Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75807 |
|
Authentication Bypass in wordpress (CVE-2026-75807)
authentication bypass in wordpress (CVE-2026-75807). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82475 |
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
| CVE-2026-82469 |
|
Vulnerability in CVE-2026-82469 (CVE-2026-82469)
vulnerability in CVE-2026-82469 (CVE-2026-82469). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-82463 |
|
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in...
|
| CVE-2026-82466 |
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
| CVE-2026-82454 |
|
Vulnerability in CVE-2026-82454 (CVE-2026-82454)
vulnerability in CVE-2026-82454 (CVE-2026-82454). Confidential information can be exposed externally.
|
| CVE-2026-82452 |
|
Vulnerability in c (CVE-2026-82452)
vulnerability in c (CVE-2026-82452). Successful exploitation can lead to full system takeover.
|
| CVE-2026-82273 |
|
Vulnerability in CVE-2026-82273 (CVE-2026-82273)
vulnerability in CVE-2026-82273 (CVE-2026-82273). Confidential information can be exposed externally. Exploitable via `GET /api/memory/threads`.
|
| CVE-2026-82276 |
|
Vulnerability in CVE-2026-82276 (CVE-2026-82276)
vulnerability in CVE-2026-82276 (CVE-2026-82276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-81777 |
|
Vulnerability in CVE-2026-81777 (CVE-2026-81777)
vulnerability in CVE-2026-81777 (CVE-2026-81777). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76581 |
|
Vulnerability in wordpress (CVE-2026-76581)
vulnerability in wordpress (CVE-2026-76581). Successful exploitation can lead to full system takeover. Exploitable via ``wdpsso_step1``.
|
| CVE-2026-6286 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6286)
cross-site scripting in wordpress (CVE-2026-6286). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75325 |
|
Authentication Bypass in CVE-2026-75325 (CVE-2026-75325)
authentication bypass in CVE-2026-75325 (CVE-2026-75325). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15985 |
|
Vulnerability in wordpress (CVE-2026-15985)
vulnerability in wordpress (CVE-2026-15985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80196 |
|
Vulnerability in CVE-2026-80196 (CVE-2026-80196)
vulnerability in CVE-2026-80196 (CVE-2026-80196). Confidential information can be exposed externally.
|
| CVE-2026-41707 |
|
Vulnerability in CVE-2026-41707 (CVE-2026-41707)
vulnerability in CVE-2026-41707 (CVE-2026-41707). Confidential information can be exposed externally.
|
| CVE-2026-16639 |
|
Vulnerability in drupal (CVE-2026-16639)
vulnerability in drupal (CVE-2026-16639). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65905 |
|
Vulnerability in apache (CVE-2026-65905)
vulnerability in apache (CVE-2026-65905). Successful exploitation can lead to full system takeover.
|
| CVE-2026-77998 |
|
Vulnerability in CVE-2026-77998 (CVE-2026-77998)
vulnerability in CVE-2026-77998 (CVE-2026-77998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79668 |
|
Vulnerability in CVE-2026-79668 (CVE-2026-79668)
vulnerability in CVE-2026-79668 (CVE-2026-79668). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/echo/like/`.
|
| CVE-2026-75037 |
|
Vulnerability in CVE-2026-75037 (CVE-2026-75037)
vulnerability in CVE-2026-75037 (CVE-2026-75037). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67578 |
|
FA-50 all versions miss authentication for some configuration.
An attacker with access to the...
FA-50 all versions miss authentication for some configuration.
An attacker with access to the...
|
| CVE-2026-19851 |
|
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17...
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17...
|
| CVE-2026-76839 |
|
Vulnerability in CVE-2026-76839 (CVE-2026-76839)
vulnerability in CVE-2026-76839 (CVE-2026-76839). Confidential information can be exposed externally.
|
| CVE-2026-56707 |
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
| CVE-2026-34968 |
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
| CVE-2026-77337 |
|
Vulnerability in CVE-2026-77337 (CVE-2026-77337)
vulnerability in CVE-2026-77337 (CVE-2026-77337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71505 |
|
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
|
| CVE-2026-77915 |
|
Vulnerability in CVE-2026-77915 (CVE-2026-77915)
vulnerability in CVE-2026-77915 (CVE-2026-77915). Successful exploitation can lead to full system takeover. Exploitable via `POST /register`.
|
| CVE-2026-67602 |
|
Vulnerability in CVE-2026-67602 (CVE-2026-67602)
vulnerability in CVE-2026-67602 (CVE-2026-67602). Confidential information can be exposed externally.
|
| CVE-2026-59564 |
|
Vulnerability in CVE-2026-59564 (CVE-2026-59564)
vulnerability in CVE-2026-59564 (CVE-2026-59564). Confidential information can be exposed externally.
|
| CVE-2026-59808 |
|
Vulnerability in CVE-2026-59808 (CVE-2026-59808)
vulnerability in CVE-2026-59808 (CVE-2026-59808). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34741 |
|
Vulnerability in CVE-2026-34741 (CVE-2026-34741)
vulnerability in CVE-2026-34741 (CVE-2026-34741). Data can be tampered with by attackers.
|
| CVE-2026-27490 |
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
|
| CVE-2026-30866 |
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
|
| CVE-2026-77264 |
|
Vulnerability in wordpress (CVE-2026-77264)
vulnerability in wordpress (CVE-2026-77264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16323 |
|
Vulnerability in CVE-2026-16323 (CVE-2026-16323)
vulnerability in CVE-2026-16323 (CVE-2026-16323). Confidential information can be exposed externally.
|
| CVE-2026-16520 |
|
Vulnerability in sqli (CVE-2026-16520)
vulnerability in sqli (CVE-2026-16520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53424 |
|
Vulnerability in CVE-2026-53424 (CVE-2026-53424)
vulnerability in CVE-2026-53424 (CVE-2026-53424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15706 |
|
Vulnerability in CVE-2026-15706 (CVE-2026-15706)
vulnerability in CVE-2026-15706 (CVE-2026-15706). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64961 |
|
Vulnerability in c (CVE-2026-64961)
vulnerability in c (CVE-2026-64961). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63722 |
|
Vulnerability in csrf (CVE-2026-63722)
vulnerability in csrf (CVE-2026-63722). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73136 |
|
Vulnerability in CVE-2026-73136 (CVE-2026-73136)
vulnerability in CVE-2026-73136 (CVE-2026-73136). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67581 |
|
Vulnerability in CVE-2026-67581 (CVE-2026-67581)
vulnerability in CVE-2026-67581 (CVE-2026-67581). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76208 |
|
Vulnerability in CVE-2026-76208 (CVE-2026-76208)
vulnerability in CVE-2026-76208 (CVE-2026-76208). Data can be tampered with by attackers. Mitigation: upgrade to `4.1.7` or later.
|
| CVE-2026-76207 |
|
Vulnerability in CVE-2026-76207 (CVE-2026-76207)
vulnerability in CVE-2026-76207 (CVE-2026-76207). Confidential information can be exposed externally.
|
| CVE-2026-75919 |
|
Vulnerability in CVE-2026-75919 (CVE-2026-75919)
vulnerability in CVE-2026-75919 (CVE-2026-75919). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/setup/update-database`.
|
| CVE-2021-43718 |
|
Vulnerability in dos (CVE-2021-43718)
vulnerability in dos (CVE-2021-43718). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71878 |
|
Vulnerability in CVE-2026-71878 (CVE-2026-71878)
vulnerability in CVE-2026-71878 (CVE-2026-71878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71879 |
|
Vulnerability in CVE-2026-71879 (CVE-2026-71879)
vulnerability in CVE-2026-71879 (CVE-2026-71879). Risk of unauthorized operations or information disclosure.
|