Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-18432 |
|
Privilege Escalation in wordpress (CVE-2026-18432)
vulnerability in wordpress (CVE-2026-18432). Successful exploitation can lead to full system takeover. Exploitable via ``item_id``.
|
| CVE-2026-15009 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15009)
cross-site scripting in wordpress (CVE-2026-15009). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15002 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15002)
cross-site scripting in wordpress (CVE-2026-15002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14524 |
|
Path Traversal in wordpress (CVE-2026-14524)
path traversal in wordpress (CVE-2026-14524). Data can be tampered with by attackers.
|
| CVE-2026-14498 |
|
Unrestricted File Upload in wordpress (CVE-2026-14498)
vulnerability in wordpress (CVE-2026-14498). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12477 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12477)
cross-site scripting in wordpress (CVE-2026-12477). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11780 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-11780)
cross-site scripting in wordpress (CVE-2026-11780). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2487 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-2487)
cross-site scripting in wordpress (CVE-2026-2487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19925 |
|
Vulnerability in sqli (CVE-2026-19925)
vulnerability in sqli (CVE-2026-19925). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19926 |
|
Vulnerability in sqli (CVE-2026-19926)
vulnerability in sqli (CVE-2026-19926). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19923 |
|
Vulnerability in sqli (CVE-2026-19923)
vulnerability in sqli (CVE-2026-19923). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19922 |
|
Cross-Site Scripting (XSS) in CVE-2026-19922 (CVE-2026-19922)
cross-site scripting in CVE-2026-19922 (CVE-2026-19922). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19920 |
|
Vulnerability in sqli (CVE-2026-19920)
vulnerability in sqli (CVE-2026-19920). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19921 |
|
Vulnerability in sqli (CVE-2026-19921)
vulnerability in sqli (CVE-2026-19921). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19917 |
|
Vulnerability in c (CVE-2026-19917)
vulnerability in c (CVE-2026-19917). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19919 |
|
Vulnerability in sqli (CVE-2026-19919)
vulnerability in sqli (CVE-2026-19919). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73053 |
|
Cross-Site Scripting (XSS) in CVE-2026-73053 (CVE-2026-73053)
cross-site scripting in CVE-2026-73053 (CVE-2026-73053). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74764 |
|
Path Traversal in path-traversal (CVE-2026-74764)
path traversal in path-traversal (CVE-2026-74764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73054 |
|
Authentication Bypass in CVE-2026-73054 (CVE-2026-73054)
authentication bypass in CVE-2026-73054 (CVE-2026-73054). Confidential information can be exposed externally.
|
| CVE-2026-73044 |
|
Cross-Site Scripting (XSS) in CVE-2026-73044 (CVE-2026-73044)
cross-site scripting in CVE-2026-73044 (CVE-2026-73044). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73050 |
|
Cross-Site Scripting (XSS) in CVE-2026-73050 (CVE-2026-73050)
cross-site scripting in CVE-2026-73050 (CVE-2026-73050). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73043 |
|
Cross-Site Scripting (XSS) in CVE-2026-73043 (CVE-2026-73043)
cross-site scripting in CVE-2026-73043 (CVE-2026-73043). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19916 |
|
Cross-Site Scripting (XSS) in CVE-2026-19916 (CVE-2026-19916)
cross-site scripting in CVE-2026-19916 (CVE-2026-19916). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19905 |
|
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
|
| CVE-2026-18855 |
|
Path Traversal in wordpress (CVE-2026-18855)
path traversal in wordpress (CVE-2026-18855). Data can be tampered with by attackers.
|
| CVE-2026-19904 |
|
Cross-Site Scripting (XSS) in CVE-2026-19904 (CVE-2026-19904)
cross-site scripting in CVE-2026-19904 (CVE-2026-19904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19899 |
|
Vulnerability in sqli (CVE-2026-19899)
vulnerability in sqli (CVE-2026-19899). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19598 |
|
Authorization Flaw in wordpress (CVE-2026-19598)
vulnerability in wordpress (CVE-2026-19598). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19474 |
|
Vulnerability in dos (CVE-2026-19474)
vulnerability in dos (CVE-2026-19474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18165 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-18165)
vulnerability in csrf (CVE-2026-18165). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74547 |
|
Vulnerability in dos (CVE-2026-74547)
vulnerability in dos (CVE-2026-74547). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74516 |
|
Vulnerability in c (CVE-2026-74516)
vulnerability in c (CVE-2026-74516). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74484 |
|
Vulnerability in dos (CVE-2026-74484)
vulnerability in dos (CVE-2026-74484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19894 |
|
Vulnerability in sqli (CVE-2026-19894)
vulnerability in sqli (CVE-2026-19894). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12248 |
|
SQL Injection in wordpress (CVE-2026-12248)
SQL injection in wordpress (CVE-2026-12248). Confidential information can be exposed externally.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15142 |
|
Privilege Escalation in wordpress (CVE-2026-15142)
vulnerability in wordpress (CVE-2026-15142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15826 |
|
Vulnerability in wordpress (CVE-2026-15826)
vulnerability in wordpress (CVE-2026-15826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14279 |
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
| CVE-2026-16007 |
|
SQL Injection in sqli (CVE-2026-16007)
SQL injection in sqli (CVE-2026-16007). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74400 |
|
Vulnerability in dos (CVE-2026-74400)
vulnerability in dos (CVE-2026-74400). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74312 |
|
Vulnerability in dos (CVE-2026-74312)
vulnerability in dos (CVE-2026-74312). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18387 |
|
SQL Injection in wordpress (CVE-2026-18387)
SQL injection in wordpress (CVE-2026-18387). Confidential information can be exposed externally.
|
| CVE-2026-17090 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17090)
cross-site scripting in wordpress (CVE-2026-17090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16146 |
|
SQL Injection in wordpress (CVE-2026-16146)
SQL injection in wordpress (CVE-2026-16146). Confidential information can be exposed externally.
|
| CVE-2026-16586 |
|
SQL Injection in wordpress (CVE-2026-16586)
SQL injection in wordpress (CVE-2026-16586). Confidential information can be exposed externally.
|
| CVE-2026-15993 |
|
SQL Injection in wordpress (CVE-2026-15993)
SQL injection in wordpress (CVE-2026-15993). Confidential information can be exposed externally.
|
| CVE-2026-16094 |
|
SQL Injection in wordpress (CVE-2026-16094)
SQL injection in wordpress (CVE-2026-16094). Confidential information can be exposed externally.
|
| CVE-2026-15948 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15948)
cross-site scripting in wordpress (CVE-2026-15948). Risk of unauthorized operations or information disclosure.
|