Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-81733 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-81733)
vulnerability in csrf (CVE-2026-81733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80210 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-80210)
vulnerability in csrf (CVE-2026-80210). Data can be tampered with by attackers.
|
| CVE-2026-56706 |
|
Vulnerability in csrf (CVE-2026-56706)
vulnerability in csrf (CVE-2026-56706). Data can be tampered with by attackers.
|
| CVE-2026-67360 |
|
Vulnerability in c (CVE-2026-67360)
vulnerability in c (CVE-2026-67360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67358 |
|
Cross-Site Request Forgery (CSRF) in c (CVE-2026-67358)
vulnerability in c (CVE-2026-67358). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54256 |
|
Vulnerability in winter/wn-backend-module (CVE-2026-54256)
vulnerability in winter/wn-backend-module (CVE-2026-54256). Risk of unauthorized operations or information disclosure. Exploitable via ``FileUpload``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-67364 |
|
Code Injection in c (CVE-2026-67364)
code injection in c (CVE-2026-67364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16732 |
|
Vulnerability in csrf (CVE-2026-16732)
vulnerability in csrf (CVE-2026-16732). Confidential information can be exposed externally.
|
| CVE-2026-55593 |
|
Cross-Site Request Forgery (CSRF) in froxlor/froxlor (CVE-2026-55593)
vulnerability in froxlor/froxlor (CVE-2026-55593). Data can be tampered with by attackers. Exploitable via ``allowed_from``. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-67921 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-67921)
vulnerability in csrf (CVE-2026-67921). Confidential information can be exposed externally.
|
| CVE-2026-61696 |
|
Vulnerability in csrf (CVE-2026-61696)
vulnerability in csrf (CVE-2026-61696). Confidential information can be exposed externally.
|
| CVE-2026-45126 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-45126)
vulnerability in csrf (CVE-2026-45126). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73847 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73847)
vulnerability in csrf (CVE-2026-73847). Confidential information can be exposed externally.
|
| CVE-2026-73482 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73482)
vulnerability in csrf (CVE-2026-73482). Data can be tampered with by attackers.
|
| CVE-2026-73481 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73481)
vulnerability in csrf (CVE-2026-73481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67990 |
|
Cross-Site Request Forgery (CSRF) in rails (CVE-2026-67990)
vulnerability in rails (CVE-2026-67990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57858 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-57858)
cross-site scripting in csrf (CVE-2026-57858). Confidential information can be exposed externally.
|
| CVE-2026-73086 |
|
Vulnerability in csrf (CVE-2026-73086)
vulnerability in csrf (CVE-2026-73086). Confidential information can be exposed externally.
|
| CVE-2026-72778 |
|
Vulnerability in csrf (CVE-2026-72778)
vulnerability in csrf (CVE-2026-72778). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71850 |
|
Vulnerability in hono (CVE-2026-71850)
vulnerability in hono (CVE-2026-71850). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.34` or later.
|
| CVE-2026-71273 |
|
Cross-Site Request Forgery (CSRF) in c (CVE-2026-71273)
vulnerability in c (CVE-2026-71273). Data can be tampered with by attackers. Exploitable via ``web_admin_password_enabled``.
|
| CVE-2026-7444 |
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
| CVE-2026-70376 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-5581 |
|
Vulnerability in wordpress (CVE-2026-5581)
vulnerability in wordpress (CVE-2026-5581). Data can be tampered with by attackers. Exploitable via ``wp_ajax_nopriv_gfmu_delete_file``.
|
| CVE-2026-67617 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-67617)
cross-site scripting in csrf (CVE-2026-67617). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/save_content_admin`.
|
| CVE-2025-67651 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-67651)
vulnerability in csrf (CVE-2025-67651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14239 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14239)
cross-site scripting in wordpress (CVE-2026-14239). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14856 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-14856)
cross-site scripting in csrf (CVE-2026-14856). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73419 |
|
Vulnerability in @auth/core (CVE-2026-73419)
vulnerability in @auth/core (CVE-2026-73419). Confidential information can be exposed externally. Exploitable via ``state``. Mitigation: upgrade to `0.41.3` or later.
|
| CVE-2026-50743 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-50743)
vulnerability in csrf (CVE-2026-50743). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32825 |
|
Vulnerability in rails (CVE-2026-32825)
vulnerability in rails (CVE-2026-32825). Confidential information can be exposed externally.
|
| CVE-2026-32823 |
|
Cross-Site Request Forgery (CSRF) in rails (CVE-2026-32823)
vulnerability in rails (CVE-2026-32823). Risk of unauthorized operations or information disclosure. Exploitable via ``GET``.
|
| CVE-2026-11563 |
|
Vulnerability in wordpress (CVE-2026-11563)
vulnerability in wordpress (CVE-2026-11563). Data can be tampered with by attackers.
|
| CVE-2026-49971 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-49971)
cross-site scripting in laravel (CVE-2026-49971). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58143 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-58143)
vulnerability in csrf (CVE-2026-58143). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58451 |
|
Path Traversal in csrf (CVE-2026-58451)
path traversal in csrf (CVE-2026-58451). Confidential information can be exposed externally.
|
| CVE-2026-56425 |
|
Vulnerability in csrf (CVE-2026-56425)
vulnerability in csrf (CVE-2026-56425). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-55745 |
|
Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55745)
vulnerability in cotonti/cotonti (CVE-2026-55745). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55742 |
|
Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55742)
vulnerability in cotonti/cotonti (CVE-2026-55742). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55744 |
|
Cross-Site Request Forgery (CSRF) in cotonti/cotonti (CVE-2026-55744)
vulnerability in cotonti/cotonti (CVE-2026-55744). Confidential information can be exposed externally.
|
| CVE-2026-55741 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-55741)
vulnerability in csrf (CVE-2026-55741). Successful exploitation can lead to full system takeover.
|
| CVE-2016-20083 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2016-20083)
vulnerability in wordpress (CVE-2016-20083). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46518 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-46518)
cross-site scripting in csrf (CVE-2026-46518). Confidential information can be exposed externally.
|
| CVE-2026-39170 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-39170)
vulnerability in csrf (CVE-2026-39170). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11603 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11603)
cross-site scripting in wordpress (CVE-2026-11603). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54458 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-54458)
cross-site scripting in WWBN/AVideo (CVE-2026-54458). Confidential information can be exposed externally. Exploitable via ``page_title``.
|
| CVE-2026-50183 |
|
Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-50183)
cross-site scripting in WWBN/AVideo (CVE-2026-50183). Risk of unauthorized operations or information disclosure. Exploitable via ``snippet.title``.
|
| CVE-2026-49279 |
|
Cross-Site Scripting (XSS) in wwbn/avideo (CVE-2026-49279)
cross-site scripting in wwbn/avideo (CVE-2026-49279). Risk of unauthorized operations or information disclosure. Exploitable via ``autoEvalCodeOnHTML``.
|
| CVE-2026-43985 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-43985)
vulnerability in csrf (CVE-2026-43985). Successful exploitation can lead to full system takeover. Exploitable via ``configUpdate``.
|
| CVE-2019-25734 |
|
Path Traversal in csrf (CVE-2019-25734)
path traversal in csrf (CVE-2019-25734). Risk of unauthorized operations or information disclosure.
|