Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-43670 |
|
Vulnerability in apple (CVE-2026-43670)
vulnerability in apple (CVE-2026-43670). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65367 |
|
Vulnerability in apple (CVE-2026-65367)
vulnerability in apple (CVE-2026-65367). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79282 |
|
Use-After-Free in Google chrome (CVE-2026-79282)
vulnerability in Google chrome (CVE-2026-79282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76060 |
|
OS Command Injection in cisa (CVE-2026-76060)
OS command injection in cisa (CVE-2026-76060). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75498 |
|
SQL Injection in CVE-2026-75498 (CVE-2026-75498)
SQL injection in CVE-2026-75498 (CVE-2026-75498). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `123c97c` or later.
|
| CVE-2026-75497 |
|
SQL Injection in CVE-2026-75497 (CVE-2026-75497)
SQL injection in CVE-2026-75497 (CVE-2026-75497). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `123c97c` or later.
|
| CVE-2026-19912 |
|
Vulnerability in deserialization (CVE-2026-19912)
vulnerability in deserialization (CVE-2026-19912). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19913 |
|
Vulnerability in CVE-2026-19913 (CVE-2026-19913)
vulnerability in CVE-2026-19913 (CVE-2026-19913). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79774 |
|
Vulnerability in CVE-2026-79774 (CVE-2026-79774)
vulnerability in CVE-2026-79774 (CVE-2026-79774). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77998 |
|
Vulnerability in CVE-2026-77998 (CVE-2026-77998)
vulnerability in CVE-2026-77998 (CVE-2026-77998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57863 |
|
Path Traversal in path-traversal (CVE-2026-57863)
path traversal in path-traversal (CVE-2026-57863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49845 |
|
Code Injection in apache (CVE-2026-49845)
code injection in apache (CVE-2026-49845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55976 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-55976)
SSRF in apache (CVE-2026-55976). Confidential information can be exposed externally.
|
| CVE-2026-53561 |
|
Authentication Bypass in apache (CVE-2026-53561)
authentication bypass in apache (CVE-2026-53561). Confidential information can be exposed externally.
|
| CVE-2026-78572 |
|
Unsafe Deserialization in wordpress (CVE-2026-78572)
vulnerability in wordpress (CVE-2026-78572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49050 |
|
Authorization Flaw in apache (CVE-2026-49050)
vulnerability in apache (CVE-2026-49050). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78562 |
|
Vulnerability in wordpress (CVE-2026-78562)
vulnerability in wordpress (CVE-2026-78562). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78566 |
|
Vulnerability in wordpress (CVE-2026-78566)
vulnerability in wordpress (CVE-2026-78566). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77138 |
|
Unsafe Deserialization in CVE-2026-77138 (CVE-2026-77138)
vulnerability in CVE-2026-77138 (CVE-2026-77138). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56095 |
|
Unsafe Deserialization in CVE-2026-56095 (CVE-2026-56095)
vulnerability in CVE-2026-56095 (CVE-2026-56095). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56096 |
|
Vulnerability in apache (CVE-2026-56096)
vulnerability in apache (CVE-2026-56096). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18323 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-16601 |
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
| CVE-2026-18328 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-69665 |
|
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
|
| CVE-2026-68062 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-68960 |
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
| CVE-2026-68959 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-78656 |
|
Vulnerability in sqli (CVE-2026-78656)
vulnerability in sqli (CVE-2026-78656). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78478 |
|
Vulnerability in wordpress (CVE-2026-78478)
vulnerability in wordpress (CVE-2026-78478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75930 |
|
Vulnerability in wordpress (CVE-2026-75930)
vulnerability in wordpress (CVE-2026-75930). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14280 |
|
Vulnerability in wordpress (CVE-2026-14280)
vulnerability in wordpress (CVE-2026-14280). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78677 |
|
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
|
| CVE-2026-75574 |
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
| CVE-2026-72699 |
|
Vulnerability in CVE-2026-72699 (CVE-2026-72699)
vulnerability in CVE-2026-72699 (CVE-2026-72699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72700 |
|
Vulnerability in CVE-2026-72700 (CVE-2026-72700)
vulnerability in CVE-2026-72700 (CVE-2026-72700). Confidential information can be exposed externally.
|
| CVE-2026-56705 |
|
Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56703 |
|
Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56706 |
|
Vulnerability in csrf (CVE-2026-56706)
vulnerability in csrf (CVE-2026-56706). Data can be tampered with by attackers.
|
| CVE-2026-56707 |
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
| CVE-2026-56702 |
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
| CVE-2026-34967 |
|
Vulnerability in path-traversal (CVE-2026-34967)
vulnerability in path-traversal (CVE-2026-34967). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34968 |
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
| CVE-2026-16434 |
|
Vulnerability in CVE-2026-16434 (CVE-2026-16434)
vulnerability in CVE-2026-16434 (CVE-2026-16434). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5.1` or later.
|
| CVE-2026-78434 |
|
Authentication Bypass in CVE-2026-78434 (CVE-2026-78434)
authentication bypass in CVE-2026-78434 (CVE-2026-78434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78435 |
|
Path Traversal in path-traversal (CVE-2026-78435)
path traversal in path-traversal (CVE-2026-78435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78265 |
|
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
|
| CVE-2026-78262 |
|
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
|
| CVE-2026-32563 |
|
Unsafe Deserialization in wordpress (CVE-2026-32563)
vulnerability in wordpress (CVE-2026-32563). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77634 |
|
Vulnerability in CVE-2026-77634 (CVE-2026-77634)
vulnerability in CVE-2026-77634 (CVE-2026-77634). Risk of unauthorized operations or information disclosure.
|