Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16142 |
|
Vulnerability in wordpress (CVE-2026-16142)
vulnerability in wordpress (CVE-2026-16142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15826 |
|
Vulnerability in wordpress (CVE-2026-15826)
vulnerability in wordpress (CVE-2026-15826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14279 |
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
| CVE-2026-18807 |
|
Vulnerability in wordpress (CVE-2026-18807)
vulnerability in wordpress (CVE-2026-18807). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18216 |
|
Authentication Bypass in wordpress (CVE-2026-18216)
authentication bypass in wordpress (CVE-2026-18216). Confidential information can be exposed externally.
|
| CVE-2026-16541 |
|
Information Disclosure in wordpress (CVE-2026-16541)
vulnerability in wordpress (CVE-2026-16541). Confidential information can be exposed externally.
|
| CVE-2026-16611 |
|
Information Disclosure in wordpress (CVE-2026-16611)
vulnerability in wordpress (CVE-2026-16611). Confidential information can be exposed externally.
|
| CVE-2026-14230 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14230)
cross-site scripting in wordpress (CVE-2026-14230). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14229 |
|
Vulnerability in wordpress (CVE-2026-14229)
vulnerability in wordpress (CVE-2026-14229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18387 |
|
SQL Injection in wordpress (CVE-2026-18387)
SQL injection in wordpress (CVE-2026-18387). Confidential information can be exposed externally.
|
| CVE-2026-17090 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17090)
cross-site scripting in wordpress (CVE-2026-17090). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16586 |
|
SQL Injection in wordpress (CVE-2026-16586)
SQL injection in wordpress (CVE-2026-16586). Confidential information can be exposed externally.
|
| CVE-2026-16146 |
|
SQL Injection in wordpress (CVE-2026-16146)
SQL injection in wordpress (CVE-2026-16146). Confidential information can be exposed externally.
|
| CVE-2026-16145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16094 |
|
SQL Injection in wordpress (CVE-2026-16094)
SQL injection in wordpress (CVE-2026-16094). Confidential information can be exposed externally.
|
| CVE-2026-15993 |
|
SQL Injection in wordpress (CVE-2026-15993)
SQL injection in wordpress (CVE-2026-15993). Confidential information can be exposed externally.
|
| CVE-2026-15948 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15948)
cross-site scripting in wordpress (CVE-2026-15948). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15453 |
|
SQL Injection in wordpress (CVE-2026-15453)
SQL injection in wordpress (CVE-2026-15453). Confidential information can be exposed externally.
|
| CVE-2026-13360 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13360)
cross-site scripting in wordpress (CVE-2026-13360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8840 |
|
Vulnerability in wordpress (CVE-2026-8840)
vulnerability in wordpress (CVE-2026-8840). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16080 |
|
SQL Injection in wordpress (CVE-2026-16080)
SQL injection in wordpress (CVE-2026-16080). Confidential information can be exposed externally.
|
| CVE-2026-15312 |
|
Privilege Escalation in wordpress (CVE-2026-15312)
vulnerability in wordpress (CVE-2026-15312). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
|
| CVE-2026-15341 |
|
Authentication Bypass in wordpress (CVE-2026-15341)
authentication bypass in wordpress (CVE-2026-15341). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
|
| CVE-2026-15965 |
|
Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15303 |
|
Authentication Bypass in wordpress (CVE-2026-15303)
authentication bypass in wordpress (CVE-2026-15303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15001 |
|
Privilege Escalation in wordpress (CVE-2026-15001)
vulnerability in wordpress (CVE-2026-15001). Successful exploitation can lead to full system takeover. Exploitable via ``save_bloyal_configuration_data``.
|
| CVE-2026-15162 |
|
SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
|
| CVE-2026-12128 |
|
Vulnerability in wordpress (CVE-2026-12128)
vulnerability in wordpress (CVE-2026-12128). Risk of unauthorized operations or information disclosure. Exploitable via ``cart_data``.
|
| CVE-2026-14433 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14433)
cross-site scripting in wordpress (CVE-2026-14433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14484 |
|
Path Traversal in wordpress (CVE-2026-14484)
path traversal in wordpress (CVE-2026-14484). Data can be tampered with by attackers.
|
| CVE-2026-73683 |
|
Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69414 |
|
Vulnerability in microsoft (CVE-2026-69414)
vulnerability in microsoft (CVE-2026-69414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50523 |
|
Command Injection in microsoft (CVE-2026-50523)
command injection in microsoft (CVE-2026-50523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73680 |
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
| CVE-2026-18554 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
|
| CVE-2026-18178 |
|
Path Traversal in path-traversal (CVE-2026-18178)
path traversal in path-traversal (CVE-2026-18178). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17227 |
|
SQL Injection in ibm (CVE-2026-17227)
SQL injection in ibm (CVE-2026-17227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17209 |
|
Cross-Site Scripting (XSS) in ibm (CVE-2026-17209)
cross-site scripting in ibm (CVE-2026-17209). Data can be tampered with by attackers.
|
| CVE-2026-17186 |
|
OS Command Injection in ibm (CVE-2026-17186)
OS command injection in ibm (CVE-2026-17186). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17184 |
|
Vulnerability in ibm (CVE-2026-17184)
vulnerability in ibm (CVE-2026-17184). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17182 |
|
Authentication Bypass in ibm (CVE-2026-17182)
authentication bypass in ibm (CVE-2026-17182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17181 |
|
Path Traversal in path-traversal (CVE-2026-17181)
path traversal in path-traversal (CVE-2026-17181). Data can be tampered with by attackers.
|
| CVE-2026-17179 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
|
| CVE-2026-17177 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
|
| CVE-2026-17175 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
|
| CVE-2026-17173 |
|
Path Traversal in ibm (CVE-2026-17173)
path traversal in ibm (CVE-2026-17173). Confidential information can be exposed externally.
|
| CVE-2026-17081 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
|
| CVE-2026-17079 |
|
Vulnerability in ibm (CVE-2026-17079)
vulnerability in ibm (CVE-2026-17079). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16915 |
|
Path Traversal in ibm (CVE-2026-16915)
path traversal in ibm (CVE-2026-16915). Confidential information can be exposed externally.
|
| CVE-2026-16905 |
|
Authentication Bypass in ibm (CVE-2026-16905)
authentication bypass in ibm (CVE-2026-16905). Risk of unauthorized operations or information disclosure.
|