Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2018-25340 |
|
SQL Injection in sqli (CVE-2018-25340)
SQL injection in sqli (CVE-2018-25340). Confidential information can be exposed externally.
|
| CVE-2026-45659 KEV |
|
[KEV] Unsafe Deserialization in Microsoft deserialization (CVE-2026-45659)
vulnerability in Microsoft deserialization (CVE-2026-45659). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-5817 |
|
Vulnerability in docker (CVE-2026-5817)
vulnerability in docker (CVE-2026-5817). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5843 |
|
Vulnerability in docker (CVE-2026-5843)
vulnerability in docker (CVE-2026-5843). Successful exploitation can lead to full system takeover.
|
| CVE-2026-6406 |
|
Authorization Flaw in docker (CVE-2026-6406)
vulnerability in docker (CVE-2026-6406). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8992 |
|
Vulnerability in ivanti (CVE-2026-8992)
vulnerability in ivanti (CVE-2026-8992). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8671 |
|
Vulnerability in avantra (CVE-2026-8671)
vulnerability in avantra (CVE-2026-8671). Data can be tampered with by attackers.
|
| CVE-2026-44417 |
|
Vulnerability in org.apache.cxf:cxf-rt-transports-jms (CVE-2026-44417)
vulnerability in org.apache.cxf:cxf-rt-transports-jms (CVE-2026-44417). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.6.11` or later.
|
| CVE-2026-46640 |
|
Code Injection in twig/twig (CVE-2026-46640)
code injection in twig/twig (CVE-2026-46640). Successful exploitation can lead to full system takeover. Exploitable via ``_self``. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-8426 |
|
Cross-Site Request Forgery (CSRF) in concrete5/concrete5 (CVE-2026-8426)
vulnerability in concrete5/concrete5 (CVE-2026-8426). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-8421 |
|
Cross-Site Request Forgery (CSRF) in concrete5/concrete5 (CVE-2026-8421)
vulnerability in concrete5/concrete5 (CVE-2026-8421). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-8428 |
|
Cross-Site Request Forgery (CSRF) in concrete5/concrete5 (CVE-2026-8428)
vulnerability in concrete5/concrete5 (CVE-2026-8428). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-8417 |
|
Cross-Site Request Forgery (CSRF) in concrete5/concrete5 (CVE-2026-8417)
vulnerability in concrete5/concrete5 (CVE-2026-8417). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-8350 |
|
Authorization Flaw in concrete5/concrete5 (CVE-2026-8350)
vulnerability in concrete5/concrete5 (CVE-2026-8350). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-47102 |
|
Authorization Flaw in litellm (CVE-2026-47102)
vulnerability in litellm (CVE-2026-47102). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.83.10` or later.
|
| CVE-2026-8135 |
|
Unsafe Deserialization in concrete5/concrete5 (CVE-2026-8135)
vulnerability in concrete5/concrete5 (CVE-2026-8135). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-8134 |
|
Vulnerability in concrete5/concrete5 (CVE-2026-8134)
vulnerability in concrete5/concrete5 (CVE-2026-8134). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `9.5.1` or later.
|
| CVE-2026-47101 |
|
Authorization Flaw in litellm (CVE-2026-47101)
vulnerability in litellm (CVE-2026-47101). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.83.14` or later.
|
| CVE-2026-46638 |
|
Vulnerability in twig/twig (CVE-2026-46638)
vulnerability in twig/twig (CVE-2026-46638). Confidential information can be exposed externally. Exploitable via ``Environment``. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-48238 |
|
SQL Injection in sqli (CVE-2026-48238)
SQL injection in sqli (CVE-2026-48238). Confidential information can be exposed externally.
|
| CVE-2026-48240 |
|
SQL Injection in sqli (CVE-2026-48240)
SQL injection in sqli (CVE-2026-48240). Confidential information can be exposed externally.
|
| CVE-2026-48239 |
|
SQL Injection in sqli (CVE-2026-48239)
SQL injection in sqli (CVE-2026-48239). Confidential information can be exposed externally.
|
| CVE-2026-48236 |
|
SQL Injection in sqli (CVE-2026-48236)
SQL injection in sqli (CVE-2026-48236). Confidential information can be exposed externally.
|
| CVE-2026-48242 |
|
Vulnerability in CVE-2026-48242 (CVE-2026-48242)
vulnerability in CVE-2026-48242 (CVE-2026-48242). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48241 |
|
Vulnerability in CVE-2026-48241 (CVE-2026-48241)
vulnerability in CVE-2026-48241 (CVE-2026-48241). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48237 |
|
SQL Injection in sqli (CVE-2026-48237)
SQL injection in sqli (CVE-2026-48237). Confidential information can be exposed externally.
|
| CVE-2026-48235 |
|
SQL Injection in sqli (CVE-2026-48235)
SQL injection in sqli (CVE-2026-48235). Confidential information can be exposed externally.
|
| CVE-2026-48232 |
|
SQL Injection in sqli (CVE-2026-48232)
SQL injection in sqli (CVE-2026-48232). Confidential information can be exposed externally.
|
| CVE-2026-48233 |
|
SQL Injection in sqli (CVE-2026-48233)
SQL injection in sqli (CVE-2026-48233). Confidential information can be exposed externally.
|
| CVE-2026-48234 |
|
SQL Injection in sqli (CVE-2026-48234)
SQL injection in sqli (CVE-2026-48234). Confidential information can be exposed externally.
|
| CVE-2026-48231 |
|
SQL Injection in sqli (CVE-2026-48231)
SQL injection in sqli (CVE-2026-48231). Confidential information can be exposed externally.
|
| CVE-2026-45208 |
|
A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker...
A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker...
|
| CVE-2026-45207 |
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
|
| CVE-2026-45206 |
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
|
| CVE-2026-34930 |
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
|
| CVE-2026-34929 |
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
|
| CVE-2026-34928 |
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
|
| CVE-2026-34927 |
|
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to...
|
| CVE-2025-71214 |
|
Vulnerability in trendmicro (CVE-2025-71214)
vulnerability in trendmicro (CVE-2025-71214). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71215 |
|
Vulnerability in trendmicro (CVE-2025-71215)
vulnerability in trendmicro (CVE-2025-71215). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71217 |
|
Vulnerability in trendmicro (CVE-2025-71217)
vulnerability in trendmicro (CVE-2025-71217). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71216 |
|
Vulnerability in trendmicro (CVE-2025-71216)
vulnerability in trendmicro (CVE-2025-71216). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71213 |
|
Vulnerability in trendmicro (CVE-2025-71213)
vulnerability in trendmicro (CVE-2025-71213). Successful exploitation can lead to full system takeover.
|
| CVE-2025-71212 |
|
Vulnerability in trendmicro (CVE-2025-71212)
vulnerability in trendmicro (CVE-2025-71212). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45760 |
|
Vulnerability in github.com/apache/camel-k/v2 (CVE-2026-45760)
vulnerability in github.com/apache/camel-k/v2 (CVE-2026-45760). Confidential information can be exposed externally. Mitigation: upgrade to `2.10.1` or later.
|
| CVE-2026-9126 |
|
Use-After-Free in google (CVE-2026-9126)
vulnerability in google (CVE-2026-9126). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9123 |
|
Vulnerability in google (CVE-2026-9123)
vulnerability in google (CVE-2026-9123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9121 |
|
Out-of-Bounds Read in google (CVE-2026-9121)
vulnerability in google (CVE-2026-9121). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9117 |
|
Vulnerability in google (CVE-2026-9117)
vulnerability in google (CVE-2026-9117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9120 |
|
Use-After-Free in google (CVE-2026-9120)
vulnerability in google (CVE-2026-9120). Successful exploitation can lead to full system takeover.
|