Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-65712 |
|
Path Traversal in CVE-2026-65712 (CVE-2026-65712)
path traversal in CVE-2026-65712 (CVE-2026-65712). Confidential information can be exposed externally.
|
| CVE-2026-65431 |
|
Path Traversal in CVE-2026-65431 (CVE-2026-65431)
path traversal in CVE-2026-65431 (CVE-2026-65431). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64875 |
|
GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
|
| CVE-2026-15761 |
|
SQL Injection in wordpress (CVE-2026-15761)
SQL injection in wordpress (CVE-2026-15761). Confidential information can be exposed externally.
|
| CVE-2026-64873 |
|
Custom query URLs could access internal or reserved network services.
Custom query URLs could access internal or reserved network services.
|
| CVE-2026-64876 |
|
Vulnerability in csrf (CVE-2026-64876)
vulnerability in csrf (CVE-2026-64876). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15794 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15794)
cross-site scripting in wordpress (CVE-2026-15794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15906 |
|
SQL Injection in wordpress (CVE-2026-15906)
SQL injection in wordpress (CVE-2026-15906). Confidential information can be exposed externally.
|
| CVE-2026-15786 |
|
Path Traversal in wordpress (CVE-2026-15786)
path traversal in wordpress (CVE-2026-15786). Confidential information can be exposed externally.
|
| CVE-2026-15646 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15646)
cross-site scripting in wordpress (CVE-2026-15646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13119 |
|
SQL Injection in wordpress (CVE-2026-13119)
SQL injection in wordpress (CVE-2026-13119). Confidential information can be exposed externally.
|
| CVE-2026-15015 |
|
Vulnerability in wordpress (CVE-2026-15015)
vulnerability in wordpress (CVE-2026-15015). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14481 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14481)
cross-site scripting in wordpress (CVE-2026-14481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13009 |
|
SQL Injection in wordpress (CVE-2026-13009)
SQL injection in wordpress (CVE-2026-13009). Confidential information can be exposed externally.
|
| CVE-2026-14282 |
|
Unrestricted File Upload in wordpress (CVE-2026-14282)
vulnerability in wordpress (CVE-2026-14282). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15011 |
|
Code Injection in wordpress (CVE-2026-15011)
code injection in wordpress (CVE-2026-15011). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15394 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15394)
cross-site scripting in wordpress (CVE-2026-15394). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15348 |
|
Authentication Bypass in wordpress (CVE-2026-15348)
authentication bypass in wordpress (CVE-2026-15348). Risk of unauthorized operations or information disclosure. Exploitable via ``wpdmppdl``.
|
| CVE-2026-15017 |
|
Privilege Escalation in wordpress (CVE-2026-15017)
vulnerability in wordpress (CVE-2026-15017). Successful exploitation can lead to full system takeover. Exploitable via ``new_role``.
|
| CVE-2026-52686 |
|
Vulnerability in CVE-2026-52686 (CVE-2026-52686)
vulnerability in CVE-2026-52686 (CVE-2026-52686). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-58330 |
|
Vulnerability in CVE-2024-58330 (CVE-2024-58330)
vulnerability in CVE-2024-58330 (CVE-2024-58330). Confidential information can be exposed externally.
|
| CVE-2026-16723 |
|
Vulnerability in com.alibaba:fastjson (CVE-2026-16723)
vulnerability in com.alibaba:fastjson (CVE-2026-16723). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52688 |
|
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
|
| CVE-2024-58023 |
|
Vulnerability in CVE-2024-58023 (CVE-2024-58023)
vulnerability in CVE-2024-58023 (CVE-2024-58023). Confidential information can be exposed externally.
|
| CVE-2026-16287 |
|
OS Command Injection in CVE-2026-16287 (CVE-2026-16287)
OS command injection in CVE-2026-16287 (CVE-2026-16287). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9713 |
|
SQL Injection in wordpress (CVE-2026-9713)
SQL injection in wordpress (CVE-2026-9713). Confidential information can be exposed externally.
|
| CVE-2026-52684 |
|
Vulnerability in CVE-2026-52684 (CVE-2026-52684)
vulnerability in CVE-2026-52684 (CVE-2026-52684). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9729 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9729)
cross-site scripting in wordpress (CVE-2026-9729). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59677 |
|
Vulnerability in CVE-2026-59677 (CVE-2026-59677)
vulnerability in CVE-2026-59677 (CVE-2026-59677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59678 |
|
Authorization Flaw in CVE-2026-59678 (CVE-2026-59678)
vulnerability in CVE-2026-59678 (CVE-2026-59678). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9577 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9577)
cross-site scripting in wordpress (CVE-2026-9577). Risk of unauthorized operations or information disclosure. Exploitable via ``mod``.
|
| CVE-2026-12421 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12421)
cross-site scripting in wordpress (CVE-2026-12421). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9635 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9635)
cross-site scripting in wordpress (CVE-2026-9635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59676 |
|
Vulnerability in CVE-2026-59676 (CVE-2026-59676)
vulnerability in CVE-2026-59676 (CVE-2026-59676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9066 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-9066)
cross-site scripting in wordpress (CVE-2026-9066). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12082 |
|
Vulnerability in wordpress (CVE-2026-12082)
vulnerability in wordpress (CVE-2026-12082). Confidential information can be exposed externally.
|
| CVE-2026-14291 |
|
Authentication Bypass in wordpress (CVE-2026-14291)
authentication bypass in wordpress (CVE-2026-14291). Confidential information can be exposed externally.
|
| CVE-2026-7534 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7534)
cross-site scripting in wordpress (CVE-2026-7534). Risk of unauthorized operations or information disclosure. Exploitable via ``user_has_cap``.
|
| CVE-2026-64600 |
|
Vulnerability in linux (CVE-2026-64600)
vulnerability in linux (CVE-2026-64600). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7232 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-7232)
cross-site scripting in wordpress (CVE-2026-7232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63226 |
|
Vulnerability in jvn (CVE-2026-63226)
vulnerability in jvn (CVE-2026-63226). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6390 |
|
Vulnerability in dos (CVE-2026-6390)
vulnerability in dos (CVE-2026-6390). Data can be tampered with by attackers.
|
| CVE-2026-7120 |
|
Vulnerability in @fastify/static (CVE-2026-7120)
vulnerability in @fastify/static (CVE-2026-7120). Risk of unauthorized operations or information disclosure. Exploitable via ``allowedPath``. Mitigation: upgrade to `10.1.2` or later.
|
| CVE-2026-15074 |
|
@fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
|
| CVE-2026-16653 |
|
Path Traversal in c (CVE-2026-16653)
path traversal in c (CVE-2026-16653). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21723 |
|
Vulnerability in CVE-2026-21723 (CVE-2026-21723)
vulnerability in CVE-2026-21723 (CVE-2026-21723). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-4028 |
|
Vulnerability in jvn (CVE-2024-4028)
vulnerability in jvn (CVE-2024-4028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16631 |
|
Command Injection in CVE-2026-16631 (CVE-2026-16631)
command injection in CVE-2026-16631 (CVE-2026-16631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16632 |
|
Vulnerability in CVE-2026-16632 (CVE-2026-16632)
vulnerability in CVE-2026-16632 (CVE-2026-16632). Risk of unauthorized operations or information disclosure.
|
| GHSA-652q-gvq3-74qv |
|
SQL Injection in n8n (GHSA-652q-gvq3-74qv)
SQL injection in n8n (GHSA-652q-gvq3-74qv). Risk of unauthorized operations or information disclosure. Exploitable via ``executeQuery``. Mitigation: upgrade to `2.31.5` or later.
|