Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-65640 |
|
Unrestricted File Upload in wordpress (CVE-2026-65640)
vulnerability in wordpress (CVE-2026-65640). Successful exploitation can lead to full system takeover. Exploitable via ``upload_files``.
|
| CVE-2026-67678 |
|
Unrestricted File Upload in CVE-2026-67678 (CVE-2026-67678)
vulnerability in CVE-2026-67678 (CVE-2026-67678). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50768 |
|
Unrestricted File Upload in CVE-2026-50768 (CVE-2026-50768)
vulnerability in CVE-2026-50768 (CVE-2026-50768). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16137 |
|
Path Traversal in path-traversal (CVE-2026-16137)
path traversal in path-traversal (CVE-2026-16137). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74845 |
|
Unrestricted File Upload in CVE-2026-74845 (CVE-2026-74845)
vulnerability in CVE-2026-74845 (CVE-2026-74845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16098 |
|
Unrestricted File Upload in wordpress (CVE-2026-16098)
vulnerability in wordpress (CVE-2026-16098). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14498 |
|
Unrestricted File Upload in wordpress (CVE-2026-14498)
vulnerability in wordpress (CVE-2026-14498). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74767 |
|
Unrestricted File Upload in CVE-2026-74767 (CVE-2026-74767)
vulnerability in CVE-2026-74767 (CVE-2026-74767). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15965 |
|
Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19839 |
|
Vulnerability in CVE-2026-19839 (CVE-2026-19839)
vulnerability in CVE-2026-19839 (CVE-2026-19839). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66271 |
|
Unrestricted File Upload in dell (CVE-2026-66271)
vulnerability in dell (CVE-2026-66271). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66270 |
|
Unrestricted File Upload in dell (CVE-2026-66270)
vulnerability in dell (CVE-2026-66270). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49827 |
|
Vulnerability in CVE-2026-49827 (CVE-2026-49827)
vulnerability in CVE-2026-49827 (CVE-2026-49827). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65939 |
|
Path Traversal in CVE-2026-65939 (CVE-2026-65939)
path traversal in CVE-2026-65939 (CVE-2026-65939). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18391 |
|
Unrestricted File Upload in wordpress (CVE-2026-18391)
vulnerability in wordpress (CVE-2026-18391). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15039 |
|
Unrestricted File Upload in wordpress (CVE-2026-15039)
vulnerability in wordpress (CVE-2026-15039). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55676 |
|
Unrestricted File Upload in nginx (CVE-2026-55676)
vulnerability in nginx (CVE-2026-55676). Successful exploitation can lead to full system takeover. Exploitable via `POST /server/php/submit.php`.
|
| CVE-2026-13457 |
|
Unrestricted File Upload in wordpress (CVE-2026-13457)
vulnerability in wordpress (CVE-2026-13457). Confidential information can be exposed externally.
|
| CVE-2025-31114 |
|
Vulnerability in CVE-2025-31114 (CVE-2025-31114)
vulnerability in CVE-2025-31114 (CVE-2025-31114). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72762 |
|
Unrestricted File Upload in CVE-2026-72762 (CVE-2026-72762)
vulnerability in CVE-2026-72762 (CVE-2026-72762). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72557 |
|
Unrestricted File Upload in CVE-2026-72557 (CVE-2026-72557)
vulnerability in CVE-2026-72557 (CVE-2026-72557). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24330 |
|
Unrestricted File Upload in CVE-2026-24330 (CVE-2026-24330)
vulnerability in CVE-2026-24330 (CVE-2026-24330). Confidential information can be exposed externally.
|
| CVE-2026-72592 |
|
Unrestricted File Upload in CVE-2026-72592 (CVE-2026-72592)
vulnerability in CVE-2026-72592 (CVE-2026-72592). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19089 |
|
Unrestricted File Upload in wordpress (CVE-2026-19089)
vulnerability in wordpress (CVE-2026-19089). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16985 |
|
Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19383 |
|
Vulnerability in CVE-2026-19383 (CVE-2026-19383)
vulnerability in CVE-2026-19383 (CVE-2026-19383). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19210 |
|
Vulnerability in CVE-2026-19210 (CVE-2026-19210)
vulnerability in CVE-2026-19210 (CVE-2026-19210). Risk of unauthorized operations or information disclosure.
|
| CVE-2022-4995 |
|
Unrestricted File Upload in CVE-2022-4995 (CVE-2022-4995)
vulnerability in CVE-2022-4995 (CVE-2022-4995). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70558 |
|
Unrestricted File Upload in CVE-2026-70558 (CVE-2026-70558)
vulnerability in CVE-2026-70558 (CVE-2026-70558). Successful exploitation can lead to full system takeover. Exploitable via `POST /download/uploadFromRsByLocal`.
|
| CVE-2026-67688 |
|
Unrestricted File Upload in CVE-2026-67688 (CVE-2026-67688)
vulnerability in CVE-2026-67688 (CVE-2026-67688). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3418 |
|
Unrestricted File Upload in CVE-2026-3418 (CVE-2026-3418)
vulnerability in CVE-2026-3418 (CVE-2026-3418). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19065 |
|
Vulnerability in CVE-2026-19065 (CVE-2026-19065)
vulnerability in CVE-2026-19065 (CVE-2026-19065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71434 |
|
Unrestricted File Upload in statamic/cms (CVE-2026-71434)
vulnerability in statamic/cms (CVE-2026-71434). Risk of unauthorized operations or information disclosure. Exploitable via ``assets``. Mitigation: upgrade to `5.74.3` or later.
|
| CVE-2026-66665 |
|
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
|
| CVE-2026-18969 |
|
Vulnerability in CVE-2026-18969 (CVE-2026-18969)
vulnerability in CVE-2026-18969 (CVE-2026-18969). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18927 |
|
Vulnerability in CVE-2026-18927 (CVE-2026-18927)
vulnerability in CVE-2026-18927 (CVE-2026-18927). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18933 |
|
Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6147 |
|
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
|
| CVE-2026-54416 |
|
Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14553 |
|
Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
|
| CVE-2026-65986 |
|
Cross-Site Scripting (XSS) in CVE-2026-65986 (CVE-2026-65986)
cross-site scripting in CVE-2026-65986 (CVE-2026-65986). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18788 |
|
Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14175 |
|
Unrestricted File Upload in CVE-2026-14175 (CVE-2026-14175)
vulnerability in CVE-2026-14175 (CVE-2026-14175). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67243 |
|
Unrestricted File Upload in jvn (CVE-2026-67243)
vulnerability in jvn (CVE-2026-67243). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16548 |
|
Unrestricted File Upload in wordpress (CVE-2026-16548)
vulnerability in wordpress (CVE-2026-16548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16618 |
|
Unrestricted File Upload in wordpress (CVE-2026-16618)
vulnerability in wordpress (CVE-2026-16618). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61524 |
|
Unrestricted File Upload in CVE-2026-61524 (CVE-2026-61524)
vulnerability in CVE-2026-61524 (CVE-2026-61524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39931 |
|
Unrestricted File Upload in sqli (CVE-2026-39931)
vulnerability in sqli (CVE-2026-39931). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16060 |
|
Unrestricted File Upload in wordpress (CVE-2026-16060)
vulnerability in wordpress (CVE-2026-16060). Successful exploitation can lead to full system takeover.
|