Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-13039 |
|
Vulnerability in wordpress (CVE-2026-13039)
vulnerability in wordpress (CVE-2026-13039). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54159 |
|
Vulnerability in prestashop/ps_facetedsearch (CVE-2026-54159)
vulnerability in prestashop/ps_facetedsearch (CVE-2026-54159). Successful exploitation can lead to full system takeover. Exploitable via ``ps_facetedsearch``. Mitigation: upgrade to `4.0.4` or later.
|
| CVE-2026-55481 |
|
Cross-Site Scripting (XSS) in snipe/snipe-it (CVE-2026-55481)
cross-site scripting in snipe/snipe-it (CVE-2026-55481). Risk of unauthorized operations or information disclosure. Exploitable via ``default.blade.php``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2026-55466 |
|
Cross-Site Scripting (XSS) in snipe/snipe-it (CVE-2026-55466)
cross-site scripting in snipe/snipe-it (CVE-2026-55466). Confidential information can be exposed externally. Exploitable via ``mimes``. Mitigation: upgrade to `8.6.2` or later.
|
| CVE-2025-30008 |
|
Cross-Site Scripting (XSS) in hestiacp (CVE-2025-30008)
cross-site scripting in hestiacp (CVE-2025-30008). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39903 |
|
Authorization Flaw in CVE-2026-39903 (CVE-2026-39903)
vulnerability in CVE-2026-39903 (CVE-2026-39903). Data can be tampered with by attackers.
|
| CVE-2026-61450 |
|
Code Injection in CVE-2026-61450 (CVE-2026-61450)
code injection in CVE-2026-61450 (CVE-2026-61450). Confidential information can be exposed externally.
|
| CVE-2026-57961 |
|
Path Traversal in path-traversal (CVE-2026-57961)
path traversal in path-traversal (CVE-2026-57961). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-11977 |
|
Vulnerability in wordpress (CVE-2025-11977)
vulnerability in wordpress (CVE-2025-11977). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15299 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15299)
cross-site scripting in wordpress (CVE-2026-15299). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15300 |
|
SQL Injection in wordpress (CVE-2026-15300)
SQL injection in wordpress (CVE-2026-15300). Data can be tampered with by attackers. Mitigation: upgrade to `4.5.5` or later.
|
| CVE-2026-15285 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15285)
cross-site scripting in wordpress (CVE-2026-15285). Risk of unauthorized operations or information disclosure. Exploitable via ``custom_attributes``.
|
| CVE-2026-13430 |
|
Unrestricted File Upload in wordpress (CVE-2026-13430)
vulnerability in wordpress (CVE-2026-13430). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15070 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-15070)
vulnerability in wordpress (CVE-2026-15070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59856 |
|
Code Injection in vim (CVE-2026-59856)
code injection in vim (CVE-2026-59856). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58143 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-58143)
vulnerability in csrf (CVE-2026-58143). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58144 |
|
Cross-Site Scripting (XSS) in CVE-2026-58144 (CVE-2026-58144)
cross-site scripting in CVE-2026-58144 (CVE-2026-58144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51926 |
|
Vulnerability in CVE-2026-51926 (CVE-2026-51926)
vulnerability in CVE-2026-51926 (CVE-2026-51926). Confidential information can be exposed externally.
|
| CVE-2026-51925 |
|
Vulnerability in CVE-2026-51925 (CVE-2026-51925)
vulnerability in CVE-2026-51925 (CVE-2026-51925). Confidential information can be exposed externally.
|
| CVE-2026-51924 |
|
Vulnerability in CVE-2026-51924 (CVE-2026-51924)
vulnerability in CVE-2026-51924 (CVE-2026-51924). Confidential information can be exposed externally.
|
| CVE-2026-60120 |
|
Cross-Site Scripting (XSS) in vue (CVE-2026-60120)
cross-site scripting in vue (CVE-2026-60120). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55212 |
|
Vulnerability in pimcore/studio-backend-bundle (CVE-2026-55212)
vulnerability in pimcore/studio-backend-bundle (CVE-2026-55212). Data can be tampered with by attackers. Exploitable via `POST /pimcore-studio/api/class/definition/configuration-view/detail/create`. Mitigation: upgrade to `2026.1.6` or later.
|
| CVE-2026-15202 |
|
Cross-Site Scripting (XSS) in CVE-2026-15202 (CVE-2026-15202)
cross-site scripting in CVE-2026-15202 (CVE-2026-15202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15190 |
|
Vulnerability in sqli (CVE-2026-15190)
vulnerability in sqli (CVE-2026-15190). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15191 |
|
Vulnerability in CVE-2026-15191 (CVE-2026-15191)
vulnerability in CVE-2026-15191 (CVE-2026-15191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59734 |
|
OS Command Injection in CVE-2026-59734 (CVE-2026-59734)
OS command injection in CVE-2026-59734 (CVE-2026-59734). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12116 |
|
Vulnerability in CVE-2026-12116 (CVE-2026-12116)
vulnerability in CVE-2026-12116 (CVE-2026-12116). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15158 |
|
Unrestricted File Upload in wordpress (CVE-2026-15158)
vulnerability in wordpress (CVE-2026-15158). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13080 |
|
Vulnerability in wordpress (CVE-2026-13080)
vulnerability in wordpress (CVE-2026-13080). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15137 |
|
Vulnerability in sqli (CVE-2026-15137)
vulnerability in sqli (CVE-2026-15137). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15135 |
|
Vulnerability in sqli (CVE-2026-15135)
vulnerability in sqli (CVE-2026-15135). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15134 |
|
Vulnerability in sqli (CVE-2026-15134)
vulnerability in sqli (CVE-2026-15134). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59946 |
|
Path Traversal in composer/composer (CVE-2026-59946)
path traversal in composer/composer (CVE-2026-59946). Confidential information can be exposed externally. Exploitable via ``bin``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59947 |
|
Vulnerability in composer/composer (CVE-2026-59947)
vulnerability in composer/composer (CVE-2026-59947). Confidential information can be exposed externally. Exploitable via ``repositories``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59948 |
|
Path Traversal in composer/composer (CVE-2026-59948)
path traversal in composer/composer (CVE-2026-59948). Successful exploitation can lead to full system takeover. Exploitable via ``install``. Mitigation: upgrade to `2.2.29` or later.
|
| CVE-2026-59882 |
|
Vulnerability in guzzlehttp/psr7 (CVE-2026-59882)
vulnerability in guzzlehttp/psr7 (CVE-2026-59882). Risk of unauthorized operations or information disclosure. Exploitable via ``SERVER_NAME``. Mitigation: upgrade to `2.12.3` or later.
|
| CVE-2026-59883 |
|
Information Disclosure in guzzlehttp/guzzle (CVE-2026-59883)
vulnerability in guzzlehttp/guzzle (CVE-2026-59883). Risk of unauthorized operations or information disclosure. Exploitable via ``CookieJar``. Mitigation: upgrade to `7.12.3` or later.
|
| CVE-2026-60092 |
|
Cross-Site Scripting (XSS) in CVE-2026-60092 (CVE-2026-60092)
cross-site scripting in CVE-2026-60092 (CVE-2026-60092). Risk of unauthorized operations or information disclosure. Exploitable via `User-Agent header`.
|
| CVE-2026-58654 |
|
Unrestricted File Upload in path-traversal (CVE-2026-58654)
vulnerability in path-traversal (CVE-2026-58654). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.0.1` or later.
|
| CVE-2026-58480 |
|
Unrestricted File Upload in wordpress (CVE-2026-58480)
vulnerability in wordpress (CVE-2026-58480). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12378 |
|
Vulnerability in wordpress (CVE-2026-12378)
vulnerability in wordpress (CVE-2026-12378). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9701 |
|
Vulnerability in wordpress (CVE-2026-9701)
vulnerability in wordpress (CVE-2026-9701). Successful exploitation can lead to full system takeover. Exploitable via ``eventer_verification_code``.
|
| CVE-2026-14487 |
|
Path Traversal in wordpress (CVE-2026-14487)
path traversal in wordpress (CVE-2026-14487). Data can be tampered with by attackers.
|
| CVE-2026-23698 |
|
Unrestricted File Upload in apache (CVE-2026-23698)
vulnerability in apache (CVE-2026-23698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23697 |
|
Unrestricted File Upload in apache (CVE-2026-23697)
vulnerability in apache (CVE-2026-23697). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6101 |
|
Vulnerability in wordpress (CVE-2026-6101)
vulnerability in wordpress (CVE-2026-6101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40187 |
|
OS Command Injection in egroupware/egroupware (CVE-2026-40187)
OS command injection in egroupware/egroupware (CVE-2026-40187). Risk of unauthorized operations or information disclosure. Exploitable via ``chgrp``. Mitigation: upgrade to `23.1.20260601` or later.
|
| CVE-2026-12277 |
|
Vulnerability in wordpress (CVE-2026-12277)
vulnerability in wordpress (CVE-2026-12277). Data can be tampered with by attackers.
|
| CVE-2026-14345 |
|
Unrestricted File Upload in wordpress (CVE-2026-14345)
vulnerability in wordpress (CVE-2026-14345). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42200 |
|
Path Traversal in CVE-2026-42200 (CVE-2026-42200)
path traversal in CVE-2026-42200 (CVE-2026-42200). Successful exploitation can lead to full system takeover.
|