Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15482 |
|
Vulnerability in sqli (CVE-2026-15482)
vulnerability in sqli (CVE-2026-15482). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15483 |
|
Buffer Overflow in CVE-2026-15483 (CVE-2026-15483)
vulnerability in CVE-2026-15483 (CVE-2026-15483). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15481 |
|
Vulnerability in CVE-2026-15481 (CVE-2026-15481)
vulnerability in CVE-2026-15481 (CVE-2026-15481). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15479 |
|
Vulnerability in CVE-2026-15479 (CVE-2026-15479)
vulnerability in CVE-2026-15479 (CVE-2026-15479). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15480 |
|
Buffer Overflow in CVE-2026-15480 (CVE-2026-15480)
vulnerability in CVE-2026-15480 (CVE-2026-15480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58281 |
|
Unsafe Deserialization in deserialization (CVE-2026-58281)
vulnerability in deserialization (CVE-2026-58281). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61442 |
|
Vulnerability in CVE-2026-61442 (CVE-2026-61442)
vulnerability in CVE-2026-61442 (CVE-2026-61442). Data can be tampered with by attackers.
|
| CVE-2026-61428 |
|
Vulnerability in CVE-2026-61428 (CVE-2026-61428)
vulnerability in CVE-2026-61428 (CVE-2026-61428). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61439 |
|
Vulnerability in CVE-2026-61439 (CVE-2026-61439)
vulnerability in CVE-2026-61439 (CVE-2026-61439). Confidential information can be exposed externally.
|
| CVE-2026-61429 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-61429)
SSRF in ssrf (CVE-2026-61429). Confidential information can be exposed externally.
|
| CVE-2026-61426 |
|
Information Disclosure in CVE-2026-61426 (CVE-2026-61426)
vulnerability in CVE-2026-61426 (CVE-2026-61426). Confidential information can be exposed externally. Exploitable via `GET /api/agents`.
|
| CVE-2026-56303 |
|
Information Disclosure in CVE-2026-56303 (CVE-2026-56303)
vulnerability in CVE-2026-56303 (CVE-2026-56303). Confidential information can be exposed externally.
|
| CVE-2026-57828 |
|
Unrestricted File Upload in phoca (CVE-2026-57828)
vulnerability in phoca (CVE-2026-57828). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1359 |
|
Authorization Flaw in wordpress (CVE-2026-1359)
vulnerability in wordpress (CVE-2026-1359). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9282 |
|
Path Traversal in wordpress (CVE-2026-9282)
path traversal in wordpress (CVE-2026-9282). Confidential information can be exposed externally.
|
| CVE-2026-4661 |
|
SQL Injection in wordpress (CVE-2026-4661)
SQL injection in wordpress (CVE-2026-4661). Confidential information can be exposed externally.
|
| CVE-2026-6939 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6939)
cross-site scripting in wordpress (CVE-2026-6939). Risk of unauthorized operations or information disclosure. Exploitable via `POST /wp-json/corvuspay/success/`.
|
| CVE-2026-15155 |
|
Vulnerability in wordpress (CVE-2026-15155)
vulnerability in wordpress (CVE-2026-15155). Successful exploitation can lead to full system takeover.
|
| CVE-2025-6784 |
|
Command Injection in wordpress (CVE-2025-6784)
command injection in wordpress (CVE-2025-6784). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7655 |
|
Vulnerability in wordpress (CVE-2026-7655)
vulnerability in wordpress (CVE-2026-7655). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2354 |
|
Unrestricted File Upload in wordpress (CVE-2026-2354)
vulnerability in wordpress (CVE-2026-2354). Successful exploitation can lead to full system takeover. Exploitable via ``wp_check_filetype_and_ext``.
|
| CVE-2026-3576 |
|
Vulnerability in wordpress (CVE-2026-3576)
vulnerability in wordpress (CVE-2026-3576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13378 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13378)
cross-site scripting in wordpress (CVE-2026-13378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14262 |
|
Privilege Escalation in wordpress (CVE-2026-14262)
vulnerability in wordpress (CVE-2026-14262). Successful exploitation can lead to full system takeover. Exploitable via ``payload``.
|
| CVE-2026-15335 |
|
SQL Injection in wordpress (CVE-2026-15335)
SQL injection in wordpress (CVE-2026-15335). Confidential information can be exposed externally.
|
| CVE-2026-15338 |
|
Vulnerability in wordpress (CVE-2026-15338)
vulnerability in wordpress (CVE-2026-15338). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13114 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13114)
cross-site scripting in wordpress (CVE-2026-13114). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13353 |
|
Code Injection in wordpress (CVE-2026-13353)
code injection in wordpress (CVE-2026-13353). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13756 |
|
Privilege Escalation in wordpress (CVE-2026-13756)
vulnerability in wordpress (CVE-2026-13756). Successful exploitation can lead to full system takeover. Exploitable via ``wp_capabilities``.
|
| CVE-2026-42952 |
|
Vulnerability in CVE-2026-42952 (CVE-2026-42952)
vulnerability in CVE-2026-42952 (CVE-2026-42952). Data can be tampered with by attackers.
|
| CVE-2026-44383 |
|
Vulnerability in CVE-2026-44383 (CVE-2026-44383)
vulnerability in CVE-2026-44383 (CVE-2026-44383). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55175 |
|
Unsafe Deserialization in io.spinnaker.rosco:rosco-manifests (CVE-2026-55175)
vulnerability in io.spinnaker.rosco:rosco-manifests (CVE-2026-55175). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.1.1` or later.
|
| CVE-2026-55810 |
|
Vulnerability in drupal/plotly_js (CVE-2026-55810)
vulnerability in drupal/plotly_js (CVE-2026-55810). Confidential information can be exposed externally. Exploitable via ``plotly_js_graph``. Mitigation: upgrade to `3.0.2` or later.
|
| CVE-2026-55809 |
|
Vulnerability in drupal/flag_attendance_field (CVE-2026-55809)
vulnerability in drupal/flag_attendance_field (CVE-2026-55809). Confidential information can be exposed externally. Exploitable via ``flag_attendance_field``. Mitigation: upgrade to `1.2.0` or later.
|
| CVE-2026-49213 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-49213)
SSRF in ssrf (CVE-2026-49213). Confidential information can be exposed externally. Exploitable via `POST /v1/typebots/{publicId}/startChat`.
|
| CVE-2026-52747 |
|
Vulnerability in nginx (CVE-2026-52747)
vulnerability in nginx (CVE-2026-52747). Data can be tampered with by attackers.
|
| CVE-2026-13244 |
|
Vulnerability in drupal/tealiumiq (CVE-2026-13244)
vulnerability in drupal/tealiumiq (CVE-2026-13244). Confidential information can be exposed externally. Exploitable via ``tealiumiq``. Mitigation: upgrade to `2.4.0` or later.
|
| CVE-2026-15081 |
|
SQL Injection in drupal/location_selector (CVE-2026-15081)
SQL injection in drupal/location_selector (CVE-2026-15081). Confidential information can be exposed externally. Mitigation: upgrade to `1.3.0` or later.
|
| CVE-2026-45196 |
|
Vulnerability in privilege-escalation (CVE-2026-45196)
vulnerability in privilege-escalation (CVE-2026-45196). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34196 |
|
Use-After-Free in imaginationtech (CVE-2026-34196)
vulnerability in imaginationtech (CVE-2026-34196). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41154 |
|
Out-of-Bounds Write in imaginationtech (CVE-2026-41154)
out-of-bounds write in imaginationtech (CVE-2026-41154). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45203 |
|
Vulnerability in imaginationtech (CVE-2026-45203)
vulnerability in imaginationtech (CVE-2026-45203). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7639 |
|
Vulnerability in imaginationtech (CVE-2026-7639)
vulnerability in imaginationtech (CVE-2026-7639). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58499 |
|
Path Traversal in everos (CVE-2026-58499)
path traversal in everos (CVE-2026-58499). Data can be tampered with by attackers. Exploitable via `POST /api/v1/memory/add`. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-57220 |
|
Vulnerability in broadcom (CVE-2026-57220)
vulnerability in broadcom (CVE-2026-57220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57219 |
|
Information Disclosure in broadcom (CVE-2026-57219)
vulnerability in broadcom (CVE-2026-57219). Confidential information can be exposed externally. Exploitable via `GET /api/auth`.
|
| CVE-2026-57215 |
|
Authorization Flaw in broadcom (CVE-2026-57215)
vulnerability in broadcom (CVE-2026-57215). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57212 |
|
Vulnerability in broadcom (CVE-2026-57212)
vulnerability in broadcom (CVE-2026-57212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55880 |
|
Vulnerability in CVE-2026-55880 (CVE-2026-55880)
vulnerability in CVE-2026-55880 (CVE-2026-55880). Data can be tampered with by attackers.
|
| CVE-2026-55659 |
|
Cross-Site Scripting (XSS) in CVE-2026-55659 (CVE-2026-55659)
cross-site scripting in CVE-2026-55659 (CVE-2026-55659). Confidential information can be exposed externally.
|