Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-7444 |
|
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
|
| CVE-2026-71209 |
|
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
|
| CVE-2026-71215 |
|
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
|
| CVE-2026-71206 |
|
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
|
| CVE-2026-71202 |
|
Vulnerability in CVE-2026-71202 (CVE-2026-71202)
vulnerability in CVE-2026-71202 (CVE-2026-71202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70378 |
|
Vulnerability in CVE-2026-70378 (CVE-2026-70378)
vulnerability in CVE-2026-70378 (CVE-2026-70378). Risk of unauthorized operations or information disclosure. Exploitable via ``scale``.
|
| CVE-2026-6639 |
|
Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
|
| CVE-2026-6627 |
|
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
|
| CVE-2026-6147 |
|
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
|
| CVE-2026-6020 |
|
Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64581 |
|
Vulnerability in c (CVE-2026-64581)
vulnerability in c (CVE-2026-64581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64580 |
|
Vulnerability in c (CVE-2026-64580)
vulnerability in c (CVE-2026-64580). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64578 |
|
Vulnerability in c (CVE-2026-64578)
vulnerability in c (CVE-2026-64578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64577 |
|
Vulnerability in c (CVE-2026-64577)
vulnerability in c (CVE-2026-64577). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64576 |
|
Vulnerability in c (CVE-2026-64576)
vulnerability in c (CVE-2026-64576). Confidential information can be exposed externally.
|
| CVE-2026-64575 |
|
Vulnerability in c (CVE-2026-64575)
vulnerability in c (CVE-2026-64575). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64574 |
|
Vulnerability in c (CVE-2026-64574)
vulnerability in c (CVE-2026-64574). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64570 |
|
Vulnerability in c (CVE-2026-64570)
vulnerability in c (CVE-2026-64570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64568 |
|
Vulnerability in c (CVE-2026-64568)
vulnerability in c (CVE-2026-64568). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64567 |
|
Vulnerability in c (CVE-2026-64567)
vulnerability in c (CVE-2026-64567). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55997 |
|
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
|
| CVE-2026-54416 |
|
Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70374 |
|
OS Command Injection in CVE-2026-70374 (CVE-2026-70374)
OS command injection in CVE-2026-70374 (CVE-2026-70374). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/{project}/{environment}/media/new.`.
|
| CVE-2026-70375 |
|
OS Command Injection in CVE-2026-70375 (CVE-2026-70375)
OS command injection in CVE-2026-70375 (CVE-2026-70375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16573 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16573)
cross-site scripting in wordpress (CVE-2026-16573). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14553 |
|
Unrestricted File Upload in wordpress (CVE-2026-14553)
vulnerability in wordpress (CVE-2026-14553). Confidential information can be exposed externally.
|
| CVE-2026-8761 |
|
Vulnerability in wordpress (CVE-2026-8761)
vulnerability in wordpress (CVE-2026-8761). Successful exploitation can lead to full system takeover. Exploitable via ``CustomersController``.
|
| CVE-2026-18322 |
|
Privilege Escalation in wordpress (CVE-2026-18322)
vulnerability in wordpress (CVE-2026-18322). Successful exploitation can lead to full system takeover. Exploitable via ``save``.
|
| CVE-2026-67862 |
|
Vulnerability in c (CVE-2026-67862)
vulnerability in c (CVE-2026-67862). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67857 |
|
Out-of-Bounds Read in c (CVE-2026-67857)
vulnerability in c (CVE-2026-67857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51401 |
|
Code Injection in c (CVE-2026-51401)
code injection in c (CVE-2026-51401). Confidential information can be exposed externally.
|
| CVE-2026-51400 |
|
Vulnerability in c (CVE-2026-51400)
vulnerability in c (CVE-2026-51400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18813 |
|
Vulnerability in c (CVE-2026-18813)
vulnerability in c (CVE-2026-18813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70479 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70479)
SSRF in open-webui (CVE-2026-70479). Confidential information can be exposed externally. Exploitable via ``PLAYWRIGHT_WS_URL``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-47618 |
|
SSRF (Server-Side Request Forgery) in nvidia (CVE-2026-47618)
SSRF in nvidia (CVE-2026-47618). Confidential information can be exposed externally.
|
| CVE-2026-18788 |
|
Vulnerability in CVE-2026-18788 (CVE-2026-18788)
vulnerability in CVE-2026-18788 (CVE-2026-18788). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56848 |
|
Use-After-Free in CVE-2026-56848 (CVE-2026-56848)
vulnerability in CVE-2026-56848 (CVE-2026-56848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18770 |
|
Vulnerability in CVE-2026-18770 (CVE-2026-18770)
vulnerability in CVE-2026-18770 (CVE-2026-18770). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67195 |
|
Vulnerability in CVE-2026-67195 (CVE-2026-67195)
vulnerability in CVE-2026-67195 (CVE-2026-67195). Successful exploitation can lead to full system takeover.
|
| CVE-2026-11368 |
|
Use-After-Free in c (CVE-2026-11368)
vulnerability in c (CVE-2026-11368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64563 |
|
Vulnerability in c (CVE-2026-64563)
vulnerability in c (CVE-2026-64563). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16623 |
|
Code Injection in wordpress (CVE-2026-16623)
code injection in wordpress (CVE-2026-16623). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56846 |
|
Vulnerability in CVE-2026-56846 (CVE-2026-56846)
vulnerability in CVE-2026-56846 (CVE-2026-56846). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10849 |
|
Vulnerability in c (CVE-2026-10849)
vulnerability in c (CVE-2026-10849). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41447 |
|
Vulnerability in c (CVE-2026-41447)
vulnerability in c (CVE-2026-41447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67598 |
|
Vulnerability in CVE-2026-67598 (CVE-2026-67598)
vulnerability in CVE-2026-67598 (CVE-2026-67598). Confidential information can be exposed externally.
|
| CVE-2026-67599 |
|
OS Command Injection in CVE-2026-67599 (CVE-2026-67599)
OS command injection in CVE-2026-67599 (CVE-2026-67599). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69246 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-69246)
vulnerability in guzzlehttp/guzzle (CVE-2026-69246). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-61524 |
|
Unrestricted File Upload in CVE-2026-61524 (CVE-2026-61524)
vulnerability in CVE-2026-61524 (CVE-2026-61524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61523 |
|
Code Injection in CVE-2026-61523 (CVE-2026-61523)
code injection in CVE-2026-61523 (CVE-2026-61523). Successful exploitation can lead to full system takeover.
|