Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-34486 KEV |
|
[KEV] Vulnerability in Apache tomcat (CVE-2026-34486)
vulnerability in Apache tomcat (CVE-2026-34486). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `9.0.117, 10.1.54, 11.0.21` or later.
|
| CVE-2026-29146 |
|
Vulnerability in apache (CVE-2026-29146)
vulnerability in apache (CVE-2026-29146). Confidential information can be exposed externally.
|
| CVE-2026-34971 |
|
Out-of-Bounds Read in bytecodealliance (CVE-2026-34971)
vulnerability in bytecodealliance (CVE-2026-34971). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `36.0.7` or later.
|
| CVE-2026-1584 |
|
Vulnerability in dos (CVE-2026-1584)
vulnerability in dos (CVE-2026-1584). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40072 |
|
SSRF (Server-Side Request Forgery) in web3 (CVE-2026-40072)
SSRF in web3 (CVE-2026-40072). Risk of unauthorized operations or information disclosure. Exploitable via ``OffchainLookup``. Mitigation: upgrade to `8.0.0b2` or later.
|
| CVE-2026-39983 |
|
Vulnerability in patrickjuchli (CVE-2026-39983)
vulnerability in patrickjuchli (CVE-2026-39983). Data can be tampered with by attackers. Mitigation: upgrade to `5.2.1` or later.
|
| CVE-2026-39981 |
|
Path Traversal in path-traversal (CVE-2026-39981)
path traversal in path-traversal (CVE-2026-39981). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.9.2` or later.
|
| CVE-2026-39911 |
|
Vulnerability in hedera (CVE-2026-39911)
vulnerability in hedera (CVE-2026-39911). Successful exploitation can lead to full system takeover.
|
| CVE-2026-39976 |
|
Authentication Bypass in laravel (CVE-2026-39976)
authentication bypass in laravel (CVE-2026-39976). Confidential information can be exposed externally. Mitigation: upgrade to `13.7.1` or later.
|
| CVE-2026-35204 |
|
Path Traversal in helm (CVE-2026-35204)
path traversal in helm (CVE-2026-35204). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.4` or later.
|
| CVE-2026-35205 |
|
Vulnerability in helm (CVE-2026-35205)
vulnerability in helm (CVE-2026-35205). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.1.4` or later.
|
| CVE-2025-70364 |
|
Code Injection in CVE-2025-70364 (CVE-2025-70364)
code injection in CVE-2025-70364 (CVE-2025-70364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4116 |
|
Vulnerability in sonicwall (CVE-2026-4116)
vulnerability in sonicwall (CVE-2026-4116). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4112 |
|
SQL Injection in sqli (CVE-2026-4112)
SQL injection in sqli (CVE-2026-4112). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4113 |
|
Vulnerability in sonicwall (CVE-2026-4113)
vulnerability in sonicwall (CVE-2026-4113). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4660 |
|
Information Disclosure in github.com/hashicorp/go-getter (CVE-2026-4660)
vulnerability in github.com/hashicorp/go-getter (CVE-2026-4660). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.6` or later.
|
| CVE-2026-34185 |
|
SQL Injection in sqli (CVE-2026-34185)
SQL injection in sqli (CVE-2026-34185). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5837 |
|
Vulnerability in sqli (CVE-2026-5837)
vulnerability in sqli (CVE-2026-5837). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5832 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-5832 (CVE-2026-5832)
SSRF in CVE-2026-5832 (CVE-2026-5832). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5828 |
|
Vulnerability in sqli (CVE-2026-5828)
vulnerability in sqli (CVE-2026-5828). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5829 |
|
Vulnerability in sqli (CVE-2026-5829)
vulnerability in sqli (CVE-2026-5829). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5830 |
|
Buffer Overflow in tenda (CVE-2026-5830)
vulnerability in tenda (CVE-2026-5830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4326 |
|
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate...
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability check...
|
| CVE-2026-5827 |
|
Vulnerability in sqli (CVE-2026-5827)
vulnerability in sqli (CVE-2026-5827). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5863 |
|
Vulnerability in google (CVE-2026-5863)
vulnerability in google (CVE-2026-5863). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5824 |
|
Vulnerability in sqli (CVE-2026-5824)
vulnerability in sqli (CVE-2026-5824). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5815 |
|
Buffer Overflow in CVE-2026-5815 (CVE-2026-5815)
vulnerability in CVE-2026-5815 (CVE-2026-5815). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5814 |
|
Vulnerability in sqli (CVE-2026-5814)
vulnerability in sqli (CVE-2026-5814). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5813 |
|
Vulnerability in c (CVE-2026-5813)
vulnerability in c (CVE-2026-5813). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5173 |
|
Vulnerability in gitlab (CVE-2026-5173)
vulnerability in gitlab (CVE-2026-5173). Confidential information can be exposed externally.
|
| CVE-2026-1092 |
|
Vulnerability in dos (CVE-2026-1092)
vulnerability in dos (CVE-2026-1092). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-12664 |
|
Vulnerability in dos (CVE-2025-12664)
vulnerability in dos (CVE-2025-12664). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5912 |
|
Vulnerability in google (CVE-2026-5912)
vulnerability in google (CVE-2026-5912). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5913 |
|
Out-of-Bounds Read in google (CVE-2026-5913)
vulnerability in google (CVE-2026-5913). Confidential information can be exposed externally.
|
| CVE-2026-5914 |
|
Vulnerability in google (CVE-2026-5914)
vulnerability in google (CVE-2026-5914). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5915 |
|
Vulnerability in google (CVE-2026-5915)
vulnerability in google (CVE-2026-5915). Data can be tampered with by attackers.
|
| CVE-2026-5907 |
|
Out-of-Bounds Read in google (CVE-2026-5907)
vulnerability in google (CVE-2026-5907). Confidential information can be exposed externally.
|
| CVE-2026-5908 |
|
Vulnerability in google (CVE-2026-5908)
vulnerability in google (CVE-2026-5908). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5909 |
|
Vulnerability in google (CVE-2026-5909)
vulnerability in google (CVE-2026-5909). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5910 |
|
Vulnerability in google (CVE-2026-5910)
vulnerability in google (CVE-2026-5910). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5884 |
|
Vulnerability in google (CVE-2026-5884)
vulnerability in google (CVE-2026-5884). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5883 |
|
Use-After-Free in google (CVE-2026-5883)
vulnerability in google (CVE-2026-5883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5877 |
|
Use-After-Free in google (CVE-2026-5877)
vulnerability in google (CVE-2026-5877). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5879 |
|
Vulnerability in google (CVE-2026-5879)
vulnerability in google (CVE-2026-5879). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5865 |
|
Vulnerability in google (CVE-2026-5865)
vulnerability in google (CVE-2026-5865). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5870 |
|
Vulnerability in google (CVE-2026-5870)
vulnerability in google (CVE-2026-5870). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5866 |
|
Use-After-Free in google (CVE-2026-5866)
vulnerability in google (CVE-2026-5866). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5868 |
|
Vulnerability in google (CVE-2026-5868)
vulnerability in google (CVE-2026-5868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5871 |
|
Vulnerability in google (CVE-2026-5871)
vulnerability in google (CVE-2026-5871). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5872 |
|
Use-After-Free in google (CVE-2026-5872)
vulnerability in google (CVE-2026-5872). Successful exploitation can lead to full system takeover.
|