Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-7344 Use-After-Free in google (CVE-2026-7344)
vulnerability in google (CVE-2026-7344). Successful exploitation can lead to full system takeover.
CVE-2026-42167 SQL Injection in proftpd (CVE-2026-42167)
SQL injection in proftpd (CVE-2026-42167). Successful exploitation can lead to full system takeover.
CVE-2026-7334 Use-After-Free in google (CVE-2026-7334)
vulnerability in google (CVE-2026-7334). Successful exploitation can lead to full system takeover.
CVE-2026-7319 Path Traversal in path-traversal (CVE-2026-7319)
path traversal in path-traversal (CVE-2026-7319). Risk of unauthorized operations or information disclosure.
CVE-2026-7314 Path Traversal in path-traversal (CVE-2026-7314)
path traversal in path-traversal (CVE-2026-7314). Risk of unauthorized operations or information disclosure.
CVE-2026-7315 Path Traversal in path-traversal (CVE-2026-7315)
path traversal in path-traversal (CVE-2026-7315). Risk of unauthorized operations or information disclosure.
CVE-2026-7316 Vulnerability in CVE-2026-7316 (CVE-2026-7316)
vulnerability in CVE-2026-7316 (CVE-2026-7316). Risk of unauthorized operations or information disclosure.
CVE-2026-41649 Vulnerability in getoutline (CVE-2026-41649)
vulnerability in getoutline (CVE-2026-41649). Confidential information can be exposed externally. Exploitable via ``shares.create``.
CVE-2026-42432 Vulnerability in openclaw (CVE-2026-42432)
vulnerability in openclaw (CVE-2026-42432). Successful exploitation can lead to full system takeover. Exploitable via ``openclaw``. Mitigation: upgrade to `2026.4.8` or later.
CVE-2026-42429 Privilege Escalation in openclaw (CVE-2026-42429)
vulnerability in openclaw (CVE-2026-42429). Data can be tampered with by attackers. Exploitable via ``operator.read``. Mitigation: upgrade to `2026.4.8` or later.
CVE-2026-38949 Cross-Site Scripting (XSS) in CVE-2026-38949 (CVE-2026-38949)
cross-site scripting in CVE-2026-38949 (CVE-2026-38949). Confidential information can be exposed externally.
CVE-2026-38651 Vulnerability in github.com/gravitl/netmaker (CVE-2026-38651)
vulnerability in github.com/gravitl/netmaker (CVE-2026-38651). Confidential information can be exposed externally. Exploitable via ``VerifyHostToken``. Mitigation: upgrade to `1.5.0` or later.
CVE-2026-7324 Buffer Overflow in mozilla (CVE-2026-7324)
vulnerability in mozilla (CVE-2026-7324). Risk of unauthorized operations or information disclosure.
CVE-2026-7320 Buffer Overflow in mozilla (CVE-2026-7320)
vulnerability in mozilla (CVE-2026-7320). Confidential information can be exposed externally.
CVE-2026-7322 Buffer Overflow in mozilla (CVE-2026-7322)
vulnerability in mozilla (CVE-2026-7322). Risk of unauthorized operations or information disclosure.
CVE-2026-7323 Buffer Overflow in mozilla (CVE-2026-7323)
vulnerability in mozilla (CVE-2026-7323). Risk of unauthorized operations or information disclosure.
CVE-2026-27760 Code Injection in CVE-2026-27760 (CVE-2026-27760)
code injection in CVE-2026-27760 (CVE-2026-27760). Successful exploitation can lead to full system takeover.
CVE-2026-5944 Vulnerability in cisco (CVE-2026-5944)
vulnerability in cisco (CVE-2026-5944). Risk of unauthorized operations or information disclosure.
CVE-2026-5781 Vulnerability in agilonhealth (CVE-2026-5781)
vulnerability in agilonhealth (CVE-2026-5781). Successful exploitation can lead to full system takeover.
CVE-2026-5435 Out-of-Bounds Write in c (CVE-2026-5435)
out-of-bounds write in c (CVE-2026-5435). Risk of unauthorized operations or information disclosure.
CVE-2025-48431 Vulnerability in apache (CVE-2025-48431)
vulnerability in apache (CVE-2025-48431). Risk of unauthorized operations or information disclosure.
CVE-2026-41603 Vulnerability in apache (CVE-2026-41603)
vulnerability in apache (CVE-2026-41603). Confidential information can be exposed externally.
CVE-2026-41604 Out-of-Bounds Read in apache (CVE-2026-41604)
vulnerability in apache (CVE-2026-41604). Risk of unauthorized operations or information disclosure.
CVE-2026-41605 Vulnerability in apache (CVE-2026-41605)
vulnerability in apache (CVE-2026-41605). Risk of unauthorized operations or information disclosure.
CVE-2026-3323 Vulnerability in vega (CVE-2026-3323)
vulnerability in vega (CVE-2026-3323). Confidential information can be exposed externally.
CVE-2026-41602 Vulnerability in apache (CVE-2026-41602)
vulnerability in apache (CVE-2026-41602). Risk of unauthorized operations or information disclosure.
CVE-2024-54013 Vulnerability in hanwhavision (CVE-2024-54013)
vulnerability in hanwhavision (CVE-2024-54013). Successful exploitation can lead to full system takeover.
CVE-2026-7223 SSRF (Server-Side Request Forgery) in CVE-2026-7223 (CVE-2026-7223)
SSRF in CVE-2026-7223 (CVE-2026-7223). Risk of unauthorized operations or information disclosure.
CVE-2026-7220 Command Injection in CVE-2026-7220 (CVE-2026-7220)
command injection in CVE-2026-7220 (CVE-2026-7220). Risk of unauthorized operations or information disclosure.
CVE-2026-7221 SSRF (Server-Side Request Forgery) in CVE-2026-7221 (CVE-2026-7221)
SSRF in CVE-2026-7221 (CVE-2026-7221). Risk of unauthorized operations or information disclosure.
CVE-2026-7219 Buffer Overflow in CVE-2026-7219 (CVE-2026-7219)
vulnerability in CVE-2026-7219 (CVE-2026-7219). Successful exploitation can lead to full system takeover.
CVE-2026-7215 Vulnerability in CVE-2026-7215 (CVE-2026-7215)
vulnerability in CVE-2026-7215 (CVE-2026-7215). Risk of unauthorized operations or information disclosure.
CVE-2026-7216 Path Traversal in path-traversal (CVE-2026-7216)
path traversal in path-traversal (CVE-2026-7216). Risk of unauthorized operations or information disclosure.
CVE-2026-7218 Buffer Overflow in CVE-2026-7218 (CVE-2026-7218)
vulnerability in CVE-2026-7218 (CVE-2026-7218). Successful exploitation can lead to full system takeover.
CVE-2026-1460 OS Command Injection in zyxel (CVE-2026-1460)
OS command injection in zyxel (CVE-2026-1460). Successful exploitation can lead to full system takeover.
CVE-2026-7212 Path Traversal in path-traversal (CVE-2026-7212)
path traversal in path-traversal (CVE-2026-7212). Risk of unauthorized operations or information disclosure.
CVE-2026-7213 Path Traversal in path-traversal (CVE-2026-7213)
path traversal in path-traversal (CVE-2026-7213). Risk of unauthorized operations or information disclosure.
CVE-2026-7214 Path Traversal in path-traversal (CVE-2026-7214)
path traversal in path-traversal (CVE-2026-7214). Risk of unauthorized operations or information disclosure.
CVE-2026-7206 Vulnerability in sqli (CVE-2026-7206)
vulnerability in sqli (CVE-2026-7206). Risk of unauthorized operations or information disclosure.
CVE-2026-7211 Vulnerability in CVE-2026-7211 (CVE-2026-7211)
vulnerability in CVE-2026-7211 (CVE-2026-7211). Risk of unauthorized operations or information disclosure.
CVE-2026-7205 Path Traversal in path-traversal (CVE-2026-7205)
path traversal in path-traversal (CVE-2026-7205). Risk of unauthorized operations or information disclosure.
CVE-2026-20766 Vulnerability in CVE-2026-20766 (CVE-2026-20766)
vulnerability in CVE-2026-20766 (CVE-2026-20766). Successful exploitation can lead to full system takeover.
CVE-2026-40973 Vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973)
vulnerability in org.springframework.boot:spring-boot (CVE-2026-40973). Successful exploitation can lead to full system takeover. Exploitable via ``ApplicationTemp``.
CVE-2026-7199 Vulnerability in sqli (CVE-2026-7199)
vulnerability in sqli (CVE-2026-7199). Risk of unauthorized operations or information disclosure.
CVE-2026-41371 Authorization Flaw in privilege-escalation (CVE-2026-41371)
vulnerability in privilege-escalation (CVE-2026-41371). Data can be tampered with by attackers.
CVE-2026-41364 Vulnerability in openclaw (CVE-2026-41364)
vulnerability in openclaw (CVE-2026-41364). Data can be tampered with by attackers.
CVE-2026-40972 Vulnerability in spring (CVE-2026-40972)
vulnerability in spring (CVE-2026-40972). Successful exploitation can lead to full system takeover.
CVE-2026-27785 Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
CVE-2024-1708 KEV [KEV] Path Traversal in Connectwise screenconnect (CVE-2024-1708)
path traversal in Connectwise screenconnect (CVE-2024-1708). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-7194 Vulnerability in sqli (CVE-2026-7194)
vulnerability in sqli (CVE-2026-7194). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →