Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-68745 |
|
Vulnerability in apache (CVE-2026-68745)
vulnerability in apache (CVE-2026-68745). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66797 |
|
Vulnerability in apache (CVE-2026-66797)
vulnerability in apache (CVE-2026-66797). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62440 |
|
Vulnerability in apache (CVE-2026-62440)
vulnerability in apache (CVE-2026-62440). Confidential information can be exposed externally.
|
| CVE-2026-63046 |
|
Vulnerability in apache (CVE-2026-63046)
vulnerability in apache (CVE-2026-63046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66721 |
|
Vulnerability in apache (CVE-2026-66721)
vulnerability in apache (CVE-2026-66721). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65613 |
|
Information Disclosure in apache (CVE-2026-65613)
vulnerability in apache (CVE-2026-65613). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61422 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-61422)
SSRF in apache (CVE-2026-61422). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50222 |
|
Information Disclosure in apache (CVE-2026-50222)
vulnerability in apache (CVE-2026-50222). Confidential information can be exposed externally.
|
| CVE-2026-61397 |
|
Information Disclosure in apache (CVE-2026-61397)
vulnerability in apache (CVE-2026-61397). Confidential information can be exposed externally.
|
| CVE-2026-59780 |
|
Information Disclosure in apache (CVE-2026-59780)
vulnerability in apache (CVE-2026-59780). Confidential information can be exposed externally.
|
| CVE-2026-61399 |
|
Vulnerability in apache (CVE-2026-61399)
vulnerability in apache (CVE-2026-61399). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61398 |
|
Vulnerability in apache (CVE-2026-61398)
vulnerability in apache (CVE-2026-61398). Confidential information can be exposed externally.
|
| CVE-2026-59799 |
|
Privilege Escalation in apache (CVE-2026-59799)
vulnerability in apache (CVE-2026-59799). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59655 |
|
Information Disclosure in apache (CVE-2026-59655)
vulnerability in apache (CVE-2026-59655). Confidential information can be exposed externally.
|
| CVE-2026-59085 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-59085)
SSRF in apache (CVE-2026-59085). Confidential information can be exposed externally.
|
| CVE-2026-59657 |
|
Vulnerability in apache (CVE-2026-59657)
vulnerability in apache (CVE-2026-59657). Confidential information can be exposed externally.
|
| CVE-2026-61400 |
|
Command Injection in apache (CVE-2026-61400)
command injection in apache (CVE-2026-61400). Successful exploitation can lead to full system takeover. Exploitable via ``getDiagnosticsData``.
|
| CVE-2026-47359 |
|
OS Command Injection in apache (CVE-2026-47359)
OS command injection in apache (CVE-2026-47359). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50112 |
|
OS Command Injection in apache (CVE-2026-50112)
OS command injection in apache (CVE-2026-50112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77264 |
|
Vulnerability in wordpress (CVE-2026-77264)
vulnerability in wordpress (CVE-2026-77264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16962 |
|
Vulnerability in wordpress (CVE-2026-16962)
vulnerability in wordpress (CVE-2026-16962). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18781 |
|
Code Injection in wordpress (CVE-2026-18781)
code injection in wordpress (CVE-2026-18781). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19085 |
|
Vulnerability in wordpress (CVE-2026-19085)
vulnerability in wordpress (CVE-2026-19085). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19435 |
|
Information Disclosure in wordpress (CVE-2026-19435)
vulnerability in wordpress (CVE-2026-19435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75796 |
|
Privilege Escalation in wordpress (CVE-2026-75796)
vulnerability in wordpress (CVE-2026-75796). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13736 |
|
Vulnerability in wordpress (CVE-2026-13736)
vulnerability in wordpress (CVE-2026-13736). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14325 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14325)
cross-site scripting in wordpress (CVE-2026-14325). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14601 |
|
SQL Injection in wordpress (CVE-2026-14601)
SQL injection in wordpress (CVE-2026-14601). Confidential information can be exposed externally.
|
| CVE-2026-16575 |
|
Information Disclosure in wordpress (CVE-2026-16575)
vulnerability in wordpress (CVE-2026-16575). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16576 |
|
Vulnerability in wordpress (CVE-2026-16576)
vulnerability in wordpress (CVE-2026-16576). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16577 |
|
Authorization Flaw in wordpress (CVE-2026-16577)
vulnerability in wordpress (CVE-2026-16577). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16959 |
|
SQL Injection in wordpress (CVE-2026-16959)
SQL injection in wordpress (CVE-2026-16959). Confidential information can be exposed externally.
|
| CVE-2025-15671 |
|
Authentication Bypass in wordpress (CVE-2025-15671)
authentication bypass in wordpress (CVE-2025-15671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18409 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18409)
cross-site scripting in wordpress (CVE-2026-18409). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65770 |
|
Vulnerability in apache (CVE-2026-65770)
vulnerability in apache (CVE-2026-65770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67446 |
|
Vulnerability in vue (CVE-2026-67446)
vulnerability in vue (CVE-2026-67446). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/message/{id}/part/{partID}/thumb`.
|
| CVE-2026-63179 |
|
Path Traversal in winter/wn-backend-module (CVE-2026-63179)
path traversal in winter/wn-backend-module (CVE-2026-63179). Confidential information can be exposed externally. Exploitable via ``BrandSetting.custom_css``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-61663 |
|
Vulnerability in django-cms (CVE-2026-61663)
vulnerability in django-cms (CVE-2026-61663). Risk of unauthorized operations or information disclosure. Exploitable via ``PageContent``. Mitigation: upgrade to `5.0.9` or later.
|
| CVE-2026-63003 |
|
Vulnerability in django-cms (CVE-2026-63003)
vulnerability in django-cms (CVE-2026-63003). Confidential information can be exposed externally. Exploitable via `POST /admin/cms/pagecontent/`. Mitigation: upgrade to `5.0.9` or later.
|
| CVE-2026-75526 |
|
Cross-Site Scripting (XSS) in django-cms (CVE-2026-75526)
cross-site scripting in django-cms (CVE-2026-75526). Risk of unauthorized operations or information disclosure. Exploitable via ``message``. Mitigation: upgrade to `5.0.9` or later.
|
| CVE-2026-55468 |
|
Vulnerability in wagtail (CVE-2026-55468)
vulnerability in wagtail (CVE-2026-55468). Risk of unauthorized operations or information disclosure. Exploitable via ``api_fields``. Mitigation: upgrade to `8.0rc2` or later.
|
| CVE-2026-54624 |
|
Vulnerability in django-cms (CVE-2026-54624)
vulnerability in django-cms (CVE-2026-54624). Confidential information can be exposed externally. Exploitable via ``render_object_structure``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-54622 |
|
Vulnerability in django-cms (CVE-2026-54622)
vulnerability in django-cms (CVE-2026-54622). Confidential information can be exposed externally. Exploitable via ``copy_plugins``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-54256 |
|
Vulnerability in winter/wn-backend-module (CVE-2026-54256)
vulnerability in winter/wn-backend-module (CVE-2026-54256). Risk of unauthorized operations or information disclosure. Exploitable via ``FileUpload``. Mitigation: upgrade to `1.2.13` or later.
|
| CVE-2026-54625 |
|
Vulnerability in django-cms (CVE-2026-54625)
vulnerability in django-cms (CVE-2026-54625). Risk of unauthorized operations or information disclosure. Exploitable via ``Vary``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-54623 |
|
Vulnerability in django-cms (CVE-2026-54623)
vulnerability in django-cms (CVE-2026-54623). Risk of unauthorized operations or information disclosure. Exploitable via ``move_plugin``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-63043 |
|
Vulnerability in apache (CVE-2026-63043)
vulnerability in apache (CVE-2026-63043). Confidential information can be exposed externally.
|
| CVE-2026-63044 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-63044)
SSRF in apache (CVE-2026-63044). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63042 |
|
Vulnerability in apache (CVE-2026-63042)
vulnerability in apache (CVE-2026-63042). Data can be tampered with by attackers.
|
| CVE-2026-63040 |
|
Vulnerability in apache (CVE-2026-63040)
vulnerability in apache (CVE-2026-63040). Data can be tampered with by attackers.
|