Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-72636 |
|
Vulnerability in dos (CVE-2026-72636)
vulnerability in dos (CVE-2026-72636). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72642 |
|
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models...
The native inference process that Elasticsearch uses to evaluate uploaded machine learning models...
|
| CVE-2026-72630 |
|
Authorization Flaw in privilege-escalation (CVE-2026-72630)
vulnerability in privilege-escalation (CVE-2026-72630). Confidential information can be exposed externally.
|
| CVE-2026-72631 |
|
Privilege Escalation in privilege-escalation (CVE-2026-72631)
vulnerability in privilege-escalation (CVE-2026-72631). Data can be tampered with by attackers.
|
| CVE-2026-49096 |
|
Vulnerability in dos (CVE-2026-49096)
vulnerability in dos (CVE-2026-49096). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49089 |
|
Vulnerability in dos (CVE-2026-49089)
vulnerability in dos (CVE-2026-49089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19746 |
|
Vulnerability in dos (CVE-2026-19746)
vulnerability in dos (CVE-2026-19746). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-19745 |
|
Vulnerability in dos (CVE-2026-19745)
vulnerability in dos (CVE-2026-19745). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18846 |
|
Out-of-Bounds Write in dos (CVE-2026-18846)
out-of-bounds write in dos (CVE-2026-18846). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17229 |
|
Vulnerability in dos (CVE-2026-17229)
vulnerability in dos (CVE-2026-17229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17223 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
|
| CVE-2026-17043 |
|
Path Traversal in path-traversal (CVE-2026-17043)
path traversal in path-traversal (CVE-2026-17043). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17069 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-17069)
vulnerability in csrf (CVE-2026-17069). Confidential information can be exposed externally.
|
| CVE-2026-17199 |
|
Vulnerability in dos (CVE-2026-17199)
vulnerability in dos (CVE-2026-17199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17029 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out...
|
| CVE-2026-17004 |
|
Vulnerability in dos (CVE-2026-17004)
vulnerability in dos (CVE-2026-17004). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16982 |
|
Out-of-Bounds Write in dos (CVE-2026-16982)
out-of-bounds write in dos (CVE-2026-16982). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16987 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to...
|
| CVE-2026-16975 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
|
| CVE-2026-16908 |
|
Path Traversal in path-traversal (CVE-2026-16908)
path traversal in path-traversal (CVE-2026-16908). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16961 |
|
SQL Injection in sqli (CVE-2026-16961)
SQL injection in sqli (CVE-2026-16961). Confidential information can be exposed externally.
|
| CVE-2026-16887 |
|
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
IBM i 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.
|
| CVE-2026-16868 |
|
Vulnerability in dos (CVE-2026-16868)
vulnerability in dos (CVE-2026-16868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16861 |
|
Out-of-Bounds Read in dos (CVE-2026-16861)
vulnerability in dos (CVE-2026-16861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16815 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and...
|
| CVE-2026-16722 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized...
|
| CVE-2026-14525 |
|
Vulnerability in ibm (CVE-2026-14525)
vulnerability in ibm (CVE-2026-14525). Confidential information can be exposed externally.
|
| CVE-2026-16692 |
|
Out-of-Bounds Write in dos (CVE-2026-16692)
out-of-bounds write in dos (CVE-2026-16692). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16674 |
|
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary...
|
| CVE-2026-10571 |
|
Unsafe Deserialization in dos (CVE-2026-10571)
vulnerability in dos (CVE-2026-10571). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73038 |
|
Cross-Site Scripting (XSS) in CVE-2026-73038 (CVE-2026-73038)
cross-site scripting in CVE-2026-73038 (CVE-2026-73038). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73481 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73481)
vulnerability in csrf (CVE-2026-73481). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73482 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73482)
vulnerability in csrf (CVE-2026-73482). Data can be tampered with by attackers.
|
| CVE-2026-73037 |
|
Cross-Site Scripting (XSS) in CVE-2026-73037 (CVE-2026-73037)
cross-site scripting in CVE-2026-73037 (CVE-2026-73037). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72777 |
|
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
|
| CVE-2026-17220 |
|
Vulnerability in dos (CVE-2026-17220)
vulnerability in dos (CVE-2026-17220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67613 |
|
Path Traversal in c (CVE-2026-67613)
path traversal in c (CVE-2026-67613). Confidential information can be exposed externally.
|
| CVE-2019-25765 |
|
SQL Injection in sqli (CVE-2019-25765)
SQL injection in sqli (CVE-2019-25765). Confidential information can be exposed externally.
|
| CVE-2026-59109 |
|
Vulnerability in sqli (CVE-2026-59109)
vulnerability in sqli (CVE-2026-59109). Successful exploitation can lead to full system takeover.
|
| CVE-2024-58374 |
|
SQL Injection in sqli (CVE-2024-58374)
SQL injection in sqli (CVE-2024-58374). Confidential information can be exposed externally.
|
| CVE-2026-55402 |
|
Out-of-Bounds Read in dos (CVE-2026-55402)
vulnerability in dos (CVE-2026-55402). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12236 |
|
Vulnerability in c (CVE-2026-12236)
vulnerability in c (CVE-2026-12236). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58508 |
|
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)
|
| CVE-2026-34491 |
|
Cross-Site Scripting (XSS) in cisa (CVE-2026-34491)
cross-site scripting in cisa (CVE-2026-34491). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7639 |
|
Unsafe Deserialization in cisa (CVE-2025-7639)
vulnerability in cisa (CVE-2025-7639). Data can be tampered with by attackers.
|
| CVE-2026-73670 |
|
SQL Injection in sqli (CVE-2026-73670)
SQL injection in sqli (CVE-2026-73670). Successful exploitation can lead to full system takeover.
|
| CVE-2026-73572 |
|
Cross-Site Scripting (XSS) in synacor (CVE-2026-73572)
cross-site scripting in synacor (CVE-2026-73572). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73573 |
|
Vulnerability in path-traversal (CVE-2026-73573)
vulnerability in path-traversal (CVE-2026-73573). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73570 KEV |
|
[KEV] OS Command Injection in Synacor zimbra-collaboration-suite (CVE-2026-73570)
OS command injection in Synacor zimbra-collaboration-suite (CVE-2026-73570). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2026-73575 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-73575)
vulnerability in csrf (CVE-2026-73575). Risk of unauthorized operations or information disclosure.
|