Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-76018 |
|
Vulnerability in google (CVE-2026-76018)
vulnerability in google (CVE-2026-76018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76020 |
|
Vulnerability in google (CVE-2026-76020)
vulnerability in google (CVE-2026-76020). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76021 |
|
Use-After-Free in Google chrome (CVE-2026-76021)
vulnerability in Google chrome (CVE-2026-76021). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76019 |
|
Authorization Flaw in google (CVE-2026-76019)
vulnerability in google (CVE-2026-76019). Confidential information can be exposed externally.
|
| CVE-2026-76023 |
|
Vulnerability in google (CVE-2026-76023)
vulnerability in google (CVE-2026-76023). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76022 |
|
Vulnerability in google (CVE-2026-76022)
vulnerability in google (CVE-2026-76022). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76017 |
|
Use-After-Free in Google chrome (CVE-2026-76017)
vulnerability in Google chrome (CVE-2026-76017). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64777 |
|
Path Traversal in apple (CVE-2026-64777)
path traversal in apple (CVE-2026-64777). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50190 |
|
Cross-Site Scripting (XSS) in CVE-2026-50190 (CVE-2026-50190)
cross-site scripting in CVE-2026-50190 (CVE-2026-50190). Risk of unauthorized operations or information disclosure. Exploitable via ``permalink``.
|
| CVE-2026-43678 |
|
Vulnerability in apple (CVE-2026-43678)
vulnerability in apple (CVE-2026-43678). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63179 |
|
Path Traversal in winter/wn-backend-module (CVE-2026-63179)
path traversal in winter/wn-backend-module (CVE-2026-63179). Confidential information can be exposed externally. Exploitable via ``BrandSetting.custom_css``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-54256 |
|
Vulnerability in winter/wn-backend-module (CVE-2026-54256)
vulnerability in winter/wn-backend-module (CVE-2026-54256). Risk of unauthorized operations or information disclosure. Exploitable via ``FileUpload``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-77020 |
|
Vulnerability in sqli (CVE-2026-77020)
vulnerability in sqli (CVE-2026-77020). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77025 |
|
Vulnerability in sqli (CVE-2026-77025)
vulnerability in sqli (CVE-2026-77025). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77019 |
|
Vulnerability in sqli (CVE-2026-77019)
vulnerability in sqli (CVE-2026-77019). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76999 |
|
Vulnerability in CVE-2026-76999 (CVE-2026-76999)
vulnerability in CVE-2026-76999 (CVE-2026-76999). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76998 |
|
Vulnerability in sqli (CVE-2026-76998)
vulnerability in sqli (CVE-2026-76998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76997 |
|
Vulnerability in sqli (CVE-2026-76997)
vulnerability in sqli (CVE-2026-76997). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63043 |
|
Vulnerability in apache (CVE-2026-63043)
vulnerability in apache (CVE-2026-63043). Confidential information can be exposed externally.
|
| CVE-2026-63042 |
|
Vulnerability in apache (CVE-2026-63042)
vulnerability in apache (CVE-2026-63042). Data can be tampered with by attackers.
|
| CVE-2026-63044 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-63044)
SSRF in apache (CVE-2026-63044). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63016 |
|
Vulnerability in apache (CVE-2026-63016)
vulnerability in apache (CVE-2026-63016). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63037 |
|
SQL Injection in apache (CVE-2026-63037)
SQL injection in apache (CVE-2026-63037). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63038 |
|
SQL Injection in apache (CVE-2026-63038)
SQL injection in apache (CVE-2026-63038). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63040 |
|
Vulnerability in apache (CVE-2026-63040)
vulnerability in apache (CVE-2026-63040). Data can be tampered with by attackers.
|
| CVE-2026-63039 |
|
SQL Injection in apache (CVE-2026-63039)
SQL injection in apache (CVE-2026-63039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63015 |
|
Vulnerability in apache (CVE-2026-63015)
vulnerability in apache (CVE-2026-63015). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76991 |
|
Vulnerability in sqli (CVE-2026-76991)
vulnerability in sqli (CVE-2026-76991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76996 |
|
Vulnerability in sqli (CVE-2026-76996)
vulnerability in sqli (CVE-2026-76996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76995 |
|
Vulnerability in CVE-2026-76995 (CVE-2026-76995)
vulnerability in CVE-2026-76995 (CVE-2026-76995). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16927 |
|
Vulnerability in ibm (CVE-2026-16927)
vulnerability in ibm (CVE-2026-16927). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16922 |
|
Vulnerability in ibm (CVE-2026-16922)
vulnerability in ibm (CVE-2026-16922). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16924 |
|
Vulnerability in dos (CVE-2026-16924)
vulnerability in dos (CVE-2026-16924). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16932 |
|
OS Command Injection in ibm (CVE-2026-16932)
OS command injection in ibm (CVE-2026-16932). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76990 |
|
Vulnerability in sqli (CVE-2026-76990)
vulnerability in sqli (CVE-2026-76990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16926 |
|
Vulnerability in ibm (CVE-2026-16926)
vulnerability in ibm (CVE-2026-16926). Data can be tampered with by attackers.
|
| CVE-2026-16923 |
|
Privilege Escalation in ibm (CVE-2026-16923)
vulnerability in ibm (CVE-2026-16923). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16925 |
|
Vulnerability in privilege-escalation (CVE-2026-16925)
vulnerability in privilege-escalation (CVE-2026-16925). Data can be tampered with by attackers.
|
| CVE-2026-16928 |
|
Vulnerability in dos (CVE-2026-16928)
vulnerability in dos (CVE-2026-16928). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76633 |
|
Vulnerability in CVE-2026-76633 (CVE-2026-76633)
vulnerability in CVE-2026-76633 (CVE-2026-76633). Confidential information can be exposed externally.
|
| CVE-2026-64972 |
|
Cross-Site Scripting (XSS) in CVE-2026-64972 (CVE-2026-64972)
cross-site scripting in CVE-2026-64972 (CVE-2026-64972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76635 |
|
SQL Injection in sqli (CVE-2026-76635)
SQL injection in sqli (CVE-2026-76635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64968 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-64968 (CVE-2026-64968)
SSRF in CVE-2026-64968 (CVE-2026-64968). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63490 |
|
Path Traversal in CVE-2026-63490 (CVE-2026-63490)
path traversal in CVE-2026-63490 (CVE-2026-63490). Confidential information can be exposed externally.
|
| CVE-2026-73993 |
|
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
|
| CVE-2026-66672 |
|
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
|
| CVE-2026-66594 |
|
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
|
| CVE-2026-66583 |
|
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
|
| CVE-2026-66592 |
|
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
|
| CVE-2026-14953 |
|
Vulnerability in CVE-2026-14953 (CVE-2026-14953)
vulnerability in CVE-2026-14953 (CVE-2026-14953). Risk of unauthorized operations or information disclosure.
|