Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14596 |
|
Authentication Bypass in wordpress (CVE-2026-14596)
authentication bypass in wordpress (CVE-2026-14596). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14561 |
|
Authentication Bypass in wordpress (CVE-2026-14561)
authentication bypass in wordpress (CVE-2026-14561). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14315 |
|
Vulnerability in wordpress (CVE-2026-14315)
vulnerability in wordpress (CVE-2026-14315). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14309 |
|
Authentication Bypass in wordpress (CVE-2026-14309)
authentication bypass in wordpress (CVE-2026-14309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14292 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14292)
cross-site scripting in wordpress (CVE-2026-14292). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14214 |
|
Authentication Bypass in wordpress (CVE-2026-14214)
authentication bypass in wordpress (CVE-2026-14214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14197 |
|
Vulnerability in wordpress (CVE-2026-14197)
vulnerability in wordpress (CVE-2026-14197). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14195 |
|
Vulnerability in wordpress (CVE-2026-14195)
vulnerability in wordpress (CVE-2026-14195). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13729 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-13729)
vulnerability in wordpress (CVE-2026-13729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13725 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13725)
cross-site scripting in wordpress (CVE-2026-13725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13604 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-13604)
SSRF in wordpress (CVE-2026-13604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13596 |
|
SQL Injection in wordpress (CVE-2026-13596)
SQL injection in wordpress (CVE-2026-13596). Confidential information can be exposed externally.
|
| CVE-2026-13329 |
|
Vulnerability in wordpress (CVE-2026-13329)
vulnerability in wordpress (CVE-2026-13329). Data can be tampered with by attackers.
|
| CVE-2026-13158 |
|
Unrestricted File Upload in wordpress (CVE-2026-13158)
vulnerability in wordpress (CVE-2026-13158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13157 |
|
Unrestricted File Upload in wordpress (CVE-2026-13157)
vulnerability in wordpress (CVE-2026-13157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12966 |
|
Vulnerability in wordpress (CVE-2026-12966)
vulnerability in wordpress (CVE-2026-12966). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12696 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12696)
cross-site scripting in wordpress (CVE-2026-12696). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11882 |
|
Vulnerability in wordpress (CVE-2026-11882)
vulnerability in wordpress (CVE-2026-11882). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10827 |
|
Vulnerability in wordpress (CVE-2026-10827)
vulnerability in wordpress (CVE-2026-10827). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15669 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-15669)
cross-site scripting in wordpress (CVE-2025-15669). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3141 |
|
Vulnerability in wordpress (CVE-2026-3141)
vulnerability in wordpress (CVE-2026-3141). Data can be tampered with by attackers.
|
| CVE-2026-7623 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7623)
cross-site scripting in wordpress (CVE-2026-7623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15414 |
|
Privilege Escalation in wordpress (CVE-2026-15414)
vulnerability in wordpress (CVE-2026-15414). Successful exploitation can lead to full system takeover. Exploitable via ``_wps_plan_user_role``.
|
| CVE-2026-15403 |
|
SQL Injection in wordpress (CVE-2026-15403)
SQL injection in wordpress (CVE-2026-15403). Confidential information can be exposed externally.
|
| CVE-2026-15006 |
|
Path Traversal in wordpress (CVE-2026-15006)
path traversal in wordpress (CVE-2026-15006). Confidential information can be exposed externally.
|
| CVE-2026-13362 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13362)
cross-site scripting in wordpress (CVE-2026-13362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9044 |
|
OS Command Injection in tp-link (CVE-2026-9044)
OS command injection in tp-link (CVE-2026-9044). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34641 |
|
Out-of-Bounds Write in adobe (CVE-2026-34641)
out-of-bounds write in adobe (CVE-2026-34641). Successful exploitation can lead to full system takeover.
|
| CVE-2016-1000305 |
|
Path Traversal in guard-livereload (CVE-2016-1000305)
path traversal in guard-livereload (CVE-2016-1000305). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.5.2` or later.
|
| CVE-2026-54785 |
|
Path Traversal in gemini-bridge (CVE-2026-54785)
path traversal in gemini-bridge (CVE-2026-54785). Confidential information can be exposed externally. Exploitable via ``consult_gemini_with_files``. Mitigation: upgrade to `1.3.1` or later.
|
| CVE-2026-54768 |
|
Vulnerability in wp-graphql/wp-graphql (CVE-2026-54768)
vulnerability in wp-graphql/wp-graphql (CVE-2026-54768). Risk of unauthorized operations or information disclosure. Exploitable via ``sendPasswordResetEmail``.
|
| CVE-2026-68771 |
|
Unsafe Deserialization in deserialization (CVE-2026-68771)
vulnerability in deserialization (CVE-2026-68771). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload/image`.
|
| CVE-2026-52371 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-52371)
SSRF in ssrf (CVE-2026-52371). Confidential information can be exposed externally.
|
| CVE-2026-52232 |
|
Cross-Site Scripting (XSS) in CVE-2026-52232 (CVE-2026-52232)
cross-site scripting in CVE-2026-52232 (CVE-2026-52232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52134 |
|
Vulnerability in c (CVE-2026-52134)
vulnerability in c (CVE-2026-52134). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51953 |
|
Vulnerability in CVE-2026-51953 (CVE-2026-51953)
vulnerability in CVE-2026-51953 (CVE-2026-51953). Confidential information can be exposed externally.
|
| CVE-2026-53573 |
|
Open Redirect in org.geonetwork-opensource:geonetwork (CVE-2026-53573)
vulnerability in org.geonetwork-opensource:geonetwork (CVE-2026-53573). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.4.11` or later.
|
| CVE-2026-54909 |
|
Vulnerability in github.com/pion/stun/v3 (CVE-2026-54909)
vulnerability in github.com/pion/stun/v3 (CVE-2026-54909). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.5` or later.
|
| CVE-2026-54787 |
|
Vulnerability in github.com/sigstore/sigstore-go (CVE-2026-54787)
vulnerability in github.com/sigstore/sigstore-go (CVE-2026-54787). Risk of unauthorized operations or information disclosure. Exploitable via ``ExpiringKey``. Mitigation: upgrade to `1.2.1` or later.
|
| CVE-2026-68770 |
|
Code Injection in CVE-2026-68770 (CVE-2026-68770)
code injection in CVE-2026-68770 (CVE-2026-68770). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65981 |
|
Vulnerability in CVE-2026-65981 (CVE-2026-65981)
vulnerability in CVE-2026-65981 (CVE-2026-65981). Confidential information can be exposed externally.
|
| CVE-2026-51785 |
|
Code Injection in CVE-2026-51785 (CVE-2026-51785)
code injection in CVE-2026-51785 (CVE-2026-51785). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50986 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-50986)
vulnerability in csrf (CVE-2026-50986). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38713 |
|
Command Injection in CVE-2026-38713 (CVE-2026-38713)
command injection in CVE-2026-38713 (CVE-2026-38713). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38710 |
|
Command Injection in CVE-2026-38710 (CVE-2026-38710)
command injection in CVE-2026-38710 (CVE-2026-38710). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38708 |
|
Command Injection in CVE-2026-38708 (CVE-2026-38708)
command injection in CVE-2026-38708 (CVE-2026-38708). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69948 |
|
SQL Injection in sqli (CVE-2025-69948)
SQL injection in sqli (CVE-2025-69948). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69946 |
|
SQL Injection in sqli (CVE-2025-69946)
SQL injection in sqli (CVE-2025-69946). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18394 |
|
Authorization Flaw in Amazon aws (CVE-2026-18394)
vulnerability in Amazon aws (CVE-2026-18394). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-62999 |
|
Path Traversal in CVE-2026-62999 (CVE-2026-62999)
path traversal in CVE-2026-62999 (CVE-2026-62999). Successful exploitation can lead to full system takeover.
|