Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-76987 Buffer Overflow in CVE-2026-76987 (CVE-2026-76987)
vulnerability in CVE-2026-76987 (CVE-2026-76987). Risk of unauthorized operations or information disclosure.
CVE-2026-74011 SQL Injection in sqli (CVE-2026-74011)
SQL injection in sqli (CVE-2026-74011). Confidential information can be exposed externally.
CVE-2026-28164 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-28164)
vulnerability in csrf (CVE-2026-28164). Successful exploitation can lead to full system takeover.
CVE-2026-28163 Vulnerability in CVE-2026-28163 (CVE-2026-28163)
vulnerability in CVE-2026-28163 (CVE-2026-28163). Risk of unauthorized operations or information disclosure.
CVE-2026-21784 Information Disclosure in CVE-2026-21784 (CVE-2026-21784)
vulnerability in CVE-2026-21784 (CVE-2026-21784). Risk of unauthorized operations or information disclosure.
CVE-2026-18482 OS Command Injection in CVE-2026-18482 (CVE-2026-18482)
OS command injection in CVE-2026-18482 (CVE-2026-18482). Successful exploitation can lead to full system takeover.
CVE-2025-62306 Vulnerability in CVE-2025-62306 (CVE-2025-62306)
vulnerability in CVE-2025-62306 (CVE-2025-62306). Risk of unauthorized operations or information disclosure.
CVE-2025-62300 Vulnerability in CVE-2025-62300 (CVE-2025-62300)
vulnerability in CVE-2025-62300 (CVE-2025-62300). Data can be tampered with by attackers.
CVE-2025-62299 Vulnerability in CVE-2025-62299 (CVE-2025-62299)
vulnerability in CVE-2025-62299 (CVE-2025-62299). Confidential information can be exposed externally.
CVE-2026-77085 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-77085)
SSRF in ssrf (CVE-2026-77085). Risk of unauthorized operations or information disclosure.
CVE-2026-77068 Path Traversal in path-traversal (CVE-2026-77068)
path traversal in path-traversal (CVE-2026-77068). Risk of unauthorized operations or information disclosure.
CVE-2026-74018 Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
CVE-2026-77084 OS Command Injection in CVE-2026-77084 (CVE-2026-77084)
OS command injection in CVE-2026-77084 (CVE-2026-77084). Risk of unauthorized operations or information disclosure.
CVE-2026-74016 Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
CVE-2026-77070 Vulnerability in CVE-2026-77070 (CVE-2026-77070)
vulnerability in CVE-2026-77070 (CVE-2026-77070). Risk of unauthorized operations or information disclosure.
CVE-2026-73998 Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
CVE-2026-77072 Cross-Site Scripting (XSS) in CVE-2026-77072 (CVE-2026-77072)
cross-site scripting in CVE-2026-77072 (CVE-2026-77072). Risk of unauthorized operations or information disclosure.
CVE-2026-74013 Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
CVE-2026-77071 SQL Injection in CVE-2026-77071 (CVE-2026-77071)
SQL injection in CVE-2026-77071 (CVE-2026-77071). Risk of unauthorized operations or information disclosure.
CVE-2026-74020 Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.
Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.
CVE-2026-74014 Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
CVE-2026-77069 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-77069)
SSRF in ssrf (CVE-2026-77069). Risk of unauthorized operations or information disclosure.
CVE-2026-74021 Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.
Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.
CVE-2026-74019 Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
CVE-2026-73993 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-73402 Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
CVE-2026-73992 Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVE-2026-68564 Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
CVE-2026-68566 Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-66680 Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66682 Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-77074 Code Injection in CVE-2026-77074 (CVE-2026-77074)
code injection in CVE-2026-77074 (CVE-2026-77074). Risk of unauthorized operations or information disclosure.
CVE-2026-77079 Vulnerability in CVE-2026-77079 (CVE-2026-77079)
vulnerability in CVE-2026-77079 (CVE-2026-77079). Risk of unauthorized operations or information disclosure.
CVE-2026-77076 Vulnerability in CVE-2026-77076 (CVE-2026-77076)
vulnerability in CVE-2026-77076 (CVE-2026-77076). Risk of unauthorized operations or information disclosure.
CVE-2026-77082 Vulnerability in dos (CVE-2026-77082)
vulnerability in dos (CVE-2026-77082). Risk of unauthorized operations or information disclosure.
CVE-2026-77073 Vulnerability in CVE-2026-77073 (CVE-2026-77073)
vulnerability in CVE-2026-77073 (CVE-2026-77073). Risk of unauthorized operations or information disclosure.
CVE-2026-77083 Vulnerability in CVE-2026-77083 (CVE-2026-77083)
vulnerability in CVE-2026-77083 (CVE-2026-77083). Risk of unauthorized operations or information disclosure.
CVE-2026-77080 OS Command Injection in CVE-2026-77080 (CVE-2026-77080)
OS command injection in CVE-2026-77080 (CVE-2026-77080). Risk of unauthorized operations or information disclosure.
CVE-2026-77077 Code Injection in CVE-2026-77077 (CVE-2026-77077)
code injection in CVE-2026-77077 (CVE-2026-77077). Risk of unauthorized operations or information disclosure.
CVE-2026-77075 Code Injection in CVE-2026-77075 (CVE-2026-77075)
code injection in CVE-2026-77075 (CVE-2026-77075). Risk of unauthorized operations or information disclosure.
CVE-2026-77081 Vulnerability in CVE-2026-77081 (CVE-2026-77081)
vulnerability in CVE-2026-77081 (CVE-2026-77081). Risk of unauthorized operations or information disclosure.
CVE-2026-74001 Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVE-2026-66677 Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
CVE-2026-66605 Cross-Site Scripting (XSS) in CVE-2026-66605 (CVE-2026-66605)
cross-site scripting in CVE-2026-66605 (CVE-2026-66605). Risk of unauthorized operations or information disclosure.
CVE-2026-66673 Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
CVE-2026-66614 Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
CVE-2026-66612 Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
CVE-2026-66609 Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVE-2026-66647 Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
CVE-2026-66616 Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →