Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Clear
ID Title
CVE-2026-75807 Authentication Bypass in wordpress (CVE-2026-75807)
authentication bypass in wordpress (CVE-2026-75807). Successful exploitation can lead to full system takeover.
CVE-2026-82474 Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
CVE-2026-82450 Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
CVE-2026-55848 XXE (XML External Entity) in org.mapfish.print:print-lib (CVE-2026-55848)
vulnerability in org.mapfish.print:print-lib (CVE-2026-55848). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.5` or later.
CVE-2026-55841 Vulnerability in org.graylog2:graylog2-server (CVE-2026-55841)
vulnerability in org.graylog2:graylog2-server (CVE-2026-55841). Data can be tampered with by attackers. Mitigation: upgrade to `7.1.2` or later.
CVE-2026-55584 Vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584)
vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584). Confidential information can be exposed externally. Exploitable via ``PSI_ALLOWED``. Mitigation: upgrade to `3.4.6` or later.
CVE-2026-55552 Path Traversal in org.yamcs:yamcs-core (CVE-2026-55552)
path traversal in org.yamcs:yamcs-core (CVE-2026-55552). Confidential information can be exposed externally. Mitigation: upgrade to `5.12.0` or later.
CVE-2026-6176 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6176)
cross-site scripting in wordpress (CVE-2026-6176). Risk of unauthorized operations or information disclosure.
CVE-2026-5934 Cross-Site Scripting (XSS) in wordpress (CVE-2026-5934)
cross-site scripting in wordpress (CVE-2026-5934). Risk of unauthorized operations or information disclosure.
CVE-2026-79996 Privilege Escalation in wordpress (CVE-2026-79996)
vulnerability in wordpress (CVE-2026-79996). Successful exploitation can lead to full system takeover.
CVE-2026-6286 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
CVE-2026-5097 SQL Injection in wordpress (CVE-2026-5097)
SQL injection in wordpress (CVE-2026-5097). Confidential information can be exposed externally.
CVE-2026-19423 Privilege Escalation in wordpress (CVE-2026-19423)
vulnerability in wordpress (CVE-2026-19423). Successful exploitation can lead to full system takeover.
CVE-2026-19084 Vulnerability in wordpress (CVE-2026-19084)
vulnerability in wordpress (CVE-2026-19084). Confidential information can be exposed externally.
CVE-2026-14558 Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
CVE-2026-76053 Cross-Site Scripting (XSS) in wordpress (CVE-2026-76053)
cross-site scripting in wordpress (CVE-2026-76053). Risk of unauthorized operations or information disclosure.
CVE-2026-77365 Cross-Site Scripting (XSS) in wordpress (CVE-2026-77365)
cross-site scripting in wordpress (CVE-2026-77365). Risk of unauthorized operations or information disclosure.
CVE-2026-18983 Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
CVE-2026-18324 Cross-Site Scripting (XSS) in wordpress (CVE-2026-18324)
cross-site scripting in wordpress (CVE-2026-18324). Risk of unauthorized operations or information disclosure.
CVE-2026-18978 Cross-Site Scripting (XSS) in wordpress (CVE-2026-18978)
cross-site scripting in wordpress (CVE-2026-18978). Risk of unauthorized operations or information disclosure.
CVE-2026-82072 Out-of-Bounds Read in google (CVE-2026-82072)
vulnerability in google (CVE-2026-82072). Successful exploitation can lead to full system takeover.
CVE-2026-75417 SQL Injection in sqli (CVE-2026-75417)
SQL injection in sqli (CVE-2026-75417). Successful exploitation can lead to full system takeover.
CVE-2026-81730 Path Traversal in CVE-2026-81730 (CVE-2026-81730)
path traversal in CVE-2026-81730 (CVE-2026-81730). Data can be tampered with by attackers.
CVE-2026-81728 SQL Injection in sqli (CVE-2026-81728)
SQL injection in sqli (CVE-2026-81728). Confidential information can be exposed externally.
CVE-2026-81525 Vulnerability in CVE-2026-81525 (CVE-2026-81525)
vulnerability in CVE-2026-81525 (CVE-2026-81525). Confidential information can be exposed externally.
CVE-2026-54718 Vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718)
vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.1` or later.
CVE-2026-78276 Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78257 Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
CVE-2026-75005 Vulnerability in apache (CVE-2026-75005)
vulnerability in apache (CVE-2026-75005). Risk of unauthorized operations or information disclosure.
CVE-2026-32564 Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
CVE-2026-78333 Cross-Site Scripting (XSS) in wordpress (CVE-2026-78333)
cross-site scripting in wordpress (CVE-2026-78333). Successful exploitation can lead to full system takeover.
CVE-2026-77018 Unrestricted File Upload in wordpress (CVE-2026-77018)
vulnerability in wordpress (CVE-2026-77018). Successful exploitation can lead to full system takeover.
CVE-2026-78137 Vulnerability in wordpress (CVE-2026-78137)
vulnerability in wordpress (CVE-2026-78137). Data can be tampered with by attackers.
CVE-2026-77017 Information Disclosure in wordpress (CVE-2026-77017)
vulnerability in wordpress (CVE-2026-77017). Confidential information can be exposed externally.
CVE-2026-13415 Privilege Escalation in wordpress (CVE-2026-13415)
vulnerability in wordpress (CVE-2026-13415). Successful exploitation can lead to full system takeover.
CVE-2026-19223 Code Injection in wordpress (CVE-2026-19223)
code injection in wordpress (CVE-2026-19223). Successful exploitation can lead to full system takeover.
CVE-2026-19715 Information Disclosure in wordpress (CVE-2026-19715)
vulnerability in wordpress (CVE-2026-19715). Confidential information can be exposed externally.
CVE-2026-47851 Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
CVE-2026-81203 Vulnerability in sqli (CVE-2026-81203)
vulnerability in sqli (CVE-2026-81203). Risk of unauthorized operations or information disclosure.
CVE-2026-81202 Authentication Bypass in CVE-2026-81202 (CVE-2026-81202)
authentication bypass in CVE-2026-81202 (CVE-2026-81202). Risk of unauthorized operations or information disclosure.
CVE-2026-75328 Path Traversal in CVE-2026-75328 (CVE-2026-75328)
path traversal in CVE-2026-75328 (CVE-2026-75328). Confidential information can be exposed externally.
CVE-2026-79938 Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication...
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication...
CVE-2026-74770 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
CVE-2026-68863 Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
CVE-2026-68861 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
CVE-2026-71171 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
CVE-2026-54550 Path Traversal in org.codehaus.izpack:izpack-installer (CVE-2026-54550)
path traversal in org.codehaus.izpack:izpack-installer (CVE-2026-54550). Data can be tampered with by attackers. Exploitable via ``targetPath``.
CVE-2026-15990 Path Traversal in wordpress (CVE-2026-15990)
path traversal in wordpress (CVE-2026-15990). Confidential information can be exposed externally.
CVE-2026-63041 Vulnerability in apache (CVE-2026-63041)
vulnerability in apache (CVE-2026-63041). Successful exploitation can lead to full system takeover.
CVE-2026-15985 Vulnerability in wordpress (CVE-2026-15985)
vulnerability in wordpress (CVE-2026-15985). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →