Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-17552 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-17552 (CVE-2026-17552)
SSRF in CVE-2026-17552 (CVE-2026-17552). Confidential information can be exposed externally.
|
| CVE-2026-59538 |
|
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
|
| CVE-2026-59533 |
|
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.
|
| CVE-2026-59549 |
|
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
|
| CVE-2026-59550 |
|
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
|
| CVE-2026-59527 |
|
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
|
| CVE-2026-61511 |
|
Vulnerability in CVE-2026-61511 (CVE-2026-61511)
vulnerability in CVE-2026-61511 (CVE-2026-61511). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65879 |
|
Vulnerability in CVE-2026-65879 (CVE-2026-65879)
vulnerability in CVE-2026-65879 (CVE-2026-65879). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58662 |
|
Out-of-Bounds Read in c (CVE-2026-58662)
vulnerability in c (CVE-2026-58662). Confidential information can be exposed externally.
|
| CVE-2026-58023 |
|
Out-of-Bounds Read in apache (CVE-2026-58023)
vulnerability in apache (CVE-2026-58023). Confidential information can be exposed externally.
|
| CVE-2026-55971 |
|
Vulnerability in c (CVE-2026-55971)
vulnerability in c (CVE-2026-55971). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48144 |
|
Vulnerability in apache (CVE-2026-48144)
vulnerability in apache (CVE-2026-48144). Confidential information can be exposed externally.
|
| CVE-2026-64535 |
|
Vulnerability in CVE-2026-64535 (CVE-2026-64535)
vulnerability in CVE-2026-64535 (CVE-2026-64535). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64534 |
|
Vulnerability in CVE-2026-64534 (CVE-2026-64534)
vulnerability in CVE-2026-64534 (CVE-2026-64534). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14289 |
|
Code Injection in wordpress (CVE-2026-14289)
code injection in wordpress (CVE-2026-14289). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13714 |
|
Unrestricted File Upload in wordpress (CVE-2026-13714)
vulnerability in wordpress (CVE-2026-13714). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13597 |
|
Authentication Bypass in wordpress (CVE-2026-13597)
authentication bypass in wordpress (CVE-2026-13597). Confidential information can be exposed externally.
|
| CVE-2026-13332 |
|
Authentication Bypass in wordpress (CVE-2026-13332)
authentication bypass in wordpress (CVE-2026-13332). Confidential information can be exposed externally.
|
| CVE-2026-12394 |
|
Privilege Escalation in wordpress (CVE-2026-12394)
vulnerability in wordpress (CVE-2026-12394). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64530 |
|
Vulnerability in CVE-2026-64530 (CVE-2026-64530)
vulnerability in CVE-2026-64530 (CVE-2026-64530). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66012 |
|
Vulnerability in CVE-2026-66012 (CVE-2026-66012)
vulnerability in CVE-2026-66012 (CVE-2026-66012). Successful exploitation can lead to full system takeover. Exploitable via `POST /mcp`.
|
| CVE-2026-64523 |
|
Vulnerability in CVE-2026-64523 (CVE-2026-64523)
vulnerability in CVE-2026-64523 (CVE-2026-64523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64459 |
|
Vulnerability in c (CVE-2026-64459)
vulnerability in c (CVE-2026-64459). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64450 |
|
Vulnerability in CVE-2026-64450 (CVE-2026-64450)
vulnerability in CVE-2026-64450 (CVE-2026-64450). Confidential information can be exposed externally.
|
| CVE-2026-64439 |
|
Vulnerability in c (CVE-2026-64439)
vulnerability in c (CVE-2026-64439). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64410 |
|
Vulnerability in CVE-2026-64410 (CVE-2026-64410)
vulnerability in CVE-2026-64410 (CVE-2026-64410). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64399 |
|
Vulnerability in CVE-2026-64399 (CVE-2026-64399)
vulnerability in CVE-2026-64399 (CVE-2026-64399). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64397 |
|
Vulnerability in CVE-2026-64397 (CVE-2026-64397)
vulnerability in CVE-2026-64397 (CVE-2026-64397). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64393 |
|
Vulnerability in CVE-2026-64393 (CVE-2026-64393)
vulnerability in CVE-2026-64393 (CVE-2026-64393). Data can be tampered with by attackers.
|
| CVE-2026-64387 |
|
Vulnerability in CVE-2026-64387 (CVE-2026-64387)
vulnerability in CVE-2026-64387 (CVE-2026-64387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64391 |
|
Vulnerability in CVE-2026-64391 (CVE-2026-64391)
vulnerability in CVE-2026-64391 (CVE-2026-64391). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64392 |
|
Vulnerability in CVE-2026-64392 (CVE-2026-64392)
vulnerability in CVE-2026-64392 (CVE-2026-64392). Data can be tampered with by attackers.
|
| CVE-2026-64383 |
|
Vulnerability in CVE-2026-64383 (CVE-2026-64383)
vulnerability in CVE-2026-64383 (CVE-2026-64383). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64385 |
|
Vulnerability in CVE-2026-64385 (CVE-2026-64385)
vulnerability in CVE-2026-64385 (CVE-2026-64385). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64386 |
|
Vulnerability in CVE-2026-64386 (CVE-2026-64386)
vulnerability in CVE-2026-64386 (CVE-2026-64386). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64384 |
|
Vulnerability in CVE-2026-64384 (CVE-2026-64384)
vulnerability in CVE-2026-64384 (CVE-2026-64384). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64355 |
|
Vulnerability in CVE-2026-64355 (CVE-2026-64355)
vulnerability in CVE-2026-64355 (CVE-2026-64355). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64319 |
|
Vulnerability in CVE-2026-64319 (CVE-2026-64319)
vulnerability in CVE-2026-64319 (CVE-2026-64319). Confidential information can be exposed externally.
|
| CVE-2026-64320 |
|
Vulnerability in c (CVE-2026-64320)
vulnerability in c (CVE-2026-64320). Confidential information can be exposed externally.
|
| CVE-2026-64303 |
|
Vulnerability in CVE-2026-64303 (CVE-2026-64303)
vulnerability in CVE-2026-64303 (CVE-2026-64303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64268 |
|
Out-of-Bounds Write in c (CVE-2026-64268)
out-of-bounds write in c (CVE-2026-64268). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64269 |
|
Vulnerability in linux (CVE-2026-64269)
vulnerability in linux (CVE-2026-64269). Confidential information can be exposed externally.
|
| CVE-2026-64257 |
|
Vulnerability in linux (CVE-2026-64257)
vulnerability in linux (CVE-2026-64257). Confidential information can be exposed externally.
|
| CVE-2026-16766 |
|
OS Command Injection in CVE-2026-16766 (CVE-2026-16766)
OS command injection in CVE-2026-16766 (CVE-2026-16766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16280 |
|
Vulnerability in imaginationtech (CVE-2026-16280)
vulnerability in imaginationtech (CVE-2026-16280). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73567 |
|
Vulnerability in sm-crypto (CVE-2026-73567)
vulnerability in sm-crypto (CVE-2026-73567). Confidential information can be exposed externally. Exploitable via ``SecureRandom``. Mitigation: upgrade to `0.5.0` or later.
|
| CVE-2026-73644 |
|
Vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644)
vulnerability in org.openidentityplatform.opendj:opendj-server-legacy (CVE-2026-73644). Confidential information can be exposed externally. Mitigation: upgrade to `5.1.2` or later.
|
| CVE-2026-62835 |
|
Vulnerability in microsoft (CVE-2026-62835)
vulnerability in microsoft (CVE-2026-62835). Confidential information can be exposed externally.
|
| CVE-2026-48021 |
|
Vulnerability in CVE-2026-48021 (CVE-2026-48021)
vulnerability in CVE-2026-48021 (CVE-2026-48021). Confidential information can be exposed externally.
|
| CVE-2026-73649 |
|
Code Injection in velocityjs (CVE-2026-73649)
code injection in velocityjs (CVE-2026-73649). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.1.7` or later.
|