Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75807 |
|
Authentication Bypass in wordpress (CVE-2026-75807)
authentication bypass in wordpress (CVE-2026-75807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82475 |
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
| CVE-2026-82474 |
|
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
|
| CVE-2026-82473 |
|
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
|
| CVE-2026-82472 |
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-82463 |
|
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
|
| CVE-2026-82461 |
|
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82333 |
|
Vulnerability in dos (CVE-2026-82333)
vulnerability in dos (CVE-2026-82333). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77078 |
|
Vulnerability in dos (CVE-2026-77078)
vulnerability in dos (CVE-2026-77078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77037 |
|
Vulnerability in dos (CVE-2026-77037)
vulnerability in dos (CVE-2026-77037). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18899 |
|
Path Traversal in path-traversal (CVE-2026-18899)
path traversal in path-traversal (CVE-2026-18899). Confidential information can be exposed externally.
|
| CVE-2026-82278 |
|
Code Injection in CVE-2026-82278 (CVE-2026-82278)
code injection in CVE-2026-82278 (CVE-2026-82278). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/v1/workflow/run_once`.
|
| CVE-2026-82275 |
|
Path Traversal in path-traversal (CVE-2026-82275)
path traversal in path-traversal (CVE-2026-82275). Confidential information can be exposed externally.
|
| CVE-2026-75124 |
|
Vulnerability in dos (CVE-2026-75124)
vulnerability in dos (CVE-2026-75124). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56100 |
|
Vulnerability in privilege-escalation (CVE-2026-56100)
vulnerability in privilege-escalation (CVE-2026-56100). Confidential information can be exposed externally.
|
| CVE-2026-54788 |
|
Vulnerability in datadog-opentelemetry (CVE-2026-54788)
vulnerability in datadog-opentelemetry (CVE-2026-54788). Risk of unauthorized operations or information disclosure. Exploitable via ``tracecontext``. Mitigation: upgrade to `0.3.3` or later.
|
| CVE-2026-82227 |
|
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
|
| CVE-2026-81760 |
|
Cross-Site Scripting (XSS) in CVE-2026-81760 (CVE-2026-81760)
cross-site scripting in CVE-2026-81760 (CVE-2026-81760). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81757 |
|
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
|
| CVE-2026-81285 |
|
Vulnerability in dos (CVE-2026-81285)
vulnerability in dos (CVE-2026-81285). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6176 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6176)
cross-site scripting in wordpress (CVE-2026-6176). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5934 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5934)
cross-site scripting in wordpress (CVE-2026-5934). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38638 |
|
Vulnerability in dos (CVE-2026-38638)
vulnerability in dos (CVE-2026-38638). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37237 |
|
Vulnerability in dos (CVE-2026-37237)
vulnerability in dos (CVE-2026-37237). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37736 |
|
Vulnerability in dos (CVE-2026-37736)
vulnerability in dos (CVE-2026-37736). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38636 |
|
Vulnerability in dos (CVE-2026-38636)
vulnerability in dos (CVE-2026-38636). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82261 |
|
Vulnerability in dos (CVE-2026-82261)
vulnerability in dos (CVE-2026-82261). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.52.2` or later.
|
| CVE-2026-82260 |
|
Vulnerability in dos (CVE-2026-82260)
vulnerability in dos (CVE-2026-82260). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.52.2` or later.
|
| CVE-2026-82259 |
|
Unsafe Deserialization in dos (CVE-2026-82259)
vulnerability in dos (CVE-2026-82259). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.53.3` or later.
|
| CVE-2026-82251 |
|
Path Traversal in path-traversal (CVE-2026-82251)
path traversal in path-traversal (CVE-2026-82251). Confidential information can be exposed externally.
|
| CVE-2026-82253 |
|
Path Traversal in path-traversal (CVE-2026-82253)
path traversal in path-traversal (CVE-2026-82253). Confidential information can be exposed externally.
|
| CVE-2026-82243 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82243)
SSRF in ssrf (CVE-2026-82243). Confidential information can be exposed externally.
|
| CVE-2026-82234 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82234)
SSRF in ssrf (CVE-2026-82234). Confidential information can be exposed externally.
|
| CVE-2026-82241 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82241)
SSRF in ssrf (CVE-2026-82241). Confidential information can be exposed externally. Exploitable via `POST /api/queries/preview`.
|
| CVE-2026-42391 |
|
Vulnerability in dos (CVE-2026-42391)
vulnerability in dos (CVE-2026-42391). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33605 |
|
Vulnerability in dos (CVE-2026-33605)
vulnerability in dos (CVE-2026-33605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27852 |
|
Vulnerability in dos (CVE-2026-27852)
vulnerability in dos (CVE-2026-27852). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5097 |
|
SQL Injection in wordpress (CVE-2026-5097)
SQL injection in wordpress (CVE-2026-5097). Confidential information can be exposed externally.
|
| CVE-2026-6286 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14558 |
|
Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76053 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76053)
cross-site scripting in wordpress (CVE-2026-76053). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77365 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-77365)
cross-site scripting in wordpress (CVE-2026-77365). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18983 |
|
Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18324 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18324)
cross-site scripting in wordpress (CVE-2026-18324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18978 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18978)
cross-site scripting in wordpress (CVE-2026-18978). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38821 |
|
Vulnerability in c (CVE-2026-38821)
vulnerability in c (CVE-2026-38821). Confidential information can be exposed externally.
|
| CVE-2026-75417 |
|
SQL Injection in sqli (CVE-2026-75417)
SQL injection in sqli (CVE-2026-75417). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75418 |
|
Vulnerability in path-traversal (CVE-2026-75418)
vulnerability in path-traversal (CVE-2026-75418). Confidential information can be exposed externally.
|