Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-63037 |
|
SQL Injection in apache (CVE-2026-63037)
SQL injection in apache (CVE-2026-63037). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63038 |
|
SQL Injection in apache (CVE-2026-63038)
SQL injection in apache (CVE-2026-63038). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63039 |
|
SQL Injection in apache (CVE-2026-63039)
SQL injection in apache (CVE-2026-63039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63015 |
|
Vulnerability in apache (CVE-2026-63015)
vulnerability in apache (CVE-2026-63015). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66594 |
|
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
|
| CVE-2026-66592 |
|
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
|
| CVE-2026-75963 |
|
Vulnerability in wordpress (CVE-2026-75963)
vulnerability in wordpress (CVE-2026-75963). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19699 |
|
Authorization Flaw in wordpress (CVE-2026-19699)
vulnerability in wordpress (CVE-2026-19699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13405 |
|
Code Injection in wordpress (CVE-2026-13405)
code injection in wordpress (CVE-2026-13405). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19615 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19615)
cross-site scripting in wordpress (CVE-2026-19615). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19697 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19697)
cross-site scripting in wordpress (CVE-2026-19697). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74992 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-74992)
cross-site scripting in wordpress (CVE-2026-74992). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17153 |
|
Vulnerability in wordpress (CVE-2026-17153)
vulnerability in wordpress (CVE-2026-17153). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15049 |
|
Unrestricted File Upload in wordpress (CVE-2026-15049)
vulnerability in wordpress (CVE-2026-15049). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75860 |
|
Privilege Escalation in wordpress (CVE-2026-75860)
vulnerability in wordpress (CVE-2026-75860). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76576 |
|
Path Traversal in vue (CVE-2026-76576)
path traversal in vue (CVE-2026-76576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54738 |
|
Vulnerability in nginx (CVE-2026-54738)
vulnerability in nginx (CVE-2026-54738). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v4/account/auth/register`.
|
| CVE-2026-18315 |
|
Vulnerability in wordpress (CVE-2026-18315)
vulnerability in wordpress (CVE-2026-18315). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62681 |
|
Code Injection in react (CVE-2026-62681)
code injection in react (CVE-2026-62681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64851 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-64851)
cross-site scripting in wordpress (CVE-2026-64851). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63408 |
|
Vulnerability in apache (CVE-2026-63408)
vulnerability in apache (CVE-2026-63408). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-62673 |
|
Vulnerability in getgrav/grav (CVE-2026-62673)
vulnerability in getgrav/grav (CVE-2026-62673). Risk of unauthorized operations or information disclosure. Exploitable via `GET /user/plugins/my-plugin/my-plugin.YAML`. Mitigation: upgrade to `2.0.4` or later.
|
| CVE-2026-73394 |
|
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
|
| CVE-2026-75981 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-75981)
cross-site scripting in wordpress (CVE-2026-75981). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15780 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15780)
cross-site scripting in wordpress (CVE-2026-15780). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15446 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15446)
cross-site scripting in wordpress (CVE-2026-15446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18779 |
|
Vulnerability in wordpress (CVE-2026-18779)
vulnerability in wordpress (CVE-2026-18779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18937 |
|
Code Injection in wordpress (CVE-2026-18937)
code injection in wordpress (CVE-2026-18937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19056 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-19056)
cross-site scripting in c (CVE-2026-19056). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17565 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-17565)
SSRF in wordpress (CVE-2026-17565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19406 |
|
Information Disclosure in wordpress (CVE-2026-19406)
vulnerability in wordpress (CVE-2026-19406). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19055 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19055)
cross-site scripting in wordpress (CVE-2026-19055). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19782 |
|
Information Disclosure in wordpress (CVE-2026-19782)
vulnerability in wordpress (CVE-2026-19782). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18778 |
|
Information Disclosure in wordpress (CVE-2026-18778)
vulnerability in wordpress (CVE-2026-18778). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19842 |
|
Authentication Bypass in wordpress (CVE-2026-19842)
authentication bypass in wordpress (CVE-2026-19842). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18776 |
|
Vulnerability in wordpress (CVE-2026-18776)
vulnerability in wordpress (CVE-2026-18776). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18031 |
|
Authentication Bypass in wordpress (CVE-2026-18031)
authentication bypass in wordpress (CVE-2026-18031). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19417 |
|
Vulnerability in wordpress (CVE-2026-19417)
vulnerability in wordpress (CVE-2026-19417). Confidential information can be exposed externally.
|
| CVE-2026-19416 |
|
Vulnerability in wordpress (CVE-2026-19416)
vulnerability in wordpress (CVE-2026-19416). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19709 |
|
Authentication Bypass in wordpress (CVE-2026-19709)
authentication bypass in wordpress (CVE-2026-19709). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18777 |
|
Vulnerability in wordpress (CVE-2026-18777)
vulnerability in wordpress (CVE-2026-18777). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14334 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14334)
cross-site scripting in wordpress (CVE-2026-14334). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18231 |
|
Information Disclosure in wordpress (CVE-2026-18231)
vulnerability in wordpress (CVE-2026-18231). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16616 |
|
Path Traversal in wordpress (CVE-2026-16616)
path traversal in wordpress (CVE-2026-16616). Confidential information can be exposed externally.
|
| CVE-2026-14287 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14287)
cross-site scripting in wordpress (CVE-2026-14287). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13174 |
|
Vulnerability in wordpress (CVE-2026-13174)
vulnerability in wordpress (CVE-2026-13174). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14826 |
|
Vulnerability in wordpress (CVE-2026-14826)
vulnerability in wordpress (CVE-2026-14826). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11565 |
|
Vulnerability in wordpress (CVE-2026-11565)
vulnerability in wordpress (CVE-2026-11565). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13173 |
|
Vulnerability in wordpress (CVE-2026-13173)
vulnerability in wordpress (CVE-2026-13173). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12983 |
|
SQL Injection in wordpress (CVE-2026-12983)
SQL injection in wordpress (CVE-2026-12983). Confidential information can be exposed externally.
|