Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75807 |
|
Authentication Bypass in wordpress (CVE-2026-75807)
authentication bypass in wordpress (CVE-2026-75807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82474 |
|
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
|
| CVE-2026-82450 |
|
Unrestricted File Upload in CVE-2026-82450 (CVE-2026-82450)
vulnerability in CVE-2026-82450 (CVE-2026-82450). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55848 |
|
XXE (XML External Entity) in org.mapfish.print:print-lib (CVE-2026-55848)
vulnerability in org.mapfish.print:print-lib (CVE-2026-55848). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-55841 |
|
Vulnerability in org.graylog2:graylog2-server (CVE-2026-55841)
vulnerability in org.graylog2:graylog2-server (CVE-2026-55841). Data can be tampered with by attackers. Mitigation: upgrade to `7.1.2` or later.
|
| CVE-2026-55584 |
|
Vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584)
vulnerability in phpsysinfo/phpsysinfo (CVE-2026-55584). Confidential information can be exposed externally. Exploitable via ``PSI_ALLOWED``. Mitigation: upgrade to `3.4.6` or later.
|
| CVE-2026-55552 |
|
Path Traversal in org.yamcs:yamcs-core (CVE-2026-55552)
path traversal in org.yamcs:yamcs-core (CVE-2026-55552). Confidential information can be exposed externally. Mitigation: upgrade to `5.12.0` or later.
|
| CVE-2026-6176 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6176)
cross-site scripting in wordpress (CVE-2026-6176). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5934 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5934)
cross-site scripting in wordpress (CVE-2026-5934). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79996 |
|
Privilege Escalation in wordpress (CVE-2026-79996)
vulnerability in wordpress (CVE-2026-79996). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6286 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5097 |
|
SQL Injection in wordpress (CVE-2026-5097)
SQL injection in wordpress (CVE-2026-5097). Confidential information can be exposed externally.
|
| CVE-2026-19423 |
|
Privilege Escalation in wordpress (CVE-2026-19423)
vulnerability in wordpress (CVE-2026-19423). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19084 |
|
Vulnerability in wordpress (CVE-2026-19084)
vulnerability in wordpress (CVE-2026-19084). Confidential information can be exposed externally.
|
| CVE-2026-14558 |
|
Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76053 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76053)
cross-site scripting in wordpress (CVE-2026-76053). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77365 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-77365)
cross-site scripting in wordpress (CVE-2026-77365). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18983 |
|
Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18324 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18324)
cross-site scripting in wordpress (CVE-2026-18324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18978 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18978)
cross-site scripting in wordpress (CVE-2026-18978). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82072 |
|
Out-of-Bounds Read in google (CVE-2026-82072)
vulnerability in google (CVE-2026-82072). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75417 |
|
SQL Injection in sqli (CVE-2026-75417)
SQL injection in sqli (CVE-2026-75417). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81730 |
|
Path Traversal in CVE-2026-81730 (CVE-2026-81730)
path traversal in CVE-2026-81730 (CVE-2026-81730). Data can be tampered with by attackers.
|
| CVE-2026-81728 |
|
SQL Injection in sqli (CVE-2026-81728)
SQL injection in sqli (CVE-2026-81728). Confidential information can be exposed externally.
|
| CVE-2026-81525 |
|
Vulnerability in CVE-2026-81525 (CVE-2026-81525)
vulnerability in CVE-2026-81525 (CVE-2026-81525). Confidential information can be exposed externally.
|
| CVE-2026-54718 |
|
Vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718)
vulnerability in symbiote/silverstripe-advancedworkflow (CVE-2026-54718). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.2.1` or later.
|
| CVE-2026-78276 |
|
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
|
| CVE-2026-78257 |
|
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
|
| CVE-2026-75005 |
|
Vulnerability in apache (CVE-2026-75005)
vulnerability in apache (CVE-2026-75005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32564 |
|
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
|
| CVE-2026-78333 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-78333)
cross-site scripting in wordpress (CVE-2026-78333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77018 |
|
Unrestricted File Upload in wordpress (CVE-2026-77018)
vulnerability in wordpress (CVE-2026-77018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78137 |
|
Vulnerability in wordpress (CVE-2026-78137)
vulnerability in wordpress (CVE-2026-78137). Data can be tampered with by attackers.
|
| CVE-2026-77017 |
|
Information Disclosure in wordpress (CVE-2026-77017)
vulnerability in wordpress (CVE-2026-77017). Confidential information can be exposed externally.
|
| CVE-2026-13415 |
|
Privilege Escalation in wordpress (CVE-2026-13415)
vulnerability in wordpress (CVE-2026-13415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19223 |
|
Code Injection in wordpress (CVE-2026-19223)
code injection in wordpress (CVE-2026-19223). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19715 |
|
Information Disclosure in wordpress (CVE-2026-19715)
vulnerability in wordpress (CVE-2026-19715). Confidential information can be exposed externally.
|
| CVE-2026-47851 |
|
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
|
| CVE-2026-81203 |
|
Vulnerability in sqli (CVE-2026-81203)
vulnerability in sqli (CVE-2026-81203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81202 |
|
Authentication Bypass in CVE-2026-81202 (CVE-2026-81202)
authentication bypass in CVE-2026-81202 (CVE-2026-81202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75328 |
|
Path Traversal in CVE-2026-75328 (CVE-2026-75328)
path traversal in CVE-2026-75328 (CVE-2026-75328). Confidential information can be exposed externally.
|
| CVE-2026-79938 |
|
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication...
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication...
|
| CVE-2026-74770 |
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
|
| CVE-2026-68863 |
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
|
| CVE-2026-68861 |
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
|
| CVE-2026-71171 |
|
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
|
| CVE-2026-54550 |
|
Path Traversal in org.codehaus.izpack:izpack-installer (CVE-2026-54550)
path traversal in org.codehaus.izpack:izpack-installer (CVE-2026-54550). Data can be tampered with by attackers. Exploitable via ``targetPath``.
|
| CVE-2026-15990 |
|
Path Traversal in wordpress (CVE-2026-15990)
path traversal in wordpress (CVE-2026-15990). Confidential information can be exposed externally.
|
| CVE-2026-63041 |
|
Vulnerability in apache (CVE-2026-63041)
vulnerability in apache (CVE-2026-63041). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15985 |
|
Vulnerability in wordpress (CVE-2026-15985)
vulnerability in wordpress (CVE-2026-15985). Successful exploitation can lead to full system takeover.
|