Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73531 |
|
Cross-Site Scripting (XSS) in django (CVE-2026-73531)
cross-site scripting in django (CVE-2026-73531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18428 |
|
Vulnerability in Amazon aws (CVE-2026-18428)
vulnerability in Amazon aws (CVE-2026-18428). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66256 |
|
Unsafe Deserialization in apache (CVE-2026-66256)
vulnerability in apache (CVE-2026-66256). Successful exploitation can lead to full system takeover.
|
| CVE-2026-28154 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-28154)
cross-site scripting in wordpress (CVE-2026-28154). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67990 |
|
Cross-Site Request Forgery (CSRF) in rails (CVE-2026-67990)
vulnerability in rails (CVE-2026-67990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66426 |
|
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.
|
| CVE-2026-55088 |
|
Information Disclosure in ep_etherpad-lite (CVE-2026-55088)
vulnerability in ep_etherpad-lite (CVE-2026-55088). Confidential information can be exposed externally. Exploitable via ``prefsHttp``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-55087 |
|
Cross-Site Scripting (XSS) in ep_etherpad-lite (CVE-2026-55087)
cross-site scripting in ep_etherpad-lite (CVE-2026-55087). Risk of unauthorized operations or information disclosure. Exploitable via ``String.prototype.replaceAll``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-15413 |
|
Vulnerability in wordpress (CVE-2026-15413)
vulnerability in wordpress (CVE-2026-15413). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14332 |
|
Vulnerability in wordpress (CVE-2026-14332)
vulnerability in wordpress (CVE-2026-14332). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3639 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-3639)
cross-site scripting in wordpress (CVE-2026-3639). Risk of unauthorized operations or information disclosure. Exploitable via ``ppwp``.
|
| CVE-2026-18146 |
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
| CVE-2026-3835 |
|
Vulnerability in wordpress (CVE-2026-3835)
vulnerability in wordpress (CVE-2026-3835). Risk of unauthorized operations or information disclosure. Exploitable via ``LIKE``.
|
| CVE-2026-19088 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-19088)
vulnerability in wordpress (CVE-2026-19088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14182 |
|
Authentication Bypass in wordpress (CVE-2026-14182)
authentication bypass in wordpress (CVE-2026-14182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13328 |
|
Vulnerability in wordpress (CVE-2026-13328)
vulnerability in wordpress (CVE-2026-13328). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18945 |
|
Vulnerability in wordpress (CVE-2026-18945)
vulnerability in wordpress (CVE-2026-18945). Data can be tampered with by attackers.
|
| CVE-2026-13610 |
|
Privilege Escalation in wordpress (CVE-2026-13610)
vulnerability in wordpress (CVE-2026-13610). Confidential information can be exposed externally.
|
| CVE-2026-14213 |
|
Vulnerability in wordpress (CVE-2026-14213)
vulnerability in wordpress (CVE-2026-14213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73330 |
|
Vulnerability in rails (CVE-2026-73330)
vulnerability in rails (CVE-2026-73330). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49466 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-49466)
cross-site scripting in wordpress (CVE-2026-49466). Risk of unauthorized operations or information disclosure. Exploitable via ``template``.
|
| CVE-2026-73240 |
|
Vulnerability in apache (CVE-2026-73240)
vulnerability in apache (CVE-2026-73240). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73238 |
|
Vulnerability in apache (CVE-2026-73238)
vulnerability in apache (CVE-2026-73238). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73239 |
|
Vulnerability in apache (CVE-2026-73239)
vulnerability in apache (CVE-2026-73239). Confidential information can be exposed externally.
|
| CVE-2026-73237 |
|
Vulnerability in apache (CVE-2026-73237)
vulnerability in apache (CVE-2026-73237). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68971 |
|
Vulnerability in apache (CVE-2026-68971)
vulnerability in apache (CVE-2026-68971). Confidential information can be exposed externally. Exploitable via `POST /api/v2/assets/{asset_id}/materialize`.
|
| CVE-2026-68970 |
|
Vulnerability in apache (CVE-2026-68970)
vulnerability in apache (CVE-2026-68970). Confidential information can be exposed externally.
|
| CVE-2026-68969 |
|
Vulnerability in apache (CVE-2026-68969)
vulnerability in apache (CVE-2026-68969). Confidential information can be exposed externally. Exploitable via `PATCH /api/v2/variables`.
|
| CVE-2026-68968 |
|
Vulnerability in apache (CVE-2026-68968)
vulnerability in apache (CVE-2026-68968). Confidential information can be exposed externally. Exploitable via ``backfill_id``.
|
| CVE-2026-68076 |
|
Vulnerability in apache (CVE-2026-68076)
vulnerability in apache (CVE-2026-68076). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v2/connections/test`.
|
| CVE-2026-67587 |
|
Unsafe Deserialization in apache (CVE-2026-67587)
vulnerability in apache (CVE-2026-67587). Successful exploitation can lead to full system takeover. Exploitable via ``Callback``.
|
| CVE-2026-67260 |
|
Unsafe Deserialization in apache (CVE-2026-67260)
vulnerability in apache (CVE-2026-67260). Risk of unauthorized operations or information disclosure. Exploitable via ``awaiting_input``.
|
| CVE-2026-65017 |
|
Information Disclosure in apache (CVE-2026-65017)
vulnerability in apache (CVE-2026-65017). Confidential information can be exposed externally.
|
| CVE-2026-59244 |
|
Vulnerability in apache (CVE-2026-59244)
vulnerability in apache (CVE-2026-59244). Confidential information can be exposed externally.
|
| CVE-2026-59242 |
|
Unsafe Deserialization in apache (CVE-2026-59242)
vulnerability in apache (CVE-2026-59242). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v2/{...}/xcomEntries/{key}`.
|
| CVE-2026-58076 |
|
Unsafe Deserialization in apache (CVE-2026-58076)
vulnerability in apache (CVE-2026-58076). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v2/dags/{dag_id}/details`.
|
| CVE-2026-54183 |
|
Information Disclosure in apache (CVE-2026-54183)
vulnerability in apache (CVE-2026-54183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35445 |
|
Vulnerability in winter/wn-backend-module (CVE-2026-35445)
vulnerability in winter/wn-backend-module (CVE-2026-35445). Risk of unauthorized operations or information disclosure. Exploitable via ``_handler``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32639 |
|
Vulnerability in winter/wn-cms-module (CVE-2026-32639)
vulnerability in winter/wn-cms-module (CVE-2026-32639). Confidential information can be exposed externally. Exploitable via ``cms.manage_pages``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32593 |
|
SQL Injection in winter/wn-backend-module (CVE-2026-32593)
SQL injection in winter/wn-backend-module (CVE-2026-32593). Confidential information can be exposed externally. Exploitable via ``numberrange``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32258 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32258)
cross-site scripting in winter/wn-backend-module (CVE-2026-32258). Confidential information can be exposed externally. Exploitable via ``backend.manage_editor``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-32257 |
|
Cross-Site Scripting (XSS) in winter/wn-backend-module (CVE-2026-32257)
cross-site scripting in winter/wn-backend-module (CVE-2026-32257). Confidential information can be exposed externally. Exploitable via ``backend.manage_branding``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-16990 |
|
Vulnerability in wordpress (CVE-2026-16990)
vulnerability in wordpress (CVE-2026-16990). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16747 |
|
Vulnerability in wordpress (CVE-2026-16747)
vulnerability in wordpress (CVE-2026-16747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15213 |
|
Vulnerability in wordpress (CVE-2026-15213)
vulnerability in wordpress (CVE-2026-15213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18044 |
|
Vulnerability in wordpress (CVE-2026-18044)
vulnerability in wordpress (CVE-2026-18044). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16621 |
|
Vulnerability in c (CVE-2026-16621)
vulnerability in c (CVE-2026-16621). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17008 |
|
Vulnerability in wordpress (CVE-2026-17008)
vulnerability in wordpress (CVE-2026-17008). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15045 |
|
Vulnerability in wordpress (CVE-2026-15045)
vulnerability in wordpress (CVE-2026-15045). Data can be tampered with by attackers.
|
| CVE-2026-68868 |
|
Vulnerability in apache (CVE-2026-68868)
vulnerability in apache (CVE-2026-68868). Confidential information can be exposed externally. Exploitable via ``team_name``.
|