Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-17157 Out-of-Bounds Write in ibm (CVE-2026-17157)
out-of-bounds write in ibm (CVE-2026-17157). Successful exploitation can lead to full system takeover.
CVE-2026-17152 Out-of-Bounds Write in ibm (CVE-2026-17152)
out-of-bounds write in ibm (CVE-2026-17152). Successful exploitation can lead to full system takeover.
CVE-2026-17145 Privilege Escalation in ibm (CVE-2026-17145)
vulnerability in ibm (CVE-2026-17145). Successful exploitation can lead to full system takeover.
CVE-2026-17142 Authentication Bypass in ibm (CVE-2026-17142)
authentication bypass in ibm (CVE-2026-17142). Successful exploitation can lead to full system takeover.
CVE-2026-17141 Out-of-Bounds Write in ibm (CVE-2026-17141)
out-of-bounds write in ibm (CVE-2026-17141). Successful exploitation can lead to full system takeover.
CVE-2026-17136 Vulnerability in ibm (CVE-2026-17136)
vulnerability in ibm (CVE-2026-17136). Successful exploitation can lead to full system takeover.
CVE-2026-17122 Out-of-Bounds Write in ibm (CVE-2026-17122)
out-of-bounds write in ibm (CVE-2026-17122). Successful exploitation can lead to full system takeover.
CVE-2026-17118 Use-After-Free in ibm (CVE-2026-17118)
vulnerability in ibm (CVE-2026-17118). Successful exploitation can lead to full system takeover.
CVE-2026-17040 Vulnerability in ibm (CVE-2026-17040)
vulnerability in ibm (CVE-2026-17040). Successful exploitation can lead to full system takeover.
CVE-2026-67567 Vulnerability in c (CVE-2026-67567)
vulnerability in c (CVE-2026-67567). Successful exploitation can lead to full system takeover.
CVE-2026-71485 Vulnerability in CVE-2026-71485 (CVE-2026-71485)
vulnerability in CVE-2026-71485 (CVE-2026-71485). Confidential information can be exposed externally.
CVE-2026-43798 Vulnerability in CVE-2026-43798 (CVE-2026-43798)
vulnerability in CVE-2026-43798 (CVE-2026-43798). Successful exploitation can lead to full system takeover.
CVE-2026-77148 Buffer Overflow in CVE-2026-77148 (CVE-2026-77148)
vulnerability in CVE-2026-77148 (CVE-2026-77148). Successful exploitation can lead to full system takeover.
CVE-2026-66788 Vulnerability in privilege-escalation (CVE-2026-66788)
vulnerability in privilege-escalation (CVE-2026-66788). Successful exploitation can lead to full system takeover.
CVE-2026-66785 Vulnerability in CVE-2026-66785 (CVE-2026-66785)
vulnerability in CVE-2026-66785 (CVE-2026-66785). Successful exploitation can lead to full system takeover.
CVE-2026-73257 Vulnerability in c (CVE-2026-73257)
vulnerability in c (CVE-2026-73257). Confidential information can be exposed externally.
CVE-2026-73256 Vulnerability in c (CVE-2026-73256)
vulnerability in c (CVE-2026-73256). Confidential information can be exposed externally.
CVE-2026-77022 Buffer Overflow in c (CVE-2026-77022)
vulnerability in c (CVE-2026-77022). Successful exploitation can lead to full system takeover.
CVE-2026-71428 Open Redirect in CVE-2026-71428 (CVE-2026-71428)
vulnerability in CVE-2026-71428 (CVE-2026-71428). Confidential information can be exposed externally.
CVE-2026-55642 Vulnerability in CVE-2026-55642 (CVE-2026-55642)
vulnerability in CVE-2026-55642 (CVE-2026-55642). Successful exploitation can lead to full system takeover.
CVE-2026-18265 Vulnerability in CVE-2026-18265 (CVE-2026-18265)
vulnerability in CVE-2026-18265 (CVE-2026-18265). Successful exploitation can lead to full system takeover.
CVE-2026-63039 SQL Injection in apache (CVE-2026-63039)
SQL injection in apache (CVE-2026-63039). Successful exploitation can lead to full system takeover.
CVE-2026-63038 SQL Injection in apache (CVE-2026-63038)
SQL injection in apache (CVE-2026-63038). Successful exploitation can lead to full system takeover.
CVE-2026-63037 SQL Injection in apache (CVE-2026-63037)
SQL injection in apache (CVE-2026-63037). Successful exploitation can lead to full system takeover.
CVE-2026-16926 Vulnerability in ibm (CVE-2026-16926)
vulnerability in ibm (CVE-2026-16926). Data can be tampered with by attackers.
CVE-2026-15706 Vulnerability in CVE-2026-15706 (CVE-2026-15706)
vulnerability in CVE-2026-15706 (CVE-2026-15706). Successful exploitation can lead to full system takeover.
CVE-2026-28164 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-28164)
vulnerability in csrf (CVE-2026-28164). Successful exploitation can lead to full system takeover.
CVE-2026-18482 OS Command Injection in CVE-2026-18482 (CVE-2026-18482)
OS command injection in CVE-2026-18482 (CVE-2026-18482). Successful exploitation can lead to full system takeover.
CVE-2026-74018 Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
CVE-2026-74016 Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
CVE-2026-74014 Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
CVE-2026-73993 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
CVE-2026-73992 Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
CVE-2026-68566 Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
CVE-2026-66680 Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
CVE-2026-66682 Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-74001 Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVE-2026-66609 Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
CVE-2026-66672 Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.
CVE-2026-66649 Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
CVE-2026-66600 Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.
CVE-2026-66593 Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
CVE-2026-66592 Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
CVE-2025-15689 Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVE-2026-66583 Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.
CVE-2025-15688 Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
CVE-2026-11861 Vulnerability in freeipa (CVE-2026-11861)
vulnerability in freeipa (CVE-2026-11861). Confidential information can be exposed externally.
CVE-2026-14950 Vulnerability in CVE-2026-14950 (CVE-2026-14950)
vulnerability in CVE-2026-14950 (CVE-2026-14950). Successful exploitation can lead to full system takeover.
CVE-2026-75860 Privilege Escalation in wordpress (CVE-2026-75860)
vulnerability in wordpress (CVE-2026-75860). Successful exploitation can lead to full system takeover.
CVE-2026-76850 Unsafe Deserialization in deserialization (CVE-2026-76850)
vulnerability in deserialization (CVE-2026-76850). Successful exploitation can lead to full system takeover. Exploitable via `POST /distserve/p2p_initialize`.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →