Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-15980 The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improp...
The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers...
CVE-2026-15369 Privilege Escalation in wordpress (CVE-2026-15369)
vulnerability in wordpress (CVE-2026-15369). Successful exploitation can lead to full system takeover.
CVE-2026-82460 Path Traversal in path-traversal (CVE-2026-82460)
path traversal in path-traversal (CVE-2026-82460). Successful exploitation can lead to full system takeover.
CVE-2026-82452 Vulnerability in c (CVE-2026-82452)
vulnerability in c (CVE-2026-82452). Successful exploitation can lead to full system takeover.
CVE-2026-82454 Vulnerability in CVE-2026-82454 (CVE-2026-82454)
vulnerability in CVE-2026-82454 (CVE-2026-82454). Confidential information can be exposed externally.
CVE-2026-14494 Unrestricted File Upload in wordpress (CVE-2026-14494)
vulnerability in wordpress (CVE-2026-14494). Successful exploitation can lead to full system takeover.
CVE-2026-3627 Vulnerability in sqli (CVE-2026-3627)
vulnerability in sqli (CVE-2026-3627). Confidential information can be exposed externally.
CVE-2026-19295 Vulnerability in privilege-escalation (CVE-2026-19295)
vulnerability in privilege-escalation (CVE-2026-19295). Successful exploitation can lead to full system takeover.
CVE-2026-82277 Vulnerability in csrf (CVE-2026-82277)
vulnerability in csrf (CVE-2026-82277). Successful exploitation can lead to full system takeover.
CVE-2026-55511 Code Injection in org.yamcs:yamcs-core (CVE-2026-55511)
code injection in org.yamcs:yamcs-core (CVE-2026-55511). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/archive/{instance}`. Mitigation: upgrade to `5.12.8` or later.
CVE-2026-82244 Code Injection in CVE-2026-82244 (CVE-2026-82244)
code injection in CVE-2026-82244 (CVE-2026-82244). Successful exploitation can lead to full system takeover.
CVE-2026-82222 Unsafe Deserialization in deserialization (CVE-2026-82222)
vulnerability in deserialization (CVE-2026-82222). Successful exploitation can lead to full system takeover.
CVE-2026-76581 Vulnerability in wordpress (CVE-2026-76581)
vulnerability in wordpress (CVE-2026-76581). Successful exploitation can lead to full system takeover. Exploitable via ``wdpsso_step1``.
CVE-2026-78032 Unsafe Deserialization in deserialization (CVE-2026-78032)
vulnerability in deserialization (CVE-2026-78032). Successful exploitation can lead to full system takeover.
CVE-2026-40541 Cross-Site Scripting (XSS) in CVE-2026-40541 (CVE-2026-40541)
cross-site scripting in CVE-2026-40541 (CVE-2026-40541). Successful exploitation can lead to full system takeover.
CVE-2026-61800 Path Traversal in CVE-2026-61800 (CVE-2026-61800)
path traversal in CVE-2026-61800 (CVE-2026-61800). Successful exploitation can lead to full system takeover.
CVE-2026-75337 Path Traversal in path-traversal (CVE-2026-75337)
path traversal in path-traversal (CVE-2026-75337). Successful exploitation can lead to full system takeover.
CVE-2026-78288 Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
CVE-2026-78260 Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
CVE-2026-59354 Vulnerability in ssrf (CVE-2026-59354)
vulnerability in ssrf (CVE-2026-59354). Confidential information can be exposed externally.
CVE-2026-32479 Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
CVE-2026-32566 Vulnerability in wordpress (CVE-2026-32566)
vulnerability in wordpress (CVE-2026-32566). Successful exploitation can lead to full system takeover.
CVE-2026-47884 Path Traversal in spring (CVE-2026-47884)
path traversal in spring (CVE-2026-47884). Successful exploitation can lead to full system takeover.
CVE-2026-75336 SQL Injection in sqli (CVE-2026-75336)
SQL injection in sqli (CVE-2026-75336). Successful exploitation can lead to full system takeover.
CVE-2026-75340 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75340)
SSRF in ssrf (CVE-2026-75340). Confidential information can be exposed externally.
CVE-2026-75330 SQL Injection in sqli (CVE-2026-75330)
SQL injection in sqli (CVE-2026-75330). Successful exploitation can lead to full system takeover.
CVE-2026-75332 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-75332)
SSRF in ssrf (CVE-2026-75332). Confidential information can be exposed externally.
CVE-2026-75325 Authentication Bypass in CVE-2026-75325 (CVE-2026-75325)
authentication bypass in CVE-2026-75325 (CVE-2026-75325). Successful exploitation can lead to full system takeover.
CVE-2026-51106 Vulnerability in cpp (CVE-2026-51106)
vulnerability in cpp (CVE-2026-51106). Confidential information can be exposed externally.
CVE-2026-54569 Vulnerability in senaite.core (CVE-2026-54569)
vulnerability in senaite.core (CVE-2026-54569). Successful exploitation can lead to full system takeover. Exploitable via `GET /senaite/bika_setup/`.
CVE-2026-74752 Vulnerability in privilege-escalation (CVE-2026-74752)
vulnerability in privilege-escalation (CVE-2026-74752). Successful exploitation can lead to full system takeover.
CVE-2026-54523 Vulnerability in github.com/kyverno/kyverno (CVE-2026-54523)
vulnerability in github.com/kyverno/kyverno (CVE-2026-54523). Confidential information can be exposed externally. Exploitable via ``NamespacedMutatingPolicy``. Mitigation: upgrade to `1.18.2` or later.
CVE-2026-77532 Vulnerability in CVE-2026-77532 (CVE-2026-77532)
vulnerability in CVE-2026-77532 (CVE-2026-77532). Successful exploitation can lead to full system takeover.
CVE-2026-18080 Unrestricted File Upload in wordpress (CVE-2026-18080)
vulnerability in wordpress (CVE-2026-18080). Successful exploitation can lead to full system takeover.
CVE-2026-18431 Vulnerability in wordpress (CVE-2026-18431)
vulnerability in wordpress (CVE-2026-18431). Successful exploitation can lead to full system takeover.
CVE-2026-16639 Vulnerability in drupal (CVE-2026-16639)
vulnerability in drupal (CVE-2026-16639). Successful exploitation can lead to full system takeover.
CVE-2026-65905 Vulnerability in apache (CVE-2026-65905)
vulnerability in apache (CVE-2026-65905). Successful exploitation can lead to full system takeover.
CVE-2026-65083 Vulnerability in dos (CVE-2026-65083)
vulnerability in dos (CVE-2026-65083). Successful exploitation can lead to full system takeover.
CVE-2026-76193 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-76193)
SSRF in ssrf (CVE-2026-76193). Successful exploitation can lead to full system takeover.
CVE-2025-71407 Out-of-Bounds Write in dos (CVE-2025-71407)
out-of-bounds write in dos (CVE-2025-71407). Successful exploitation can lead to full system takeover.
CVE-2022-51000 Use-After-Free in dos (CVE-2022-51000)
vulnerability in dos (CVE-2022-51000). Successful exploitation can lead to full system takeover.
CVE-2026-79657 Unsafe Deserialization in CVE-2026-79657 (CVE-2026-79657)
vulnerability in CVE-2026-79657 (CVE-2026-79657). Successful exploitation can lead to full system takeover.
CVE-2026-55976 SSRF (Server-Side Request Forgery) in apache (CVE-2026-55976)
SSRF in apache (CVE-2026-55976). Confidential information can be exposed externally.
CVE-2026-49845 Code Injection in apache (CVE-2026-49845)
code injection in apache (CVE-2026-49845). Successful exploitation can lead to full system takeover.
CVE-2026-78570 Privilege Escalation in wordpress (CVE-2026-78570)
vulnerability in wordpress (CVE-2026-78570). Successful exploitation can lead to full system takeover.
CVE-2026-78568 SQL Injection in wordpress (CVE-2026-78568)
SQL injection in wordpress (CVE-2026-78568). Successful exploitation can lead to full system takeover.
CVE-2026-78477 Vulnerability in wordpress (CVE-2026-78477)
vulnerability in wordpress (CVE-2026-78477). Successful exploitation can lead to full system takeover.
CVE-2026-13214 Out-of-Bounds Write in c (CVE-2026-13214)
out-of-bounds write in c (CVE-2026-13214). Successful exploitation can lead to full system takeover.
CVE-2026-78683 Unsafe Deserialization in deserialization (CVE-2026-78683)
vulnerability in deserialization (CVE-2026-78683). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
CVE-2026-56705 Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →