). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38763 |
|
Vulnerability in dos (CVE-2026-38763)
vulnerability in dos (CVE-2026-38763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73415 |
|
Cross-Site Scripting (XSS) in jupyterlab (CVE-2026-73415)
cross-site scripting in jupyterlab (CVE-2026-73415). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.5.10` or later.
|
| CVE-2026-59942 |
|
Vulnerability in dompdf/dompdf (CVE-2026-59942)
vulnerability in dompdf/dompdf (CVE-2026-59942). Risk of unauthorized operations or information disclosure. Exploitable via ``exploit.py``. Mitigation: upgrade to `3.1.6` or later.
|
| CVE-2026-56816 |
|
Vulnerability in io.netty:netty-codec-http3 (CVE-2026-56816)
vulnerability in io.netty:netty-codec-http3 (CVE-2026-56816). Risk of unauthorized operations or information disclosure. Exploitable via ``payLoadLength``. Mitigation: upgrade to `4.2.16.Final` or later.
|
| CVE-2026-64795 |
|
Cross-Site Scripting (XSS) in CVE-2026-64795 (CVE-2026-64795)
cross-site scripting in CVE-2026-64795 (CVE-2026-64795). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63281 |
|
Stored condition values could also execute HTML/JavaScript in administrator summaries.
Stored condition values could also execute HTML/JavaScript in administrator summaries.
|
| CVE-2026-63265 |
|
Vulnerability in csrf (CVE-2026-63265)
vulnerability in csrf (CVE-2026-63265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63685 |
|
Vulnerability in csrf (CVE-2026-63685)
vulnerability in csrf (CVE-2026-63685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63684 |
|
Vulnerability in csrf (CVE-2026-63684)
vulnerability in csrf (CVE-2026-63684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64791 |
|
Vulnerability in csrf (CVE-2026-64791)
vulnerability in csrf (CVE-2026-64791). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63280 |
|
Vulnerability in csrf (CVE-2026-63280)
vulnerability in csrf (CVE-2026-63280). Successful exploitation can lead to full system takeover.
|
| CVE-2025-60835 |
|
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
|
| CVE-2025-50325 |
|
Vulnerability in CVE-2025-50325 (CVE-2025-50325)
vulnerability in CVE-2025-50325 (CVE-2025-50325). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13073 |
|
Vulnerability in dos (CVE-2026-13073)
vulnerability in dos (CVE-2026-13073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13065 |
|
Vulnerability in dos (CVE-2026-13065)
vulnerability in dos (CVE-2026-13065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13058 |
|
Vulnerability in dos (CVE-2026-13058)
vulnerability in dos (CVE-2026-13058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64834 |
|
Vulnerability in c (CVE-2026-64834)
vulnerability in c (CVE-2026-64834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65650 |
|
Vulnerability in dos (CVE-2026-65650)
vulnerability in dos (CVE-2026-65650). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64828 |
|
Cross-Site Scripting (XSS) in CVE-2026-64828 (CVE-2026-64828)
cross-site scripting in CVE-2026-64828 (CVE-2026-64828). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16607 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16607)
vulnerability in privilege-escalation (CVE-2026-16607). Successful exploitation can lead to full system takeover.
|