Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-78267 Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-32555 Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
CVE-2026-32554 Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
CVE-2026-77915 Vulnerability in CVE-2026-77915 (CVE-2026-77915)
vulnerability in CVE-2026-77915 (CVE-2026-77915). Successful exploitation can lead to full system takeover. Exploitable via `POST /register`.
CVE-2026-66906 Vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906)
vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
CVE-2026-76071 Vulnerability in CVE-2026-76071 (CVE-2026-76071)
vulnerability in CVE-2026-76071 (CVE-2026-76071). Successful exploitation can lead to full system takeover.
CVE-2026-76070 Vulnerability in CVE-2026-76070 (CVE-2026-76070)
vulnerability in CVE-2026-76070 (CVE-2026-76070). Successful exploitation can lead to full system takeover.
CVE-2026-67602 Vulnerability in CVE-2026-67602 (CVE-2026-67602)
vulnerability in CVE-2026-67602 (CVE-2026-67602). Confidential information can be exposed externally.
CVE-2026-59564 Vulnerability in CVE-2026-59564 (CVE-2026-59564)
vulnerability in CVE-2026-59564 (CVE-2026-59564). Confidential information can be exposed externally.
CVE-2026-59568 Vulnerability in CVE-2026-59568 (CVE-2026-59568)
vulnerability in CVE-2026-59568 (CVE-2026-59568). Confidential information can be exposed externally.
CVE-2026-28165 Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
CVE-2026-66648 Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
CVE-2026-32558 Vulnerability in wordpress (CVE-2026-32558)
vulnerability in wordpress (CVE-2026-32558). Successful exploitation can lead to full system takeover.
CVE-2026-32551 Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
CVE-2026-66897 Path Traversal in path-traversal (CVE-2026-66897)
path traversal in path-traversal (CVE-2026-66897). Successful exploitation can lead to full system takeover.
CVE-2026-8445 Cross-Site Scripting (XSS) in CVE-2026-8445 (CVE-2026-8445)
cross-site scripting in CVE-2026-8445 (CVE-2026-8445). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.12.0` or later.
CVE-2026-7808 Vulnerability in CVE-2026-7808 (CVE-2026-7808)
vulnerability in CVE-2026-7808 (CVE-2026-7808). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.16.0` or later.
CVE-2026-78155 Vulnerability in privilege-escalation (CVE-2026-78155)
vulnerability in privilege-escalation (CVE-2026-78155). Successful exploitation can lead to full system takeover.
CVE-2026-4703 Unsafe Deserialization in wordpress (CVE-2026-4703)
vulnerability in wordpress (CVE-2026-4703). Successful exploitation can lead to full system takeover.
CVE-2026-78003 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-78003)
SSRF in wordpress (CVE-2026-78003). Successful exploitation can lead to full system takeover.
CVE-2026-49849 Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
CVE-2026-76904 SQL Injection in org.geotools.jdbc:gt-jdbc-postgis (CVE-2026-76904)
SQL injection in org.geotools.jdbc:gt-jdbc-postgis (CVE-2026-76904). Successful exploitation can lead to full system takeover. Exploitable via ``jsonArrayContains``. Mitigation: upgrade to `33.6` or later.
CVE-2026-69502 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-69502)
SSRF in ssrf (CVE-2026-69502). Confidential information can be exposed externally.
CVE-2026-77086 Path Traversal in path-traversal (CVE-2026-77086)
path traversal in path-traversal (CVE-2026-77086). Successful exploitation can lead to full system takeover.
CVE-2026-59085 SSRF (Server-Side Request Forgery) in apache (CVE-2026-59085)
SSRF in apache (CVE-2026-59085). Confidential information can be exposed externally.
CVE-2026-77264 Vulnerability in wordpress (CVE-2026-77264)
vulnerability in wordpress (CVE-2026-77264). Successful exploitation can lead to full system takeover.
CVE-2026-69836 KEV [KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-69836)
vulnerability in Microsoft deserialization (CVE-2026-69836). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-69851 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-69851)
SSRF in ssrf (CVE-2026-69851). Successful exploitation can lead to full system takeover.
CVE-2026-69400 Path Traversal in path-traversal (CVE-2026-69400)
path traversal in path-traversal (CVE-2026-69400). Successful exploitation can lead to full system takeover.
CVE-2026-68789 SQL Injection in sqli (CVE-2026-68789)
SQL injection in sqli (CVE-2026-68789). Successful exploitation can lead to full system takeover.
CVE-2026-68782 SQL Injection in sqli (CVE-2026-68782)
SQL injection in sqli (CVE-2026-68782). Successful exploitation can lead to full system takeover.
CVE-2026-65801 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65801)
SSRF in ssrf (CVE-2026-65801). Successful exploitation can lead to full system takeover.
CVE-2026-63509 Vulnerability in path-traversal (CVE-2026-63509)
vulnerability in path-traversal (CVE-2026-63509). Successful exploitation can lead to full system takeover.
CVE-2026-66788 Vulnerability in privilege-escalation (CVE-2026-66788)
vulnerability in privilege-escalation (CVE-2026-66788). Successful exploitation can lead to full system takeover.
CVE-2026-18265 Vulnerability in CVE-2026-18265 (CVE-2026-18265)
vulnerability in CVE-2026-18265 (CVE-2026-18265). Successful exploitation can lead to full system takeover.
CVE-2026-63039 SQL Injection in apache (CVE-2026-63039)
SQL injection in apache (CVE-2026-63039). Successful exploitation can lead to full system takeover.
CVE-2026-63038 SQL Injection in apache (CVE-2026-63038)
SQL injection in apache (CVE-2026-63038). Successful exploitation can lead to full system takeover.
CVE-2026-63037 SQL Injection in apache (CVE-2026-63037)
SQL injection in apache (CVE-2026-63037). Successful exploitation can lead to full system takeover.
CVE-2026-15706 Vulnerability in CVE-2026-15706 (CVE-2026-15706)
vulnerability in CVE-2026-15706 (CVE-2026-15706). Successful exploitation can lead to full system takeover.
CVE-2026-28164 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-28164)
vulnerability in csrf (CVE-2026-28164). Successful exploitation can lead to full system takeover.
CVE-2026-73992 Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVE-2026-66682 Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-68566 Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-66680 Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66593 Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVE-2026-66609 Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVE-2026-66649 Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
CVE-2025-15689 Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVE-2026-66592 Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVE-2025-15688 Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →