Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-58373 |
|
Vulnerability in cvat (CVE-2026-58373)
vulnerability in cvat (CVE-2026-58373). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58377 |
|
Vulnerability in CVE-2026-58377 (CVE-2026-58377)
vulnerability in CVE-2026-58377 (CVE-2026-58377). Confidential information can be exposed externally.
|
| CVE-2026-58167 |
|
Vulnerability in CVE-2026-58167 (CVE-2026-58167)
vulnerability in CVE-2026-58167 (CVE-2026-58167). Confidential information can be exposed externally. Exploitable via `POST /api/n9e/datasource/list.`.
|
| CVE-2026-58165 |
|
Vulnerability in privilege-escalation (CVE-2026-58165)
vulnerability in privilege-escalation (CVE-2026-58165). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58168 |
|
Vulnerability in CVE-2026-58168 (CVE-2026-58168)
vulnerability in CVE-2026-58168 (CVE-2026-58168). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54475 |
|
Vulnerability in activemq (CVE-2026-54475)
vulnerability in activemq (CVE-2026-54475). Data can be tampered with by attackers. Mitigation: upgrade to `5.19.8, 6.2.7` or later.
|
| CVE-2026-12349 |
|
Vulnerability in c (CVE-2026-12349)
vulnerability in c (CVE-2026-12349). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57498 |
|
Vulnerability in CVE-2026-57498 (CVE-2026-57498)
vulnerability in CVE-2026-57498 (CVE-2026-57498). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.0-beta.474` or later.
|
| CVE-2026-57946 |
|
Vulnerability in CVE-2026-57946 (CVE-2026-57946)
vulnerability in CVE-2026-57946 (CVE-2026-57946). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57954 |
|
Vulnerability in CVE-2026-57954 (CVE-2026-57954)
vulnerability in CVE-2026-57954 (CVE-2026-57954). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57952 |
|
Vulnerability in its-a-feature (CVE-2026-57952)
vulnerability in its-a-feature (CVE-2026-57952). Confidential information can be exposed externally.
|
| CVE-2026-57949 |
|
Vulnerability in vue (CVE-2026-57949)
vulnerability in vue (CVE-2026-57949). Confidential information can be exposed externally. Exploitable via `GET /admin-api/crm/follow-up-record/get`.
|
| CVE-2026-57332 |
|
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
|
| CVE-2026-57335 |
|
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
|
| CVE-2026-57327 |
|
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
|
| CVE-2026-57340 |
|
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
|
| CVE-2026-57339 |
|
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
|
| CVE-2026-57334 |
|
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
|
| CVE-2025-2902 |
|
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.
...
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform.
...
|
| CVE-2026-13537 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-13537 (CVE-2026-13537)
vulnerability in CVE-2026-13537 (CVE-2026-13537). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13484 |
|
Vulnerability in lfprojects (CVE-2026-13484)
vulnerability in lfprojects (CVE-2026-13484). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11773 |
|
Vulnerability in wordpress (CVE-2026-11773)
vulnerability in wordpress (CVE-2026-11773). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12471 |
|
Vulnerability in wordpress (CVE-2026-12471)
vulnerability in wordpress (CVE-2026-12471). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9233 |
|
Vulnerability in wordpress (CVE-2026-9233)
vulnerability in wordpress (CVE-2026-9233). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12432 |
|
Vulnerability in wordpress (CVE-2026-12432)
vulnerability in wordpress (CVE-2026-12432). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3462 |
|
Vulnerability in wordpress (CVE-2026-3462)
vulnerability in wordpress (CVE-2026-3462). Data can be tampered with by attackers.
|
| CVE-2026-11364 |
|
Vulnerability in wordpress (CVE-2026-11364)
vulnerability in wordpress (CVE-2026-11364). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12404 |
|
Vulnerability in wordpress (CVE-2026-12404)
vulnerability in wordpress (CVE-2026-12404). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49258 |
|
Vulnerability in github.com/juev/nebula-mesh (CVE-2026-49258)
vulnerability in github.com/juev/nebula-mesh (CVE-2026-49258). Successful exploitation can lead to full system takeover. Exploitable via `POST /ui/hosts/{id}/block`.
|
| CVE-2026-55188 |
|
Information Disclosure in CVE-2026-55188 (CVE-2026-55188)
vulnerability in CVE-2026-55188 (CVE-2026-55188). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.0-beta.9` or later.
|
| CVE-2026-55189 |
|
Vulnerability in CVE-2026-55189 (CVE-2026-55189)
vulnerability in CVE-2026-55189 (CVE-2026-55189). Confidential information can be exposed externally. Mitigation: upgrade to `1.0.0-beta.9` or later.
|
| CVE-2026-55838 |
|
Vulnerability in CVE-2026-55838 (CVE-2026-55838)
vulnerability in CVE-2026-55838 (CVE-2026-55838). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49991 |
|
Path Traversal in path-traversal (CVE-2026-49991)
path traversal in path-traversal (CVE-2026-49991). Data can be tampered with by attackers.
|
| CVE-2026-47193 |
|
Information Disclosure in CVE-2026-47193 (CVE-2026-47193)
vulnerability in CVE-2026-47193 (CVE-2026-47193). Confidential information can be exposed externally. Mitigation: upgrade to `17.3.3` or later.
|
| CVE-2026-44734 |
|
Vulnerability in CVE-2026-44734 (CVE-2026-44734)
vulnerability in CVE-2026-44734 (CVE-2026-44734). Data can be tampered with by attackers. Mitigation: upgrade to `17.3.2` or later.
|
| CVE-2026-57518 |
|
Vulnerability in privilege-escalation (CVE-2026-57518)
vulnerability in privilege-escalation (CVE-2026-57518). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48751 |
|
Vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751)
vulnerability in github.com/lxc/incus/v7/cmd/incusd (CVE-2026-48751). Successful exploitation can lead to full system takeover. Exploitable via ``raw.lxc``. Mitigation: upgrade to `7.2.0` or later.
|
| CVE-2026-12411 |
|
Vulnerability in canonical (CVE-2026-12411)
vulnerability in canonical (CVE-2026-12411). Confidential information can be exposed externally.
|
| CVE-2026-57640 |
|
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.
|
| CVE-2026-57645 |
|
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
|
| CVE-2026-57654 |
|
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
|
| CVE-2026-57648 |
|
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.
|
| CVE-2026-57649 |
|
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
|
| CVE-2026-57661 |
|
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
|
| CVE-2026-57660 |
|
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
|
| CVE-2026-56773 |
|
Vulnerability in CVE-2026-56773 (CVE-2026-56773)
vulnerability in CVE-2026-56773 (CVE-2026-56773). Successful exploitation can lead to full system takeover. Exploitable via `GET /api/v2/tables/get`.
|
| CVE-2026-57324 |
|
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
|
| CVE-2026-57622 |
|
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
|
| CVE-2026-57323 |
|
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
|
| CVE-2026-57430 |
|
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.
|