Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Clear
ID Title
CVE-2026-60023 Information Disclosure in apache (CVE-2026-60023)
vulnerability in apache (CVE-2026-60023). Confidential information can be exposed externally.
CVE-2026-60053 Vulnerability in apache (CVE-2026-60053)
vulnerability in apache (CVE-2026-60053). Confidential information can be exposed externally.
CVE-2026-48911 Vulnerability in apache (CVE-2026-48911)
vulnerability in apache (CVE-2026-48911). Data can be tampered with by attackers.
CVE-2026-48912 Vulnerability in apache (CVE-2026-48912)
vulnerability in apache (CVE-2026-48912). Data can be tampered with by attackers.
CVE-2026-50749 Authorization Flaw in apache (CVE-2026-50749)
vulnerability in apache (CVE-2026-50749). Data can be tampered with by attackers.
CVE-2026-53992 Cross-Site Scripting (XSS) in CVE-2026-53992 (CVE-2026-53992)
cross-site scripting in CVE-2026-53992 (CVE-2026-53992). Risk of unauthorized operations or information disclosure.
CVE-2026-48834 Vulnerability in apache (CVE-2026-48834)
vulnerability in apache (CVE-2026-48834). Risk of unauthorized operations or information disclosure.
CVE-2026-18531 Vulnerability in ibm (CVE-2026-18531)
vulnerability in ibm (CVE-2026-18531). Risk of unauthorized operations or information disclosure.
CVE-2026-15656 Vulnerability in ibm (CVE-2026-15656)
vulnerability in ibm (CVE-2026-15656). Risk of unauthorized operations or information disclosure.
CVE-2026-13477 OS Command Injection in ibm (CVE-2026-13477)
OS command injection in ibm (CVE-2026-13477). Risk of unauthorized operations or information disclosure.
CVE-2026-12762 Vulnerability in ibm (CVE-2026-12762)
vulnerability in ibm (CVE-2026-12762). Risk of unauthorized operations or information disclosure.
CVE-2026-12730 Vulnerability in ibm (CVE-2026-12730)
vulnerability in ibm (CVE-2026-12730). Risk of unauthorized operations or information disclosure.
CVE-2026-10025 XXE (XML External Entity) in ibm (CVE-2026-10025)
vulnerability in ibm (CVE-2026-10025). Confidential information can be exposed externally.
CVE-2026-7529 Vulnerability in wordpress (CVE-2026-7529)
vulnerability in wordpress (CVE-2026-7529). Data can be tampered with by attackers.
CVE-2026-7456 Vulnerability in wordpress (CVE-2026-7456)
vulnerability in wordpress (CVE-2026-7456). Data can be tampered with by attackers.
CVE-2026-67623 Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
CVE-2026-17506 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17506)
cross-site scripting in wordpress (CVE-2026-17506). Risk of unauthorized operations or information disclosure.
CVE-2026-15979 Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
CVE-2026-71294 Unsafe Deserialization in CVE-2026-71294 (CVE-2026-71294)
vulnerability in CVE-2026-71294 (CVE-2026-71294). Confidential information can be exposed externally. Exploitable via ``allowed_classes``.
CVE-2026-71293 Information Disclosure in CVE-2026-71293 (CVE-2026-71293)
vulnerability in CVE-2026-71293 (CVE-2026-71293). Confidential information can be exposed externally. Exploitable via ``two_factor_recovery_codes``.
CVE-2026-71292 SQL Injection in CVE-2026-71292 (CVE-2026-71292)
SQL injection in CVE-2026-71292 (CVE-2026-71292). Successful exploitation can lead to full system takeover. Exploitable via ``dir``.
CVE-2026-71291 Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
CVE-2026-71287 Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
CVE-2026-71251 Vulnerability in CVE-2026-71251 (CVE-2026-71251)
vulnerability in CVE-2026-71251 (CVE-2026-71251). Confidential information can be exposed externally.
CVE-2026-71252 Vulnerability in CVE-2026-71252 (CVE-2026-71252)
vulnerability in CVE-2026-71252 (CVE-2026-71252). Data can be tampered with by attackers.
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
CVE-2026-71250 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71250)
SSRF in ssrf (CVE-2026-71250). Risk of unauthorized operations or information disclosure.
CVE-2026-71249 Cross-Site Scripting (XSS) in CVE-2026-71249 (CVE-2026-71249)
cross-site scripting in CVE-2026-71249 (CVE-2026-71249). Risk of unauthorized operations or information disclosure.
CVE-2026-71248 SQL Injection in sqli (CVE-2026-71248)
SQL injection in sqli (CVE-2026-71248). Successful exploitation can lead to full system takeover.
CVE-2026-71245 SQL Injection in CVE-2026-71245 (CVE-2026-71245)
SQL injection in CVE-2026-71245 (CVE-2026-71245). Confidential information can be exposed externally.
CVE-2026-71237 SQL Injection in sqli (CVE-2026-71237)
SQL injection in sqli (CVE-2026-71237). Successful exploitation can lead to full system takeover. Exploitable via `POST /userlogin`.
CVE-2026-71236 Cross-Site Scripting (XSS) in CVE-2026-71236 (CVE-2026-71236)
cross-site scripting in CVE-2026-71236 (CVE-2026-71236). Confidential information can be exposed externally.
CVE-2026-71233 Cross-Site Scripting (XSS) in laravel (CVE-2026-71233)
cross-site scripting in laravel (CVE-2026-71233). Confidential information can be exposed externally. Exploitable via `PUT /api/v1/invoices/{id}`.
CVE-2026-71231 SQL Injection in sqli (CVE-2026-71231)
SQL injection in sqli (CVE-2026-71231). Successful exploitation can lead to full system takeover.
CVE-2026-71232 Code Injection in CVE-2026-71232 (CVE-2026-71232)
code injection in CVE-2026-71232 (CVE-2026-71232). Successful exploitation can lead to full system takeover.
CVE-2026-15452 Cross-Site Scripting (XSS) in wordpress (CVE-2026-15452)
cross-site scripting in wordpress (CVE-2026-15452). Risk of unauthorized operations or information disclosure.
CVE-2026-7726 Vulnerability in wordpress (CVE-2026-7726)
vulnerability in wordpress (CVE-2026-7726). Risk of unauthorized operations or information disclosure. Exploitable via ``wp_ajax_nopriv_handle_sync``.
CVE-2026-7441 Cross-Site Scripting (XSS) in wordpress (CVE-2026-7441)
cross-site scripting in wordpress (CVE-2026-7441). Risk of unauthorized operations or information disclosure. Exploitable via ``posttype``.
CVE-2026-7105 Vulnerability in wordpress (CVE-2026-7105)
vulnerability in wordpress (CVE-2026-7105). Risk of unauthorized operations or information disclosure. Exploitable via ``xpro_content``.
CVE-2026-7693 Command Injection in wordpress (CVE-2026-7693)
command injection in wordpress (CVE-2026-7693). Successful exploitation can lead to full system takeover. Exploitable via ``file``.
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-71207 SQL Injection in CVE-2026-71207 (CVE-2026-71207)
SQL injection in CVE-2026-71207 (CVE-2026-71207). Successful exploitation can lead to full system takeover.
CVE-2026-6972 Cross-Site Scripting (XSS) in wordpress (CVE-2026-6972)
cross-site scripting in wordpress (CVE-2026-6972). Risk of unauthorized operations or information disclosure. Exploitable via ``chart_size``.
CVE-2026-70376 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
vulnerability in csrf (CVE-2026-70376). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
CVE-2026-6639 Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-6079 Vulnerability in wordpress (CVE-2026-6079)
vulnerability in wordpress (CVE-2026-6079). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →