Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-77002 |
|
Authentication Bypass in wordpress (CVE-2026-77002)
authentication bypass in wordpress (CVE-2026-77002). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77000 |
|
Authentication Bypass in wordpress (CVE-2026-77000)
authentication bypass in wordpress (CVE-2026-77000). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77001 |
|
Authentication Bypass in wordpress (CVE-2026-77001)
authentication bypass in wordpress (CVE-2026-77001). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19222 |
|
Privilege Escalation in wordpress (CVE-2026-19222)
vulnerability in wordpress (CVE-2026-19222). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76793 |
|
Authentication Bypass in wordpress (CVE-2026-76793)
authentication bypass in wordpress (CVE-2026-76793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19221 |
|
Code Injection in wordpress (CVE-2026-19221)
code injection in wordpress (CVE-2026-19221). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76789 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76789)
cross-site scripting in wordpress (CVE-2026-76789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18052 |
|
Authentication Bypass in wordpress (CVE-2026-18052)
authentication bypass in wordpress (CVE-2026-18052). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16738 |
|
Vulnerability in wordpress (CVE-2026-16738)
vulnerability in wordpress (CVE-2026-16738). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19093 |
|
Vulnerability in wordpress (CVE-2026-19093)
vulnerability in wordpress (CVE-2026-19093). Confidential information can be exposed externally.
|
| CVE-2026-16612 |
|
Information Disclosure in wordpress (CVE-2026-16612)
vulnerability in wordpress (CVE-2026-16612). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16260 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16260)
cross-site scripting in wordpress (CVE-2026-16260). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14187 |
|
Vulnerability in wordpress (CVE-2026-14187)
vulnerability in wordpress (CVE-2026-14187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76074 |
|
Vulnerability in wordpress (CVE-2026-76074)
vulnerability in wordpress (CVE-2026-76074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76057 |
|
Vulnerability in wordpress (CVE-2026-76057)
vulnerability in wordpress (CVE-2026-76057). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75027 |
|
Vulnerability in wordpress (CVE-2026-75027)
vulnerability in wordpress (CVE-2026-75027). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19883 |
|
Privilege Escalation in wordpress (CVE-2026-19883)
vulnerability in wordpress (CVE-2026-19883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49849 |
|
Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34836 |
|
Vulnerability in CVE-2026-34836 (CVE-2026-34836)
vulnerability in CVE-2026-34836 (CVE-2026-34836). Confidential information can be exposed externally.
|
| CVE-2026-34741 |
|
Vulnerability in CVE-2026-34741 (CVE-2026-34741)
vulnerability in CVE-2026-34741 (CVE-2026-34741). Data can be tampered with by attackers.
|
| CVE-2026-31803 |
|
Cross-Site Scripting (XSS) in CVE-2026-31803 (CVE-2026-31803)
cross-site scripting in CVE-2026-31803 (CVE-2026-31803). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63135 |
|
Cross-Site Scripting (XSS) in yourls/yourls (CVE-2026-63135)
cross-site scripting in yourls/yourls (CVE-2026-63135). Data can be tampered with by attackers. Exploitable via `Referer header`. Mitigation: upgrade to `1.10.4` or later.
|
| CVE-2026-59989 |
|
Code Injection in phalcon/cphalcon (CVE-2026-59989)
code injection in phalcon/cphalcon (CVE-2026-59989). Risk of unauthorized operations or information disclosure. Exploitable via ``join``. Mitigation: upgrade to `5.16.0` or later.
|
| CVE-2026-76904 |
|
SQL Injection in org.geotools.jdbc:gt-jdbc-postgis (CVE-2026-76904)
SQL injection in org.geotools.jdbc:gt-jdbc-postgis (CVE-2026-76904). Successful exploitation can lead to full system takeover. Exploitable via ``jsonArrayContains``. Mitigation: upgrade to `33.6` or later.
|
| CVE-2026-74252 |
|
Cross-Site Scripting (XSS) in CVE-2026-74252 (CVE-2026-74252)
cross-site scripting in CVE-2026-74252 (CVE-2026-74252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62960 |
|
Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_interna...
Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-...
|
| CVE-2026-30819 |
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
|
| CVE-2026-54789 |
|
Out-of-Bounds Read in apache (CVE-2026-54789)
vulnerability in apache (CVE-2026-54789). Risk of unauthorized operations or information disclosure. Exploitable via ``mod_auth_openidc``.
|
| CVE-2026-59654 |
|
Vulnerability in apache (CVE-2026-59654)
vulnerability in apache (CVE-2026-59654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18356 |
|
Vulnerability in wordpress (CVE-2026-18356)
vulnerability in wordpress (CVE-2026-18356). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19848 |
|
Vulnerability in wordpress (CVE-2026-19848)
vulnerability in wordpress (CVE-2026-19848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17559 |
|
Authorization Flaw in wordpress (CVE-2026-17559)
vulnerability in wordpress (CVE-2026-17559). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16650 |
|
Vulnerability in wordpress (CVE-2026-16650)
vulnerability in wordpress (CVE-2026-16650). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15150 |
|
Vulnerability in wordpress (CVE-2026-15150)
vulnerability in wordpress (CVE-2026-15150). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15046 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15046)
vulnerability in wordpress (CVE-2026-15046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13176 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-13176)
SSRF in wordpress (CVE-2026-13176). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77686 |
|
Vulnerability in CVE-2026-77686 (CVE-2026-77686)
vulnerability in CVE-2026-77686 (CVE-2026-77686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77681 |
|
Vulnerability in CVE-2026-77681 (CVE-2026-77681)
vulnerability in CVE-2026-77681 (CVE-2026-77681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66797 |
|
Vulnerability in apache (CVE-2026-66797)
vulnerability in apache (CVE-2026-66797). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66722 |
|
Vulnerability in apache (CVE-2026-66722)
vulnerability in apache (CVE-2026-66722). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68745 |
|
Vulnerability in apache (CVE-2026-68745)
vulnerability in apache (CVE-2026-68745). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61399 |
|
Vulnerability in apache (CVE-2026-61399)
vulnerability in apache (CVE-2026-61399). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50222 |
|
Information Disclosure in apache (CVE-2026-50222)
vulnerability in apache (CVE-2026-50222). Confidential information can be exposed externally.
|
| CVE-2026-59780 |
|
Information Disclosure in apache (CVE-2026-59780)
vulnerability in apache (CVE-2026-59780). Confidential information can be exposed externally.
|
| CVE-2026-66721 |
|
Vulnerability in apache (CVE-2026-66721)
vulnerability in apache (CVE-2026-66721). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65613 |
|
Information Disclosure in apache (CVE-2026-65613)
vulnerability in apache (CVE-2026-65613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62440 |
|
Vulnerability in apache (CVE-2026-62440)
vulnerability in apache (CVE-2026-62440). Confidential information can be exposed externally.
|
| CVE-2026-61397 |
|
Information Disclosure in apache (CVE-2026-61397)
vulnerability in apache (CVE-2026-61397). Confidential information can be exposed externally.
|
| CVE-2026-63046 |
|
Vulnerability in apache (CVE-2026-63046)
vulnerability in apache (CVE-2026-63046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61422 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-61422)
SSRF in apache (CVE-2026-61422). Risk of unauthorized operations or information disclosure.
|