Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-16009 |
|
Vulnerability in sqli (CVE-2026-16009)
vulnerability in sqli (CVE-2026-16009). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15982 |
|
Privilege Escalation in wordpress (CVE-2026-15982)
vulnerability in wordpress (CVE-2026-15982). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14503 |
|
Information Disclosure in wordpress (CVE-2026-14503)
vulnerability in wordpress (CVE-2026-14503). Confidential information can be exposed externally.
|
| CVE-2026-62237 |
|
Vulnerability in dos (CVE-2026-62237)
vulnerability in dos (CVE-2026-62237). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62230 |
|
Vulnerability in CVE-2026-62230 (CVE-2026-62230)
vulnerability in CVE-2026-62230 (CVE-2026-62230). Confidential information can be exposed externally.
|
| CVE-2026-55579 |
|
Vulnerability in pheditor/pheditor (CVE-2026-55579)
vulnerability in pheditor/pheditor (CVE-2026-55579). Successful exploitation can lead to full system takeover. Exploitable via ``admin``. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-55578 |
|
OS Command Injection in pheditor/pheditor (CVE-2026-55578)
OS command injection in pheditor/pheditor (CVE-2026-55578). Successful exploitation can lead to full system takeover. Exploitable via ``terminal``. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-54540 |
|
OS Command Injection in pheditor/pheditor (CVE-2026-54540)
OS command injection in pheditor/pheditor (CVE-2026-54540). Successful exploitation can lead to full system takeover. Exploitable via ``TERMINAL_COMMANDS``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-46513 |
|
Vulnerability in CVE-2026-46513 (CVE-2026-46513)
vulnerability in CVE-2026-46513 (CVE-2026-46513). Confidential information can be exposed externally.
|
| CVE-2026-46512 |
|
Code Injection in CVE-2026-46512 (CVE-2026-46512)
code injection in CVE-2026-46512 (CVE-2026-46512). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46514 |
|
Vulnerability in CVE-2026-46514 (CVE-2026-46514)
vulnerability in CVE-2026-46514 (CVE-2026-46514). Confidential information can be exposed externally.
|
| CVE-2026-46686 |
|
Cross-Site Scripting (XSS) in CVE-2026-46686 (CVE-2026-46686)
cross-site scripting in CVE-2026-46686 (CVE-2026-46686). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-46687 |
|
Vulnerability in CVE-2026-46687 (CVE-2026-46687)
vulnerability in CVE-2026-46687 (CVE-2026-46687). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54733 |
|
Vulnerability in CVE-2026-54733 (CVE-2026-54733)
vulnerability in CVE-2026-54733 (CVE-2026-54733). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63304 |
|
OS Command Injection in CVE-2026-63304 (CVE-2026-63304)
OS command injection in CVE-2026-63304 (CVE-2026-63304). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63305 |
|
OS Command Injection in CVE-2026-63305 (CVE-2026-63305)
OS command injection in CVE-2026-63305 (CVE-2026-63305). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59859 |
|
Code Injection in Microsoft.OpenApi.Kiota (CVE-2026-59859)
code injection in Microsoft.OpenApi.Kiota (CVE-2026-59859). Risk of unauthorized operations or information disclosure. Exploitable via ``description``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-15008 |
|
Unsafe Deserialization in wordpress (CVE-2026-15008)
vulnerability in wordpress (CVE-2026-15008). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15005 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15005)
vulnerability in wordpress (CVE-2026-15005). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15909 |
|
Vulnerability in CVE-2026-15909 (CVE-2026-15909)
vulnerability in CVE-2026-15909 (CVE-2026-15909). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54494 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54494)
SSRF in phanan/koel (CVE-2026-54494). Risk of unauthorized operations or information disclosure. Exploitable via `GET /secret`. Mitigation: upgrade to `9.7.1` or later.
|
| CVE-2026-54493 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54493)
SSRF in phanan/koel (CVE-2026-54493). Confidential information can be exposed externally. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-54492 |
|
SSRF (Server-Side Request Forgery) in phanan/koel (CVE-2026-54492)
SSRF in phanan/koel (CVE-2026-54492). Risk of unauthorized operations or information disclosure. Exploitable via ``SafeUrl``. Mitigation: upgrade to `9.7.0` or later.
|
| CVE-2026-61873 |
|
Vulnerability in path-traversal (CVE-2026-61873)
vulnerability in path-traversal (CVE-2026-61873). Data can be tampered with by attackers.
|
| CVE-2026-61457 |
|
Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
vulnerability in CVE-2026-61457 (CVE-2026-61457). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59235 |
|
Vulnerability in CVE-2026-59235 (CVE-2026-59235)
vulnerability in CVE-2026-59235 (CVE-2026-59235). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/bank-account`.
|
| CVE-2026-46627 |
|
Vulnerability in symfony (CVE-2026-46627)
vulnerability in symfony (CVE-2026-46627). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15715 |
|
Cross-Site Scripting (XSS) in CVE-2026-15715 (CVE-2026-15715)
cross-site scripting in CVE-2026-15715 (CVE-2026-15715). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15700 |
|
Path Traversal in path-traversal (CVE-2026-15700)
path traversal in path-traversal (CVE-2026-15700). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15703 |
|
Vulnerability in sqli (CVE-2026-15703)
vulnerability in sqli (CVE-2026-15703). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52840 |
|
SSRF (Server-Side Request Forgery) in alextselegidis/easyappointments (CVE-2026-52840)
SSRF in alextselegidis/easyappointments (CVE-2026-52840). Risk of unauthorized operations or information disclosure. Exploitable via ``caldav_url``.
|
| CVE-2026-52841 |
|
Vulnerability in alextselegidis/easyappointments (CVE-2026-52841)
vulnerability in alextselegidis/easyappointments (CVE-2026-52841). Risk of unauthorized operations or information disclosure. Exploitable via ``provider_id``.
|
| CVE-2026-52837 |
|
Information Disclosure in alextselegidis/easyappointments (CVE-2026-52837)
vulnerability in alextselegidis/easyappointments (CVE-2026-52837). Risk of unauthorized operations or information disclosure. Exploitable via ``appointment_hash``.
|
| CVE-2026-15678 |
|
Cross-Site Scripting (XSS) in CVE-2026-15678 (CVE-2026-15678)
cross-site scripting in CVE-2026-15678 (CVE-2026-15678). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15677 |
|
Vulnerability in CVE-2026-15677 (CVE-2026-15677)
vulnerability in CVE-2026-15677 (CVE-2026-15677). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11563 |
|
Vulnerability in wordpress (CVE-2026-11563)
vulnerability in wordpress (CVE-2026-11563). Data can be tampered with by attackers.
|
| CVE-2026-12583 |
|
Unsafe Deserialization in wordpress (CVE-2026-12583)
vulnerability in wordpress (CVE-2026-12583). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15672 |
|
Vulnerability in sqli (CVE-2026-15672)
vulnerability in sqli (CVE-2026-15672). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15676 |
|
Vulnerability in sqli (CVE-2026-15676)
vulnerability in sqli (CVE-2026-15676). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15675 |
|
Vulnerability in sqli (CVE-2026-15675)
vulnerability in sqli (CVE-2026-15675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57855 |
|
Vulnerability in CVE-2026-57855 (CVE-2026-57855)
vulnerability in CVE-2026-57855 (CVE-2026-57855). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57856 |
|
Path Traversal in path-traversal (CVE-2026-57856)
path traversal in path-traversal (CVE-2026-57856). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58411 |
|
Cross-Site Scripting (XSS) in privilege-escalation (CVE-2026-58411)
cross-site scripting in privilege-escalation (CVE-2026-58411). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15597 |
|
Vulnerability in sqli (CVE-2026-15597)
vulnerability in sqli (CVE-2026-15597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15596 |
|
Cross-Site Scripting (XSS) in CVE-2026-15596 (CVE-2026-15596)
cross-site scripting in CVE-2026-15596 (CVE-2026-15596). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12385 |
|
Information Disclosure in wordpress (CVE-2026-12385)
vulnerability in wordpress (CVE-2026-12385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15595 |
|
Cross-Site Scripting (XSS) in CVE-2026-15595 (CVE-2026-15595)
cross-site scripting in CVE-2026-15595 (CVE-2026-15595). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58409 |
|
Unrestricted File Upload in CVE-2026-58409 (CVE-2026-58409)
vulnerability in CVE-2026-58409 (CVE-2026-58409). Successful exploitation can lead to full system takeover. Exploitable via ``php``.
|
| CVE-2026-58408 |
|
Vulnerability in CVE-2026-58408 (CVE-2026-58408)
vulnerability in CVE-2026-58408 (CVE-2026-58408). Confidential information can be exposed externally. Exploitable via `POST /CSVCreateFile.php`.
|
| CVE-2026-49972 |
|
Unrestricted File Upload in laravel (CVE-2026-49972)
vulnerability in laravel (CVE-2026-49972). Successful exploitation can lead to full system takeover.
|