Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-62249 |
|
Information Disclosure in CVE-2026-62249 (CVE-2026-62249)
vulnerability in CVE-2026-62249 (CVE-2026-62249). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55227 |
|
Vulnerability in weblate (CVE-2026-55227)
vulnerability in weblate (CVE-2026-55227). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.7` or later.
|
| CVE-2026-79938 |
|
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication...
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication...
|
| CVE-2026-77652 |
|
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
|
| CVE-2026-75601 |
|
Vulnerability in CVE-2026-75601 (CVE-2026-75601)
vulnerability in CVE-2026-75601 (CVE-2026-75601). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74774 |
|
Vulnerability in dell (CVE-2026-74774)
vulnerability in dell (CVE-2026-74774). Confidential information can be exposed externally.
|
| CVE-2026-71172 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71172)
SSRF in ssrf (CVE-2026-71172). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74770 |
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
|
| CVE-2026-71054 |
|
Vulnerability in c (CVE-2026-71054)
vulnerability in c (CVE-2026-71054). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68861 |
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
|
| CVE-2026-68863 |
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
|
| CVE-2026-66003 |
|
Authorization Flaw in CVE-2026-66003 (CVE-2026-66003)
vulnerability in CVE-2026-66003 (CVE-2026-66003). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56547 |
|
Vulnerability in CVE-2026-56547 (CVE-2026-56547)
vulnerability in CVE-2026-56547 (CVE-2026-56547). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49809 |
|
SQL Injection in sqli (CVE-2026-49809)
SQL injection in sqli (CVE-2026-49809). Confidential information can be exposed externally.
|
| CVE-2026-26446 |
|
Vulnerability in dos (CVE-2026-26446)
vulnerability in dos (CVE-2026-26446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26447 |
|
Use-After-Free in dos (CVE-2026-26447)
vulnerability in dos (CVE-2026-26447). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26448 |
|
Use-After-Free in CVE-2026-26448 (CVE-2026-26448)
vulnerability in CVE-2026-26448 (CVE-2026-26448). Successful exploitation can lead to full system takeover.
|
| CVE-2026-26449 |
|
Vulnerability in CVE-2026-26449 (CVE-2026-26449)
vulnerability in CVE-2026-26449 (CVE-2026-26449). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-70290 |
|
Vulnerability in CVE-2025-70290 (CVE-2025-70290)
vulnerability in CVE-2025-70290 (CVE-2025-70290). Successful exploitation can lead to full system takeover.
|
| CVE-2026-79940 |
|
Vulnerability in CVE-2026-79940 (CVE-2026-79940)
vulnerability in CVE-2026-79940 (CVE-2026-79940). Data can be tampered with by attackers.
|
| CVE-2026-75325 |
|
Authentication Bypass in CVE-2026-75325 (CVE-2026-75325)
authentication bypass in CVE-2026-75325 (CVE-2026-75325). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71171 |
|
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of...
|
| CVE-2026-70419 |
|
OS Command Injection in CVE-2026-70419 (CVE-2026-70419)
OS command injection in CVE-2026-70419 (CVE-2026-70419). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51106 |
|
Vulnerability in cpp (CVE-2026-51106)
vulnerability in cpp (CVE-2026-51106). Confidential information can be exposed externally.
|
| CVE-2026-36851 |
|
Path Traversal in path-traversal (CVE-2026-36851)
path traversal in path-traversal (CVE-2026-36851). Confidential information can be exposed externally.
|
| CVE-2026-19485 |
|
Vulnerability in CVE-2026-19485 (CVE-2026-19485)
vulnerability in CVE-2026-19485 (CVE-2026-19485). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61165 |
|
Unrestricted File Upload in CVE-2025-61165 (CVE-2025-61165)
vulnerability in CVE-2025-61165 (CVE-2025-61165). Successful exploitation can lead to full system takeover.
|
| CVE-2025-61164 |
|
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
|
| CVE-2025-61162 |
|
Vulnerability in CVE-2025-61162 (CVE-2025-61162)
vulnerability in CVE-2025-61162 (CVE-2025-61162). Data can be tampered with by attackers.
|
| CVE-2026-80348 |
|
Vulnerability in CVE-2026-80348 (CVE-2026-80348)
vulnerability in CVE-2026-80348 (CVE-2026-80348). Successful exploitation can lead to full system takeover.
|
| CVE-2026-80200 |
|
Open Redirect in CVE-2026-80200 (CVE-2026-80200)
vulnerability in CVE-2026-80200 (CVE-2026-80200). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-80214 |
|
OS Command Injection in CVE-2026-80214 (CVE-2026-80214)
OS command injection in CVE-2026-80214 (CVE-2026-80214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58474 |
|
Code Injection in CVE-2026-58474 (CVE-2026-58474)
code injection in CVE-2026-58474 (CVE-2026-58474). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47837 |
|
Vulnerability in CVE-2026-47837 (CVE-2026-47837)
vulnerability in CVE-2026-47837 (CVE-2026-47837). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-56798 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2025-56798)
vulnerability in csrf (CVE-2025-56798). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81036 |
|
Open Redirect in CVE-2026-81036 (CVE-2026-81036)
vulnerability in CVE-2026-81036 (CVE-2026-81036). Confidential information can be exposed externally.
|
| CVE-2026-81032 |
|
Vulnerability in cpp (CVE-2026-81032)
vulnerability in cpp (CVE-2026-81032). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81035 |
|
Vulnerability in CVE-2026-81035 (CVE-2026-81035)
vulnerability in CVE-2026-81035 (CVE-2026-81035). Data can be tampered with by attackers.
|
| CVE-2026-81034 |
|
Vulnerability in CVE-2026-81034 (CVE-2026-81034)
vulnerability in CVE-2026-81034 (CVE-2026-81034). Confidential information can be exposed externally.
|
| CVE-2026-81027 |
|
Vulnerability in c (CVE-2026-81027)
vulnerability in c (CVE-2026-81027). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-80428 |
|
Unsafe Deserialization in CVE-2026-80428 (CVE-2026-80428)
vulnerability in CVE-2026-80428 (CVE-2026-80428). Successful exploitation can lead to full system takeover.
|
| CVE-2026-81030 |
|
Path Traversal in CVE-2026-81030 (CVE-2026-81030)
path traversal in CVE-2026-81030 (CVE-2026-81030). Confidential information can be exposed externally.
|
| CVE-2026-81028 |
|
Path Traversal in cpp (CVE-2026-81028)
path traversal in cpp (CVE-2026-81028). Confidential information can be exposed externally.
|
| CVE-2026-81029 |
|
Open Redirect in CVE-2026-81029 (CVE-2026-81029)
vulnerability in CVE-2026-81029 (CVE-2026-81029). Confidential information can be exposed externally.
|
| CVE-2026-80426 |
|
Cross-Site Scripting (XSS) in react (CVE-2026-80426)
cross-site scripting in react (CVE-2026-80426). Confidential information can be exposed externally.
|
| CVE-2026-80427 |
|
Vulnerability in CVE-2026-80427 (CVE-2026-80427)
vulnerability in CVE-2026-80427 (CVE-2026-80427). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48548 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-48548)
vulnerability in csrf (CVE-2026-48548). Data can be tampered with by attackers.
|
| CVE-2026-48549 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-48549)
vulnerability in csrf (CVE-2026-48549). Data can be tampered with by attackers. Exploitable via `Cookie header`.
|
| CVE-2026-54614 |
|
Vulnerability in cakephp/debug_kit (CVE-2026-54614)
vulnerability in cakephp/debug_kit (CVE-2026-54614). Risk of unauthorized operations or information disclosure. Exploitable via ``MailPreview``. Mitigation: upgrade to `5.2.4` or later.
|
| CVE-2026-54569 |
|
Vulnerability in senaite.core (CVE-2026-54569)
vulnerability in senaite.core (CVE-2026-54569). Successful exploitation can lead to full system takeover. Exploitable via `GET /senaite/bika_setup/`.
|