Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-75089 |
|
Vulnerability in sqli (CVE-2026-75089)
vulnerability in sqli (CVE-2026-75089). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75086 |
|
Vulnerability in sqli (CVE-2026-75086)
vulnerability in sqli (CVE-2026-75086). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75087 |
|
Vulnerability in sqli (CVE-2026-75087)
vulnerability in sqli (CVE-2026-75087). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75079 |
|
Vulnerability in sqli (CVE-2026-75079)
vulnerability in sqli (CVE-2026-75079). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75080 |
|
Vulnerability in sqli (CVE-2026-75080)
vulnerability in sqli (CVE-2026-75080). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67919 |
|
Code Injection in CVE-2026-67919 (CVE-2026-67919)
code injection in CVE-2026-67919 (CVE-2026-67919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75078 |
|
Cross-Site Scripting (XSS) in CVE-2026-75078 (CVE-2026-75078)
cross-site scripting in CVE-2026-75078 (CVE-2026-75078). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67960 |
|
Code Injection in CVE-2026-67960 (CVE-2026-67960)
code injection in CVE-2026-67960 (CVE-2026-67960). Successful exploitation can lead to full system takeover.
|
| CVE-2026-75077 |
|
Cross-Site Scripting (XSS) in c (CVE-2026-75077)
cross-site scripting in c (CVE-2026-75077). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64782 |
|
Vulnerability in c (CVE-2026-64782)
vulnerability in c (CVE-2026-64782). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64781 |
|
Vulnerability in c (CVE-2026-64781)
vulnerability in c (CVE-2026-64781). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-64779 |
|
Vulnerability in c (CVE-2026-64779)
vulnerability in c (CVE-2026-64779). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-43794 |
|
Buffer Overflow in c (CVE-2026-43794)
vulnerability in c (CVE-2026-43794). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64849 KEV |
|
[KEV] SSRF (Server-Side Request Forgery) in mlflow (CVE-2026-64849)
SSRF in mlflow (CVE-2026-64849). Confidential information can be exposed externally. Exploitable via `POST /api/2.0/mlflow/webhooks/{id}/test`. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `3.15.0` or later.
|
| CVE-2026-56677 |
|
Vulnerability in 9router (CVE-2026-56677)
vulnerability in 9router (CVE-2026-56677). Data can be tampered with by attackers. Exploitable via `POST /api/auth/oidc/test`.
|
| CVE-2026-75531 |
|
Cross-Site Scripting (XSS) in CVE-2026-75531 (CVE-2026-75531)
cross-site scripting in CVE-2026-75531 (CVE-2026-75531). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75105 |
|
Vulnerability in CVE-2026-75105 (CVE-2026-75105)
vulnerability in CVE-2026-75105 (CVE-2026-75105). Confidential information can be exposed externally.
|
| CVE-2026-65976 |
|
Vulnerability in cpp (CVE-2026-65976)
vulnerability in cpp (CVE-2026-65976). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-65832 |
|
Out-of-Bounds Read in cpp (CVE-2026-65832)
vulnerability in cpp (CVE-2026-65832). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63409 |
|
Out-of-Bounds Read in cpp (CVE-2026-63409)
vulnerability in cpp (CVE-2026-63409). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34789 |
|
Code Injection in cpp (CVE-2026-34789)
code injection in cpp (CVE-2026-34789). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34399 |
|
Vulnerability in CVE-2026-34399 (CVE-2026-34399)
vulnerability in CVE-2026-34399 (CVE-2026-34399). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34398 |
|
Vulnerability in CVE-2026-34398 (CVE-2026-34398)
vulnerability in CVE-2026-34398 (CVE-2026-34398). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40506 |
|
Path Traversal in path-traversal (CVE-2026-40506)
path traversal in path-traversal (CVE-2026-40506). Data can be tampered with by attackers.
|
| CVE-2026-75014 |
|
Vulnerability in sqli (CVE-2026-75014)
vulnerability in sqli (CVE-2026-75014). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-75012 |
|
Vulnerability in c (CVE-2026-75012)
vulnerability in c (CVE-2026-75012). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-74234 |
|
Vulnerability in CVE-2026-74234 (CVE-2026-74234)
vulnerability in CVE-2026-74234 (CVE-2026-74234). Confidential information can be exposed externally.
|
| CVE-2026-71553 |
|
Vulnerability in dos (CVE-2026-71553)
vulnerability in dos (CVE-2026-71553). Risk of unauthorized operations or information disclosure. Exploitable via `PATCH /api/v1/article/`.
|
| CVE-2026-63670 |
|
Cross-Site Scripting (XSS) in CVE-2026-63670 (CVE-2026-63670)
cross-site scripting in CVE-2026-63670 (CVE-2026-63670). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68004 |
|
Vulnerability in cpp (CVE-2026-68004)
vulnerability in cpp (CVE-2026-68004). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54758 |
|
Vulnerability in cpp (CVE-2026-54758)
vulnerability in cpp (CVE-2026-54758). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57485 |
|
Information Disclosure in CVE-2026-57485 (CVE-2026-57485)
vulnerability in CVE-2026-57485 (CVE-2026-57485). Confidential information can be exposed externally.
|
| CVE-2026-63669 |
|
Vulnerability in CVE-2026-63669 (CVE-2026-63669)
vulnerability in CVE-2026-63669 (CVE-2026-63669). Data can be tampered with by attackers.
|
| CVE-2026-63667 |
|
Path Traversal in CVE-2026-63667 (CVE-2026-63667)
path traversal in CVE-2026-63667 (CVE-2026-63667). Confidential information can be exposed externally.
|
| CVE-2026-75011 |
|
Vulnerability in CVE-2026-75011 (CVE-2026-75011)
vulnerability in CVE-2026-75011 (CVE-2026-75011). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50769 |
|
SQL Injection in sqli (CVE-2026-50769)
SQL injection in sqli (CVE-2026-50769). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71979 |
|
Vulnerability in cpp (CVE-2026-71979)
vulnerability in cpp (CVE-2026-71979). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71980 |
|
Out-of-Bounds Read in c (CVE-2026-71980)
vulnerability in c (CVE-2026-71980). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73523 |
|
Vulnerability in c (CVE-2026-73523)
vulnerability in c (CVE-2026-73523). Confidential information can be exposed externally.
|
| CVE-2026-59893 |
|
Vulnerability in sqlparse (CVE-2026-59893)
vulnerability in sqlparse (CVE-2026-59893). Risk of unauthorized operations or information disclosure. Exploitable via ``SQL_REGEX``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-54284 |
|
Vulnerability in sqlparse (CVE-2026-54284)
vulnerability in sqlparse (CVE-2026-54284). Risk of unauthorized operations or information disclosure. Exploitable via ``sqlparse``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-47698 |
|
Vulnerability in vm2 (CVE-2026-47698)
vulnerability in vm2 (CVE-2026-47698). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.11.6` or later.
|
| CVE-2026-47686 |
|
Vulnerability in vm2 (CVE-2026-47686)
vulnerability in vm2 (CVE-2026-47686). Successful exploitation can lead to full system takeover. Exploitable via ``process``. Mitigation: upgrade to `3.11.6` or later.
|
| CVE-2026-47683 |
|
Vulnerability in vm2 (CVE-2026-47683)
vulnerability in vm2 (CVE-2026-47683). Risk of unauthorized operations or information disclosure. Exploitable via ``bufferAllocLimit``. Mitigation: upgrade to `3.11.6` or later.
|
| CVE-2026-71491 |
|
Vulnerability in sqlparse (CVE-2026-71491)
vulnerability in sqlparse (CVE-2026-71491). Risk of unauthorized operations or information disclosure. Exploitable via ``group_comments``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-59894 |
|
Code Injection in sqlparse (CVE-2026-59894)
code injection in sqlparse (CVE-2026-59894). Risk of unauthorized operations or information disclosure. Exploitable via ``EVOHUNT_OUTPUT_FORMAT_INJECTION_VERIFIED``. Mitigation: upgrade to `0.6.0` or later.
|
| CVE-2026-9771 |
|
Vulnerability in c (CVE-2026-9771)
vulnerability in c (CVE-2026-9771). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12630 |
|
Out-of-Bounds Read in c (CVE-2026-12630)
vulnerability in c (CVE-2026-12630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12629 |
|
Vulnerability in c (CVE-2026-12629)
vulnerability in c (CVE-2026-12629). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12519 |
|
Out-of-Bounds Write in c (CVE-2026-12519)
out-of-bounds write in c (CVE-2026-12519). Risk of unauthorized operations or information disclosure.
|