Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5425 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5425)
cross-site scripting in wordpress (CVE-2026-5425). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4896 |
|
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu...
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via multiple AJAX actions including `wcfm_modify_order_status`, `delete_wcfm_article`,...
|
| CVE-2026-23448 |
|
Vulnerability in express (CVE-2026-23448)
vulnerability in express (CVE-2026-23448). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23447 |
|
Vulnerability in express (CVE-2026-23447)
vulnerability in express (CVE-2026-23447). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4350 |
|
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verifi...
|
| CVE-2026-34759 |
|
Vulnerability in nginx (CVE-2026-34759)
vulnerability in nginx (CVE-2026-34759). Successful exploitation can lead to full system takeover.
|
| CVE-2025-65114 |
|
Vulnerability in apache (CVE-2025-65114)
vulnerability in apache (CVE-2025-65114). Data can be tampered with by attackers.
|
| CVE-2025-58136 |
|
Vulnerability in apache (CVE-2025-58136)
vulnerability in apache (CVE-2025-58136). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34406 |
|
Vulnerability in django (CVE-2026-34406)
vulnerability in django (CVE-2026-34406). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/auth/edituser/`.
|
| CVE-2026-34404 |
|
Vulnerability in vue (CVE-2026-34404)
vulnerability in vue (CVE-2026-34404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34381 |
|
Vulnerability in apache (CVE-2026-34381)
vulnerability in apache (CVE-2026-34381). Confidential information can be exposed externally.
|
| CVE-2026-4267 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4267)
cross-site scripting in wordpress (CVE-2026-4267). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-28367 |
|
Vulnerability in io.undertow:undertow-parent (CVE-2026-28367)
vulnerability in io.undertow:undertow-parent (CVE-2026-28367). Confidential information can be exposed externally.
|
| CVE-2026-27654 |
|
Vulnerability in nginx (CVE-2026-27654)
vulnerability in nginx (CVE-2026-27654). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.3, 1.29.7` or later.
|
| CVE-2026-27784 |
|
Vulnerability in nginx-gateway (CVE-2026-27784)
vulnerability in nginx-gateway (CVE-2026-27784). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.28.3, 1.29.7` or later.
|
| CVE-2026-32647 |
|
Out-of-Bounds Read in nginx-gateway (CVE-2026-32647)
vulnerability in nginx-gateway (CVE-2026-32647). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.28.3, 1.29.7` or later.
|
| CVE-2026-27651 |
|
Vulnerability in nginx-gateway (CVE-2026-27651)
vulnerability in nginx-gateway (CVE-2026-27651). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.3, 1.29.7` or later.
|
| CVE-2025-54068 KEV |
|
[KEV] Code Injection in Laravel livewire (CVE-2025-54068)
code injection in Laravel livewire (CVE-2025-54068). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-4342 |
|
Vulnerability in nginx (CVE-2026-4342)
vulnerability in nginx (CVE-2026-4342). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24281 |
|
Vulnerability in zookeeper (CVE-2026-24281)
vulnerability in zookeeper (CVE-2026-24281). Confidential information can be exposed externally. Mitigation: upgrade to `3.8.6, 3.9.5` or later.
|
| CVE-2026-24308 |
|
Vulnerability in zookeeper (CVE-2026-24308)
vulnerability in zookeeper (CVE-2026-24308). Confidential information can be exposed externally. Mitigation: upgrade to `3.8.6, 3.9.5` or later.
|
| CVE-2026-25673 |
|
Vulnerability in django (CVE-2026-25673)
vulnerability in django (CVE-2026-25673). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25747 |
|
Unsafe Deserialization in apache (CVE-2026-25747)
vulnerability in apache (CVE-2026-25747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27134 |
|
Authentication Bypass in apache (CVE-2026-27134)
authentication bypass in apache (CVE-2026-27134). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0974 |
|
Vulnerability in wordpress (CVE-2026-0974)
vulnerability in wordpress (CVE-2026-0974). Successful exploitation can lead to full system takeover.
|
| CVE-2026-24734 |
|
Vulnerability in apache (CVE-2026-24734)
vulnerability in apache (CVE-2026-24734). Data can be tampered with by attackers.
|
| CVE-2026-26214 |
|
Vulnerability in apache (CVE-2026-26214)
vulnerability in apache (CVE-2026-26214). Confidential information can be exposed externally.
|
| CVE-2026-23864 |
|
Vulnerability in react (CVE-2026-23864)
vulnerability in react (CVE-2026-23864). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22774 |
|
Vulnerability in dos (CVE-2026-22774)
vulnerability in dos (CVE-2026-22774). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.6.2` or later.
|
| CVE-2026-22775 |
|
Vulnerability in dos (CVE-2026-22775)
vulnerability in dos (CVE-2026-22775). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.6.2` or later.
|
| CVE-2025-68493 |
|
XXE (XML External Entity) in apache (CVE-2025-68493)
vulnerability in apache (CVE-2025-68493). Confidential information can be exposed externally.
|
| CVE-2026-22029 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-22029)
cross-site scripting in react (CVE-2026-22029). Confidential information can be exposed externally.
|
| CVE-2025-59057 |
|
Cross-Site Scripting (XSS) in react (CVE-2025-59057)
cross-site scripting in react (CVE-2025-59057). Confidential information can be exposed externally.
|
| CVE-2026-21884 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-21884)
cross-site scripting in react (CVE-2026-21884). Confidential information can be exposed externally.
|
| CVE-2025-51741 |
|
Vulnerability in dos (CVE-2025-51741)
vulnerability in dos (CVE-2025-51741). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56399 |
|
Code Injection in laravel (CVE-2025-56399)
code injection in laravel (CVE-2025-56399). Successful exploitation can lead to full system takeover.
|
| CVE-2025-40079 |
|
Vulnerability in wordpress (CVE-2025-40079)
vulnerability in wordpress (CVE-2025-40079). Successful exploitation can lead to full system takeover.
|
| CVE-2025-55752 |
|
Vulnerability in org.apache.tomcat:tomcat (CVE-2025-55752)
vulnerability in org.apache.tomcat:tomcat (CVE-2025-55752). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.0.109, 10.1.45, 11.0.11` or later.
|
| CVE-2025-8361 |
|
Vulnerability in drupal (CVE-2025-8361)
vulnerability in drupal (CVE-2025-8361). Confidential information can be exposed externally.
|
| CVE-2025-48989 |
|
Vulnerability in org.apache.tomcat:tomcat-coyote (CVE-2025-48989)
vulnerability in org.apache.tomcat:tomcat-coyote (CVE-2025-48989). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.0.108` or later.
|
| CVE-2019-5418 KEV |
|
[KEV] Path Traversal in rails (CVE-2019-5418)
path traversal in rails (CVE-2019-5418). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2022-50014 |
|
Vulnerability in wordpress (CVE-2022-50014)
vulnerability in wordpress (CVE-2022-50014). Successful exploitation can lead to full system takeover.
|
| CVE-2023-53110 |
|
Vulnerability in nginx (CVE-2023-53110)
vulnerability in nginx (CVE-2023-53110). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-38475 KEV |
|
[KEV] Vulnerability in Apache http-server (CVE-2024-38475)
vulnerability in Apache http-server (CVE-2024-38475). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-3891 |
|
Vulnerability in apache (CVE-2025-3891)
vulnerability in apache (CVE-2025-3891). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-24813 KEV |
|
[KEV] Vulnerability in Apache tomcat (CVE-2025-24813)
vulnerability in Apache tomcat (CVE-2025-24813). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-31692 |
|
OS Command Injection in drupal (CVE-2025-31692)
OS command injection in drupal (CVE-2025-31692). Successful exploitation can lead to full system takeover.
|
| CVE-2024-45195 KEV |
|
[KEV] Vulnerability in Apache ofbiz (CVE-2024-45195)
vulnerability in Apache ofbiz (CVE-2024-45195). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-50780 |
|
Vulnerability in apache (CVE-2023-50780)
vulnerability in apache (CVE-2023-50780). Successful exploitation can lead to full system takeover.
|
| CVE-2024-27348 KEV |
|
[KEV] Vulnerability in Apache hugegraph-server (CVE-2024-27348)
vulnerability in Apache hugegraph-server (CVE-2024-27348). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|