Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-72699 Vulnerability in CVE-2026-72699 (CVE-2026-72699)
vulnerability in CVE-2026-72699 (CVE-2026-72699). Risk of unauthorized operations or information disclosure.
CVE-2026-72698 Information Disclosure in CVE-2026-72698 (CVE-2026-72698)
vulnerability in CVE-2026-72698 (CVE-2026-72698). Confidential information can be exposed externally.
CVE-2026-72697 Path Traversal in path-traversal (CVE-2026-72697)
path traversal in path-traversal (CVE-2026-72697). Confidential information can be exposed externally.
CVE-2026-72696 Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
CVE-2026-72695 Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
CVE-2026-56710 Authorization Flaw in CVE-2026-56710 (CVE-2026-56710)
vulnerability in CVE-2026-56710 (CVE-2026-56710). Successful exploitation can lead to full system takeover.
CVE-2026-56709 Vulnerability in CVE-2026-56709 (CVE-2026-56709)
vulnerability in CVE-2026-56709 (CVE-2026-56709). Confidential information can be exposed externally. Exploitable via `Host header`.
CVE-2026-56708 Vulnerability in CVE-2026-56708 (CVE-2026-56708)
vulnerability in CVE-2026-56708 (CVE-2026-56708). Risk of unauthorized operations or information disclosure.
CVE-2026-56707 Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
CVE-2026-56706 Vulnerability in csrf (CVE-2026-56706)
vulnerability in csrf (CVE-2026-56706). Data can be tampered with by attackers.
CVE-2026-56705 Vulnerability in CVE-2026-56705 (CVE-2026-56705)
vulnerability in CVE-2026-56705 (CVE-2026-56705). Successful exploitation can lead to full system takeover.
CVE-2026-56704 Cross-Site Scripting (XSS) in CVE-2026-56704 (CVE-2026-56704)
cross-site scripting in CVE-2026-56704 (CVE-2026-56704). Risk of unauthorized operations or information disclosure.
CVE-2026-56703 Code Injection in CVE-2026-56703 (CVE-2026-56703)
code injection in CVE-2026-56703 (CVE-2026-56703). Successful exploitation can lead to full system takeover.
CVE-2026-56702 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
CVE-2026-34968 Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
CVE-2026-34967 Vulnerability in path-traversal (CVE-2026-34967)
vulnerability in path-traversal (CVE-2026-34967). Risk of unauthorized operations or information disclosure.
CVE-2026-34964 SSRF (Server-Side Request Forgery) in CVE-2026-34964 (CVE-2026-34964)
SSRF in CVE-2026-34964 (CVE-2026-34964). Risk of unauthorized operations or information disclosure.
CVE-2026-34959 Vulnerability in CVE-2026-34959 (CVE-2026-34959)
vulnerability in CVE-2026-34959 (CVE-2026-34959). Risk of unauthorized operations or information disclosure.
CVE-2026-19801 Vulnerability in wordpress (CVE-2026-19801)
vulnerability in wordpress (CVE-2026-19801). Risk of unauthorized operations or information disclosure.
CVE-2026-16434 Vulnerability in CVE-2026-16434 (CVE-2026-16434)
vulnerability in CVE-2026-16434 (CVE-2026-16434). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.5.1` or later.
CVE-2026-15023 SQL Injection in wordpress (CVE-2026-15023)
SQL injection in wordpress (CVE-2026-15023). Confidential information can be exposed externally.
CVE-2026-10630 Vulnerability in wordpress (CVE-2026-10630)
vulnerability in wordpress (CVE-2026-10630). Risk of unauthorized operations or information disclosure.
CVE-2026-66766 Vulnerability in dos (CVE-2026-66766)
vulnerability in dos (CVE-2026-66766). Risk of unauthorized operations or information disclosure.
CVE-2026-59183 Vulnerability in CVE-2026-59183 (CVE-2026-59183)
vulnerability in CVE-2026-59183 (CVE-2026-59183). Risk of unauthorized operations or information disclosure.
CVE-2026-55373 Vulnerability in CVE-2026-55373 (CVE-2026-55373)
vulnerability in CVE-2026-55373 (CVE-2026-55373). Risk of unauthorized operations or information disclosure.
CVE-2026-55371 Vulnerability in c (CVE-2026-55371)
vulnerability in c (CVE-2026-55371). Risk of unauthorized operations or information disclosure.
CVE-2026-55059 Out-of-Bounds Write in CVE-2026-55059 (CVE-2026-55059)
out-of-bounds write in CVE-2026-55059 (CVE-2026-55059). Risk of unauthorized operations or information disclosure.
CVE-2026-54920 Vulnerability in dos (CVE-2026-54920)
vulnerability in dos (CVE-2026-54920). Risk of unauthorized operations or information disclosure.
CVE-2026-60004 KEV [KEV] Code Injection in gitea (CVE-2026-60004)
code injection in gitea (CVE-2026-60004). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-53532 Vulnerability in dos (CVE-2026-53532)
vulnerability in dos (CVE-2026-53532). Risk of unauthorized operations or information disclosure.
CVE-2026-78435 Path Traversal in path-traversal (CVE-2026-78435)
path traversal in path-traversal (CVE-2026-78435). Risk of unauthorized operations or information disclosure.
CVE-2026-78434 Authentication Bypass in CVE-2026-78434 (CVE-2026-78434)
authentication bypass in CVE-2026-78434 (CVE-2026-78434). Risk of unauthorized operations or information disclosure.
CVE-2026-78284 Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
CVE-2026-78282 Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
CVE-2026-78268 Vulnerability in CVE-2026-78268 (CVE-2026-78268)
vulnerability in CVE-2026-78268 (CVE-2026-78268). Confidential information can be exposed externally.
CVE-2026-78267 Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
CVE-2026-78266 Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
CVE-2026-78265 Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
CVE-2026-78264 Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
CVE-2026-78263 Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
CVE-2026-78262 Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
CVE-2026-78259 Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
CVE-2026-77384 Vulnerability in dos (CVE-2026-77384)
vulnerability in dos (CVE-2026-77384). Risk of unauthorized operations or information disclosure.
CVE-2026-77337 Vulnerability in CVE-2026-77337 (CVE-2026-77337)
vulnerability in CVE-2026-77337 (CVE-2026-77337). Risk of unauthorized operations or information disclosure.
CVE-2026-68516 Vulnerability in dos (CVE-2026-68516)
vulnerability in dos (CVE-2026-68516). Risk of unauthorized operations or information disclosure.
CVE-2026-32563 Unsafe Deserialization in wordpress (CVE-2026-32563)
vulnerability in wordpress (CVE-2026-32563). Successful exploitation can lead to full system takeover.
CVE-2026-32561 Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
CVE-2026-32560 Vulnerability in wordpress (CVE-2026-32560)
vulnerability in wordpress (CVE-2026-32560). Successful exploitation can lead to full system takeover.
CVE-2026-32559 Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
CVE-2026-32556 Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →