Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-12525 |
|
Privilege Escalation in wordpress (CVE-2026-12525)
vulnerability in wordpress (CVE-2026-12525). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53444 |
|
Privilege Escalation in CVE-2026-53444 (CVE-2026-53444)
vulnerability in CVE-2026-53444 (CVE-2026-53444). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62355 |
|
Privilege Escalation in CVE-2026-62355 (CVE-2026-62355)
vulnerability in CVE-2026-62355 (CVE-2026-62355). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14960 |
|
Privilege Escalation in CVE-2026-14960 (CVE-2026-14960)
vulnerability in CVE-2026-14960 (CVE-2026-14960). Successful exploitation can lead to full system takeover. Exploitable via ``Tdelo64.sys``.
|
| CVE-2026-14961 |
|
Vulnerability in privilege-escalation (CVE-2026-14961)
vulnerability in privilege-escalation (CVE-2026-14961). Confidential information can be exposed externally. Exploitable via ``Tdelo64.sys``.
|
| CVE-2026-53515 |
|
Privilege Escalation in @better-auth/sso (CVE-2026-53515)
vulnerability in @better-auth/sso (CVE-2026-53515). Data can be tampered with by attackers. Exploitable via `POST /sso/register`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-57996 |
|
Privilege Escalation in privilege-escalation (CVE-2026-57996)
vulnerability in privilege-escalation (CVE-2026-57996). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/api/user/add`.
|
| CVE-2026-49501 |
|
Privilege Escalation in dell (CVE-2026-49501)
vulnerability in dell (CVE-2026-49501). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50391 |
|
Privilege Escalation in microsoft (CVE-2026-50391)
vulnerability in microsoft (CVE-2026-50391). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50343 |
|
Privilege Escalation in microsoft (CVE-2026-50343)
vulnerability in microsoft (CVE-2026-50343). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50295 |
|
Privilege Escalation in microsoft (CVE-2026-50295)
vulnerability in microsoft (CVE-2026-50295). Data can be tampered with by attackers.
|
| CVE-2026-49176 |
|
Vulnerability in microsoft (CVE-2026-49176)
vulnerability in microsoft (CVE-2026-49176). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53565 |
|
Privilege Escalation in CVE-2026-53565 (CVE-2026-53565)
vulnerability in CVE-2026-53565 (CVE-2026-53565). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52533 |
|
Privilege Escalation in CVE-2026-52533 (CVE-2026-52533)
vulnerability in CVE-2026-52533 (CVE-2026-52533). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61463 |
|
Privilege Escalation in privilege-escalation (CVE-2026-61463)
vulnerability in privilege-escalation (CVE-2026-61463). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59245 |
|
Privilege Escalation in apache (CVE-2026-59245)
vulnerability in apache (CVE-2026-59245). Confidential information can be exposed externally. Exploitable via ``dag_id``.
|
| CVE-2026-59260 |
|
Privilege Escalation in CVE-2026-59260 (CVE-2026-59260)
vulnerability in CVE-2026-59260 (CVE-2026-59260). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14262 |
|
Privilege Escalation in wordpress (CVE-2026-14262)
vulnerability in wordpress (CVE-2026-14262). Successful exploitation can lead to full system takeover. Exploitable via ``payload``.
|
| CVE-2026-13756 |
|
Privilege Escalation in wordpress (CVE-2026-13756)
vulnerability in wordpress (CVE-2026-13756). Successful exploitation can lead to full system takeover. Exploitable via ``wp_capabilities``.
|
| CVE-2026-55843 |
|
Privilege Escalation in snipe/snipe-it (CVE-2026-55843)
vulnerability in snipe/snipe-it (CVE-2026-55843). Data can be tampered with by attackers. Exploitable via `PUT /users/{id}`. Mitigation: upgrade to `8.6.0` or later.
|
| CVE-2026-51119 |
|
Privilege Escalation in CVE-2026-51119 (CVE-2026-51119)
vulnerability in CVE-2026-51119 (CVE-2026-51119). Confidential information can be exposed externally.
|
| CVE-2026-40009 |
|
Privilege Escalation in apache (CVE-2026-40009)
vulnerability in apache (CVE-2026-40009). Confidential information can be exposed externally.
|
| CVE-2026-44787 |
|
Privilege Escalation in discourse (CVE-2026-44787)
vulnerability in discourse (CVE-2026-44787). Confidential information can be exposed externally.
|
| CVE-2026-0276 |
|
Privilege Escalation in privilege-escalation (CVE-2026-0276)
vulnerability in privilege-escalation (CVE-2026-0276). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0275 |
|
Privilege Escalation in privilege-escalation (CVE-2026-0275)
vulnerability in privilege-escalation (CVE-2026-0275). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54652 |
|
Privilege Escalation in nginx (CVE-2026-54652)
vulnerability in nginx (CVE-2026-54652). Confidential information can be exposed externally. Exploitable via `GET /api/logs/{service}`.
|
| CVE-2026-14250 |
|
Privilege Escalation in wordpress (CVE-2026-14250)
vulnerability in wordpress (CVE-2026-14250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9842 |
|
Privilege Escalation in wordpress (CVE-2026-9842)
vulnerability in wordpress (CVE-2026-9842). Data can be tampered with by attackers. Exploitable via ``manage_options``.
|
| CVE-2026-14482 |
|
Privilege Escalation in wordpress (CVE-2026-14482)
vulnerability in wordpress (CVE-2026-14482). Successful exploitation can lead to full system takeover. Exploitable via ``update_option``.
|
| CVE-2026-58583 |
|
Privilege Escalation in privilege-escalation (CVE-2026-58583)
vulnerability in privilege-escalation (CVE-2026-58583). Confidential information can be exposed externally.
|
| CVE-2026-53645 |
|
Privilege Escalation in privilege-escalation (CVE-2026-53645)
vulnerability in privilege-escalation (CVE-2026-53645). Risk of unauthorized operations or information disclosure. Exploitable via ``staff.create_and_edit_staff``.
|
| CVE-2026-14719 |
|
Vulnerability in CVE-2026-14719 (CVE-2026-14719)
vulnerability in CVE-2026-14719 (CVE-2026-14719). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13228 |
|
Privilege Escalation in wordpress (CVE-2026-13228)
vulnerability in wordpress (CVE-2026-13228). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12224 |
|
Privilege Escalation in wordpress (CVE-2026-12224)
vulnerability in wordpress (CVE-2026-12224). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57995 |
|
Privilege Escalation in privilege-escalation (CVE-2026-57995)
vulnerability in privilege-escalation (CVE-2026-57995). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14101 |
|
Privilege Escalation in google (CVE-2026-14101)
vulnerability in google (CVE-2026-14101). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14124 |
|
Privilege Escalation in privilege-escalation (CVE-2026-14124)
vulnerability in privilege-escalation (CVE-2026-14124). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7406 |
|
Privilege Escalation in privilege-escalation (CVE-2025-7406)
vulnerability in privilege-escalation (CVE-2025-7406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58053 |
|
Privilege Escalation in CVE-2026-58053 (CVE-2026-58053)
vulnerability in CVE-2026-58053 (CVE-2026-58053). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58054 |
|
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when...
|
| CVE-2026-12415 |
|
Privilege Escalation in wordpress (CVE-2026-12415)
vulnerability in wordpress (CVE-2026-12415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45256 |
|
Privilege Escalation in dos (CVE-2026-45256)
vulnerability in dos (CVE-2026-45256). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56245 |
|
Privilege Escalation in CVE-2026-56245 (CVE-2026-56245)
vulnerability in CVE-2026-56245 (CVE-2026-56245). Data can be tampered with by attackers. Exploitable via `POST /rest/v1/rpc/record_build_time`.
|
| CVE-2026-52808 |
|
Privilege Escalation in gogs.io/gogs (CVE-2026-52808)
vulnerability in gogs.io/gogs (CVE-2026-52808). Data can be tampered with by attackers.
|
| CVE-2026-56225 |
|
Privilege Escalation in CVE-2026-56225 (CVE-2026-56225)
vulnerability in CVE-2026-56225 (CVE-2026-56225). Confidential information can be exposed externally.
|
| CVE-2026-54099 |
|
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container...
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container...
|
| CVE-2026-8157 |
|
Privilege Escalation in wordpress (CVE-2026-8157)
vulnerability in wordpress (CVE-2026-8157). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56239 |
|
Privilege Escalation in privilege-escalation (CVE-2026-56239)
vulnerability in privilege-escalation (CVE-2026-56239). Data can be tampered with by attackers.
|
| CVE-2026-56212 |
|
Privilege Escalation in CVE-2026-56212 (CVE-2026-56212)
vulnerability in CVE-2026-56212 (CVE-2026-56212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56216 |
|
Privilege Escalation in CVE-2026-56216 (CVE-2026-56216)
vulnerability in CVE-2026-56216 (CVE-2026-56216). Successful exploitation can lead to full system takeover. Exploitable via `POST /functions/v1/apikey`.
|