Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-19851 |
|
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17...
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17...
|
| CVE-2026-18512 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18512)
cross-site scripting in wordpress (CVE-2026-18512). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18328 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-18323 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-18100 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-18100)
cross-site scripting in wordpress (CVE-2026-18100). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16601 |
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
| CVE-2026-78656 |
|
Vulnerability in sqli (CVE-2026-78656)
vulnerability in sqli (CVE-2026-78656). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69665 |
|
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
|
| CVE-2026-68960 |
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
| CVE-2026-68959 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-68062 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-78470 |
|
SQL Injection in wordpress (CVE-2026-78470)
SQL injection in wordpress (CVE-2026-78470). Confidential information can be exposed externally.
|
| CVE-2026-78477 |
|
Vulnerability in wordpress (CVE-2026-78477)
vulnerability in wordpress (CVE-2026-78477). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78478 |
|
Vulnerability in wordpress (CVE-2026-78478)
vulnerability in wordpress (CVE-2026-78478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78466 |
|
Vulnerability in wordpress (CVE-2026-78466)
vulnerability in wordpress (CVE-2026-78466). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78637 |
|
Vulnerability in CVE-2026-78637 (CVE-2026-78637)
vulnerability in CVE-2026-78637 (CVE-2026-78637). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78467 |
|
Vulnerability in wordpress (CVE-2026-78467)
vulnerability in wordpress (CVE-2026-78467). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12561 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-12561)
cross-site scripting in wordpress (CVE-2026-12561). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-41741 |
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
| CVE-2026-78654 |
|
Code Injection in CVE-2026-78654 (CVE-2026-78654)
code injection in CVE-2026-78654 (CVE-2026-78654). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78638 |
|
Path Traversal in path-traversal (CVE-2026-78638)
path traversal in path-traversal (CVE-2026-78638). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13215 |
|
Out-of-Bounds Write in c (CVE-2026-13215)
out-of-bounds write in c (CVE-2026-13215). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13214 |
|
Out-of-Bounds Write in c (CVE-2026-13214)
out-of-bounds write in c (CVE-2026-13214). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76063 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-76063)
cross-site scripting in wordpress (CVE-2026-76063). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75930 |
|
Vulnerability in wordpress (CVE-2026-75930)
vulnerability in wordpress (CVE-2026-75930). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19943 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-19943)
cross-site scripting in wordpress (CVE-2026-19943). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19892 |
|
Vulnerability in wordpress (CVE-2026-19892)
vulnerability in wordpress (CVE-2026-19892). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17089 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-17089)
cross-site scripting in wordpress (CVE-2026-17089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14280 |
|
Vulnerability in wordpress (CVE-2026-14280)
vulnerability in wordpress (CVE-2026-14280). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75019 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-75019)
cross-site scripting in wordpress (CVE-2026-75019). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10627 |
|
Vulnerability in wordpress (CVE-2026-10627)
vulnerability in wordpress (CVE-2026-10627). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75982 |
|
Vulnerability in wordpress (CVE-2026-75982)
vulnerability in wordpress (CVE-2026-75982). Data can be tampered with by attackers.
|
| CVE-2025-9878 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2025-9878)
cross-site scripting in wordpress (CVE-2025-9878). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78685 |
|
Vulnerability in CVE-2026-78685 (CVE-2026-78685)
vulnerability in CVE-2026-78685 (CVE-2026-78685). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78683 |
|
Unsafe Deserialization in deserialization (CVE-2026-78683)
vulnerability in deserialization (CVE-2026-78683). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.10.0` or later.
|
| CVE-2026-78682 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-78682 (CVE-2026-78682)
SSRF in CVE-2026-78682 (CVE-2026-78682). Confidential information can be exposed externally.
|
| CVE-2026-78681 |
|
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
|
| CVE-2026-78680 |
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
| CVE-2026-78679 |
|
Vulnerability in CVE-2026-78679 (CVE-2026-78679)
vulnerability in CVE-2026-78679 (CVE-2026-78679). Confidential information can be exposed externally.
|
| CVE-2026-78678 |
|
Vulnerability in CVE-2026-78678 (CVE-2026-78678)
vulnerability in CVE-2026-78678 (CVE-2026-78678). Confidential information can be exposed externally.
|
| CVE-2026-78677 |
|
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
|
| CVE-2026-78676 |
|
Vulnerability in CVE-2026-78676 (CVE-2026-78676)
vulnerability in CVE-2026-78676 (CVE-2026-78676). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78675 |
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
| CVE-2026-76846 |
|
Vulnerability in CVE-2026-76846 (CVE-2026-76846)
vulnerability in CVE-2026-76846 (CVE-2026-76846). Confidential information can be exposed externally.
|
| CVE-2026-76839 |
|
Vulnerability in CVE-2026-76839 (CVE-2026-76839)
vulnerability in CVE-2026-76839 (CVE-2026-76839). Confidential information can be exposed externally.
|
| CVE-2026-75575 |
|
Vulnerability in CVE-2026-75575 (CVE-2026-75575)
vulnerability in CVE-2026-75575 (CVE-2026-75575). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/method.callAnon/sendForgotPasswordEmail`.
|
| CVE-2026-75574 |
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
| CVE-2026-72702 |
|
Vulnerability in CVE-2026-72702 (CVE-2026-72702)
vulnerability in CVE-2026-72702 (CVE-2026-72702). Risk of unauthorized operations or information disclosure. Exploitable via `Referer header`.
|
| CVE-2026-72701 |
|
Vulnerability in csrf (CVE-2026-72701)
vulnerability in csrf (CVE-2026-72701). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72700 |
|
Vulnerability in CVE-2026-72700 (CVE-2026-72700)
vulnerability in CVE-2026-72700 (CVE-2026-72700). Confidential information can be exposed externally.
|