Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14825 |
|
Vulnerability in wordpress (CVE-2026-14825)
vulnerability in wordpress (CVE-2026-14825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16058 |
|
Vulnerability in wordpress (CVE-2026-16058)
vulnerability in wordpress (CVE-2026-16058). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14334 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14334)
cross-site scripting in wordpress (CVE-2026-14334). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16616 |
|
Path Traversal in wordpress (CVE-2026-16616)
path traversal in wordpress (CVE-2026-16616). Confidential information can be exposed externally.
|
| CVE-2026-14287 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14287)
cross-site scripting in wordpress (CVE-2026-14287). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13174 |
|
Vulnerability in wordpress (CVE-2026-13174)
vulnerability in wordpress (CVE-2026-13174). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14826 |
|
Vulnerability in wordpress (CVE-2026-14826)
vulnerability in wordpress (CVE-2026-14826). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13175 |
|
Vulnerability in wordpress (CVE-2026-13175)
vulnerability in wordpress (CVE-2026-13175). Data can be tampered with by attackers.
|
| CVE-2026-14196 |
|
Vulnerability in wordpress (CVE-2026-14196)
vulnerability in wordpress (CVE-2026-14196). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15253 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15253)
cross-site scripting in wordpress (CVE-2026-15253). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12983 |
|
SQL Injection in wordpress (CVE-2026-12983)
SQL injection in wordpress (CVE-2026-12983). Confidential information can be exposed externally.
|
| CVE-2026-13173 |
|
Vulnerability in wordpress (CVE-2026-13173)
vulnerability in wordpress (CVE-2026-13173). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11565 |
|
Vulnerability in wordpress (CVE-2026-11565)
vulnerability in wordpress (CVE-2026-11565). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13169 |
|
Vulnerability in wordpress (CVE-2026-13169)
vulnerability in wordpress (CVE-2026-13169). Confidential information can be exposed externally.
|
| CVE-2026-19942 |
|
Path Traversal in wordpress (CVE-2026-19942)
path traversal in wordpress (CVE-2026-19942). Data can be tampered with by attackers.
|
| CVE-2026-15421 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15421)
cross-site scripting in wordpress (CVE-2026-15421). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-11729 |
|
Vulnerability in wordpress (CVE-2025-11729)
vulnerability in wordpress (CVE-2025-11729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66602 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-66602)
vulnerability in wordpress (CVE-2026-66602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73529 |
|
Vulnerability in laravel (CVE-2026-73529)
vulnerability in laravel (CVE-2026-73529). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/sessions`.
|
| CVE-2026-19670 |
|
Authorization Flaw in nginx (CVE-2026-19670)
vulnerability in nginx (CVE-2026-19670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68923 |
|
Cross-Site Request Forgery (CSRF) in mobsf (CVE-2026-68923)
vulnerability in mobsf (CVE-2026-68923). Data can be tampered with by attackers. Exploitable via ``CsrfViewMiddleware``. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-63642 |
|
SSRF (Server-Side Request Forgery) in magicmirror (CVE-2026-63642)
SSRF in magicmirror (CVE-2026-63642). Risk of unauthorized operations or information disclosure. Exploitable via ``CHECK_ARTICLE_URL``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-63641 |
|
Vulnerability in magicmirror (CVE-2026-63641)
vulnerability in magicmirror (CVE-2026-63641). Risk of unauthorized operations or information disclosure. Exploitable via ``ipWhitelist``. Mitigation: upgrade to `2.37.0` or later.
|
| CVE-2026-12564 |
|
SSRF (Server-Side Request Forgery) in django (CVE-2026-12564)
SSRF in django (CVE-2026-12564). Confidential information can be exposed externally.
|
| CVE-2026-75784 |
|
Buffer Overflow in nginx (CVE-2026-75784)
vulnerability in nginx (CVE-2026-75784). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73351 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-73351)
cross-site scripting in wordpress (CVE-2026-73351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34884 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-34884)
SSRF in apache (CVE-2026-34884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75091 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-75091)
cross-site scripting in wordpress (CVE-2026-75091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15748 |
|
Unrestricted File Upload in wordpress (CVE-2026-15748)
vulnerability in wordpress (CVE-2026-15748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11801 |
|
Vulnerability in wordpress (CVE-2026-11801)
vulnerability in wordpress (CVE-2026-11801). Confidential information can be exposed externally.
|
| CVE-2026-75529 |
|
Cross-Site Scripting (XSS) in flask (CVE-2026-75529)
cross-site scripting in flask (CVE-2026-75529). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65640 |
|
Unrestricted File Upload in wordpress (CVE-2026-65640)
vulnerability in wordpress (CVE-2026-65640). Successful exploitation can lead to full system takeover. Exploitable via ``upload_files``.
|
| CVE-2026-13700 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-13700)
SSRF in wordpress (CVE-2026-13700). Confidential information can be exposed externally.
|
| CVE-2026-14832 |
|
Vulnerability in wordpress (CVE-2026-14832)
vulnerability in wordpress (CVE-2026-14832). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-13784 |
|
Unsafe Deserialization in wordpress (CVE-2024-13784)
vulnerability in wordpress (CVE-2024-13784). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2497 |
|
SQL Injection in wordpress (CVE-2026-2497)
SQL injection in wordpress (CVE-2026-2497). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2357 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2357)
cross-site scripting in wordpress (CVE-2026-2357). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18347 |
|
Vulnerability in wordpress (CVE-2026-18347)
vulnerability in wordpress (CVE-2026-18347). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17608 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-17608)
vulnerability in wordpress (CVE-2026-17608). Data can be tampered with by attackers.
|
| CVE-2026-17604 |
|
Path Traversal in wordpress (CVE-2026-17604)
path traversal in wordpress (CVE-2026-17604). Confidential information can be exposed externally.
|
| CVE-2026-17087 |
|
Vulnerability in wordpress (CVE-2026-17087)
vulnerability in wordpress (CVE-2026-17087). Confidential information can be exposed externally.
|
| CVE-2026-13424 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13424)
cross-site scripting in wordpress (CVE-2026-13424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12998 |
|
Vulnerability in wordpress (CVE-2026-12998)
vulnerability in wordpress (CVE-2026-12998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10734 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10734)
cross-site scripting in wordpress (CVE-2026-10734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19717 |
|
Information Disclosure in wordpress (CVE-2026-19717)
vulnerability in wordpress (CVE-2026-19717). Confidential information can be exposed externally.
|
| CVE-2026-2283 |
|
SQL Injection in wordpress (CVE-2026-2283)
SQL injection in wordpress (CVE-2026-2283). Confidential information can be exposed externally.
|
| CVE-2026-19726 |
|
Authorization Flaw in wordpress (CVE-2026-19726)
vulnerability in wordpress (CVE-2026-19726). Confidential information can be exposed externally.
|
| CVE-2026-18402 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18402)
cross-site scripting in wordpress (CVE-2026-18402). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19725 |
|
Path Traversal in wordpress (CVE-2026-19725)
path traversal in wordpress (CVE-2026-19725). Confidential information can be exposed externally.
|
| CVE-2026-9767 |
|
SQL Injection in wordpress (CVE-2026-9767)
SQL injection in wordpress (CVE-2026-9767). Confidential information can be exposed externally.
|