Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15679 |
|
Unsafe Deserialization in deserialization (CVE-2026-15679)
vulnerability in deserialization (CVE-2026-15679). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15686 |
|
Vulnerability in CVE-2026-15686 (CVE-2026-15686)
vulnerability in CVE-2026-15686 (CVE-2026-15686). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13121 |
|
Vulnerability in privilege-escalation (CVE-2026-13121)
vulnerability in privilege-escalation (CVE-2026-13121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76998 |
|
Vulnerability in sqli (CVE-2026-76998)
vulnerability in sqli (CVE-2026-76998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63043 |
|
Vulnerability in apache (CVE-2026-63043)
vulnerability in apache (CVE-2026-63043). Confidential information can be exposed externally.
|
| CVE-2026-76996 |
|
Vulnerability in sqli (CVE-2026-76996)
vulnerability in sqli (CVE-2026-76996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61897 |
|
Vulnerability in privilege-escalation (CVE-2026-61897)
vulnerability in privilege-escalation (CVE-2026-61897). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76990 |
|
Vulnerability in sqli (CVE-2026-76990)
vulnerability in sqli (CVE-2026-76990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16925 |
|
Vulnerability in privilege-escalation (CVE-2026-16925)
vulnerability in privilege-escalation (CVE-2026-16925). Data can be tampered with by attackers.
|
| CVE-2026-16928 |
|
Vulnerability in dos (CVE-2026-16928)
vulnerability in dos (CVE-2026-16928). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16924 |
|
Vulnerability in dos (CVE-2026-16924)
vulnerability in dos (CVE-2026-16924). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76635 |
|
SQL Injection in sqli (CVE-2026-76635)
SQL injection in sqli (CVE-2026-76635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74011 |
|
SQL Injection in sqli (CVE-2026-74011)
SQL injection in sqli (CVE-2026-74011). Confidential information can be exposed externally.
|
| CVE-2026-68564 |
|
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
|
| CVE-2026-73998 |
|
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
|
| CVE-2026-74013 |
|
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
|
| CVE-2026-66594 |
|
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
|
| CVE-2026-66605 |
|
Cross-Site Scripting (XSS) in CVE-2026-66605 (CVE-2026-66605)
cross-site scripting in CVE-2026-66605 (CVE-2026-66605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66673 |
|
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
|
| CVE-2026-66614 |
|
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
|
| CVE-2026-66612 |
|
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
|
| CVE-2026-66616 |
|
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
|
| CVE-2026-66598 |
|
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
|
| CVE-2026-66597 |
|
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
|
| CVE-2026-66606 |
|
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
|
| CVE-2026-66604 |
|
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
|
| CVE-2026-66607 |
|
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
|
| CVE-2026-66611 |
|
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
|
| CVE-2026-66615 |
|
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
|
| CVE-2026-66582 |
|
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
|
| CVE-2026-66581 |
|
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
|
| CVE-2026-66590 |
|
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
|
| CVE-2026-73197 |
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
|
| CVE-2026-73198 |
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in...
|
| CVE-2026-13097 |
|
Vulnerability in privilege-escalation (CVE-2026-13097)
vulnerability in privilege-escalation (CVE-2026-13097). Confidential information can be exposed externally.
|
| CVE-2026-18917 |
|
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow...
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow...
|
| CVE-2026-14947 |
|
Vulnerability in path-traversal (CVE-2026-14947)
vulnerability in path-traversal (CVE-2026-14947). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15049 |
|
Unrestricted File Upload in wordpress (CVE-2026-15049)
vulnerability in wordpress (CVE-2026-15049). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76783 |
|
Vulnerability in sqli (CVE-2026-76783)
vulnerability in sqli (CVE-2026-76783). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76764 |
|
Vulnerability in sqli (CVE-2026-76764)
vulnerability in sqli (CVE-2026-76764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76762 |
|
Vulnerability in sqli (CVE-2026-76762)
vulnerability in sqli (CVE-2026-76762). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76928 |
|
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76886 |
|
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76879 |
|
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76880 |
|
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
|
| CVE-2026-76832 |
|
Path Traversal in path-traversal (CVE-2026-76832)
path traversal in path-traversal (CVE-2026-76832). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76395 |
|
Unsafe Deserialization in deserialization (CVE-2026-76395)
vulnerability in deserialization (CVE-2026-76395). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76325 |
|
Cross-Site Scripting (XSS) in splunk (CVE-2026-76325)
cross-site scripting in splunk (CVE-2026-76325). Confidential information can be exposed externally.
|
| CVE-2026-76319 |
|
Vulnerability in splunk (CVE-2026-76319)
vulnerability in splunk (CVE-2026-76319). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76313 |
|
Vulnerability in splunk (CVE-2026-76313)
vulnerability in splunk (CVE-2026-76313). Successful exploitation can lead to full system takeover.
|