Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-7344 |
|
Use-After-Free in google (CVE-2026-7344)
vulnerability in google (CVE-2026-7344). Successful exploitation can lead to full system takeover.
|
| CVE-2026-42167 |
|
SQL Injection in proftpd (CVE-2026-42167)
SQL injection in proftpd (CVE-2026-42167). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7334 |
|
Use-After-Free in google (CVE-2026-7334)
vulnerability in google (CVE-2026-7334). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7319 |
|
Path Traversal in path-traversal (CVE-2026-7319)
path traversal in path-traversal (CVE-2026-7319). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7314 |
|
Path Traversal in path-traversal (CVE-2026-7314)
path traversal in path-traversal (CVE-2026-7314). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7315 |
|
Path Traversal in path-traversal (CVE-2026-7315)
path traversal in path-traversal (CVE-2026-7315). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7316 |
|
Vulnerability in CVE-2026-7316 (CVE-2026-7316)
vulnerability in CVE-2026-7316 (CVE-2026-7316). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41649 |
|
Vulnerability in getoutline (CVE-2026-41649)
vulnerability in getoutline (CVE-2026-41649). Confidential information can be exposed externally. Exploitable via ``shares.create``.
|
| CVE-2026-42432 |
|
Vulnerability in openclaw (CVE-2026-42432)
vulnerability in openclaw (CVE-2026-42432). Successful exploitation can lead to full system takeover. Exploitable via ``openclaw``. Mitigation: upgrade to `2026.4.8` or later.
|
| CVE-2026-42429 |
|
Privilege Escalation in openclaw (CVE-2026-42429)
vulnerability in openclaw (CVE-2026-42429). Data can be tampered with by attackers. Exploitable via ``operator.read``. Mitigation: upgrade to `2026.4.8` or later.
|
| CVE-2026-38949 |
|
Cross-Site Scripting (XSS) in CVE-2026-38949 (CVE-2026-38949)
cross-site scripting in CVE-2026-38949 (CVE-2026-38949). Confidential information can be exposed externally.
|
| CVE-2026-38651 |
|
Vulnerability in github.com/gravitl/netmaker (CVE-2026-38651)
vulnerability in github.com/gravitl/netmaker (CVE-2026-38651). Confidential information can be exposed externally. Exploitable via ``VerifyHostToken``. Mitigation: upgrade to `1.5.0` or later.
|
| CVE-2026-7324 |
|
Buffer Overflow in mozilla (CVE-2026-7324)
vulnerability in mozilla (CVE-2026-7324). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7320 |
|
Buffer Overflow in mozilla (CVE-2026-7320)
vulnerability in mozilla (CVE-2026-7320). Confidential information can be exposed externally.
|
| CVE-2026-7322 |
|
Buffer Overflow in mozilla (CVE-2026-7322)
vulnerability in mozilla (CVE-2026-7322). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7323 |
|
Buffer Overflow in mozilla (CVE-2026-7323)
vulnerability in mozilla (CVE-2026-7323). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-27760 |
|
Code Injection in CVE-2026-27760 (CVE-2026-27760)
code injection in CVE-2026-27760 (CVE-2026-27760). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5944 |
|
Vulnerability in cisco (CVE-2026-5944)
vulnerability in cisco (CVE-2026-5944). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5781 |
|
Vulnerability in agilonhealth (CVE-2026-5781)
vulnerability in agilonhealth (CVE-2026-5781). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5435 |
|
Out-of-Bounds Write in c (CVE-2026-5435)
out-of-bounds write in c (CVE-2026-5435). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-48431 |
|
Vulnerability in apache (CVE-2025-48431)
vulnerability in apache (CVE-2025-48431). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41603 |
|
Vulnerability in apache (CVE-2026-41603)
vulnerability in apache (CVE-2026-41603). Confidential information can be exposed externally.
|
| CVE-2026-41604 |
|
Out-of-Bounds Read in apache (CVE-2026-41604)
vulnerability in apache (CVE-2026-41604). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41605 |
|
Vulnerability in apache (CVE-2026-41605)
vulnerability in apache (CVE-2026-41605). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3323 |
|
Vulnerability in vega (CVE-2026-3323)
vulnerability in vega (CVE-2026-3323). Confidential information can be exposed externally.
|
| CVE-2026-41602 |
|
Vulnerability in apache (CVE-2026-41602)
vulnerability in apache (CVE-2026-41602). Risk of unauthorized operations or information disclosure.
|
| CVE-2024-54013 |
|
Vulnerability in hanwhavision (CVE-2024-54013)
vulnerability in hanwhavision (CVE-2024-54013). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7223 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-7223 (CVE-2026-7223)
SSRF in CVE-2026-7223 (CVE-2026-7223). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7220 |
|
Command Injection in CVE-2026-7220 (CVE-2026-7220)
command injection in CVE-2026-7220 (CVE-2026-7220). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7221 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-7221 (CVE-2026-7221)
SSRF in CVE-2026-7221 (CVE-2026-7221). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7219 |
|
Buffer Overflow in CVE-2026-7219 (CVE-2026-7219)
vulnerability in CVE-2026-7219 (CVE-2026-7219). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7215 |
|
Vulnerability in CVE-2026-7215 (CVE-2026-7215)
vulnerability in CVE-2026-7215 (CVE-2026-7215). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7216 |
|
Path Traversal in path-traversal (CVE-2026-7216)
path traversal in path-traversal (CVE-2026-7216). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7218 |
|
Buffer Overflow in CVE-2026-7218 (CVE-2026-7218)
vulnerability in CVE-2026-7218 (CVE-2026-7218). Successful exploitation can lead to full system takeover.
|
| CVE-2026-1460 |
|
OS Command Injection in zyxel (CVE-2026-1460)
OS command injection in zyxel (CVE-2026-1460). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7212 |
|
Path Traversal in path-traversal (CVE-2026-7212)
path traversal in path-traversal (CVE-2026-7212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7213 |
|
Path Traversal in path-traversal (CVE-2026-7213)
path traversal in path-traversal (CVE-2026-7213). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7214 |
|
Path Traversal in path-traversal (CVE-2026-7214)
path traversal in path-traversal (CVE-2026-7214). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7206 |
|
Vulnerability in sqli (CVE-2026-7206)
vulnerability in sqli (CVE-2026-7206). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7211 |
|
Vulnerability in CVE-2026-7211 (CVE-2026-7211)
vulnerability in CVE-2026-7211 (CVE-2026-7211). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7205 |
|
Path Traversal in path-traversal (CVE-2026-7205)
path traversal in path-traversal (CVE-2026-7205). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20766 |
|
Vulnerability in CVE-2026-20766 (CVE-2026-20766)
vulnerability in CVE-2026-20766 (CVE-2026-20766). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40973 |
|
Vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973)
vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973). Successful exploitation can lead to full system takeover. Exploitable via ``ApplicationTemp``.
|
| CVE-2026-7199 |
|
Vulnerability in sqli (CVE-2026-7199)
vulnerability in sqli (CVE-2026-7199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41371 |
|
Authorization Flaw in privilege-escalation (CVE-2026-41371)
vulnerability in privilege-escalation (CVE-2026-41371). Data can be tampered with by attackers.
|
| CVE-2026-41364 |
|
Vulnerability in openclaw (CVE-2026-41364)
vulnerability in openclaw (CVE-2026-41364). Data can be tampered with by attackers.
|
| CVE-2026-40972 |
|
Vulnerability in spring (CVE-2026-40972)
vulnerability in spring (CVE-2026-40972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-27785 |
|
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
|
| CVE-2024-1708 KEV |
|
[KEV] Path Traversal in Connectwise screenconnect (CVE-2024-1708)
path traversal in Connectwise screenconnect (CVE-2024-1708). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-7194 |
|
Vulnerability in sqli (CVE-2026-7194)
vulnerability in sqli (CVE-2026-7194). Risk of unauthorized operations or information disclosure.
|