Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-50222 |
|
Information Disclosure in apache (CVE-2026-50222)
vulnerability in apache (CVE-2026-50222). Confidential information can be exposed externally.
|
| CVE-2026-63046 |
|
Vulnerability in apache (CVE-2026-63046)
vulnerability in apache (CVE-2026-63046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50112 |
|
OS Command Injection in apache (CVE-2026-50112)
OS command injection in apache (CVE-2026-50112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47359 |
|
OS Command Injection in apache (CVE-2026-47359)
OS command injection in apache (CVE-2026-47359). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75796 |
|
Privilege Escalation in wordpress (CVE-2026-75796)
vulnerability in wordpress (CVE-2026-75796). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18781 |
|
Code Injection in wordpress (CVE-2026-18781)
code injection in wordpress (CVE-2026-18781). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16576 |
|
Vulnerability in wordpress (CVE-2026-16576)
vulnerability in wordpress (CVE-2026-16576). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18409 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18409)
cross-site scripting in wordpress (CVE-2026-18409). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54623 |
|
Vulnerability in django-cms (CVE-2026-54623)
vulnerability in django-cms (CVE-2026-54623). Risk of unauthorized operations or information disclosure. Exploitable via ``move_plugin``. Mitigation: upgrade to `5.0.8` or later.
|
| CVE-2026-63043 |
|
Vulnerability in apache (CVE-2026-63043)
vulnerability in apache (CVE-2026-63043). Confidential information can be exposed externally.
|
| CVE-2026-63042 |
|
Vulnerability in apache (CVE-2026-63042)
vulnerability in apache (CVE-2026-63042). Data can be tampered with by attackers.
|
| CVE-2026-63040 |
|
Vulnerability in apache (CVE-2026-63040)
vulnerability in apache (CVE-2026-63040). Data can be tampered with by attackers.
|
| CVE-2026-66594 |
|
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
|
| CVE-2026-75963 |
|
Vulnerability in wordpress (CVE-2026-75963)
vulnerability in wordpress (CVE-2026-75963). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15049 |
|
Unrestricted File Upload in wordpress (CVE-2026-15049)
vulnerability in wordpress (CVE-2026-15049). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63408 |
|
Vulnerability in apache (CVE-2026-63408)
vulnerability in apache (CVE-2026-63408). Confidential information can be exposed externally. Exploitable via `Referer header`.
|
| CVE-2026-73394 |
|
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
|
| CVE-2026-75981 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-75981)
cross-site scripting in wordpress (CVE-2026-75981). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15780 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15780)
cross-site scripting in wordpress (CVE-2026-15780). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19842 |
|
Authentication Bypass in wordpress (CVE-2026-19842)
authentication bypass in wordpress (CVE-2026-19842). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19055 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19055)
cross-site scripting in wordpress (CVE-2026-19055). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17565 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-17565)
SSRF in wordpress (CVE-2026-17565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19056 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-19056)
cross-site scripting in c (CVE-2026-19056). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16570 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16570)
cross-site scripting in wordpress (CVE-2026-16570). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14861 |
|
Vulnerability in wordpress (CVE-2026-14861)
vulnerability in wordpress (CVE-2026-14861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16950 |
|
SQL Injection in wordpress (CVE-2026-16950)
SQL injection in wordpress (CVE-2026-16950). Confidential information can be exposed externally.
|
| CVE-2026-16617 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16617)
cross-site scripting in wordpress (CVE-2026-16617). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14334 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14334)
cross-site scripting in wordpress (CVE-2026-14334). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16616 |
|
Path Traversal in wordpress (CVE-2026-16616)
path traversal in wordpress (CVE-2026-16616). Confidential information can be exposed externally.
|
| CVE-2026-13174 |
|
Vulnerability in wordpress (CVE-2026-13174)
vulnerability in wordpress (CVE-2026-13174). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12983 |
|
SQL Injection in wordpress (CVE-2026-12983)
SQL injection in wordpress (CVE-2026-12983). Confidential information can be exposed externally.
|
| CVE-2026-11565 |
|
Vulnerability in wordpress (CVE-2026-11565)
vulnerability in wordpress (CVE-2026-11565). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13169 |
|
Vulnerability in wordpress (CVE-2026-13169)
vulnerability in wordpress (CVE-2026-13169). Confidential information can be exposed externally.
|
| CVE-2026-19942 |
|
Path Traversal in wordpress (CVE-2026-19942)
path traversal in wordpress (CVE-2026-19942). Data can be tampered with by attackers.
|
| CVE-2026-66602 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-66602)
vulnerability in wordpress (CVE-2026-66602). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73351 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-73351)
cross-site scripting in wordpress (CVE-2026-73351). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75091 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-75091)
cross-site scripting in wordpress (CVE-2026-75091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11801 |
|
Vulnerability in wordpress (CVE-2026-11801)
vulnerability in wordpress (CVE-2026-11801). Confidential information can be exposed externally.
|
| CVE-2026-65640 |
|
Unrestricted File Upload in wordpress (CVE-2026-65640)
vulnerability in wordpress (CVE-2026-65640). Successful exploitation can lead to full system takeover. Exploitable via ``upload_files``.
|
| CVE-2026-2497 |
|
SQL Injection in wordpress (CVE-2026-2497)
SQL injection in wordpress (CVE-2026-2497). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17087 |
|
Vulnerability in wordpress (CVE-2026-17087)
vulnerability in wordpress (CVE-2026-17087). Confidential information can be exposed externally.
|
| CVE-2026-13424 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13424)
cross-site scripting in wordpress (CVE-2026-13424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10734 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10734)
cross-site scripting in wordpress (CVE-2026-10734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19728 |
|
Vulnerability in wordpress (CVE-2026-19728)
vulnerability in wordpress (CVE-2026-19728). Confidential information can be exposed externally.
|
| CVE-2026-19717 |
|
Information Disclosure in wordpress (CVE-2026-19717)
vulnerability in wordpress (CVE-2026-19717). Confidential information can be exposed externally.
|
| CVE-2026-18653 |
|
SQL Injection in wordpress (CVE-2026-18653)
SQL injection in wordpress (CVE-2026-18653). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17123 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-17123)
SSRF in wordpress (CVE-2026-17123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17581 |
|
Code Injection in wordpress (CVE-2026-17581)
code injection in wordpress (CVE-2026-17581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17533 |
|
Privilege Escalation in wordpress (CVE-2026-17533)
vulnerability in wordpress (CVE-2026-17533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16099 |
|
Unsafe Deserialization in wordpress (CVE-2026-16099)
vulnerability in wordpress (CVE-2026-16099). Successful exploitation can lead to full system takeover.
|