Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55553 |
|
Information Disclosure in urllib (CVE-2026-55553)
vulnerability in urllib (CVE-2026-55553). Confidential information can be exposed externally. Exploitable via `Cookie header`. Mitigation: upgrade to `2.44.1` or later.
|
| CVE-2026-66585 |
|
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
|
| CVE-2026-59809 |
|
Vulnerability in CVE-2026-59809 (CVE-2026-59809)
vulnerability in CVE-2026-59809 (CVE-2026-59809). Confidential information can be exposed externally.
|
| CVE-2026-63481 |
|
Vulnerability in CVE-2026-63481 (CVE-2026-63481)
vulnerability in CVE-2026-63481 (CVE-2026-63481). Risk of unauthorized operations or information disclosure. Exploitable via `Cookie header`.
|
| CVE-2026-75953 |
|
Vulnerability in CVE-2026-75953 (CVE-2026-75953)
vulnerability in CVE-2026-75953 (CVE-2026-75953). Confidential information can be exposed externally.
|
| CVE-2026-73386 |
|
Vulnerability in CVE-2026-73386 (CVE-2026-73386)
vulnerability in CVE-2026-73386 (CVE-2026-73386). Confidential information can be exposed externally.
|
| CVE-2026-73384 |
|
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
|
| CVE-2026-74008 |
|
Vulnerability in CVE-2026-74008 (CVE-2026-74008)
vulnerability in CVE-2026-74008 (CVE-2026-74008). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66463 |
|
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
|
| CVE-2026-66443 |
|
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
|
| CVE-2026-28174 |
|
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
|
| CVE-2026-16637 |
|
Vulnerability in ssrf (CVE-2026-16637)
vulnerability in ssrf (CVE-2026-16637). Confidential information can be exposed externally.
|
| CVE-2026-64652 |
|
Vulnerability in CVE-2026-64652 (CVE-2026-64652)
vulnerability in CVE-2026-64652 (CVE-2026-64652). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66696 |
|
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.
|
| CVE-2026-66685 |
|
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
|
| CVE-2026-66684 |
|
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
|
| CVE-2026-66683 |
|
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
|
| CVE-2026-65543 |
|
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
|
| CVE-2026-66901 |
|
Vulnerability in CVE-2026-66901 (CVE-2026-66901)
vulnerability in CVE-2026-66901 (CVE-2026-66901). Confidential information can be exposed externally.
|
| CVE-2026-20484 |
|
Vulnerability in mediatek (CVE-2026-20484)
vulnerability in mediatek (CVE-2026-20484). Confidential information can be exposed externally.
|
| CVE-2026-67355 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-67355)
vulnerability in guzzlehttp/guzzle (CVE-2026-67355). Confidential information can be exposed externally. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.15.1` or later.
|
| CVE-2026-67354 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-67354)
vulnerability in guzzlehttp/guzzle (CVE-2026-67354). Confidential information can be exposed externally. Exploitable via ``referer``. Mitigation: upgrade to `7.15.1` or later.
|
| CVE-2026-28144 |
|
Vulnerability in CVE-2026-28144 (CVE-2026-28144)
vulnerability in CVE-2026-28144 (CVE-2026-28144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6267 |
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
|
| CVE-2026-67425 |
|
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
|
| CVE-2026-54660 |
|
Information Disclosure in swagger-typescript-api (CVE-2026-54660)
vulnerability in swagger-typescript-api (CVE-2026-54660). Confidential information can be exposed externally. Exploitable via `GET /exfil-endpoint/data.json`. Mitigation: upgrade to `13.12.2` or later.
|
| CVE-2026-65434 |
|
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
|
| CVE-2026-66339 |
|
Vulnerability in gnome (CVE-2026-66339)
vulnerability in gnome (CVE-2026-66339). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-16798 |
|
Vulnerability in devolutions (CVE-2026-16798)
vulnerability in devolutions (CVE-2026-16798). Confidential information can be exposed externally.
|
| CVE-2026-27372 |
|
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
|
| CVE-2026-64643 |
|
Vulnerability in next (CVE-2026-64643)
vulnerability in next (CVE-2026-64643). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `16.2.11` or later.
|
| CVE-2026-12547 |
|
Vulnerability in CVE-2026-12547 (CVE-2026-12547)
vulnerability in CVE-2026-12547 (CVE-2026-12547). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
|
| CVE-2026-13380 |
|
Vulnerability in vsee (CVE-2026-13380)
vulnerability in vsee (CVE-2026-13380). Confidential information can be exposed externally.
|
| CVE-2026-7488 |
|
Vulnerability in CVE-2026-7488 (CVE-2026-7488)
vulnerability in CVE-2026-7488 (CVE-2026-7488). Confidential information can be exposed externally.
|
| CVE-2026-7189 |
|
Vulnerability in CVE-2026-7189 (CVE-2026-7189)
vulnerability in CVE-2026-7189 (CVE-2026-7189). Confidential information can be exposed externally.
|
| CVE-2026-54171 |
|
Vulnerability in excon (CVE-2026-54171)
vulnerability in excon (CVE-2026-54171). Confidential information can be exposed externally. Mitigation: upgrade to `1.5.0` or later.
|
| CVE-2026-1365 |
|
Vulnerability in CVE-2026-1365 (CVE-2026-1365)
vulnerability in CVE-2026-1365 (CVE-2026-1365). Confidential information can be exposed externally.
|
| CVE-2026-56460 |
|
Vulnerability in hcltechsw (CVE-2026-56460)
vulnerability in hcltechsw (CVE-2026-56460). Confidential information can be exposed externally.
|
| CVE-2026-42505 |
|
Vulnerability in golang (CVE-2026-42505)
vulnerability in golang (CVE-2026-42505). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59519 |
|
Vulnerability in CVE-2026-59519 (CVE-2026-59519)
vulnerability in CVE-2026-59519 (CVE-2026-59519). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59511 |
|
Vulnerability in CVE-2026-59511 (CVE-2026-59511)
vulnerability in CVE-2026-59511 (CVE-2026-59511). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57347 |
|
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
|
| CVE-2025-69132 |
|
Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
|
| CVE-2026-57736 |
|
Vulnerability in CVE-2026-57736 (CVE-2026-57736)
vulnerability in CVE-2026-57736 (CVE-2026-57736). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13211 |
|
Vulnerability in CVE-2026-13211 (CVE-2026-13211)
vulnerability in CVE-2026-13211 (CVE-2026-13211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12085 |
|
Vulnerability in ibm (CVE-2026-12085)
vulnerability in ibm (CVE-2026-12085). Confidential information can be exposed externally.
|
| CVE-2026-13437 |
|
Vulnerability in devolutions (CVE-2026-13437)
vulnerability in devolutions (CVE-2026-13437). Confidential information can be exposed externally.
|
| CVE-2026-55180 |
|
Information Disclosure in pnpm (CVE-2026-55180)
vulnerability in pnpm (CVE-2026-55180). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `11.5.3` or later.
|
| CVE-2026-57318 |
|
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.
|
| CVE-2026-54834 |
|
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
|