Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66766 |
|
Vulnerability in dos (CVE-2026-66766)
vulnerability in dos (CVE-2026-66766). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59183 |
|
Vulnerability in CVE-2026-59183 (CVE-2026-59183)
vulnerability in CVE-2026-59183 (CVE-2026-59183). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55373 |
|
Vulnerability in CVE-2026-55373 (CVE-2026-55373)
vulnerability in CVE-2026-55373 (CVE-2026-55373). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55371 |
|
Vulnerability in c (CVE-2026-55371)
vulnerability in c (CVE-2026-55371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55059 |
|
Out-of-Bounds Write in CVE-2026-55059 (CVE-2026-55059)
out-of-bounds write in CVE-2026-55059 (CVE-2026-55059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54920 |
|
Vulnerability in dos (CVE-2026-54920)
vulnerability in dos (CVE-2026-54920). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-60004 KEV |
|
[KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-53532 |
|
Vulnerability in dos (CVE-2026-53532)
vulnerability in dos (CVE-2026-53532). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78435 |
|
Path Traversal in path-traversal (CVE-2026-78435)
path traversal in path-traversal (CVE-2026-78435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78434 |
|
Authentication Bypass in CVE-2026-78434 (CVE-2026-78434)
authentication bypass in CVE-2026-78434 (CVE-2026-78434). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78284 |
|
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
|
| CVE-2026-78282 |
|
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
|
| CVE-2026-78268 |
|
Vulnerability in CVE-2026-78268 (CVE-2026-78268)
vulnerability in CVE-2026-78268 (CVE-2026-78268). Confidential information can be exposed externally.
|
| CVE-2026-78267 |
|
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
|
| CVE-2026-78266 |
|
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
|
| CVE-2026-78265 |
|
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
|
| CVE-2026-78264 |
|
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
|
| CVE-2026-78263 |
|
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
|
| CVE-2026-78262 |
|
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
|
| CVE-2026-78259 |
|
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
|
| CVE-2026-77384 |
|
Vulnerability in dos (CVE-2026-77384)
vulnerability in dos (CVE-2026-77384). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77337 |
|
Vulnerability in CVE-2026-77337 (CVE-2026-77337)
vulnerability in CVE-2026-77337 (CVE-2026-77337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68516 |
|
Vulnerability in dos (CVE-2026-68516)
vulnerability in dos (CVE-2026-68516). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32563 |
|
Unsafe Deserialization in wordpress (CVE-2026-32563)
vulnerability in wordpress (CVE-2026-32563). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32561 |
|
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
|
| CVE-2026-32560 |
|
Vulnerability in wordpress (CVE-2026-32560)
vulnerability in wordpress (CVE-2026-32560). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32559 |
|
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
|
| CVE-2026-32556 |
|
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
|
| CVE-2026-32555 |
|
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
|
| CVE-2026-32554 |
|
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
|
| CVE-2026-27364 |
|
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
|
| CVE-2026-17113 |
|
Vulnerability in CVE-2026-17113 (CVE-2026-17113)
vulnerability in CVE-2026-17113 (CVE-2026-17113). Risk of unauthorized operations or information disclosure. Exploitable via ``mergeEnvs``.
|
| GHSA-fx4f-mhw4-qm7j |
|
Vulnerability in vibeio-http (GHSA-fx4f-mhw4-qm7j)
vulnerability in vibeio-http (GHSA-fx4f-mhw4-qm7j). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.3.2` or later.
|
| GHSA-w8j7-39hp-8x59 |
|
Path Traversal in github.com/cloudreve/Cloudreve/v4 (GHSA-w8j7-39hp-8x59)
path traversal in github.com/cloudreve/Cloudreve/v4 (GHSA-w8j7-39hp-8x59). Risk of unauthorized operations or information disclosure. Exploitable via ``downloader.TaskFile.Name``.
|
| GHSA-vx2m-jpxr-xv7w |
|
Authorization Flaw in github.com/cloudreve/Cloudreve/v4 (GHSA-vx2m-jpxr-xv7w)
vulnerability in github.com/cloudreve/Cloudreve/v4 (GHSA-vx2m-jpxr-xv7w). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v4/file`.
|
| CVE-2026-7455 |
|
Out-of-Bounds Write in autodesk (CVE-2026-7455)
out-of-bounds write in autodesk (CVE-2026-7455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19568 |
|
Vulnerability in autodesk (CVE-2026-19568)
vulnerability in autodesk (CVE-2026-19568). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75464 |
|
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
|
| CVE-2026-5006 |
|
Vulnerability in CVE-2026-5006 (CVE-2026-5006)
vulnerability in CVE-2026-5006 (CVE-2026-5006). Confidential information can be exposed externally.
|
| CVE-2026-52492 |
|
Vulnerability in CVE-2026-52492 (CVE-2026-52492)
vulnerability in CVE-2026-52492 (CVE-2026-52492). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16783 |
|
Out-of-Bounds Write in autodesk (CVE-2026-16783)
out-of-bounds write in autodesk (CVE-2026-16783). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52490 |
|
Code Injection in c (CVE-2026-52490)
code injection in c (CVE-2026-52490). Successful exploitation can lead to full system takeover.
|
| CVE-2022-30983 |
|
Cross-Site Scripting (XSS) in CVE-2022-30983 (CVE-2022-30983)
cross-site scripting in CVE-2022-30983 (CVE-2022-30983). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16781 |
|
Vulnerability in autodesk (CVE-2026-16781)
vulnerability in autodesk (CVE-2026-16781). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16782 |
|
Out-of-Bounds Read in autodesk (CVE-2026-16782)
vulnerability in autodesk (CVE-2026-16782). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77635 |
|
SQL Injection in sqli (CVE-2026-77635)
SQL injection in sqli (CVE-2026-77635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77634 |
|
Vulnerability in CVE-2026-77634 (CVE-2026-77634)
vulnerability in CVE-2026-77634 (CVE-2026-77634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77567 |
|
Authentication Bypass in laravel (CVE-2026-77567)
authentication bypass in laravel (CVE-2026-77567). Confidential information can be exposed externally.
|
| CVE-2026-75554 |
|
Vulnerability in CVE-2026-75554 (CVE-2026-75554)
vulnerability in CVE-2026-75554 (CVE-2026-75554). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75542 |
|
Authorization Flaw in CVE-2026-75542 (CVE-2026-75542)
vulnerability in CVE-2026-75542 (CVE-2026-75542). Risk of unauthorized operations or information disclosure.
|