Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Clear
ID Title
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
CVE-2026-71215 art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
CVE-2026-71206 Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
CVE-2026-71202 Vulnerability in CVE-2026-71202 (CVE-2026-71202)
vulnerability in CVE-2026-71202 (CVE-2026-71202). Risk of unauthorized operations or information disclosure.
CVE-2026-70378 Vulnerability in CVE-2026-70378 (CVE-2026-70378)
vulnerability in CVE-2026-70378 (CVE-2026-70378). Risk of unauthorized operations or information disclosure. Exploitable via ``scale``.
CVE-2026-6639 Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-6020 Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
CVE-2026-64581 Vulnerability in c (CVE-2026-64581)
vulnerability in c (CVE-2026-64581). Successful exploitation can lead to full system takeover.
CVE-2026-64580 Vulnerability in c (CVE-2026-64580)
vulnerability in c (CVE-2026-64580). Successful exploitation can lead to full system takeover.
CVE-2026-64578 Vulnerability in c (CVE-2026-64578)
vulnerability in c (CVE-2026-64578). Risk of unauthorized operations or information disclosure.
CVE-2026-64577 Vulnerability in c (CVE-2026-64577)
vulnerability in c (CVE-2026-64577). Risk of unauthorized operations or information disclosure.
CVE-2026-64576 Vulnerability in c (CVE-2026-64576)
vulnerability in c (CVE-2026-64576). Confidential information can be exposed externally.
CVE-2026-64575 Vulnerability in c (CVE-2026-64575)
vulnerability in c (CVE-2026-64575). Successful exploitation can lead to full system takeover.
CVE-2026-64574 Vulnerability in c (CVE-2026-64574)
vulnerability in c (CVE-2026-64574). Successful exploitation can lead to full system takeover.
CVE-2026-64570 Vulnerability in c (CVE-2026-64570)
vulnerability in c (CVE-2026-64570). Successful exploitation can lead to full system takeover.
CVE-2026-64568 Vulnerability in c (CVE-2026-64568)
vulnerability in c (CVE-2026-64568). Successful exploitation can lead to full system takeover.
CVE-2026-64567 Vulnerability in c (CVE-2026-64567)
vulnerability in c (CVE-2026-64567). Successful exploitation can lead to full system takeover.
CVE-2026-55997 Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
CVE-2026-54416 Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
CVE-2026-70374 OS Command Injection in CVE-2026-70374 (CVE-2026-70374)
OS command injection in CVE-2026-70374 (CVE-2026-70374). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/{project}/{environment}/media/new.`.
CVE-2026-70375 OS Command Injection in CVE-2026-70375 (CVE-2026-70375)
OS command injection in CVE-2026-70375 (CVE-2026-70375). Successful exploitation can lead to full system takeover.
CVE-2026-16573 Cross-Site Scripting (XSS) in wordpress (CVE-2026-16573)
cross-site scripting in wordpress (CVE-2026-16573). Successful exploitation can lead to full system takeover.
CVE-2026-14553 Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
CVE-2026-8761 Vulnerability in wordpress (CVE-2026-8761)
vulnerability in wordpress (CVE-2026-8761). Successful exploitation can lead to full system takeover. Exploitable via ``CustomersController``.
CVE-2026-18322 Privilege Escalation in wordpress (CVE-2026-18322)
vulnerability in wordpress (CVE-2026-18322). Successful exploitation can lead to full system takeover. Exploitable via ``save``.
CVE-2026-67862 Vulnerability in c (CVE-2026-67862)
vulnerability in c (CVE-2026-67862). Risk of unauthorized operations or information disclosure.
CVE-2026-67857 Out-of-Bounds Read in c (CVE-2026-67857)
vulnerability in c (CVE-2026-67857). Risk of unauthorized operations or information disclosure.
CVE-2026-51401 Code Injection in c (CVE-2026-51401)
code injection in c (CVE-2026-51401). Confidential information can be exposed externally.
CVE-2026-51400 Vulnerability in c (CVE-2026-51400)
vulnerability in c (CVE-2026-51400). Successful exploitation can lead to full system takeover.
CVE-2026-18813 Vulnerability in c (CVE-2026-18813)
vulnerability in c (CVE-2026-18813). Successful exploitation can lead to full system takeover.
CVE-2026-70479 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70479)
SSRF in open-webui (CVE-2026-70479). Confidential information can be exposed externally. Exploitable via ``PLAYWRIGHT_WS_URL``. Mitigation: upgrade to `0.11.0` or later.
CVE-2026-47618 SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47618)
SSRF in nvidia (CVE-2026-47618). Confidential information can be exposed externally.
CVE-2026-18788 Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
CVE-2026-56848 Use-After-Free in CVE-2026-56848 (CVE-2026-56848)
vulnerability in CVE-2026-56848 (CVE-2026-56848). Risk of unauthorized operations or information disclosure.
CVE-2026-18770 Vulnerability in CVE-2026-18770 (CVE-2026-18770)
vulnerability in CVE-2026-18770 (CVE-2026-18770). Risk of unauthorized operations or information disclosure.
CVE-2026-67195 Vulnerability in CVE-2026-67195 (CVE-2026-67195)
vulnerability in CVE-2026-67195 (CVE-2026-67195). Successful exploitation can lead to full system takeover.
CVE-2026-11368 Use-After-Free in c (CVE-2026-11368)
vulnerability in c (CVE-2026-11368). Risk of unauthorized operations or information disclosure.
CVE-2026-64563 Vulnerability in c (CVE-2026-64563)
vulnerability in c (CVE-2026-64563). Successful exploitation can lead to full system takeover.
CVE-2026-16623 Code Injection in wordpress (CVE-2026-16623)
code injection in wordpress (CVE-2026-16623). Successful exploitation can lead to full system takeover.
CVE-2026-56846 Vulnerability in CVE-2026-56846 (CVE-2026-56846)
vulnerability in CVE-2026-56846 (CVE-2026-56846). Risk of unauthorized operations or information disclosure.
CVE-2026-10849 Vulnerability in c (CVE-2026-10849)
vulnerability in c (CVE-2026-10849). Risk of unauthorized operations or information disclosure.
CVE-2026-41447 Vulnerability in c (CVE-2026-41447)
vulnerability in c (CVE-2026-41447). Successful exploitation can lead to full system takeover.
CVE-2026-67598 Vulnerability in CVE-2026-67598 (CVE-2026-67598)
vulnerability in CVE-2026-67598 (CVE-2026-67598). Confidential information can be exposed externally.
CVE-2026-67599 OS Command Injection in CVE-2026-67599 (CVE-2026-67599)
OS command injection in CVE-2026-67599 (CVE-2026-67599). Successful exploitation can lead to full system takeover.
CVE-2026-69246 Vulnerability in guzzlehttp/guzzle (CVE-2026-69246)
vulnerability in guzzlehttp/guzzle (CVE-2026-69246). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `7.15.2` or later.
CVE-2026-61524 Unrestricted File Upload in CVE-2026-61524 (CVE-2026-61524)
vulnerability in CVE-2026-61524 (CVE-2026-61524). Successful exploitation can lead to full system takeover.
CVE-2026-61523 Code Injection in CVE-2026-61523 (CVE-2026-61523)
code injection in CVE-2026-61523 (CVE-2026-61523). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →