Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-21884 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-21884)
cross-site scripting in react (CVE-2026-21884). Confidential information can be exposed externally.
|
| CVE-2025-9222 |
|
Cross-Site Scripting (XSS) in gitlab (CVE-2025-9222)
cross-site scripting in gitlab (CVE-2025-9222). Confidential information can be exposed externally. Mitigation: upgrade to `18.5.5, 18.6.3, 18.7.1` or later.
|
| CVE-2025-65518 |
|
Vulnerability in dos (CVE-2025-65518)
vulnerability in dos (CVE-2025-65518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-21639 |
|
Vulnerability in ui (CVE-2026-21639)
vulnerability in ui (CVE-2026-21639). Successful exploitation can lead to full system takeover.
|
| CVE-2025-50334 |
|
Vulnerability in dos (CVE-2025-50334)
vulnerability in dos (CVE-2025-50334). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-69262 |
|
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings....
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code E...
|
| CVE-2025-69264 |
|
Vulnerability in pnpm (CVE-2025-69264)
vulnerability in pnpm (CVE-2025-69264). Successful exploitation can lead to full system takeover.
|
| CVE-2025-69263 |
|
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve differe...
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package w...
|
| CVE-2025-69223 |
|
Vulnerability in aiohttp (CVE-2025-69223)
vulnerability in aiohttp (CVE-2025-69223). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.13.3` or later.
|
| CVE-2025-68428 |
|
Vulnerability in path-traversal (CVE-2025-68428)
vulnerability in path-traversal (CVE-2025-68428). Confidential information can be exposed externally. Exploitable via ``addImage``.
|
| CVE-2026-0621 |
|
Vulnerability in @modelcontextprotocol/sdk (CVE-2026-0621)
vulnerability in @modelcontextprotocol/sdk (CVE-2026-0621). Risk of unauthorized operations or information disclosure. Exploitable via ``UriTemplate``. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2025-67269 |
|
Vulnerability in c (CVE-2025-67269)
vulnerability in c (CVE-2025-67269). Risk of unauthorized operations or information disclosure. Exploitable via ``ffa1d6f40bca0b035fc7f5e563160ebb67199da7``.
|
| CVE-2025-67160 |
|
Path Traversal in path-traversal (CVE-2025-67160)
path traversal in path-traversal (CVE-2025-67160). Confidential information can be exposed externally.
|
| CVE-2025-67158 |
|
Authentication Bypass in revotech (CVE-2025-67158)
authentication bypass in revotech (CVE-2025-67158). Confidential information can be exposed externally.
|
| CVE-2025-11157 |
|
Unsafe Deserialization in feast (CVE-2025-11157)
vulnerability in feast (CVE-2025-11157). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.54.0` or later.
|
| CVE-2025-66824 |
|
Cross-Site Scripting (XSS) in trueconf (CVE-2025-66824)
cross-site scripting in trueconf (CVE-2025-66824). Confidential information can be exposed externally.
|
| CVE-2025-2307 |
|
Cross-Site Scripting (XSS) in CVE-2025-2307 (CVE-2025-2307)
cross-site scripting in CVE-2025-2307 (CVE-2025-2307). Data can be tampered with by attackers.
|
| CVE-2025-2405 |
|
Cross-Site Scripting (XSS) in CVE-2025-2405 (CVE-2025-2405)
cross-site scripting in CVE-2025-2405 (CVE-2025-2405). Data can be tampered with by attackers.
|
| CVE-2025-2406 |
|
Cross-Site Scripting (XSS) in CVE-2025-2406 (CVE-2025-2406)
cross-site scripting in CVE-2025-2406 (CVE-2025-2406). Data can be tampered with by attackers.
|
| CVE-2025-2515 |
|
Authorization Flaw in privilege-escalation (CVE-2025-2515)
vulnerability in privilege-escalation (CVE-2025-2515). Successful exploitation can lead to full system takeover.
|
| CVE-2025-2155 |
|
Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade...
Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade...
|
| CVE-2025-65865 |
|
Vulnerability in dos (CVE-2025-65865)
vulnerability in dos (CVE-2025-65865). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13183 |
|
Cross-Site Scripting (XSS) in CVE-2025-13183 (CVE-2025-13183)
cross-site scripting in CVE-2025-13183 (CVE-2025-13183). Confidential information can be exposed externally.
|
| CVE-2025-34290 |
|
Vulnerability in c (CVE-2025-34290)
vulnerability in c (CVE-2025-34290). Successful exploitation can lead to full system takeover.
|
| CVE-2025-14300 |
|
Vulnerability in dos (CVE-2025-14300)
vulnerability in dos (CVE-2025-14300). Data can be tampered with by attackers.
|
| CVE-2025-1927 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-1927)
vulnerability in csrf (CVE-2025-1927). Data can be tampered with by attackers.
|
| CVE-2025-68246 |
|
Vulnerability in dos (CVE-2025-68246)
vulnerability in dos (CVE-2025-68246). Risk of unauthorized operations or information disclosure.
|
| CVE-2023-53888 |
|
Code Injection in zomp (CVE-2023-53888)
code injection in zomp (CVE-2023-53888). Successful exploitation can lead to full system takeover.
|
| CVE-2024-44599 |
|
FNT Command 13.4.0 is vulnerable to Directory Traversal.
FNT Command 13.4.0 is vulnerable to Directory Traversal.
|
| CVE-2025-63895 |
|
Vulnerability in dos (CVE-2025-63895)
vulnerability in dos (CVE-2025-63895). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-34429 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-34429)
vulnerability in csrf (CVE-2025-34429). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-34410 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-34410)
vulnerability in csrf (CVE-2025-34410). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-7073 |
|
Vulnerability in c (CVE-2025-7073)
vulnerability in c (CVE-2025-7073). Successful exploitation can lead to full system takeover.
|
| CVE-2025-1161 |
|
Vulnerability in privilege-escalation (CVE-2025-1161)
vulnerability in privilege-escalation (CVE-2025-1161). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61258 |
|
Vulnerability in dos (CVE-2025-61258)
vulnerability in dos (CVE-2025-61258). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-64666 |
|
Vulnerability in microsoft (CVE-2025-64666)
vulnerability in microsoft (CVE-2025-64666). Successful exploitation can lead to full system takeover.
|
| CVE-2025-34291 KEV |
|
[KEV] Vulnerability in langflow (CVE-2025-34291)
vulnerability in langflow (CVE-2025-34291). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `1.7.0` or later.
|
| CVE-2025-64053 |
|
Vulnerability in dos (CVE-2025-64053)
vulnerability in dos (CVE-2025-64053). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-64057 |
|
Path Traversal in path-traversal (CVE-2025-64057)
path traversal in path-traversal (CVE-2025-64057). Data can be tampered with by attackers.
|
| CVE-2025-11838 |
|
Vulnerability in dos (CVE-2025-11838)
vulnerability in dos (CVE-2025-11838). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-3884 |
|
Vulnerability in dos (CVE-2024-3884)
vulnerability in dos (CVE-2024-3884). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-63365 |
|
Path Traversal in path-traversal (CVE-2025-63365)
path traversal in path-traversal (CVE-2025-63365). Confidential information can be exposed externally.
|
| CVE-2025-51741 |
|
Vulnerability in dos (CVE-2025-51741)
vulnerability in dos (CVE-2025-51741). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13502 |
|
Out-of-Bounds Read in dos (CVE-2025-13502)
vulnerability in dos (CVE-2025-13502). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56400 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-56400)
vulnerability in csrf (CVE-2025-56400). Successful exploitation can lead to full system takeover.
|
| CVE-2025-56401 |
|
ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
|
| CVE-2025-0643 |
|
Cross-Site Scripting (XSS) in CVE-2025-0643 (CVE-2025-0643)
cross-site scripting in CVE-2025-0643 (CVE-2025-0643). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61662 |
|
Use-After-Free in dos (CVE-2025-61662)
vulnerability in dos (CVE-2025-61662). Successful exploitation can lead to full system takeover.
|
| CVE-2025-8855 |
|
Vulnerability in CVE-2025-8855 (CVE-2025-8855)
vulnerability in CVE-2025-8855 (CVE-2025-8855). Confidential information can be exposed externally.
|
| CVE-2025-60691 |
|
Vulnerability in dos (CVE-2025-60691)
vulnerability in dos (CVE-2025-60691). Successful exploitation can lead to full system takeover.
|