Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-74798 |
|
Path Traversal in path-traversal (CVE-2026-74798)
path traversal in path-traversal (CVE-2026-74798). Confidential information can be exposed externally.
|
| CVE-2026-74795 |
|
Vulnerability in csharp (CVE-2026-74795)
vulnerability in csharp (CVE-2026-74795). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74788 |
|
Vulnerability in csharp (CVE-2026-74788)
vulnerability in csharp (CVE-2026-74788). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74789 |
|
Vulnerability in dos (CVE-2026-74789)
vulnerability in dos (CVE-2026-74789). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73057 |
|
Vulnerability in dos (CVE-2026-73057)
vulnerability in dos (CVE-2026-73057). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73060 |
|
Vulnerability in dos (CVE-2026-73060)
vulnerability in dos (CVE-2026-73060). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73062 |
|
Vulnerability in dos (CVE-2026-73062)
vulnerability in dos (CVE-2026-73062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2497 |
|
SQL Injection in wordpress (CVE-2026-2497)
SQL injection in wordpress (CVE-2026-2497). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17087 |
|
Vulnerability in wordpress (CVE-2026-17087)
vulnerability in wordpress (CVE-2026-17087). Confidential information can be exposed externally.
|
| CVE-2026-13424 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13424)
cross-site scripting in wordpress (CVE-2026-13424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10734 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10734)
cross-site scripting in wordpress (CVE-2026-10734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18653 |
|
SQL Injection in wordpress (CVE-2026-18653)
SQL injection in wordpress (CVE-2026-18653). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17581 |
|
Code Injection in wordpress (CVE-2026-17581)
code injection in wordpress (CVE-2026-17581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16099 |
|
Unsafe Deserialization in wordpress (CVE-2026-16099)
vulnerability in wordpress (CVE-2026-16099). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15002 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15002)
cross-site scripting in wordpress (CVE-2026-15002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14498 |
|
Unrestricted File Upload in wordpress (CVE-2026-14498)
vulnerability in wordpress (CVE-2026-14498). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19926 |
|
Vulnerability in sqli (CVE-2026-19926)
vulnerability in sqli (CVE-2026-19926). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19919 |
|
Vulnerability in sqli (CVE-2026-19919)
vulnerability in sqli (CVE-2026-19919). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73054 |
|
Authentication Bypass in CVE-2026-73054 (CVE-2026-73054)
authentication bypass in CVE-2026-73054 (CVE-2026-73054). Confidential information can be exposed externally.
|
| CVE-2026-19905 |
|
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
|
| CVE-2026-19899 |
|
Vulnerability in sqli (CVE-2026-19899)
vulnerability in sqli (CVE-2026-19899). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19474 |
|
Vulnerability in dos (CVE-2026-19474)
vulnerability in dos (CVE-2026-19474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74516 |
|
Vulnerability in c (CVE-2026-74516)
vulnerability in c (CVE-2026-74516). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15142 |
|
Privilege Escalation in wordpress (CVE-2026-15142)
vulnerability in wordpress (CVE-2026-15142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14279 |
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
| CVE-2026-74312 |
|
Vulnerability in dos (CVE-2026-74312)
vulnerability in dos (CVE-2026-74312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13360 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13360)
cross-site scripting in wordpress (CVE-2026-13360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15312 |
|
Privilege Escalation in wordpress (CVE-2026-15312)
vulnerability in wordpress (CVE-2026-15312). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
|
| CVE-2026-15001 |
|
Privilege Escalation in wordpress (CVE-2026-15001)
vulnerability in wordpress (CVE-2026-15001). Successful exploitation can lead to full system takeover. Exploitable via ``save_bloyal_configuration_data``.
|
| CVE-2026-15162 |
|
SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
|
| CVE-2026-15965 |
|
Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14433 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14433)
cross-site scripting in wordpress (CVE-2026-14433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73683 |
|
Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73682 |
|
Vulnerability in CVE-2026-73682 (CVE-2026-73682)
vulnerability in CVE-2026-73682 (CVE-2026-73682). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73680 |
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
| CVE-2026-19910 |
|
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution...
PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution...
|
| CVE-2026-19909 |
|
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This...
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This...
|
| CVE-2026-18554 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
|
| CVE-2026-17175 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
|
| CVE-2026-17177 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
|
| CVE-2026-17179 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
|
| CVE-2026-17081 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
|
| CVE-2026-16879 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
|
| CVE-2026-73679 |
|
Code Injection in CVE-2026-73679 (CVE-2026-73679)
code injection in CVE-2026-73679 (CVE-2026-73679). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19629 |
|
Authorization Flaw in privilege-escalation (CVE-2026-19629)
vulnerability in privilege-escalation (CVE-2026-19629). Confidential information can be exposed externally.
|
| CVE-2026-19635 |
|
OS Command Injection in privilege-escalation (CVE-2026-19635)
OS command injection in privilege-escalation (CVE-2026-19635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19680 |
|
SQL Injection in sqli (CVE-2026-19680)
SQL injection in sqli (CVE-2026-19680). Confidential information can be exposed externally.
|
| CVE-2026-12366 |
|
Use-After-Free in c (CVE-2026-12366)
vulnerability in c (CVE-2026-12366). Successful exploitation can lead to full system takeover.
|