Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64662 |
|
Vulnerability in statamic/cms (CVE-2026-64662)
vulnerability in statamic/cms (CVE-2026-64662). Confidential information can be exposed externally. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-64663 |
|
Vulnerability in statamic/cms (CVE-2026-64663)
vulnerability in statamic/cms (CVE-2026-64663). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-64665 |
|
Authentication Bypass in statamic/cms (CVE-2026-64665)
authentication bypass in statamic/cms (CVE-2026-64665). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-64664 |
|
Information Disclosure in statamic/cms (CVE-2026-64664)
vulnerability in statamic/cms (CVE-2026-64664). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.74.1` or later.
|
| CVE-2026-71433 |
|
Information Disclosure in langgraph-checkpoint-postgres (CVE-2026-71433)
vulnerability in langgraph-checkpoint-postgres (CVE-2026-71433). Confidential information can be exposed externally. Exploitable via ``memories.alice``. Mitigation: upgrade to `3.1.1` or later.
|
| CVE-2026-71325 |
|
Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-71325)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-71325). Risk of unauthorized operations or information disclosure. Exploitable via ``TraefikService``. Mitigation: upgrade to `2.11.54` or later.
|
| CVE-2026-71326 |
|
Authentication Bypass in github.com/traefik/traefik/v3 (CVE-2026-71326)
authentication bypass in github.com/traefik/traefik/v3 (CVE-2026-71326). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/http/middlewares/{id}`. Mitigation: upgrade to `3.7.10` or later.
|
| CVE-2026-68747 |
|
Vulnerability in rrrene (CVE-2026-68747)
vulnerability in rrrene (CVE-2026-68747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66829 |
|
Open Redirect in rrrene (CVE-2026-66829)
vulnerability in rrrene (CVE-2026-66829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66843 |
|
Vulnerability in rrrene (CVE-2026-66843)
vulnerability in rrrene (CVE-2026-66843). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66370 |
|
Open Redirect in rrrene (CVE-2026-66370)
vulnerability in rrrene (CVE-2026-66370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53977 |
|
Vulnerability in express (CVE-2026-53977)
vulnerability in express (CVE-2026-53977). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53985 |
|
Vulnerability in CVE-2026-53985 (CVE-2026-53985)
vulnerability in CVE-2026-53985 (CVE-2026-53985). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3430 |
|
SQL Injection in wordpress (CVE-2026-3430)
SQL injection in wordpress (CVE-2026-3430). Confidential information can be exposed externally.
|
| CVE-2026-43622 |
|
Vulnerability in c (CVE-2026-43622)
vulnerability in c (CVE-2026-43622). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19047 |
|
Vulnerability in CVE-2026-19047 (CVE-2026-19047)
vulnerability in CVE-2026-19047 (CVE-2026-19047). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19046 |
|
Path Traversal in path-traversal (CVE-2026-19046)
path traversal in path-traversal (CVE-2026-19046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18277 |
|
Vulnerability in escriptorium (CVE-2026-18277)
vulnerability in escriptorium (CVE-2026-18277). Data can be tampered with by attackers.
|
| CVE-2026-18359 |
|
SSRF (Server-Side Request Forgery) in escriptorium (CVE-2026-18359)
SSRF in escriptorium (CVE-2026-18359). Confidential information can be exposed externally. Exploitable via `POST /api/documents/{pk}/imports/`.
|
| CVE-2026-18427 |
|
Path Traversal in CVE-2026-18427 (CVE-2026-18427)
path traversal in CVE-2026-18427 (CVE-2026-18427). Confidential information can be exposed externally.
|
| CVE-2026-18276 |
|
Vulnerability in escriptorium (CVE-2026-18276)
vulnerability in escriptorium (CVE-2026-18276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71324 |
|
Vulnerability in github.com/traefik/traefik/v2 (CVE-2026-71324)
vulnerability in github.com/traefik/traefik/v2 (CVE-2026-71324). Risk of unauthorized operations or information disclosure. Exploitable via `GET /delay/2`. Mitigation: upgrade to `2.11.53` or later.
|
| CVE-2026-66710 |
|
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
|
| CVE-2026-66712 |
|
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
|
| CVE-2026-67261 |
|
OS Command Injection in dell (CVE-2026-67261)
OS command injection in dell (CVE-2026-67261). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66711 |
|
Cross-Site Scripting (XSS) in CVE-2026-66711 (CVE-2026-66711)
cross-site scripting in CVE-2026-66711 (CVE-2026-66711). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66702 |
|
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
|
| CVE-2026-66703 |
|
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
|
| CVE-2026-66705 |
|
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
|
| CVE-2026-66706 |
|
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
|
| CVE-2026-66707 |
|
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
|
| CVE-2026-66708 |
|
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
|
| CVE-2026-66709 |
|
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
|
| CVE-2026-66688 |
|
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
|
| CVE-2026-66690 |
|
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
|
| CVE-2026-66694 |
|
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
|
| CVE-2026-66695 |
|
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
|
| CVE-2026-66699 |
|
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
Custom role Broken Access Control in Dokan <= 5.0.10 versions.
|
| CVE-2026-66701 |
|
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
|
| CVE-2026-66678 |
|
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
|
| CVE-2026-66664 |
|
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
|
| CVE-2026-66681 |
|
Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.
|
| CVE-2026-66686 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-66686)
vulnerability in csrf (CVE-2026-66686). Data can be tampered with by attackers.
|
| CVE-2026-66665 |
|
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
|
| CVE-2026-66447 |
|
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
|
| CVE-2026-66440 |
|
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
|
| CVE-2026-66457 |
|
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
|
| CVE-2026-66663 |
|
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
|
| CVE-2026-66452 |
|
Vulnerability in CVE-2026-66452 (CVE-2026-66452)
vulnerability in CVE-2026-66452 (CVE-2026-66452). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66470 |
|
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
|