Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: attack-types Clear
ID Title
CVE-2026-11588 Cross-Site Scripting (XSS) in wordpress (CVE-2026-11588)
cross-site scripting in wordpress (CVE-2026-11588). Risk of unauthorized operations or information disclosure.
CVE-2026-12713 SQL Injection in wordpress (CVE-2026-12713)
SQL injection in wordpress (CVE-2026-12713). Confidential information can be exposed externally.
CVE-2026-15459 Authentication Bypass in wordpress (CVE-2026-15459)
authentication bypass in wordpress (CVE-2026-15459). Successful exploitation can lead to full system takeover.
CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-18909 Vulnerability in dos (CVE-2026-18909)
vulnerability in dos (CVE-2026-18909). Risk of unauthorized operations or information disclosure.
CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
CVE-2026-18991 Path Traversal in path-traversal (CVE-2026-18991)
path traversal in path-traversal (CVE-2026-18991). Risk of unauthorized operations or information disclosure.
CVE-2026-67872 Vulnerability in dos (CVE-2026-67872)
vulnerability in dos (CVE-2026-67872). Risk of unauthorized operations or information disclosure.
CVE-2026-19028 Out-of-Bounds Read in c (CVE-2026-19028)
vulnerability in c (CVE-2026-19028). Risk of unauthorized operations or information disclosure.
CVE-2026-67869 Vulnerability in dos (CVE-2026-67869)
vulnerability in dos (CVE-2026-67869). Risk of unauthorized operations or information disclosure.
CVE-2026-67871 Vulnerability in c (CVE-2026-67871)
vulnerability in c (CVE-2026-67871). Risk of unauthorized operations or information disclosure.
CVE-2026-18968 Cross-Site Scripting (XSS) in CVE-2026-18968 (CVE-2026-18968)
cross-site scripting in CVE-2026-18968 (CVE-2026-18968). Risk of unauthorized operations or information disclosure.
CVE-2026-18970 Vulnerability in sqli (CVE-2026-18970)
vulnerability in sqli (CVE-2026-18970). Risk of unauthorized operations or information disclosure.
CVE-2026-67531 Code Injection in CVE-2026-67531 (CVE-2026-67531)
code injection in CVE-2026-67531 (CVE-2026-67531). Risk of unauthorized operations or information disclosure.
CVE-2026-19023 Vulnerability in dos (CVE-2026-19023)
vulnerability in dos (CVE-2026-19023). Risk of unauthorized operations or information disclosure.
CVE-2026-19024 Vulnerability in dos (CVE-2026-19024)
vulnerability in dos (CVE-2026-19024). Risk of unauthorized operations or information disclosure.
CVE-2026-19025 Vulnerability in c (CVE-2026-19025)
vulnerability in c (CVE-2026-19025). Risk of unauthorized operations or information disclosure.
CVE-2026-19026 Vulnerability in c (CVE-2026-19026)
vulnerability in c (CVE-2026-19026). Risk of unauthorized operations or information disclosure.
CVE-2026-67863 Use-After-Free in dos (CVE-2026-67863)
vulnerability in dos (CVE-2026-67863). Risk of unauthorized operations or information disclosure.
CVE-2026-67866 Vulnerability in dos (CVE-2026-67866)
vulnerability in dos (CVE-2026-67866). Risk of unauthorized operations or information disclosure.
CVE-2026-67867 Vulnerability in dos (CVE-2026-67867)
vulnerability in dos (CVE-2026-67867). Risk of unauthorized operations or information disclosure.
CVE-2026-67864 Vulnerability in dos (CVE-2026-67864)
vulnerability in dos (CVE-2026-67864). Risk of unauthorized operations or information disclosure.
CVE-2026-67865 Out-of-Bounds Read in dos (CVE-2026-67865)
vulnerability in dos (CVE-2026-67865). Risk of unauthorized operations or information disclosure.
CVE-2026-15996 Vulnerability in dos (CVE-2026-15996)
vulnerability in dos (CVE-2026-15996). Risk of unauthorized operations or information disclosure.
CVE-2026-18839 Vulnerability in dos (CVE-2026-18839)
vulnerability in dos (CVE-2026-18839). Risk of unauthorized operations or information disclosure.
CVE-2026-34966 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34966)
SSRF in ssrf (CVE-2026-34966). Confidential information can be exposed externally.
CVE-2026-18959 Path Traversal in path-traversal (CVE-2026-18959)
path traversal in path-traversal (CVE-2026-18959). Risk of unauthorized operations or information disclosure.
CVE-2026-69111 Vulnerability in dos (CVE-2026-69111)
vulnerability in dos (CVE-2026-69111). Risk of unauthorized operations or information disclosure.
CVE-2026-66885 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66885)
vulnerability in csrf (CVE-2026-66885). Confidential information can be exposed externally.
CVE-2026-66881 Vulnerability in path-traversal (CVE-2026-66881)
vulnerability in path-traversal (CVE-2026-66881). Data can be tampered with by attackers.
CVE-2026-55522 Code Injection in praisonaiagents (CVE-2026-55522)
code injection in praisonaiagents (CVE-2026-55522). Successful exploitation can lead to full system takeover. Exploitable via ``tools.py``. Mitigation: upgrade to `1.6.58` or later.
CVE-2026-55524 Vulnerability in praisonaiagents (CVE-2026-55524)
vulnerability in praisonaiagents (CVE-2026-55524). Confidential information can be exposed externally. Mitigation: upgrade to `1.6.58` or later.
CVE-2026-55523 SSRF (Server-Side Request Forgery) in praisonaiagents (CVE-2026-55523)
SSRF in praisonaiagents (CVE-2026-55523). Risk of unauthorized operations or information disclosure. Exploitable via ``web_crawl``. Mitigation: upgrade to `1.6.58` or later.
CVE-2026-18958 Vulnerability in sqli (CVE-2026-18958)
vulnerability in sqli (CVE-2026-18958). Risk of unauthorized operations or information disclosure.
CVE-2026-17556 Path Traversal in path-traversal (CVE-2026-17556)
path traversal in path-traversal (CVE-2026-17556). Data can be tampered with by attackers.
CVE-2026-7869 Path Traversal in path-traversal (CVE-2026-7869)
path traversal in path-traversal (CVE-2026-7869). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge_bases`.
CVE-2026-7658 Path Traversal in path-traversal (CVE-2026-7658)
path traversal in path-traversal (CVE-2026-7658). Data can be tampered with by attackers.
CVE-2026-63457 Vulnerability in dos (CVE-2026-63457)
vulnerability in dos (CVE-2026-63457). Risk of unauthorized operations or information disclosure.
CVE-2026-18485 Vulnerability in privilege-escalation (CVE-2026-18485)
vulnerability in privilege-escalation (CVE-2026-18485). Successful exploitation can lead to full system takeover.
CVE-2026-10547 Vulnerability in dos (CVE-2026-10547)
vulnerability in dos (CVE-2026-10547). Data can be tampered with by attackers. Exploitable via `POST /api/v1/build/{flow_id}/vertices`.
CVE-2026-9081 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9081)
SSRF in ssrf (CVE-2026-9081). Confidential information can be exposed externally.
CVE-2026-7657 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-7657)
SSRF in ssrf (CVE-2026-7657). Confidential information can be exposed externally.
CVE-2026-70441 Cross-Site Scripting (XSS) in CVE-2026-70441 (CVE-2026-70441)
cross-site scripting in CVE-2026-70441 (CVE-2026-70441). Risk of unauthorized operations or information disclosure.
CVE-2026-70440 Cross-Site Scripting (XSS) in CVE-2026-70440 (CVE-2026-70440)
cross-site scripting in CVE-2026-70440 (CVE-2026-70440). Risk of unauthorized operations or information disclosure.
CVE-2026-70434 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70434)
vulnerability in csrf (CVE-2026-70434). Risk of unauthorized operations or information disclosure.
CVE-2026-70432 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70432)
vulnerability in csrf (CVE-2026-70432). Successful exploitation can lead to full system takeover.
CVE-2026-10716 SQL Injection in sqli (CVE-2026-10716)
SQL injection in sqli (CVE-2026-10716). Risk of unauthorized operations or information disclosure.
CVE-2026-70428 Path Traversal in path-traversal (CVE-2026-70428)
path traversal in path-traversal (CVE-2026-70428). Risk of unauthorized operations or information disclosure.
CVE-2026-7646 Path Traversal in path-traversal (CVE-2026-7646)
path traversal in path-traversal (CVE-2026-7646). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →