Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2025-10913 |
|
Cross-Site Scripting (XSS) in CVE-2025-10913 (CVE-2025-10913)
cross-site scripting in CVE-2025-10913 (CVE-2025-10913). Data can be tampered with by attackers.
|
| CVE-2026-25870 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-25870)
SSRF in ssrf (CVE-2026-25870). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0651 |
|
Path Traversal in path-traversal (CVE-2026-0651)
path traversal in path-traversal (CVE-2026-0651). Successful exploitation can lead to full system takeover.
|
| CVE-2025-7636 |
|
SQL Injection in sqli (CVE-2025-7636)
SQL injection in sqli (CVE-2025-7636). Successful exploitation can lead to full system takeover.
|
| CVE-2025-6967 |
|
Vulnerability in CVE-2025-6967 (CVE-2025-6967)
vulnerability in CVE-2025-6967 (CVE-2025-6967). Confidential information can be exposed externally.
|
| CVE-2025-11242 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-11242)
SSRF in ssrf (CVE-2025-11242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25639 |
|
Vulnerability in axios (CVE-2026-25639)
vulnerability in axios (CVE-2026-25639). Risk of unauthorized operations or information disclosure. Exploitable via ``mergeConfig``. Mitigation: upgrade to `0.30.3` or later.
|
| CVE-2025-14831 |
|
Vulnerability in dos (CVE-2025-14831)
vulnerability in dos (CVE-2025-14831). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-6830 |
|
SQL Injection in sqli (CVE-2025-6830)
SQL injection in sqli (CVE-2025-6830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-23903 |
|
Vulnerability in spring (CVE-2026-23903)
vulnerability in spring (CVE-2026-23903). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7799 |
|
Cross-Site Scripting (XSS) in CVE-2025-7799 (CVE-2025-7799)
cross-site scripting in CVE-2025-7799 (CVE-2025-7799). Data can be tampered with by attackers.
|
| CVE-2026-1615 |
|
Code Injection in CVE-2026-1615 (CVE-2026-1615)
code injection in CVE-2026-1615 (CVE-2026-1615). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25580 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-25580)
SSRF in ssrf (CVE-2026-25580). Confidential information can be exposed externally. Mitigation: upgrade to `1.56.0` or later.
|
| CVE-2026-25640 |
|
Path Traversal in path-traversal (CVE-2026-25640)
path traversal in path-traversal (CVE-2026-25640). Confidential information can be exposed externally. Mitigation: upgrade to `1.51.0` or later.
|
| CVE-2026-1709 |
|
Vulnerability in keylime (CVE-2026-1709)
vulnerability in keylime (CVE-2026-1709). Data can be tampered with by attackers. Mitigation: upgrade to `7.12.0` or later.
|
| CVE-2026-25727 |
|
Vulnerability in dos (CVE-2026-25727)
vulnerability in dos (CVE-2026-25727). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1337 |
|
Vulnerability in neo4j (CVE-2026-1337)
vulnerability in neo4j (CVE-2026-1337). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-12131 |
|
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
|
| CVE-2025-69619 |
|
Path Traversal in path-traversal (CVE-2025-69619)
path traversal in path-traversal (CVE-2025-69619). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-37131 |
|
Vulnerability in dos (CVE-2020-37131)
vulnerability in dos (CVE-2020-37131). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-37121 |
|
Vulnerability in c (CVE-2020-37121)
vulnerability in c (CVE-2020-37121). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1312 |
|
SQL Injection in django (CVE-2026-1312)
SQL injection in django (CVE-2026-1312). Risk of unauthorized operations or information disclosure. Exploitable via ``FilteredRelation``. Mitigation: upgrade to `4.2.28, 5.2.11, 6.0.2` or later.
|
| CVE-2026-1287 |
|
SQL Injection in django (CVE-2026-1287)
SQL injection in django (CVE-2026-1287). Risk of unauthorized operations or information disclosure. Exploitable via ``FilteredRelation``. Mitigation: upgrade to `4.2.28, 5.2.11, 6.0.2` or later.
|
| CVE-2026-24423 KEV |
|
[KEV] Vulnerability in Smartertools smartermail (CVE-2026-24423)
vulnerability in Smartertools smartermail (CVE-2026-24423). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-20111 |
|
Vulnerability in cisco (CVE-2026-20111)
vulnerability in cisco (CVE-2026-20111). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-70545 |
|
Cross-Site Scripting (XSS) in belden (CVE-2025-70545)
cross-site scripting in belden (CVE-2025-70545). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-23060 |
|
Vulnerability in dos (CVE-2026-23060)
vulnerability in dos (CVE-2026-23060). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-5329 |
|
SQL Injection in sqli (CVE-2025-5329)
SQL injection in sqli (CVE-2025-5329). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1819 |
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
|
| CVE-2025-69620 |
|
Path Traversal in path-traversal (CVE-2025-69620)
path traversal in path-traversal (CVE-2025-69620). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69848 |
|
Cross-Site Scripting (XSS) in netbox (CVE-2025-69848)
cross-site scripting in netbox (CVE-2025-69848). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-5319 |
|
SQL Injection in sqli (CVE-2025-5319)
SQL injection in sqli (CVE-2025-5319). Successful exploitation can lead to full system takeover.
|
| CVE-2025-6397 |
|
Cross-Site Scripting (XSS) in CVE-2025-6397 (CVE-2025-6397)
cross-site scripting in CVE-2025-6397 (CVE-2025-6397). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7760 |
|
Cross-Site Scripting (XSS) in CVE-2025-7760 (CVE-2025-7760)
cross-site scripting in CVE-2025-7760 (CVE-2025-7760). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8456 |
|
Cross-Site Scripting (XSS) in CVE-2025-8456 (CVE-2025-8456)
cross-site scripting in CVE-2025-8456 (CVE-2025-8456). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8461 |
|
Cross-Site Scripting (XSS) in CVE-2025-8461 (CVE-2025-8461)
cross-site scripting in CVE-2025-8461 (CVE-2025-8461). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-8589 |
|
Cross-Site Scripting (XSS) in CVE-2025-8589 (CVE-2025-8589)
cross-site scripting in CVE-2025-8589 (CVE-2025-8589). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-22778 |
|
Vulnerability in vllm (CVE-2026-22778)
vulnerability in vllm (CVE-2026-22778). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/chat/completions`. Mitigation: upgrade to `0.14.1` or later.
|
| CVE-2025-8587 |
|
SQL Injection in sqli (CVE-2025-8587)
SQL injection in sqli (CVE-2025-8587). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-1518 |
|
Vulnerability in ssrf (CVE-2026-1518)
vulnerability in ssrf (CVE-2026-1518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-25069 |
|
Path Traversal in path-traversal (CVE-2026-25069)
path traversal in path-traversal (CVE-2026-25069). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-4686 |
|
SQL Injection in sqli (CVE-2025-4686)
SQL injection in sqli (CVE-2025-4686). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-4027 |
|
Vulnerability in dos (CVE-2024-4027)
vulnerability in dos (CVE-2024-4027). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15549 |
|
Cross-Site Scripting (XSS) in fluentcms (CVE-2025-15549)
cross-site scripting in fluentcms (CVE-2025-15549). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7714 |
|
SQL Injection in sqli (CVE-2025-7714)
SQL injection in sqli (CVE-2025-7714). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7713 |
|
Cross-Site Scripting (XSS) in globalmedya (CVE-2025-7713)
cross-site scripting in globalmedya (CVE-2025-7713). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-37015 |
|
Path Traversal in path-traversal (CVE-2020-37015)
path traversal in path-traversal (CVE-2020-37015). Confidential information can be exposed externally.
|
| CVE-2020-37004 |
|
SQL Injection in sqli (CVE-2020-37004)
SQL injection in sqli (CVE-2020-37004). Confidential information can be exposed externally.
|
| CVE-2020-37002 |
|
OS Command Injection in CVE-2020-37002 (CVE-2020-37002)
OS command injection in CVE-2020-37002 (CVE-2020-37002). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71001 |
|
Out-of-Bounds Read in dos (CVE-2025-71001)
vulnerability in dos (CVE-2025-71001). Risk of unauthorized operations or information disclosure.
|