Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-7336 |
|
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7337 |
|
Vulnerability in google (CVE-2026-7337)
vulnerability in google (CVE-2026-7337). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7338 |
|
Use-After-Free in google (CVE-2026-7338)
vulnerability in google (CVE-2026-7338). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7339 |
|
Vulnerability in google (CVE-2026-7339)
vulnerability in google (CVE-2026-7339). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7340 |
|
Vulnerability in google (CVE-2026-7340)
vulnerability in google (CVE-2026-7340). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7341 |
|
Use-After-Free in google (CVE-2026-7341)
vulnerability in google (CVE-2026-7341). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7342 |
|
Use-After-Free in google (CVE-2026-7342)
vulnerability in google (CVE-2026-7342). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7343 |
|
Use-After-Free in google (CVE-2026-7343)
vulnerability in google (CVE-2026-7343). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7344 |
|
Use-After-Free in google (CVE-2026-7344)
vulnerability in google (CVE-2026-7344). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7333 |
|
Use-After-Free in google (CVE-2026-7333)
vulnerability in google (CVE-2026-7333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7334 |
|
Use-After-Free in google (CVE-2026-7334)
vulnerability in google (CVE-2026-7334). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40296 |
|
Cross-Site Scripting (XSS) in phpoffice/phpspreadsheet (CVE-2026-40296)
cross-site scripting in phpoffice/phpspreadsheet (CVE-2026-40296). Risk of unauthorized operations or information disclosure. Exploitable via ``General``. Mitigation: upgrade to `1.30.4` or later.
|
| CVE-2026-30246 |
|
Vulnerability in github.com/gofiber/fiber/v3 (CVE-2026-30246)
vulnerability in github.com/gofiber/fiber/v3 (CVE-2026-30246). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-7306 |
|
Vulnerability in CVE-2026-7306 (CVE-2026-7306)
vulnerability in CVE-2026-7306 (CVE-2026-7306). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7296 |
|
Cross-Site Scripting (XSS) in CVE-2026-7296 (CVE-2026-7296)
cross-site scripting in CVE-2026-7296 (CVE-2026-7296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7297 |
|
Cross-Site Scripting (XSS) in CVE-2026-7297 (CVE-2026-7297)
cross-site scripting in CVE-2026-7297 (CVE-2026-7297). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7303 |
|
Vulnerability in CVE-2026-7303 (CVE-2026-7303)
vulnerability in CVE-2026-7303 (CVE-2026-7303). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7305 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-7305 (CVE-2026-7305)
SSRF in CVE-2026-7305 (CVE-2026-7305). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37750 |
|
Cross-Site Scripting (XSS) in CVE-2026-37750 (CVE-2026-37750)
cross-site scripting in CVE-2026-37750 (CVE-2026-37750). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33467 |
|
Vulnerability in github.com/elastic/package-registry (CVE-2026-33467)
vulnerability in github.com/elastic/package-registry (CVE-2026-33467). Data can be tampered with by attackers. Mitigation: upgrade to `1.38.0` or later.
|
| CVE-2026-7295 |
|
Cross-Site Scripting (XSS) in CVE-2026-7295 (CVE-2026-7295)
cross-site scripting in CVE-2026-7295 (CVE-2026-7295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6238 |
|
Vulnerability in c (CVE-2026-6238)
vulnerability in c (CVE-2026-6238). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42432 |
|
Vulnerability in openclaw (CVE-2026-42432)
vulnerability in openclaw (CVE-2026-42432). Successful exploitation can lead to full system takeover. Exploitable via ``openclaw``. Mitigation: upgrade to `2026.4.8` or later.
|
| CVE-2026-42429 |
|
Privilege Escalation in openclaw (CVE-2026-42429)
vulnerability in openclaw (CVE-2026-42429). Data can be tampered with by attackers. Exploitable via ``operator.read``. Mitigation: upgrade to `2026.4.8` or later.
|
| CVE-2026-7324 |
|
Buffer Overflow in mozilla (CVE-2026-7324)
vulnerability in mozilla (CVE-2026-7324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7320 |
|
Buffer Overflow in mozilla (CVE-2026-7320)
vulnerability in mozilla (CVE-2026-7320). Confidential information can be exposed externally.
|
| CVE-2026-7322 |
|
Buffer Overflow in mozilla (CVE-2026-7322)
vulnerability in mozilla (CVE-2026-7322). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7323 |
|
Buffer Overflow in mozilla (CVE-2026-7323)
vulnerability in mozilla (CVE-2026-7323). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27760 |
|
Code Injection in CVE-2026-27760 (CVE-2026-27760)
code injection in CVE-2026-27760 (CVE-2026-27760). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5944 |
|
Vulnerability in cisco (CVE-2026-5944)
vulnerability in cisco (CVE-2026-5944). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5435 |
|
Out-of-Bounds Write in c (CVE-2026-5435)
out-of-bounds write in c (CVE-2026-5435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41603 |
|
Vulnerability in apache (CVE-2026-41603)
vulnerability in apache (CVE-2026-41603). Confidential information can be exposed externally.
|
| CVE-2026-41604 |
|
Out-of-Bounds Read in apache (CVE-2026-41604)
vulnerability in apache (CVE-2026-41604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41607 |
|
Out-of-Bounds Read in apache (CVE-2026-41607)
vulnerability in apache (CVE-2026-41607). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41605 |
|
Vulnerability in apache (CVE-2026-41605)
vulnerability in apache (CVE-2026-41605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41606 |
|
Vulnerability in apache (CVE-2026-41606)
vulnerability in apache (CVE-2026-41606). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-48431 |
|
Vulnerability in apache (CVE-2025-48431)
vulnerability in apache (CVE-2025-48431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41602 |
|
Vulnerability in apache (CVE-2026-41602)
vulnerability in apache (CVE-2026-41602). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7222 |
|
Cross-Site Scripting (XSS) in CVE-2026-7222 (CVE-2026-7222)
cross-site scripting in CVE-2026-7222 (CVE-2026-7222). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0711 |
|
OS Command Injection in zyxel (CVE-2026-0711)
OS command injection in zyxel (CVE-2026-0711). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1460 |
|
OS Command Injection in zyxel (CVE-2026-1460)
OS command injection in zyxel (CVE-2026-1460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40973 |
|
Vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973)
vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973). Successful exploitation can lead to full system takeover. Exploitable via ``ApplicationTemp``.
|
| CVE-2026-40976 |
|
Vulnerability in org.springframework.boot:spring-boot (CVE-2026-40976)
vulnerability in org.springframework.boot:spring-boot (CVE-2026-40976). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.6` or later.
|
| CVE-2026-7200 |
|
Cross-Site Scripting (XSS) in CVE-2026-7200 (CVE-2026-7200)
cross-site scripting in CVE-2026-7200 (CVE-2026-7200). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7199 |
|
Vulnerability in sqli (CVE-2026-7199)
vulnerability in sqli (CVE-2026-7199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41368 |
|
Vulnerability in openclaw (CVE-2026-41368)
vulnerability in openclaw (CVE-2026-41368). Confidential information can be exposed externally.
|
| CVE-2026-41369 |
|
Vulnerability in openclaw (CVE-2026-41369)
vulnerability in openclaw (CVE-2026-41369). Confidential information can be exposed externally.
|
| CVE-2026-41370 |
|
Path Traversal in path-traversal (CVE-2026-41370)
path traversal in path-traversal (CVE-2026-41370). Confidential information can be exposed externally.
|
| CVE-2026-41371 |
|
Authorization Flaw in privilege-escalation (CVE-2026-41371)
vulnerability in privilege-escalation (CVE-2026-41371). Data can be tampered with by attackers.
|
| CVE-2026-41372 |
|
Vulnerability in openclaw (CVE-2026-41372)
vulnerability in openclaw (CVE-2026-41372). Risk of unauthorized operations or information disclosure.
|