Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-77634 |
|
Vulnerability in CVE-2026-77634 (CVE-2026-77634)
vulnerability in CVE-2026-77634 (CVE-2026-77634). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75542 |
|
Authorization Flaw in CVE-2026-75542 (CVE-2026-75542)
vulnerability in CVE-2026-75542 (CVE-2026-75542). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56136 |
|
Out-of-Bounds Read in c (CVE-2026-56136)
vulnerability in c (CVE-2026-56136). Confidential information can be exposed externally.
|
| CVE-2026-56135 |
|
Vulnerability in c (CVE-2026-56135)
vulnerability in c (CVE-2026-56135). Successful exploitation can lead to full system takeover.
|
| CVE-2026-78555 |
|
Information Disclosure in CVE-2026-78555 (CVE-2026-78555)
vulnerability in CVE-2026-78555 (CVE-2026-78555). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78553 |
|
Vulnerability in flask (CVE-2026-78553)
vulnerability in flask (CVE-2026-78553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78551 |
|
Vulnerability in dos (CVE-2026-78551)
vulnerability in dos (CVE-2026-78551). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78430 |
|
Command Injection in CVE-2026-78430 (CVE-2026-78430)
command injection in CVE-2026-78430 (CVE-2026-78430). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77923 |
|
Authorization Flaw in CVE-2026-77923 (CVE-2026-77923)
vulnerability in CVE-2026-77923 (CVE-2026-77923). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-77310 |
|
SSRF (Server-Side Request Forgery) in csharp (CVE-2026-77310)
SSRF in csharp (CVE-2026-77310). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76816 |
|
Vulnerability in CVE-2026-76816 (CVE-2026-76816)
vulnerability in CVE-2026-76816 (CVE-2026-76816). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75369 |
|
Out-of-Bounds Read in dos (CVE-2026-75369)
vulnerability in dos (CVE-2026-75369). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75509 |
|
Vulnerability in CVE-2026-75509 (CVE-2026-75509)
vulnerability in CVE-2026-75509 (CVE-2026-75509). Data can be tampered with by attackers.
|
| CVE-2026-75368 |
|
Vulnerability in dos (CVE-2026-75368)
vulnerability in dos (CVE-2026-75368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-72703 |
|
Vulnerability in CVE-2026-72703 (CVE-2026-72703)
vulnerability in CVE-2026-72703 (CVE-2026-72703). Data can be tampered with by attackers.
|
| CVE-2026-72704 |
|
Vulnerability in CVE-2026-72704 (CVE-2026-72704)
vulnerability in CVE-2026-72704 (CVE-2026-72704). Data can be tampered with by attackers.
|
| CVE-2026-72705 |
|
Vulnerability in CVE-2026-72705 (CVE-2026-72705)
vulnerability in CVE-2026-72705 (CVE-2026-72705). Data can be tampered with by attackers.
|
| CVE-2026-72714 |
|
Vulnerability in CVE-2026-72714 (CVE-2026-72714)
vulnerability in CVE-2026-72714 (CVE-2026-72714). Data can be tampered with by attackers.
|
| CVE-2026-72711 |
|
Vulnerability in CVE-2026-72711 (CVE-2026-72711)
vulnerability in CVE-2026-72711 (CVE-2026-72711). Data can be tampered with by attackers. Mitigation: upgrade to `4.32.2` or later.
|
| CVE-2026-71511 |
|
Vulnerability in CVE-2026-71511 (CVE-2026-71511)
vulnerability in CVE-2026-71511 (CVE-2026-71511). Confidential information can be exposed externally.
|
| CVE-2026-71510 |
|
Authorization Flaw in sqli (CVE-2026-71510)
vulnerability in sqli (CVE-2026-71510). Confidential information can be exposed externally.
|
| CVE-2026-61419 |
|
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability....
|
| CVE-2020-37268 |
|
Vulnerability in CVE-2020-37268 (CVE-2020-37268)
vulnerability in CVE-2020-37268 (CVE-2020-37268). Data can be tampered with by attackers.
|
| CVE-2026-78541 |
|
OS Command Injection in CVE-2026-78541 (CVE-2026-78541)
OS command injection in CVE-2026-78541 (CVE-2026-78541). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75370 |
|
Out-of-Bounds Read in dos (CVE-2026-75370)
vulnerability in dos (CVE-2026-75370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75371 |
|
Vulnerability in dos (CVE-2026-75371)
vulnerability in dos (CVE-2026-75371). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71509 |
|
Vulnerability in CVE-2026-71509 (CVE-2026-71509)
vulnerability in CVE-2026-71509 (CVE-2026-71509). Data can be tampered with by attackers.
|
| CVE-2026-71508 |
|
Vulnerability in CVE-2026-71508 (CVE-2026-71508)
vulnerability in CVE-2026-71508 (CVE-2026-71508). Data can be tampered with by attackers.
|
| CVE-2026-71506 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
| CVE-2026-71504 |
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
| CVE-2026-71503 |
|
Cross-Site Scripting (XSS) in CVE-2026-71503 (CVE-2026-71503)
cross-site scripting in CVE-2026-71503 (CVE-2026-71503). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40877 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
| CVE-2026-39975 |
|
Code Injection in CVE-2026-39975 (CVE-2026-39975)
code injection in CVE-2026-39975 (CVE-2026-39975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30864 |
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
| CVE-2025-26238 |
|
Code Injection in CVE-2025-26238 (CVE-2025-26238)
code injection in CVE-2025-26238 (CVE-2025-26238). Confidential information can be exposed externally.
|
| CVE-2025-26237 |
|
Command Injection in CVE-2025-26237 (CVE-2025-26237)
command injection in CVE-2025-26237 (CVE-2025-26237). Confidential information can be exposed externally.
|
| CVE-2026-76837 |
|
Cross-Site Scripting (XSS) in CVE-2026-76837 (CVE-2026-76837)
cross-site scripting in CVE-2026-76837 (CVE-2026-76837). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/user/account/`.
|
| CVE-2026-9254 |
|
OS Command Injection in CVE-2026-9254 (CVE-2026-9254)
OS command injection in CVE-2026-9254 (CVE-2026-9254). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-78475 |
|
Out-of-Bounds Read in dos (CVE-2026-78475)
vulnerability in dos (CVE-2026-78475). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-76838 |
|
SSRF (Server-Side Request Forgery) in laravel (CVE-2026-76838)
SSRF in laravel (CVE-2026-76838). Confidential information can be exposed externally.
|
| CVE-2026-71943 |
|
OS Command Injection in CVE-2026-71943 (CVE-2026-71943)
OS command injection in CVE-2026-71943 (CVE-2026-71943). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76836 |
|
Code Injection in CVE-2026-76836 (CVE-2026-76836)
code injection in CVE-2026-76836 (CVE-2026-76836). Successful exploitation can lead to full system takeover. Exploitable via `PUT /api/station/{station_id}/profile/edit`.
|
| CVE-2026-76072 |
|
Vulnerability in CVE-2026-76072 (CVE-2026-76072)
vulnerability in CVE-2026-76072 (CVE-2026-76072). Data can be tampered with by attackers.
|
| CVE-2026-71942 |
|
Vulnerability in dos (CVE-2026-71942)
vulnerability in dos (CVE-2026-71942). Successful exploitation can lead to full system takeover.
|
| CVE-2026-76835 |
|
Vulnerability in CVE-2026-76835 (CVE-2026-76835)
vulnerability in CVE-2026-76835 (CVE-2026-76835). Confidential information can be exposed externally.
|
| CVE-2026-71941 |
|
Vulnerability in dos (CVE-2026-71941)
vulnerability in dos (CVE-2026-71941). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71937 |
|
Vulnerability in dos (CVE-2026-71937)
vulnerability in dos (CVE-2026-71937). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71940 |
|
Vulnerability in dos (CVE-2026-71940)
vulnerability in dos (CVE-2026-71940). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71935 |
|
Vulnerability in dos (CVE-2026-71935)
vulnerability in dos (CVE-2026-71935). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71939 |
|
Vulnerability in dos (CVE-2026-71939)
vulnerability in dos (CVE-2026-71939). Successful exploitation can lead to full system takeover.
|