Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14365 |
|
Vulnerability in wordpress (CVE-2026-14365)
vulnerability in wordpress (CVE-2026-14365). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65667 |
|
Vulnerability in microsoft (CVE-2026-65667)
vulnerability in microsoft (CVE-2026-65667). Confidential information can be exposed externally.
|
| CVE-2026-62830 |
|
Vulnerability in microsoft (CVE-2026-62830)
vulnerability in microsoft (CVE-2026-62830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70636 |
|
Vulnerability in CVE-2026-70636 (CVE-2026-70636)
vulnerability in CVE-2026-70636 (CVE-2026-70636). Data can be tampered with by attackers.
|
| CVE-2026-67621 |
|
Vulnerability in CVE-2026-67621 (CVE-2026-67621)
vulnerability in CVE-2026-67621 (CVE-2026-67621). Data can be tampered with by attackers.
|
| CVE-2026-48085 |
|
Vulnerability in csrf (CVE-2026-48085)
vulnerability in csrf (CVE-2026-48085). Successful exploitation can lead to full system takeover. Exploitable via ``default``.
|
| CVE-2026-48088 |
|
Vulnerability in CVE-2026-48088 (CVE-2026-48088)
vulnerability in CVE-2026-48088 (CVE-2026-48088). Confidential information can be exposed externally. Exploitable via `POST /api/tenants/{tenantId}/staff/{staffId}/crypto`.
|
| CVE-2026-48077 |
|
Vulnerability in CVE-2026-48077 (CVE-2026-48077)
vulnerability in CVE-2026-48077 (CVE-2026-48077). Risk of unauthorized operations or information disclosure. Exploitable via ``encryptedPayload``.
|
| CVE-2026-48075 |
|
Vulnerability in CVE-2026-48075 (CVE-2026-48075)
vulnerability in CVE-2026-48075 (CVE-2026-48075). Data can be tampered with by attackers. Exploitable via `Authorization header`.
|
| CVE-2026-47765 |
|
Vulnerability in CVE-2026-47765 (CVE-2026-47765)
vulnerability in CVE-2026-47765 (CVE-2026-47765). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13399 |
|
Vulnerability in wordpress (CVE-2026-13399)
vulnerability in wordpress (CVE-2026-13399). Data can be tampered with by attackers.
|
| CVE-2026-64662 |
|
Vulnerability in statamic/cms (CVE-2026-64662)
vulnerability in statamic/cms (CVE-2026-64662). Confidential information can be exposed externally. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-64664 |
|
Information Disclosure in statamic/cms (CVE-2026-64664)
vulnerability in statamic/cms (CVE-2026-64664). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-18277 |
|
Vulnerability in escriptorium (CVE-2026-18277)
vulnerability in escriptorium (CVE-2026-18277). Data can be tampered with by attackers.
|
| CVE-2026-18276 |
|
Vulnerability in escriptorium (CVE-2026-18276)
vulnerability in escriptorium (CVE-2026-18276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66712 |
|
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
|
| CVE-2026-66708 |
|
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
|
| CVE-2026-66701 |
|
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
|
| CVE-2026-66699 |
|
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
|
| CVE-2026-66678 |
|
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
|
| CVE-2026-66452 |
|
Vulnerability in CVE-2026-66452 (CVE-2026-66452)
vulnerability in CVE-2026-66452 (CVE-2026-66452). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66470 |
|
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
|
| CVE-2026-65554 |
|
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
|
| CVE-2026-65541 |
|
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
|
| CVE-2026-65504 |
|
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
|
| CVE-2026-32548 |
|
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
|
| CVE-2026-28140 |
|
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
|
| CVE-2026-25403 |
|
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
|
| CVE-2026-28005 |
|
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
|
| CVE-2026-15246 |
|
Vulnerability in wordpress (CVE-2026-15246)
vulnerability in wordpress (CVE-2026-15246). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65551 |
|
Vulnerability in CVE-2026-65551 (CVE-2026-65551)
vulnerability in CVE-2026-65551 (CVE-2026-65551). Confidential information can be exposed externally.
|
| CVE-2026-11983 |
|
Vulnerability in wordpress (CVE-2026-11983)
vulnerability in wordpress (CVE-2026-11983). Risk of unauthorized operations or information disclosure. Exploitable via ``ai_ajax``.
|
| CVE-2025-9266 |
|
Vulnerability in wordpress (CVE-2025-9266)
vulnerability in wordpress (CVE-2025-9266). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19010 |
|
Vulnerability in CVE-2026-19010 (CVE-2026-19010)
vulnerability in CVE-2026-19010 (CVE-2026-19010). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16734 |
|
Vulnerability in wordpress (CVE-2026-16734)
vulnerability in wordpress (CVE-2026-16734). Data can be tampered with by attackers.
|
| CVE-2026-16290 |
|
Vulnerability in wordpress (CVE-2026-16290)
vulnerability in wordpress (CVE-2026-16290). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15991 |
|
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
|
| CVE-2026-71316 |
|
Vulnerability in nuxt (CVE-2026-71316)
vulnerability in nuxt (CVE-2026-71316). Confidential information can be exposed externally. Exploitable via ``routeRules``. Mitigation: upgrade to `4.5.1` or later.
|
| CVE-2026-70617 |
|
Vulnerability in CVE-2026-70617 (CVE-2026-70617)
vulnerability in CVE-2026-70617 (CVE-2026-70617). Confidential information can be exposed externally. Exploitable via `PUT /channels/{channel_id}/recipients/{user_id}`.
|
| CVE-2026-70618 |
|
Vulnerability in CVE-2026-70618 (CVE-2026-70618)
vulnerability in CVE-2026-70618 (CVE-2026-70618). Risk of unauthorized operations or information disclosure. Exploitable via `GET /guilds/{guild_id}/roles/{role_id}/member-ids`.
|
| CVE-2026-48168 |
|
Vulnerability in CVE-2026-48168 (CVE-2026-48168)
vulnerability in CVE-2026-48168 (CVE-2026-48168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70439 |
|
Vulnerability in CVE-2026-70439 (CVE-2026-70439)
vulnerability in CVE-2026-70439 (CVE-2026-70439). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70445 |
|
Vulnerability in CVE-2026-70445 (CVE-2026-70445)
vulnerability in CVE-2026-70445 (CVE-2026-70445). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70447 |
|
Vulnerability in CVE-2026-70447 (CVE-2026-70447)
vulnerability in CVE-2026-70447 (CVE-2026-70447). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70446 |
|
Vulnerability in CVE-2026-70446 (CVE-2026-70446)
vulnerability in CVE-2026-70446 (CVE-2026-70446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70435 |
|
Vulnerability in CVE-2026-70435 (CVE-2026-70435)
vulnerability in CVE-2026-70435 (CVE-2026-70435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70438 |
|
Vulnerability in CVE-2026-70438 (CVE-2026-70438)
vulnerability in CVE-2026-70438 (CVE-2026-70438). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70436 |
|
Vulnerability in CVE-2026-70436 (CVE-2026-70436)
vulnerability in CVE-2026-70436 (CVE-2026-70436). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70433 |
|
Vulnerability in CVE-2026-70433 (CVE-2026-70433)
vulnerability in CVE-2026-70433 (CVE-2026-70433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17613 |
|
Vulnerability in CVE-2026-17613 (CVE-2026-17613)
vulnerability in CVE-2026-17613 (CVE-2026-17613). Risk of unauthorized operations or information disclosure.
|