Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-9810 |
|
Privilege Escalation in wordpress (CVE-2026-9810)
vulnerability in wordpress (CVE-2026-9810). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15982 |
|
Privilege Escalation in wordpress (CVE-2026-15982)
vulnerability in wordpress (CVE-2026-15982). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14956 |
|
Privilege Escalation in wordpress (CVE-2026-14956)
vulnerability in wordpress (CVE-2026-14956). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55579 |
|
Vulnerability in pheditor/pheditor (CVE-2026-55579)
vulnerability in pheditor/pheditor (CVE-2026-55579). Successful exploitation can lead to full system takeover. Exploitable via ``admin``. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-46512 |
|
Code Injection in CVE-2026-46512 (CVE-2026-46512)
code injection in CVE-2026-46512 (CVE-2026-46512). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12492 |
|
Authentication Bypass in wordpress (CVE-2026-12492)
authentication bypass in wordpress (CVE-2026-12492). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15013 |
|
Vulnerability in wordpress (CVE-2026-15013)
vulnerability in wordpress (CVE-2026-15013). Successful exploitation can lead to full system takeover. Exploitable via ``SignatureMethod``.
|
| CVE-2026-39808 KEV |
|
[KEV] OS Command Injection in Fortinet fortisandbox (CVE-2026-39808)
OS command injection in Fortinet fortisandbox (CVE-2026-39808). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-50148 |
|
Vulnerability in metabase (CVE-2026-50148)
vulnerability in metabase (CVE-2026-50148). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48334 |
|
Vulnerability in adobe (CVE-2026-48334)
vulnerability in adobe (CVE-2026-48334). Confidential information can be exposed externally.
|
| CVE-2026-48359 |
|
XXE (XML External Entity) in adobe (CVE-2026-48359)
vulnerability in adobe (CVE-2026-48359). Confidential information can be exposed externally.
|
| CVE-2026-48356 |
|
Unrestricted File Upload in adobe (CVE-2026-48356)
vulnerability in adobe (CVE-2026-48356). Confidential information can be exposed externally.
|
| CVE-2026-48358 |
|
Vulnerability in adobe (CVE-2026-48358)
vulnerability in adobe (CVE-2026-48358). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48259 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-48259)
SSRF in c (CVE-2026-48259). Confidential information can be exposed externally.
|
| CVE-2026-13001 |
|
Vulnerability in wordpress (CVE-2026-13001)
vulnerability in wordpress (CVE-2026-13001). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48324 |
|
SQL Injection in sqli (CVE-2026-48324)
SQL injection in sqli (CVE-2026-48324). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48325 |
|
Vulnerability in adobe (CVE-2026-48325)
vulnerability in adobe (CVE-2026-48325). Confidential information can be exposed externally.
|
| CVE-2026-48327 |
|
Authorization Flaw in adobe (CVE-2026-48327)
vulnerability in adobe (CVE-2026-48327). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48284 |
|
Vulnerability in adobe (CVE-2026-48284)
vulnerability in adobe (CVE-2026-48284). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48318 |
|
Path Traversal in path-traversal (CVE-2026-48318)
path traversal in path-traversal (CVE-2026-48318). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48319 |
|
Path Traversal in path-traversal (CVE-2026-48319)
path traversal in path-traversal (CVE-2026-48319). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48321 |
|
Authorization Flaw in privilege-escalation (CVE-2026-48321)
vulnerability in privilege-escalation (CVE-2026-48321). Confidential information can be exposed externally.
|
| CVE-2026-48322 |
|
Code Injection in adobe (CVE-2026-48322)
code injection in adobe (CVE-2026-48322). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15773 |
|
Use-After-Free in google (CVE-2026-15773)
vulnerability in google (CVE-2026-15773). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55010 |
|
Vulnerability in microsoft (CVE-2026-55010)
vulnerability in microsoft (CVE-2026-55010). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50447 |
|
Vulnerability in microsoft (CVE-2026-50447)
vulnerability in microsoft (CVE-2026-50447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50380 |
|
Vulnerability in microsoft (CVE-2026-50380)
vulnerability in microsoft (CVE-2026-50380). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57092 |
|
Use-After-Free in microsoft (CVE-2026-57092)
vulnerability in microsoft (CVE-2026-57092). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56190 |
|
Vulnerability in microsoft (CVE-2026-56190)
vulnerability in microsoft (CVE-2026-56190). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56188 |
|
Vulnerability in microsoft (CVE-2026-56188)
vulnerability in microsoft (CVE-2026-56188). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56159 |
|
Vulnerability in microsoft (CVE-2026-56159)
vulnerability in microsoft (CVE-2026-56159). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55944 |
|
Unsafe Deserialization in deserialization (CVE-2026-55944)
vulnerability in deserialization (CVE-2026-55944). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55040 KEV |
|
[KEV] Vulnerability in Microsoft sharepoint-server (CVE-2026-55040)
vulnerability in Microsoft sharepoint-server (CVE-2026-55040). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-50518 |
|
Vulnerability in microsoft (CVE-2026-50518)
vulnerability in microsoft (CVE-2026-50518). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58644 KEV |
|
[KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-58644)
vulnerability in Microsoft deserialization (CVE-2026-58644). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-55008 |
|
Cross-Site Scripting (XSS) in microsoft (CVE-2026-55008)
cross-site scripting in microsoft (CVE-2026-55008). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54990 |
|
Vulnerability in microsoft (CVE-2026-54990)
vulnerability in microsoft (CVE-2026-54990). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54118 |
|
Unsafe Deserialization in deserialization (CVE-2026-54118)
vulnerability in deserialization (CVE-2026-54118). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54117 |
|
Unsafe Deserialization in deserialization (CVE-2026-54117)
vulnerability in deserialization (CVE-2026-54117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50522 KEV |
|
[KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-50522)
vulnerability in Microsoft deserialization (CVE-2026-50522). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-49798 |
|
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
|
| CVE-2026-49172 |
|
Vulnerability in microsoft (CVE-2026-49172)
vulnerability in microsoft (CVE-2026-49172). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48561 |
|
Command Injection in microsoft (CVE-2026-48561)
command injection in microsoft (CVE-2026-48561). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42990 |
|
Vulnerability in microsoft (CVE-2026-42990)
vulnerability in microsoft (CVE-2026-42990). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62392 |
|
OS Command Injection in apache (CVE-2026-62392)
OS command injection in apache (CVE-2026-62392). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62390 |
|
SQL Injection in apache (CVE-2026-62390)
SQL injection in apache (CVE-2026-62390). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62422 |
|
Vulnerability in jetbrains (CVE-2026-62422)
vulnerability in jetbrains (CVE-2026-62422). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58319 |
|
Vulnerability in apache (CVE-2026-58319)
vulnerability in apache (CVE-2026-58319). Data can be tampered with by attackers.
|
| CVE-2026-57898 |
|
Path Traversal in CVE-2026-57898 (CVE-2026-57898)
path traversal in CVE-2026-57898 (CVE-2026-57898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59084 |
|
Vulnerability in apache (CVE-2026-59084)
vulnerability in apache (CVE-2026-59084). Confidential information can be exposed externally.
|