Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-81668 Vulnerability in CVE-2026-81668 (CVE-2026-81668)
vulnerability in CVE-2026-81668 (CVE-2026-81668). Risk of unauthorized operations or information disclosure.
CVE-2026-81662 Vulnerability in CVE-2026-81662 (CVE-2026-81662)
vulnerability in CVE-2026-81662 (CVE-2026-81662). Risk of unauthorized operations or information disclosure.
CVE-2026-81659 Path Traversal in CVE-2026-81659 (CVE-2026-81659)
path traversal in CVE-2026-81659 (CVE-2026-81659). Risk of unauthorized operations or information disclosure.
CVE-2026-81658 Vulnerability in CVE-2026-81658 (CVE-2026-81658)
vulnerability in CVE-2026-81658 (CVE-2026-81658). Confidential information can be exposed externally.
CVE-2026-81562 Command Injection in CVE-2026-81562 (CVE-2026-81562)
command injection in CVE-2026-81562 (CVE-2026-81562). Risk of unauthorized operations or information disclosure.
CVE-2026-81560 Path Traversal in path-traversal (CVE-2026-81560)
path traversal in path-traversal (CVE-2026-81560). Risk of unauthorized operations or information disclosure.
CVE-2026-74233 OS Command Injection in c (CVE-2026-74233)
OS command injection in c (CVE-2026-74233). Successful exploitation can lead to full system takeover.
CVE-2026-74232 Vulnerability in CVE-2026-74232 (CVE-2026-74232)
vulnerability in CVE-2026-74232 (CVE-2026-74232). Successful exploitation can lead to full system takeover.
CVE-2026-66155 Cross-Site Scripting (XSS) in CVE-2026-66155 (CVE-2026-66155)
cross-site scripting in CVE-2026-66155 (CVE-2026-66155). Confidential information can be exposed externally.
CVE-2026-5218 Vulnerability in CVE-2026-5218 (CVE-2026-5218)
vulnerability in CVE-2026-5218 (CVE-2026-5218). Risk of unauthorized operations or information disclosure.
CVE-2026-17562 Vulnerability in CVE-2026-17562 (CVE-2026-17562)
vulnerability in CVE-2026-17562 (CVE-2026-17562). Risk of unauthorized operations or information disclosure.
CVE-2026-81625 Out-of-Bounds Write in CVE-2026-81625 (CVE-2026-81625)
out-of-bounds write in CVE-2026-81625 (CVE-2026-81625). Successful exploitation can lead to full system takeover.
CVE-2026-81581 Buffer Overflow in privilege-escalation (CVE-2026-81581)
vulnerability in privilege-escalation (CVE-2026-81581). Successful exploitation can lead to full system takeover.
CVE-2026-81579 Vulnerability in privilege-escalation (CVE-2026-81579)
vulnerability in privilege-escalation (CVE-2026-81579). Successful exploitation can lead to full system takeover.
CVE-2026-81576 Vulnerability in CVE-2026-81576 (CVE-2026-81576)
vulnerability in CVE-2026-81576 (CVE-2026-81576). Confidential information can be exposed externally.
CVE-2026-81575 Vulnerability in CVE-2026-81575 (CVE-2026-81575)
vulnerability in CVE-2026-81575 (CVE-2026-81575). Risk of unauthorized operations or information disclosure.
CVE-2026-81574 Vulnerability in CVE-2026-81574 (CVE-2026-81574)
vulnerability in CVE-2026-81574 (CVE-2026-81574). Risk of unauthorized operations or information disclosure.
CVE-2026-81573 Vulnerability in c (CVE-2026-81573)
vulnerability in c (CVE-2026-81573). Data can be tampered with by attackers.
CVE-2026-81572 Vulnerability in c (CVE-2026-81572)
vulnerability in c (CVE-2026-81572). Successful exploitation can lead to full system takeover.
CVE-2026-81279 Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.
CVE-2026-81277 Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
CVE-2026-81276 Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
CVE-2026-81274 Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
Subscriber Broken Access Control in Ditty <= 3.1.67 versions.
CVE-2026-81273 Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
CVE-2026-81272 Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
CVE-2026-81271 Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
CVE-2026-80433 Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
CVE-2026-78293 Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
CVE-2026-78292 Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
CVE-2026-78289 Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
CVE-2026-78288 Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.
CVE-2026-78286 Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
CVE-2026-78285 Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
CVE-2026-78283 Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
CVE-2026-78281 Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
CVE-2026-78276 Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78275 Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78274 Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78273 Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
CVE-2026-78271 Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
CVE-2026-78261 Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
CVE-2026-78260 Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.
CVE-2026-78257 Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
CVE-2026-75020 Vulnerability in apache (CVE-2026-75020)
vulnerability in apache (CVE-2026-75020). Risk of unauthorized operations or information disclosure.
CVE-2026-75005 Vulnerability in apache (CVE-2026-75005)
vulnerability in apache (CVE-2026-75005). Risk of unauthorized operations or information disclosure.
CVE-2026-74848 Vulnerability in apache (CVE-2026-74848)
vulnerability in apache (CVE-2026-74848). Risk of unauthorized operations or information disclosure.
CVE-2026-59355 Open Redirect in CVE-2026-59355 (CVE-2026-59355)
vulnerability in CVE-2026-59355 (CVE-2026-59355). Risk of unauthorized operations or information disclosure.
CVE-2026-59354 Vulnerability in ssrf (CVE-2026-59354)
vulnerability in ssrf (CVE-2026-59354). Confidential information can be exposed externally.
CVE-2026-32566 Vulnerability in wordpress (CVE-2026-32566)
vulnerability in wordpress (CVE-2026-32566). Successful exploitation can lead to full system takeover.
CVE-2026-32564 Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →