Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-15951 |
|
SQL Injection in wordpress (CVE-2026-15951)
SQL injection in wordpress (CVE-2026-15951). Confidential information can be exposed externally. Exploitable via ``fields``.
|
| CVE-2026-16090 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16090)
cross-site scripting in wordpress (CVE-2026-16090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16091 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16091)
cross-site scripting in wordpress (CVE-2026-16091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15964 |
|
Vulnerability in wordpress (CVE-2026-15964)
vulnerability in wordpress (CVE-2026-15964). Successful exploitation can lead to full system takeover. Exploitable via ``wp_ajax_nopriv_ssoprocess_ajax``.
|
| CVE-2026-16635 |
|
Privilege Escalation in wordpress (CVE-2026-16635)
vulnerability in wordpress (CVE-2026-16635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15601 |
|
Path Traversal in wordpress (CVE-2026-15601)
path traversal in wordpress (CVE-2026-15601). Confidential information can be exposed externally.
|
| CVE-2026-15644 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15644)
cross-site scripting in wordpress (CVE-2026-15644). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15645 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15645)
cross-site scripting in wordpress (CVE-2026-15645). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15649 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15649)
cross-site scripting in wordpress (CVE-2026-15649). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15662 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15662)
cross-site scripting in wordpress (CVE-2026-15662). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15950 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15950)
cross-site scripting in wordpress (CVE-2026-15950). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15450 |
|
Path Traversal in wordpress (CVE-2026-15450)
path traversal in wordpress (CVE-2026-15450). Data can be tampered with by attackers.
|
| CVE-2026-15018 |
|
SQL Injection in wordpress (CVE-2026-15018)
SQL injection in wordpress (CVE-2026-15018). Confidential information can be exposed externally.
|
| CVE-2026-13458 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13458)
cross-site scripting in wordpress (CVE-2026-13458). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15052 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15052)
cross-site scripting in wordpress (CVE-2026-15052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15988 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15988)
vulnerability in wordpress (CVE-2026-15988). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15932 |
|
Path Traversal in wordpress (CVE-2026-15932)
path traversal in wordpress (CVE-2026-15932). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15244 |
|
Path Traversal in c (CVE-2026-15244)
path traversal in c (CVE-2026-15244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13729 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-13729)
vulnerability in wordpress (CVE-2026-13729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13596 |
|
SQL Injection in wordpress (CVE-2026-13596)
SQL injection in wordpress (CVE-2026-13596). Confidential information can be exposed externally.
|
| CVE-2026-13725 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13725)
cross-site scripting in wordpress (CVE-2026-13725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3141 |
|
Vulnerability in wordpress (CVE-2026-3141)
vulnerability in wordpress (CVE-2026-3141). Data can be tampered with by attackers.
|
| CVE-2026-7623 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7623)
cross-site scripting in wordpress (CVE-2026-7623). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15403 |
|
SQL Injection in wordpress (CVE-2026-15403)
SQL injection in wordpress (CVE-2026-15403). Confidential information can be exposed externally.
|
| CVE-2026-13362 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13362)
cross-site scripting in wordpress (CVE-2026-13362). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15006 |
|
Path Traversal in wordpress (CVE-2026-15006)
path traversal in wordpress (CVE-2026-15006). Confidential information can be exposed externally.
|
| CVE-2026-15414 |
|
Privilege Escalation in wordpress (CVE-2026-15414)
vulnerability in wordpress (CVE-2026-15414). Successful exploitation can lead to full system takeover. Exploitable via ``_wps_plan_user_role``.
|
| CVE-2026-68771 |
|
Unsafe Deserialization in deserialization (CVE-2026-68771)
vulnerability in deserialization (CVE-2026-68771). Successful exploitation can lead to full system takeover. Exploitable via `POST /upload/image`.
|
| CVE-2026-52232 |
|
Cross-Site Scripting (XSS) in CVE-2026-52232 (CVE-2026-52232)
cross-site scripting in CVE-2026-52232 (CVE-2026-52232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52371 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-52371)
SSRF in ssrf (CVE-2026-52371). Confidential information can be exposed externally.
|
| CVE-2026-54909 |
|
Vulnerability in github.com/pion/stun/v3 (CVE-2026-54909)
vulnerability in github.com/pion/stun/v3 (CVE-2026-54909). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.5` or later.
|
| CVE-2026-50986 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-50986)
vulnerability in csrf (CVE-2026-50986). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69948 |
|
SQL Injection in sqli (CVE-2025-69948)
SQL injection in sqli (CVE-2025-69948). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69946 |
|
SQL Injection in sqli (CVE-2025-69946)
SQL injection in sqli (CVE-2025-69946). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53551 |
|
Vulnerability in github.com/free5gc/free5gc (CVE-2026-53551)
vulnerability in github.com/free5gc/free5gc (CVE-2026-53551). Risk of unauthorized operations or information disclosure. Exploitable via `POST /nausf-auth/v1/ue-authentications`. Mitigation: upgrade to `4.2.2` or later.
|
| CVE-2026-18420 |
|
Vulnerability in Amazon aws (CVE-2026-18420)
vulnerability in Amazon aws (CVE-2026-18420). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57232 |
|
SSRF (Server-Side Request Forgery) in symfony (CVE-2026-57232)
SSRF in symfony (CVE-2026-57232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18481 |
|
Cross-Site Scripting (XSS) in Amazon aws (CVE-2026-18481)
cross-site scripting in Amazon aws (CVE-2026-18481). Confidential information can be exposed externally.
|
| CVE-2026-53505 |
|
Vulnerability in thumbor (CVE-2026-53505)
vulnerability in thumbor (CVE-2026-53505). Risk of unauthorized operations or information disclosure. Exploitable via ``value``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53503 |
|
Vulnerability in thumbor (CVE-2026-53503)
vulnerability in thumbor (CVE-2026-53503). Risk of unauthorized operations or information disclosure. Exploitable via ``columns_count``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-34495 |
|
Cross-Site Scripting (XSS) in johnsoncontrols (CVE-2026-34495)
cross-site scripting in johnsoncontrols (CVE-2026-34495). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34497 |
|
Vulnerability in johnsoncontrols (CVE-2026-34497)
vulnerability in johnsoncontrols (CVE-2026-34497). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55100 |
|
Vulnerability in hashi-vault-js (CVE-2026-55100)
vulnerability in hashi-vault-js (CVE-2026-55100). Risk of unauthorized operations or information disclosure. Exploitable via ``encodeURIComponent``. Mitigation: upgrade to `0.5.2` or later.
|
| CVE-2026-54729 |
|
SSRF (Server-Side Request Forgery) in dssrf (CVE-2026-54729)
SSRF in dssrf (CVE-2026-54729). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.5` or later.
|
| CVE-2026-67607 |
|
Vulnerability in c (CVE-2026-67607)
vulnerability in c (CVE-2026-67607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59232 |
|
Cross-Site Scripting (XSS) in CVE-2026-59232 (CVE-2026-59232)
cross-site scripting in CVE-2026-59232 (CVE-2026-59232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18141 |
|
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
|
| CVE-2026-17566 |
|
OS Command Injection in pgadmin (CVE-2026-17566)
OS command injection in pgadmin (CVE-2026-17566). Successful exploitation can lead to full system takeover. Exploitable via `POST /import_export/job/`.
|
| CVE-2026-17347 |
|
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
|
| CVE-2026-17351 |
|
SQL Injection in pgadmin (CVE-2026-17351)
SQL injection in pgadmin (CVE-2026-17351). Successful exploitation can lead to full system takeover.
|