Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75908 |
|
Vulnerability in wordpress (CVE-2026-75908)
vulnerability in wordpress (CVE-2026-75908). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55976 |
|
SSRF (Server-Side Request Forgery) in apache (CVE-2026-55976)
SSRF in apache (CVE-2026-55976). Confidential information can be exposed externally.
|
| CVE-2026-53561 |
|
Authentication Bypass in apache (CVE-2026-53561)
authentication bypass in apache (CVE-2026-53561). Confidential information can be exposed externally.
|
| CVE-2026-17587 |
|
Vulnerability in wordpress (CVE-2026-17587)
vulnerability in wordpress (CVE-2026-17587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-79652 |
|
Vulnerability in CVE-2026-79652 (CVE-2026-79652)
vulnerability in CVE-2026-79652 (CVE-2026-79652). Confidential information can be exposed externally.
|
| CVE-2026-78863 |
|
Authentication Bypass in CVE-2026-78863 (CVE-2026-78863)
authentication bypass in CVE-2026-78863 (CVE-2026-78863). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59335 |
|
Vulnerability in CVE-2026-59335 (CVE-2026-59335)
vulnerability in CVE-2026-59335 (CVE-2026-59335). Confidential information can be exposed externally.
|
| CVE-2026-19949 |
|
SQL Injection in wordpress (CVE-2026-19949)
SQL injection in wordpress (CVE-2026-19949). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18547 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18547)
cross-site scripting in wordpress (CVE-2026-18547). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49845 |
|
Code Injection in apache (CVE-2026-49845)
code injection in apache (CVE-2026-49845). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21758 |
|
Information Disclosure in CVE-2026-21758 (CVE-2026-21758)
vulnerability in CVE-2026-21758 (CVE-2026-21758). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12600 |
|
Vulnerability in dos (CVE-2026-12600)
vulnerability in dos (CVE-2026-12600). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78572 |
|
Unsafe Deserialization in wordpress (CVE-2026-78572)
vulnerability in wordpress (CVE-2026-78572). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78570 |
|
Privilege Escalation in wordpress (CVE-2026-78570)
vulnerability in wordpress (CVE-2026-78570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75037 |
|
Vulnerability in CVE-2026-75037 (CVE-2026-75037)
vulnerability in CVE-2026-75037 (CVE-2026-75037). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78576 |
|
SQL Injection in wordpress (CVE-2026-78576)
SQL injection in wordpress (CVE-2026-78576). Confidential information can be exposed externally.
|
| CVE-2026-76128 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76128)
cross-site scripting in wordpress (CVE-2026-76128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49050 |
|
Authorization Flaw in apache (CVE-2026-49050)
vulnerability in apache (CVE-2026-49050). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16231 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-16231)
cross-site scripting in express (CVE-2026-16231). Confidential information can be exposed externally. Mitigation: upgrade to `4.3.0` or later.
|
| CVE-2026-12878 |
|
Privilege Escalation in CVE-2026-12878 (CVE-2026-12878)
vulnerability in CVE-2026-12878 (CVE-2026-12878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77139 |
|
Path Traversal in path-traversal (CVE-2026-77139)
path traversal in path-traversal (CVE-2026-77139). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77142 |
|
Vulnerability in CVE-2026-77142 (CVE-2026-77142)
vulnerability in CVE-2026-77142 (CVE-2026-77142). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77143 |
|
Vulnerability in CVE-2026-77143 (CVE-2026-77143)
vulnerability in CVE-2026-77143 (CVE-2026-77143). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77140 |
|
Vulnerability in CVE-2026-77140 (CVE-2026-77140)
vulnerability in CVE-2026-77140 (CVE-2026-77140). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77141 |
|
Vulnerability in CVE-2026-77141 (CVE-2026-77141)
vulnerability in CVE-2026-77141 (CVE-2026-77141). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77146 |
|
Vulnerability in CVE-2026-77146 (CVE-2026-77146)
vulnerability in CVE-2026-77146 (CVE-2026-77146). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78566 |
|
Vulnerability in wordpress (CVE-2026-78566)
vulnerability in wordpress (CVE-2026-78566). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78562 |
|
Vulnerability in wordpress (CVE-2026-78562)
vulnerability in wordpress (CVE-2026-78562). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78568 |
|
SQL Injection in wordpress (CVE-2026-78568)
SQL injection in wordpress (CVE-2026-78568). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78563 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-78563)
cross-site scripting in wordpress (CVE-2026-78563). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77137 |
|
SQL Injection in CVE-2026-77137 (CVE-2026-77137)
SQL injection in CVE-2026-77137 (CVE-2026-77137). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77138 |
|
Unsafe Deserialization in CVE-2026-77138 (CVE-2026-77138)
vulnerability in CVE-2026-77138 (CVE-2026-77138). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77134 |
|
Authorization Flaw in CVE-2026-77134 (CVE-2026-77134)
vulnerability in CVE-2026-77134 (CVE-2026-77134). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77128 |
|
Vulnerability in CVE-2026-77128 (CVE-2026-77128)
vulnerability in CVE-2026-77128 (CVE-2026-77128). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77133 |
|
Vulnerability in privilege-escalation (CVE-2026-77133)
vulnerability in privilege-escalation (CVE-2026-77133). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77129 |
|
Vulnerability in CVE-2026-77129 (CVE-2026-77129)
vulnerability in CVE-2026-77129 (CVE-2026-77129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77136 |
|
Vulnerability in CVE-2026-77136 (CVE-2026-77136)
vulnerability in CVE-2026-77136 (CVE-2026-77136). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63587 |
|
Vulnerability in CVE-2026-63587 (CVE-2026-63587)
vulnerability in CVE-2026-63587 (CVE-2026-63587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56095 |
|
Unsafe Deserialization in CVE-2026-56095 (CVE-2026-56095)
vulnerability in CVE-2026-56095 (CVE-2026-56095). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17548 |
|
Vulnerability in CVE-2026-17548 (CVE-2026-17548)
vulnerability in CVE-2026-17548 (CVE-2026-17548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56092 |
|
Vulnerability in CVE-2026-56092 (CVE-2026-56092)
vulnerability in CVE-2026-56092 (CVE-2026-56092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63586 |
|
OS Command Injection in CVE-2026-63586 (CVE-2026-63586)
OS command injection in CVE-2026-63586 (CVE-2026-63586). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`.
|
| CVE-2026-78701 |
|
Out-of-Bounds Write in dos (CVE-2026-78701)
out-of-bounds write in dos (CVE-2026-78701). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78322 |
|
Vulnerability in dos (CVE-2026-78322)
vulnerability in dos (CVE-2026-78322). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67578 |
|
FA-50 all versions miss authentication for some configuration.
An attacker with access to the...
FA-50 all versions miss authentication for some configuration.
An attacker with access to the...
|
| CVE-2026-66882 |
|
Cross-Site Scripting (XSS) in CVE-2026-66882 (CVE-2026-66882)
cross-site scripting in CVE-2026-66882 (CVE-2026-66882). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59769 |
|
Vulnerability in cisa (CVE-2026-59769)
vulnerability in cisa (CVE-2026-59769). Data can be tampered with by attackers.
|
| CVE-2026-65633 |
|
Authentication Bypass in CVE-2026-65633 (CVE-2026-65633)
authentication bypass in CVE-2026-65633 (CVE-2026-65633). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`.
|
| CVE-2026-16601 |
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
| CVE-2026-18512 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18512)
cross-site scripting in wordpress (CVE-2026-18512). Risk of unauthorized operations or information disclosure.
|