Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55779 |
|
Cross-Site Scripting (XSS) in silverstripe/versioned (CVE-2026-55779)
cross-site scripting in silverstripe/versioned (CVE-2026-55779). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-55891 |
|
Vulnerability in privatebin/privatebin (CVE-2026-55891)
vulnerability in privatebin/privatebin (CVE-2026-55891). Risk of unauthorized operations or information disclosure. Exploitable via ``FILTER_SANITIZE_URL``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-77939 |
|
Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
|
| CVE-2026-55634 |
|
SQL Injection in pimcore/pimcore (CVE-2026-55634)
SQL injection in pimcore/pimcore (CVE-2026-55634). Successful exploitation can lead to full system takeover. Exploitable via ``objects``. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-55220 |
|
Unsafe Deserialization in pimcore/pimcore (CVE-2026-55220)
vulnerability in pimcore/pimcore (CVE-2026-55220). Risk of unauthorized operations or information disclosure. Exploitable via ``true``. Mitigation: upgrade to `12.3.10` or later.
|
| CVE-2026-55584 |
|
Vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584)
vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584). Confidential information can be exposed externally. Exploitable via ``PSI_ALLOWED``. Mitigation: upgrade to `3.4.6` or later.
|
| CVE-2026-5096 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-5096)
SSRF in wordpress (CVE-2026-5096). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38725 |
|
Cross-Site Scripting (XSS) in CVE-2026-38725 (CVE-2026-38725)
cross-site scripting in CVE-2026-38725 (CVE-2026-38725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81732 |
|
Information Disclosure in CVE-2026-81732 (CVE-2026-81732)
vulnerability in CVE-2026-81732 (CVE-2026-81732). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81733 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-81733)
vulnerability in csrf (CVE-2026-81733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6286 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12513 |
|
Vulnerability in wordpress (CVE-2026-12513)
vulnerability in wordpress (CVE-2026-12513). Data can be tampered with by attackers.
|
| CVE-2026-12514 |
|
Vulnerability in wordpress (CVE-2026-12514)
vulnerability in wordpress (CVE-2026-12514). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14558 |
|
Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18983 |
|
Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16759 |
|
Vulnerability in wordpress (CVE-2026-16759)
vulnerability in wordpress (CVE-2026-16759). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75417 |
|
SQL Injection in sqli (CVE-2026-75417)
SQL injection in sqli (CVE-2026-75417). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81931 |
|
Unrestricted File Upload in CVE-2026-81931 (CVE-2026-81931)
vulnerability in CVE-2026-81931 (CVE-2026-81931). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81728 |
|
SQL Injection in sqli (CVE-2026-81728)
SQL injection in sqli (CVE-2026-81728). Confidential information can be exposed externally.
|
| CVE-2026-81730 |
|
Path Traversal in CVE-2026-81730 (CVE-2026-81730)
path traversal in CVE-2026-81730 (CVE-2026-81730). Data can be tampered with by attackers.
|
| CVE-2026-81729 |
|
Authorization Flaw in CVE-2026-81729 (CVE-2026-81729)
vulnerability in CVE-2026-81729 (CVE-2026-81729). Data can be tampered with by attackers. Exploitable via `DELETE /api/index.php/documents`.
|
| CVE-2026-65931 |
|
Vulnerability in CVE-2026-65931 (CVE-2026-65931)
vulnerability in CVE-2026-65931 (CVE-2026-65931). Risk of unauthorized operations or information disclosure. Exploitable via `POST /index.php/admin/menuentries/sa/create`.
|
| CVE-2026-37067 |
|
Vulnerability in CVE-2026-37067 (CVE-2026-37067)
vulnerability in CVE-2026-37067 (CVE-2026-37067). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19092 |
|
Vulnerability in wordpress (CVE-2026-19092)
vulnerability in wordpress (CVE-2026-19092). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80210 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-80210)
vulnerability in csrf (CVE-2026-80210). Data can be tampered with by attackers.
|
| CVE-2026-54718 |
|
Vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718)
vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-40526 |
|
Path Traversal in path-traversal (CVE-2026-40526)
path traversal in path-traversal (CVE-2026-40526). Confidential information can be exposed externally. Exploitable via `GET /public/get-file/{path}`.
|
| CVE-2026-78286 |
|
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
|
| CVE-2026-78292 |
|
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
|
| CVE-2026-78276 |
|
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
|
| CVE-2026-78257 |
|
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
|
| CVE-2026-77991 |
|
Unrestricted File Upload in csharp (CVE-2026-77991)
vulnerability in csharp (CVE-2026-77991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81203 |
|
Vulnerability in sqli (CVE-2026-81203)
vulnerability in sqli (CVE-2026-81203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81202 |
|
Authentication Bypass in CVE-2026-81202 (CVE-2026-81202)
authentication bypass in CVE-2026-81202 (CVE-2026-81202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39275 |
|
Cross-Site Scripting (XSS) in CVE-2026-39275 (CVE-2026-39275)
cross-site scripting in CVE-2026-39275 (CVE-2026-39275). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80428 |
|
Unsafe Deserialization in CVE-2026-80428 (CVE-2026-80428)
vulnerability in CVE-2026-80428 (CVE-2026-80428). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54614 |
|
Vulnerability in cakephp/debug_kit (CVE-2026-54614)
vulnerability in cakephp/debug_kit (CVE-2026-54614). Risk of unauthorized operations or information disclosure. Exploitable via ``MailPreview``. Mitigation: upgrade to `5.2.4` or later.
|
| CVE-2026-80203 |
|
Authorization Flaw in CVE-2026-80203 (CVE-2026-80203)
vulnerability in CVE-2026-80203 (CVE-2026-80203). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18080 |
|
Unrestricted File Upload in wordpress (CVE-2026-18080)
vulnerability in wordpress (CVE-2026-18080). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18431 |
|
Vulnerability in wordpress (CVE-2026-18431)
vulnerability in wordpress (CVE-2026-18431). Successful exploitation can lead to full system takeover.
|
| CVE-2026-79804 |
|
Vulnerability in sqli (CVE-2026-79804)
vulnerability in sqli (CVE-2026-79804). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79845 |
|
Vulnerability in sqli (CVE-2026-79845)
vulnerability in sqli (CVE-2026-79845). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79793 |
|
Cross-Site Scripting (XSS) in CVE-2026-79793 (CVE-2026-79793)
cross-site scripting in CVE-2026-79793 (CVE-2026-79793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76060 |
|
OS Command Injection in cisa (CVE-2026-76060)
OS command injection in cisa (CVE-2026-76060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75498 |
|
SQL Injection in CVE-2026-75498 (CVE-2026-75498)
SQL injection in CVE-2026-75498 (CVE-2026-75498). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `123c97c` or later.
|
| CVE-2026-75497 |
|
SQL Injection in CVE-2026-75497 (CVE-2026-75497)
SQL injection in CVE-2026-75497 (CVE-2026-75497). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `123c97c` or later.
|
| CVE-2026-79774 |
|
Vulnerability in CVE-2026-79774 (CVE-2026-79774)
vulnerability in CVE-2026-79774 (CVE-2026-79774). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57863 |
|
Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78572 |
|
Unsafe Deserialization in wordpress (CVE-2026-78572)
vulnerability in wordpress (CVE-2026-78572). Successful exploitation can lead to full system takeover.
|