Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-14574 |
|
Vulnerability in eclipse (CVE-2026-14574)
vulnerability in eclipse (CVE-2026-14574). Data can be tampered with by attackers. Exploitable via ``PreferenceUtils.merge``.
|
| CVE-2026-66747 |
|
Vulnerability in CVE-2026-66747 (CVE-2026-66747)
vulnerability in CVE-2026-66747 (CVE-2026-66747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60009 |
|
Path Traversal in eclipse (CVE-2026-60009)
path traversal in eclipse (CVE-2026-60009). Successful exploitation can lead to full system takeover. Exploitable via `POST /file-upload`.
|
| CVE-2026-12609 |
|
Path Traversal in eclipse (CVE-2026-12609)
path traversal in eclipse (CVE-2026-12609). Confidential information can be exposed externally.
|
| CVE-2026-44945 |
|
Vulnerability in privilege-escalation (CVE-2026-44945)
vulnerability in privilege-escalation (CVE-2026-44945). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25703 |
|
Vulnerability in CVE-2026-25703 (CVE-2026-25703)
vulnerability in CVE-2026-25703 (CVE-2026-25703). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15452 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15452)
cross-site scripting in wordpress (CVE-2026-15452). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8029 |
|
SQL Injection in sqli (CVE-2026-8029)
SQL injection in sqli (CVE-2026-8029). Confidential information can be exposed externally.
|
| CVE-2026-10090 |
|
Vulnerability in privilege-escalation (CVE-2026-10090)
vulnerability in privilege-escalation (CVE-2026-10090). Confidential information can be exposed externally.
|
| CVE-2026-7444 |
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
| CVE-2026-7105 |
|
Vulnerability in wordpress (CVE-2026-7105)
vulnerability in wordpress (CVE-2026-7105). Risk of unauthorized operations or information disclosure. Exploitable via ``xpro_content``.
|
| CVE-2026-7520 |
|
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
|
| CVE-2026-7726 |
|
Vulnerability in wordpress (CVE-2026-7726)
vulnerability in wordpress (CVE-2026-7726). Risk of unauthorized operations or information disclosure. Exploitable via ``wp_ajax_nopriv_handle_sync``.
|
| CVE-2026-7693 |
|
Command Injection in wordpress (CVE-2026-7693)
command injection in wordpress (CVE-2026-7693). Successful exploitation can lead to full system takeover. Exploitable via ``file``.
|
| CVE-2026-7441 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7441)
cross-site scripting in wordpress (CVE-2026-7441). Risk of unauthorized operations or information disclosure. Exploitable via ``posttype``.
|
| CVE-2026-71214 |
|
Vulnerability in CVE-2026-71214 (CVE-2026-71214)
vulnerability in CVE-2026-71214 (CVE-2026-71214). Successful exploitation can lead to full system takeover. Exploitable via `POST /command-expansion/put-expansion`.
|
| CVE-2026-71210 |
|
Vulnerability in ssrf (CVE-2026-71210)
vulnerability in ssrf (CVE-2026-71210). Confidential information can be exposed externally.
|
| CVE-2026-71212 |
|
Vulnerability in CVE-2026-71212 (CVE-2026-71212)
vulnerability in CVE-2026-71212 (CVE-2026-71212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71211 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71211)
SSRF in ssrf (CVE-2026-71211). Confidential information can be exposed externally.
|
| CVE-2026-71209 |
|
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
|
| CVE-2026-71215 |
|
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
|
| CVE-2026-71208 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-71208 (CVE-2026-71208)
SSRF in CVE-2026-71208 (CVE-2026-71208). Confidential information can be exposed externally.
|
| CVE-2026-71204 |
|
Vulnerability in CVE-2026-71204 (CVE-2026-71204)
vulnerability in CVE-2026-71204 (CVE-2026-71204). Confidential information can be exposed externally.
|
| CVE-2026-71203 |
|
Vulnerability in CVE-2026-71203 (CVE-2026-71203)
vulnerability in CVE-2026-71203 (CVE-2026-71203). Risk of unauthorized operations or information disclosure. Exploitable via `X-API-Key header`.
|
| CVE-2026-71202 |
|
Vulnerability in CVE-2026-71202 (CVE-2026-71202)
vulnerability in CVE-2026-71202 (CVE-2026-71202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71207 |
|
SQL Injection in CVE-2026-71207 (CVE-2026-71207)
SQL injection in CVE-2026-71207 (CVE-2026-71207). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6972 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-6972)
cross-site scripting in wordpress (CVE-2026-6972). Risk of unauthorized operations or information disclosure. Exploitable via ``chart_size``.
|
| CVE-2026-70376 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2026-6627 |
|
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
|
| CVE-2026-6639 |
|
Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
|
| CVE-2026-6147 |
|
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
|
| CVE-2026-6079 |
|
Vulnerability in wordpress (CVE-2026-6079)
vulnerability in wordpress (CVE-2026-6079). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6020 |
|
Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5581 |
|
Vulnerability in wordpress (CVE-2026-5581)
vulnerability in wordpress (CVE-2026-5581). Data can be tampered with by attackers. Exploitable via ``wp_ajax_nopriv_gfmu_delete_file``.
|
| CVE-2026-61484 |
|
Unsafe Deserialization in apache (CVE-2026-61484)
vulnerability in apache (CVE-2026-61484). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5651 |
|
SQL Injection in wordpress (CVE-2026-5651)
SQL injection in wordpress (CVE-2026-5651). Confidential information can be exposed externally.
|
| CVE-2026-61486 |
|
Vulnerability in apache (CVE-2026-61486)
vulnerability in apache (CVE-2026-61486). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55997 |
|
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
|
| CVE-2026-5108 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5108)
cross-site scripting in wordpress (CVE-2026-5108). Risk of unauthorized operations or information disclosure. Exploitable via ``innerHTML``.
|
| CVE-2026-5116 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5116)
cross-site scripting in wordpress (CVE-2026-5116). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55996 |
|
Vulnerability in dos (CVE-2026-55996)
vulnerability in dos (CVE-2026-55996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59675 |
|
Vulnerability in CVE-2026-59675 (CVE-2026-59675)
vulnerability in CVE-2026-59675 (CVE-2026-59675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55747 |
|
Path Traversal in CVE-2026-55747 (CVE-2026-55747)
path traversal in CVE-2026-55747 (CVE-2026-55747). Confidential information can be exposed externally.
|
| CVE-2026-4431 |
|
Vulnerability in wordpress (CVE-2026-4431)
vulnerability in wordpress (CVE-2026-4431). Data can be tampered with by attackers. Exploitable via ``rbsm_submit_post``.
|
| CVE-2026-54418 |
|
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
|
| CVE-2026-54416 |
|
Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18881 |
|
SQL Injection in wordpress (CVE-2026-18881)
SQL injection in wordpress (CVE-2026-18881). Confidential information can be exposed externally. Exploitable via ``tableon_get_table_data``.
|
| CVE-2026-17532 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17532)
cross-site scripting in wordpress (CVE-2026-17532). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17505 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17505)
cross-site scripting in wordpress (CVE-2026-17505). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11969 |
|
SQL Injection in wordpress (CVE-2026-11969)
SQL injection in wordpress (CVE-2026-11969). Confidential information can be exposed externally.
|