Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: web-frameworks Clear
ID Title
CVE-2026-15369 Privilege Escalation in wordpress (CVE-2026-15369)
vulnerability in wordpress (CVE-2026-15369). Successful exploitation can lead to full system takeover.
CVE-2026-14494 Unrestricted File Upload in wordpress (CVE-2026-14494)
vulnerability in wordpress (CVE-2026-14494). Successful exploitation can lead to full system takeover.
CVE-2026-77012 Vulnerability in wordpress (CVE-2026-77012)
vulnerability in wordpress (CVE-2026-77012). Risk of unauthorized operations or information disclosure.
CVE-2026-16947 Vulnerability in wordpress (CVE-2026-16947)
vulnerability in wordpress (CVE-2026-16947). Risk of unauthorized operations or information disclosure.
CVE-2026-16259 Vulnerability in wordpress (CVE-2026-16259)
vulnerability in wordpress (CVE-2026-16259). Risk of unauthorized operations or information disclosure.
CVE-2026-76581 Vulnerability in wordpress (CVE-2026-76581)
vulnerability in wordpress (CVE-2026-76581). Successful exploitation can lead to full system takeover. Exploitable via ``wdpsso_step1``.
CVE-2026-59313 Vulnerability in spring (CVE-2026-59313)
vulnerability in spring (CVE-2026-59313). Successful exploitation can lead to full system takeover.
CVE-2026-59283 Vulnerability in spring (CVE-2026-59283)
vulnerability in spring (CVE-2026-59283). Data can be tampered with by attackers.
CVE-2026-19092 Vulnerability in wordpress (CVE-2026-19092)
vulnerability in wordpress (CVE-2026-19092). Successful exploitation can lead to full system takeover.
CVE-2026-32566 Vulnerability in wordpress (CVE-2026-32566)
vulnerability in wordpress (CVE-2026-32566). Successful exploitation can lead to full system takeover.
CVE-2026-77016 Vulnerability in wordpress (CVE-2026-77016)
vulnerability in wordpress (CVE-2026-77016). Data can be tampered with by attackers.
CVE-2026-47892 Authorization Flaw in spring (CVE-2026-47892)
vulnerability in spring (CVE-2026-47892). Successful exploitation can lead to full system takeover.
CVE-2026-47884 Path Traversal in spring (CVE-2026-47884)
path traversal in spring (CVE-2026-47884). Successful exploitation can lead to full system takeover.
CVE-2026-47890 Vulnerability in spring (CVE-2026-47890)
vulnerability in spring (CVE-2026-47890). Successful exploitation can lead to full system takeover.
CVE-2026-47891 Vulnerability in spring (CVE-2026-47891)
vulnerability in spring (CVE-2026-47891). Successful exploitation can lead to full system takeover.
CVE-2026-18080 Unrestricted File Upload in wordpress (CVE-2026-18080)
vulnerability in wordpress (CVE-2026-18080). Successful exploitation can lead to full system takeover.
CVE-2026-18431 Vulnerability in wordpress (CVE-2026-18431)
vulnerability in wordpress (CVE-2026-18431). Successful exploitation can lead to full system takeover.
CVE-2026-19632 Vulnerability in wordpress (CVE-2026-19632)
vulnerability in wordpress (CVE-2026-19632). Successful exploitation can lead to full system takeover.
CVE-2026-16639 Vulnerability in drupal (CVE-2026-16639)
vulnerability in drupal (CVE-2026-16639). Successful exploitation can lead to full system takeover.
CVE-2026-16644 Authorization Flaw in drupal (CVE-2026-16644)
vulnerability in drupal (CVE-2026-16644). Confidential information can be exposed externally.
CVE-2026-16645 Vulnerability in drupal (CVE-2026-16645)
vulnerability in drupal (CVE-2026-16645). Confidential information can be exposed externally.
CVE-2026-16641 Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
CVE-2026-65637 Vulnerability in apache (CVE-2026-65637)
vulnerability in apache (CVE-2026-65637). Successful exploitation can lead to full system takeover.
CVE-2026-65905 Vulnerability in apache (CVE-2026-65905)
vulnerability in apache (CVE-2026-65905). Successful exploitation can lead to full system takeover.
CVE-2026-65182 Vulnerability in apache (CVE-2026-65182)
vulnerability in apache (CVE-2026-65182). Confidential information can be exposed externally.
CVE-2026-68525 Authorization Flaw in apache (CVE-2026-68525)
vulnerability in apache (CVE-2026-68525). Confidential information can be exposed externally.
CVE-2026-49845 Code Injection in apache (CVE-2026-49845)
code injection in apache (CVE-2026-49845). Successful exploitation can lead to full system takeover.
CVE-2026-55976 SSRF (Server-Side Request Forgery) in apache (CVE-2026-55976)
SSRF in apache (CVE-2026-55976). Confidential information can be exposed externally.
CVE-2026-78570 Privilege Escalation in wordpress (CVE-2026-78570)
vulnerability in wordpress (CVE-2026-78570). Successful exploitation can lead to full system takeover.
CVE-2026-78568 SQL Injection in wordpress (CVE-2026-78568)
SQL injection in wordpress (CVE-2026-78568). Successful exploitation can lead to full system takeover.
CVE-2026-78477 Vulnerability in wordpress (CVE-2026-78477)
vulnerability in wordpress (CVE-2026-78477). Successful exploitation can lead to full system takeover.
CVE-2026-32563 Unsafe Deserialization in wordpress (CVE-2026-32563)
vulnerability in wordpress (CVE-2026-32563). Successful exploitation can lead to full system takeover.
CVE-2026-78329 Vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329)
vulnerability in org.apache.camel:camel-undertow (CVE-2026-78329). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.
CVE-2026-71300 Vulnerability in org.apache.camel:camel-atmosphere-websocket (CVE-2026-71300)
vulnerability in org.apache.camel:camel-atmosphere-websocket (CVE-2026-71300). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.22.0` or later.
CVE-2026-66906 Vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906)
vulnerability in org.apache.camel:camel-azure-storage-blob (CVE-2026-66906). Confidential information can be exposed externally. Mitigation: upgrade to `4.22.0` or later.
CVE-2026-32558 Vulnerability in wordpress (CVE-2026-32558)
vulnerability in wordpress (CVE-2026-32558). Successful exploitation can lead to full system takeover.
CVE-2026-21962 KEV [KEV] Vulnerability in Oracle c (CVE-2026-21962)
vulnerability in Oracle c (CVE-2026-21962). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-13598 Privilege Escalation in wordpress (CVE-2026-13598)
vulnerability in wordpress (CVE-2026-13598). Successful exploitation can lead to full system takeover.
CVE-2026-4703 Unsafe Deserialization in wordpress (CVE-2026-4703)
vulnerability in wordpress (CVE-2026-4703). Successful exploitation can lead to full system takeover.
CVE-2026-78003 SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-78003)
SSRF in wordpress (CVE-2026-78003). Successful exploitation can lead to full system takeover.
CVE-2026-77002 Authentication Bypass in wordpress (CVE-2026-77002)
authentication bypass in wordpress (CVE-2026-77002). Successful exploitation can lead to full system takeover.
CVE-2026-77001 Authentication Bypass in wordpress (CVE-2026-77001)
authentication bypass in wordpress (CVE-2026-77001). Successful exploitation can lead to full system takeover.
CVE-2026-77000 Authentication Bypass in wordpress (CVE-2026-77000)
authentication bypass in wordpress (CVE-2026-77000). Successful exploitation can lead to full system takeover.
CVE-2026-49849 Unrestricted File Upload in laravel (CVE-2026-49849)
vulnerability in laravel (CVE-2026-49849). Successful exploitation can lead to full system takeover.
CVE-2026-59085 SSRF (Server-Side Request Forgery) in apache (CVE-2026-59085)
SSRF in apache (CVE-2026-59085). Confidential information can be exposed externally.
CVE-2026-62440 Vulnerability in apache (CVE-2026-62440)
vulnerability in apache (CVE-2026-62440). Confidential information can be exposed externally.
CVE-2026-61398 Vulnerability in apache (CVE-2026-61398)
vulnerability in apache (CVE-2026-61398). Confidential information can be exposed externally.
CVE-2026-77264 Vulnerability in wordpress (CVE-2026-77264)
vulnerability in wordpress (CVE-2026-77264). Successful exploitation can lead to full system takeover.
CVE-2026-65770 Vulnerability in apache (CVE-2026-65770)
vulnerability in apache (CVE-2026-65770). Successful exploitation can lead to full system takeover.
CVE-2026-63039 SQL Injection in apache (CVE-2026-63039)
SQL injection in apache (CVE-2026-63039). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →