Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-71233 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-71233)
cross-site scripting in laravel (CVE-2026-71233). Confidential information can be exposed externally. Exploitable via `PUT /api/v1/invoices/{id}`.
|
| CVE-2026-71232 |
|
Code Injection in CVE-2026-71232 (CVE-2026-71232)
code injection in CVE-2026-71232 (CVE-2026-71232). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71231 |
|
SQL Injection in sqli (CVE-2026-71231)
SQL injection in sqli (CVE-2026-71231). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7693 |
|
Command Injection in wordpress (CVE-2026-7693)
command injection in wordpress (CVE-2026-7693). Successful exploitation can lead to full system takeover. Exploitable via ``file``.
|
| CVE-2026-7444 |
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
| CVE-2026-7520 |
|
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
|
| CVE-2026-71207 |
|
SQL Injection in CVE-2026-71207 (CVE-2026-71207)
SQL injection in CVE-2026-71207 (CVE-2026-71207). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6627 |
|
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
|
| CVE-2026-6147 |
|
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
|
| CVE-2026-6639 |
|
Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
|
| CVE-2026-70376 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-6020 |
|
Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61485 |
|
Vulnerability in apache (CVE-2026-61485)
vulnerability in apache (CVE-2026-61485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61486 |
|
Vulnerability in apache (CVE-2026-61486)
vulnerability in apache (CVE-2026-61486). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61483 |
|
Vulnerability in apache (CVE-2026-61483)
vulnerability in apache (CVE-2026-61483). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61484 |
|
Unsafe Deserialization in apache (CVE-2026-61484)
vulnerability in apache (CVE-2026-61484). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54416 |
|
Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17532 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17532)
cross-site scripting in wordpress (CVE-2026-17532). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11977 |
|
SQL Injection in wordpress (CVE-2026-11977)
SQL injection in wordpress (CVE-2026-11977). Confidential information can be exposed externally.
|
| CVE-2026-68080 |
|
Vulnerability in apache (CVE-2026-68080)
vulnerability in apache (CVE-2026-68080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68078 |
|
Vulnerability in apache (CVE-2026-68078)
vulnerability in apache (CVE-2026-68078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68077 |
|
Vulnerability in apache (CVE-2026-68077)
vulnerability in apache (CVE-2026-68077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68075 |
|
Vulnerability in apache (CVE-2026-68075)
vulnerability in apache (CVE-2026-68075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67554 |
|
Vulnerability in apache (CVE-2026-67554)
vulnerability in apache (CVE-2026-67554). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68073 |
|
Vulnerability in apache (CVE-2026-68073)
vulnerability in apache (CVE-2026-68073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67591 |
|
Vulnerability in apache (CVE-2026-67591)
vulnerability in apache (CVE-2026-67591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67552 |
|
Vulnerability in apache (CVE-2026-67552)
vulnerability in apache (CVE-2026-67552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67553 |
|
Vulnerability in apache (CVE-2026-67553)
vulnerability in apache (CVE-2026-67553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67555 |
|
Vulnerability in apache (CVE-2026-67555)
vulnerability in apache (CVE-2026-67555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67592 |
|
Vulnerability in apache (CVE-2026-67592)
vulnerability in apache (CVE-2026-67592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67590 |
|
Vulnerability in apache (CVE-2026-67590)
vulnerability in apache (CVE-2026-67590). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66275 |
|
Vulnerability in apache (CVE-2026-66275)
vulnerability in apache (CVE-2026-66275). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66274 |
|
Vulnerability in apache (CVE-2026-66274)
vulnerability in apache (CVE-2026-66274). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16993 |
|
Information Disclosure in wordpress (CVE-2026-16993)
vulnerability in wordpress (CVE-2026-16993). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66276 |
|
Vulnerability in apache (CVE-2026-66276)
vulnerability in apache (CVE-2026-66276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66277 |
|
Vulnerability in apache (CVE-2026-66277)
vulnerability in apache (CVE-2026-66277). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16940 |
|
Path Traversal in wordpress (CVE-2026-16940)
path traversal in wordpress (CVE-2026-16940). Data can be tampered with by attackers.
|
| CVE-2026-14553 |
|
Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
|
| CVE-2026-8761 |
|
Vulnerability in wordpress (CVE-2026-8761)
vulnerability in wordpress (CVE-2026-8761). Successful exploitation can lead to full system takeover. Exploitable via ``CustomersController``.
|
| CVE-2026-7753 |
|
Vulnerability in wordpress (CVE-2026-7753)
vulnerability in wordpress (CVE-2026-7753). Confidential information can be exposed externally. Exploitable via ``ccb_export_nonce``.
|
| CVE-2026-9273 |
|
Vulnerability in wordpress (CVE-2026-9273)
vulnerability in wordpress (CVE-2026-9273). Confidential information can be exposed externally.
|
| CVE-2026-67588 |
|
Vulnerability in apache (CVE-2026-67588)
vulnerability in apache (CVE-2026-67588). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68074 |
|
Vulnerability in apache (CVE-2026-68074)
vulnerability in apache (CVE-2026-68074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66257 |
|
Vulnerability in apache (CVE-2026-66257)
vulnerability in apache (CVE-2026-66257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67589 |
|
Vulnerability in apache (CVE-2026-67589)
vulnerability in apache (CVE-2026-67589). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68060 |
|
Vulnerability in apache (CVE-2026-68060)
vulnerability in apache (CVE-2026-68060). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67551 |
|
Vulnerability in apache (CVE-2026-67551)
vulnerability in apache (CVE-2026-67551). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66273 |
|
Vulnerability in apache (CVE-2026-66273)
vulnerability in apache (CVE-2026-66273). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67465 |
|
Vulnerability in apache (CVE-2026-67465)
vulnerability in apache (CVE-2026-67465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18322 |
|
Privilege Escalation in wordpress (CVE-2026-18322)
vulnerability in wordpress (CVE-2026-18322). Successful exploitation can lead to full system takeover. Exploitable via ``save``.
|