Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-6079 |
|
Vulnerability in wordpress (CVE-2026-6079)
vulnerability in wordpress (CVE-2026-6079). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6020 |
|
Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64581 |
|
Vulnerability in c (CVE-2026-64581)
vulnerability in c (CVE-2026-64581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64580 |
|
Vulnerability in c (CVE-2026-64580)
vulnerability in c (CVE-2026-64580). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64578 |
|
Vulnerability in c (CVE-2026-64578)
vulnerability in c (CVE-2026-64578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64577 |
|
Vulnerability in c (CVE-2026-64577)
vulnerability in c (CVE-2026-64577). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64576 |
|
Vulnerability in c (CVE-2026-64576)
vulnerability in c (CVE-2026-64576). Confidential information can be exposed externally.
|
| CVE-2026-64575 |
|
Vulnerability in c (CVE-2026-64575)
vulnerability in c (CVE-2026-64575). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64574 |
|
Vulnerability in c (CVE-2026-64574)
vulnerability in c (CVE-2026-64574). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64570 |
|
Vulnerability in c (CVE-2026-64570)
vulnerability in c (CVE-2026-64570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64568 |
|
Vulnerability in c (CVE-2026-64568)
vulnerability in c (CVE-2026-64568). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64567 |
|
Vulnerability in c (CVE-2026-64567)
vulnerability in c (CVE-2026-64567). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61485 |
|
Vulnerability in apache (CVE-2026-61485)
vulnerability in apache (CVE-2026-61485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61483 |
|
Vulnerability in apache (CVE-2026-61483)
vulnerability in apache (CVE-2026-61483). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59675 |
|
Vulnerability in CVE-2026-59675 (CVE-2026-59675)
vulnerability in CVE-2026-59675 (CVE-2026-59675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55997 |
|
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
|
| CVE-2026-55739 |
|
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
|
| CVE-2026-54418 |
|
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
|
| CVE-2026-54416 |
|
Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18881 |
|
SQL Injection in wordpress (CVE-2026-18881)
SQL injection in wordpress (CVE-2026-18881). Confidential information can be exposed externally. Exploitable via ``tableon_get_table_data``.
|
| CVE-2026-12000 |
|
Vulnerability in wordpress (CVE-2026-12000)
vulnerability in wordpress (CVE-2026-12000). Confidential information can be exposed externally.
|
| CVE-2026-70375 |
|
OS Command Injection in CVE-2026-70375 (CVE-2026-70375)
OS command injection in CVE-2026-70375 (CVE-2026-70375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70374 |
|
OS Command Injection in CVE-2026-70374 (CVE-2026-70374)
OS command injection in CVE-2026-70374 (CVE-2026-70374). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/{project}/{environment}/media/new.`.
|
| CVE-2026-68073 |
|
Vulnerability in apache (CVE-2026-68073)
vulnerability in apache (CVE-2026-68073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67592 |
|
Vulnerability in apache (CVE-2026-67592)
vulnerability in apache (CVE-2026-67592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67590 |
|
Vulnerability in apache (CVE-2026-67590)
vulnerability in apache (CVE-2026-67590). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67552 |
|
Vulnerability in apache (CVE-2026-67552)
vulnerability in apache (CVE-2026-67552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66274 |
|
Vulnerability in apache (CVE-2026-66274)
vulnerability in apache (CVE-2026-66274). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16736 |
|
Vulnerability in wordpress (CVE-2026-16736)
vulnerability in wordpress (CVE-2026-16736). Confidential information can be exposed externally.
|
| CVE-2026-16605 |
|
Vulnerability in wordpress (CVE-2026-16605)
vulnerability in wordpress (CVE-2026-16605). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16604 |
|
Information Disclosure in wordpress (CVE-2026-16604)
vulnerability in wordpress (CVE-2026-16604). Confidential information can be exposed externally.
|
| CVE-2026-16603 |
|
Information Disclosure in wordpress (CVE-2026-16603)
vulnerability in wordpress (CVE-2026-16603). Confidential information can be exposed externally.
|
| CVE-2026-16602 |
|
Information Disclosure in wordpress (CVE-2026-16602)
vulnerability in wordpress (CVE-2026-16602). Confidential information can be exposed externally.
|
| CVE-2026-16573 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16573)
cross-site scripting in wordpress (CVE-2026-16573). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16561 |
|
Vulnerability in wordpress (CVE-2026-16561)
vulnerability in wordpress (CVE-2026-16561). Confidential information can be exposed externally.
|
| CVE-2026-16055 |
|
Authentication Bypass in wordpress (CVE-2026-16055)
authentication bypass in wordpress (CVE-2026-16055). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16036 |
|
Authentication Bypass in wordpress (CVE-2026-16036)
authentication bypass in wordpress (CVE-2026-16036). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15372 |
|
Authentication Bypass in wordpress (CVE-2026-15372)
authentication bypass in wordpress (CVE-2026-15372). Confidential information can be exposed externally.
|
| CVE-2026-15230 |
|
Vulnerability in wordpress (CVE-2026-15230)
vulnerability in wordpress (CVE-2026-15230). Confidential information can be exposed externally.
|
| CVE-2026-14553 |
|
Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
|
| CVE-2026-8761 |
|
Vulnerability in wordpress (CVE-2026-8761)
vulnerability in wordpress (CVE-2026-8761). Successful exploitation can lead to full system takeover. Exploitable via ``CustomersController``.
|
| CVE-2026-68074 |
|
Vulnerability in apache (CVE-2026-68074)
vulnerability in apache (CVE-2026-68074). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67588 |
|
Vulnerability in apache (CVE-2026-67588)
vulnerability in apache (CVE-2026-67588). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67551 |
|
Vulnerability in apache (CVE-2026-67551)
vulnerability in apache (CVE-2026-67551). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67589 |
|
Vulnerability in apache (CVE-2026-67589)
vulnerability in apache (CVE-2026-67589). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68060 |
|
Vulnerability in apache (CVE-2026-68060)
vulnerability in apache (CVE-2026-68060). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66273 |
|
Vulnerability in apache (CVE-2026-66273)
vulnerability in apache (CVE-2026-66273). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67465 |
|
Vulnerability in apache (CVE-2026-67465)
vulnerability in apache (CVE-2026-67465). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66257 |
|
Vulnerability in apache (CVE-2026-66257)
vulnerability in apache (CVE-2026-66257). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15918 |
|
SQL Injection in wordpress (CVE-2026-15918)
SQL injection in wordpress (CVE-2026-15918). Confidential information can be exposed externally.
|