Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-82483 |
|
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The m...
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotely. The exploit is now...
|
| CVE-2026-82482 |
|
A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint....
A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The attack can be initiat...
|
| CVE-2026-81766 |
|
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-sup...
The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to install and execute arbi...
|
| CVE-2026-81660 |
|
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputt...
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perform Stored Cross-Site...
|
| CVE-2026-78364 |
|
The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low a...
The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.
|
| CVE-2026-76585 |
|
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated u...
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
|
| CVE-2026-19722 |
|
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users s...
The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore directory, which can lea...
|
| CVE-2026-14835 |
|
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict...
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and...
|
| CVE-2026-14307 |
|
The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unau...
The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victim is tricked into sub...
|
| CVE-2026-82480 |
|
Vulnerability in c (CVE-2026-82480)
vulnerability in c (CVE-2026-82480). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82479 |
|
Buffer Overflow in c (CVE-2026-82479)
vulnerability in c (CVE-2026-82479). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82478 |
|
Buffer Overflow in cpp (CVE-2026-82478)
vulnerability in cpp (CVE-2026-82478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15980 |
|
Vulnerability in wordpress (CVE-2026-15980)
vulnerability in wordpress (CVE-2026-15980). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77846 |
|
Vulnerability in CVE-2026-77846 (CVE-2026-77846)
vulnerability in CVE-2026-77846 (CVE-2026-77846). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75759 |
|
Vulnerability in CVE-2026-75759 (CVE-2026-75759)
vulnerability in CVE-2026-75759 (CVE-2026-75759). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82562 |
|
Vulnerability in CVE-2026-82562 (CVE-2026-82562)
vulnerability in CVE-2026-82562 (CVE-2026-82562). Risk of unauthorized operations or information disclosure. Exploitable via ``qs.parse``. Mitigation: upgrade to `6.16.0` or later.
|
| CVE-2026-77970 |
|
Vulnerability in CVE-2026-77970 (CVE-2026-77970)
vulnerability in CVE-2026-77970 (CVE-2026-77970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77831 |
|
Vulnerability in dos (CVE-2026-77831)
vulnerability in dos (CVE-2026-77831). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75847 |
|
Vulnerability in CVE-2026-75847 (CVE-2026-75847)
vulnerability in CVE-2026-75847 (CVE-2026-75847). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82417 |
|
Vulnerability in express (CVE-2026-82417)
vulnerability in express (CVE-2026-82417). Risk of unauthorized operations or information disclosure. Exploitable via ``qs.stringify``. Mitigation: upgrade to `6.16.0` or later.
|
| CVE-2026-82424 |
|
Vulnerability in sqli (CVE-2026-82424)
vulnerability in sqli (CVE-2026-82424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82423 |
|
Vulnerability in CVE-2026-82423 (CVE-2026-82423)
vulnerability in CVE-2026-82423 (CVE-2026-82423). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82422 |
|
Vulnerability in sqli (CVE-2026-82422)
vulnerability in sqli (CVE-2026-82422). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82421 |
|
Vulnerability in sqli (CVE-2026-82421)
vulnerability in sqli (CVE-2026-82421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15369 |
|
Privilege Escalation in wordpress (CVE-2026-15369)
vulnerability in wordpress (CVE-2026-15369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75807 |
|
Authentication Bypass in wordpress (CVE-2026-75807)
authentication bypass in wordpress (CVE-2026-75807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82476 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82476)
SSRF in ssrf (CVE-2026-82476). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82475 |
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
| CVE-2026-82474 |
|
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in...
|
| CVE-2026-82473 |
|
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without...
|
| CVE-2026-82472 |
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
| CVE-2026-82470 |
|
Vulnerability in CVE-2026-82470 (CVE-2026-82470)
vulnerability in CVE-2026-82470 (CVE-2026-82470). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82469 |
|
Vulnerability in CVE-2026-82469 (CVE-2026-82469)
vulnerability in CVE-2026-82469 (CVE-2026-82469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82468 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-82468)
vulnerability in csrf (CVE-2026-82468). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82467 |
|
Open Redirect in CVE-2026-82467 (CVE-2026-82467)
vulnerability in CVE-2026-82467 (CVE-2026-82467). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-82465 |
|
Vulnerability in CVE-2026-82465 (CVE-2026-82465)
vulnerability in CVE-2026-82465 (CVE-2026-82465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82464 |
|
Open Redirect in CVE-2026-82464 (CVE-2026-82464)
vulnerability in CVE-2026-82464 (CVE-2026-82464). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82463 |
|
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
|
| CVE-2026-82462 |
|
Vulnerability in CVE-2026-82462 (CVE-2026-82462)
vulnerability in CVE-2026-82462 (CVE-2026-82462). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82461 |
|
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry...
|
| CVE-2026-82460 |
|
Path Traversal in path-traversal (CVE-2026-82460)
path traversal in path-traversal (CVE-2026-82460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82481 |
|
The cohttp package before 6.3.0 for OCaml allows directory traversal.
The cohttp package before 6.3.0 for OCaml allows directory traversal.
|
| CVE-2026-82477 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-82477)
SSRF in ssrf (CVE-2026-82477). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82457 |
|
Vulnerability in CVE-2026-82457 (CVE-2026-82457)
vulnerability in CVE-2026-82457 (CVE-2026-82457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82456 |
|
Vulnerability in CVE-2026-82456 (CVE-2026-82456)
vulnerability in CVE-2026-82456 (CVE-2026-82456). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82454 |
|
Vulnerability in CVE-2026-82454 (CVE-2026-82454)
vulnerability in CVE-2026-82454 (CVE-2026-82454). Confidential information can be exposed externally.
|
| CVE-2026-82452 |
|
Vulnerability in c (CVE-2026-82452)
vulnerability in c (CVE-2026-82452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82451 |
|
Cross-Site Scripting (XSS) in CVE-2026-82451 (CVE-2026-82451)
cross-site scripting in CVE-2026-82451 (CVE-2026-82451). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2026-82455 |
|
Vulnerability in CVE-2026-82455 (CVE-2026-82455)
vulnerability in CVE-2026-82455 (CVE-2026-82455). Data can be tampered with by attackers.
|