Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-50237 |
|
SSRF (Server-Side Request Forgery) in privilege-escalation (CVE-2026-50237)
SSRF in privilege-escalation (CVE-2026-50237). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72693 |
|
Vulnerability in privilege-escalation (CVE-2026-72693)
vulnerability in privilege-escalation (CVE-2026-72693). Successful exploitation can lead to full system takeover. Exploitable via ``login``.
|
| CVE-2026-72694 |
|
Vulnerability in privilege-escalation (CVE-2026-72694)
vulnerability in privilege-escalation (CVE-2026-72694). Confidential information can be exposed externally.
|
| CVE-2026-5303 |
|
Vulnerability in privilege-escalation (CVE-2026-5303)
vulnerability in privilege-escalation (CVE-2026-5303). Confidential information can be exposed externally.
|
| CVE-2026-5304 |
|
Vulnerability in privilege-escalation (CVE-2026-5304)
vulnerability in privilege-escalation (CVE-2026-5304). Confidential information can be exposed externally.
|
| CVE-2026-6505 |
|
Vulnerability in privilege-escalation (CVE-2026-6505)
vulnerability in privilege-escalation (CVE-2026-6505). Confidential information can be exposed externally.
|
| CVE-2026-4757 |
|
Vulnerability in privilege-escalation (CVE-2026-4757)
vulnerability in privilege-escalation (CVE-2026-4757). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8917 |
|
Vulnerability in privilege-escalation (CVE-2026-8917)
vulnerability in privilege-escalation (CVE-2026-8917). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66764 |
|
Vulnerability in privilege-escalation (CVE-2026-66764)
vulnerability in privilege-escalation (CVE-2026-66764). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63622 |
|
Vulnerability in privilege-escalation (CVE-2026-63622)
vulnerability in privilege-escalation (CVE-2026-63622). Successful exploitation can lead to full system takeover. Exploitable via ``swtpm``.
|
| CVE-2026-18950 |
|
Privilege Escalation in privilege-escalation (CVE-2026-18950)
vulnerability in privilege-escalation (CVE-2026-18950). Successful exploitation can lead to full system takeover. Exploitable via ``roleRef``.
|
| CVE-2026-18617 |
|
Vulnerability in privilege-escalation (CVE-2026-18617)
vulnerability in privilege-escalation (CVE-2026-18617). Successful exploitation can lead to full system takeover.
|
| CVE-2026-72912 |
|
Vulnerability in privilege-escalation (CVE-2026-72912)
vulnerability in privilege-escalation (CVE-2026-72912). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19278 |
|
Vulnerability in privilege-escalation (CVE-2026-19278)
vulnerability in privilege-escalation (CVE-2026-19278). Confidential information can be exposed externally.
|
| CVE-2026-16742 |
|
Privilege Escalation in privilege-escalation (CVE-2026-16742)
vulnerability in privilege-escalation (CVE-2026-16742). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40920 |
|
Vulnerability in apache (CVE-2026-40920)
vulnerability in apache (CVE-2026-40920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14644 |
|
Vulnerability in privilege-escalation (CVE-2026-14644)
vulnerability in privilege-escalation (CVE-2026-14644). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7867 |
|
Authorization Flaw in privilege-escalation (CVE-2026-7867)
vulnerability in privilege-escalation (CVE-2026-7867). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48086 |
|
Privilege Escalation in privilege-escalation (CVE-2026-48086)
vulnerability in privilege-escalation (CVE-2026-48086). Successful exploitation can lead to full system takeover. Exploitable via ``GLOBAL_ADMIN``.
|
| CVE-2026-19169 |
|
Vulnerability in privilege-escalation (CVE-2026-19169)
vulnerability in privilege-escalation (CVE-2026-19169). Successful exploitation can lead to full system takeover.
|
| CVE-2026-19139 |
|
Vulnerability in privilege-escalation (CVE-2026-19139)
vulnerability in privilege-escalation (CVE-2026-19139). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18367 |
|
Vulnerability in privilege-escalation (CVE-2026-18367)
vulnerability in privilege-escalation (CVE-2026-18367). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66662 |
|
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
|
| CVE-2026-65559 |
|
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
|
| CVE-2026-65507 |
|
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
|
| CVE-2026-28183 |
|
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
|
| CVE-2026-28111 |
|
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
|
| CVE-2026-28005 |
|
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
|
| CVE-2026-18485 |
|
Vulnerability in privilege-escalation (CVE-2026-18485)
vulnerability in privilege-escalation (CVE-2026-18485). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70596 |
|
Cross-Site Scripting (XSS) in ghost (CVE-2026-70596)
cross-site scripting in ghost (CVE-2026-70596). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-44945 |
|
Vulnerability in privilege-escalation (CVE-2026-44945)
vulnerability in privilege-escalation (CVE-2026-44945). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10059 |
|
Vulnerability in privilege-escalation (CVE-2026-10059)
vulnerability in privilege-escalation (CVE-2026-10059). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10090 |
|
Vulnerability in privilege-escalation (CVE-2026-10090)
vulnerability in privilege-escalation (CVE-2026-10090). Confidential information can be exposed externally.
|
| CVE-2026-8761 |
|
Vulnerability in wordpress (CVE-2026-8761)
vulnerability in wordpress (CVE-2026-8761). Successful exploitation can lead to full system takeover. Exploitable via ``CustomersController``.
|
| CVE-2026-18322 |
|
Privilege Escalation in wordpress (CVE-2026-18322)
vulnerability in wordpress (CVE-2026-18322). Successful exploitation can lead to full system takeover. Exploitable via ``save``.
|
| CVE-2026-70475 |
|
Vulnerability in flowise (CVE-2026-70475)
vulnerability in flowise (CVE-2026-70475). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v1/executions/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-64634 |
|
A vulnerability allowing local privilege escalation to the Reporter service context.
A vulnerability allowing local privilege escalation to the Reporter service context.
|
| CVE-2026-18650 |
|
Vulnerability in privilege-escalation (CVE-2026-18650)
vulnerability in privilege-escalation (CVE-2026-18650). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18759 |
|
Privilege Escalation in path-traversal (CVE-2026-18759)
vulnerability in path-traversal (CVE-2026-18759). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48333 |
|
Authorization Flaw in privilege-escalation (CVE-2026-48333)
vulnerability in privilege-escalation (CVE-2026-48333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48331 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-48331)
SSRF in ssrf (CVE-2026-48331). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18477 |
|
Vulnerability in privilege-escalation (CVE-2026-18477)
vulnerability in privilege-escalation (CVE-2026-18477). Data can be tampered with by attackers.
|
| CVE-2026-15430 |
|
Privilege Escalation in privilege-escalation (CVE-2026-15430)
vulnerability in privilege-escalation (CVE-2026-15430). Confidential information can be exposed externally.
|
| CVE-2026-18248 |
|
Vulnerability in privilege-escalation (CVE-2026-18248)
vulnerability in privilege-escalation (CVE-2026-18248). Confidential information can be exposed externally.
|
| CVE-2026-67609 |
|
Vulnerability in apache (CVE-2026-67609)
vulnerability in apache (CVE-2026-67609). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16635 |
|
Privilege Escalation in wordpress (CVE-2026-16635)
vulnerability in wordpress (CVE-2026-16635). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15414 |
|
Privilege Escalation in wordpress (CVE-2026-15414)
vulnerability in wordpress (CVE-2026-15414). Successful exploitation can lead to full system takeover. Exploitable via ``_wps_plan_user_role``.
|
| CVE-2026-51272 |
|
Vulnerability in privilege-escalation (CVE-2026-51272)
vulnerability in privilege-escalation (CVE-2026-51272). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58222 |
|
Vulnerability in privilege-escalation (CVE-2026-58222)
vulnerability in privilege-escalation (CVE-2026-58222). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44106 |
|
A privilege escalation vulnerability in the init-script for user-applications allows a low...
A privilege escalation vulnerability in the init-script for user-applications allows a low...
|