Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-67288 |
|
Vulnerability in CVE-2026-67288 (CVE-2026-67288)
vulnerability in CVE-2026-67288 (CVE-2026-67288). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71403 |
|
Open Redirect in CVE-2025-71403 (CVE-2025-71403)
vulnerability in CVE-2025-71403 (CVE-2025-71403). Data can be tampered with by attackers.
|
| CVE-2026-18536 |
|
Vulnerability in rrwo (CVE-2026-18536)
vulnerability in rrwo (CVE-2026-18536). Confidential information can be exposed externally.
|
| CVE-2026-16635 |
|
Privilege Escalation in wordpress (CVE-2026-16635)
vulnerability in wordpress (CVE-2026-16635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16144 |
|
Code Injection in wordpress (CVE-2026-16144)
code injection in wordpress (CVE-2026-16144). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15450 |
|
Path Traversal in wordpress (CVE-2026-15450)
path traversal in wordpress (CVE-2026-15450). Data can be tampered with by attackers.
|
| CVE-2026-15052 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15052)
cross-site scripting in wordpress (CVE-2026-15052). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15988 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15988)
vulnerability in wordpress (CVE-2026-15988). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15368 |
|
Privilege Escalation in wordpress (CVE-2026-15368)
vulnerability in wordpress (CVE-2026-15368). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15244 |
|
Path Traversal in c (CVE-2026-15244)
path traversal in c (CVE-2026-15244). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14839 |
|
Information Disclosure in wordpress (CVE-2026-14839)
vulnerability in wordpress (CVE-2026-14839). Confidential information can be exposed externally.
|
| CVE-2026-14836 |
|
Authentication Bypass in wordpress (CVE-2026-14836)
authentication bypass in wordpress (CVE-2026-14836). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14596 |
|
Authentication Bypass in wordpress (CVE-2026-14596)
authentication bypass in wordpress (CVE-2026-14596). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14309 |
|
Authentication Bypass in wordpress (CVE-2026-14309)
authentication bypass in wordpress (CVE-2026-14309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13725 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-13725)
cross-site scripting in wordpress (CVE-2026-13725). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13158 |
|
Unrestricted File Upload in wordpress (CVE-2026-13158)
vulnerability in wordpress (CVE-2026-13158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13157 |
|
Unrestricted File Upload in wordpress (CVE-2026-13157)
vulnerability in wordpress (CVE-2026-13157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15414 |
|
Privilege Escalation in wordpress (CVE-2026-15414)
vulnerability in wordpress (CVE-2026-15414). Successful exploitation can lead to full system takeover. Exploitable via ``_wps_plan_user_role``.
|
| CVE-2026-15006 |
|
Path Traversal in wordpress (CVE-2026-15006)
path traversal in wordpress (CVE-2026-15006). Confidential information can be exposed externally.
|
| CVE-2026-9044 |
|
OS Command Injection in tp-link (CVE-2026-9044)
OS command injection in tp-link (CVE-2026-9044). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34641 |
|
Out-of-Bounds Write in adobe (CVE-2026-34641)
out-of-bounds write in adobe (CVE-2026-34641). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51953 |
|
Vulnerability in CVE-2026-51953 (CVE-2026-51953)
vulnerability in CVE-2026-51953 (CVE-2026-51953). Confidential information can be exposed externally.
|
| CVE-2026-65981 |
|
Vulnerability in CVE-2026-65981 (CVE-2026-65981)
vulnerability in CVE-2026-65981 (CVE-2026-65981). Confidential information can be exposed externally.
|
| CVE-2026-50986 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-50986)
vulnerability in csrf (CVE-2026-50986). Successful exploitation can lead to full system takeover.
|
| CVE-2026-38710 |
|
Command Injection in CVE-2026-38710 (CVE-2026-38710)
command injection in CVE-2026-38710 (CVE-2026-38710). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18394 |
|
Authorization Flaw in Amazon aws (CVE-2026-18394)
vulnerability in Amazon aws (CVE-2026-18394). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-62999 |
|
Path Traversal in CVE-2026-62999 (CVE-2026-62999)
path traversal in CVE-2026-62999 (CVE-2026-62999). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53599 |
|
Unrestricted File Upload in redaxo/source (CVE-2026-53599)
vulnerability in redaxo/source (CVE-2026-53599). Successful exploitation can lead to full system takeover. Exploitable via ``shell.php.any.jpg``. Mitigation: upgrade to `5.21.1` or later.
|
| CVE-2026-53510 |
|
Code Injection in savon (CVE-2026-53510)
code injection in savon (CVE-2026-53510). Successful exploitation can lead to full system takeover. Exploitable via ``module_eval``. Mitigation: upgrade to `2.17.2` or later.
|
| CVE-2026-18420 |
|
Vulnerability in Amazon aws (CVE-2026-18420)
vulnerability in Amazon aws (CVE-2026-18420). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18481 |
|
Cross-Site Scripting (XSS) in Amazon aws (CVE-2026-18481)
cross-site scripting in Amazon aws (CVE-2026-18481). Confidential information can be exposed externally.
|
| CVE-2026-53505 |
|
Vulnerability in thumbor (CVE-2026-53505)
vulnerability in thumbor (CVE-2026-53505). Risk of unauthorized operations or information disclosure. Exploitable via ``value``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53504 |
|
Vulnerability in thumbor (CVE-2026-53504)
vulnerability in thumbor (CVE-2026-53504). Risk of unauthorized operations or information disclosure. Exploitable via ``convolution``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53503 |
|
Vulnerability in thumbor (CVE-2026-53503)
vulnerability in thumbor (CVE-2026-53503). Risk of unauthorized operations or information disclosure. Exploitable via ``columns_count``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53501 |
|
Vulnerability in thumbor (CVE-2026-53501)
vulnerability in thumbor (CVE-2026-53501). Data can be tampered with by attackers. Exploitable via ``url_to_validate``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-53500 |
|
SSRF (Server-Side Request Forgery) in thumbor (CVE-2026-53500)
SSRF in thumbor (CVE-2026-53500). Confidential information can be exposed externally. Exploitable via ``ALLOWED_SOURCES``. Mitigation: upgrade to `7.8.0` or later.
|
| CVE-2026-54737 |
|
Vulnerability in @phun-ky/defaults-deep (CVE-2026-54737)
vulnerability in @phun-ky/defaults-deep (CVE-2026-54737). Risk of unauthorized operations or information disclosure. Exploitable via ``__proto__``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-52856 |
|
Vulnerability in github.com/pterodactyl/wings (CVE-2026-52856)
vulnerability in github.com/pterodactyl/wings (CVE-2026-52856). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.13.0` or later.
|
| CVE-2026-18141 |
|
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven...
|
| CVE-2026-17347 |
|
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
|
| CVE-2026-17346 |
|
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON /...
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON /...
|
| CVE-2026-18446 |
|
Vulnerability in fast-uri (CVE-2026-18446)
vulnerability in fast-uri (CVE-2026-18446). Data can be tampered with by attackers. Exploitable via ``URL``. Mitigation: upgrade to `4.1.2` or later.
|
| CVE-2026-10685 |
|
Use-After-Free in c (CVE-2026-10685)
vulnerability in c (CVE-2026-10685). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18358 |
|
Vulnerability in CVE-2026-18358 (CVE-2026-18358)
vulnerability in CVE-2026-18358 (CVE-2026-18358). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62391 |
|
Path Traversal in apache (CVE-2026-62391)
path traversal in apache (CVE-2026-62391). Confidential information can be exposed externally.
|
| CVE-2026-16843 |
|
OS Command Injection in CVE-2026-16843 (CVE-2026-16843)
OS command injection in CVE-2026-16843 (CVE-2026-16843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15722 |
|
Vulnerability in c (CVE-2026-15722)
vulnerability in c (CVE-2026-15722). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11770 |
|
Vulnerability in redhat (CVE-2026-11770)
vulnerability in redhat (CVE-2026-11770). Confidential information can be exposed externally.
|
| CVE-2026-10079 |
|
Vulnerability in CVE-2026-10079 (CVE-2026-10079)
vulnerability in CVE-2026-10079 (CVE-2026-10079). Data can be tampered with by attackers.
|
| CVE-2026-65313 |
|
Vulnerability in CVE-2026-65313 (CVE-2026-65313)
vulnerability in CVE-2026-65313 (CVE-2026-65313). Confidential information can be exposed externally.
|