Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-41465 |
|
Path Traversal in path-traversal (CVE-2026-41465)
path traversal in path-traversal (CVE-2026-41465). Confidential information can be exposed externally.
|
| CVE-2026-40514 |
|
Vulnerability in smartertools (CVE-2026-40514)
vulnerability in smartertools (CVE-2026-40514). Confidential information can be exposed externally.
|
| CVE-2026-40022 |
|
Vulnerability in org.apache.camel:camel-platform-http-main (CVE-2026-40022)
vulnerability in org.apache.camel:camel-platform-http-main (CVE-2026-40022). Confidential information can be exposed externally. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-27172 |
|
Unsafe Deserialization in apache (CVE-2026-27172)
vulnerability in apache (CVE-2026-27172). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33453 |
|
Vulnerability in apache (CVE-2026-33453)
vulnerability in apache (CVE-2026-33453). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40858 |
|
Unsafe Deserialization in apache (CVE-2026-40858)
vulnerability in apache (CVE-2026-40858). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33454 |
|
Unsafe Deserialization in apache (CVE-2026-33454)
vulnerability in apache (CVE-2026-33454). Confidential information can be exposed externally.
|
| CVE-2026-40453 |
|
Vulnerability in org.apache.camel:camel-coap (CVE-2026-40453)
vulnerability in org.apache.camel:camel-coap (CVE-2026-40453). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-40860 |
|
Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-40860)
vulnerability in org.apache.camel:camel-jms (CVE-2026-40860). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.20.0` or later.
|
| CVE-2026-40048 |
|
Unsafe Deserialization in apache (CVE-2026-40048)
vulnerability in apache (CVE-2026-40048). Successful exploitation can lead to full system takeover. Exploitable via ``java.security.KeyPair``.
|
| CVE-2026-40473 |
|
Unsafe Deserialization in apache (CVE-2026-40473)
vulnerability in apache (CVE-2026-40473). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6786 |
|
Out-of-Bounds Read in mozilla (CVE-2026-6786)
vulnerability in mozilla (CVE-2026-6786). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6785 |
|
Out-of-Bounds Read in mozilla (CVE-2026-6785)
vulnerability in mozilla (CVE-2026-6785). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41473 |
|
Vulnerability in dos (CVE-2026-41473)
vulnerability in dos (CVE-2026-41473). Data can be tampered with by attackers.
|
| CVE-2026-41472 |
|
Cross-Site Scripting (XSS) in cyberpanel (CVE-2026-41472)
cross-site scripting in cyberpanel (CVE-2026-41472). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/ai-scanner/callback`.
|
| CVE-2026-40466 |
|
Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-40466). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
|
| CVE-2026-41044 |
|
Vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044)
vulnerability in org.apache.activemq:apache-activemq (CVE-2026-41044). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.2.5` or later.
|
| CVE-2026-21728 |
|
Vulnerability in github.com/grafana/tempo (CVE-2026-21728)
vulnerability in github.com/grafana/tempo (CVE-2026-21728). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.10.2` or later.
|
| CVE-2026-5488 |
|
Vulnerability in wordpress (CVE-2026-5488)
vulnerability in wordpress (CVE-2026-5488). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-29635 KEV |
|
[KEV] Command Injection in D-link dir-823x (CVE-2025-29635)
command injection in D-link dir-823x (CVE-2025-29635). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-7399 KEV |
|
[KEV] Path Traversal in Samsung magicinfo-9-server (CVE-2024-7399)
path traversal in Samsung magicinfo-9-server (CVE-2024-7399). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-57728 KEV |
|
[KEV] Path Traversal in Simplehelp path-traversal (CVE-2024-57728)
path traversal in Simplehelp path-traversal (CVE-2024-57728). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-57726 KEV |
|
[KEV] Vulnerability in Simplehelp auth (CVE-2024-57726)
vulnerability in Simplehelp auth (CVE-2024-57726). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-6919 |
|
Use-After-Free in google (CVE-2026-6919)
vulnerability in google (CVE-2026-6919). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6920 |
|
Out-of-Bounds Read in google (CVE-2026-6920)
vulnerability in google (CVE-2026-6920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6921 |
|
Vulnerability in google (CVE-2026-6921)
vulnerability in google (CVE-2026-6921). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39987 KEV |
|
[KEV] Vulnerability in Marimo remote-attack (CVE-2026-39987)
vulnerability in Marimo remote-attack (CVE-2026-39987). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-28950 |
|
Vulnerability in apple (CVE-2026-28950)
vulnerability in apple (CVE-2026-28950). Confidential information can be exposed externally.
|
| CVE-2026-41459 |
|
Vulnerability in path-traversal (CVE-2026-41459)
vulnerability in path-traversal (CVE-2026-41459). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34414 |
|
Path Traversal in path-traversal (CVE-2026-34414)
path traversal in path-traversal (CVE-2026-34414). Data can be tampered with by attackers.
|
| CVE-2026-34415 |
|
Vulnerability in path-traversal (CVE-2026-34415)
vulnerability in path-traversal (CVE-2026-34415). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34413 |
|
Vulnerability in path-traversal (CVE-2026-34413)
vulnerability in path-traversal (CVE-2026-34413). Data can be tampered with by attackers.
|
| CVE-2026-32885 |
|
Path Traversal in github.com/ddev/ddev (CVE-2026-32885)
path traversal in github.com/ddev/ddev (CVE-2026-32885). Data can be tampered with by attackers. Exploitable via ``os.MkdirAll``. Mitigation: upgrade to `1.25.2` or later.
|
| CVE-2026-40542 |
|
Vulnerability in apache (CVE-2026-40542)
vulnerability in apache (CVE-2026-40542). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33825 KEV |
|
[KEV] Vulnerability in Microsoft defender (CVE-2026-33825)
vulnerability in Microsoft defender (CVE-2026-33825). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-33518 |
|
Vulnerability in esri (CVE-2026-33518)
vulnerability in esri (CVE-2026-33518). Successful exploitation can lead to full system takeover.
|
| CVE-2026-33519 |
|
Vulnerability in esri (CVE-2026-33519)
vulnerability in esri (CVE-2026-33519). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30452 |
|
Vulnerability in textpattern (CVE-2026-30452)
vulnerability in textpattern (CVE-2026-30452). Data can be tampered with by attackers.
|
| CVE-2025-41029 |
|
SQL Injection in sqli (CVE-2025-41029)
SQL injection in sqli (CVE-2025-41029). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6784 |
|
Out-of-Bounds Read in mozilla (CVE-2026-6784)
vulnerability in mozilla (CVE-2026-6784). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6754 |
|
Use-After-Free in mozilla (CVE-2026-6754)
vulnerability in mozilla (CVE-2026-6754). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6746 |
|
Use-After-Free in mozilla (CVE-2026-6746)
vulnerability in mozilla (CVE-2026-6746). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6747 |
|
Use-After-Free in mozilla (CVE-2026-6747)
vulnerability in mozilla (CVE-2026-6747). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6749 |
|
Vulnerability in mozilla (CVE-2026-6749)
vulnerability in mozilla (CVE-2026-6749). Confidential information can be exposed externally.
|
| CVE-2026-6748 |
|
Vulnerability in mozilla (CVE-2026-6748)
vulnerability in mozilla (CVE-2026-6748). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6750 |
|
Privilege Escalation in privilege-escalation (CVE-2026-6750)
vulnerability in privilege-escalation (CVE-2026-6750). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6753 |
|
Buffer Overflow in mozilla (CVE-2026-6753)
vulnerability in mozilla (CVE-2026-6753). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6752 |
|
Buffer Overflow in mozilla (CVE-2026-6752)
vulnerability in mozilla (CVE-2026-6752). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6751 |
|
Vulnerability in mozilla (CVE-2026-6751)
vulnerability in mozilla (CVE-2026-6751). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-31018 |
|
Code Injection in dolibarr (CVE-2026-31018)
code injection in dolibarr (CVE-2026-31018). Successful exploitation can lead to full system takeover.
|