Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Clear
ID Title
CVE-2018-25325 Path Traversal in wordpress (CVE-2018-25325)
path traversal in wordpress (CVE-2018-25325). Confidential information can be exposed externally.
CVE-2026-8751 Vulnerability in deserialization (CVE-2026-8751)
vulnerability in deserialization (CVE-2026-8751). Risk of unauthorized operations or information disclosure.
CVE-2026-8719 Privilege Escalation in wordpress (CVE-2026-8719)
vulnerability in wordpress (CVE-2026-8719). Successful exploitation can lead to full system takeover.
CVE-2021-47976 Cross-Site Request Forgery (CSRF) in csrf (CVE-2021-47976)
vulnerability in csrf (CVE-2021-47976). Successful exploitation can lead to full system takeover.
CVE-2021-47977 Path Traversal in wordpress (CVE-2021-47977)
path traversal in wordpress (CVE-2021-47977). Confidential information can be exposed externally.
CVE-2021-47979 Path Traversal in c (CVE-2021-47979)
path traversal in c (CVE-2021-47979). Successful exploitation can lead to full system takeover.
CVE-2021-47954 SQL Injection in sqli (CVE-2021-47954)
SQL injection in sqli (CVE-2021-47954). Confidential information can be exposed externally.
CVE-2021-47956 SQL Injection in sqli (CVE-2021-47956)
SQL injection in sqli (CVE-2021-47956). Confidential information can be exposed externally.
CVE-2020-37227 Unrestricted File Upload in CVE-2020-37227 (CVE-2020-37227)
vulnerability in CVE-2020-37227 (CVE-2020-37227). Successful exploitation can lead to full system takeover.
CVE-2026-46367 Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
CVE-2026-46408 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter t...
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter the payment flow without verifying cart ownership. A logged-in attacker can therefore reuse another u...
CVE-2026-46359 phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
CVE-2026-46366 phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
CVE-2021-47964 Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated...
Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated...
CVE-2021-47966 PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in...
PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in...
CVE-2021-47959 WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows...
WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows...
CVE-2026-45578 OS Command Injection in WWBN/AVideo (CVE-2026-45578)
OS command injection in WWBN/AVideo (CVE-2026-45578). Successful exploitation can lead to full system takeover. Exploitable via ``on_publish.php``.
CVE-2026-45575 Vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-45575)
vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-45575). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.2` or later.
CVE-2026-45574 Vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-45574)
vulnerability in com.oviva.telematik:epa4all-client (CVE-2026-45574). Confidential information can be exposed externally. Mitigation: upgrade to `1.2.2` or later.
CVE-2026-46491 Path Traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491)
path traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491). Data can be tampered with by attackers. Exploitable via ``ticket``. Mitigation: upgrade to `7.0.3` or later.
CVE-2026-44692 Vulnerability in code16/sharp (CVE-2026-44692)
vulnerability in code16/sharp (CVE-2026-44692). Confidential information can be exposed externally. Exploitable via `GET /sharp/{globalFilter}/download/{entityKey}/{instanceId`. Mitigation: upgrade to `9.22.0` or later.
CVE-2026-45062 Vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062)
vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062). Successful exploitation can lead to full system takeover. Exploitable via ``cgi.go``. Mitigation: upgrade to `1.12.3` or later.
CVE-2026-35194 Code Injection in flink (CVE-2026-35194)
code injection in flink (CVE-2026-35194). Confidential information can be exposed externally. Mitigation: upgrade to `1.20.4, 2.0.2, 2.1.1, 2.2.1` or later.
CVE-2026-46333 Privilege Escalation in cisa (CVE-2026-46333)
vulnerability in cisa (CVE-2026-46333). Confidential information can be exposed externally.
CVE-2026-6228 Privilege Escalation in wordpress (CVE-2026-6228)
vulnerability in wordpress (CVE-2026-6228). Successful exploitation can lead to full system takeover.
CVE-2026-6403 Path Traversal in wordpress (CVE-2026-6403)
path traversal in wordpress (CVE-2026-6403). Confidential information can be exposed externally.
CVE-2026-4094 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
CVE-2026-41702 VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an...
CVE-2026-43490 Out-of-Bounds Write in linux (CVE-2026-43490)
out-of-bounds write in linux (CVE-2026-43490). Successful exploitation can lead to full system takeover.
CVE-2026-8585 Vulnerability in c (CVE-2026-8585)
vulnerability in c (CVE-2026-8585). Successful exploitation can lead to full system takeover.
CVE-2026-8587 Use-After-Free in google (CVE-2026-8587)
vulnerability in google (CVE-2026-8587). Successful exploitation can lead to full system takeover.
CVE-2026-8581 Use-After-Free in google (CVE-2026-8581)
vulnerability in google (CVE-2026-8581). Successful exploitation can lead to full system takeover.
CVE-2026-8571 Vulnerability in google (CVE-2026-8571)
vulnerability in google (CVE-2026-8571). Successful exploitation can lead to full system takeover.
CVE-2026-8555 Use-After-Free in Google chrome (CVE-2026-8555)
vulnerability in Google chrome (CVE-2026-8555). Successful exploitation can lead to full system takeover.
CVE-2026-8558 Out-of-Bounds Write in google (CVE-2026-8558)
out-of-bounds write in google (CVE-2026-8558). Successful exploitation can lead to full system takeover.
CVE-2026-8557 Use-After-Free in privilege-escalation (CVE-2026-8557)
vulnerability in privilege-escalation (CVE-2026-8557). Successful exploitation can lead to full system takeover.
CVE-2026-8573 Vulnerability in google (CVE-2026-8573)
vulnerability in google (CVE-2026-8573). Successful exploitation can lead to full system takeover.
CVE-2026-8575 Use-After-Free in google (CVE-2026-8575)
vulnerability in google (CVE-2026-8575). Successful exploitation can lead to full system takeover.
CVE-2026-8569 Out-of-Bounds Write in google (CVE-2026-8569)
out-of-bounds write in google (CVE-2026-8569). Successful exploitation can lead to full system takeover.
CVE-2026-8574 Use-After-Free in google (CVE-2026-8574)
vulnerability in google (CVE-2026-8574). Successful exploitation can lead to full system takeover.
CVE-2026-8577 Vulnerability in google (CVE-2026-8577)
vulnerability in google (CVE-2026-8577). Successful exploitation can lead to full system takeover.
CVE-2026-8526 Out-of-Bounds Write in google (CVE-2026-8526)
out-of-bounds write in google (CVE-2026-8526). Successful exploitation can lead to full system takeover.
CVE-2026-8527 Vulnerability in google (CVE-2026-8527)
vulnerability in google (CVE-2026-8527). Successful exploitation can lead to full system takeover.
CVE-2026-8544 Use-After-Free in google (CVE-2026-8544)
vulnerability in google (CVE-2026-8544). Successful exploitation can lead to full system takeover.
CVE-2026-8529 Vulnerability in google (CVE-2026-8529)
vulnerability in google (CVE-2026-8529). Successful exploitation can lead to full system takeover.
CVE-2026-8534 Vulnerability in google (CVE-2026-8534)
vulnerability in google (CVE-2026-8534). Successful exploitation can lead to full system takeover.
CVE-2026-8542 Use-After-Free in google (CVE-2026-8542)
vulnerability in google (CVE-2026-8542). Successful exploitation can lead to full system takeover.
CVE-2026-8547 Vulnerability in privilege-escalation (CVE-2026-8547)
vulnerability in privilege-escalation (CVE-2026-8547). Successful exploitation can lead to full system takeover.
CVE-2026-8530 Use-After-Free in google (CVE-2026-8530)
vulnerability in google (CVE-2026-8530). Successful exploitation can lead to full system takeover.
CVE-2026-8532 Vulnerability in google (CVE-2026-8532)
vulnerability in google (CVE-2026-8532). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →