Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73337 |
|
Authentication Bypass in CVE-2026-73337 (CVE-2026-73337)
authentication bypass in CVE-2026-73337 (CVE-2026-73337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75479 |
|
Vulnerability in CVE-2026-75479 (CVE-2026-75479)
vulnerability in CVE-2026-75479 (CVE-2026-75479). Confidential information can be exposed externally.
|
| CVE-2026-74894 |
|
Authentication Bypass in CVE-2026-74894 (CVE-2026-74894)
authentication bypass in CVE-2026-74894 (CVE-2026-74894). Successful exploitation can lead to full system takeover. Exploitable via `Authorization header`.
|
| CVE-2026-74901 |
|
Vulnerability in CVE-2026-74901 (CVE-2026-74901)
vulnerability in CVE-2026-74901 (CVE-2026-74901). Successful exploitation can lead to full system takeover.
|
| CVE-2026-74890 |
|
Vulnerability in CVE-2026-74890 (CVE-2026-74890)
vulnerability in CVE-2026-74890 (CVE-2026-74890). Data can be tampered with by attackers.
|
| CVE-2026-19349 |
|
Vulnerability in CVE-2026-19349 (CVE-2026-19349)
vulnerability in CVE-2026-19349 (CVE-2026-19349). Successful exploitation can lead to full system takeover. Exploitable via ``kind``.
|
| CVE-2026-73054 |
|
Authentication Bypass in CVE-2026-73054 (CVE-2026-73054)
authentication bypass in CVE-2026-73054 (CVE-2026-73054). Confidential information can be exposed externally.
|
| CVE-2026-15826 |
|
Vulnerability in wordpress (CVE-2026-15826)
vulnerability in wordpress (CVE-2026-15826). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15341 |
|
Authentication Bypass in wordpress (CVE-2026-15341)
authentication bypass in wordpress (CVE-2026-15341). Successful exploitation can lead to full system takeover. Exploitable via ``init``.
|
| CVE-2026-15303 |
|
Authentication Bypass in wordpress (CVE-2026-15303)
authentication bypass in wordpress (CVE-2026-15303). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73683 |
|
Vulnerability in laravel (CVE-2026-73683)
vulnerability in laravel (CVE-2026-73683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16879 |
|
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass...
|
| CVE-2026-1621 |
|
Vulnerability in CVE-2026-1621 (CVE-2026-1621)
vulnerability in CVE-2026-1621 (CVE-2026-1621). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72856 |
|
Vulnerability in CVE-2026-72856 (CVE-2026-72856)
vulnerability in CVE-2026-72856 (CVE-2026-72856). Confidential information can be exposed externally. Exploitable via `PUT /api/global/users/tenant/owner`.
|
| CVE-2026-14525 |
|
Vulnerability in ibm (CVE-2026-14525)
vulnerability in ibm (CVE-2026-14525). Confidential information can be exposed externally.
|
| CVE-2026-6387 |
|
Vulnerability in CVE-2026-6387 (CVE-2026-6387)
vulnerability in CVE-2026-6387 (CVE-2026-6387). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12263 |
|
Vulnerability in CVE-2026-12263 (CVE-2026-12263)
vulnerability in CVE-2026-12263 (CVE-2026-12263). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0292 |
|
Vulnerability in CVE-2026-0292 (CVE-2026-0292)
vulnerability in CVE-2026-0292 (CVE-2026-0292). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72809 |
|
Vulnerability in CVE-2026-72809 (CVE-2026-72809)
vulnerability in CVE-2026-72809 (CVE-2026-72809). Confidential information can be exposed externally. Mitigation: upgrade to `3.7.4` or later.
|
| CVE-2026-72806 |
|
Vulnerability in CVE-2026-72806 (CVE-2026-72806)
vulnerability in CVE-2026-72806 (CVE-2026-72806). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72786 |
|
Vulnerability in CVE-2026-72786 (CVE-2026-72786)
vulnerability in CVE-2026-72786 (CVE-2026-72786). Confidential information can be exposed externally.
|
| CVE-2026-59914 |
|
Vulnerability in dell (CVE-2026-59914)
vulnerability in dell (CVE-2026-59914). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46731 |
|
Vulnerability in dell (CVE-2026-46731)
vulnerability in dell (CVE-2026-46731). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70468 |
|
Vulnerability in CVE-2026-70468 (CVE-2026-70468)
vulnerability in CVE-2026-70468 (CVE-2026-70468). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18961 |
|
Authentication Bypass in wordpress (CVE-2026-18961)
authentication bypass in wordpress (CVE-2026-18961). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18691 |
|
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable...
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable...
|
| CVE-2026-15426 |
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
| CVE-2026-12571 |
|
Authentication Bypass in CVE-2026-12571 (CVE-2026-12571)
authentication bypass in CVE-2026-12571 (CVE-2026-12571). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62911 |
|
Vulnerability in microsoft (CVE-2026-62911)
vulnerability in microsoft (CVE-2026-62911). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72746 |
|
Authentication Bypass in CVE-2026-72746 (CVE-2026-72746)
authentication bypass in CVE-2026-72746 (CVE-2026-72746). Confidential information can be exposed externally.
|
| CVE-2026-72533 |
|
Authentication Bypass in CVE-2026-72533 (CVE-2026-72533)
authentication bypass in CVE-2026-72533 (CVE-2026-72533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6181 |
|
Vulnerability in CVE-2026-6181 (CVE-2026-6181)
vulnerability in CVE-2026-6181 (CVE-2026-6181). Confidential information can be exposed externally.
|
| CVE-2025-15681 |
|
Vulnerability in CVE-2025-15681 (CVE-2025-15681)
vulnerability in CVE-2025-15681 (CVE-2025-15681). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72691 |
|
Vulnerability in CVE-2026-72691 (CVE-2026-72691)
vulnerability in CVE-2026-72691 (CVE-2026-72691). Confidential information can be exposed externally.
|
| CVE-2026-11430 |
|
Vulnerability in CVE-2026-11430 (CVE-2026-11430)
vulnerability in CVE-2026-11430 (CVE-2026-11430). Risk of unauthorized operations or information disclosure. Exploitable via `POST /scheduler/webhook`.
|
| CVE-2026-70636 |
|
Vulnerability in CVE-2026-70636 (CVE-2026-70636)
vulnerability in CVE-2026-70636 (CVE-2026-70636). Data can be tampered with by attackers.
|
| CVE-2026-48088 |
|
Vulnerability in CVE-2026-48088 (CVE-2026-48088)
vulnerability in CVE-2026-48088 (CVE-2026-48088). Confidential information can be exposed externally. Exploitable via `POST /api/tenants/{tenantId}/staff/{staffId}/crypto`.
|
| CVE-2026-53977 |
|
Vulnerability in express (CVE-2026-53977)
vulnerability in express (CVE-2026-53977). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-53976 |
|
Path Traversal in path-traversal (CVE-2026-53976)
path traversal in path-traversal (CVE-2026-53976). Confidential information can be exposed externally.
|
| CVE-2026-65583 |
|
Vulnerability in apache (CVE-2026-65583)
vulnerability in apache (CVE-2026-65583). Confidential information can be exposed externally.
|
| CVE-2026-15459 |
|
Authentication Bypass in wordpress (CVE-2026-15459)
authentication bypass in wordpress (CVE-2026-15459). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8446 |
|
Vulnerability in langflow (CVE-2026-8446)
vulnerability in langflow (CVE-2026-8446). Confidential information can be exposed externally.
|
| CVE-2026-9192 |
|
Authentication Bypass in CVE-2026-9192 (CVE-2026-9192)
authentication bypass in CVE-2026-9192 (CVE-2026-9192). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71248 |
|
SQL Injection in sqli (CVE-2026-71248)
SQL injection in sqli (CVE-2026-71248). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7520 |
|
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
|
| CVE-2026-71206 |
|
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
|
| CVE-2026-6627 |
|
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
|
| CVE-2026-55997 |
|
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...
|
| CVE-2026-70552 |
|
Vulnerability in CVE-2026-70552 (CVE-2026-70552)
vulnerability in CVE-2026-70552 (CVE-2026-70552). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61514 |
|
Vulnerability in CVE-2026-61514 (CVE-2026-61514)
vulnerability in CVE-2026-61514 (CVE-2026-61514). Successful exploitation can lead to full system takeover.
|