Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-37073 |
|
Vulnerability in CVE-2026-37073 (CVE-2026-37073)
vulnerability in CVE-2026-37073 (CVE-2026-37073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37065 |
|
Vulnerability in CVE-2026-37065 (CVE-2026-37065)
vulnerability in CVE-2026-37065 (CVE-2026-37065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37069 |
|
Vulnerability in CVE-2026-37069 (CVE-2026-37069)
vulnerability in CVE-2026-37069 (CVE-2026-37069). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37070 |
|
Vulnerability in CVE-2026-37070 (CVE-2026-37070)
vulnerability in CVE-2026-37070 (CVE-2026-37070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37067 |
|
Vulnerability in CVE-2026-37067 (CVE-2026-37067)
vulnerability in CVE-2026-37067 (CVE-2026-37067). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37066 |
|
Vulnerability in path-traversal (CVE-2026-37066)
vulnerability in path-traversal (CVE-2026-37066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37068 |
|
Vulnerability in CVE-2026-37068 (CVE-2026-37068)
vulnerability in CVE-2026-37068 (CVE-2026-37068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37064 |
|
Vulnerability in CVE-2026-37064 (CVE-2026-37064)
vulnerability in CVE-2026-37064 (CVE-2026-37064). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19092 |
|
Vulnerability in wordpress (CVE-2026-19092)
vulnerability in wordpress (CVE-2026-19092). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80211 |
|
Vulnerability in CVE-2026-80211 (CVE-2026-80211)
vulnerability in CVE-2026-80211 (CVE-2026-80211). Confidential information can be exposed externally.
|
| CVE-2026-80210 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-80210)
vulnerability in csrf (CVE-2026-80210). Data can be tampered with by attackers.
|
| CVE-2026-54718 |
|
Vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718)
vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-40526 |
|
Path Traversal in path-traversal (CVE-2026-40526)
path traversal in path-traversal (CVE-2026-40526). Confidential information can be exposed externally. Exploitable via `GET /public/get-file/{path}`.
|
| CVE-2026-78286 |
|
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
|
| CVE-2026-78292 |
|
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
|
| CVE-2026-78276 |
|
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
|
| CVE-2026-75020 |
|
Vulnerability in apache (CVE-2026-75020)
vulnerability in apache (CVE-2026-75020). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74848 |
|
Vulnerability in apache (CVE-2026-74848)
vulnerability in apache (CVE-2026-74848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78257 |
|
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
|
| CVE-2026-75005 |
|
Vulnerability in apache (CVE-2026-75005)
vulnerability in apache (CVE-2026-75005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32566 |
|
Vulnerability in wordpress (CVE-2026-32566)
vulnerability in wordpress (CVE-2026-32566). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32564 |
|
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
|
| CVE-2026-78139 |
|
Vulnerability in wordpress (CVE-2026-78139)
vulnerability in wordpress (CVE-2026-78139). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78333 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-78333)
cross-site scripting in wordpress (CVE-2026-78333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78125 |
|
Information Disclosure in wordpress (CVE-2026-78125)
vulnerability in wordpress (CVE-2026-78125). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78138 |
|
Information Disclosure in wordpress (CVE-2026-78138)
vulnerability in wordpress (CVE-2026-78138). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77991 |
|
Unrestricted File Upload in csharp (CVE-2026-77991)
vulnerability in csharp (CVE-2026-77991). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77018 |
|
Unrestricted File Upload in wordpress (CVE-2026-77018)
vulnerability in wordpress (CVE-2026-77018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78137 |
|
Vulnerability in wordpress (CVE-2026-78137)
vulnerability in wordpress (CVE-2026-78137). Data can be tampered with by attackers.
|
| CVE-2026-77016 |
|
Vulnerability in wordpress (CVE-2026-77016)
vulnerability in wordpress (CVE-2026-77016). Data can be tampered with by attackers.
|
| CVE-2026-76549 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-76549)
vulnerability in wordpress (CVE-2026-76549). Data can be tampered with by attackers.
|
| CVE-2026-77017 |
|
Information Disclosure in wordpress (CVE-2026-77017)
vulnerability in wordpress (CVE-2026-77017). Confidential information can be exposed externally.
|
| CVE-2026-59278 |
|
SSRF (Server-Side Request Forgery) in csharp (CVE-2026-59278)
SSRF in csharp (CVE-2026-59278). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16567 |
|
Vulnerability in wordpress (CVE-2026-16567)
vulnerability in wordpress (CVE-2026-16567). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19454 |
|
Authorization Flaw in wordpress (CVE-2026-19454)
vulnerability in wordpress (CVE-2026-19454). Confidential information can be exposed externally.
|
| CVE-2026-16568 |
|
Vulnerability in wordpress (CVE-2026-16568)
vulnerability in wordpress (CVE-2026-16568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19223 |
|
Code Injection in wordpress (CVE-2026-19223)
code injection in wordpress (CVE-2026-19223). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13416 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13416)
cross-site scripting in wordpress (CVE-2026-13416). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19715 |
|
Information Disclosure in wordpress (CVE-2026-19715)
vulnerability in wordpress (CVE-2026-19715). Confidential information can be exposed externally.
|
| CVE-2026-13415 |
|
Privilege Escalation in wordpress (CVE-2026-13415)
vulnerability in wordpress (CVE-2026-13415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16569 |
|
Vulnerability in wordpress (CVE-2026-16569)
vulnerability in wordpress (CVE-2026-16569). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47864 |
|
Unsafe Deserialization in deserialization (CVE-2026-47864)
vulnerability in deserialization (CVE-2026-47864). Confidential information can be exposed externally.
|
| CVE-2026-19225 |
|
Code Injection in wordpress (CVE-2026-19225)
code injection in wordpress (CVE-2026-19225). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13414 |
|
Vulnerability in wordpress (CVE-2026-13414)
vulnerability in wordpress (CVE-2026-13414). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47851 |
|
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
|
| CVE-2026-81203 |
|
Vulnerability in sqli (CVE-2026-81203)
vulnerability in sqli (CVE-2026-81203). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-49105 KEV |
|
[KEV] Authentication Bypass in owncloud (CVE-2023-49105)
authentication bypass in owncloud (CVE-2023-49105). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-81202 |
|
Authentication Bypass in CVE-2026-81202 (CVE-2026-81202)
authentication bypass in CVE-2026-81202 (CVE-2026-81202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75331 |
|
Unrestricted File Upload in CVE-2026-75331 (CVE-2026-75331)
vulnerability in CVE-2026-75331 (CVE-2026-75331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75328 |
|
Path Traversal in CVE-2026-75328 (CVE-2026-75328)
path traversal in CVE-2026-75328 (CVE-2026-75328). Confidential information can be exposed externally.
|