Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16258 |
|
Unsafe Deserialization in wordpress (CVE-2026-16258)
vulnerability in wordpress (CVE-2026-16258). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65400 KEV |
|
[KEV] Authentication Bypass in Apple macos (CVE-2026-65400)
authentication bypass in Apple macos (CVE-2026-65400). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-19175 |
|
Use-After-Free in google (CVE-2026-19175)
vulnerability in google (CVE-2026-19175). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19170 |
|
Use-After-Free in google (CVE-2026-19170)
vulnerability in google (CVE-2026-19170). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19171 |
|
Use-After-Free in google (CVE-2026-19171)
vulnerability in google (CVE-2026-19171). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19166 |
|
Use-After-Free in google (CVE-2026-19166)
vulnerability in google (CVE-2026-19166). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19164 |
|
Vulnerability in google (CVE-2026-19164)
vulnerability in google (CVE-2026-19164). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19157 |
|
Out-of-Bounds Write in google (CVE-2026-19157)
out-of-bounds write in google (CVE-2026-19157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19149 |
|
Use-After-Free in google (CVE-2026-19149)
vulnerability in google (CVE-2026-19149). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11976 |
|
Vulnerability in CVE-2026-11976 (CVE-2026-11976)
vulnerability in CVE-2026-11976 (CVE-2026-11976). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65581 |
|
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
|
| CVE-2026-65579 |
|
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
|
| CVE-2026-65578 |
|
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
|
| CVE-2026-65577 |
|
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
|
| CVE-2026-65575 |
|
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
|
| CVE-2026-65576 |
|
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
|
| CVE-2026-65571 |
|
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
|
| CVE-2026-65572 |
|
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
|
| CVE-2026-65573 |
|
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
|
| CVE-2026-65574 |
|
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
|
| CVE-2026-65552 |
|
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
|
| CVE-2026-65556 |
|
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
|
| CVE-2026-34191 |
|
SQL Injection in apache (CVE-2026-34191)
SQL injection in apache (CVE-2026-34191). Confidential information can be exposed externally.
|
| CVE-2026-32327 |
|
Vulnerability in apache (CVE-2026-32327)
vulnerability in apache (CVE-2026-32327). Confidential information can be exposed externally.
|
| CVE-2026-28139 |
|
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
|
| CVE-2026-63687 |
|
Vulnerability in apache (CVE-2026-63687)
vulnerability in apache (CVE-2026-63687). Confidential information can be exposed externally.
|
| CVE-2026-61466 |
|
Vulnerability in apache (CVE-2026-61466)
vulnerability in apache (CVE-2026-61466). Confidential information can be exposed externally. Exploitable via ``scope``.
|
| CVE-2026-65583 |
|
Vulnerability in apache (CVE-2026-65583)
vulnerability in apache (CVE-2026-65583). Confidential information can be exposed externally.
|
| CVE-2026-68079 |
|
Vulnerability in apache (CVE-2026-68079)
vulnerability in apache (CVE-2026-68079). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66909 |
|
Unsafe Deserialization in apache (CVE-2026-66909)
vulnerability in apache (CVE-2026-66909). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60053 |
|
Vulnerability in apache (CVE-2026-60053)
vulnerability in apache (CVE-2026-60053). Confidential information can be exposed externally.
|
| CVE-2026-71248 |
|
SQL Injection in sqli (CVE-2026-71248)
SQL injection in sqli (CVE-2026-71248). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71237 |
|
SQL Injection in sqli (CVE-2026-71237)
SQL injection in sqli (CVE-2026-71237). Successful exploitation can lead to full system takeover. Exploitable via `POST /userlogin`.
|
| CVE-2026-71231 |
|
SQL Injection in sqli (CVE-2026-71231)
SQL injection in sqli (CVE-2026-71231). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71207 |
|
SQL Injection in CVE-2026-71207 (CVE-2026-71207)
SQL injection in CVE-2026-71207 (CVE-2026-71207). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70376 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-61486 |
|
Vulnerability in apache (CVE-2026-61486)
vulnerability in apache (CVE-2026-61486). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61484 |
|
Unsafe Deserialization in apache (CVE-2026-61484)
vulnerability in apache (CVE-2026-61484). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16940 |
|
Path Traversal in wordpress (CVE-2026-16940)
path traversal in wordpress (CVE-2026-16940). Data can be tampered with by attackers.
|
| CVE-2026-9273 |
|
Vulnerability in wordpress (CVE-2026-9273)
vulnerability in wordpress (CVE-2026-9273). Confidential information can be exposed externally.
|
| CVE-2026-70554 |
|
Unsafe Deserialization in CVE-2026-70554 (CVE-2026-70554)
vulnerability in CVE-2026-70554 (CVE-2026-70554). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70553 |
|
Code Injection in CVE-2026-70553 (CVE-2026-70553)
code injection in CVE-2026-70553 (CVE-2026-70553). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70552 |
|
Vulnerability in CVE-2026-70552 (CVE-2026-70552)
vulnerability in CVE-2026-70552 (CVE-2026-70552). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69703 |
|
Vulnerability in CVE-2026-69703 (CVE-2026-69703)
vulnerability in CVE-2026-69703 (CVE-2026-69703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16618 |
|
Unrestricted File Upload in wordpress (CVE-2026-16618)
vulnerability in wordpress (CVE-2026-16618). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48333 |
|
Authorization Flaw in privilege-escalation (CVE-2026-48333)
vulnerability in privilege-escalation (CVE-2026-48333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48323 |
|
Vulnerability in c (CVE-2026-48323)
vulnerability in c (CVE-2026-48323). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48326 |
|
SQL Injection in c (CVE-2026-48326)
SQL injection in c (CVE-2026-48326). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48331 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48331)
SSRF in ssrf (CVE-2026-48331). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48330 |
|
SQL Injection in c (CVE-2026-48330)
SQL injection in c (CVE-2026-48330). Successful exploitation can lead to full system takeover.
|