Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-0049 |
|
Vulnerability in dos (CVE-2026-0049)
vulnerability in dos (CVE-2026-0049). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5672 |
|
Vulnerability in sqli (CVE-2026-5672)
vulnerability in sqli (CVE-2026-5672). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5675 |
|
Vulnerability in sqli (CVE-2026-5675)
vulnerability in sqli (CVE-2026-5675). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5671 |
|
Cross-Site Scripting (XSS) in CVE-2026-5671 (CVE-2026-5671)
cross-site scripting in CVE-2026-5671 (CVE-2026-5671). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35470 |
|
SQL Injection in sqli (CVE-2026-35470)
SQL injection in sqli (CVE-2026-35470). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2.10.2` or later.
|
| CVE-2026-35177 |
|
Path Traversal in c (CVE-2026-35177)
path traversal in c (CVE-2026-35177). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `9.2.0280` or later.
|
| CVE-2026-35209 |
|
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or...
defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype...
|
| CVE-2026-35174 |
|
Path Traversal in path-traversal (CVE-2026-35174)
path traversal in path-traversal (CVE-2026-35174). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `2026.01` or later.
|
| CVE-2026-35029 |
|
Authorization Flaw in litellm (CVE-2026-35029)
vulnerability in litellm (CVE-2026-35029). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.83.0` or later.
|
| CVE-2026-34977 |
|
OS Command Injection in c (CVE-2026-34977)
OS command injection in c (CVE-2026-34977). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.2.1` or later.
|
| CVE-2026-31313 |
|
Cross-Site Scripting (XSS) in feehi (CVE-2026-31313)
cross-site scripting in feehi (CVE-2026-31313). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34756 |
|
Vulnerability in vllm (CVE-2026-34756)
vulnerability in vllm (CVE-2026-34756). Risk of unauthorized operations or information disclosure. Exploitable via ``ChatCompletionRequest``. Mitigation: upgrade to `0.19.0` or later.
|
| CVE-2026-31153 |
|
Cross-Site Scripting (XSS) in CVE-2026-31153 (CVE-2026-31153)
cross-site scripting in CVE-2026-31153 (CVE-2026-31153). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5636 |
|
Vulnerability in sqli (CVE-2026-5636)
vulnerability in sqli (CVE-2026-5636). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5635 |
|
Vulnerability in sqli (CVE-2026-5635)
vulnerability in sqli (CVE-2026-5635). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5634 |
|
Vulnerability in sqli (CVE-2026-5634)
vulnerability in sqli (CVE-2026-5634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5630 |
|
Cross-Site Scripting (XSS) in CVE-2026-5630 (CVE-2026-5630)
cross-site scripting in CVE-2026-5630 (CVE-2026-5630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5625 |
|
Cross-Site Scripting (XSS) in CVE-2026-5625 (CVE-2026-5625)
cross-site scripting in CVE-2026-5625 (CVE-2026-5625). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5620 |
|
Vulnerability in sqli (CVE-2026-5620)
vulnerability in sqli (CVE-2026-5620). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5615 |
|
Cross-Site Scripting (XSS) in CVE-2026-5615 (CVE-2026-5615)
cross-site scripting in CVE-2026-5615 (CVE-2026-5615). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5611 |
|
A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBandSwitch of the file /goform/formCrossBandSwitch. Performing a manipulation of the argument webpage results in...
A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBandSwitch of the file /goform/formCrossBandSwitch. Performing a manipulation of the argument webpage results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public...
|
| CVE-2026-5612 |
|
A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the function formWlEncrypt of the file /goform/formWlEncrypt. Executing a manipulation of the argument webpage can...
A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the function formWlEncrypt of the file /goform/formWlEncrypt. Executing a manipulation of the argument webpage can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been publi...
|
| CVE-2026-5606 |
|
Vulnerability in sqli (CVE-2026-5606)
vulnerability in sqli (CVE-2026-5606). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-35616 KEV |
|
[KEV] Vulnerability in Fortinet forticlient-ems (CVE-2026-35616)
vulnerability in Fortinet forticlient-ems (CVE-2026-35616). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-5604 |
|
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Perfor...
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploita...
|
| CVE-2026-5597 |
|
Path Traversal in path-traversal (CVE-2026-5597)
path traversal in path-traversal (CVE-2026-5597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5596 |
|
Vulnerability in sqli (CVE-2026-5596)
vulnerability in sqli (CVE-2026-5596). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25694 |
|
SQL Injection in sqli (CVE-2019-25694)
SQL injection in sqli (CVE-2019-25694). Confidential information can be exposed externally.
|
| CVE-2019-25696 |
|
SQL Injection in sqli (CVE-2019-25696)
SQL injection in sqli (CVE-2019-25696). Confidential information can be exposed externally.
|
| CVE-2019-25698 |
|
SQL Injection in sqli (CVE-2019-25698)
SQL injection in sqli (CVE-2019-25698). Confidential information can be exposed externally.
|
| CVE-2019-25700 |
|
SQL Injection in sqli (CVE-2019-25700)
SQL injection in sqli (CVE-2019-25700). Confidential information can be exposed externally.
|
| CVE-2019-25702 |
|
SQL Injection in sqli (CVE-2019-25702)
SQL injection in sqli (CVE-2019-25702). Confidential information can be exposed externally.
|
| CVE-2019-25704 |
|
SQL Injection in sqli (CVE-2019-25704)
SQL injection in sqli (CVE-2019-25704). Confidential information can be exposed externally.
|
| CVE-2019-25687 |
|
Path Traversal in wisdom (CVE-2019-25687)
path traversal in wisdom (CVE-2019-25687). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25688 |
|
SQL Injection in sqli (CVE-2019-25688)
SQL injection in sqli (CVE-2019-25688). Confidential information can be exposed externally.
|
| CVE-2019-25690 |
|
SQL Injection in sqli (CVE-2019-25690)
SQL injection in sqli (CVE-2019-25690). Confidential information can be exposed externally.
|
| CVE-2019-25692 |
|
SQL Injection in sqli (CVE-2019-25692)
SQL injection in sqli (CVE-2019-25692). Confidential information can be exposed externally.
|
| CVE-2019-25686 |
|
Vulnerability in dos (CVE-2019-25686)
vulnerability in dos (CVE-2019-25686). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25683 |
|
Vulnerability in dos (CVE-2019-25683)
vulnerability in dos (CVE-2019-25683). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25680 |
|
SQL Injection in sqli (CVE-2019-25680)
SQL injection in sqli (CVE-2019-25680). Confidential information can be exposed externally.
|
| CVE-2019-25684 |
|
SQL Injection in sqli (CVE-2019-25684)
SQL injection in sqli (CVE-2019-25684). Confidential information can be exposed externally.
|
| CVE-2019-25674 |
|
SQL Injection in sqli (CVE-2019-25674)
SQL injection in sqli (CVE-2019-25674). Confidential information can be exposed externally.
|
| CVE-2019-25675 |
|
SQL Injection in sqli (CVE-2019-25675)
SQL injection in sqli (CVE-2019-25675). Confidential information can be exposed externally.
|
| CVE-2019-25676 |
|
Cross-Site Scripting (XSS) in sqli (CVE-2019-25676)
cross-site scripting in sqli (CVE-2019-25676). Confidential information can be exposed externally.
|
| CVE-2019-25678 |
|
Vulnerability in sqli (CVE-2019-25678)
vulnerability in sqli (CVE-2019-25678). Confidential information can be exposed externally.
|
| CVE-2019-25677 |
|
Vulnerability in dos (CVE-2019-25677)
vulnerability in dos (CVE-2019-25677). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25667 |
|
Out-of-Bounds Write in dos (CVE-2019-25667)
out-of-bounds write in dos (CVE-2019-25667). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-25671 |
|
Path Traversal in c (CVE-2019-25671)
path traversal in c (CVE-2019-25671). Successful exploitation can lead to full system takeover.
|
| CVE-2019-25668 |
|
SQL Injection in sqli (CVE-2019-25668)
SQL injection in sqli (CVE-2019-25668). Confidential information can be exposed externally.
|
| CVE-2019-25669 |
|
SQL Injection in sqli (CVE-2019-25669)
SQL injection in sqli (CVE-2019-25669). Confidential information can be exposed externally.
|