Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-25703 Vulnerability in CVE-2026-25703 (CVE-2026-25703)
vulnerability in CVE-2026-25703 (CVE-2026-25703). Risk of unauthorized operations or information disclosure.
CVE-2026-7693 Command Injection in wordpress (CVE-2026-7693)
command injection in wordpress (CVE-2026-7693). Successful exploitation can lead to full system takeover. Exploitable via ``file``.
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-71215 art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
CVE-2026-71211 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71211)
SSRF in ssrf (CVE-2026-71211). Confidential information can be exposed externally.
CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
CVE-2026-71206 Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
CVE-2026-71202 Vulnerability in CVE-2026-71202 (CVE-2026-71202)
vulnerability in CVE-2026-71202 (CVE-2026-71202). Risk of unauthorized operations or information disclosure.
CVE-2026-70378 Vulnerability in CVE-2026-70378 (CVE-2026-70378)
vulnerability in CVE-2026-70378 (CVE-2026-70378). Risk of unauthorized operations or information disclosure. Exploitable via ``scale``.
CVE-2026-70377 Vulnerability in CVE-2026-70377 (CVE-2026-70377)
vulnerability in CVE-2026-70377 (CVE-2026-70377). Risk of unauthorized operations or information disclosure.
CVE-2026-6639 Vulnerability in wordpress (CVE-2026-6639)
vulnerability in wordpress (CVE-2026-6639). Confidential information can be exposed externally. Exploitable via ``wp_ajax_nopriv_``.
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-6079 Vulnerability in wordpress (CVE-2026-6079)
vulnerability in wordpress (CVE-2026-6079). Risk of unauthorized operations or information disclosure.
CVE-2026-6020 Vulnerability in wordpress (CVE-2026-6020)
vulnerability in wordpress (CVE-2026-6020). Successful exploitation can lead to full system takeover.
CVE-2026-64581 Vulnerability in c (CVE-2026-64581)
vulnerability in c (CVE-2026-64581). Successful exploitation can lead to full system takeover.
CVE-2026-64580 Vulnerability in c (CVE-2026-64580)
vulnerability in c (CVE-2026-64580). Successful exploitation can lead to full system takeover.
CVE-2026-64578 Vulnerability in c (CVE-2026-64578)
vulnerability in c (CVE-2026-64578). Risk of unauthorized operations or information disclosure.
CVE-2026-64577 Vulnerability in c (CVE-2026-64577)
vulnerability in c (CVE-2026-64577). Risk of unauthorized operations or information disclosure.
CVE-2026-64576 Vulnerability in c (CVE-2026-64576)
vulnerability in c (CVE-2026-64576). Confidential information can be exposed externally.
CVE-2026-64575 Vulnerability in c (CVE-2026-64575)
vulnerability in c (CVE-2026-64575). Successful exploitation can lead to full system takeover.
CVE-2026-64574 Vulnerability in c (CVE-2026-64574)
vulnerability in c (CVE-2026-64574). Successful exploitation can lead to full system takeover.
CVE-2026-64570 Vulnerability in c (CVE-2026-64570)
vulnerability in c (CVE-2026-64570). Successful exploitation can lead to full system takeover.
CVE-2026-64568 Vulnerability in c (CVE-2026-64568)
vulnerability in c (CVE-2026-64568). Successful exploitation can lead to full system takeover.
CVE-2026-64567 Vulnerability in c (CVE-2026-64567)
vulnerability in c (CVE-2026-64567). Successful exploitation can lead to full system takeover.
CVE-2026-61485 Vulnerability in apache (CVE-2026-61485)
vulnerability in apache (CVE-2026-61485). Risk of unauthorized operations or information disclosure.
CVE-2026-61483 Vulnerability in apache (CVE-2026-61483)
vulnerability in apache (CVE-2026-61483). Risk of unauthorized operations or information disclosure.
CVE-2026-59675 Vulnerability in CVE-2026-59675 (CVE-2026-59675)
vulnerability in CVE-2026-59675 (CVE-2026-59675). Risk of unauthorized operations or information disclosure.
CVE-2026-55997 Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
CVE-2026-55739 Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
CVE-2026-54418 Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
CVE-2026-54416 Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
vulnerability in CVE-2026-54416 (CVE-2026-54416). Successful exploitation can lead to full system takeover.
CVE-2026-18881 SQL Injection in wordpress (CVE-2026-18881)
SQL injection in wordpress (CVE-2026-18881). Confidential information can be exposed externally. Exploitable via ``tableon_get_table_data``.
CVE-2026-12000 Vulnerability in wordpress (CVE-2026-12000)
vulnerability in wordpress (CVE-2026-12000). Confidential information can be exposed externally.
CVE-2026-70375 OS Command Injection in CVE-2026-70375 (CVE-2026-70375)
OS command injection in CVE-2026-70375 (CVE-2026-70375). Successful exploitation can lead to full system takeover.
CVE-2026-70374 OS Command Injection in CVE-2026-70374 (CVE-2026-70374)
OS command injection in CVE-2026-70374 (CVE-2026-70374). Successful exploitation can lead to full system takeover. Exploitable via `POST /api/{project}/{environment}/media/new.`.
CVE-2026-68073 Vulnerability in apache (CVE-2026-68073)
vulnerability in apache (CVE-2026-68073). Risk of unauthorized operations or information disclosure.
CVE-2026-67592 Vulnerability in apache (CVE-2026-67592)
vulnerability in apache (CVE-2026-67592). Risk of unauthorized operations or information disclosure.
CVE-2026-67590 Vulnerability in apache (CVE-2026-67590)
vulnerability in apache (CVE-2026-67590). Risk of unauthorized operations or information disclosure.
CVE-2026-67552 Vulnerability in apache (CVE-2026-67552)
vulnerability in apache (CVE-2026-67552). Risk of unauthorized operations or information disclosure.
CVE-2026-66274 Vulnerability in apache (CVE-2026-66274)
vulnerability in apache (CVE-2026-66274). Risk of unauthorized operations or information disclosure.
CVE-2026-16736 Vulnerability in wordpress (CVE-2026-16736)
vulnerability in wordpress (CVE-2026-16736). Confidential information can be exposed externally.
CVE-2026-16605 Vulnerability in wordpress (CVE-2026-16605)
vulnerability in wordpress (CVE-2026-16605). Successful exploitation can lead to full system takeover.
CVE-2026-16604 Information Disclosure in wordpress (CVE-2026-16604)
vulnerability in wordpress (CVE-2026-16604). Confidential information can be exposed externally.
CVE-2026-16603 Information Disclosure in wordpress (CVE-2026-16603)
vulnerability in wordpress (CVE-2026-16603). Confidential information can be exposed externally.
CVE-2026-16602 Information Disclosure in wordpress (CVE-2026-16602)
vulnerability in wordpress (CVE-2026-16602). Confidential information can be exposed externally.
CVE-2026-16573 Cross-Site Scripting (XSS) in wordpress (CVE-2026-16573)
cross-site scripting in wordpress (CVE-2026-16573). Successful exploitation can lead to full system takeover.
CVE-2026-16561 Vulnerability in wordpress (CVE-2026-16561)
vulnerability in wordpress (CVE-2026-16561). Confidential information can be exposed externally.
CVE-2026-16055 Authentication Bypass in wordpress (CVE-2026-16055)
authentication bypass in wordpress (CVE-2026-16055). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →