Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-18478 |
|
Cross-Site Scripting (XSS) in CVE-2026-18478 (CVE-2026-18478)
cross-site scripting in CVE-2026-18478 (CVE-2026-18478). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63106 |
|
SQL Injection in sqli (CVE-2026-63106)
SQL injection in sqli (CVE-2026-63106). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72691 |
|
Vulnerability in CVE-2026-72691 (CVE-2026-72691)
vulnerability in CVE-2026-72691 (CVE-2026-72691). Confidential information can be exposed externally.
|
| CVE-2026-68411 |
|
Vulnerability in dos (CVE-2026-68411)
vulnerability in dos (CVE-2026-68411). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18370 |
|
Vulnerability in dos (CVE-2026-18370)
vulnerability in dos (CVE-2026-18370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19278 |
|
Vulnerability in privilege-escalation (CVE-2026-19278)
vulnerability in privilege-escalation (CVE-2026-19278). Confidential information can be exposed externally.
|
| CVE-2026-19429 |
|
Vulnerability in CVE-2026-19429 (CVE-2026-19429)
vulnerability in CVE-2026-19429 (CVE-2026-19429). Successful exploitation can lead to full system takeover. Exploitable via `POST /job/{name}/build`.
|
| CVE-2026-72761 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72761)
SSRF in ssrf (CVE-2026-72761). Risk of unauthorized operations or information disclosure. Exploitable via ``ip.is_global``.
|
| CVE-2026-16742 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16742)
vulnerability in privilege-escalation (CVE-2026-16742). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15059 |
|
Path Traversal in path-traversal (CVE-2026-15059)
path traversal in path-traversal (CVE-2026-15059). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59088 |
|
Vulnerability in dos (CVE-2026-59088)
vulnerability in dos (CVE-2026-59088). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72594 |
|
Cross-Site Scripting (XSS) in CVE-2026-72594 (CVE-2026-72594)
cross-site scripting in CVE-2026-72594 (CVE-2026-72594). Confidential information can be exposed externally.
|
| CVE-2026-72591 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72591)
SSRF in ssrf (CVE-2026-72591). Confidential information can be exposed externally. Exploitable via `PATCH /apis/web/v1/album/{id}/image`.
|
| CVE-2026-72583 |
|
Cross-Site Scripting (XSS) in CVE-2026-72583 (CVE-2026-72583)
cross-site scripting in CVE-2026-72583 (CVE-2026-72583). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72581 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72581)
SSRF in ssrf (CVE-2026-72581). Confidential information can be exposed externally.
|
| CVE-2026-72576 |
|
Cross-Site Scripting (XSS) in CVE-2026-72576 (CVE-2026-72576)
cross-site scripting in CVE-2026-72576 (CVE-2026-72576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72578 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-72578)
vulnerability in csrf (CVE-2026-72578). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72570 |
|
Cross-Site Scripting (XSS) in CVE-2026-72570 (CVE-2026-72570)
cross-site scripting in CVE-2026-72570 (CVE-2026-72570). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72572 |
|
Path Traversal in path-traversal (CVE-2026-72572)
path traversal in path-traversal (CVE-2026-72572). Confidential information can be exposed externally.
|
| CVE-2026-72571 |
|
Path Traversal in path-traversal (CVE-2026-72571)
path traversal in path-traversal (CVE-2026-72571). Confidential information can be exposed externally.
|
| CVE-2026-72569 |
|
Path Traversal in path-traversal (CVE-2026-72569)
path traversal in path-traversal (CVE-2026-72569). Data can be tampered with by attackers.
|
| CVE-2026-72567 |
|
Path Traversal in path-traversal (CVE-2026-72567)
path traversal in path-traversal (CVE-2026-72567). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72566 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-72566)
SSRF in ssrf (CVE-2026-72566). Confidential information can be exposed externally.
|
| CVE-2026-72568 |
|
Out-of-Bounds Read in dos (CVE-2026-72568)
vulnerability in dos (CVE-2026-72568). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72565 |
|
SQL Injection in sqli (CVE-2026-72565)
SQL injection in sqli (CVE-2026-72565). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66642 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66642)
vulnerability in csrf (CVE-2026-66642). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66484 |
|
Path Traversal in path-traversal (CVE-2026-66484)
path traversal in path-traversal (CVE-2026-66484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66485 |
|
Vulnerability in c (CVE-2026-66485)
vulnerability in c (CVE-2026-66485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59087 |
|
Out-of-Bounds Write in dos (CVE-2026-59087)
out-of-bounds write in dos (CVE-2026-59087). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40920 |
|
Vulnerability in apache (CVE-2026-40920)
vulnerability in apache (CVE-2026-40920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32227 |
|
SQL Injection in apache (CVE-2026-32227)
SQL injection in apache (CVE-2026-32227). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55799 |
|
Code Injection in apache (CVE-2026-55799)
code injection in apache (CVE-2026-55799). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44416 |
|
Code Injection in apache (CVE-2026-44416)
code injection in apache (CVE-2026-44416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42537 |
|
Vulnerability in apache (CVE-2026-42537)
vulnerability in apache (CVE-2026-42537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66915 |
|
Code Injection in CVE-2026-66915 (CVE-2026-66915)
code injection in CVE-2026-66915 (CVE-2026-66915). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44630 |
|
Vulnerability in apache (CVE-2026-44630)
vulnerability in apache (CVE-2026-44630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21082 |
|
Vulnerability in path-traversal (CVE-2026-21082)
vulnerability in path-traversal (CVE-2026-21082). Confidential information can be exposed externally.
|
| CVE-2026-19053 |
|
SQL Injection in wordpress (CVE-2026-19053)
SQL injection in wordpress (CVE-2026-19053). Confidential information can be exposed externally.
|
| CVE-2026-19089 |
|
Unrestricted File Upload in wordpress (CVE-2026-19089)
vulnerability in wordpress (CVE-2026-19089). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18666 |
|
SQL Injection in wordpress (CVE-2026-18666)
SQL injection in wordpress (CVE-2026-18666). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17540 |
|
Vulnerability in wordpress (CVE-2026-17540)
vulnerability in wordpress (CVE-2026-17540). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17010 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17010)
cross-site scripting in wordpress (CVE-2026-17010). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17019 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17019)
cross-site scripting in wordpress (CVE-2026-17019). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16949 |
|
SQL Injection in wordpress (CVE-2026-16949)
SQL injection in wordpress (CVE-2026-16949). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16985 |
|
Unrestricted File Upload in wordpress (CVE-2026-16985)
vulnerability in wordpress (CVE-2026-16985). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15047 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15047)
cross-site scripting in wordpress (CVE-2026-15047). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14238 |
|
SQL Injection in wordpress (CVE-2026-14238)
SQL injection in wordpress (CVE-2026-14238). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13701 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13701)
cross-site scripting in wordpress (CVE-2026-13701). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12570 |
|
Vulnerability in dos (CVE-2026-12570)
vulnerability in dos (CVE-2026-12570). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19387 |
|
Out-of-Bounds Write in dos (CVE-2026-19387)
out-of-bounds write in dos (CVE-2026-19387). Risk of unauthorized operations or information disclosure.
|