Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-42017 Information Disclosure in jfrog (CVE-2026-42017)
vulnerability in jfrog (CVE-2026-42017). Successful exploitation can lead to full system takeover.
CVE-2026-56748 Vulnerability in cribl (CVE-2026-56748)
vulnerability in cribl (CVE-2026-56748). Successful exploitation can lead to full system takeover.
CVE-2026-42016 Authorization Flaw in privilege-escalation (CVE-2026-42016)
vulnerability in privilege-escalation (CVE-2026-42016). Confidential information can be exposed externally.
CVE-2026-56747 Code Injection in cribl (CVE-2026-56747)
code injection in cribl (CVE-2026-56747). Successful exploitation can lead to full system takeover.
CVE-2026-66758 Vulnerability in dos (CVE-2026-66758)
vulnerability in dos (CVE-2026-66758). Successful exploitation can lead to full system takeover.
CVE-2026-12383 Vulnerability in CVE-2026-12383 (CVE-2026-12383)
vulnerability in CVE-2026-12383 (CVE-2026-12383). Data can be tampered with by attackers.
CVE-2026-51244 Vulnerability in CVE-2026-51244 (CVE-2026-51244)
vulnerability in CVE-2026-51244 (CVE-2026-51244). Risk of unauthorized operations or information disclosure.
CVE-2026-51235 Vulnerability in cpp (CVE-2026-51235)
vulnerability in cpp (CVE-2026-51235). Successful exploitation can lead to full system takeover.
CVE-2026-17568 Authorization Flaw in devolutions (CVE-2026-17568)
vulnerability in devolutions (CVE-2026-17568). Successful exploitation can lead to full system takeover.
CVE-2026-24252 OS Command Injection in CVE-2026-24252 (CVE-2026-24252)
OS command injection in CVE-2026-24252 (CVE-2026-24252). Successful exploitation can lead to full system takeover.
CVE-2026-66394 Cross-Site Scripting (XSS) in CVE-2026-66394 (CVE-2026-66394)
cross-site scripting in CVE-2026-66394 (CVE-2026-66394). Confidential information can be exposed externally.
CVE-2026-66730 Vulnerability in CVE-2026-66730 (CVE-2026-66730)
vulnerability in CVE-2026-66730 (CVE-2026-66730). Risk of unauthorized operations or information disclosure.
CVE-2026-66731 Out-of-Bounds Read in CVE-2026-66731 (CVE-2026-66731)
vulnerability in CVE-2026-66731 (CVE-2026-66731). Risk of unauthorized operations or information disclosure.
CVE-2026-17192 SSRF (Server-Side Request Forgery) in CVE-2026-17192 (CVE-2026-17192)
SSRF in CVE-2026-17192 (CVE-2026-17192). Confidential information can be exposed externally.
CVE-2026-66729 Out-of-Bounds Read in CVE-2026-66729 (CVE-2026-66729)
vulnerability in CVE-2026-66729 (CVE-2026-66729). Risk of unauthorized operations or information disclosure.
CVE-2026-66396 Cross-Site Scripting (XSS) in CVE-2026-66396 (CVE-2026-66396)
cross-site scripting in CVE-2026-66396 (CVE-2026-66396). Successful exploitation can lead to full system takeover.
CVE-2026-51304 Use-After-Free in dos (CVE-2026-51304)
vulnerability in dos (CVE-2026-51304). Risk of unauthorized operations or information disclosure.
CVE-2026-51296 Use-After-Free in sqlite (CVE-2026-51296)
vulnerability in sqlite (CVE-2026-51296). Risk of unauthorized operations or information disclosure.
CVE-2026-51297 Use-After-Free in sqlite (CVE-2026-51297)
vulnerability in sqlite (CVE-2026-51297). Successful exploitation can lead to full system takeover.
CVE-2026-51302 Use-After-Free in dos (CVE-2026-51302)
vulnerability in dos (CVE-2026-51302). Successful exploitation can lead to full system takeover.
CVE-2026-59251 Vulnerability in c (CVE-2026-59251)
vulnerability in c (CVE-2026-59251). Risk of unauthorized operations or information disclosure.
CVE-2026-58227 Vulnerability in erlang (CVE-2026-58227)
vulnerability in erlang (CVE-2026-58227). Risk of unauthorized operations or information disclosure.
CVE-2026-55953 Vulnerability in erlang (CVE-2026-55953)
vulnerability in erlang (CVE-2026-55953). Confidential information can be exposed externally.
CVE-2026-55737 Vulnerability in c (CVE-2026-55737)
vulnerability in c (CVE-2026-55737). Risk of unauthorized operations or information disclosure.
CVE-2026-54890 Vulnerability in c (CVE-2026-54890)
vulnerability in c (CVE-2026-54890). Risk of unauthorized operations or information disclosure.
CVE-2026-42792 Vulnerability in c (CVE-2026-42792)
vulnerability in c (CVE-2026-42792). Risk of unauthorized operations or information disclosure.
CVE-2026-66050 Path Traversal in path-traversal (CVE-2026-66050)
path traversal in path-traversal (CVE-2026-66050). Data can be tampered with by attackers.
CVE-2026-66427 Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
CVE-2026-59558 Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
CVE-2026-59552 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-59552)
SSRF in ssrf (CVE-2026-59552). Risk of unauthorized operations or information disclosure.
CVE-2026-59536 Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
CVE-2026-59548 Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
CVE-2026-59556 Cross-Site Scripting (XSS) in CVE-2026-59556 (CVE-2026-59556)
cross-site scripting in CVE-2026-59556 (CVE-2026-59556). Risk of unauthorized operations or information disclosure.
CVE-2026-59551 Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
CVE-2026-59537 SQL Injection in sqli (CVE-2026-59537)
SQL injection in sqli (CVE-2026-59537). Confidential information can be exposed externally.
CVE-2026-59553 Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
CVE-2026-59546 Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
CVE-2026-59535 Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
CVE-2026-59539 Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
CVE-2026-59532 Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
CVE-2026-59534 Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
CVE-2026-59531 Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
CVE-2026-59529 Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-59530 Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
CVE-2026-59528 Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
CVE-2026-59690 Vulnerability in progress (CVE-2026-59690)
vulnerability in progress (CVE-2026-59690). Successful exploitation can lead to full system takeover.
CVE-2026-59688 OS Command Injection in progress (CVE-2026-59688)
OS command injection in progress (CVE-2026-59688). Successful exploitation can lead to full system takeover.
CVE-2026-59687 OS Command Injection in progress (CVE-2026-59687)
OS command injection in progress (CVE-2026-59687). Successful exploitation can lead to full system takeover.
CVE-2026-59689 Authorization Flaw in progress (CVE-2026-59689)
vulnerability in progress (CVE-2026-59689). Successful exploitation can lead to full system takeover.
CVE-2026-59686 OS Command Injection in progress (CVE-2026-59686)
OS command injection in progress (CVE-2026-59686). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →