Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75807 |
|
Authentication Bypass in wordpress (CVE-2026-75807)
authentication bypass in wordpress (CVE-2026-75807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6176 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6176)
cross-site scripting in wordpress (CVE-2026-6176). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5934 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5934)
cross-site scripting in wordpress (CVE-2026-5934). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79996 |
|
Privilege Escalation in wordpress (CVE-2026-79996)
vulnerability in wordpress (CVE-2026-79996). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5097 |
|
SQL Injection in wordpress (CVE-2026-5097)
SQL injection in wordpress (CVE-2026-5097). Confidential information can be exposed externally.
|
| CVE-2026-6286 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14558 |
|
Unsafe Deserialization in wordpress (CVE-2026-14558)
vulnerability in wordpress (CVE-2026-14558). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19084 |
|
Vulnerability in wordpress (CVE-2026-19084)
vulnerability in wordpress (CVE-2026-19084). Confidential information can be exposed externally.
|
| CVE-2026-19423 |
|
Privilege Escalation in wordpress (CVE-2026-19423)
vulnerability in wordpress (CVE-2026-19423). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76053 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76053)
cross-site scripting in wordpress (CVE-2026-76053). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77365 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-77365)
cross-site scripting in wordpress (CVE-2026-77365). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18983 |
|
Unrestricted File Upload in wordpress (CVE-2026-18983)
vulnerability in wordpress (CVE-2026-18983). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18324 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18324)
cross-site scripting in wordpress (CVE-2026-18324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18978 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18978)
cross-site scripting in wordpress (CVE-2026-18978). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59282 |
|
Vulnerability in spring (CVE-2026-59282)
vulnerability in spring (CVE-2026-59282). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80208 |
|
Vulnerability in nginx (CVE-2026-80208)
vulnerability in nginx (CVE-2026-80208). Data can be tampered with by attackers.
|
| CVE-2026-75005 |
|
Vulnerability in apache (CVE-2026-75005)
vulnerability in apache (CVE-2026-75005). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32564 |
|
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
|
| CVE-2026-78333 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-78333)
cross-site scripting in wordpress (CVE-2026-78333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77018 |
|
Unrestricted File Upload in wordpress (CVE-2026-77018)
vulnerability in wordpress (CVE-2026-77018). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78137 |
|
Vulnerability in wordpress (CVE-2026-78137)
vulnerability in wordpress (CVE-2026-78137). Data can be tampered with by attackers.
|
| CVE-2026-77017 |
|
Information Disclosure in wordpress (CVE-2026-77017)
vulnerability in wordpress (CVE-2026-77017). Confidential information can be exposed externally.
|
| CVE-2026-47893 |
|
Vulnerability in spring (CVE-2026-47893)
vulnerability in spring (CVE-2026-47893). Confidential information can be exposed externally.
|
| CVE-2026-19715 |
|
Information Disclosure in wordpress (CVE-2026-19715)
vulnerability in wordpress (CVE-2026-19715). Confidential information can be exposed externally.
|
| CVE-2026-13415 |
|
Privilege Escalation in wordpress (CVE-2026-13415)
vulnerability in wordpress (CVE-2026-13415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19223 |
|
Code Injection in wordpress (CVE-2026-19223)
code injection in wordpress (CVE-2026-19223). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47885 |
|
Vulnerability in spring (CVE-2026-47885)
vulnerability in spring (CVE-2026-47885). Data can be tampered with by attackers.
|
| CVE-2026-47886 |
|
Vulnerability in spring (CVE-2026-47886)
vulnerability in spring (CVE-2026-47886). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47889 |
|
Vulnerability in spring (CVE-2026-47889)
vulnerability in spring (CVE-2026-47889). Confidential information can be exposed externally.
|
| CVE-2026-47888 |
|
Vulnerability in spring (CVE-2026-47888)
vulnerability in spring (CVE-2026-47888). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-47852 |
|
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a...
|
| CVE-2026-47851 |
|
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError...
|
| CVE-2026-80426 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-80426)
cross-site scripting in react (CVE-2026-80426). Confidential information can be exposed externally.
|
| CVE-2026-15990 |
|
Path Traversal in wordpress (CVE-2026-15990)
path traversal in wordpress (CVE-2026-15990). Confidential information can be exposed externally.
|
| CVE-2026-63041 |
|
Vulnerability in apache (CVE-2026-63041)
vulnerability in apache (CVE-2026-63041). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15985 |
|
Vulnerability in wordpress (CVE-2026-15985)
vulnerability in wordpress (CVE-2026-15985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75977 |
|
Privilege Escalation in wordpress (CVE-2026-75977)
vulnerability in wordpress (CVE-2026-75977). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18884 |
|
SQL Injection in wordpress (CVE-2026-18884)
SQL injection in wordpress (CVE-2026-18884). Confidential information can be exposed externally.
|
| CVE-2026-18331 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18331)
cross-site scripting in wordpress (CVE-2026-18331). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77693 |
|
Vulnerability in wordpress (CVE-2026-77693)
vulnerability in wordpress (CVE-2026-77693). Data can be tampered with by attackers.
|
| CVE-2026-75797 |
|
Path Traversal in wordpress (CVE-2026-75797)
path traversal in wordpress (CVE-2026-75797). Confidential information can be exposed externally.
|
| CVE-2026-74851 |
|
Code Injection in wordpress (CVE-2026-74851)
code injection in wordpress (CVE-2026-74851). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19760 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19760)
cross-site scripting in wordpress (CVE-2026-19760). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`.
|
| CVE-2026-74928 |
|
Vulnerability in wordpress (CVE-2026-74928)
vulnerability in wordpress (CVE-2026-74928). Data can be tampered with by attackers.
|
| CVE-2026-19718 |
|
Authentication Bypass in wordpress (CVE-2026-19718)
authentication bypass in wordpress (CVE-2026-19718). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18985 |
|
Authorization Flaw in drupal (CVE-2026-18985)
vulnerability in drupal (CVE-2026-18985). Confidential information can be exposed externally.
|
| CVE-2026-18259 |
|
Vulnerability in drupal (CVE-2026-18259)
vulnerability in drupal (CVE-2026-18259). Confidential information can be exposed externally.
|
| CVE-2026-68763 |
|
Vulnerability in apache (CVE-2026-68763)
vulnerability in apache (CVE-2026-68763). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65183 |
|
Vulnerability in apache (CVE-2026-65183)
vulnerability in apache (CVE-2026-65183). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66422 |
|
Vulnerability in apache (CVE-2026-66422)
vulnerability in apache (CVE-2026-66422). Data can be tampered with by attackers.
|