Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: cwe-288 Clear
ID Title
CVE-2026-82269 Vulnerability in CVE-2026-82269 (CVE-2026-82269)
vulnerability in CVE-2026-82269 (CVE-2026-82269). Confidential information can be exposed externally.
CVE-2026-76943 Vulnerability in CVE-2026-76943 (CVE-2026-76943)
vulnerability in CVE-2026-76943 (CVE-2026-76943). Successful exploitation can lead to full system takeover.
CVE-2026-65641 Vulnerability in CVE-2026-65641 (CVE-2026-65641)
vulnerability in CVE-2026-65641 (CVE-2026-65641). Risk of unauthorized operations or information disclosure.
CVE-2026-3035 Vulnerability in CVE-2026-3035 (CVE-2026-3035)
vulnerability in CVE-2026-3035 (CVE-2026-3035). Risk of unauthorized operations or information disclosure.
CVE-2026-58092 Vulnerability in privilege-escalation (CVE-2026-58092)
vulnerability in privilege-escalation (CVE-2026-58092). Confidential information can be exposed externally.
CVE-2026-16639 Vulnerability in drupal (CVE-2026-16639)
vulnerability in drupal (CVE-2026-16639). Successful exploitation can lead to full system takeover.
CVE-2026-63587 Vulnerability in CVE-2026-63587 (CVE-2026-63587)
vulnerability in CVE-2026-63587 (CVE-2026-63587). Risk of unauthorized operations or information disclosure.
CVE-2026-78259 Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
CVE-2026-74001 Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
CVE-2026-66677 Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
CVE-2026-19490 Vulnerability in CVE-2026-19490 (CVE-2026-19490)
vulnerability in CVE-2026-19490 (CVE-2026-19490). Risk of unauthorized operations or information disclosure.
CVE-2026-50191 Authentication Bypass in CVE-2026-50191 (CVE-2026-50191)
authentication bypass in CVE-2026-50191 (CVE-2026-50191). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/register`.
CVE-2026-24185 Vulnerability in CVE-2026-24185 (CVE-2026-24185)
vulnerability in CVE-2026-24185 (CVE-2026-24185). Successful exploitation can lead to full system takeover.
CVE-2021-43718 Vulnerability in dos (CVE-2021-43718)
vulnerability in dos (CVE-2021-43718). Risk of unauthorized operations or information disclosure.
CVE-2026-71879 Vulnerability in CVE-2026-71879 (CVE-2026-71879)
vulnerability in CVE-2026-71879 (CVE-2026-71879). Risk of unauthorized operations or information disclosure.
CVE-2026-73396 Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
CVE-2026-73399 Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
CVE-2026-73381 Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73398 Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVE-2026-73379 Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-32481 Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
CVE-2026-75627 Vulnerability in CVE-2026-75627 (CVE-2026-75627)
vulnerability in CVE-2026-75627 (CVE-2026-75627). Successful exploitation can lead to full system takeover.
CVE-2026-75045 Vulnerability in CVE-2026-75045 (CVE-2026-75045)
vulnerability in CVE-2026-75045 (CVE-2026-75045). Confidential information can be exposed externally.
CVE-2026-73188 Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.
CVE-2026-66465 Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
CVE-2026-66453 Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
CVE-2026-70468 Vulnerability in CVE-2026-70468 (CVE-2026-70468)
vulnerability in CVE-2026-70468 (CVE-2026-70468). Successful exploitation can lead to full system takeover.
CVE-2026-18636 Vulnerability in CVE-2026-18636 (CVE-2026-18636)
vulnerability in CVE-2026-18636 (CVE-2026-18636). Confidential information can be exposed externally.
CVE-2026-72691 Vulnerability in CVE-2026-72691 (CVE-2026-72691)
vulnerability in CVE-2026-72691 (CVE-2026-72691). Confidential information can be exposed externally.
CVE-2026-66451 Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
CVE-2026-66425 Vulnerability in CVE-2026-66425 (CVE-2026-66425)
vulnerability in CVE-2026-66425 (CVE-2026-66425). Risk of unauthorized operations or information disclosure.
CVE-2026-65542 Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
CVE-2026-24254 Vulnerability in dos (CVE-2026-24254)
vulnerability in dos (CVE-2026-24254). Successful exploitation can lead to full system takeover.
CVE-2026-58073 Vulnerability in CVE-2026-58073 (CVE-2026-58073)
vulnerability in CVE-2026-58073 (CVE-2026-58073). Risk of unauthorized operations or information disclosure.
CVE-2026-68584 Vulnerability in CVE-2026-68584 (CVE-2026-68584)
vulnerability in CVE-2026-68584 (CVE-2026-68584). Confidential information can be exposed externally.
CVE-2026-18574 Vulnerability in CVE-2026-18574 (CVE-2026-18574)
vulnerability in CVE-2026-18574 (CVE-2026-18574). Risk of unauthorized operations or information disclosure.
CVE-2026-33591 Vulnerability in CVE-2026-33591 (CVE-2026-33591)
vulnerability in CVE-2026-33591 (CVE-2026-33591). Risk of unauthorized operations or information disclosure.
CVE-2026-18577 KEV [KEV] Vulnerability in N-able n-central (CVE-2026-18577)
vulnerability in N-able n-central (CVE-2026-18577). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-18556 KEV [KEV] Vulnerability in N-able n-central (CVE-2026-18556)
vulnerability in N-able n-central (CVE-2026-18556). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2026-67337 Vulnerability in CVE-2026-67337 (CVE-2026-67337)
vulnerability in CVE-2026-67337 (CVE-2026-67337). Confidential information can be exposed externally.
CVE-2026-8338 Vulnerability in CVE-2026-8338 (CVE-2026-8338)
vulnerability in CVE-2026-8338 (CVE-2026-8338). Risk of unauthorized operations or information disclosure.
CVE-2026-20079 Vulnerability in cisco (CVE-2026-20079)
vulnerability in cisco (CVE-2026-20079). Successful exploitation can lead to full system takeover.
CVE-2026-12703 Vulnerability in CVE-2026-12703 (CVE-2026-12703)
vulnerability in CVE-2026-12703 (CVE-2026-12703). Successful exploitation can lead to full system takeover.
CVE-2026-18047 Vulnerability in tomcat (CVE-2026-18047)
vulnerability in tomcat (CVE-2026-18047). Risk of unauthorized operations or information disclosure.
CVE-2026-15014 Vulnerability in wordpress (CVE-2026-15014)
vulnerability in wordpress (CVE-2026-15014). Successful exploitation can lead to full system takeover. Exploitable via ``billing_phone``.
CVE-2026-59545 Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVE-2026-59524 Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions.
CVE-2026-22049 Vulnerability in netapp (CVE-2026-22049)
vulnerability in netapp (CVE-2026-22049). Successful exploitation can lead to full system takeover.
CVE-2026-61884 Vulnerability in cisa (CVE-2026-61884)
vulnerability in cisa (CVE-2026-61884). Successful exploitation can lead to full system takeover.
CVE-2026-61425 Vulnerability in CVE-2026-61425 (CVE-2026-61425)
vulnerability in CVE-2026-61425 (CVE-2026-61425). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →