Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-35025 |
|
Vulnerability in proftpd (CVE-2026-35025)
vulnerability in proftpd (CVE-2026-35025). Confidential information can be exposed externally.
|
| CVE-2026-12537 |
|
Vulnerability in google (CVE-2026-12537)
vulnerability in google (CVE-2026-12537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56257 |
|
Vulnerability in CVE-2026-56257 (CVE-2026-56257)
vulnerability in CVE-2026-56257 (CVE-2026-56257). Data can be tampered with by attackers.
|
| CVE-2026-56256 |
|
Vulnerability in CVE-2026-56256 (CVE-2026-56256)
vulnerability in CVE-2026-56256 (CVE-2026-56256). Data can be tampered with by attackers.
|
| CVE-2026-56245 |
|
Privilege Escalation in CVE-2026-56245 (CVE-2026-56245)
vulnerability in CVE-2026-56245 (CVE-2026-56245). Data can be tampered with by attackers. Exploitable via `POST /rest/v1/rpc/record_build_time`.
|
| CVE-2026-56244 |
|
Information Disclosure in CVE-2026-56244 (CVE-2026-56244)
vulnerability in CVE-2026-56244 (CVE-2026-56244). Confidential information can be exposed externally.
|
| CVE-2026-56232 |
|
Authorization Flaw in CVE-2026-56232 (CVE-2026-56232)
vulnerability in CVE-2026-56232 (CVE-2026-56232). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56231 |
|
Vulnerability in dos (CVE-2026-56231)
vulnerability in dos (CVE-2026-56231). Risk of unauthorized operations or information disclosure. Exploitable via `POST /build/start/`.
|
| CVE-2026-56223 |
|
Authentication Bypass in CVE-2026-56223 (CVE-2026-56223)
authentication bypass in CVE-2026-56223 (CVE-2026-56223). Confidential information can be exposed externally.
|
| CVE-2026-12242 |
|
Code Injection in wordpress (CVE-2026-12242)
code injection in wordpress (CVE-2026-12242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52943 |
|
Use-After-Free in privilege-escalation (CVE-2026-52943)
vulnerability in privilege-escalation (CVE-2026-52943). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7761 |
|
Vulnerability in wordpress (CVE-2026-7761)
vulnerability in wordpress (CVE-2026-7761). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52942 |
|
Out-of-Bounds Read in c (CVE-2026-52942)
vulnerability in c (CVE-2026-52942). Confidential information can be exposed externally.
|
| CVE-2026-56052 |
|
SQL Injection in sqli (CVE-2026-56052)
SQL injection in sqli (CVE-2026-56052). Confidential information can be exposed externally.
|
| CVE-2026-52919 |
|
Vulnerability in linux (CVE-2026-52919)
vulnerability in linux (CVE-2026-52919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52917 |
|
Out-of-Bounds Read in linux (CVE-2026-52917)
vulnerability in linux (CVE-2026-52917). Confidential information can be exposed externally.
|
| CVE-2026-52920 |
|
Vulnerability in linux (CVE-2026-52920)
vulnerability in linux (CVE-2026-52920). Confidential information can be exposed externally.
|
| CVE-2026-52923 |
|
Vulnerability in linux (CVE-2026-52923)
vulnerability in linux (CVE-2026-52923). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52922 |
|
Vulnerability in linux (CVE-2026-52922)
vulnerability in linux (CVE-2026-52922). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52918 |
|
Vulnerability in linux (CVE-2026-52918)
vulnerability in linux (CVE-2026-52918). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52933 |
|
Vulnerability in linux (CVE-2026-52933)
vulnerability in linux (CVE-2026-52933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52932 |
|
Vulnerability in linux (CVE-2026-52932)
vulnerability in linux (CVE-2026-52932). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52935 |
|
Out-of-Bounds Write in linux (CVE-2026-52935)
out-of-bounds write in linux (CVE-2026-52935). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52927 |
|
Out-of-Bounds Read in linux (CVE-2026-52927)
vulnerability in linux (CVE-2026-52927). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52929 |
|
Vulnerability in linux (CVE-2026-52929)
vulnerability in linux (CVE-2026-52929). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52934 |
|
Vulnerability in linux (CVE-2026-52934)
vulnerability in linux (CVE-2026-52934). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52912 |
|
Use-After-Free in linux (CVE-2026-52912)
vulnerability in linux (CVE-2026-52912). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52915 |
|
Vulnerability in c (CVE-2026-52915)
vulnerability in c (CVE-2026-52915). Confidential information can be exposed externally. Exploitable via ``IP6T_OPTS_OPTSNR``.
|
| CVE-2026-9643 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9643)
cross-site scripting in wordpress (CVE-2026-9643). Risk of unauthorized operations or information disclosure. Exploitable via ``wp_wpms_links.link_url``.
|
| CVE-2026-9710 |
|
Vulnerability in wordpress (CVE-2026-9710)
vulnerability in wordpress (CVE-2026-9710). Confidential information can be exposed externally. Exploitable via ``cornerstone``.
|
| CVE-2026-9709 |
|
Vulnerability in wordpress (CVE-2026-9709)
vulnerability in wordpress (CVE-2026-9709). Confidential information can be exposed externally. Exploitable via ``cornerstone``.
|
| CVE-2026-9178 |
|
Vulnerability in wordpress (CVE-2026-9178)
vulnerability in wordpress (CVE-2026-9178). Confidential information can be exposed externally.
|
| CVE-2026-9179 |
|
SQL Injection in wordpress (CVE-2026-9179)
SQL injection in wordpress (CVE-2026-9179). Confidential information can be exposed externally.
|
| CVE-2026-8705 |
|
SQL Injection in wordpress (CVE-2026-8705)
SQL injection in wordpress (CVE-2026-8705). Confidential information can be exposed externally. Exploitable via ``clearsale_total_push``.
|
| CVE-2026-4297 |
|
Vulnerability in wordpress (CVE-2026-4297)
vulnerability in wordpress (CVE-2026-4297). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12100 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-12100)
SSRF in wordpress (CVE-2026-12100). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12095 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-12095)
SSRF in wordpress (CVE-2026-12095). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10092 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10092)
cross-site scripting in wordpress (CVE-2026-10092). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10091 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-10091)
cross-site scripting in wordpress (CVE-2026-10091). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10735 |
|
Vulnerability in wordpress (CVE-2026-10735)
vulnerability in wordpress (CVE-2026-10735). Confidential information can be exposed externally.
|
| CVE-2026-10749 |
|
Vulnerability in wordpress (CVE-2026-10749)
vulnerability in wordpress (CVE-2026-10749). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3652 |
|
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value`...
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value`...
|
| CVE-2026-54639 |
|
Style Dictionary - Prototype Pollution in convertTokenData utility function
Style Dictionary - Prototype Pollution in convertTokenData utility function
|
| CVE-2026-7574 |
|
Vulnerability in CVE-2026-7574 (CVE-2026-7574)
vulnerability in CVE-2026-7574 (CVE-2026-7574). Confidential information can be exposed externally.
|
| CVE-2026-56785 |
|
Cross-Site Scripting (XSS) in CVE-2026-56785 (CVE-2026-56785)
cross-site scripting in CVE-2026-56785 (CVE-2026-56785). Confidential information can be exposed externally.
|
| CVE-2026-54329 |
|
Vulnerability in snipe/snipe-it (CVE-2026-54329)
vulnerability in snipe/snipe-it (CVE-2026-54329). Data can be tampered with by attackers. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-54512 |
|
Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54512)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54512). Successful exploitation can lead to full system takeover. Exploitable via ``PolymorphicTypeValidator``. Mitigation: upgrade to `2.21.4` or later.
|
| CVE-2026-50193 |
|
Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-50193)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-50193). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonNode``. Mitigation: upgrade to `2.14.0` or later.
|
| CVE-2026-56120 |
|
Vulnerability in CVE-2026-56120 (CVE-2026-56120)
vulnerability in CVE-2026-56120 (CVE-2026-56120). Confidential information can be exposed externally.
|
| CVE-2026-54513 |
|
Vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54513)
vulnerability in com.fasterxml.jackson.core:jackson-databind (CVE-2026-54513). Successful exploitation can lead to full system takeover. Exploitable via ``EvilType``. Mitigation: upgrade to `3.1.4` or later.
|