Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-73257 |
|
Vulnerability in c (CVE-2026-73257)
vulnerability in c (CVE-2026-73257). Confidential information can be exposed externally.
|
| CVE-2026-73256 |
|
Vulnerability in c (CVE-2026-73256)
vulnerability in c (CVE-2026-73256). Confidential information can be exposed externally.
|
| CVE-2026-63385 |
|
Vulnerability in c (CVE-2026-63385)
vulnerability in c (CVE-2026-63385). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63379 |
|
Vulnerability in c (CVE-2026-63379)
vulnerability in c (CVE-2026-63379). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63382 |
|
Vulnerability in c (CVE-2026-63382)
vulnerability in c (CVE-2026-63382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55087 |
|
Cross-Site Scripting (XSS) in ep_etherpad-lite (CVE-2026-55087)
cross-site scripting in ep_etherpad-lite (CVE-2026-55087). Risk of unauthorized operations or information disclosure. Exploitable via ``String.prototype.replaceAll``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-62899 |
|
Vulnerability in Microsoft.NETCore.App.Runtime.linux-arm (CVE-2026-62899)
vulnerability in Microsoft.NETCore.App.Runtime.linux-arm (CVE-2026-62899). Confidential information can be exposed externally. Mitigation: upgrade to `8.0.30` or later.
|
| CVE-2026-71554 |
|
Vulnerability in h2 (CVE-2026-71554)
vulnerability in h2 (CVE-2026-71554). Risk of unauthorized operations or information disclosure. Exploitable via `Host header`. Mitigation: upgrade to `4.4.1` or later.
|
| CVE-2026-58044 |
|
Vulnerability in CVE-2026-58044 (CVE-2026-58044)
vulnerability in CVE-2026-58044 (CVE-2026-58044). Risk of unauthorized operations or information disclosure. Exploitable via ``IncomingMessage``.
|
| CVE-2026-69243 |
|
Vulnerability in aiohttp (CVE-2026-69243)
vulnerability in aiohttp (CVE-2026-69243). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.14.2` or later.
|
| CVE-2026-67182 |
|
Vulnerability in CVE-2026-67182 (CVE-2026-67182)
vulnerability in CVE-2026-67182 (CVE-2026-67182). Data can be tampered with by attackers.
|
| CVE-2026-38969 |
|
Vulnerability in CVE-2026-38969 (CVE-2026-38969)
vulnerability in CVE-2026-38969 (CVE-2026-38969). Data can be tampered with by attackers.
|
| CVE-2026-58055 |
|
Vulnerability in c (CVE-2026-58055)
vulnerability in c (CVE-2026-58055). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48979 |
|
Vulnerability in php-standard-library/h2 (CVE-2026-48979)
vulnerability in php-standard-library/h2 (CVE-2026-48979). Data can be tampered with by attackers. Exploitable via ``StreamException``. Mitigation: upgrade to `6.2.1` or later.
|
| CVE-2026-52845 |
|
Authentication Bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845)
authentication bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845). Confidential information can be exposed externally. Exploitable via `GET /index.php`. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-53538 |
|
Vulnerability in python-multipart (CVE-2026-53538)
vulnerability in python-multipart (CVE-2026-53538). Risk of unauthorized operations or information disclosure. Exploitable via ``QuerystringParser``. Mitigation: upgrade to `0.0.30` or later.
|
| CVE-2026-45372 |
|
Vulnerability in c (CVE-2026-45372)
vulnerability in c (CVE-2026-45372). Data can be tampered with by attackers. Mitigation: upgrade to `0.44.0` or later.
|
| CVE-2026-47676 |
|
Vulnerability in hono (CVE-2026-47676)
vulnerability in hono (CVE-2026-47676). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-46342 |
|
Cross-Site Scripting (XSS) in nuxt (CVE-2026-46342)
cross-site scripting in nuxt (CVE-2026-46342). Risk of unauthorized operations or information disclosure. Exploitable via ``props``. Mitigation: upgrade to `4.4.6` or later.
|
| CVE-2026-40175 |
|
Vulnerability in axios (CVE-2026-40175)
vulnerability in axios (CVE-2026-40175). Risk of unauthorized operations or information disclosure. Exploitable via `GET /pings`. Mitigation: upgrade to `0.31.0` or later.
|
| CVE-2026-31842 |
|
Vulnerability in c (CVE-2026-31842)
vulnerability in c (CVE-2026-31842). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34441 |
|
Vulnerability in c (CVE-2026-34441)
vulnerability in c (CVE-2026-34441). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-61884 KEV |
|
[KEV] Path Traversal in Oracle e-business-suite (CVE-2025-61884)
path traversal in Oracle e-business-suite (CVE-2025-61884). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
|
| CVE-2015-5740 |
|
Vulnerability in golang (CVE-2015-5740)
vulnerability in golang (CVE-2015-5740). Successful exploitation can lead to full system takeover.
|
| CVE-2015-5739 |
|
Vulnerability in golang (CVE-2015-5739)
vulnerability in golang (CVE-2015-5739). Successful exploitation can lead to full system takeover.
|