Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12432 |
|
Vulnerability in wordpress (CVE-2026-12432)
vulnerability in wordpress (CVE-2026-12432). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3462 |
|
Vulnerability in wordpress (CVE-2026-3462)
vulnerability in wordpress (CVE-2026-3462). Data can be tampered with by attackers.
|
| CVE-2026-11364 |
|
Vulnerability in wordpress (CVE-2026-11364)
vulnerability in wordpress (CVE-2026-11364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13245 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13245)
cross-site scripting in wordpress (CVE-2026-13245). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12404 |
|
Vulnerability in wordpress (CVE-2026-12404)
vulnerability in wordpress (CVE-2026-12404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9677 |
|
Vulnerability in wordpress (CVE-2026-9677)
vulnerability in wordpress (CVE-2026-9677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12415 |
|
Privilege Escalation in wordpress (CVE-2026-12415)
vulnerability in wordpress (CVE-2026-12415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10820 |
|
Vulnerability in wordpress (CVE-2026-10820)
vulnerability in wordpress (CVE-2026-10820). Data can be tampered with by attackers.
|
| CVE-2026-11356 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11356)
cross-site scripting in wordpress (CVE-2026-11356). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13335 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13335)
cross-site scripting in wordpress (CVE-2026-13335). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13331 |
|
SQL Injection in wordpress (CVE-2026-13331)
SQL injection in wordpress (CVE-2026-13331). Confidential information can be exposed externally.
|
| CVE-2026-13333 |
|
SQL Injection in wordpress (CVE-2026-13333)
SQL injection in wordpress (CVE-2026-13333). Confidential information can be exposed externally.
|
| CVE-2026-13422 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-13422)
vulnerability in wordpress (CVE-2026-13422). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54244 |
|
Authorization Flaw in statamic/cms (CVE-2026-54244)
vulnerability in statamic/cms (CVE-2026-54244). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.0` or later.
|
| CVE-2026-54243 |
|
Vulnerability in statamic/cms (CVE-2026-54243)
vulnerability in statamic/cms (CVE-2026-54243). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.73.24` or later.
|
| CVE-2026-54242 |
|
Vulnerability in statamic/cms (CVE-2026-54242)
vulnerability in statamic/cms (CVE-2026-54242). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.73.24` or later.
|
| CVE-2026-52783 |
|
Vulnerability in rails (CVE-2026-52783)
vulnerability in rails (CVE-2026-52783). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-46386 |
|
Unsafe Deserialization in rails (CVE-2026-46386)
vulnerability in rails (CVE-2026-46386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56011 |
|
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
|
| CVE-2025-68063 |
|
Vulnerability in wordpress (CVE-2025-68063)
vulnerability in wordpress (CVE-2025-68063). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57915 |
|
Vulnerability in apache (CVE-2026-57915)
vulnerability in apache (CVE-2026-57915). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-64152 |
|
Path Traversal in apache (CVE-2025-64152)
path traversal in apache (CVE-2025-64152). Confidential information can be exposed externally.
|
| CVE-2025-55017 |
|
Path Traversal in apache (CVE-2025-55017)
path traversal in apache (CVE-2025-55017). Confidential information can be exposed externally.
|
| CVE-2026-57914 |
|
Vulnerability in apache (CVE-2026-57914)
vulnerability in apache (CVE-2026-57914). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1869 |
|
Vulnerability in wordpress (CVE-2026-1869)
vulnerability in wordpress (CVE-2026-1869). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-10268 |
|
Vulnerability in wordpress (CVE-2025-10268)
vulnerability in wordpress (CVE-2025-10268). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10823 |
|
Vulnerability in wordpress (CVE-2026-10823)
vulnerability in wordpress (CVE-2026-10823). Confidential information can be exposed externally.
|
| CVE-2026-8380 |
|
Vulnerability in wordpress (CVE-2026-8380)
vulnerability in wordpress (CVE-2026-8380). Data can be tampered with by attackers.
|
| CVE-2026-10835 |
|
Vulnerability in wordpress (CVE-2026-10835)
vulnerability in wordpress (CVE-2026-10835). Confidential information can be exposed externally.
|
| CVE-2026-49486 |
|
Vulnerability in apache-airflow-providers-ftp (CVE-2026-49486)
vulnerability in apache-airflow-providers-ftp (CVE-2026-49486). Confidential information can be exposed externally. Exploitable via ``ftplib.FTP_TLS``. Mitigation: upgrade to `3.15.1` or later.
|
| CVE-2026-13226 |
|
SQL Injection in wordpress (CVE-2026-13226)
SQL injection in wordpress (CVE-2026-13226). Confidential information can be exposed externally.
|
| CVE-2026-48508 |
|
Authorization Flaw in lemur (CVE-2026-48508)
vulnerability in lemur (CVE-2026-48508). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/1/authorities`. Mitigation: upgrade to `1.9.1` or later.
|
| CVE-2026-48946 |
|
Unrestricted File Upload in apache (CVE-2026-48946)
vulnerability in apache (CVE-2026-48946). Risk of unauthorized operations or information disclosure. Exploitable via ``shell.php``.
|
| CVE-2026-56091 |
|
Vulnerability in apache (CVE-2026-56091)
vulnerability in apache (CVE-2026-56091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56130 |
|
Vulnerability in apache (CVE-2026-56130)
vulnerability in apache (CVE-2026-56130). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54226 |
|
Vulnerability in apache (CVE-2026-54226)
vulnerability in apache (CVE-2026-54226). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46751 |
|
Vulnerability in apache (CVE-2026-46751)
vulnerability in apache (CVE-2026-46751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46752 |
|
Vulnerability in apache (CVE-2026-46752)
vulnerability in apache (CVE-2026-46752). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12937 |
|
SQL Injection in wordpress (CVE-2026-12937)
SQL injection in wordpress (CVE-2026-12937). Confidential information can be exposed externally.
|
| CVE-2026-5305 |
|
Vulnerability in wordpress (CVE-2026-5305)
vulnerability in wordpress (CVE-2026-5305). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10824 |
|
Vulnerability in wordpress (CVE-2026-10824)
vulnerability in wordpress (CVE-2026-10824). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9702 |
|
Vulnerability in wordpress (CVE-2026-9702)
vulnerability in wordpress (CVE-2026-9702). Data can be tampered with by attackers.
|
| CVE-2026-41566 |
|
Vulnerability in apache (CVE-2026-41566)
vulnerability in apache (CVE-2026-41566). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45188 |
|
Vulnerability in apache (CVE-2026-45188)
vulnerability in apache (CVE-2026-45188). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2508 |
|
SQL Injection in wordpress (CVE-2026-2508)
SQL injection in wordpress (CVE-2026-2508). Confidential information can be exposed externally.
|
| CVE-2026-12079 |
|
SQL Injection in wordpress (CVE-2026-12079)
SQL injection in wordpress (CVE-2026-12079). Confidential information can be exposed externally.
|
| CVE-2026-10833 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10833)
cross-site scripting in wordpress (CVE-2026-10833). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12077 |
|
SQL Injection in wordpress (CVE-2026-12077)
SQL injection in wordpress (CVE-2026-12077). Confidential information can be exposed externally.
|
| CVE-2026-53038 |
|
Out-of-Bounds Read in wordpress (CVE-2026-53038)
vulnerability in wordpress (CVE-2026-53038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12242 |
|
Code Injection in wordpress (CVE-2026-12242)
code injection in wordpress (CVE-2026-12242). Successful exploitation can lead to full system takeover.
|