Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18983 |
|
Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81931 |
|
Unrestricted File Upload in CVE-2026-81931 (CVE-2026-81931)
vulnerability in CVE-2026-81931 (CVE-2026-81931). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77991 |
|
Unrestricted File Upload in csharp (CVE-2026-77991)
vulnerability in csharp (CVE-2026-77991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75331 |
|
Unrestricted File Upload in CVE-2026-75331 (CVE-2026-75331)
vulnerability in CVE-2026-75331 (CVE-2026-75331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18080 |
|
Unrestricted File Upload in wordpress (CVE-2026-18080)
vulnerability in wordpress (CVE-2026-18080). Successful exploitation can lead to full system takeover.
|
| CVE-2026-79670 |
|
Unrestricted File Upload in CVE-2026-79670 (CVE-2026-79670)
vulnerability in CVE-2026-79670 (CVE-2026-79670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16601 |
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
| CVE-2026-56702 |
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
| CVE-2026-78337 |
|
Unrestricted File Upload in CVE-2026-78337 (CVE-2026-78337)
vulnerability in CVE-2026-78337 (CVE-2026-78337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78245 |
|
Vulnerability in CVE-2026-78245 (CVE-2026-78245)
vulnerability in CVE-2026-78245 (CVE-2026-78245). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78202 |
|
Vulnerability in CVE-2026-78202 (CVE-2026-78202)
vulnerability in CVE-2026-78202 (CVE-2026-78202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49849 |
|
Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77681 |
|
Vulnerability in CVE-2026-77681 (CVE-2026-77681)
vulnerability in CVE-2026-77681 (CVE-2026-77681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76995 |
|
Vulnerability in CVE-2026-76995 (CVE-2026-76995)
vulnerability in CVE-2026-76995 (CVE-2026-76995). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14946 |
|
Unrestricted File Upload in CVE-2026-14946 (CVE-2026-14946)
vulnerability in CVE-2026-14946 (CVE-2026-14946). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15049 |
|
Unrestricted File Upload in wordpress (CVE-2026-15049)
vulnerability in wordpress (CVE-2026-15049). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76800 |
|
Vulnerability in CVE-2026-76800 (CVE-2026-76800)
vulnerability in CVE-2026-76800 (CVE-2026-76800). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68899 |
|
Unrestricted File Upload in CVE-2026-68899 (CVE-2026-68899)
vulnerability in CVE-2026-68899 (CVE-2026-68899). Confidential information can be exposed externally.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19839 |
|
Vulnerability in CVE-2026-19839 (CVE-2026-19839)
vulnerability in CVE-2026-19839 (CVE-2026-19839). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49827 |
|
Vulnerability in CVE-2026-49827 (CVE-2026-49827)
vulnerability in CVE-2026-49827 (CVE-2026-49827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18391 |
|
Unrestricted File Upload in wordpress (CVE-2026-18391)
vulnerability in wordpress (CVE-2026-18391). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15039 |
|
Unrestricted File Upload in wordpress (CVE-2026-15039)
vulnerability in wordpress (CVE-2026-15039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55676 |
|
Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
|
| CVE-2026-13457 |
|
Unrestricted File Upload in wordpress (CVE-2026-13457)
vulnerability in wordpress (CVE-2026-13457). Confidential information can be exposed externally.
|
| CVE-2026-72557 |
|
Unrestricted File Upload in CVE-2026-72557 (CVE-2026-72557)
vulnerability in CVE-2026-72557 (CVE-2026-72557). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24330 |
|
Unrestricted File Upload in CVE-2026-24330 (CVE-2026-24330)
vulnerability in CVE-2026-24330 (CVE-2026-24330). Confidential information can be exposed externally.
|
| CVE-2026-72592 |
|
Unrestricted File Upload in CVE-2026-72592 (CVE-2026-72592)
vulnerability in CVE-2026-72592 (CVE-2026-72592). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16985 |
|
Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19210 |
|
Vulnerability in CVE-2026-19210 (CVE-2026-19210)
vulnerability in CVE-2026-19210 (CVE-2026-19210). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70558 |
|
Unrestricted File Upload in CVE-2026-70558 (CVE-2026-70558)
vulnerability in CVE-2026-70558 (CVE-2026-70558). Successful exploitation can lead to full system takeover. Exploitable via `POST /download/uploadFromRsByLocal`.
|
| CVE-2026-19065 |
|
Vulnerability in CVE-2026-19065 (CVE-2026-19065)
vulnerability in CVE-2026-19065 (CVE-2026-19065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71434 |
|
Unrestricted File Upload in statamic/cms (CVE-2026-71434)
vulnerability in statamic/cms (CVE-2026-71434). Risk of unauthorized operations or information disclosure. Exploitable via ``assets``. Mitigation: upgrade to `5.74.3` or later.
|
| CVE-2026-18927 |
|
Vulnerability in CVE-2026-18927 (CVE-2026-18927)
vulnerability in CVE-2026-18927 (CVE-2026-18927). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18933 |
|
Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6147 |
|
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
|
| CVE-2026-54416 |
|
Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14553 |
|
Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
|
| CVE-2026-65986 |
|
Cross-Site Scripting (XSS) in CVE-2026-65986 (CVE-2026-65986)
cross-site scripting in CVE-2026-65986 (CVE-2026-65986). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18788 |
|
Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16618 |
|
Unrestricted File Upload in wordpress (CVE-2026-16618)
vulnerability in wordpress (CVE-2026-16618). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61524 |
|
Unrestricted File Upload in CVE-2026-61524 (CVE-2026-61524)
vulnerability in CVE-2026-61524 (CVE-2026-61524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39931 |
|
Unrestricted File Upload in sqli (CVE-2026-39931)
vulnerability in sqli (CVE-2026-39931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16250 |
|
Unrestricted File Upload in wordpress (CVE-2026-16250)
vulnerability in wordpress (CVE-2026-16250). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12872 |
|
Unrestricted File Upload in wordpress (CVE-2026-12872)
vulnerability in wordpress (CVE-2026-12872). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13157 |
|
Unrestricted File Upload in wordpress (CVE-2026-13157)
vulnerability in wordpress (CVE-2026-13157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13158 |
|
Unrestricted File Upload in wordpress (CVE-2026-13158)
vulnerability in wordpress (CVE-2026-13158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53599 |
|
Unrestricted File Upload in redaxo/source (CVE-2026-53599)
vulnerability in redaxo/source (CVE-2026-53599). Successful exploitation can lead to full system takeover. Exploitable via ``shell.php.any.jpg``. Mitigation: upgrade to `5.21.1` or later.
|
| CVE-2026-63223 |
|
Unrestricted File Upload in codeigniter4/framework (CVE-2026-63223)
vulnerability in codeigniter4/framework (CVE-2026-63223). Successful exploitation can lead to full system takeover. Exploitable via ``is_image``. Mitigation: upgrade to `4.7.4` or later.
|