Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-67599 |
|
OS Command Injection in CVE-2026-67599 (CVE-2026-67599)
OS command injection in CVE-2026-67599 (CVE-2026-67599). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67598 |
|
Vulnerability in CVE-2026-67598 (CVE-2026-67598)
vulnerability in CVE-2026-67598 (CVE-2026-67598). Confidential information can be exposed externally.
|
| CVE-2026-68979 |
|
Vulnerability in apache (CVE-2026-68979)
vulnerability in apache (CVE-2026-68979). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62354 |
|
Authorization Flaw in apache (CVE-2026-62354)
vulnerability in apache (CVE-2026-62354). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58139 |
|
Authorization Flaw in CVE-2026-58139 (CVE-2026-58139)
vulnerability in CVE-2026-58139 (CVE-2026-58139). Confidential information can be exposed externally.
|
| CVE-2026-68980 |
|
Authorization Flaw in apache (CVE-2026-68980)
vulnerability in apache (CVE-2026-68980). Confidential information can be exposed externally.
|
| CVE-2026-18647 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18647 (CVE-2026-18647)
SSRF in CVE-2026-18647 (CVE-2026-18647). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18648 |
|
Path Traversal in react (CVE-2026-18648)
path traversal in react (CVE-2026-18648). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18645 |
|
Path Traversal in path-traversal (CVE-2026-18645)
path traversal in path-traversal (CVE-2026-18645). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18646 |
|
Path Traversal in path-traversal (CVE-2026-18646)
path traversal in path-traversal (CVE-2026-18646). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66296 |
|
Cross-Site Scripting (XSS) in lud (CVE-2026-66296)
cross-site scripting in lud (CVE-2026-66296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18615 |
|
Vulnerability in CVE-2026-18615 (CVE-2026-18615)
vulnerability in CVE-2026-18615 (CVE-2026-18615). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18616 |
|
Vulnerability in CVE-2026-18616 (CVE-2026-18616)
vulnerability in CVE-2026-18616 (CVE-2026-18616). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18614 |
|
Vulnerability in CVE-2026-18614 (CVE-2026-18614)
vulnerability in CVE-2026-18614 (CVE-2026-18614). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18641 |
|
Command Injection in CVE-2026-18641 (CVE-2026-18641)
command injection in CVE-2026-18641 (CVE-2026-18641). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38444 |
|
Cross-Site Scripting (XSS) in CVE-2026-38444 (CVE-2026-38444)
cross-site scripting in CVE-2026-38444 (CVE-2026-38444). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38446 |
|
Cross-Site Scripting (XSS) in CVE-2026-38446 (CVE-2026-38446)
cross-site scripting in CVE-2026-38446 (CVE-2026-38446). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18644 |
|
Path Traversal in path-traversal (CVE-2026-18644)
path traversal in path-traversal (CVE-2026-18644). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59912 |
|
Vulnerability in dell (CVE-2026-59912)
vulnerability in dell (CVE-2026-59912). Successful exploitation can lead to full system takeover.
|
| CVE-2025-15630 |
|
Vulnerability in tp-link (CVE-2025-15630)
vulnerability in tp-link (CVE-2025-15630). Confidential information can be exposed externally.
|
| CVE-2026-18631 |
|
Vulnerability in CVE-2026-18631 (CVE-2026-18631)
vulnerability in CVE-2026-18631 (CVE-2026-18631). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59913 |
|
Vulnerability in dell (CVE-2026-59913)
vulnerability in dell (CVE-2026-59913). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18632 |
|
Vulnerability in CVE-2026-18632 (CVE-2026-18632)
vulnerability in CVE-2026-18632 (CVE-2026-18632). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15628 |
|
Vulnerability in tp-link (CVE-2025-15628)
vulnerability in tp-link (CVE-2025-15628). Confidential information can be exposed externally.
|
| CVE-2025-15627 |
|
Vulnerability in tp-link (CVE-2025-15627)
vulnerability in tp-link (CVE-2025-15627). Confidential information can be exposed externally.
|
| CVE-2026-69248 |
|
Vulnerability in cryptography (CVE-2026-69248)
vulnerability in cryptography (CVE-2026-69248). Risk of unauthorized operations or information disclosure. Exploitable via ``foo.example.com``. Mitigation: upgrade to `49.0.0` or later.
|
| CVE-2026-69249 |
|
Vulnerability in cryptography (CVE-2026-69249)
vulnerability in cryptography (CVE-2026-69249). Risk of unauthorized operations or information disclosure. Exploitable via ``build_chain_inner``. Mitigation: upgrade to `49.0.0` or later.
|
| CVE-2026-69247 |
|
Vulnerability in cryptography (CVE-2026-69247)
vulnerability in cryptography (CVE-2026-69247). Risk of unauthorized operations or information disclosure. Exploitable via ``pkcs7_decrypt_der``. Mitigation: upgrade to `50.0.0` or later.
|
| CVE-2026-66065 |
|
Vulnerability in CVE-2026-66065 (CVE-2026-66065)
vulnerability in CVE-2026-66065 (CVE-2026-66065). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69246 |
|
Vulnerability in guzzlehttp/guzzle (CVE-2026-69246)
vulnerability in guzzlehttp/guzzle (CVE-2026-69246). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `7.15.2` or later.
|
| CVE-2026-69244 |
|
Out-of-Bounds Read in aiohttp (CVE-2026-69244)
vulnerability in aiohttp (CVE-2026-69244). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.3` or later.
|
| CVE-2026-69243 |
|
Vulnerability in aiohttp (CVE-2026-69243)
vulnerability in aiohttp (CVE-2026-69243). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.2` or later.
|
| CVE-2026-69240 |
|
SQL Injection in sequelize (CVE-2026-69240)
SQL injection in sequelize (CVE-2026-69240). Successful exploitation can lead to full system takeover. Exploitable via ``oracle``. Mitigation: upgrade to `6.37.4` or later.
|
| CVE-2026-69192 |
|
Vulnerability in ip-address (CVE-2026-69192)
vulnerability in ip-address (CVE-2026-69192). Risk of unauthorized operations or information disclosure. Exploitable via ``Address4``. Mitigation: upgrade to `10.3.1` or later.
|
| CVE-2026-69198 |
|
Vulnerability in ip-address (CVE-2026-69198)
vulnerability in ip-address (CVE-2026-69198). Risk of unauthorized operations or information disclosure. Exploitable via ``isInSubnet``. Mitigation: upgrade to `10.2.2` or later.
|
| CVE-2026-18655 |
|
Vulnerability in Amazon aws (CVE-2026-18655)
vulnerability in Amazon aws (CVE-2026-18655). Confidential information can be exposed externally.
|
| CVE-2026-69185 |
|
Vulnerability in socket.io-parser (CVE-2026-69185)
vulnerability in socket.io-parser (CVE-2026-69185). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.3.6` or later.
|
| CVE-2026-18612 |
|
Vulnerability in CVE-2026-18612 (CVE-2026-18612)
vulnerability in CVE-2026-18612 (CVE-2026-18612). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40717 |
|
Vulnerability in dell (CVE-2026-40717)
vulnerability in dell (CVE-2026-40717). Data can be tampered with by attackers.
|
| CVE-2025-9291 |
|
Vulnerability in tp-link (CVE-2025-9291)
vulnerability in tp-link (CVE-2025-9291). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18613 |
|
Vulnerability in CVE-2026-18613 (CVE-2026-18613)
vulnerability in CVE-2026-18613 (CVE-2026-18613). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61524 |
|
Unrestricted File Upload in CVE-2026-61524 (CVE-2026-61524)
vulnerability in CVE-2026-61524 (CVE-2026-61524). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61523 |
|
Code Injection in CVE-2026-61523 (CVE-2026-61523)
code injection in CVE-2026-61523 (CVE-2026-61523). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39932 |
|
Vulnerability in open-emr (CVE-2026-39932)
vulnerability in open-emr (CVE-2026-39932). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61372 |
|
Path Traversal in apache (CVE-2026-61372)
path traversal in apache (CVE-2026-61372). Confidential information can be exposed externally.
|
| CVE-2026-18610 |
|
Authentication Bypass in CVE-2026-18610 (CVE-2026-18610)
authentication bypass in CVE-2026-18610 (CVE-2026-18610). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41453 |
|
SQL Injection in sqli (CVE-2026-41453)
SQL injection in sqli (CVE-2026-41453). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67612 |
|
Cross-Site Scripting (XSS) in CVE-2026-67612 (CVE-2026-67612)
cross-site scripting in CVE-2026-67612 (CVE-2026-67612). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18718 |
|
Vulnerability in CVE-2026-18718 (CVE-2026-18718)
vulnerability in CVE-2026-18718 (CVE-2026-18718). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18607 |
|
Buffer Overflow in CVE-2026-18607 (CVE-2026-18607)
vulnerability in CVE-2026-18607 (CVE-2026-18607). Successful exploitation can lead to full system takeover.
|