Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-79668 |
|
Vulnerability in CVE-2026-79668 (CVE-2026-79668)
vulnerability in CVE-2026-79668 (CVE-2026-79668). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/echo/like/`.
|
| CVE-2026-79660 |
|
Information Disclosure in c (CVE-2026-79660)
vulnerability in c (CVE-2026-79660). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79665 |
|
Vulnerability in CVE-2026-79665 (CVE-2026-79665)
vulnerability in CVE-2026-79665 (CVE-2026-79665). Successful exploitation can lead to full system takeover.
|
| CVE-2026-79659 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-79659 (CVE-2026-79659)
SSRF in CVE-2026-79659 (CVE-2026-79659). Confidential information can be exposed externally.
|
| CVE-2026-79664 |
|
Vulnerability in CVE-2026-79664 (CVE-2026-79664)
vulnerability in CVE-2026-79664 (CVE-2026-79664). Confidential information can be exposed externally.
|
| CVE-2026-79662 |
|
Open Redirect in CVE-2026-79662 (CVE-2026-79662)
vulnerability in CVE-2026-79662 (CVE-2026-79662). Confidential information can be exposed externally. Exploitable via `POST /api/auth/exchange`. Mitigation: upgrade to `4.7.3` or later.
|
| CVE-2026-79661 |
|
Vulnerability in CVE-2026-79661 (CVE-2026-79661)
vulnerability in CVE-2026-79661 (CVE-2026-79661). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/echo/like/`. Mitigation: upgrade to `4.7.3` or later.
|
| CVE-2026-79663 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-79663)
cross-site scripting in c (CVE-2026-79663). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79658 |
|
Vulnerability in dos (CVE-2026-79658)
vulnerability in dos (CVE-2026-79658). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78864 |
|
Vulnerability in sqli (CVE-2026-78864)
vulnerability in sqli (CVE-2026-78864). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78684 |
|
Vulnerability in dos (CVE-2026-78684)
vulnerability in dos (CVE-2026-78684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79657 |
|
Unsafe Deserialization in CVE-2026-79657 (CVE-2026-79657)
vulnerability in CVE-2026-79657 (CVE-2026-79657). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77997 |
|
Vulnerability in CVE-2026-77997 (CVE-2026-77997)
vulnerability in CVE-2026-77997 (CVE-2026-77997). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77824 |
|
SQL Injection in wordpress (CVE-2026-77824)
SQL injection in wordpress (CVE-2026-77824). Confidential information can be exposed externally.
|
| CVE-2026-77996 |
|
Cross-Site Scripting (XSS) in CVE-2026-77996 (CVE-2026-77996)
cross-site scripting in CVE-2026-77996 (CVE-2026-77996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75971 |
|
Privilege Escalation in wordpress (CVE-2026-75971)
vulnerability in wordpress (CVE-2026-75971). Successful exploitation can lead to full system takeover. Exploitable via ``import_start``.
|
| CVE-2026-75908 |
|
Vulnerability in wordpress (CVE-2026-75908)
vulnerability in wordpress (CVE-2026-75908). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57909 |
|
Code Injection in path-traversal (CVE-2026-57909)
code injection in path-traversal (CVE-2026-57909). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57910 |
|
Vulnerability in CVE-2026-57910 (CVE-2026-57910)
vulnerability in CVE-2026-57910 (CVE-2026-57910). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17587 |
|
Vulnerability in wordpress (CVE-2026-17587)
vulnerability in wordpress (CVE-2026-17587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78863 |
|
Authentication Bypass in CVE-2026-78863 (CVE-2026-78863)
authentication bypass in CVE-2026-78863 (CVE-2026-78863). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49845 |
|
Code Injection in apache (CVE-2026-49845)
code injection in apache (CVE-2026-49845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18547 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18547)
cross-site scripting in wordpress (CVE-2026-18547). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19949 |
|
SQL Injection in wordpress (CVE-2026-19949)
SQL injection in wordpress (CVE-2026-19949). Successful exploitation can lead to full system takeover.
|
| CVE-2026-79652 |
|
Vulnerability in CVE-2026-79652 (CVE-2026-79652)
vulnerability in CVE-2026-79652 (CVE-2026-79652). Confidential information can be exposed externally.
|
| CVE-2026-53561 |
|
Authentication Bypass in apache (CVE-2026-53561)
authentication bypass in apache (CVE-2026-53561). Confidential information can be exposed externally.
|
| CVE-2026-55976 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-55976)
SSRF in apache (CVE-2026-55976). Confidential information can be exposed externally.
|
| CVE-2026-59335 |
|
Vulnerability in CVE-2026-59335 (CVE-2026-59335)
vulnerability in CVE-2026-59335 (CVE-2026-59335). Confidential information can be exposed externally.
|
| CVE-2026-21754 |
|
Vulnerability in CVE-2026-21754 (CVE-2026-21754)
vulnerability in CVE-2026-21754 (CVE-2026-21754). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21753 |
|
Vulnerability in CVE-2026-21753 (CVE-2026-21753)
vulnerability in CVE-2026-21753 (CVE-2026-21753). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21758 |
|
Information Disclosure in CVE-2026-21758 (CVE-2026-21758)
vulnerability in CVE-2026-21758 (CVE-2026-21758). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12600 |
|
Vulnerability in dos (CVE-2026-12600)
vulnerability in dos (CVE-2026-12600). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78576 |
|
SQL Injection in wordpress (CVE-2026-78576)
SQL injection in wordpress (CVE-2026-78576). Confidential information can be exposed externally.
|
| CVE-2026-78572 |
|
Unsafe Deserialization in wordpress (CVE-2026-78572)
vulnerability in wordpress (CVE-2026-78572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78570 |
|
Privilege Escalation in wordpress (CVE-2026-78570)
vulnerability in wordpress (CVE-2026-78570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76128 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76128)
cross-site scripting in wordpress (CVE-2026-76128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75038 |
|
Vulnerability in CVE-2026-75038 (CVE-2026-75038)
vulnerability in CVE-2026-75038 (CVE-2026-75038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75037 |
|
Vulnerability in CVE-2026-75037 (CVE-2026-75037)
vulnerability in CVE-2026-75037 (CVE-2026-75037). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49050 |
|
Authorization Flaw in apache (CVE-2026-49050)
vulnerability in apache (CVE-2026-49050). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16231 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-16231)
cross-site scripting in express (CVE-2026-16231). Confidential information can be exposed externally. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2026-12878 |
|
Privilege Escalation in CVE-2026-12878 (CVE-2026-12878)
vulnerability in CVE-2026-12878 (CVE-2026-12878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78563 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-78563)
cross-site scripting in wordpress (CVE-2026-78563). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77142 |
|
Vulnerability in CVE-2026-77142 (CVE-2026-77142)
vulnerability in CVE-2026-77142 (CVE-2026-77142). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77145 |
|
Vulnerability in CVE-2026-77145 (CVE-2026-77145)
vulnerability in CVE-2026-77145 (CVE-2026-77145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78566 |
|
Vulnerability in wordpress (CVE-2026-78566)
vulnerability in wordpress (CVE-2026-78566). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78568 |
|
SQL Injection in wordpress (CVE-2026-78568)
SQL injection in wordpress (CVE-2026-78568). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78562 |
|
Vulnerability in wordpress (CVE-2026-78562)
vulnerability in wordpress (CVE-2026-78562). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77143 |
|
Vulnerability in CVE-2026-77143 (CVE-2026-77143)
vulnerability in CVE-2026-77143 (CVE-2026-77143). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77144 |
|
Vulnerability in CVE-2026-77144 (CVE-2026-77144)
vulnerability in CVE-2026-77144 (CVE-2026-77144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77140 |
|
Vulnerability in CVE-2026-77140 (CVE-2026-77140)
vulnerability in CVE-2026-77140 (CVE-2026-77140). Risk of unauthorized operations or information disclosure.
|