Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-39581 |
|
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
|
| CVE-2026-49772 |
|
SQL Injection in sqli (CVE-2026-49772)
SQL injection in sqli (CVE-2026-49772). Confidential information can be exposed externally.
|
| CVE-2026-52712 |
|
Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.
|
| CVE-2026-39490 |
|
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
|
| CVE-2026-40809 |
|
Vulnerability in CVE-2026-40809 (CVE-2026-40809)
vulnerability in CVE-2026-40809 (CVE-2026-40809). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52711 |
|
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.
|
| CVE-2026-49774 |
|
Code Injection in CVE-2026-49774 (CVE-2026-49774)
code injection in CVE-2026-49774 (CVE-2026-49774). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39437 |
|
Cross-Site Scripting (XSS) in CVE-2026-39437 (CVE-2026-39437)
cross-site scripting in CVE-2026-39437 (CVE-2026-39437). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10825 |
|
Vulnerability in CVE-2026-10825 (CVE-2026-10825)
vulnerability in CVE-2026-10825 (CVE-2026-10825). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2381 |
|
Vulnerability in wordpress (CVE-2026-2381)
vulnerability in wordpress (CVE-2026-2381). Risk of unauthorized operations or information disclosure. Exploitable via ``wc_stripe_pay_for_order``.
|
| CVE-2025-68045 |
|
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
|
| CVE-2026-8444 |
|
SQL Injection in wordpress (CVE-2026-8444)
SQL injection in wordpress (CVE-2026-8444). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10093 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10093)
cross-site scripting in wordpress (CVE-2026-10093). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46331 |
|
Vulnerability in linux (CVE-2026-46331)
vulnerability in linux (CVE-2026-46331). Successful exploitation can lead to full system takeover.
|
| CVE-2025-9912 |
|
Privilege Escalation in privilege-escalation (CVE-2025-9912)
vulnerability in privilege-escalation (CVE-2025-9912). Data can be tampered with by attackers.
|
| CVE-2026-5667 |
|
Vulnerability in jvn (CVE-2026-5667)
vulnerability in jvn (CVE-2026-5667). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6933 |
|
Unrestricted File Upload in wordpress (CVE-2026-6933)
vulnerability in wordpress (CVE-2026-6933). Successful exploitation can lead to full system takeover.
|
| CVE-2025-10262 |
|
Vulnerability in privilege-escalation (CVE-2025-10262)
vulnerability in privilege-escalation (CVE-2025-10262). Data can be tampered with by attackers.
|
| CVE-2026-9187 |
|
Vulnerability in wordpress (CVE-2026-9187)
vulnerability in wordpress (CVE-2026-9187). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5149 |
|
Authorization Flaw in wordpress (CVE-2026-5149)
vulnerability in wordpress (CVE-2026-5149). Confidential information can be exposed externally.
|
| CVE-2026-8443 |
|
SQL Injection in wordpress (CVE-2026-8443)
SQL injection in wordpress (CVE-2026-8443). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50255 |
|
Vulnerability in CVE-2026-50255 (CVE-2026-50255)
vulnerability in CVE-2026-50255 (CVE-2026-50255). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10635 |
|
Use-After-Free in c (CVE-2026-10635)
vulnerability in c (CVE-2026-10635). Data can be tampered with by attackers.
|
| CVE-2026-6964 |
|
Vulnerability in wordpress (CVE-2026-6964)
vulnerability in wordpress (CVE-2026-6964). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7273 |
|
Vulnerability in CVE-2026-7273 (CVE-2026-7273)
vulnerability in CVE-2026-7273 (CVE-2026-7273). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1765 |
|
Out-of-Bounds Read in dos (CVE-2026-1765)
vulnerability in dos (CVE-2026-1765). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1764 |
|
Out-of-Bounds Read in dos (CVE-2026-1764)
vulnerability in dos (CVE-2026-1764). Risk of unauthorized operations or information disclosure. Exploitable via ``extract_performers_tags``.
|
| CVE-2026-12161 |
|
OS Command Injection in devolutions (CVE-2026-12161)
OS command injection in devolutions (CVE-2026-12161). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9262 |
|
Vulnerability in canon (CVE-2026-9262)
vulnerability in canon (CVE-2026-9262). Confidential information can be exposed externally.
|
| CVE-2026-9258 |
|
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
|
| CVE-2026-9259 |
|
Vulnerability in canon (CVE-2026-9259)
vulnerability in canon (CVE-2026-9259). Confidential information can be exposed externally.
|
| CVE-2026-9260 |
|
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
|
| CVE-2026-48853 |
|
Unsafe Deserialization in grpc (CVE-2026-48853)
vulnerability in grpc (CVE-2026-48853). Risk of unauthorized operations or information disclosure. Exploitable via ``Enum.map``. Mitigation: upgrade to `1.0.0` or later.
|
| CVE-2026-48854 |
|
Vulnerability in grpc (CVE-2026-48854)
vulnerability in grpc (CVE-2026-48854). Risk of unauthorized operations or information disclosure. Exploitable via ``WINDOW_UPDATE``. Mitigation: upgrade to `1.0.0` or later.
|
| CVE-2026-48723 |
|
OS Command Injection in CVE-2026-48723 (CVE-2026-48723)
OS command injection in CVE-2026-48723 (CVE-2026-48723). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5064 |
|
Vulnerability in dos (CVE-2026-5064)
vulnerability in dos (CVE-2026-5064). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48713 |
|
Vulnerability in i18next-fs-backend (CVE-2026-48713)
vulnerability in i18next-fs-backend (CVE-2026-48713). Data can be tampered with by attackers. Exploitable via ``missingKeyHandler``. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-48714 |
|
Vulnerability in i18next-http-middleware (CVE-2026-48714)
vulnerability in i18next-http-middleware (CVE-2026-48714). Data can be tampered with by attackers. Exploitable via ``missingKeyHandler``. Mitigation: upgrade to `3.9.7` or later.
|
| CVE-2026-48157 |
|
Cross-Site Scripting (XSS) in slim/slim (CVE-2026-48157)
cross-site scripting in slim/slim (CVE-2026-48157). Risk of unauthorized operations or information disclosure. Exploitable via ``HttpNotFoundException``. Mitigation: upgrade to `4.15.2` or later.
|
| CVE-2026-12087 |
|
Out-of-Bounds Read in CVE-2026-12087 (CVE-2026-12087)
vulnerability in CVE-2026-12087 (CVE-2026-12087). Confidential information can be exposed externally.
|
| CVE-2026-49776 |
|
SQL Injection in wordpress (CVE-2026-49776)
SQL injection in wordpress (CVE-2026-49776). Confidential information can be exposed externally.
|
| CVE-2026-52693 |
|
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
|
| CVE-2026-52697 |
|
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
|
| CVE-2026-52700 |
|
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
|
| CVE-2026-49773 |
|
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
|
| CVE-2026-52702 |
|
Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
|
| CVE-2026-49775 |
|
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
|
| CVE-2026-49765 |
|
Unsafe Deserialization in CVE-2026-49765 (CVE-2026-49765)
vulnerability in CVE-2026-49765 (CVE-2026-49765). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49770 |
|
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
|
| CVE-2026-49781 |
|
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
|