Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-68969 |
|
Vulnerability in apache (CVE-2026-68969)
vulnerability in apache (CVE-2026-68969). Confidential information can be exposed externally. Exploitable via `PATCH /api/v2/variables`.
|
| CVE-2026-68970 |
|
Vulnerability in apache (CVE-2026-68970)
vulnerability in apache (CVE-2026-68970). Confidential information can be exposed externally.
|
| CVE-2026-68971 |
|
Vulnerability in apache (CVE-2026-68971)
vulnerability in apache (CVE-2026-68971). Confidential information can be exposed externally. Exploitable via `POST /api/v2/assets/{asset_id}/materialize`.
|
| CVE-2026-67587 |
|
Unsafe Deserialization in apache (CVE-2026-67587)
vulnerability in apache (CVE-2026-67587). Successful exploitation can lead to full system takeover. Exploitable via ``Callback``.
|
| CVE-2026-68076 |
|
Vulnerability in apache (CVE-2026-68076)
vulnerability in apache (CVE-2026-68076). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v2/connections/test`.
|
| CVE-2026-67260 |
|
Unsafe Deserialization in apache (CVE-2026-67260)
vulnerability in apache (CVE-2026-67260). Risk of unauthorized operations or information disclosure. Exploitable via ``awaiting_input``.
|
| CVE-2026-65017 |
|
Information Disclosure in apache (CVE-2026-65017)
vulnerability in apache (CVE-2026-65017). Confidential information can be exposed externally.
|
| CVE-2026-59242 |
|
Unsafe Deserialization in apache (CVE-2026-59242)
vulnerability in apache (CVE-2026-59242). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v2/{...}/xcomEntries/{key}`.
|
| CVE-2026-59244 |
|
Vulnerability in apache (CVE-2026-59244)
vulnerability in apache (CVE-2026-59244). Confidential information can be exposed externally.
|
| CVE-2026-58076 |
|
Unsafe Deserialization in apache (CVE-2026-58076)
vulnerability in apache (CVE-2026-58076). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v2/dags/{dag_id}/details`.
|
| CVE-2026-54183 |
|
Information Disclosure in apache (CVE-2026-54183)
vulnerability in apache (CVE-2026-54183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35445 |
|
Vulnerability in winter/wn-backend-module (CVE-2026-35445)
vulnerability in winter/wn-backend-module (CVE-2026-35445). Risk of unauthorized operations or information disclosure. Exploitable via ``_handler``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32639 |
|
Vulnerability in winter/wn-cms-module (CVE-2026-32639)
vulnerability in winter/wn-cms-module (CVE-2026-32639). Confidential information can be exposed externally. Exploitable via ``cms.manage_pages``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32593 |
|
SQL Injection in winter/wn-backend-module (CVE-2026-32593)
SQL injection in winter/wn-backend-module (CVE-2026-32593). Confidential information can be exposed externally. Exploitable via ``numberrange``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32258 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32258)
cross-site scripting in winter/wn-backend-module (CVE-2026-32258). Confidential information can be exposed externally. Exploitable via ``backend.manage_editor``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32257 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32257)
cross-site scripting in winter/wn-backend-module (CVE-2026-32257). Confidential information can be exposed externally. Exploitable via ``backend.manage_branding``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-67285 |
|
Path Traversal in CVE-2026-67285 (CVE-2026-67285)
path traversal in CVE-2026-67285 (CVE-2026-67285). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18044 |
|
Vulnerability in wordpress (CVE-2026-18044)
vulnerability in wordpress (CVE-2026-18044). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16747 |
|
Vulnerability in wordpress (CVE-2026-16747)
vulnerability in wordpress (CVE-2026-16747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15213 |
|
Vulnerability in wordpress (CVE-2026-15213)
vulnerability in wordpress (CVE-2026-15213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16621 |
|
Vulnerability in c (CVE-2026-16621)
vulnerability in c (CVE-2026-16621). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17008 |
|
Vulnerability in wordpress (CVE-2026-17008)
vulnerability in wordpress (CVE-2026-17008). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16990 |
|
Vulnerability in wordpress (CVE-2026-16990)
vulnerability in wordpress (CVE-2026-16990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15045 |
|
Vulnerability in wordpress (CVE-2026-15045)
vulnerability in wordpress (CVE-2026-15045). Data can be tampered with by attackers.
|
| CVE-2026-68868 |
|
Vulnerability in apache (CVE-2026-68868)
vulnerability in apache (CVE-2026-68868). Confidential information can be exposed externally. Exploitable via ``team_name``.
|
| CVE-2026-19050 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-19050)
SSRF in wordpress (CVE-2026-19050). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18057 |
|
SQL Injection in wordpress (CVE-2026-18057)
SQL injection in wordpress (CVE-2026-18057). Confidential information can be exposed externally.
|
| CVE-2026-18230 |
|
SQL Injection in wordpress (CVE-2026-18230)
SQL injection in wordpress (CVE-2026-18230). Confidential information can be exposed externally.
|
| CVE-2026-18049 |
|
Information Disclosure in wordpress (CVE-2026-18049)
vulnerability in wordpress (CVE-2026-18049). Confidential information can be exposed externally.
|
| CVE-2026-18962 |
|
Vulnerability in wordpress (CVE-2026-18962)
vulnerability in wordpress (CVE-2026-18962). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19217 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19217)
cross-site scripting in wordpress (CVE-2026-19217). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16538 |
|
Vulnerability in wordpress (CVE-2026-16538)
vulnerability in wordpress (CVE-2026-16538). Confidential information can be exposed externally.
|
| CVE-2026-19052 |
|
Vulnerability in wordpress (CVE-2026-19052)
vulnerability in wordpress (CVE-2026-19052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18943 |
|
Information Disclosure in wordpress (CVE-2026-18943)
vulnerability in wordpress (CVE-2026-18943). Confidential information can be exposed externally.
|
| CVE-2026-16294 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16294)
SSRF in wordpress (CVE-2026-16294). Confidential information can be exposed externally.
|
| CVE-2026-18789 |
|
Vulnerability in wordpress (CVE-2026-18789)
vulnerability in wordpress (CVE-2026-18789). Confidential information can be exposed externally.
|
| CVE-2026-18474 |
|
SQL Injection in wordpress (CVE-2026-18474)
SQL injection in wordpress (CVE-2026-18474). Confidential information can be exposed externally.
|
| CVE-2026-19073 |
|
Information Disclosure in wordpress (CVE-2026-19073)
vulnerability in wordpress (CVE-2026-19073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18366 |
|
Privilege Escalation in wordpress (CVE-2026-18366)
vulnerability in wordpress (CVE-2026-18366). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17013 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17013)
cross-site scripting in wordpress (CVE-2026-17013). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16051 |
|
Code Injection in wordpress (CVE-2026-16051)
code injection in wordpress (CVE-2026-16051). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18035 |
|
Vulnerability in wordpress (CVE-2026-18035)
vulnerability in wordpress (CVE-2026-18035). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18048 |
|
Vulnerability in wordpress (CVE-2026-18048)
vulnerability in wordpress (CVE-2026-18048). Data can be tampered with by attackers.
|
| CVE-2026-18046 |
|
Authorization Flaw in wordpress (CVE-2026-18046)
vulnerability in wordpress (CVE-2026-18046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16977 |
|
SQL Injection in wordpress (CVE-2026-16977)
SQL injection in wordpress (CVE-2026-16977). Confidential information can be exposed externally.
|
| CVE-2026-16737 |
|
Vulnerability in wordpress (CVE-2026-16737)
vulnerability in wordpress (CVE-2026-16737). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16253 |
|
Information Disclosure in wordpress (CVE-2026-16253)
vulnerability in wordpress (CVE-2026-16253). Confidential information can be exposed externally.
|
| CVE-2026-15249 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15249)
cross-site scripting in wordpress (CVE-2026-15249). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15388 |
|
Authorization Flaw in wordpress (CVE-2026-15388)
vulnerability in wordpress (CVE-2026-15388). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16066)
cross-site scripting in wordpress (CVE-2026-16066). Risk of unauthorized operations or information disclosure.
|