Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2019-25726 |
|
SQL Injection in sqli (CVE-2019-25726)
SQL injection in sqli (CVE-2019-25726). Confidential information can be exposed externally.
|
| CVE-2026-45337 |
|
Vulnerability in better-auth (CVE-2026-45337)
vulnerability in better-auth (CVE-2026-45337). Confidential information can be exposed externally. Exploitable via `POST /device/approve`. Mitigation: upgrade to `1.6.11` or later.
|
| CVE-2026-44496 |
|
Vulnerability in axios (CVE-2026-44496)
vulnerability in axios (CVE-2026-44496). Risk of unauthorized operations or information disclosure. Exploitable via ``document.cookie``. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-44488 |
|
Vulnerability in axios (CVE-2026-44488)
vulnerability in axios (CVE-2026-44488). Risk of unauthorized operations or information disclosure. Exploitable via ``fetch``. Mitigation: upgrade to `1.16.0` or later.
|
| CVE-2026-44487 |
|
Vulnerability in axios (CVE-2026-44487)
vulnerability in axios (CVE-2026-44487). Confidential information can be exposed externally. Exploitable via `Authorization header`. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-44486 |
|
Information Disclosure in axios (CVE-2026-44486)
vulnerability in axios (CVE-2026-44486). Confidential information can be exposed externally. Exploitable via `GET /start`. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-10843 |
|
Vulnerability in CVE-2026-10843 (CVE-2026-10843)
vulnerability in CVE-2026-10843 (CVE-2026-10843). Successful exploitation can lead to full system takeover.
|
| CVE-2025-52612 |
|
Vulnerability in hcltech (CVE-2025-52612)
vulnerability in hcltech (CVE-2025-52612). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10840 |
|
Vulnerability in CVE-2026-10840 (CVE-2026-10840)
vulnerability in CVE-2026-10840 (CVE-2026-10840). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-12694 |
|
Vulnerability in privilege-escalation (CVE-2025-12694)
vulnerability in privilege-escalation (CVE-2025-12694). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49771 |
|
SQL Injection in sqli (CVE-2026-49771)
SQL injection in sqli (CVE-2026-49771). Confidential information can be exposed externally.
|
| CVE-2026-50210 |
|
Information Disclosure in acer (CVE-2026-50210)
vulnerability in acer (CVE-2026-50210). Confidential information can be exposed externally.
|
| CVE-2026-50213 |
|
Vulnerability in acer (CVE-2026-50213)
vulnerability in acer (CVE-2026-50213). Confidential information can be exposed externally.
|
| CVE-2026-3820 |
|
OS Command Injection in CVE-2026-3820 (CVE-2026-3820)
OS command injection in CVE-2026-3820 (CVE-2026-3820). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50207 |
|
Path Traversal in acer (CVE-2026-50207)
path traversal in acer (CVE-2026-50207). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50209 |
|
Vulnerability in acer (CVE-2026-50209)
vulnerability in acer (CVE-2026-50209). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50205 |
|
Vulnerability in acer (CVE-2026-50205)
vulnerability in acer (CVE-2026-50205). Confidential information can be exposed externally.
|
| CVE-2026-49193 |
|
Information Disclosure in acer (CVE-2026-49193)
vulnerability in acer (CVE-2026-49193). Confidential information can be exposed externally.
|
| CVE-2026-49194 |
|
Authentication Bypass in acer (CVE-2026-49194)
authentication bypass in acer (CVE-2026-49194). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49202 |
|
Authentication Bypass in acer (CVE-2026-49202)
authentication bypass in acer (CVE-2026-49202). Confidential information can be exposed externally.
|
| CVE-2026-49203 |
|
Authentication Bypass in acer (CVE-2026-49203)
authentication bypass in acer (CVE-2026-49203). Data can be tampered with by attackers.
|
| CVE-2026-49190 |
|
OS Command Injection in acer (CVE-2026-49190)
OS command injection in acer (CVE-2026-49190). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49187 |
|
Information Disclosure in acer (CVE-2026-49187)
vulnerability in acer (CVE-2026-49187). Confidential information can be exposed externally.
|
| CVE-2026-49189 |
|
Privilege Escalation in acer (CVE-2026-49189)
vulnerability in acer (CVE-2026-49189). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41010 |
|
OS Command Injection in c (CVE-2026-41010)
OS command injection in c (CVE-2026-41010). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `282.1.12` or later.
|
| CVE-2026-10737 |
|
Vulnerability in wordpress (CVE-2026-10737)
vulnerability in wordpress (CVE-2026-10737). Confidential information can be exposed externally.
|
| CVE-2026-41859 |
|
Vulnerability in CVE-2026-41859 (CVE-2026-41859)
vulnerability in CVE-2026-41859 (CVE-2026-41859). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `282.1.9` or later.
|
| CVE-2026-41860 |
|
Vulnerability in CVE-2026-41860 (CVE-2026-41860)
vulnerability in CVE-2026-41860 (CVE-2026-41860). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `282.1.9` or later.
|
| CVE-2026-41858 |
|
Vulnerability in CVE-2026-41858 (CVE-2026-41858)
vulnerability in CVE-2026-41858 (CVE-2026-41858). Confidential information can be exposed externally. Mitigation: upgrade to `0.23.0` or later.
|
| CVE-2026-8829 |
|
Use-After-Free in oalders (CVE-2026-8829)
vulnerability in oalders (CVE-2026-8829). Confidential information can be exposed externally.
|
| CVE-2026-41011 |
|
OS Command Injection in c (CVE-2026-41011)
OS command injection in c (CVE-2026-41011). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `282.1.12` or later.
|
| CVE-2026-10777 |
|
A vulnerability was identified in ealpha072 Student-Management-System up to...
A vulnerability was identified in ealpha072 Student-Management-System up to...
|
| CVE-2026-10771 |
|
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate...
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate...
|
| CVE-2026-22054 |
|
Vulnerability in netapp (CVE-2026-22054)
vulnerability in netapp (CVE-2026-22054). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22055 |
|
Vulnerability in netapp (CVE-2026-22055)
vulnerability in netapp (CVE-2026-22055). Successful exploitation can lead to full system takeover.
|
| CVE-2026-52793 |
|
Authentication Bypass in froxlor/froxlor (CVE-2026-52793)
authentication bypass in froxlor/froxlor (CVE-2026-52793). Confidential information can be exposed externally. Exploitable via `POST /index.php`. Mitigation: upgrade to `2.3.7` or later.
|
| CVE-2026-44023 |
|
Path Traversal in docling-core (CVE-2026-44023)
path traversal in docling-core (CVE-2026-44023). Confidential information can be exposed externally. Mitigation: upgrade to `2.74.1` or later.
|
| CVE-2026-44019 |
|
Vulnerability in docling-core (CVE-2026-44019)
vulnerability in docling-core (CVE-2026-44019). Confidential information can be exposed externally. Mitigation: upgrade to `2.74.1` or later.
|
| CVE-2026-47214 |
|
Vulnerability in docling (CVE-2026-47214)
vulnerability in docling (CVE-2026-47214). Confidential information can be exposed externally. Exploitable via ``base_path``. Mitigation: upgrade to `2.94.0` or later.
|
| CVE-2026-44020 |
|
XXE (XML External Entity) in docling (CVE-2026-44020)
vulnerability in docling (CVE-2026-44020). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.74.0` or later.
|
| CVE-2026-44016 |
|
Code Injection in docling (CVE-2026-44016)
code injection in docling (CVE-2026-44016). Confidential information can be exposed externally. Exploitable via ``enable_remote_fetch``. Mitigation: upgrade to `2.91.0` or later.
|
| CVE-2026-41234 |
|
Vulnerability in froxlor/froxlor (CVE-2026-41234)
vulnerability in froxlor/froxlor (CVE-2026-41234). Data can be tampered with by attackers. Exploitable via ``DomainZones.add``. Mitigation: upgrade to `2.3.7` or later.
|
| CVE-2026-44609 |
|
Vulnerability in privilege-escalation (CVE-2026-44609)
vulnerability in privilege-escalation (CVE-2026-44609). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44682 |
|
Vulnerability in privilege-escalation (CVE-2026-44682)
vulnerability in privilege-escalation (CVE-2026-44682). Successful exploitation can lead to full system takeover.
|
| CVE-2026-50033 |
|
Vulnerability in privilege-escalation (CVE-2026-50033)
vulnerability in privilege-escalation (CVE-2026-50033). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42061 |
|
Vulnerability in privilege-escalation (CVE-2026-42061)
vulnerability in privilege-escalation (CVE-2026-42061). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44017 |
|
Path Traversal in docling (CVE-2026-44017)
path traversal in docling (CVE-2026-44017). Successful exploitation can lead to full system takeover. Exploitable via ``SecurityError``. Mitigation: upgrade to `2.91.0` or later.
|
| CVE-2026-8874 |
|
Vulnerability in c (CVE-2026-8874)
vulnerability in c (CVE-2026-8874). Data can be tampered with by attackers.
|
| CVE-2026-8876 |
|
Vulnerability in securly (CVE-2026-8876)
vulnerability in securly (CVE-2026-8876). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8878 |
|
Vulnerability in securly (CVE-2026-8878)
vulnerability in securly (CVE-2026-8878). Confidential information can be exposed externally.
|