Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-20472 |
|
Out-of-Bounds Write in dos (CVE-2026-20472)
out-of-bounds write in dos (CVE-2026-20472). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3245 |
|
Unsafe Deserialization in deserialization (CVE-2026-3245)
vulnerability in deserialization (CVE-2026-3245). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18577 KEV |
|
[KEV] Vulnerability in N-able n-central (CVE-2026-18577)
vulnerability in N-able n-central (CVE-2026-18577). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-10848 |
|
Out-of-Bounds Read in c (CVE-2026-10848)
vulnerability in c (CVE-2026-10848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9856 |
|
Path Traversal in path-traversal (CVE-2026-9856)
path traversal in path-traversal (CVE-2026-9856). Data can be tampered with by attackers. Exploitable via ``PreTrainedTokenizerBase``.
|
| CVE-2026-65321 |
|
SQL Injection in sqli (CVE-2026-65321)
SQL injection in sqli (CVE-2026-65321). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68583 |
|
Cross-Site Scripting (XSS) in CVE-2026-68583 (CVE-2026-68583)
cross-site scripting in CVE-2026-68583 (CVE-2026-68583). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68580 |
|
Vulnerability in dos (CVE-2026-68580)
vulnerability in dos (CVE-2026-68580). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71401 |
|
Vulnerability in dos (CVE-2025-71401)
vulnerability in dos (CVE-2025-71401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12231 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12231)
cross-site scripting in wordpress (CVE-2026-12231). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16292 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-16292)
vulnerability in wordpress (CVE-2026-16292). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16062 |
|
Unsafe Deserialization in wordpress (CVE-2026-16062)
vulnerability in wordpress (CVE-2026-16062). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12586 |
|
Authentication Bypass in wordpress (CVE-2026-12586)
authentication bypass in wordpress (CVE-2026-12586). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14864 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14864)
cross-site scripting in wordpress (CVE-2026-14864). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15675 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-15675)
cross-site scripting in wordpress (CVE-2025-15675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18352 |
|
Path Traversal in wordpress (CVE-2026-18352)
path traversal in wordpress (CVE-2026-18352). Confidential information can be exposed externally.
|
| CVE-2026-13339 |
|
Path Traversal in wordpress (CVE-2026-13339)
path traversal in wordpress (CVE-2026-13339). Confidential information can be exposed externally.
|
| CVE-2026-8457 |
|
Vulnerability in wordpress (CVE-2026-8457)
vulnerability in wordpress (CVE-2026-8457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18556 KEV |
|
[KEV] Vulnerability in N-able n-central (CVE-2026-18556)
vulnerability in N-able n-central (CVE-2026-18556). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-55735 |
|
Vulnerability in dos (CVE-2026-55735)
vulnerability in dos (CVE-2026-55735). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55734 |
|
Vulnerability in dos (CVE-2026-55734)
vulnerability in dos (CVE-2026-55734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55733 |
|
Vulnerability in dos (CVE-2026-55733)
vulnerability in dos (CVE-2026-55733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54894 |
|
Vulnerability in dos (CVE-2026-54894)
vulnerability in dos (CVE-2026-54894). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67353 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-67353)
vulnerability in guzzlehttp/guzzle (CVE-2026-67353). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.15.1` or later.
|
| CVE-2026-67352 |
|
Cross-Site Scripting (XSS) in CVE-2026-67352 (CVE-2026-67352)
cross-site scripting in CVE-2026-67352 (CVE-2026-67352). Confidential information can be exposed externally.
|
| CVE-2026-67338 |
|
Vulnerability in CVE-2026-67338 (CVE-2026-67338)
vulnerability in CVE-2026-67338 (CVE-2026-67338). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67337 |
|
Vulnerability in CVE-2026-67337 (CVE-2026-67337)
vulnerability in CVE-2026-67337 (CVE-2026-67337). Confidential information can be exposed externally.
|
| CVE-2026-67326 |
|
Vulnerability in CVE-2026-67326 (CVE-2026-67326)
vulnerability in CVE-2026-67326 (CVE-2026-67326). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67328 |
|
Cross-Site Scripting (XSS) in CVE-2026-67328 (CVE-2026-67328)
cross-site scripting in CVE-2026-67328 (CVE-2026-67328). Confidential information can be exposed externally.
|
| CVE-2026-67321 |
|
Vulnerability in dos (CVE-2026-67321)
vulnerability in dos (CVE-2026-67321). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67312 |
|
Vulnerability in dos (CVE-2026-67312)
vulnerability in dos (CVE-2026-67312). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67305 |
|
Vulnerability in CVE-2026-67305 (CVE-2026-67305)
vulnerability in CVE-2026-67305 (CVE-2026-67305). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67309 |
|
Path Traversal in github.com/traefik/traefik/v3 (CVE-2026-67309)
path traversal in github.com/traefik/traefik/v3 (CVE-2026-67309). Risk of unauthorized operations or information disclosure. Exploitable via ``RewriteTarget``. Mitigation: upgrade to `3.7.8` or later.
|
| CVE-2026-67303 |
|
Vulnerability in c (CVE-2026-67303)
vulnerability in c (CVE-2026-67303). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67296 |
|
Vulnerability in dos (CVE-2026-67296)
vulnerability in dos (CVE-2026-67296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67292 |
|
Vulnerability in c (CVE-2026-67292)
vulnerability in c (CVE-2026-67292). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66401 |
|
Out-of-Bounds Read in dos (CVE-2026-66401)
vulnerability in dos (CVE-2026-66401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10773 |
|
Out-of-Bounds Read in c (CVE-2026-10773)
vulnerability in c (CVE-2026-10773). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71404 |
|
Cross-Site Scripting (XSS) in CVE-2025-71404 (CVE-2025-71404)
cross-site scripting in CVE-2025-71404 (CVE-2025-71404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6453 |
|
SQL Injection in wordpress (CVE-2026-6453)
SQL injection in wordpress (CVE-2026-6453). Confidential information can be exposed externally.
|
| CVE-2026-18062 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18062)
cross-site scripting in wordpress (CVE-2026-18062). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18344 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18344)
cross-site scripting in wordpress (CVE-2026-18344). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18435 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18435)
cross-site scripting in wordpress (CVE-2026-18435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17555 |
|
SQL Injection in wordpress (CVE-2026-17555)
SQL injection in wordpress (CVE-2026-17555). Confidential information can be exposed externally.
|
| CVE-2026-16684 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16684)
cross-site scripting in wordpress (CVE-2026-16684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16685 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16685)
cross-site scripting in wordpress (CVE-2026-16685). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17571 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17571)
cross-site scripting in wordpress (CVE-2026-17571). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16144 |
|
Code Injection in wordpress (CVE-2026-16144)
code injection in wordpress (CVE-2026-16144). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16614 |
|
SQL Injection in wordpress (CVE-2026-16614)
SQL injection in wordpress (CVE-2026-16614). Confidential information can be exposed externally.
|
| CVE-2026-16087 |
|
SQL Injection in wordpress (CVE-2026-16087)
SQL injection in wordpress (CVE-2026-16087). Confidential information can be exposed externally.
|