Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13147 |
|
Vulnerability in wordpress (CVE-2026-13147)
vulnerability in wordpress (CVE-2026-13147). Confidential information can be exposed externally.
|
| CVE-2026-63030 KEV |
|
WordPress Core — WordPress Core Interpretation Conflict Vulnerability
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
|
| CVE-2026-42168 |
|
OS Command Injection in django (CVE-2026-42168)
OS command injection in django (CVE-2026-42168). Confidential information can be exposed externally.
|
| CVE-2026-9810 |
|
Privilege Escalation in wordpress (CVE-2026-9810)
vulnerability in wordpress (CVE-2026-9810). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15982 |
|
Privilege Escalation in wordpress (CVE-2026-15982)
vulnerability in wordpress (CVE-2026-15982). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14956 |
|
Privilege Escalation in wordpress (CVE-2026-14956)
vulnerability in wordpress (CVE-2026-14956). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45336 |
|
Vulnerability in flask (CVE-2026-45336)
vulnerability in flask (CVE-2026-45336). Confidential information can be exposed externally.
|
| CVE-2026-12492 |
|
Authentication Bypass in wordpress (CVE-2026-12492)
authentication bypass in wordpress (CVE-2026-12492). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15013 |
|
Vulnerability in wordpress (CVE-2026-15013)
vulnerability in wordpress (CVE-2026-15013). Successful exploitation can lead to full system takeover. Exploitable via ``SignatureMethod``.
|
| CVE-2026-13001 |
|
Vulnerability in wordpress (CVE-2026-13001)
vulnerability in wordpress (CVE-2026-13001). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62390 |
|
SQL Injection in apache (CVE-2026-62390)
SQL injection in apache (CVE-2026-62390). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62392 |
|
OS Command Injection in apache (CVE-2026-62392)
OS command injection in apache (CVE-2026-62392). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58319 |
|
Vulnerability in apache (CVE-2026-58319)
vulnerability in apache (CVE-2026-58319). Data can be tampered with by attackers.
|
| CVE-2026-59083 |
|
Vulnerability in apache (CVE-2026-59083)
vulnerability in apache (CVE-2026-59083). Confidential information can be exposed externally.
|
| CVE-2026-59084 |
|
Vulnerability in apache (CVE-2026-59084)
vulnerability in apache (CVE-2026-59084). Confidential information can be exposed externally.
|
| CVE-2026-11563 |
|
Vulnerability in wordpress (CVE-2026-11563)
vulnerability in wordpress (CVE-2026-11563). Data can be tampered with by attackers.
|
| CVE-2026-41041 |
|
Vulnerability in apache (CVE-2026-41041)
vulnerability in apache (CVE-2026-41041). Confidential information can be exposed externally.
|
| CVE-2026-11964 |
|
Vulnerability in wordpress (CVE-2026-11964)
vulnerability in wordpress (CVE-2026-11964). Confidential information can be exposed externally.
|
| CVE-2026-15089 |
|
Authentication Bypass in drupal (CVE-2026-15089)
authentication bypass in drupal (CVE-2026-15089). Confidential information can be exposed externally.
|
| CVE-2026-12535 |
|
Vulnerability in drupal/formatter_field (CVE-2026-12535)
vulnerability in drupal/formatter_field (CVE-2026-12535). Successful exploitation can lead to full system takeover. Exploitable via ``formatter_field``. Mitigation: upgrade to `2.0.0` or later.
|
| CVE-2026-12761 |
|
Authentication Bypass in wordpress (CVE-2026-12761)
authentication bypass in wordpress (CVE-2026-12761). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40008 |
|
Vulnerability in c (CVE-2026-40008)
vulnerability in c (CVE-2026-40008). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40005 |
|
Path Traversal in apache (CVE-2026-40005)
path traversal in apache (CVE-2026-40005). Confidential information can be exposed externally.
|
| CVE-2026-28564 |
|
Vulnerability in apache (CVE-2026-28564)
vulnerability in apache (CVE-2026-28564). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15300 |
|
SQL Injection in wordpress (CVE-2026-15300)
SQL injection in wordpress (CVE-2026-15300). Data can be tampered with by attackers. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-15282 |
|
Unrestricted File Upload in wordpress (CVE-2026-15282)
vulnerability in wordpress (CVE-2026-15282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14894 |
|
Unrestricted File Upload in wordpress (CVE-2026-14894)
vulnerability in wordpress (CVE-2026-14894). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15158 |
|
Unrestricted File Upload in wordpress (CVE-2026-15158)
vulnerability in wordpress (CVE-2026-15158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14245 |
|
Vulnerability in wordpress (CVE-2026-14245)
vulnerability in wordpress (CVE-2026-14245). Successful exploitation can lead to full system takeover. Exploitable via ``form_nonce``.
|
| CVE-2026-58480 |
|
Unrestricted File Upload in wordpress (CVE-2026-58480)
vulnerability in wordpress (CVE-2026-58480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41042 |
|
Vulnerability in apache (CVE-2026-41042)
vulnerability in apache (CVE-2026-41042). Confidential information can be exposed externally.
|
| CVE-2026-12153 |
|
Vulnerability in wordpress (CVE-2026-12153)
vulnerability in wordpress (CVE-2026-12153). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9701 |
|
Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
|
| CVE-2026-14487 |
|
Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
|
| CVE-2026-33264 |
|
Unsafe Deserialization in apache (CVE-2026-33264)
vulnerability in apache (CVE-2026-33264). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4375 |
|
Vulnerability in wordpress (CVE-2026-4375)
vulnerability in wordpress (CVE-2026-4375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12375 |
|
Vulnerability in wordpress (CVE-2026-12375)
vulnerability in wordpress (CVE-2026-12375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56140 |
|
Vulnerability in org.apache.camel:camel-aws2-sns (CVE-2026-56140)
vulnerability in org.apache.camel:camel-aws2-sns (CVE-2026-56140). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-53913 |
|
Authentication Bypass in org.apache.camel:camel-keycloak (CVE-2026-53913)
authentication bypass in org.apache.camel:camel-keycloak (CVE-2026-53913). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-48205 |
|
Vulnerability in org.apache.camel:camel-dns (CVE-2026-48205)
vulnerability in org.apache.camel:camel-dns (CVE-2026-48205). Confidential information can be exposed externally. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-48203 |
|
Vulnerability in org.apache.camel:camel-solr (CVE-2026-48203)
vulnerability in org.apache.camel:camel-solr (CVE-2026-48203). Confidential information can be exposed externally. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-48204 |
|
Vulnerability in org.apache.camel:camel-mongodb-gridfs (CVE-2026-48204)
vulnerability in org.apache.camel:camel-mongodb-gridfs (CVE-2026-48204). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46456 |
|
Vulnerability in org.apache.camel:camel-aws2-sqs (CVE-2026-46456)
vulnerability in org.apache.camel:camel-aws2-sqs (CVE-2026-46456). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-43867 |
|
Unsafe Deserialization in org.apache.camel:camel-pqc (CVE-2026-43867)
vulnerability in org.apache.camel:camel-pqc (CVE-2026-43867). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-46455 |
|
Vulnerability in org.apache.camel:camel-keycloak (CVE-2026-46455)
vulnerability in org.apache.camel:camel-keycloak (CVE-2026-46455). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|
| CVE-2026-24014 |
|
Vulnerability in apache (CVE-2026-24014)
vulnerability in apache (CVE-2026-24014). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40047 |
|
Vulnerability in org.apache.camel:camel-docling (CVE-2026-40047)
vulnerability in org.apache.camel:camel-docling (CVE-2026-40047). Confidential information can be exposed externally. Exploitable via ``docling``. Mitigation: upgrade to `4.18.3` or later.
|
| CVE-2026-24013 |
|
Vulnerability in apache (CVE-2026-24013)
vulnerability in apache (CVE-2026-24013). Confidential information can be exposed externally.
|
| CVE-2026-46454 |
|
Vulnerability in org.apache.camel:camel-cometd (CVE-2026-46454)
vulnerability in org.apache.camel:camel-cometd (CVE-2026-46454). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.21.0` or later.
|