Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-56705 |
|
Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78265 |
|
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
|
| CVE-2026-78262 |
|
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
|
| CVE-2026-32563 |
|
Unsafe Deserialization in wordpress (CVE-2026-32563)
vulnerability in wordpress (CVE-2026-32563). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78329 |
|
Vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329)
vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-77915 |
|
Vulnerability in CVE-2026-77915 (CVE-2026-77915)
vulnerability in CVE-2026-77915 (CVE-2026-77915). Successful exploitation can lead to full system takeover. Exploitable via `POST /register`.
|
| CVE-2026-71300 |
|
Vulnerability in org.apache.camel:camel-atmosphere-websocket (CVE-2026-71300)
vulnerability in org.apache.camel:camel-atmosphere-websocket (CVE-2026-71300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-66906 |
|
Vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906)
vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
|
| CVE-2026-66650 |
|
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.
|
| CVE-2026-21962 KEV |
|
[KEV] Vulnerability in Oracle c (CVE-2026-21962)
vulnerability in Oracle c (CVE-2026-21962). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-4703 |
|
Unsafe Deserialization in wordpress (CVE-2026-4703)
vulnerability in wordpress (CVE-2026-4703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49849 |
|
Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59085 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-59085)
SSRF in apache (CVE-2026-59085). Confidential information can be exposed externally.
|
| CVE-2026-62440 |
|
Vulnerability in apache (CVE-2026-62440)
vulnerability in apache (CVE-2026-62440). Confidential information can be exposed externally.
|
| CVE-2026-61398 |
|
Vulnerability in apache (CVE-2026-61398)
vulnerability in apache (CVE-2026-61398). Confidential information can be exposed externally.
|
| CVE-2026-77647 |
|
Code Injection in CVE-2026-77647 (CVE-2026-77647)
code injection in CVE-2026-77647 (CVE-2026-77647). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65770 |
|
Vulnerability in apache (CVE-2026-65770)
vulnerability in apache (CVE-2026-65770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63038 |
|
SQL Injection in apache (CVE-2026-63038)
SQL injection in apache (CVE-2026-63038). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63037 |
|
SQL Injection in apache (CVE-2026-63037)
SQL injection in apache (CVE-2026-63037). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63039 |
|
SQL Injection in apache (CVE-2026-63039)
SQL injection in apache (CVE-2026-63039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73993 |
|
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
|
| CVE-2026-66672 |
|
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
|
| CVE-2026-66583 |
|
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
|
| CVE-2026-73389 |
|
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
|
| CVE-2026-73364 |
|
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
|
| CVE-2026-18937 |
|
Code Injection in wordpress (CVE-2026-18937)
code injection in wordpress (CVE-2026-18937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18051 |
|
Path Traversal in wordpress (CVE-2026-18051)
path traversal in wordpress (CVE-2026-18051). Data can be tampered with by attackers.
|
| CVE-2026-76036 |
|
Vulnerability in google (CVE-2026-76036)
vulnerability in google (CVE-2026-76036). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76035 |
|
Vulnerability in google (CVE-2026-76035)
vulnerability in google (CVE-2026-76035). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60977 |
|
Vulnerability in c (CVE-2026-60977)
vulnerability in c (CVE-2026-60977). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60861 |
|
Vulnerability in c (CVE-2026-60861)
vulnerability in c (CVE-2026-60861). Confidential information can be exposed externally.
|
| CVE-2026-60696 |
|
Vulnerability in c (CVE-2026-60696)
vulnerability in c (CVE-2026-60696). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60698 |
|
Vulnerability in c (CVE-2026-60698)
vulnerability in c (CVE-2026-60698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60702 |
|
Vulnerability in c (CVE-2026-60702)
vulnerability in c (CVE-2026-60702). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60672 |
|
Vulnerability in c (CVE-2026-60672)
vulnerability in c (CVE-2026-60672). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62988 |
|
Information Disclosure in froxlor/froxlor (CVE-2026-62988)
vulnerability in froxlor/froxlor (CVE-2026-62988). Confidential information can be exposed externally. Exploitable via ``password``. Mitigation: upgrade to `2.3.8` or later.
|
| CVE-2026-52610 |
|
Path Traversal in path-traversal (CVE-2026-52610)
path traversal in path-traversal (CVE-2026-52610). Confidential information can be exposed externally.
|
| CVE-2026-52608 |
|
Vulnerability in CVE-2026-52608 (CVE-2026-52608)
vulnerability in CVE-2026-52608 (CVE-2026-52608). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45118 |
|
Vulnerability in CVE-2026-45118 (CVE-2026-45118)
vulnerability in CVE-2026-45118 (CVE-2026-45118). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-45117 |
|
Code Injection in CVE-2026-45117 (CVE-2026-45117)
code injection in CVE-2026-45117 (CVE-2026-45117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73341 |
|
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
|
| CVE-2026-73380 |
|
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
|
| CVE-2026-73366 |
|
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
|
| CVE-2026-73376 |
|
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
|
| CVE-2026-32470 |
|
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
|
| CVE-2026-75874 |
|
Vulnerability in mozilla (CVE-2026-75874)
vulnerability in mozilla (CVE-2026-75874). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74985 |
|
Privilege Escalation in privilege-escalation (CVE-2026-74985)
vulnerability in privilege-escalation (CVE-2026-74985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74988 |
|
Buffer Overflow in mozilla (CVE-2026-74988)
vulnerability in mozilla (CVE-2026-74988). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74987 |
|
Buffer Overflow in mozilla (CVE-2026-74987)
vulnerability in mozilla (CVE-2026-74987). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74990 |
|
Buffer Overflow in mozilla (CVE-2026-74990)
vulnerability in mozilla (CVE-2026-74990). Successful exploitation can lead to full system takeover.
|