Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-40244 |
|
Vulnerability in openexr (CVE-2026-40244)
vulnerability in openexr (CVE-2026-40244). Data can be tampered with by attackers. Exploitable via ``int32``.
|
| CVE-2026-5928 |
|
Vulnerability in c (CVE-2026-5928)
vulnerability in c (CVE-2026-5928). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41445 |
|
Vulnerability in c (CVE-2026-41445)
vulnerability in c (CVE-2026-41445). Successful exploitation can lead to full system takeover.
|
| CVE-2026-30266 |
|
Vulnerability in deepcool (CVE-2026-30266)
vulnerability in deepcool (CVE-2026-30266). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34427 |
|
Vulnerability in privilege-escalation (CVE-2026-34427)
vulnerability in privilege-escalation (CVE-2026-34427). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34428 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-34428 (CVE-2026-34428)
SSRF in CVE-2026-34428 (CVE-2026-34428). Confidential information can be exposed externally.
|
| CVE-2026-31430 |
|
Out-of-Bounds Read in linux (CVE-2026-31430)
vulnerability in linux (CVE-2026-31430). Confidential information can be exposed externally.
|
| CVE-2026-5966 |
|
Vulnerability in path-traversal (CVE-2026-5966)
vulnerability in path-traversal (CVE-2026-5966). Data can be tampered with by attackers.
|
| CVE-2026-39454 |
|
Vulnerability in skygroup (CVE-2026-39454)
vulnerability in skygroup (CVE-2026-39454). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5967 |
|
OS Command Injection in privilege-escalation (CVE-2026-5967)
OS command injection in privilege-escalation (CVE-2026-5967). Successful exploitation can lead to full system takeover.
|
| CVE-2026-20122 KEV |
|
[KEV] Vulnerability in Cisco catalyst-sd-wan-manger (CVE-2026-20122)
vulnerability in Cisco catalyst-sd-wan-manger (CVE-2026-20122). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-20133 KEV |
|
[KEV] Information Disclosure in Cisco catalyst-sd-wan-manager (CVE-2026-20133)
vulnerability in Cisco catalyst-sd-wan-manager (CVE-2026-20133). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-2749 KEV |
|
[KEV] Path Traversal in Kentico path-traversal (CVE-2025-2749)
path traversal in Kentico path-traversal (CVE-2025-2749). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-27351 KEV |
|
[KEV] Authentication Bypass in Papercut ngmf (CVE-2023-27351)
authentication bypass in Papercut ngmf (CVE-2023-27351). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-48700 KEV |
|
[KEV] Cross-Site Scripting (XSS) in Synacor zimbra-collaboration-suite-zcs (CVE-2025-48700)
cross-site scripting in Synacor zimbra-collaboration-suite-zcs (CVE-2025-48700). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-20128 KEV |
|
[KEV] Vulnerability in Cisco catalyst-sd-wan-manager (CVE-2026-20128)
vulnerability in Cisco catalyst-sd-wan-manager (CVE-2026-20128). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-32975 KEV |
|
[KEV] Authentication Bypass in Quest kace-systems-management-appliance-sma (CVE-2025-32975)
authentication bypass in Quest kace-systems-management-appliance-sma (CVE-2025-32975). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-27199 KEV |
|
[KEV] Vulnerability in Jetbrains teamcity (CVE-2024-27199)
vulnerability in Jetbrains teamcity (CVE-2024-27199). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-40192 |
|
Vulnerability in pillow (CVE-2026-40192)
vulnerability in pillow (CVE-2026-40192). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.2.0` or later.
|
| CVE-2026-40323 |
|
Vulnerability in succinct (CVE-2026-40323)
vulnerability in succinct (CVE-2026-40323). Data can be tampered with by attackers.
|
| CVE-2026-40476 |
|
Vulnerability in webonyx/graphql-php (CVE-2026-40476)
vulnerability in webonyx/graphql-php (CVE-2026-40476). Risk of unauthorized operations or information disclosure. Exploitable via ``OverlappingFieldsCanBeMerged``. Mitigation: upgrade to `15.31.5` or later.
|
| CVE-2026-40527 |
|
OS Command Injection in radare (CVE-2026-40527)
OS command injection in radare (CVE-2026-40527). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40066 |
|
Vulnerability in anviz (CVE-2026-40066)
vulnerability in anviz (CVE-2026-40066). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5718 |
|
Unrestricted File Upload in wordpress (CVE-2026-5718)
vulnerability in wordpress (CVE-2026-5718). Successful exploitation can lead to full system takeover.
|
| CVE-2026-21733 |
|
Vulnerability in imaginationtech (CVE-2026-21733)
vulnerability in imaginationtech (CVE-2026-21733). Confidential information can be exposed externally.
|
| CVE-2026-40518 |
|
Path Traversal in path-traversal (CVE-2026-40518)
path traversal in path-traversal (CVE-2026-40518). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40515 |
|
Authorization Flaw in hkuds (CVE-2026-40515)
vulnerability in hkuds (CVE-2026-40515). Confidential information can be exposed externally.
|
| CVE-2026-40516 |
|
SSRF (Server-Side Request Forgery) in hkuds (CVE-2026-40516)
SSRF in hkuds (CVE-2026-40516). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6507 |
|
Out-of-Bounds Write in dos (CVE-2026-6507)
out-of-bounds write in dos (CVE-2026-6507). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-15623 |
|
Vulnerability in sparxsystems (CVE-2025-15623)
vulnerability in sparxsystems (CVE-2025-15623). Confidential information can be exposed externally.
|
| CVE-2025-15624 |
|
Vulnerability in sparxsystems (CVE-2025-15624)
vulnerability in sparxsystems (CVE-2025-15624). Confidential information can be exposed externally.
|
| CVE-2026-23853 |
|
Vulnerability in dell (CVE-2026-23853)
vulnerability in dell (CVE-2026-23853). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5807 |
|
Vulnerability in github.com/hashicorp/vault (CVE-2026-5807)
vulnerability in github.com/hashicorp/vault (CVE-2026-5807). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4525 |
|
Vulnerability in github.com/hashicorp/vault (CVE-2026-4525)
vulnerability in github.com/hashicorp/vault (CVE-2026-4525). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3605 |
|
Vulnerability in github.com/hashicorp/vault (CVE-2026-3605)
vulnerability in github.com/hashicorp/vault (CVE-2026-3605). Data can be tampered with by attackers.
|
| CVE-2026-6100 |
|
Use-After-Free in python (CVE-2026-6100)
vulnerability in python (CVE-2026-6100). Successful exploitation can lead to full system takeover. Exploitable via ``lzma.LZMADecompressor``. Mitigation: upgrade to `3.14.5` or later.
|
| CVE-2026-4786 |
|
Command Injection in libpython (CVE-2026-4786)
command injection in libpython (CVE-2026-4786). Confidential information can be exposed externally. Mitigation: upgrade to `3.14.5` or later.
|
| CVE-2026-41113 |
|
OS Command Injection in c (CVE-2026-41113)
OS command injection in c (CVE-2026-41113). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40170 |
|
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buf...
ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transpo...
|
| CVE-2025-54502 |
|
Vulnerability in privilege-escalation (CVE-2025-54502)
vulnerability in privilege-escalation (CVE-2025-54502). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56270 |
|
Vulnerability in flowise (CVE-2026-56270)
vulnerability in flowise (CVE-2026-56270). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/loginmethod`. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-41205 |
|
Path Traversal in Mako (CVE-2026-41205)
path traversal in Mako (CVE-2026-41205). Confidential information can be exposed externally. Exploitable via ``Template.__init__``. Mitigation: upgrade to `1.3.11` or later.
|
| CVE-2026-41082 |
|
Vulnerability in ocaml (CVE-2026-41082)
vulnerability in ocaml (CVE-2026-41082). Data can be tampered with by attackers.
|
| CVE-2026-2336 |
|
Vulnerability in privilege-escalation (CVE-2026-2336)
vulnerability in privilege-escalation (CVE-2026-2336). Successful exploitation can lead to full system takeover.
|
| CVE-2026-3324 |
|
Vulnerability in zohocorp (CVE-2026-3324)
vulnerability in zohocorp (CVE-2026-3324). Confidential information can be exposed externally.
|
| CVE-2026-33804 |
|
Vulnerability in fastify (CVE-2026-33804)
vulnerability in fastify (CVE-2026-33804). Confidential information can be exposed externally.
|
| CVE-2026-30459 |
|
Vulnerability in thedaylightstudio (CVE-2026-30459)
vulnerability in thedaylightstudio (CVE-2026-30459). Data can be tampered with by attackers.
|
| CVE-2026-41035 |
|
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort...
In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort...
|
| CVE-2026-6351 |
|
Vulnerability in CVE-2026-6351 (CVE-2026-6351)
vulnerability in CVE-2026-6351 (CVE-2026-6351). Confidential information can be exposed externally.
|
| CVE-2026-6348 |
|
Vulnerability in CVE-2026-6348 (CVE-2026-6348)
vulnerability in CVE-2026-6348 (CVE-2026-6348). Successful exploitation can lead to full system takeover.
|