Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Clear
ID Title
CVE-2026-45129 Cross-Site Request Forgery (CSRF) in CVE-2026-45129 (CVE-2026-45129)
vulnerability in CVE-2026-45129 (CVE-2026-45129). Risk of unauthorized operations or information disclosure.
CVE-2026-45126 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-45126)
vulnerability in csrf (CVE-2026-45126). Risk of unauthorized operations or information disclosure.
CVE-2026-45127 Cross-Site Request Forgery (CSRF) in CVE-2026-45127 (CVE-2026-45127)
vulnerability in CVE-2026-45127 (CVE-2026-45127). Risk of unauthorized operations or information disclosure.
CVE-2026-45125 Vulnerability in CVE-2026-45125 (CVE-2026-45125)
vulnerability in CVE-2026-45125 (CVE-2026-45125). Risk of unauthorized operations or information disclosure.
CVE-2026-45123 SSRF (Server-Side Request Forgery) in CVE-2026-45123 (CVE-2026-45123)
SSRF in CVE-2026-45123 (CVE-2026-45123). Risk of unauthorized operations or information disclosure.
CVE-2026-45124 Vulnerability in CVE-2026-45124 (CVE-2026-45124)
vulnerability in CVE-2026-45124 (CVE-2026-45124). Risk of unauthorized operations or information disclosure.
CVE-2026-45121 Authorization Flaw in CVE-2026-45121 (CVE-2026-45121)
vulnerability in CVE-2026-45121 (CVE-2026-45121). Risk of unauthorized operations or information disclosure.
CVE-2026-45122 Authorization Flaw in CVE-2026-45122 (CVE-2026-45122)
vulnerability in CVE-2026-45122 (CVE-2026-45122). Risk of unauthorized operations or information disclosure.
CVE-2026-45119 Cross-Site Request Forgery (CSRF) in CVE-2026-45119 (CVE-2026-45119)
vulnerability in CVE-2026-45119 (CVE-2026-45119). Risk of unauthorized operations or information disclosure.
CVE-2026-45116 Cross-Site Scripting (XSS) in CVE-2026-45116 (CVE-2026-45116)
cross-site scripting in CVE-2026-45116 (CVE-2026-45116). Confidential information can be exposed externally.
CVE-2026-45115 Cross-Site Scripting (XSS) in CVE-2026-45115 (CVE-2026-45115)
cross-site scripting in CVE-2026-45115 (CVE-2026-45115). Confidential information can be exposed externally.
CVE-2026-45117 Code Injection in CVE-2026-45117 (CVE-2026-45117)
code injection in CVE-2026-45117 (CVE-2026-45117). Successful exploitation can lead to full system takeover.
CVE-2026-19500 Vulnerability in CVE-2026-19500 (CVE-2026-19500)
vulnerability in CVE-2026-19500 (CVE-2026-19500). Risk of unauthorized operations or information disclosure.
CVE-2026-15806 Vulnerability in CVE-2026-15806 (CVE-2026-15806)
vulnerability in CVE-2026-15806 (CVE-2026-15806). Risk of unauthorized operations or information disclosure.
CVE-2026-12564 SSRF (Server-Side Request Forgery) in django (CVE-2026-12564)
SSRF in django (CVE-2026-12564). Confidential information can be exposed externally.
CVE-2026-75898 SSRF (Server-Side Request Forgery) in CVE-2026-75898 (CVE-2026-75898)
SSRF in CVE-2026-75898 (CVE-2026-75898). Confidential information can be exposed externally.
CVE-2026-74012 Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
Editor PHP Object Injection in TaxoPress <= 3.51.0 versions.
CVE-2026-73397 Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
CVE-2026-73383 Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.
CVE-2026-74006 Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.
CVE-2026-74004 Vulnerability in CVE-2026-74004 (CVE-2026-74004)
vulnerability in CVE-2026-74004 (CVE-2026-74004). Risk of unauthorized operations or information disclosure.
CVE-2026-73404 Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.
CVE-2026-74003 Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.
CVE-2026-73994 Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
CVE-2026-73997 Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
CVE-2026-75032 Out-of-Bounds Read in dos (CVE-2026-75032)
vulnerability in dos (CVE-2026-75032). Risk of unauthorized operations or information disclosure.
CVE-2026-73393 Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
CVE-2026-73382 Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
CVE-2026-74015 Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
CVE-2026-73392 Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.
CVE-2026-73400 Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
CVE-2026-75872 Vulnerability in c (CVE-2026-75872)
vulnerability in c (CVE-2026-75872). Risk of unauthorized operations or information disclosure.
CVE-2026-73396 Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
CVE-2026-73399 Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
CVE-2026-73381 Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
CVE-2026-73398 Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.
CVE-2026-73995 Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
CVE-2026-73996 Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.
CVE-2026-74007 Vulnerability in CVE-2026-74007 (CVE-2026-74007)
vulnerability in CVE-2026-74007 (CVE-2026-74007). Risk of unauthorized operations or information disclosure.
CVE-2026-75784 Buffer Overflow in nginx (CVE-2026-75784)
vulnerability in nginx (CVE-2026-75784). Successful exploitation can lead to full system takeover.
CVE-2026-73379 Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-73367 Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
CVE-2026-71539 Vulnerability in CVE-2026-71539 (CVE-2026-71539)
vulnerability in CVE-2026-71539 (CVE-2026-71539). Risk of unauthorized operations or information disclosure.
CVE-2026-73378 Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
CVE-2026-73362 Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
CVE-2026-73375 Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
CVE-2026-73360 Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
CVE-2026-73351 Cross-Site Scripting (XSS) in wordpress (CVE-2026-73351)
cross-site scripting in wordpress (CVE-2026-73351). Risk of unauthorized operations or information disclosure.
CVE-2026-73361 Cross-Site Scripting (XSS) in CVE-2026-73361 (CVE-2026-73361)
cross-site scripting in CVE-2026-73361 (CVE-2026-73361). Risk of unauthorized operations or information disclosure.
CVE-2026-73359 Cross-Site Scripting (XSS) in CVE-2026-73359 (CVE-2026-73359)
cross-site scripting in CVE-2026-73359 (CVE-2026-73359). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →