Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59553 |
|
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
|
| CVE-2026-59556 |
|
Cross-Site Scripting (XSS) in CVE-2026-59556 (CVE-2026-59556)
cross-site scripting in CVE-2026-59556 (CVE-2026-59556). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59558 |
|
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
|
| CVE-2026-59552 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59552)
SSRF in ssrf (CVE-2026-59552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59551 |
|
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
|
| CVE-2026-59537 |
|
SQL Injection in sqli (CVE-2026-59537)
SQL injection in sqli (CVE-2026-59537). Confidential information can be exposed externally.
|
| CVE-2026-17523 |
|
Vulnerability in privilege-escalation (CVE-2026-17523)
vulnerability in privilege-escalation (CVE-2026-17523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13726 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13726)
cross-site scripting in wordpress (CVE-2026-13726). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17496 |
|
Cross-Site Scripting (XSS) in notegen (CVE-2026-17496)
cross-site scripting in notegen (CVE-2026-17496). Confidential information can be exposed externally.
|
| CVE-2026-17497 |
|
OS Command Injection in notegen (CVE-2026-17497)
OS command injection in notegen (CVE-2026-17497). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63720 |
|
Code Injection in CVE-2026-63720 (CVE-2026-63720)
code injection in CVE-2026-63720 (CVE-2026-63720). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15962 |
|
Unsafe Deserialization in wordpress (CVE-2026-15962)
vulnerability in wordpress (CVE-2026-15962). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64400 |
|
Vulnerability in path-traversal (CVE-2026-64400)
vulnerability in path-traversal (CVE-2026-64400). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10818 |
|
Unrestricted File Upload in wordpress (CVE-2026-10818)
vulnerability in wordpress (CVE-2026-10818). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66374 |
|
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the...
|
| CVE-2026-66373 |
|
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...
|
| CVE-2026-73493 |
|
Vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493)
vulnerability in org.http4s:http4s-blaze-server_2.13 (CVE-2026-73493). Risk of unauthorized operations or information disclosure. Exploitable via ``OutOfMemoryError``. Mitigation: upgrade to `1.0.0-M42` or later.
|
| CVE-2026-66040 |
|
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability...
|
| CVE-2026-66036 |
|
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability...
|
| CVE-2026-73507 |
|
Vulnerability in io.netty:netty-codec-xml (CVE-2026-73507)
vulnerability in io.netty:netty-codec-xml (CVE-2026-73507). Risk of unauthorized operations or information disclosure. Exploitable via ``maxFrameLength``. Mitigation: upgrade to `4.1.136.Final` or later.
|
| CVE-2026-9765 |
|
Vulnerability in privilege-escalation (CVE-2026-9765)
vulnerability in privilege-escalation (CVE-2026-9765). Data can be tampered with by attackers.
|
| CVE-2026-66144 |
|
Vulnerability in dos (CVE-2026-66144)
vulnerability in dos (CVE-2026-66144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66142 |
|
Vulnerability in apache (CVE-2026-66142)
vulnerability in apache (CVE-2026-66142). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66143 |
|
Vulnerability in apache (CVE-2026-66143)
vulnerability in apache (CVE-2026-66143). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15401 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15401)
cross-site scripting in wordpress (CVE-2026-15401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49744 |
|
Vulnerability in privilege-escalation (CVE-2026-49744)
vulnerability in privilege-escalation (CVE-2026-49744). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16870 |
|
Vulnerability in CVE-2026-16870 (CVE-2026-16870)
vulnerability in CVE-2026-16870 (CVE-2026-16870). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66141 |
|
Vulnerability in privilege-escalation (CVE-2026-66141)
vulnerability in privilege-escalation (CVE-2026-66141). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66140 |
|
Vulnerability in path-traversal (CVE-2026-66140)
vulnerability in path-traversal (CVE-2026-66140). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12736 |
|
Privilege Escalation in wordpress (CVE-2026-12736)
vulnerability in wordpress (CVE-2026-12736). Successful exploitation can lead to full system takeover. Exploitable via `POST /wp-json/wpify-woo/v1/option`.
|
| CVE-2026-56167 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-56167)
SSRF in ssrf (CVE-2026-56167). Confidential information can be exposed externally.
|
| CVE-2026-65694 |
|
Path Traversal in path-traversal (CVE-2026-65694)
path traversal in path-traversal (CVE-2026-65694). Confidential information can be exposed externally.
|
| CVE-2026-63313 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63313)
SSRF in ssrf (CVE-2026-63313). Confidential information can be exposed externally.
|
| CVE-2026-16765 |
|
Vulnerability in sqli (CVE-2026-16765)
vulnerability in sqli (CVE-2026-16765). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58355 |
|
Vulnerability in react (CVE-2024-58355)
vulnerability in react (CVE-2024-58355). Confidential information can be exposed externally. Mitigation: upgrade to `4.7.16` or later.
|
| CVE-2024-58353 |
|
Vulnerability in react (CVE-2024-58353)
vulnerability in react (CVE-2024-58353). Confidential information can be exposed externally.
|
| CVE-2026-49035 |
|
Vulnerability in dos (CVE-2026-49035)
vulnerability in dos (CVE-2026-49035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15968 |
|
Cross-Site Scripting (XSS) in progress (CVE-2026-15968)
cross-site scripting in progress (CVE-2026-15968). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16002 |
|
Out-of-Bounds Read in dos (CVE-2026-16002)
vulnerability in dos (CVE-2026-16002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47219 |
|
Vulnerability in find-my-way (CVE-2026-47219)
vulnerability in find-my-way (CVE-2026-47219). Risk of unauthorized operations or information disclosure. Exploitable via ``req.method``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-16756 |
|
Vulnerability in Amazon aws-smithy-http-server (CVE-2026-16756)
vulnerability in Amazon aws-smithy-http-server (CVE-2026-16756). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.66.5` or later.
|
| CVE-2026-63765 |
|
Vulnerability in CVE-2026-63765 (CVE-2026-63765)
vulnerability in CVE-2026-63765 (CVE-2026-63765). Data can be tampered with by attackers.
|
| CVE-2026-65918 |
|
Out-of-Bounds Read in dos (CVE-2026-65918)
vulnerability in dos (CVE-2026-65918). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65702 |
|
Path Traversal in path-traversal (CVE-2026-65702)
path traversal in path-traversal (CVE-2026-65702). Data can be tampered with by attackers.
|
| CVE-2026-44909 |
|
Vulnerability in dos (CVE-2026-44909)
vulnerability in dos (CVE-2026-44909). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65690 |
|
Path Traversal in path-traversal (CVE-2026-65690)
path traversal in path-traversal (CVE-2026-65690). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45623 |
|
Path Traversal in postcss (CVE-2026-45623)
path traversal in postcss (CVE-2026-45623). Confidential information can be exposed externally. Exploitable via ``PreviousMap``. Mitigation: upgrade to `8.5.12` or later.
|
| CVE-2026-59933 |
|
Vulnerability in phpoffice/phpspreadsheet (CVE-2026-59933)
vulnerability in phpoffice/phpspreadsheet (CVE-2026-59933). Risk of unauthorized operations or information disclosure. Exploitable via ``bigBlockChain``. Mitigation: upgrade to `1.30.6` or later.
|
| CVE-2026-59932 |
|
Vulnerability in phpoffice/phpspreadsheet (CVE-2026-59932)
vulnerability in phpoffice/phpspreadsheet (CVE-2026-59932). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.30.6` or later.
|
| CVE-2026-59931 |
|
SSRF (Server-Side Request Forgery) in phpoffice/phpspreadsheet (CVE-2026-59931)
SSRF in phpoffice/phpspreadsheet (CVE-2026-59931). Confidential information can be exposed externally. Exploitable via ``example.com``. Mitigation: upgrade to `1.30.6` or later.
|