Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-73996 Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
CVE-2026-73392 Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
CVE-2026-73381 Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73376 Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73380 Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73365 Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
CVE-2026-73343 Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
CVE-2026-73355 Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
CVE-2026-73339 Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
CVE-2026-73366 Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
CVE-2026-73341 Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
CVE-2026-73187 Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
CVE-2026-66627 Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.
CVE-2026-32470 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-32474 Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
CVE-2026-32463 Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
CVE-2026-75874 Vulnerability in mozilla (CVE-2026-75874)
vulnerability in mozilla (CVE-2026-75874). Successful exploitation can lead to full system takeover.
CVE-2026-75783 Buffer Overflow in CVE-2026-75783 (CVE-2026-75783)
vulnerability in CVE-2026-75783 (CVE-2026-75783). Successful exploitation can lead to full system takeover.
CVE-2026-32444 Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
CVE-2026-28192 Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
CVE-2026-74990 Buffer Overflow in mozilla (CVE-2026-74990)
vulnerability in mozilla (CVE-2026-74990). Successful exploitation can lead to full system takeover.
CVE-2026-74987 Buffer Overflow in mozilla (CVE-2026-74987)
vulnerability in mozilla (CVE-2026-74987). Successful exploitation can lead to full system takeover.
CVE-2026-74988 Buffer Overflow in mozilla (CVE-2026-74988)
vulnerability in mozilla (CVE-2026-74988). Successful exploitation can lead to full system takeover.
CVE-2026-74985 Privilege Escalation in privilege-escalation (CVE-2026-74985)
vulnerability in privilege-escalation (CVE-2026-74985). Successful exploitation can lead to full system takeover.
CVE-2026-74989 Buffer Overflow in mozilla (CVE-2026-74989)
vulnerability in mozilla (CVE-2026-74989). Successful exploitation can lead to full system takeover.
CVE-2026-74986 Information Disclosure in mozilla (CVE-2026-74986)
vulnerability in mozilla (CVE-2026-74986). Confidential information can be exposed externally.
CVE-2026-74979 Vulnerability in mozilla (CVE-2026-74979)
vulnerability in mozilla (CVE-2026-74979). Successful exploitation can lead to full system takeover.
CVE-2026-74964 Vulnerability in mozilla (CVE-2026-74964)
vulnerability in mozilla (CVE-2026-74964). Successful exploitation can lead to full system takeover.
CVE-2026-74956 Vulnerability in mozilla (CVE-2026-74956)
vulnerability in mozilla (CVE-2026-74956). Confidential information can be exposed externally.
CVE-2026-74959 Vulnerability in mozilla (CVE-2026-74959)
vulnerability in mozilla (CVE-2026-74959). Confidential information can be exposed externally.
CVE-2026-74961 Vulnerability in mozilla (CVE-2026-74961)
vulnerability in mozilla (CVE-2026-74961). Confidential information can be exposed externally.
CVE-2026-74943 Use-After-Free in mozilla (CVE-2026-74943)
vulnerability in mozilla (CVE-2026-74943). Successful exploitation can lead to full system takeover.
CVE-2026-74940 Use-After-Free in mozilla (CVE-2026-74940)
vulnerability in mozilla (CVE-2026-74940). Successful exploitation can lead to full system takeover.
CVE-2026-74944 Use-After-Free in mozilla (CVE-2026-74944)
vulnerability in mozilla (CVE-2026-74944). Successful exploitation can lead to full system takeover.
CVE-2026-74938 Vulnerability in mozilla (CVE-2026-74938)
vulnerability in mozilla (CVE-2026-74938). Confidential information can be exposed externally.
CVE-2026-74936 Use-After-Free in mozilla (CVE-2026-74936)
vulnerability in mozilla (CVE-2026-74936). Successful exploitation can lead to full system takeover.
CVE-2026-75851 Privilege Escalation in CVE-2026-75851 (CVE-2026-75851)
vulnerability in CVE-2026-75851 (CVE-2026-75851). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `26.8.1` or later.
CVE-2026-75852 Vulnerability in c (CVE-2026-75852)
vulnerability in c (CVE-2026-75852). Successful exploitation can lead to full system takeover.
CVE-2026-75843 Privilege Escalation in CVE-2026-75843 (CVE-2026-75843)
vulnerability in CVE-2026-75843 (CVE-2026-75843). Successful exploitation can lead to full system takeover.
CVE-2026-75854 Vulnerability in CVE-2026-75854 (CVE-2026-75854)
vulnerability in CVE-2026-75854 (CVE-2026-75854). Successful exploitation can lead to full system takeover.
CVE-2026-75837 Privilege Escalation in CVE-2026-75837 (CVE-2026-75837)
vulnerability in CVE-2026-75837 (CVE-2026-75837). Successful exploitation can lead to full system takeover.
CVE-2026-75627 Vulnerability in CVE-2026-75627 (CVE-2026-75627)
vulnerability in CVE-2026-75627 (CVE-2026-75627). Successful exploitation can lead to full system takeover.
CVE-2026-75626 Cross-Site Scripting (XSS) in CVE-2026-75626 (CVE-2026-75626)
cross-site scripting in CVE-2026-75626 (CVE-2026-75626). Confidential information can be exposed externally.
CVE-2026-34884 SSRF (Server-Side Request Forgery) in apache (CVE-2026-34884)
SSRF in apache (CVE-2026-34884). Successful exploitation can lead to full system takeover.
CVE-2026-15748 Unrestricted File Upload in wordpress (CVE-2026-15748)
vulnerability in wordpress (CVE-2026-15748). Successful exploitation can lead to full system takeover.
CVE-2026-75094 Command Injection in CVE-2026-75094 (CVE-2026-75094)
command injection in CVE-2026-75094 (CVE-2026-75094). Successful exploitation can lead to full system takeover.
CVE-2026-67919 Code Injection in CVE-2026-67919 (CVE-2026-67919)
code injection in CVE-2026-67919 (CVE-2026-67919). Successful exploitation can lead to full system takeover.
CVE-2026-42164 Information Disclosure in CVE-2026-42164 (CVE-2026-42164)
vulnerability in CVE-2026-42164 (CVE-2026-42164). Successful exploitation can lead to full system takeover.
CVE-2026-42162 Path Traversal in CVE-2026-42162 (CVE-2026-42162)
path traversal in CVE-2026-42162 (CVE-2026-42162). Confidential information can be exposed externally.
CVE-2026-38165 Code Injection in CVE-2026-38165 (CVE-2026-38165)
code injection in CVE-2026-38165 (CVE-2026-38165). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →