Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-65640 |
|
Unrestricted File Upload in wordpress (CVE-2026-65640)
vulnerability in wordpress (CVE-2026-65640). Successful exploitation can lead to full system takeover. Exploitable via ``upload_files``.
|
| CVE-2026-75014 |
|
Vulnerability in sqli (CVE-2026-75014)
vulnerability in sqli (CVE-2026-75014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57485 |
|
Information Disclosure in CVE-2026-57485 (CVE-2026-57485)
vulnerability in CVE-2026-57485 (CVE-2026-57485). Confidential information can be exposed externally.
|
| CVE-2026-56686 |
|
OS Command Injection in dell (CVE-2026-56686)
OS command injection in dell (CVE-2026-56686). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56090 |
|
Vulnerability in dell (CVE-2026-56090)
vulnerability in dell (CVE-2026-56090). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56685 |
|
OS Command Injection in dell (CVE-2026-56685)
OS command injection in dell (CVE-2026-56685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59910 |
|
OS Command Injection in dell (CVE-2026-59910)
OS command injection in dell (CVE-2026-59910). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59909 |
|
Vulnerability in path-traversal (CVE-2026-59909)
vulnerability in path-traversal (CVE-2026-59909). Data can be tampered with by attackers.
|
| CVE-2026-2497 |
|
SQL Injection in wordpress (CVE-2026-2497)
SQL injection in wordpress (CVE-2026-2497). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10734 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10734)
cross-site scripting in wordpress (CVE-2026-10734). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13424 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13424)
cross-site scripting in wordpress (CVE-2026-13424). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17087 |
|
Vulnerability in wordpress (CVE-2026-17087)
vulnerability in wordpress (CVE-2026-17087). Confidential information can be exposed externally.
|
| CVE-2026-18653 |
|
SQL Injection in wordpress (CVE-2026-18653)
SQL injection in wordpress (CVE-2026-18653). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19717 |
|
Information Disclosure in wordpress (CVE-2026-19717)
vulnerability in wordpress (CVE-2026-19717). Confidential information can be exposed externally.
|
| CVE-2026-19728 |
|
Vulnerability in wordpress (CVE-2026-19728)
vulnerability in wordpress (CVE-2026-19728). Confidential information can be exposed externally.
|
| CVE-2026-17581 |
|
Code Injection in wordpress (CVE-2026-17581)
code injection in wordpress (CVE-2026-17581). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17533 |
|
Privilege Escalation in wordpress (CVE-2026-17533)
vulnerability in wordpress (CVE-2026-17533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16099 |
|
Unsafe Deserialization in wordpress (CVE-2026-16099)
vulnerability in wordpress (CVE-2026-16099). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17123 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-17123)
SSRF in wordpress (CVE-2026-17123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14498 |
|
Unrestricted File Upload in wordpress (CVE-2026-14498)
vulnerability in wordpress (CVE-2026-14498). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15002 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15002)
cross-site scripting in wordpress (CVE-2026-15002). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19919 |
|
Vulnerability in sqli (CVE-2026-19919)
vulnerability in sqli (CVE-2026-19919). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19899 |
|
Vulnerability in sqli (CVE-2026-19899)
vulnerability in sqli (CVE-2026-19899). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73635 |
|
Vulnerability in apache (CVE-2026-73635)
vulnerability in apache (CVE-2026-73635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73634 |
|
Vulnerability in apache (CVE-2026-73634)
vulnerability in apache (CVE-2026-73634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18438 |
|
Unrestricted File Upload in wordpress (CVE-2026-18438)
vulnerability in wordpress (CVE-2026-18438). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15142 |
|
Privilege Escalation in wordpress (CVE-2026-15142)
vulnerability in wordpress (CVE-2026-15142). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14279 |
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
| CVE-2026-16611 |
|
Information Disclosure in wordpress (CVE-2026-16611)
vulnerability in wordpress (CVE-2026-16611). Confidential information can be exposed externally.
|
| CVE-2026-16145 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16145)
cross-site scripting in wordpress (CVE-2026-16145). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13360 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13360)
cross-site scripting in wordpress (CVE-2026-13360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15162 |
|
SQL Injection in wordpress (CVE-2026-15162)
SQL injection in wordpress (CVE-2026-15162). Confidential information can be exposed externally.
|
| CVE-2026-15001 |
|
Privilege Escalation in wordpress (CVE-2026-15001)
vulnerability in wordpress (CVE-2026-15001). Successful exploitation can lead to full system takeover. Exploitable via ``save_bloyal_configuration_data``.
|
| CVE-2026-15965 |
|
Unrestricted File Upload in wordpress (CVE-2026-15965)
vulnerability in wordpress (CVE-2026-15965). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15312 |
|
Privilege Escalation in wordpress (CVE-2026-15312)
vulnerability in wordpress (CVE-2026-15312). Successful exploitation can lead to full system takeover. Exploitable via ``role``.
|
| CVE-2026-14433 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14433)
cross-site scripting in wordpress (CVE-2026-14433). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73683 |
|
Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69414 |
|
Vulnerability in microsoft (CVE-2026-69414)
vulnerability in microsoft (CVE-2026-69414). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50523 |
|
Command Injection in microsoft (CVE-2026-50523)
command injection in microsoft (CVE-2026-50523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73680 |
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
| CVE-2026-18554 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
|
| CVE-2026-17179 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a...
|
| CVE-2026-17177 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service...
|
| CVE-2026-17175 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain...
|
| CVE-2026-17081 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due...
|
| CVE-2026-16915 |
|
Path Traversal in ibm (CVE-2026-16915)
path traversal in ibm (CVE-2026-16915). Confidential information can be exposed externally.
|
| CVE-2026-16879 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
|
| CVE-2026-16708 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive...
|
| CVE-2026-73679 |
|
Code Injection in CVE-2026-73679 (CVE-2026-73679)
code injection in CVE-2026-73679 (CVE-2026-73679). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72970 |
|
Vulnerability in microsoft (CVE-2026-72970)
vulnerability in microsoft (CVE-2026-72970). Confidential information can be exposed externally.
|