Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-56010 Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
CVE-2026-57926 Vulnerability in jetbrains (CVE-2026-57926)
vulnerability in jetbrains (CVE-2026-57926). Risk of unauthorized operations or information disclosure.
CVE-2026-30040 Vulnerability in CVE-2026-30040 (CVE-2026-30040)
vulnerability in CVE-2026-30040 (CVE-2026-30040). Risk of unauthorized operations or information disclosure.
CVE-2026-24547 Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
CVE-2025-68063 Vulnerability in wordpress (CVE-2025-68063)
vulnerability in wordpress (CVE-2025-68063). Successful exploitation can lead to full system takeover.
CVE-2025-68075 Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.
Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.
CVE-2026-57940 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-57940)
SSRF in ssrf (CVE-2026-57940). Risk of unauthorized operations or information disclosure.
CVE-2025-68074 Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.
CVE-2025-68052 Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
CVE-2025-64636 Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
CVE-2025-66123 Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
CVE-2025-63041 Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
CVE-2025-68064 Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
CVE-2025-63079 Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
CVE-2025-63078 Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
CVE-2026-53914 Unsafe Deserialization in org.jetbrains.kotlin:kotlin-gradle-plugin (CVE-2026-53914)
vulnerability in org.jetbrains.kotlin:kotlin-gradle-plugin (CVE-2026-53914). Confidential information can be exposed externally. Mitigation: upgrade to `2.4.20-Beta1` or later.
CVE-2026-57923 Vulnerability in jetbrains (CVE-2026-57923)
vulnerability in jetbrains (CVE-2026-57923). Data can be tampered with by attackers.
CVE-2026-57925 Vulnerability in jetbrains (CVE-2026-57925)
vulnerability in jetbrains (CVE-2026-57925). Risk of unauthorized operations or information disclosure.
CVE-2026-13426 Path Traversal in c (CVE-2026-13426)
path traversal in c (CVE-2026-13426). Risk of unauthorized operations or information disclosure.
CVE-2025-55017 Path Traversal in apache (CVE-2025-55017)
path traversal in apache (CVE-2025-55017). Confidential information can be exposed externally.
CVE-2025-64152 Path Traversal in apache (CVE-2025-64152)
path traversal in apache (CVE-2025-64152). Confidential information can be exposed externally.
CVE-2026-57920 Vulnerability in peplink (CVE-2026-57920)
vulnerability in peplink (CVE-2026-57920). Confidential information can be exposed externally.
CVE-2026-57915 Vulnerability in apache (CVE-2026-57915)
vulnerability in apache (CVE-2026-57915). Risk of unauthorized operations or information disclosure.
CVE-2026-57924 Vulnerability in jetbrains (CVE-2026-57924)
vulnerability in jetbrains (CVE-2026-57924). Risk of unauthorized operations or information disclosure.
CVE-2026-40711 OS Command Injection in CVE-2026-40711 (CVE-2026-40711)
OS command injection in CVE-2026-40711 (CVE-2026-40711). Successful exploitation can lead to full system takeover.
CVE-2026-57922 In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
CVE-2026-57921 Vulnerability in jetbrains (CVE-2026-57921)
vulnerability in jetbrains (CVE-2026-57921). Risk of unauthorized operations or information disclosure.
CVE-2026-45257 Vulnerability in freebsd (CVE-2026-45257)
vulnerability in freebsd (CVE-2026-45257). Successful exploitation can lead to full system takeover.
CGA-v3w7-3995-rc8x CGA-v3w7-3995-rc8x
CGA-76ww-cr8v-ffww CGA-76ww-cr8v-ffww
CGA-hmmj-rjm7-wx8w CGA-hmmj-rjm7-wx8w
MAL-2026-6521 Vulnerability in @carvana.authentication-flows/shared (MAL-2026-6521)
vulnerability in @carvana.authentication-flows/shared (MAL-2026-6521). Risk of unauthorized operations or information disclosure. Exploitable via ``whoami``.
MAL-2026-6523 Vulnerability in express-plugin (MAL-2026-6523)
vulnerability in express-plugin (MAL-2026-6523). Risk of unauthorized operations or information disclosure. Exploitable via ``cookie``.
CGA-j4v7-hwx9-qh36 CGA-j4v7-hwx9-qh36
PYSEC-2026-235 Vulnerability in ppkt2synergy (PYSEC-2026-235)
vulnerability in ppkt2synergy (PYSEC-2026-235). Risk of unauthorized operations or information disclosure.
PYSEC-2026-234 Vulnerability in phenopacket-store-toolkit (PYSEC-2026-234)
vulnerability in phenopacket-store-toolkit (PYSEC-2026-234). Risk of unauthorized operations or information disclosure.
GHSA-mjcv-m7fg-mg8j Vulnerability in ts-einkle (GHSA-mjcv-m7fg-mg8j)
vulnerability in ts-einkle (GHSA-mjcv-m7fg-mg8j). Risk of unauthorized operations or information disclosure. Exploitable via ``packProjectBundle``.
GHSA-8cxx-rp6g-mcr9 Vulnerability in ts-einkle-slot (GHSA-8cxx-rp6g-mcr9)
vulnerability in ts-einkle-slot (GHSA-8cxx-rp6g-mcr9). Risk of unauthorized operations or information disclosure. Exploitable via ``big.js``.
GHSA-x7jg-w433-8q2r Vulnerability in @epsteinlovekids483/crossmint-wallets-sdk-pentest (GHSA-x7jg-w433-8q2r)
vulnerability in @epsteinlovekids483/crossmint-wallets-sdk-pentest (GHSA-x7jg-w433-8q2r). Risk of unauthorized operations or information disclosure.
SUSE-SU-2026:2667-1 Vulnerability in giflib (SUSE-SU-2026:2667-1)
vulnerability in giflib (SUSE-SU-2026:2667-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.0.6-13.15.1` or later.
SUSE-SU-2026:2666-1 Vulnerability in giflib (SUSE-SU-2026:2666-1)
vulnerability in giflib (SUSE-SU-2026:2666-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.2.2-150000.4.22.1` or later.
SUSE-SU-2026:2665-1 Vulnerability in google-osconfig-agent (SUSE-SU-2026:2665-1)
vulnerability in google-osconfig-agent (SUSE-SU-2026:2665-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `20260615.01-1.47.1` or later.
SUSE-SU-2026:2664-1 Vulnerability in python (SUSE-SU-2026:2664-1)
vulnerability in python (SUSE-SU-2026:2664-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.7.18-33.79.1` or later.
SUSE-SU-2026:2663-1 Vulnerability in exiv2 (SUSE-SU-2026:2663-1)
vulnerability in exiv2 (SUSE-SU-2026:2663-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.23-12.26.1` or later.
SUSE-SU-2026:2662-1 Vulnerability in openssl-3-livepatches (SUSE-SU-2026:2662-1)
vulnerability in openssl-3-livepatches (SUSE-SU-2026:2662-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.4-150700.16.6.1` or later.
MINI-rg5h-rcv4-39rx MINI-rg5h-rcv4-39rx
MINI-8hm4-jrc4-3cff MINI-8hm4-jrc4-3cff
MINI-j5xg-3hqq-jpgm MINI-j5xg-3hqq-jpgm
MINI-5c6x-833f-cvh8 MINI-5c6x-833f-cvh8
MINI-2hf8-pw34-h5jp MINI-2hf8-pw34-h5jp

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →