Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-5581 |
|
Vulnerability in wordpress (CVE-2026-5581)
vulnerability in wordpress (CVE-2026-5581). Data can be tampered with by attackers. Exploitable via ``wp_ajax_nopriv_gfmu_delete_file``.
|
| CVE-2026-5116 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5116)
cross-site scripting in wordpress (CVE-2026-5116). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5108 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-5108)
cross-site scripting in wordpress (CVE-2026-5108). Risk of unauthorized operations or information disclosure. Exploitable via ``innerHTML``.
|
| CVE-2026-59675 |
|
Vulnerability in CVE-2026-59675 (CVE-2026-59675)
vulnerability in CVE-2026-59675 (CVE-2026-59675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55998 |
|
Vulnerability in CVE-2026-55998 (CVE-2026-55998)
vulnerability in CVE-2026-55998 (CVE-2026-55998). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55997 |
|
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
|
| CVE-2026-55996 |
|
Vulnerability in dos (CVE-2026-55996)
vulnerability in dos (CVE-2026-55996). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55747 |
|
Path Traversal in CVE-2026-55747 (CVE-2026-55747)
path traversal in CVE-2026-55747 (CVE-2026-55747). Confidential information can be exposed externally.
|
| CVE-2026-55739 |
|
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
|
| CVE-2026-54418 |
|
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
|
| CVE-2026-54416 |
|
Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4431 |
|
Vulnerability in wordpress (CVE-2026-4431)
vulnerability in wordpress (CVE-2026-4431). Data can be tampered with by attackers. Exploitable via ``rbsm_submit_post``.
|
| CVE-2026-18881 |
|
SQL Injection in wordpress (CVE-2026-18881)
SQL injection in wordpress (CVE-2026-18881). Confidential information can be exposed externally. Exploitable via ``tableon_get_table_data``.
|
| CVE-2026-17532 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17532)
cross-site scripting in wordpress (CVE-2026-17532). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17505 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17505)
cross-site scripting in wordpress (CVE-2026-17505). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15281 |
|
SQL Injection in wordpress (CVE-2026-15281)
SQL injection in wordpress (CVE-2026-15281). Confidential information can be exposed externally.
|
| CVE-2026-12000 |
|
Vulnerability in wordpress (CVE-2026-12000)
vulnerability in wordpress (CVE-2026-12000). Confidential information can be exposed externally.
|
| CVE-2026-11977 |
|
SQL Injection in wordpress (CVE-2026-11977)
SQL injection in wordpress (CVE-2026-11977). Confidential information can be exposed externally.
|
| CVE-2026-11969 |
|
SQL Injection in wordpress (CVE-2026-11969)
SQL injection in wordpress (CVE-2026-11969). Confidential information can be exposed externally.
|
| CVE-2026-11920 |
|
SQL Injection in wordpress (CVE-2026-11920)
SQL injection in wordpress (CVE-2026-11920). Confidential information can be exposed externally.
|
| CVE-2026-11454 |
|
Vulnerability in wordpress (CVE-2026-11454)
vulnerability in wordpress (CVE-2026-11454). Confidential information can be exposed externally. Exploitable via `GET /wp-json/gh/v4/contacts/`.
|
| CVE-2022-35948 |
|
Vulnerability in jvn (CVE-2022-35948)
vulnerability in jvn (CVE-2022-35948). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71201 |
|
Authorization Flaw in CVE-2026-71201 (CVE-2026-71201)
vulnerability in CVE-2026-71201 (CVE-2026-71201). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70375 |
|
OS Command Injection in CVE-2026-70375 (CVE-2026-70375)
OS command injection in CVE-2026-70375 (CVE-2026-70375). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70374 |
|
OS Command Injection in CVE-2026-70374 (CVE-2026-70374)
OS command injection in CVE-2026-70374 (CVE-2026-70374). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/{project}/{environment}/media/new.`.
|
| CVE-2026-68080 |
|
Vulnerability in apache (CVE-2026-68080)
vulnerability in apache (CVE-2026-68080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68078 |
|
Vulnerability in apache (CVE-2026-68078)
vulnerability in apache (CVE-2026-68078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68077 |
|
Vulnerability in apache (CVE-2026-68077)
vulnerability in apache (CVE-2026-68077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68075 |
|
Vulnerability in apache (CVE-2026-68075)
vulnerability in apache (CVE-2026-68075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68073 |
|
Vulnerability in apache (CVE-2026-68073)
vulnerability in apache (CVE-2026-68073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67592 |
|
Vulnerability in apache (CVE-2026-67592)
vulnerability in apache (CVE-2026-67592). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67591 |
|
Vulnerability in apache (CVE-2026-67591)
vulnerability in apache (CVE-2026-67591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67590 |
|
Vulnerability in apache (CVE-2026-67590)
vulnerability in apache (CVE-2026-67590). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67555 |
|
Vulnerability in apache (CVE-2026-67555)
vulnerability in apache (CVE-2026-67555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67554 |
|
Vulnerability in apache (CVE-2026-67554)
vulnerability in apache (CVE-2026-67554). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67553 |
|
Vulnerability in apache (CVE-2026-67553)
vulnerability in apache (CVE-2026-67553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67552 |
|
Vulnerability in apache (CVE-2026-67552)
vulnerability in apache (CVE-2026-67552). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66277 |
|
Vulnerability in apache (CVE-2026-66277)
vulnerability in apache (CVE-2026-66277). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66276 |
|
Vulnerability in apache (CVE-2026-66276)
vulnerability in apache (CVE-2026-66276). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66275 |
|
Vulnerability in apache (CVE-2026-66275)
vulnerability in apache (CVE-2026-66275). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66274 |
|
Vulnerability in apache (CVE-2026-66274)
vulnerability in apache (CVE-2026-66274). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49004 |
|
SQL Injection in CVE-2026-49004 (CVE-2026-49004)
SQL injection in CVE-2026-49004 (CVE-2026-49004). Confidential information can be exposed externally.
|
| CVE-2026-17515 |
|
Information Disclosure in wordpress (CVE-2026-17515)
vulnerability in wordpress (CVE-2026-17515). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16993 |
|
Information Disclosure in wordpress (CVE-2026-16993)
vulnerability in wordpress (CVE-2026-16993). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16981 |
|
Vulnerability in wordpress (CVE-2026-16981)
vulnerability in wordpress (CVE-2026-16981). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16968 |
|
Information Disclosure in wordpress (CVE-2026-16968)
vulnerability in wordpress (CVE-2026-16968). Confidential information can be exposed externally.
|
| CVE-2026-16942 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16942)
cross-site scripting in wordpress (CVE-2026-16942). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16940 |
|
Path Traversal in wordpress (CVE-2026-16940)
path traversal in wordpress (CVE-2026-16940). Data can be tampered with by attackers.
|
| CVE-2026-16746 |
|
Vulnerability in wordpress (CVE-2026-16746)
vulnerability in wordpress (CVE-2026-16746). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16736 |
|
Vulnerability in wordpress (CVE-2026-16736)
vulnerability in wordpress (CVE-2026-16736). Confidential information can be exposed externally.
|