Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19916 |
|
Cross-Site Scripting (XSS) in CVE-2026-19916 (CVE-2026-19916)
cross-site scripting in CVE-2026-19916 (CVE-2026-19916). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19905 |
|
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
|
| CVE-2026-18855 |
|
Path Traversal in wordpress (CVE-2026-18855)
path traversal in wordpress (CVE-2026-18855). Data can be tampered with by attackers.
|
| CVE-2026-19906 |
|
Vulnerability in CVE-2026-19906 (CVE-2026-19906)
vulnerability in CVE-2026-19906 (CVE-2026-19906). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19903 |
|
Vulnerability in CVE-2026-19903 (CVE-2026-19903)
vulnerability in CVE-2026-19903 (CVE-2026-19903). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19598 |
|
Authorization Flaw in wordpress (CVE-2026-19598)
vulnerability in wordpress (CVE-2026-19598). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19900 |
|
Vulnerability in CVE-2026-19900 (CVE-2026-19900)
vulnerability in CVE-2026-19900 (CVE-2026-19900). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19901 |
|
Vulnerability in CVE-2026-19901 (CVE-2026-19901)
vulnerability in CVE-2026-19901 (CVE-2026-19901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19904 |
|
Cross-Site Scripting (XSS) in CVE-2026-19904 (CVE-2026-19904)
cross-site scripting in CVE-2026-19904 (CVE-2026-19904). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19899 |
|
Vulnerability in sqli (CVE-2026-19899)
vulnerability in sqli (CVE-2026-19899). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19896 |
|
Vulnerability in flask (CVE-2026-19896)
vulnerability in flask (CVE-2026-19896). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18165 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-18165)
vulnerability in csrf (CVE-2026-18165). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18500 |
|
Vulnerability in CVE-2026-18500 (CVE-2026-18500)
vulnerability in CVE-2026-18500 (CVE-2026-18500). Confidential information can be exposed externally.
|
| CVE-2026-19474 |
|
Vulnerability in dos (CVE-2026-19474)
vulnerability in dos (CVE-2026-19474). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18549 |
|
Vulnerability in CVE-2026-18549 (CVE-2026-18549)
vulnerability in CVE-2026-18549 (CVE-2026-18549). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19894 |
|
Vulnerability in sqli (CVE-2026-19894)
vulnerability in sqli (CVE-2026-19894). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73193 |
|
Vulnerability in CVE-2026-73193 (CVE-2026-73193)
vulnerability in CVE-2026-73193 (CVE-2026-73193). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73194 |
|
Out-of-Bounds Write in CVE-2026-73194 (CVE-2026-73194)
out-of-bounds write in CVE-2026-73194 (CVE-2026-73194). Confidential information can be exposed externally.
|
| CVE-2026-19893 |
|
Vulnerability in CVE-2026-19893 (CVE-2026-19893)
vulnerability in CVE-2026-19893 (CVE-2026-19893). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73635 |
|
Vulnerability in apache (CVE-2026-73635)
vulnerability in apache (CVE-2026-73635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73634 |
|
Vulnerability in apache (CVE-2026-73634)
vulnerability in apache (CVE-2026-73634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12248 |
|
SQL Injection in wordpress (CVE-2026-12248)
SQL injection in wordpress (CVE-2026-12248). Confidential information can be exposed externally.
|
| CVE-2026-19891 |
|
Vulnerability in CVE-2026-19891 (CVE-2026-19891)
vulnerability in CVE-2026-19891 (CVE-2026-19891). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15142 |
|
Privilege Escalation in wordpress (CVE-2026-15142)
vulnerability in wordpress (CVE-2026-15142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14279 |
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
| CVE-2026-15826 |
|
Vulnerability in wordpress (CVE-2026-15826)
vulnerability in wordpress (CVE-2026-15826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16611 |
|
Information Disclosure in wordpress (CVE-2026-16611)
vulnerability in wordpress (CVE-2026-16611). Confidential information can be exposed externally.
|
| CVE-2026-16541 |
|
Information Disclosure in wordpress (CVE-2026-16541)
vulnerability in wordpress (CVE-2026-16541). Confidential information can be exposed externally.
|
| CVE-2026-14230 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14230)
cross-site scripting in wordpress (CVE-2026-14230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16007 |
|
SQL Injection in sqli (CVE-2026-16007)
SQL injection in sqli (CVE-2026-16007). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18216 |
|
Authentication Bypass in wordpress (CVE-2026-18216)
authentication bypass in wordpress (CVE-2026-18216). Confidential information can be exposed externally.
|
| CVE-2026-14229 |
|
Vulnerability in wordpress (CVE-2026-14229)
vulnerability in wordpress (CVE-2026-14229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18807 |
|
Vulnerability in wordpress (CVE-2026-18807)
vulnerability in wordpress (CVE-2026-18807). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18387 |
|
SQL Injection in wordpress (CVE-2026-18387)
SQL injection in wordpress (CVE-2026-18387). Confidential information can be exposed externally.
|
| CVE-2026-17090 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17090)
cross-site scripting in wordpress (CVE-2026-17090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16586 |
|
SQL Injection in wordpress (CVE-2026-16586)
SQL injection in wordpress (CVE-2026-16586). Confidential information can be exposed externally.
|
| CVE-2026-16146 |
|
SQL Injection in wordpress (CVE-2026-16146)
SQL injection in wordpress (CVE-2026-16146). Confidential information can be exposed externally.
|
| CVE-2026-16094 |
|
SQL Injection in wordpress (CVE-2026-16094)
SQL injection in wordpress (CVE-2026-16094). Confidential information can be exposed externally.
|
| CVE-2026-15993 |
|
SQL Injection in wordpress (CVE-2026-15993)
SQL injection in wordpress (CVE-2026-15993). Confidential information can be exposed externally.
|
| CVE-2026-15948 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15948)
cross-site scripting in wordpress (CVE-2026-15948). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15453 |
|
SQL Injection in wordpress (CVE-2026-15453)
SQL injection in wordpress (CVE-2026-15453). Confidential information can be exposed externally.
|
| CVE-2026-13360 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13360)
cross-site scripting in wordpress (CVE-2026-13360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8840 |
|
Vulnerability in wordpress (CVE-2026-8840)
vulnerability in wordpress (CVE-2026-8840). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15341 |
|
Authentication Bypass in wordpress (CVE-2026-15341)
authentication bypass in wordpress (CVE-2026-15341). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
|
| CVE-2026-15303 |
|
Authentication Bypass in wordpress (CVE-2026-15303)
authentication bypass in wordpress (CVE-2026-15303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15312 |
|
Privilege Escalation in wordpress (CVE-2026-15312)
vulnerability in wordpress (CVE-2026-15312). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
|
| CVE-2026-15001 |
|
Privilege Escalation in wordpress (CVE-2026-15001)
vulnerability in wordpress (CVE-2026-15001). Successful exploitation can lead to full system takeover. Exploitable via ``save_bloyal_configuration_data``.
|
| CVE-2026-15965 |
|
Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
|